{"id":9459,"date":"2025-12-06T05:32:19","date_gmt":"2025-12-06T05:32:19","guid":{"rendered":"https:\/\/techtrendfeed.com\/?p=9459"},"modified":"2025-12-06T05:32:19","modified_gmt":"2025-12-06T05:32:19","slug":"in-different-information-x-fined-e120-million-array-flaw-exploited-new-iranian-backdoor","status":"publish","type":"post","link":"https:\/\/techtrendfeed.com\/?p=9459","title":{"rendered":"In Different Information: X Fined \u20ac120 Million, Array Flaw Exploited, New Iranian Backdoor"},"content":{"rendered":"<p> <br \/>\n<\/p>\n<div>\n<p><strong>SecurityWeek\u2019s cybersecurity information roundup gives a concise compilation of noteworthy tales which may have slipped below the radar.<\/strong><\/p>\n<p>We offer a precious abstract of tales that won&#8217;t warrant a whole article, however are nonetheless necessary for a complete understanding of the cybersecurity panorama.<\/p>\n<p><a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.securityweek.com\/topics\/in-other-news\/\">Every week<\/a>, we curate and current a group of noteworthy developments, starting from the newest vulnerability discoveries and rising assault methods to important coverage modifications and trade reviews.\u00a0<\/p>\n<p><strong>Listed here are this week\u2019s tales:<\/strong><\/p>\n<p><strong>Claude Expertise used to execute ransomware<\/strong><\/p>\n<p>Cato Networks has used Expertise, a brand new characteristic for Anthropic\u2019s Claude AI assistant, to execute ransomware in a managed setting. Antrophic says the code execution performance works as meant for Expertise. Cato <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.catonetworks.com\/blog\/cato-ctrl-weaponizing-claude-skills-with-medusalocker\/\">argues<\/a> that authentic Expertise may very well be weaponized through minor modifications, and that they&#8217;ll propagate by public repositories and social engineering. Nonetheless, the safety agency admits that Claude shows clear approval prompts to the consumer.\u00a0<\/p>\n<p><strong>Array vulnerability exploited within the wild<\/strong><\/p>\n<p>Japan\u2019s JPCERT\/CC has <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.jpcert.or.jp\/at\/2025\/at250024.html\">warned<\/a> {that a} vulnerability affecting Array Networks\u2019 AG safe entry gateways has been exploited in assaults. The flaw, a command injection subject that doesn&#8217;t have a CVE identifier, was patched in Could 2025 with the discharge of ArrayOS AG 9.4.5.9. JPCERT has discovered proof that the vulnerability has been exploited towards customers in Japan since August 2025. The impacted product is prevalent in Asia.\u00a0<\/p>\n<div class=\"zox-post-ad-wrap\"><span class=\"zox-ad-label\">Commercial. Scroll to proceed studying.<\/span><\/div>\n<p><strong>North Korea suspected of $30 million Upbit cryptocurrency heist<\/strong><\/p>\n<p>Upbit, a significant South Korea-based cryptocurrency change, not too long ago had roughly $30 million of cryptocurrency stolen. The <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/en.yna.co.kr\/view\/AEN20251128003952320?section=national\/national\">heist<\/a> is believed to be the work of the North Korean hacking group Lazarus. Again in 2019, <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.securityweek.com\/hackers-steal-49-million-ethereum-cryptocurrency-exchange-upbit\/\">hackers stole $49 million<\/a> price of Ethereum from Upbit.\u00a0<\/p>\n<p><strong>Akamai patches HTTP request smuggling vulnerability<\/strong><\/p>\n<p>Akamai introduced this week that it not too long ago patched a vulnerability tracked as <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.akamai.com\/blog\/security\/2025\/dec\/cve-2025-66373-http-request-smuggling-chunked-body-size\">CVE-2025-66373<\/a> that might have uncovered clients to HTTP request smuggling assaults. Some of these assaults can usually be leveraged to steal credentials or different delicate knowledge, and to redirect customers to arbitrary web sites. <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.securityweek.com\/new-http-request-smuggling-attacks-impacted-cdns-major-orgs-millions-of-websites\/\">HTTP request smuggling<\/a> makes headlines each few years because of its probably important affect.\u00a0<\/p>\n<p><strong>CISA workers advised to not converse with reporters<\/strong><\/p>\n<p>A leaked inside e-mail revealed that management on the cybersecurity company CISA has requested workers to not speak to information reporters in an unauthorized capability, in keeping with <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.nextgov.com\/cybersecurity\/2025\/12\/cisa-tells-staff-not-speak-reporters-internal-email-shows\/409884\/\">Nextgov\/FCW<\/a>. \u201cIn in the present day\u2019s tradition of data saturation, it&#8217;s crucial that we guarantee all official data communicated on behalf of CISA is present, correct, unbiased, and authoritative. This contains any official data communicated to the media,\u201d the e-mail reads. It\u2019s unclear whether or not the memo was triggered by a selected incident.