Opalsec’s Post

Hello cyber practitioners! The team at Opalsec is here with your daily cyber news rundown for **Saturday, October 4, 2025**. The past 24 hours have seen a significant focus on widespread data breaches, sophisticated extortion attempts, evolving malware threats, and critical discussions around privacy and national security. Here's a snapshot of the key incidents and developments: * ⚠️ Scattered Lapsus$ Hunters extort 39 companies after Salesforce breaches, with a larger leak from Salesloft Drift expected. * 🛡️ Red Hat confirmed 'Crimson Collective' accessed and copied data from its consulting GitLab, impacting 28,000 repositories. * 🚨 Japanese giant Asahi Group Holdings confirmed a ransomware attack causing IT disruptions and potential data theft. * 🚗 Renault and Dacia UK customers were notified of a third-party data breach, exposing personal details but no financial info. * 💸 Oracle E-Business Suite customers receive Clop-linked extortion emails, exploiting vulnerabilities or configuration abuse. * 🏛️ U.S. Federal Judiciary faces criticism for slow MFA implementation on PACER after a major breach and transparency issues. * 🐺 'Cavalry Werewolf' targets Russian state agencies and critical infrastructure via phishing, deploying custom FoalShell and StallionRAT malware. * 📈 Rhadamanthys info stealer evolved to v0.9.2, adding device fingerprinting, steganography, and advanced evasion techniques. * 📧 'CometJacking' exploits Perplexity's Comet AI browser via prompt injection to exfiltrate sensitive data without credentials. * 🇮🇱 Citizen Lab uncovered 'PRISONBREAK,' an Israeli-backed AI disinformation campaign using deepfakes to foment revolt in Iran. * 🔒 Flock Safety's new 'Raven' gunshot detection product raises privacy concerns amidst ongoing controversies over ALPR data misuse. * 🇬🇧 UK government clarified non-compulsory digital ID plans to streamline services, despite public petitions and privacy warnings. * ✉️ Gmail enterprise users now have end-to-end encryption for sending emails to anyone, enhancing data security and compliance. * 📶 Signal introduced Sparse Post-Quantum Ratchet (SPQR) for hybrid post-quantum cryptographic defence against future quantum threats. For more in-depth analysis and discussion, listen to the latest episode of the stdout Podcast: https://lnkd.in/g-78X79D Read the detailed summary on Mastodon: https://lnkd.in/gfGUe-4e #CyberSecurity #ThreatIntelligence #Ransomware #DataBreach #Malware #SupplyChainAttack #Privacy #Disinformation #AI #InfoSec

To view or add a comment, sign in

Explore content categories