{"id":7103,"date":"2025-09-22T10:03:27","date_gmt":"2025-09-22T10:03:27","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2025\/09\/22\/cybersecurity-newsletter-weekly-shai-halud-attack-ivanti-exploits-finwise-bmw-data-leak-and-more\/"},"modified":"2025-09-22T10:03:27","modified_gmt":"2025-09-22T10:03:27","slug":"cybersecurity-newsletter-weekly-shai-halud-attack-ivanti-exploits-finwise-bmw-data-leak-and-more","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2025\/09\/22\/cybersecurity-newsletter-weekly-shai-halud-attack-ivanti-exploits-finwise-bmw-data-leak-and-more\/","title":{"rendered":"Cybersecurity Newsletter Weekly \u2013 Shai Halud Attack, Ivanti Exploits, FinWise, BMW Data Leak, and More"},"content":{"rendered":"<p>    Cybersecurity Newsletter Weekly \u2013 Shai Halud Attack, Ivanti Exploits, FinWise, BMW Data Leak, and More<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>This week in cybersecurity, researchers exposed hidden alliances between ransomware groups, the rise of AI-powered phishing platforms, and large-scale vulnerabilities affecting telecom and enterprise systems. <\/p>\n<p>Major data breaches at financial services and luxury brands highlighted insider threats and supply chain risks, while arrests of Scattered Spider hackers signaled rare law enforcement wins. <\/p>\n<p>From botnets hijacking VPS servers to disinformation networks expanding globally, the threat landscape shows how cybercrime, espionage, and propaganda increasingly intersect, demanding stronger defenses and smarter detection strategies.<\/p>\n<p>Stay updated with the latest critical vulnerabilities, exploits, and supply chain threats impacting software, infrastructure, and end-users.<\/p>\n<h2 class=\"wp-block-heading\" id=\"h-vulnerabilities\"><strong>Vulnerabilities<\/strong><\/h2>\n<h3 class=\"wp-block-heading\" id=\"h-jenkins-security-updates-patch-multiple-flaws\"><strong>Jenkins Security Updates Patch Multiple Flaws<\/strong><\/h3>\n<p>Jenkins has released urgent patches for four vulnerabilities affecting its weekly releases up to 2.527 and LTS up to 2.516.2. The most severe,\u00a0<strong>CVE-2025-5115<\/strong>, is an HTTP\/2 denial-of-service issue in the bundled Jetty component, rated\u00a0<em>high severity<\/em>. Additional flaws include permission-check omissions and a log message injection bug.<\/p>\n<p>Administrators are strongly advised to upgrade to\u00a0<strong>weekly 2.528 or LTS 2.516.3<\/strong>\u00a0or disable HTTP\/2 where immediate upgrades aren\u2019t feasible. <a href=\"https:\/\/cybersecuritynews.com\/jenkins-patches-multiple-vulnerabilities\/\" target=\"_blank\" rel=\"noreferrer noopener\">Read More<\/a><\/p>\n<h3 class=\"wp-block-heading\"><strong>Pixie Dust Wi-Fi Attack Targets WPS<\/strong><\/h3>\n<p>The\u00a0<strong>Pixie Dust<\/strong>\u00a0attack re-emerges as a significant threat to Wi-Fi security, exploiting weak randomization in the\u00a0<strong>WPS (Wi-Fi Protected Setup)<\/strong>\u00a0protocol. Attackers can recover router WPS PINs offline, bypass WPA2 safeguards, and obtain the network\u2019s pre-shared key without brute forcing.<\/p>\n<p>Researchers emphasize disabling WPS or updating firmware as the only reliable defense. Organizations should audit wireless infrastructure immediately. <a href=\"https:\/\/cybersecuritynews.com\/pixie-dust-wi-fi-attack\/\" target=\"_blank\" rel=\"noreferrer noopener\">Read More<\/a><\/p>\n<h3 class=\"wp-block-heading\"><strong>Greenshot Vulnerability Exposes Sensitive Data<\/strong><\/h3>\n<p>Researchers discovered a flaw in\u00a0<strong>Greenshot<\/strong>, the popular screenshot tool, that could expose sensitive information. The vulnerability stems from unsafe file handling and could allow attackers to access or leak captured screenshots. A patch has been released, and users are urged to upgrade promptly. <a href=\"https:\/\/cybersecuritynews.com\/greenshot-vulnerability\/\" target=\"_blank\" rel=\"noreferrer noopener\">Read More<\/a><\/p>\n<h3 class=\"wp-block-heading\"><strong>Chaos Mesh Vulnerabilities Impact Kubernetes Workloads<\/strong><\/h3>\n<p>Multiple vulnerabilities have been identified in\u00a0<strong>Chaos Mesh<\/strong>, the chaos engineering tool for Kubernetes testing. Flaws could allow attackers to escalate privileges, inject malicious configurations, or disrupt cluster stability. Organizations using Chaos Mesh must apply the latest security updates.