Top news stories this week
- Very patchy. Record number of patches released by Microsoft and Adobe
- Joined-up justice. FBI unveils collaborative cyber disruption strategy
- Test environment. AI agents collaborate and hijack German website to train AI models
- License to steal. ShinyHunters targets Florida driver database
- Hijacked trust. Brazilian government websites turned into criminal infrastructure
- Frequent flyer. Security misconfiguration exposes 220 million traveller records
1. Record number of patches released by Microsoft and Adobe
Microsoft released almost 1,000 software security fixes in its largest ever 'patch Tuesday' this month. Adobe also patched over 170 vulnerabilities including urgent fixes for a critical-severity flaw in Adobe Commerce and Magento Open Source.
So what?
Increasing numbers of vulnerabilities being reported could be driven by AI and likely to continue. Organisations should focus remediation efforts on vulnerabilities that are exploitable, exposed, and relevant to their environment rather than attempting to address volume alone.
[Researcher: Denisa Greconici]
2. FBI moves towards more collaborative cyber disruptions
The FBI has unveiled a new cyber strategy aimed at strengthening and accelerating collaboration with government agencies and the private sector. Built around four pillars, the strategy prioritises threat attribution, victim support, partnership-building and more frequent disruption operations, moving beyond ad hoc takedowns towards a more sustained approach to cyber defence.
So what?
Closer public-private coordination could increase the speed and frequency of operations against cyber adversaries. However, its effectiveness will depend on organisations being willing and prepared to share actionable information promptly.
[Researcher: Tlhalefo Dikolomela]
3. AI agents use German website as testing ground
OpenAI agents turned a German website into a communication hub to connect with other agents and made over 15,000 edits. Researchers discovered the activity while observing the speed and the scale of solving specifically technical problems on the site, which is a common technique by AI companies to train their models.
So what?
The incident shows that AI agents develop the ability to collaborate, share workarounds and act collectively in ways humans did not anticipate which could lead to loss of visibility over processes.
[Researcher: Lena Krummeich]
4. ShinyHunters targets Florida driver database
Ransomware gang ShinyHunters claims to have breached Florida’s driver and vehicle information database (DAVID) system and exfiltrated over 200,000 records containing personally identifiable information (PII). The group alleges it exploited a password reset vulnerability to compromise multiple accounts. Florida officials have not yet confirmed the breach.
SO WHAT?
The alleged breach highlights the continued appeal of government databases as targets for cybercriminals, particularly those containing large volumes of identity-related data. Stolen PII can be used to facilitate fraud, identity theft and social engineering attacks, increasing the potential downstream impact on affected individuals even where financial information is not involved.
[Researcher: Steve Ross]
5. Brazilian government websites turned into criminal infrastructure
As part of a long-running campaign, the threat actor group Gambling Goblin hijacked Brazilian government and educational web servers to support phishing operations. The group exploited the reputation of legitimate domains to boost the credibility and reach of malicious sites, while also deploying backdoors and credential-stealing tools.
So What?
The abuse of trusted domains makes phishing campaigns harder to detect and more likely to succeed. Organisations should monitor internet-facing systems closely and remain cautious of seemingly legitimate websites requesting credentials.
[Researcher: Jenny Eysert]
6. Security misconfiguration exposes 220 million traveller records in Vietnam-linked APIS leak
More than 220 million passenger and crew travel records linked to a Vietnam-based Advance Passenger Information System (APIS) were exposed online due to security misconfigurations. The data included passport details, personal information and flight itineraries spanning 2017 to 2026, affecting travellers across multiple international airlines.
SO WHAT?
Organisations should regularly review cloud services, APIs, and databases for misconfigurations, enforce strong authentication, and remove default credentials. The incident also highlights the importance of third-party risk management, as a weakness at a single provider can expose sensitive data across multiple organisations and jurisdictions.
[Researcher: Houren Lee]
