Massive Surge of NFC Relay Malware Steals Europeans’ Credit Cards

NFC relay malware significantly increased in Eastern Europe, with over 760 malicious Android apps identified stealing credit card data. This malware utilizes Android’s Host Card Emulation to capture payment information and perform unauthorized transactions without the card present. It first appeared in Poland and has spread to several countries. Security experts advise Android users to avoid installing risky apps, check permissions, and utilize built-in anti-malware tools.

https://www.bleepingcomputer.com/news/security/massive-surge-of-nfc-relay-malware-steals-europeans-credit-cards/

When AI Agents Go Rogue: Agent Session Smuggling Attack in A2A Systems

Extreme TLDR: A new attack method, “agent session smuggling,” exploits AI agents' communication protocols (A2A) to inject harmful instructions during ongoing sessions, allowing malicious agents to manipulate and deceive victim agents. This dynamic threat leverages trust relationships and stateful interactions, making detection difficult. Mitigation strategies include human oversight, remote party verification, and context awareness. The research emphasizes the need for advanced security tools and proactive assessments to safeguard AI environments against evolving threats.

https://unit42.paloaltonetworks.com/agent-session-smuggling-in-agent2agent-systems/

Has Anyone Actually Found Real Value in AI for Cybersecurity?

Most cybersecurity professionals find significant value in AI when it comes to streamlining repetitive tasks, such as report writing, log parsing, code review, incident triage, and policy drafting. AI is widely used as a productivity booster and workflow accelerator, not as a revolutionary technology for actual threat detection. There is skepticism about AI’s ability to detect novel attacks, with most reliable detections still relying on traditional rule-based systems. Custom AI applications for detection work in large, well-resourced organizations, but widespread breakthrough results are lacking. Overhyped vendor claims, verification challenges, and trust issues are common concerns. Overall, AI’s practical benefits in cybersecurity today primarily involve reducing manual workloads and enhancing efficiency in support tasks, rather than transforming threat detection.

https://www.reddit.com/r/cybersecurity/comments/1om1kbp/has_anyone_actually_found_real_value_in_ai_for/

New Physical Attacks Are Quickly Diluting Secure Enclave Defenses From Nvidia, AMD, and Intel

Novel physical attacks, including TEE.fail, undermine secure enclave protections from Nvidia, AMD, and Intel, allowing attackers to compromise Trusted Execution Environments (TEEs) despite system-level safeguards. These attacks, cheap and quick, exploit deterministic encryption, posing risks to encryption integrity and data confidentiality across industries reliant on TEEs. Chipmakers fail to adequately address physical attack threats, leading to misinformation and user vulnerability. Users need to recognize inherent limitations when utilizing TEE technologies, as current default protections are insufficient against physical breaches.

https://arstechnica.com/security/2025/10/new-physical-attacks-are-quickly-diluting-secure-enclave-defenses-from-nvidia-amd-and-intel/

Keeping the Internet Fast and Secure- Introducing Merkle Tree Certificates

Cloudflare introduces Merkle Tree Certificates (MTCs) to transition to Post-Quantum (PQ) cryptography, addressing the threat of quantum computers to Internet security. Current TLS handshakes use excessive signatures and public keys, causing performance issues. MTCs aim to minimize this by allowing clients to validate certificates with reduced overhead (1 signature, 1 public key, 1 inclusion proof). An experiment to implement MTCs, in collaboration with Chrome, will test the concept while ensuring users' security through bootstrap certificates. The results are expected to improve both security and performance, keeping the Internet fast and secure amid evolving cryptographic needs.

https://blog.cloudflare.com/bootstrap-mtc/

Experts Reports Sharp Increase in Automated Botnet Attacks Targeting PHP Servers and IoT Devices

Spike in automated botnet attacks targeting PHP servers and IoT devices, exploiting known vulnerabilities and cloud misconfigurations. Major threats come from botnets like Mirai and Gafgyt, with PHP servers as key targets due to common CMS usage. Recommendations include updating software, removing debug tools, and securing credentials. Threat actors now leverage compromised devices for various illicit activities, including credential stuffing and DDoS attacks. Bots can easily evade security controls, suggesting a need for heightened defenses.