<\/p>\n<p><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/s.w.org\/images\/core\/emoji\/16.0.1\/72x72\/1f517.png?ssl=1\" alt=\"\ud83d\udd17\" class=\"wp-smiley\" style=\"height: 1em; max-height: 1em;\">\u00a0<a rel=\"noreferrer noopener\" target=\"_blank\" href=\"https:\/\/cybersecuritynews.com\/chaos-mesh-vulnerabilities\/\">Read More<\/a><\/p>\n<h3 class=\"wp-block-heading\"><strong>Kubernetes C Client Vulnerability Exposes Clusters<\/strong><\/h3>\n<p>The Kubernetes\u00a0<strong>C Client library<\/strong>\u00a0vulnerability exposes clusters to potential privilege escalation and unauthorized API access. Attackers could exploit misconfigurations or API flaws to gain deeper control over workloads. Upgrading to patched versions and tightening API access controls is advised. <a href=\"https:\/\/cybersecuritynews.com\/kubernetes-c-client-vulnerability-exposes\/\" target=\"_blank\" rel=\"noreferrer noopener\">Read More<\/a><\/p>\n<h3 class=\"wp-block-heading\"><strong>Linux Kernel KSMBD Subsystem Vulnerability<\/strong><\/h3>\n<p>A critical flaw in the\u00a0<strong>KSMBD subsystem<\/strong>\u00a0of the Linux kernel allows attackers to execute code remotely in certain configurations. This vulnerability poses a high risk for file-sharing services relying on SMB. Admins should apply kernel patches as soon as possible. <a href=\"https:\/\/cybersecuritynews.com\/linux-kernels-ksmbd-subsystem-vulnerability\/\" target=\"_blank\" rel=\"noreferrer noopener\">Read More<\/a><\/p>\n<h3 class=\"wp-block-heading\"><strong>Shai Halud Supply Chain Attack Uncovered<\/strong><\/h3>\n<p>A new\u00a0<strong>software supply-chain attack<\/strong>\u00a0named\u00a0<em>Shai Halud<\/em>\u00a0has been observed abusing CI\/CD pipelines and developer tools. Malicious dependencies were injected into trusted builds, potentially impacting downstream software users. Organizations are urged to implement strict code-signing and package validation practices. <a href=\"https:\/\/cybersecuritynews.com\/shai-halud-supply-chain-attack\/\" target=\"_blank\" rel=\"noreferrer noopener\">Read More<\/a><\/p>\n<h3 class=\"wp-block-heading\"><strong>0-Click Linux Kernel KSMBD RCE Exploit<\/strong><\/h3>\n<p>Researchers have demonstrated a\u00a0<strong>0-click RCE exploit<\/strong>\u00a0in the Linux kernel\u2019s\u00a0<strong>KSMBD subsystem<\/strong>, allowing remote code execution without user interaction. This development raises the severity of ongoing kernel threats, highlighting the urgency of patching affected systems immediately. <a href=\"https:\/\/cybersecuritynews.com\/0-click-linux-kernel-ksmbd-rce-exploit\/\" target=\"_blank\" rel=\"noreferrer noopener\">Read More<\/a><\/p>\n<h3 class=\"wp-block-heading\"><strong>Spring Framework and Microsoft 900+ XSS Vulnerabilities<\/strong><\/h3>\n<p>Two major updates reveal widespread exposure:<\/p>\n<ul class=\"wp-block-list\">\n<li>\n<strong>Spring Framework<\/strong>\u00a0patches multiple flaws, including input validation weaknesses that could lead to system compromise.<\/li>\n<li>\n<strong>Microsoft confirms over 900 XSS vulnerabilities<\/strong>\u00a0across its ecosystem, stressing the scale of insecure coding practices.<\/li>\n<\/ul>\n<p>Both cases underscore the growing challenge of secure software development at scale. <a href=\"https:\/\/cybersecuritynews.com\/spring-framework-and-security-vulnerabilities\/https:\/\/cybersecuritynews.com\/microsoft-confirms-900-xss-vulnerabilities\/\" target=\"_blank\" rel=\"noreferrer noopener\">Read More<\/a><\/p>\n<h2 class=\"wp-block-heading\" id=\"h-theats\"><strong>Theats<\/strong><\/h2>\n<h3 class=\"wp-block-heading\"><strong>Hidden Connections Between Ransomware Groups<\/strong><\/h3>\n<p>Recent research shows that ransomware operations like Conti, LockBit, and Evil Corp are no longer isolated competitors but participants