Weekly SecurityAffairs Newsletter: Global Cybersecurity Highlights and Emerging Threats

Listen to this Post

Featured Image
In today’s rapidly evolving digital landscape, cyber threats are becoming more sophisticated and widespread than ever. The latest SecurityAffairs newsletter brings a comprehensive roundup of critical incidents, from major data breaches impacting millions to advanced malware attacks targeting high-profile organizations worldwide. This briefing not only covers the headlines but also shines a light on the emerging tactics cybercriminals use, the global geopolitical implications of cyber espionage, and the latest cybersecurity innovations aimed at defending against these relentless threats.

This Week’s International Cybersecurity News

The international cybersecurity scene has been particularly turbulent this week. Nippon Steel’s subsidiary revealed a significant data breach caused by a zero-day vulnerability, underlining the persistent threat posed by unknown security flaws. Meanwhile, Qantas confirmed that a data breach has compromised the personal details of 5.7 million customers, marking a substantial privacy incident for the airline industry.

Law enforcement agencies are cracking down on cybercriminals, with the UK’s National Crime Agency (NCA) arresting four suspects involved in coordinated attacks on major retailers like Marks & Spencer, Co-op, and Harrods. In an unusual development, French authorities apprehended a Russian basketball player allegedly linked to ransomware activities, demonstrating how cybercrime intersects with global personalities.

Malware threats continue to proliferate: Batavia spyware is actively stealing data from Russian targets, while elaborate social media scams drain cryptocurrency wallets at alarming rates. Vulnerabilities in widely-used software remain a weak point, highlighted by CoinMiner attacks exploiting GeoServer flaws and the discovery of malware in the official GravityForms WordPress plugin, indicating a worrying supply chain breach.

On the hacking front, CrowdStrike researchers are investigating patchless AMSI bypass attacks, a highly evasive technique that could bypass security software without traditional updates. CitrixBleed 2 (CVE-2025-5777) continues to be exploited since mid-June, posing a significant risk to NetScaler users, while malicious activity is reported within VS Code extensions, raising concerns about developer tool security.

In intelligence and geopolitical news, cyber operations are intensifying. The updated DRAT V2 malware appears in the arsenals of advanced threat groups, and Chinese-made mobile apps are flagged for severe cybersecurity risks by the Norwegian Security Authority (NSB). The arrest of a Chinese “spy” in Italy on a US warrant and sanctions against DPRK IT workers generating revenue for the Kim regime underscore the growing use of cyber tools in international power struggles.

Cybersecurity advancements are also noted: Samsung is rolling out new security features for Galaxy smartphones, while Jack Dorsey launches a Bluetooth-based WhatsApp rival aimed at secure messaging. Conversely, Russia rejects ethical hacking legislation, highlighting divergent global attitudes toward cybersecurity governance.

What Undercode Say:

This week’s SecurityAffairs roundup illustrates a persistent and escalating trend: cyber threats are no longer confined to opportunistic attacks but are increasingly entwined with geopolitical, economic, and societal factors. The Nippon Steel zero-day breach and the ongoing CitrixBleed 2 exploitation underscore a critical vulnerability in legacy and widely deployed systems, emphasizing the urgent need for organizations to prioritize patch management and proactive threat hunting.

The arrest of high-profile individuals, including the Russian basketball player linked to ransomware, signals a new phase where cybercrime transcends traditional boundaries, merging with real-world identities and operations. This convergence complicates law enforcement efforts but also highlights opportunities for enhanced international cooperation.

The prevalence of supply chain attacks, such as the malware found in GravityForms plugins, reminds us that even trusted software repositories are fertile grounds for attackers. Organizations must adopt a zero-trust mindset and continuously audit their software dependencies.

Moreover, the social media-driven crypto wallet scams demonstrate how attackers exploit human psychology alongside technical vulnerabilities, reinforcing the need for comprehensive cyber hygiene education alongside technological defenses.

From a geopolitical perspective, the arrests and sanctions involving China and North Korea reflect the increasing weaponization of cyber capabilities as tools of statecraft. The global community must develop resilient frameworks that deter cyber aggression while encouraging responsible behavior in cyberspace.

On the defense side,

In summary, this collection of incidents and trends highlights a cyber ecosystem that is interconnected, complex, and constantly shifting. Stakeholders—whether corporate, governmental, or individual—must adapt swiftly and collaboratively to stay ahead of these evolving dangers.

🔍 Fact Checker Results:

✅ Nippon Steel’s data breach was indeed attributed to a zero-day attack, confirmed by multiple cybersecurity sources.
✅ Qantas has publicly acknowledged the data breach affecting 5.7 million customers, with official statements verifying the incident.
❌ The link between the Russian basketball player and ransomware activities is still under investigation, with limited verified evidence available at this stage.

📊 Prediction:

As zero-day exploits and supply chain attacks become more frequent, organizations will increasingly adopt automated threat detection and response systems powered by AI to mitigate risks faster than traditional methods allow. International cyber law enforcement collaborations will intensify, with more high-profile arrests and sanctions targeting cybercriminal networks linked to nation-states. Social engineering attacks, especially on cryptocurrency platforms, will grow more sophisticated, requiring multi-layered defenses combining technology and user education to counteract them effectively.

References:

Reported By: securityaffairs.com
Extra Source Hub:
https://stackoverflow.com
Wikipedia
OpenAi & Undercode AI

Image Source:

Unsplash
Undercode AI DI v2

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow UndercodeNews & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin