← All issues
cybersecurityCyberBubblemalware

Your Car Has Malware, Your Email Server's Exposed, and TikTok Owes $400M

🌐  World Intel
Global: Chinese Cybercrime Group Uses AI to Hit Servers Across Five Countries

A cybercrime group called UAT-10147 is using malware and AI-powered tools to break into web servers in education, media, tech, and gaming companies. Targets have been found in Brazil, Bolivia, Canada, China, and Vietnam. Researchers at Cisco Talos discovered the operation after the group accidentally left a public-facing directory open — think of it as a burglar leaving their bag of tools on the front porch.

↗ The Hacker News
USA: TikTok Pays $400 Million Over Children's Privacy Violations

TikTok will pay $400 million to settle a US Department of Justice lawsuit accusing it of knowingly letting children under 13 open accounts and secretly collecting their data — even when parents asked for it to be deleted. ByteDance, TikTok's parent company, disputed the claims at the time but agreed to settle. It's one of the largest children's privacy penalties in US history.

↗ The Hacker News
USA: CISA Orders Emergency Patch for Actively Exploited Zimbra Flaw

The US government's cybersecurity agency, CISA, told all federal agencies they have just three days to patch a security hole in Zimbra Collaboration Suite — a widely used business email platform. The flaw is already being actively exploited in the wild, meaning hackers aren't waiting around. If you use Zimbra at work, flag it to your IT team today.

↗ BleepingComputer
⚔️  Active Attacks
Fake npm Packages Are Sneaking Malware Onto Developer Computers

Attackers published 14 fake software packages to npm, a popular tool developers use to download reusable code. The packages were disguised as innocent calendar and productivity utilities. The moment a developer imported one — even indirectly through another package — a hidden backdoor called RedC2 4.0 quietly installed itself in the background. This kind of attack is called a supply-chain attack, and it's especially nasty because the victim never does anything obviously wrong. The fake packages had names like streak-map-kit and streak-calc-math — designed to look legitimate at a glance.

🛡 What to do: If you're a developer or work with developers, ask your team whether they audit new package dependencies before installing them. Tools like Socket.dev can automatically flag suspicious packages before they touch your codebase.
ToxicPanda Android Malware Now Targets 349 Apps — Including Banking Apps

The ToxicPanda Android malware has gotten a significant upgrade. It now targets 349 apps — up sharply from earlier versions — and supports 167 remote commands that let attackers control an infected phone from afar. It abuses VPN permissions (which users often grant without thinking) to hide its traffic and bypass Google Play's security checks. Banking apps are a primary target.

🛡 What to do: Be suspicious of any app that asks for VPN permissions unless you know exactly why it needs them. Only install apps from sources you trust, and keep your Android OS updated.
🔓  New Vulnerabilities
BTR.sys / Windows Defender Microsoft Windows 7 through Windows 11 25H2 CRITICAL

Researchers at Check Point found that a legitimate, Microsoft-signed driver built into Windows Defender — called BTR.sys — can be turned against you. An attacker with the right access can use it to delete security software or tamper with system settings at boot time, with no outside tools required. Because the driver is a required Windows component, Microsoft can't simply block it without breaking Defender itself. No real-world attacks using this technique have been found yet, but the research was presented publicly at Black Hat USA 2026, which means the clock is ticking.

Status: No patch yet. Microsoft is aware. No evidence of active exploitation at time of publication.

Zimbra Collaboration Suite Zimbra ZCS — all versions before patched release HIGH — ACTIVELY EXPLOITED

This vulnerability in Zimbra's popular business email platform is already being exploited in real attacks right now. An attacker who exploits it could gain unauthorized access to email servers — potentially reading messages, stealing credentials, or using the server as a launchpad for deeper attacks on an organization's network. CISA gave US federal agencies just three days to patch it, which signals how urgent the situation is.

Status: Patch available. Apply immediately. CISA has issued a mandatory patching order for federal agencies.

TrueConf Server TrueConf self-hosted video conferencing platform HIGH — ACTIVELY EXPLOITED

CISA also flagged two actively exploited flaws in TrueConf Server, a self-hosted video conferencing tool used by businesses and government agencies. Organizations running TrueConf on their own servers are at risk. Attackers exploiting these flaws could potentially take control of the server or steal sensitive communications. This is a platform many people haven't heard of, but it's widely deployed in enterprise settings.

Status: Patches available. CISA has ordered federal agencies to patch immediately.

🛠  New Tech
DecryptAds: A Free Tool That Shows Who's Tracking You Through Website Ads

A new free service called DecryptAds (decryptads.com) lets anyone look up which advertising companies are collecting data on visitors to any website or app — and flags when those companies are based in high-risk countries like Russia, China, or the UAE. It was built by Zach Edwards, Chief Research Officer at Infoblox, alongside two other founders. The tool works by scraping publicly available but hard-to-read files that websites are required to publish listing their ad partners. A search for ESPN.com, for example, revealed 143 ad partners, 19 data brokers, and four ad companies linked to Russia, China, or the UAE — including one that processes payments through a sanctioned Russian bank. This matters for regular people because those ad trackers follow you across the web, often without you knowing.

↗ Krebs on Security
💡  Deep Dive
Your Car Has Malware Now: How Hackers Infected Android Head Units Through Fake Updates

For years, security researchers warned that as cars got smarter, they'd become targets. This week, that warning came true in a new way. Kaspersky disclosed the first documented malware family specifically designed to infect Android-based car head units — the touchscreen systems in millions of vehicles that handle navigation, music, and phone calls.

Here's how the attack works. The malware spread through the head unit's own built-in software updater — the same system meant to keep the device secure. Think of it like a pharmacist accidentally putting poison in your vitamins. Kaspersky researchers discovered the threat in June 2026 and linked it to a group called MoYu Group, which Google previously sued in 2025 for running a massive botnet called BADBOX. Once installed, the malware turns the car's head unit into one of two things: a device that clicks on invisible ads to generate fake revenue, or a proxy node that lets attackers disguise their location by routing traffic through your car's internet connection.

For most drivers, this probably won't feel like anything — your GPS still works, your music still plays. But in the background, your car is quietly doing the attacker's bidding. And because the malware arrives via the update system, your car's own defenses let it right in. The affected firmware is made by a manufacturer called DoFun. It's not a household name, but their software is in head units sold under many different brand names, meaning the actual reach could be significant.

This is the beginning of a trend, not a one-off. As more vehicles run Android and connect to the internet, they become permanent fixtures in the Internet of Things ecosystem, with all the same vulnerabilities. Unlike your phone, you can't easily factory reset your car's dashboard. Watch for firmware update notices from your vehicle manufacturer, and if your head unit behaves strangely — unexpected network activity, sluggishness, or battery drain — it's worth flagging to your dealer.

🛡️

Stay sharp. It's free.

Join thousands of readers who get daily cybersecurity news in plain English.

Subscribe Free →