in a flexible underground marketplace. After the Conti takedown, affiliates regrouped under new banners, leading to overlaps in infrastructure and code reuse. Analysts identified shared SSL certificates, passive DNS footprints, and identical encryption routines across Black Basta and QakBot, showing how code and infrastructure circulate freely. This evolution means defenders must focus less on brand names and more on shared TTPs and hidden infrastructure patterns. <a href=\"https:\/\/cybersecuritynews.com\/researchers-uncover-hidden-connections-between-ransomware-groups\/\" target=\"_blank\" rel=\"noreferrer noopener\">Read More<\/a><\/p>\n<h3 class=\"wp-block-heading\"><strong>AI-Powered Phishing Platforms on the Rise<\/strong><\/h3>\n<p>Phishing has entered a new era with the adoption of AI-driven platforms capable of generating convincing lures at scale. Attackers increasingly automate email writing, domain registration, and credential phishing kits, making campaigns harder to detect. These platforms drastically lower the barrier for novice cybercriminals while amplifying the reach of veteran actors. Security teams are now challenged to identify behavioral anomalies rather than relying on syntactic cues. <a href=\"https:\/\/cybersecuritynews.com\/phishing-attacks-using-ai-powered-platforms\/\" target=\"_blank\" rel=\"noreferrer noopener\">Read More<\/a><\/p>\n<h3 class=\"wp-block-heading\"><strong>Russian Groups Gamaredon and Turla Join Forces<\/strong><\/h3>\n<p>Two of Russia\u2019s most notorious cyber-espionage groups, Gamaredon and Turla, have shown signs of collaboration. While Gamaredon specializes in initial compromise across Ukrainian targets, Turla is known for stealthy persistence and espionage capabilities. By combining tools and infrastructure, these groups present a growing strategic risk for governmental and defense organizations. <a href=\"https:\/\/cybersecuritynews.com\/russian-hacking-groups-gamaredon-and-turla\/\" target=\"_blank\" rel=\"noreferrer noopener\">Read More<\/a><\/p>\n<h3 class=\"wp-block-heading\"><strong>Hackers Exploiting Ivanti Endpoint Manager Mobile<\/strong><\/h3>\n<p>Threat actors are abusing multiple vulnerabilities in Ivanti Endpoint Manager Mobile (EPMM), targeting enterprise networks with remote exploitation. These flaws allow attackers to gain initial footholds into corporate infrastructure, often chaining with other exploits for lateral movement. Nation-state groups and ransomware affiliates have already begun weaponizing these vulnerabilities in the wild. <a href=\"https:\/\/cybersecuritynews.com\/hackers-exploiting-ivanti-endpoint-manager-mobile-vulnerabilities\/\" target=\"_blank\" rel=\"noreferrer noopener\">Read More<\/a><\/p>\n<h3 class=\"wp-block-heading\"><strong>Weaponized ScreenConnect App<\/strong><\/h3>\n<p>In another software abuse trend, attackers are turning legitimate tools like ConnectWise\u2019s ScreenConnect app into weapons. By deploying trojanized installers, hackers establish remote access footholds disguised as IT management activity. This \u201cliving-off-the-land\u201d technique allows evasion of traditional defenses and grants persistent control of victim networks. <a href=\"https:\/\/cybersecuritynews.com\/beware-of-weaponized-screenconnect-app\/\" target=\"_blank\" rel=\"noreferrer noopener\">Read More<\/a><\/p>\n<h3 class=\"wp-block-heading\"><strong>Belsen Malware Campaign Linked<\/strong><\/h3>\n<p>Researchers uncovered connections between a new malware strain dubbed\u00a0<em>Belsen<\/em>\u00a0and previously active intrusion sets. Analysis indicates shared C2 infrastructure and loader techniques overlapping with known financially motivated threat groups. This discovery highlights the trend of rebranded payloads leveraging old foundations for renewed attacks. <a href=\"https:\/\/cybersecuritynews.com\/researchers-uncover-link-between-belsen\/\" target=\"_blank\" rel=\"noreferrer noopener\">Read More<\/a><\/p>\n<h3 class=\"wp-block-heading\"><strong>SystemBC Botnet Hits 1,500 VPS Servers<\/strong><\/h3>\n<p>The notorious SystemBC botnet continues to expand its footprint, recently