Your Cybersecurity Update for Friday, 28 November 2025 (Ep.34)

RadioCSIRT English Edition
RadioCSIRT English Edition
Your Cybersecurity Update for Friday, 28 November 2025 (Ep.34)
Loading
/

Welcome to your daily cybersecurity briefing.

CISA & Commercial Spyware Targeting Messaging Apps
Following a joint alert by CISA, a technical breakdown reveals how multiple threat actors use QR-based session hijacking, zero-click exploits, and fake apps to compromise end-to-end encrypted messaging platforms such as Signal and WhatsApp. Victims include senior officials and civil society actors across the U.S., Europe, and the Middle East.

ORCA Initiative from Linux Foundation
The Linux Foundation has announced the creation of ORCA, a new Open Robust Compartmentalization Alliance aiming to promote memory safety and software isolation primitives. Key members include Microsoft, Google, Arm, and defense actors such as RTX and DARPA, focusing on securing toolchains for C, C++, and Rust.

Dell ControlVault2 & GL.iNet Flaws
Cisco Talos has disclosed vulnerabilities in Dell ControlVault2 and GL.iNet firmware affecting hardware security and OpenWRT-based VPN routers respectively. Exploits include heap overflows and race conditions. Patches are pending for multiple devices.

Poland Arrests Russian Hacker
Polish authorities have detained a Russian citizen linked to several intrusions against defense and public institutions. The individual is suspected of operating within a pro-Russian cybercriminal network supporting disinformation campaigns in Eastern Europe.

TOR Network Introduces Counter-Galois Encryption
The Tor Project is migrating from AES to a new encryption primitive called Counter-Galois (cgMul), developed specifically for onion-routing contexts. The move is intended to harden Tor nodes against speculative execution attacks and improve cryptographic agility.

Rey, Administrator of Scattered LAPSUS$ Hunters, Unmasked
KrebsOnSecurity has confirmed the identity of “Rey,” administrator of the Scattered LAPSUS$ Hunters Telegram channel and operator behind the ShinySp1d3r ransomware-as-a-service. Rey is a 15-year-old linked to past defacements and BreachForums activity. Despite claiming cooperation with law enforcement, he remains active within SLSH.

Don’t Think – Patch Now.

Sources:
CISA – Spyware & Messaging Apps
https://blog.marcfredericgomez.com/spyware-targeting-secure-mobile-messaging-applications/

 Linux Foundation – ORCA
https://www.linuxfoundation.org/press/linux-foundation-launches-the-open-robust-compartmentalization-alliance-orca-to-advance-software-security
 Cisco Talos – Dell / GL.iNet
https://blog.talosintelligence.com/dell-controlvault-lasso-gl-inet-vulnerabilities/
The Record – Arrest in Poland
https://therecord.media/poland-detains-russian-citizen-accused-of-hacks
 BleepingComputer – Tor Encryption Update
https://www.bleepingcomputer.com/news/security/tor-switches-to-new-counter-galois-onion-relay-encryption-algorithm/
 KrebsOnSecurity – SLSH / Rey
https://krebsonsecurity.com/2025/11/meet-rey-the-admin-of-scattered-lapsus-hunters/

Your feedback is welcome.
Email: radiocsirt@gmail.com
Website: https://www.radiocsirt.org
Weekly Newsletter: https://radiocsirtintl.substack.com