Check Point Research reported multiple notable incidents and disclosures, led by RansomHub claiming a ransomware attack on Luxshare (a major electronics manufacturer in the Apple/Nvidia/LG/Tesla supply chain) and alleging theft of sensitive IP such as 3D CAD models, circuit board designs, and engineering documentation; Luxshare had not confirmed the breach at the time of reporting. The bulletin also cited an alleged Under Armour customer database leak affecting 72 million records following a prior ransomware attack, a Raaga music-streaming breach involving 10.2 million users with passwords stored as unsalted MD5 hashes, and a confirmed disruptive cyberattack on Germany’s Dresden State Art Collections (SKD) that impacted ticketing and visitor services without reported data theft; it additionally highlighted an indirect prompt-injection issue in Gemini’s Google Calendar assistant that could bypass privacy controls via malicious invite content.
The Hacker News’ weekly recap focused on active exploitation risk tied to Fortinet firewalls, where Fortinet said it is working to fully address a FortiCloud SSO authentication bypass that has been exploited even on “fully patched” devices, indicating an incomplete fix and a new attack path. The activity was linked to incomplete patches for CVE-2025-59718 and CVE-2025-59719, enabling unauthenticated SSO login bypass via crafted SAML messages when FortiCloud SSO is enabled; mitigations recommended included restricting administrative access and disabling FortiCloud SSO logins (e.g., turning off admin-forticloud-sso-login) until a complete fix is available.

See which actors are running it and whether you're in range.
20 events from the most recent confirmed update back to the earliest known activity.
Researchers reported widespread abuse of browser extensions, including cases involving theft of OpenAI API keys. The activity emphasized the security risks posed by trusted browser add-ons.
The weekly recap noted vishing campaigns focused on identity providers that used bespoke panels to intercept credentials in real time. The activity showed increasing sophistication in social-engineering operations.
The report said advanced AI models were observed producing functional exploit code for a purported QuickJS zero-day. This highlighted concerns about LLMs lowering the barrier to exploit development.
Researchers described web pages with hidden prompts that use LLM APIs to generate polymorphic malicious JavaScript. The technique demonstrated a new way to automate evasive payload creation.
A reported attack showed that indirect prompt injection could manipulate Gemini’s Google Calendar assistant. The finding illustrated how AI assistants can be influenced through untrusted content.
Researchers reported a new Osiris ransomware family that uses a malicious 'Poortry' driver and Rclone for data exfiltration. The disclosure added technical details on the group’s tooling and tradecraft.
Threat intelligence reporting identified a large phishing wave abusing Microsoft Teams guest invitations. The campaign used trusted collaboration workflows to target users.
Researchers observed KONNI-linked phishing activity in the Asia-Pacific region using AI-generated PowerShell backdoors. The campaign reflected the operational use of AI to speed malware creation.
Threat intelligence reporting also described a North Korea-linked operation using VS Code tunnels in South Korea. The activity showed continued abuse of developer tooling for intrusion and persistence.
Researchers said the North Korea-linked Contagious Interview activity evolved to abuse VS Code workspace tasks so malware runs automatically when a folder is opened. The campaign used code-repository lures aimed at developers and delivered a new backdoor.
Security researchers reported on VoidLink, a Linux malware framework said to have been built largely with AI assistance. The disclosure underscored the growing use of generative AI in malware development.
Researchers detailed a malvertising-driven 'CrashFix' scheme that tricks users into installing a browser extension and executing a ClickFix-style workflow. The campaign ultimately delivers ModeloRAT.
Fortinet said attackers were exploiting FortiGate devices even when fully updated because fixes for two FortiCloud SSO authentication-bypass CVEs were incomplete. The company advised disabling FortiCloud SSO admin login and restricting administrative access until a complete fix is available.
Researchers highlighted a long-standing critical authentication-bypass flaw in GNU InetUtils telnetd. A public proof-of-concept was available, increasing the risk of exploitation.
A critical command-injection vulnerability affecting Zoom’s Node Multimedia Router was disclosed. The report states the issue had been patched.
Newly disclosed vulnerabilities in Anthropic’s mcp-server-git showed that prompt injection could lead to path traversal and argument injection. The issues were also reported as patched.
The RansomHub ransomware group allegedly claimed responsibility for an attack on Luxshare. The reference presents this as a claimed victim disclosure in threat reporting.
A large-scale leak of Raaga user data was reported, with passwords allegedly protected using weak MD5 hashing. The disclosure highlighted the scale of exposed user information and poor password security.
A customer database leak affecting Under Armour was reported and linked to a prior ransomware incident. The reference frames this as an alleged leak rather than a newly confirmed breach.
Germany’s Dresden State Art Collections (SKD) suffered a confirmed cyberattack that disrupted operations. The report says no data theft was reported.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.