compromising over 1,500 VPS servers. Known for serving as a proxy for ransomware affiliates, SystemBC enhances anonymity by tunneling malicious traffic. The surge shows ongoing demand for infrastructure capable of concealing command-and-control operations behind layers of obfuscation. <a href=\"https:\/\/cybersecuritynews.com\/systembc-botnet-hacking-1500-vps-servers\/\" target=\"_blank\" rel=\"noreferrer noopener\">Read More<\/a><\/p>\n<h3 class=\"wp-block-heading\"><strong>New Malware Loader \u201cCountLoader\u201d<\/strong><\/h3>\n<p>A fresh loader called\u00a0<em>CountLoader<\/em>\u00a0has surfaced in underground markets, featuring modular design and advanced evasion tactics. Its ability to deliver diverse payloads\u2014ranging from banking trojans to ransomware\u2014makes it a high-value tool for cybercriminal groups. Analysts note that its dynamic configuration updates make blocking efforts difficult.<br \/><a rel=\"noreferrer noopener\" target=\"_blank\" href=\"https:\/\/cybersecuritynews.com\/new-malware-loader-countloader\/\">Read More<\/a><\/p>\n<h3 class=\"wp-block-heading\"><strong>Phishing Attack Targets Facebook Users<\/strong><\/h3>\n<p>Social media users face renewed phishing threats as adversaries launch campaigns to steal Facebook login credentials. The attacks employ deceptive login pages and multi-step phishing kits designed to evade detection. Given the centrality of social media accounts for identity theft, the scale of these attacks poses a broad consumer security challenge. <a href=\"https:\/\/cybersecuritynews.com\/new-phishing-attack-targets-facebook-users\/\" target=\"_blank\" rel=\"noreferrer noopener\">Read More<\/a><\/p>\n<h3 class=\"wp-block-heading\"><strong>Russian Disinformation Network Expands<\/strong><\/h3>\n<p>Beyond malware, Russia-linked\u00a0<em>CopyCop<\/em>\u00a0has expanded its fake news infrastructure by adding 200 new websites. The campaign seeks to amplify disinformation globally, blurring the lines between targeted psychological operations and cyber-enabled propaganda. Coordinated amplification on these sites makes detection and takedown a persistent challenge for defenders. <a href=\"https:\/\/cybersecuritynews.com\/russian-fake-news-network-copycop-added-200-new-websites\/\" target=\"_blank\" rel=\"noreferrer noopener\">Read More<\/a><\/p>\n<h2 class=\"wp-block-heading\" id=\"h-data-breaches\"><strong>Data Breaches<\/strong><\/h2>\n<h3 class=\"wp-block-heading\"><strong>FinWise Insider Breach Exposes 689K Records<\/strong><\/h3>\n<p>American First Finance confirmed a major insider incident after a terminated employee exploited residual access to its production database. The breach compromised nearly 700,000 sensitive records, including Social Security numbers and financial data, which were exfiltrated using direct SQL queries and SSH tunnels. Investigators found the attacker took advantage of an archived service account with lingering privileges, bypassing standard RBAC and MFA safeguards. The company has since moved toward just-in-time access and user behavior analytics, alongside offering affected customers 24 months of identity protection. <a href=\"https:\/\/cybersecuritynews.com\/finwise-insider-breach\/\" target=\"_blank\" rel=\"noreferrer noopener\">Read More<\/a><\/p>\n<h3 class=\"wp-block-heading\"><strong>Tiffany &amp; Co. Confirms Data Breach<\/strong><\/h3>\n<p>Luxury jeweler Tiffany &amp; Co. disclosed a data breach that exposed sensitive employee and customer information following unauthorized access to internal systems. Although the company did not release specifics on the volume, the breach has raised concerns over the protection of VIP clientele data. The incident adds to a growing list of attacks aimed at brands handling high-net-worth individuals. <a href=\"https:\/\/cybersecuritynews.com\/tiffany-confirms-data-breach\" target=\"_blank\" rel=\"noreferrer noopener\">Read More<\/a><\/p>\n<h3 class=\"wp-block-heading\"><strong>Gucci, Balenciaga, and Alexander McQueen Leak Linked to BMW Breach<\/strong><\/h3>\n<p>A massive breach has reportedly tied together data leaks affecting iconic fashion