Friday Wrap Up: 12 September 2025
π₯ This week in cyber was one for the history books.
π¦ The worldβs largest supply chain attack hit npm, with billions of downloads tainted.
β‘ Nation-state espionage escalated as China-linked groups ramped up campaigns tied to trade negotiations.
π» Ransomware evolved yet again, with HybridPetya breaking UEFI Secure Boot and Akira exploiting SonicWall appliances.
π± Meanwhile, Samsung scrambled to patch a WhatsApp-linked zero-day, and Apple unveiled a five-year project to shut down spyware developers.
And thatβs just scratching the surface β phishing kits got smarter, backdoors stealthier, and even βAI-codedβ mistakes sent companies back to hiring human developers.
π Curious about how these stories connect, and what they mean for your security strategy? β‘οΈ Check out this weekβs Friday Wrap-Up!
π¨ Major Supply Chain & Data Breaches
This week saw what may be the largest supply chain attack in history, alongside new corporate breaches.
π¦ Hackers hijack npm packages with 2.6B weekly downloads in historic supply chain attack (Published on 9/8/2025, BleepingComputer). Read More
ποΈ Plex urges password resets after hackers breach database of auth data (Published on 9/9/2025, SecurityWeek). Read More
π Blast radius of Salesloft Drift attacks still widening, severity unclear (Published on 9/4/2025, Dark Reading). Read More
π‘οΈ Malware & Vulnerabilities
Stealthy backdoors, cross-platform RATs, and new zero-days reminded defenders that attackers innovate quickly.
π GPUGate malware spreads via Google ads and fake GitHub commits (Published on 9/8/2025, The Hacker News). Read More
π§ Sitecore zero-day exploited to deploy WEEPSTEEL malware (Published on 9/8/2025, Hackread). Read More
π» MystRodX backdoor uses DNS & ICMP triggers for stealthy control (Published on 9/2/2025, The Hacker News). Read More
π CHILLYHELL macOS backdoor and ZynorRAT hit macOS, Windows, Linux (Published on 9/10/2025, The Hacker News). Read More
π ChillyHell macOS malware resurfaces using Google.com as a decoy (Published on 9/11/2025, Hackread). Read More
β‘ New VMScape attack breaks VM isolation on AMD & Intel CPUs (Published on 9/11/2025, BleepingComputer). Read More
π± Samsung patches actively exploited zero-day reported by WhatsApp (Published on 9/12/2025, BleepingComputer). Read More
π§ Fortinet, Ivanti & Nvidia issue patches for high-severity flaws (Published on 9/10/2025, SecurityWeek). Read More
π‘ Espionage & Nation-State Operations
China-linked actors dominated headlines with brazen espionage tied to trade negotiations and infrastructure access.
π¨π³ APT41 impersonated U.S. lawmaker to target trade groups with malware (Published on 9/8/2025, SecurityWeek). Read More
π°οΈ New infrastructure links 45 more domains to Salt Typhoon/UNC4841 espionage ops (Published on 9/8/2025, Dark Reading). Read More
ποΈ APT41 actively targeting U.S. trade officials amid negotiations (Published on 9/10/2025, The Hacker News). Read More
π» Ransomware & Financial Crime
AI and new tactics continue to fuel ransomwareβs evolution, including a throwback with a dangerous twist.
π Ransomware losses climb as AI drives phishing and triple extortion (Published on 9/9/2025, SecurityWeek). Read More
π Akira ransomware exploiting SonicWall flaw for access (Published on 9/11/2025, SecurityWeek). Read More
𧨠New HybridPetya ransomware bypasses UEFI Secure Boot via CVE-2024-7344 (Published on 9/12/2025, The Hacker News). Read More
π Phishing & Social Engineering
Attackers continue refining phishing kits and lures, targeting both MFA and public services.
πͺ Salty2FA phishing kit bypasses MFA & clones login portals (Published on 9/9/2025, Hackread). Read More
π Fake Bureau of Motor Vehicles texts steal banking details (Published on 9/11/2025, Malwarebytes). Read More
βοΈ Policy, Regulation & Industry Trends
Legal battles and compliance challenges reshaped the business side of cybersecurity.
π§© Apple unveils Memory Integrity Enforcement, crippling spyware devs (Published on 9/10/2025, CyberScoop). Read More
πΌ UK court to rule on legality of reselling enterprise software licenses (Published on 9/10/2025, ComputerWeekly). Read More
πͺπΊ Microsoft avoids EU fine by unbundling Teams from Office (Published on 9/12/2025, Ars Technica). Read More
π₯ Scattered Lapsus$ Hunters hacking group announces shutdown (Published on 9/12/2025, Hackread). Read More
π€ After AI layoffs, companies rehire coders to fix βvibe-codedβ errors (Published on 9/12/2025, Gizmodo). Read More
Stay informed and secure in the tech and cybersecurity world. Have a great weekend, and remember to patch and protect your systems!