Weekly Cybersecurity Recap - 3 November 2025

Major Threats, Exploits, Malware and Industry Updates

01 / Blog Article

Weekly Cybersecurity Recap - 3 November 2025
    Weekly Recap

    Introduction

    This week, the cybersecurity landscape highlighted an accelerating mix of automation, large-scale disruptions, and state-backed cyber activity. From new AI-powered defense tools to zero-day exploits and supply chain compromises, the digital battlefield continues to evolve. Here’s a breakdown of the key developments shaping global cybersecurity this week.

    AI, Automation & Digital Resilience

    OpenAI Unveils Aardvark: GPT-5 Agent That Finds and Fixes Code Flaws Automatically

    OpenAI announced the launch of “Aardvark,” an AI-powered autonomous security agent built on GPT-5 that can scan, understand, and patch code vulnerabilities automatically. The company says the agent is designed to act like a human security researcher capable of identifying and fixing flaws at scale - a move that could significantly accelerate secure software development. Currently in private beta, Aardvark reflects a growing shift toward embedding intelligent automation within DevSecOps workflows.

    Cloud Outages Highlight the Need for Resilient, Secure Infrastructure Recovery

    Two major cloud outages this week, impacting Amazon Web Services (AWS) and Microsoft Azure, reinforced the importance of resilient recovery planning. The AWS incident caused widespread service disruptions affecting platforms like Snapchat and Disney+, while Azure’s downtime crippled critical business operations. These incidents serve as a stark reminder that even leading cloud providers are not immune to failure - and underscore the need for security teams to prioritize recovery strategies that prevent cascading cyber risks.

    Threats, Exploits & Supply Chain Attacks

    PhantomRaven Malware Found in 126 npm Packages Stealing GitHub Tokens From Devs

    Researchers uncovered a large-scale npm supply chain attack involving more than 100 malicious packages under the codename “PhantomRaven.” The malware steals GitHub credentials, CI/CD secrets, and developer tokens directly from infected systems. Active since August 2025, the campaign has drawn over 86,000 installs, showing just how quickly malicious code can infiltrate open-source ecosystems and compromise entire development pipelines.

    Nation-State Hackers Deploy New Airstalk Malware in Suspected Supply Chain Attack

    A newly discovered malware dubbed “Airstalk” has been linked to a suspected nation-state operation, tracked as CL-STA-1009 by Unit 42. The campaign likely originated through a supply chain compromise, underscoring how state actors continue to exploit trusted channels to deliver espionage tools. The discovery adds to a growing list of sophisticated intrusions leveraging third-party software as the initial attack vector.

    China-Linked Tick Group Exploits Lanscope Zero-Day to Hijack Corporate Systems

    The China-backed Tick group has been observed exploiting a zero-day vulnerability in Motex Lanscope Endpoint Manager (CVE-2025-61932) to gain full system privileges. The flaw allows remote code execution and has been actively abused to drop backdoors on compromised systems. Security experts note this is part of a broader trend where advanced persistent threats (APTs) target IT management tools as stepping stones into corporate networks.

    Open VSX Downplays Impact From GlassWorm Campaign

    The team behind the Open VSX registry confirmed that the GlassWorm attacks targeting its VS Code extension marketplace have been fully contained. While the incident initially raised fears of a self-replicating worm, Open VSX clarified it was not traditional malware and that affected packages were swiftly removed. The event highlights the growing security pressures on open-source infrastructure providers serving developer communities.

    Corporate & Infrastructure Breaches

    LG Uplus is Latest South Korean Telco to Confirm Cybersecurity Incident

    South Korean telecom provider LG Uplus has reported a suspected data breach to the Korea Internet & Security Agency (KISA), making it the third major telco in the country to face such an incident in six months. The company did not disclose the scale or impact of the breach, but the pattern of repeated telecom intrusions points to a sustained campaign targeting critical communications infrastructure across South Korea.

    Industrial Giants Schneider Electric and Emerson Named as Victims of Oracle Hack

    Cybercriminals linked to the FIN11 threat group have claimed responsibility for data theft impacting Schneider Electric and Emerson. The breach, tied to vulnerabilities in Oracle E-Business Suite (EBS), resulted in stolen data being posted on the Cl0p ransomware leak site. The inclusion of two major industrial players in this campaign underscores the expanding reach of financially motivated groups into critical manufacturing and infrastructure sectors.

    Browser & Platform Security

    New "Brash" Exploit Crashes Chromium Browsers Instantly with a Single Malicious URL

    A newly disclosed exploit, dubbed “Brash,” targets an architectural flaw in Chromium’s Blink rendering engine, allowing attackers to crash browsers like Chrome and Edge within seconds. Researcher Jose Pino revealed that the flaw stems from how certain DOM operations are handled, and while it doesn’t lead to remote code execution, its simplicity makes it ripe for use in denial-of-service or browser-crash campaigns.

    Google's Built-In AI Defenses on Android Now Block 10 Billion Scam Messages a Month

    Google announced new figures demonstrating the scale of its AI-powered defenses on Android, which now block more than 10 billion suspected scam calls and messages every month. The system uses on-device machine learning to identify and intercept spam before it reaches users, while over 100 million suspicious numbers have been banned from RCS messaging. The company says this marks a major milestone in leveraging AI to proactively defend against social engineering and phishing threats.