houses Gucci, Balenciaga, and Alexander McQueen, allegedly connected to a wider compromise involving BMW\u2019s systems. The intrusion exposed internal documents, customer records, and operational data, raising alarms about cross-industry supply chain vulnerabilities. The fashion and automotive sectors, both attractive to cybercriminals, now appear increasingly linked through shared risk factors. <a href=\"https:\/\/cybersecuritynews.com\/gucci-balenciaga-alexander-mcqueen-data-leak\/https:\/\/cybersecuritynews.com\/bmw-allegedly-breached\/\" target=\"_blank\" rel=\"noreferrer noopener\">Read More<\/a><\/p>\n<h3 class=\"wp-block-heading\"><strong>UK Arrests Two Scattered Spider Hackers<\/strong><\/h3>\n<p>British law enforcement arrested two alleged members of the Scattered Spider group, which has been tied to high-profile intrusions, including MGM Resorts. The arrests mark a significant disruption to the group\u2019s operations, known for SIM swap attacks, phishing campaigns, and corporate intrusions. While arrests disrupt some activity, experts note that the group\u2019s wide affiliate network means residual risk is expected to continue. <a href=\"https:\/\/cybersecuritynews.com\/uk-arrested-2-scattered-spider-hackers\/\" target=\"_blank\" rel=\"noreferrer noopener\">Read More<\/a><\/p>\n<h3 class=\"wp-block-heading\"><strong>Great Firewall of China Data Leak<\/strong><\/h3>\n<p>An unprecedented leak exposed sensitive datasets tied to China\u2019s Great Firewall infrastructure, revealing operational insights into surveillance operations and censorship controls. The compromised data, reportedly accessible on cybercriminal forums, included internal schema, employee records, and technical configurations. This incident underscores the rising risks posed when state or nation-level security tools themselves become the targets of hackers. <a href=\"https:\/\/cybersecuritynews.com\/great-firewall-of-china-sensitive-data-leaked\/\" target=\"_blank\" rel=\"noreferrer noopener\">Read More<\/a><\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 89%,rgb(169,184,195) 100%)\"><code><strong>Follow Us on <a href=\"https:\/\/news.google.com\/publications\/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google News<\/a>,\u00a0<a href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">LinkedIn<\/a>, <a href=\"https:\/\/x.com\/cyber_press_org\" target=\"_blank\" rel=\"noreferrer noopener\">X<\/a>\u00a0to Get Daily Cyber Security Updates and <a href=\"https:\/\/cybersecuritynews.com\/contact-us\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Contact Us<\/a> to Feature Your Stories.<\/strong><\/code><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/cybersecurity-newsletter-weekly\/\">Cybersecurity Newsletter Weekly \u2013 Shai Halud Attack, Ivanti Exploits, FinWise, BMW Data Leak, and More<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Balaji N<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/cybersecurity-newsletter-weekly\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Cybersecurity Newsletter Weekly \u2013 Shai Halud Attack, Ivanti Exploits, FinWise, BMW Data Leak, and More This week in cybersecurity, researchers exposed hidden alliances between ransomware groups, the rise of AI-powered phishing platforms, and large-scale vulnerabilities affecting telecom and enterprise systems. Major data breaches at financial services and luxury brands highlighted insider threats and supply chain [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1857,63,1858],"tags":[130],"class_list":["post-7103","post","type-post","status-publish","format-standard","hentry","category-cyber-newsletter","category-cyber-security-news","category-cybersecurity-newsletter","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/7103"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=7103"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/7103\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=7103"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=7103"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=7103"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}