https://thehackernews.com/2025/10/experts-reports-sharp-increase-in.html

Ransomware Hackers Look for New Tactics Amid Falling Profits

Ransomware profits are down, forcing cybercriminals to adopt new tactics to demand payment, including bribing insiders and using social engineering techniques such as callback phishing. Fewer organizations are paying ransoms, and the average payment has dropped significantly. This has fragmented the ransomware ecosystem, with smaller groups targeting industries and regions that weren’t previously affected. Attackers now focus on recruiting insiders, directly contacting executives with ransom demands, and exploiting supply chains. Enterprises should become more vigilant against internal threats as hackers adapt their techniques to make up for lost earnings.

https://www.databreachtoday.com/ransomware-hackers-look-for-new-tactics-amid-falling-profits-a-29867

Agentic AI and Security

Agentic AI systems raise significant security concerns due to their inability to distinguish between instructions and data. This vulnerability leads to the “Lethal Trifecta” risk, where access to sensitive data, exposure to untrusted content, and external communication can result in data leaks. To mitigate these risks, developers should minimize access to sensitive information, restrict untrusted content consumption, and utilize sandboxing or containerization to isolate tasks. Key strategies include splitting tasks, maintaining human oversight, and applying the Principle of Least Privilege. These precautions aim to improve security without discarding the powerful capabilities of LLM-driven applications.

https://martinfowler.com/articles/agentic-ai-security.html

Google Disputes False Claims of Massive Gmail Data Breach

Google denies recent claims of a massive Gmail data breach affecting 183 million accounts, clarifying that compromised credentials result from various past attacks, not a new breach. The misinformation originated from misinterpretations of credential databases compiled over years. Google emphasizes strong defenses and offers advice for users concerned about past credential exposure.

https://www.bleepingcomputer.com/news/security/google-disputes-false-claims-of-massive-gmail-data-breach/

US Declines to Join More Than 70 Countries in Signing UN Cybercrime Treaty

U.S. did not sign U.N. cybercrime treaty despite over 70 countries agreeing to it, aiming to counter global digital crime. The U.N. states the convention strengthens defenses against cybercrime, facilitates cross-border evidence sharing, and addresses serious offenses. Critics warn it may empower authoritarian regimes and infringe on rights. Some emphasize the need for protecting fundamental rights while pursuing cybercrime.

https://therecord.media/us-declines-signing-cybercrime-treaty

Ransomware Profits Drop as Victims Stop Paying Hackers

Ransomware payments have dropped to 23% among breached companies, marking a continuous decline. Enhanced security and pressure from authorities are cited as reasons for this trend. As ransomware groups shift focus from encryption to data theft, newer attacks show only a 19% payment rate when data is stolen without encryption. Average ransom payments decreased to $377,000. Targeting mid-sized firms increases as larger companies fortify defenses. Cyber attackers may pivot to social engineering to gain access as profits dwindle.

https://www.bleepingcomputer.com/news/security/ransomware-profits-drop-as-victims-stop-paying-hackers/

Compromised YouTube Accounts Distribute Infostealer Malware

A large-scale malware campaign called the “YouTube Ghost Network” exploited over 3,000 malicious YouTube videos, hosted on fake or compromised accounts, to distribute infostealers targeting users seeking pirated software or game hacks. The top targets were Adobe and FL Studio products, with videos guiding users to download files from third-party sites and often to disable Windows Defender. The operation relied on a structure that quickly replaced banned accounts and faked user trust with positive comments. Main infostealers included Lumma, Rhadamanthys, StealC, and Redline. The report highlights the risks of using cracked software and notes the increasing sophistication of such attacks on popular platforms.

https://thecyberexpress.com/compromised-youtube-accounts-infostealer-malware/

US to Attend UN Cybercrime Treaty Signing in Hanoi Despite Industry Concerns

US to attend UN cybercrime treaty signing in Hanoi despite industry and human rights concerns. The treaty, adopted after five years amid backlash, aims to improve international cooperation on cybercrime but raises fears over electronic surveillance and human rights violations. Approximately 30-36 countries may sign, while critics warn it could facilitate digital repression. The US, previously opposed, now supports the treaty for potential reforms, although concerns about its implications persist.

https://therecord.media/cybercrime-treaty-signing-hanoi

LockBit Returns — and It Already Has Victims

LockBit ransomware has resurfaced, targeting organizations globally with a new variant, LockBit 5.0. This group, previously disrupted in early 2024, has resumed operations, exploiting vulnerabilities across Windows, Linux, and ESXi systems. With enhanced evasion techniques, faster encryption, and multi-platform support, it poses a renewed threat to businesses.

https://blog.checkpoint.com/research/lockbit-returns-and-it-already-has-victims/

Scroll to Top