    02/ Related Posts

    view all
    Weekly Recap Weekly Recap

    Weekly Cybersecurity Recap - 24 March 2025

    This Week in Cybersecurity: Phishing, Ransomware, and a $32B Acquisition

    Weekly Recap Weekly Recap

    Weekly Cybersecurity Recap - 7 April 2025

    AI Weaknesses, Airport Ransomware, Cloud Gaps & Phishing PhaaS

    Weekly Recap Weekly Recap

    Weekly Cybersecurity Recap - 14 April 2025

    Fake Apps, Data Leaks, Ransomware Tactics & WordPress Plugin Exploits

    Weekly Recap Weekly Recap

    Weekly Cybersecurity Recap - 21 April 2025

    Multi-stage malware, GPS spoofing, ClickFix campaigns, and Shadow AI adoption—this week’s cybersecurity recap has it all

    Weekly Recap Weekly Recap

    Weekly Cybersecurity Recap - 28 April 2025

    QR code scams, GenAI hallucinations, mobile spyware, and double extortion — it’s another action-packed week in cybersecurity.

    Weekly Recap Weekly Recap

    Weekly Cybersecurity Recap - 5 May 2025

    TikTok fined €530M, hackers breach CNI, and top 2025 cyber threats – your weekly cyber update

    Weekly Recap Weekly Recap

    Weekly Cybersecurity Recap - 12 May 2025

    FreeDrain Crypto Phishing, Qilin Ransomware Surge & Google’s AI Moves

    Weekly Recap Weekly Recap

    Weekly Cybersecurity Recap - 19 May 2025

    Botnets, Bounties, and the AI Balancing Act

    Weekly Recap Weekly Recap

    Weekly Cybersecurity Recap - 26 May 2025

    Fake Installers, Ransomware Fallout & Malicious Extensions: Last Week’s Cyber Recap

    Weekly Recap Weekly Recap

    Weekly Cybersecurity Recap - 2 June 2025

    Malware campaigns, breaches, and the $111B cloud security boom

    Weekly Recap Weekly Recap

    Weekly Cybersecurity Recap - 9 June 2025

    From a massive AT&T data leak to new macOS malware and a takedown of a notorious carding site - here's what happened last week.

    Weekly Recap Weekly Recap

    Weekly Cybersecurity Recap - 16 June 2025

    Discord Malware, Salesforce Risks, SME Pressures and more

    Weekly Recap Weekly Recap

    Weekly Cybersecurity Recap - 23 June 2025

    Cybercriminal Innovation, Record-Breaking DDoS, and Retail Breaches - What You Missed Last Week

    Weekly Recap Weekly Recap

    Weekly Cybersecurity Recap - 30 June 2025

    Emerging Quantum Threats, UAE Cyber Trends, and Critical Exploits – Last Week’s Cybersecurity Recap

    Weekly Recap Weekly Recap

    Weekly Cybersecurity Recap - 7 July 2025

    Weekly Cybersecurity Recap: AI-Enhanced Phishing, Android Fraud, and Emerging Risks

    Weekly Recap Weekly Recap

    Weekly Cybersecurity Recap - 14 July 2025

    Weekly Cybersecurity Recap: Human Weakness, AI Risks, and Critical Vulnerabilities

    Weekly Recap Weekly Recap

    Weekly Cybersecurity Recap - 11 August 2025

    Weekly Cybersecurity Recap: AI-Powered Scams, Vault Flaws, Airline Breaches & GPT-5 Jailbreaks

    Weekly Recap Weekly Recap

    Weekly Cybersecurity Recap - 25 August 2025

    Weekly Cybersecurity Recap: Wi-Fi Breaches, AI Risks, and Major Exploits

    Weekly Recap Weekly Recap

    Weekly Cybersecurity Recap - 1 September 2025

    AI Ransomware, WhatsApp Zero-Click Exploit, and Salesforce Credential Theft

    Weekly Recap Weekly Recap

    Weekly Cybersecurity Recap - 8 September 2025

    AI-powered Threats, Global Partnerships, Zero-Day Exploits & Record DDoS Attack

    Weekly Recap Weekly Recap

    Weekly Cybersecurity Recap - 15 September 2025

    npm Breach, Zero-Days, AI Jailbreaks and More

    Weekly Recap Weekly Recap

    Weekly Cybersecurity Recap - 22 September 2025

    AI-powered threats, airport cyberattacks, phishing surges & critical vulnerabilities

    Weekly Recap Weekly Recap

    Weekly Cybersecurity Recap - 6 October 2025

    Oracle Extortion, Red Hat Breach, and AI Browser Exploits

    Weekly Recap Weekly Recap

    Weekly Cybersecurity Recap - 13 October 2025

    New Malware Strains, Supply Chain Risks, and Massive Breaches

    Weekly Recap Weekly Recap

    Weekly Cybersecurity Recap - 20 October 2025

    Smart Contract Malware, Corporate Breaches, and Ransomware Disruptions

    Weekly Recap Weekly Recap

    Weekly Cybersecurity Recap - 27 October 2025

    GlassWorm Supply Chain Attack, WSUS Exploited, and a $2.5B JLR Fallout

    Protect your business with Paratus

    Ready to get started? Fill out the form below and we'll get back to you in no time!

    To: Paratus

    risk decrease

    96% Risks from dealing with clients and traders decrease by 96%