Welcome to your daily cybersecurity briefing.
💸 FBI: Bank Impersonation Alert – The FBI reports that cybercriminals have stolen $262 million since January by impersonating bank support teams through sophisticated vishing and smishing campaigns.
📉 Microsoft: Exchange Online Outage – A major service disruption in North America is blocking access to Outlook mailboxes, caused by a configuration change that Microsoft is currently rolling back.
🐛 Supply Chain: Shai-Hulud Worm – A self-replicating worm has infected over 800 npm packages, modifying package.json scripts to exfiltrate AWS and GitHub secrets to external servers.
🦊 Mozilla: Critical Patch Released – Mozilla addresses CVE-2025-13016 in Firefox and Thunderbird, a critical vulnerability allowing remote code execution via malicious animation timelines.
🎓 Harvard: Vishing Data Breach – The university confirms a data breach exposing donor contact details after attackers impersonated IT support to gain remote control of an employee’s workstation.
⚡ Don’t Think – Patch Now and ask later.
📚 Sources:
🔗 Bleeping Computer https://www.bleepingcomputer.com/news/security/fbi-cybercriminals-stole-262-million-by-impersonating-bank-support-teams-since-january/
🔗 Bleeping Computer (Microsoft) https://www.bleepingcomputer.com/news/microsoft/microsoft-exchange-online-outage-blocks-access-to-outlook-mailboxes/
🔗 Blog Marc-Frédéric Gomez https://blog.marcfredericgomez.fr/shai-hulud-un-ver-npm-infecte-plus-de-800-packages-et-exfiltre-des-secrets-sur-github/
🔗 HackRead https://hackread.com/update-firefox-patch-cve-2025-13016-vulnerability/
🔗 Security Affairs https://securityaffairs.com/185034/security/harvard-reports-vishing-breach-exposing-alumni-and-donor-contact-data.html
📞 Your feedback is welcome!
📧 Email: radiocsirt@gmail.com
🌐 Website: https://www.radiocsirt.org
📰 Weekly Newsletter: https://radiocsirtintl.substack.com