⚡ SECURITY ALERT: Chinese APT Hijacks Google Calendar While Zero-Click Exploits Surge – This Week’s Critical Threats


# Modern Cyber Threats: Quiet, Convincing, and Fast

In today’s cybersecurity landscape, attacks happen with alarming subtlety. Defenders aren’t just battling hackers—they’re struggling to trust their own systems amid overwhelming alerts. When defense relies solely on obvious signs, you’re not protecting assets; you’re merely documenting their compromise.

## Threat Spotlight: APT41 Exploits Google Calendar

Chinese state-sponsored threat actor APT41 has deployed TOUGHPROGRESS malware that ingeniously uses Google Calendar for command-and-control operations. Observed in October 2024, the malware reads and writes events in attacker-controlled Google Calendars, extracting commands for execution and writing results back to Calendar events. The campaign targeted multiple government entities after being hosted on a compromised government website.

## Key Security Incidents

– **Law Enforcement Takes Down AvCheck.net**: US authorities, with Finland and Netherlands, seized domains offering counter-antivirus tools and crypting services that helped malware evade detection. The seizure exploited administrative mistakes, capturing user databases containing emails and payment information.

– **Void Blizzard Exposed**: A previously unknown Kremlin-linked hacker group responsible for the 2023 Dutch police cyberattack has been identified. The group has successfully remained undetected by using simple attack methods and readily available tools, targeting Ukraine and NATO member states.

– **EDDIESTEALER Bypasses Chrome Security**: A new Rust-based information stealer propagated via fake CAPTCHA pages can bypass Chromium’s app-bound encryption to access sensitive data like cookies by implementing ChromeKatz in Rust.

– **Earth Lamia Expands Operations**: This China-linked threat actor has broadened attacks targeting organizations in Brazil, India, and Southeast Asia since 2023, exploiting vulnerabilities in internet-exposed servers to deploy tools like Cobalt Strike and Brute Ratel C4.

– **ConnectWise Targeted by Nation-State Actor**: The developer of ScreenConnect disclosed a breach likely perpetrated by a nation-state actor exploiting CVE-2025-3935, a high-severity vulnerability in ScreenConnect that enables ViewState code injection attacks.

## Critical Vulnerabilities to Address

This week’s critical vulnerabilities include flaws in ConnectWise ScreenConnect, WooCommerce Wishlist plugin, GIMP, Arm Mali GPU, Citrix XenServer VM Tools, Argo CD, Apache Tomcat CGI servlet, Icinga 2, vBulletin, and several industrial control systems.

## Industry Developments

– **Australia Mandates Ransomware Payment Disclosure**: Australia became the first country requiring victims to declare ransomware payments to the government within 72 hours. The law applies to organizations with annual turnover exceeding AU$3 million.

– **X Pauses Encrypted DMs**: The platform is temporarily suspending its encrypted direct messaging feature for improvements. Users can still access existing encrypted DMs but cannot send new ones.

– **vBulletin Flaws Under Active Exploitation**: Two critical security flaws in vBulletin (CVE-2025-48827 and CVE-2025-48828) are being actively exploited, allowing unauthenticated users to execute arbitrary PHP code.

– **Safari Credential Theft Vulnerability**: A weakness in Apple’s Safari browser enables attackers to use the Fullscreen API for browser-in-the-middle attacks, stealing credentials by tricking users into typing sensitive data in attacker-controlled windows.

– **FTC Orders GoDaddy to Improve Security**: Following multiple data breaches between 2019-2022, GoDaddy must implement multi-factor authentication, conduct biennial security reviews, and report new breaches within 10 days.

– **US Government Employee Arrested for Attempted Espionage**: A 28-year-old DIA IT specialist was arrested for allegedly attempting to transmit classified information to a foreign government.

– **Android Malware Threats Evolve**: New Android malware GhostSpy enables comprehensive device monitoring and control, while Zanubis banking trojan has evolved to target financial institutions in Peru with improved data exfiltration capabilities.

## Security Tip: Use AI to Challenge Security Assumptions

AI tools can help identify vulnerabilities that even experts might miss. When reviewing systems, provide AI models with specific functions and background information, then ask targeted questions about potential failure points. AI explores all paths without making assumptions, potentially uncovering weak spots before attackers do.

Share This Article