⚡ Weekly Recap: Instagram Account Hacks, Android Zero-Day, GitHub Worm and More
This week’s security news highlights a series of attacks and vulnerabilities, including a supply chain attack targeting Microsoft GitHub repositories via the Miasma Worm, a zero-day exploit in Android, and ongoing cybercrime operations targeting various sectors globally. The reports emphasize the continued effectiveness of traditional attack methods alongside the increasing sophistication of AI-powered attacks and the expansion of Chinese-linked cybercriminal groups. The vulnerability landscape remains active, with multiple organizations experiencing exploitation of known flaws.
Last week saw a significant supply chain attack, spearheaded by the Miasma Worm, impacting 73 Microsoft GitHub repositories across its Azure, Azure-Samples, Microsoft, and MicrosoftDocs organizations. This attack, a variant of Mini Shai-Hulud, demonstrates the ongoing risk posed by self-replicating malware within software development environments, leading GitHub to temporarily disable access to affected repositories. Simultaneously, Google released patches for a high-severity vulnerability (CVE-2025-48595) in the Android Framework, which was actively being exploited, impacting Android versions 14, 15, 16, and 16 QPR2. Furthermore, U.S. authorities disrupted cyber-enabled fraud schemes targeting Americans, seizing millions of compromised accounts and freezing over $3.8 million in cryptocurrency linked to transnational criminal groups operating out of Southeast Asia. Finally, a China-linked cybercrime group, TA4922, expanded its operations to Europe and Africa, utilizing a range of malware including Atlas RAT and RomulusLoader, while a previously unreported threat cluster, OP-512, targeted Microsoft IIS servers with a custom web shell framework, likely for espionage activities. The reports underscore the diverse and evolving nature of cyber threats.