<\/p>\n<p><strong>North Korean faux IT employee recruiters caught on digicam<\/strong><\/p>\n<p>Researchers performed an intensive <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/any.run\/cybersecurity-blog\/lazarus-group-it-workers-investigation\/\">investigation<\/a> into <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.securityweek.com\/topics\/fake-it-workers\/\">North Korea\u2019s faux IT employee scheme<\/a>, detailing how authentic builders are lured into renting their credentials and identities to safe distant jobs in firms that prohibit hiring from the nation. The investigation, which included video calls with a number of North Korean recruiters, revealed that the recruiters requested for twenty-four\/7 entry to the developer\u2019s pc to facilitate the masquerade.<\/p>\n<p><strong>X fined \u20ac120 million over disinformation<\/strong><\/p>\n<p>The European Fee has <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/therecord.media\/eu-fines-x-under-digital-services-act-disinformation-transparecy-rules\">fined<\/a> the social media firm X with \u20ac120 million ($139 million) over its alleged failures to deal with disinformation. The effective was issued below the Digital Providers Act (DSA), which requires firms to guard customers towards disinformation and affect operations or face fines of as much as 6% of their turnover.\u00a0<\/p>\n<p><strong>New MuddyViper backdoor utilized by Iranian cyberspies\u00a0<\/strong><\/p>\n<p>The Iranian cyberespionage group named <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.securityweek.com\/us-cyber-command-officially-links-muddywater-group-iranian-intelligence\/\">MuddyWater<\/a> has developed a brand new backdoor dubbed <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.welivesecurity.com\/en\/eset-research\/muddywater-snakes-riverbank\/\">MuddyViper<\/a> by ESET. The safety agency has noticed assaults aimed toward Israel, with at the very least one sufferer in Egypt. In contrast to earlier MuddyWater assaults, which had been noisy and simple to detect, the brand new exercise was extra targeted and complicated.<\/p>\n<p><strong>PickleScan vulnerabilities<\/strong><\/p>\n<p>JFrog has disclosed the main points of three not too long ago patched <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/jfrog.com\/blog\/unveiling-3-zero-day-vulnerabilities-in-picklescan\/\">PickleScan vulnerabilities<\/a>. PickleScan is a instrument for scanning machine studying (ML) fashions to detect malicious content material. The vulnerabilities discovered by JFrog might have been exploited to \u201cevade PickleScan\u2019s malware detection and probably execute a large-scale provide chain assault by distributing malicious ML fashions that conceal undetectable malicious code\u201d.<\/p>\n<p><strong>Associated<\/strong>: <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.securityweek.com\/in-other-news-hashjack-ai-browser-attack-charming-kitten-leak-hacker-unmasked\/\">In Different Information: HashJack AI Browser Assault, Charming Kitten Leak, Hacker Unmasked<\/a><\/p>\n<p><strong>Associated<\/strong>: <a rel=\"nofollow\" target=\"_blank\" href=\"https:\/\/www.securityweek.com\/in-other-news-atm-jackpotting-whatsapp-nso-lawsuit-continues-cisa-hiring\/\">In Different Information: ATM Jackpotting, WhatsApp-NSO Lawsuit Continues, CISA Hiring<\/a>\n\t\t\t<\/p>\n<\/div>\n\n","protected":false},"excerpt":{"rendered":"<p>SecurityWeek\u2019s cybersecurity information roundup gives a concise compilation of noteworthy tales which may have slipped below the radar. We offer a precious abstract of tales that won&#8217;t warrant a whole article, however are nonetheless necessary for a complete understanding of the cybersecurity panorama. Every week, we curate and current a group of noteworthy developments, starting [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":9461,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[58],"tags":[6777,558,1994,5201,2705,3549,1636,121],"class_list":["post-9459","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity","tag-array","tag-backdoor","tag-exploited","tag-fined","tag-flaw","tag-iranian","tag-million","tag-news"],"_links":{"self":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts\/9459","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=9459"}],"version-history":[{"count":1,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts\/9459\/revisions"}],"predecessor-version":[{"id":9460,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/posts\/9459\/revisions\/9460"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=\/wp\/v2\/media\/9461"}],"wp:attachment":[{"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=9459"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=9459"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/techtrendfeed.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=9459"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}<!-- This website is optimized by Airlift. Learn more: https://airlift.net. Template:. Learn more: https://airlift.net. Template: 69d9690a190636c2e0989534. Config Timestamp: 2026-04-10 21:18:02 UTC, Cached Timestamp: 2026-05-27 15:06:43 UTC -->