## Threat of the Week
**Google Patches Actively Exploited Chrome Zero-Day**
Google has addressed a high-severity vulnerability (CVE-2025-2783, CVSS 8.3) in Chrome for Windows that threat actors exploited against Russian entities. The sophisticated attack combined multiple exploits to escape Chrome’s sandbox and execute remote code. Similar vulnerabilities have been patched in Mozilla Firefox and Tor Browser (CVE-2025-2857), though no exploitation has been detected for these browsers.
## Top Security Developments
**Critical Kubernetes Flaws Discovered**
Researchers uncovered “IngressNightmare,” a set of five vulnerabilities in the Ingress NGINX Controller for Kubernetes. The most severe (CVE-2025-1974, CVSS 9.8) allows unauthenticated attackers to execute arbitrary code. Patches are available in versions 1.12.1, 1.11.5, and 1.10.7.
**BlackLock Ransomware Group Exposed**
Security researchers infiltrated BlackLock’s data leak site through a local file inclusion vulnerability, extracting configuration files, credentials, and command history. The group uses Rclone to exfiltrate victim data to MEGA cloud storage across eight accounts.
**SUN:DOWN: 46 Vulnerabilities in Solar Inverters**
Researchers identified 46 security flaws in solar inverters from Sungrow, Growatt, and SMA. These vulnerabilities could allow attackers to execute arbitrary commands, take over accounts, and potentially cause power blackouts.
**RedCurl Deploys Custom Ransomware**
The corporate espionage group RedCurl has pivoted to deploying QWCrypt ransomware, marking an unusual tactical shift that raises questions about their motivations and business model.
**Credential Stuffing Tool Targets 140+ Platforms**
Threat actors are using Atlantis AIO Multi-Checker to automate credential stuffing attacks across more than 140 platforms, testing millions of stolen credentials rapidly while also supporting brute-force attacks.
**Chinese Hackers Maintain 4-Year Stealth Breach**
The Weaver Ant group maintained undetected access to a major Asian telecommunications company for over four years after exploiting a misconfiguration in a public-facing application.
**Morphing Meerkat: Sophisticated Phishing-as-a-Service**
A PhaaS operation called Morphing Meerkat uses DNS MX records and DNS-over-HTTPS to dynamically serve fake login pages impersonating 114 brands, exfiltrating captured credentials via Telegram or AJAX requests.
## Industry News
**23andMe Files for Bankruptcy**
Genetic testing company 23andMe has filed for Chapter 11 bankruptcy, raising concerns about the future of DNA records and personal information from 15 million customers. California’s Attorney General has issued a privacy alert detailing how users can delete their genetic data.
**North Korean Konni Group Using AsyncRAT**
The North Korea-linked Konni threat actor is distributing AsyncRAT malware through LNK files disguised as PDFs, using Dropbox and Google Drive to host intermediate payloads.
**Meta AI Launches in Europe with Limitations**
Meta has begun rolling out its AI assistant across Facebook, Instagram, WhatsApp, and Messenger in the EU and UK, but with limitations. The company confirmed the model wasn’t trained on first-party data from EU users due to regulatory constraints.
**Orion Framework Enables Privacy-Preserving AI**
Researchers from New York University have developed Orion, a framework that supports fully homomorphic encryption for deep learning, allowing AI models to operate on encrypted data without decryption.
**Pegasus Spyware Targets Serbian Journalists**
Two investigative journalists in Serbia were targeted with NSO Group’s Pegasus spyware via suspicious Viber messages, marking the third documented use of Pegasus against Serbian civil society in two years.
## Security Tips
**Disable Browser Autofill for Sensitive Fields**
Autofill features can leak data to malicious websites through hidden form fields. Disable autofill for personal and sensitive information in your browser settings:
– Chrome: Settings → Autofill
– Firefox: Settings → Privacy & Security
– Edge: Profiles → Personal Info & Payment Info
– Safari: Preferences → AutoFill
Consider using a password manager like Bitwarden or KeePassXC that requires explicit approval for autofill operations.
