Cyber Briefing: 2025.10.01
Apple font fix, Tesla TCU patch, EvilAI malware, WestJet breach, RemoteCOM leak, Medusa recruit try, Trinity hacks, UK £5.5B BTC seizure, MS AI SIEM.
👉 What are the latest cybersecurity alerts, incidents, and news?
Welcome to Cyber Briefing, the newsletter that informs you about the latest cybersecurity advisories, alerts, incidents and news every weekday.
First time seeing this? Please Subscribe
🚨 Cyber Alerts
1. Apple Pushes iPhone and Mac Updates
Apple recently released updates for iOS and macOS to fix a critical font processing vulnerability. This flaw could allow a maliciously crafted font file to cause a denial-of-service condition, leading to app crashes or memory corruption. Users are advised to update their devices immediately to patch the security hole.
2. Tesla Fixes TCU Bug With USB Risk
Tesla’s recent patch of a TCU vulnerability, which allowed attackers to gain root access via USB, underscores the security challenges in connected vehicles. This flaw, patched with an over-the-air update, allowed an attacker with physical access to the car to exploit a bug in the telematics control unit (TCU), highlighting the risks of physical attack vectors in modern automotive systems.
3. EvilAI Malware Posing As AI Tools
Threat actors are using seemingly legitimate AI tools to sneak malware into organizations around the world. These malicious programs are designed to appear authentic, making them difficult for both users and security tools to detect.
For more alerts, click here!
💥 Cyber Incidents
4. WestJet Confirms Data Breach
WestJet, a major Canadian airline, confirmed a June cyberattack that exposed customer passports, government IDs, and other sensitive personal information. While the company says no credit card or debit information was compromised and operational safety wasn’t impacted, it is offering affected customers 24 months of free identity theft protection.
5. US Surveillance Hack Exposes Data
A major data breach at RemoteCOM exposed the personal files and police contacts of 14,000 people from its SCOUT software, revealing what the invasive spyware records and the high risks for everyone involved.
6. Ransomware Gang Recruits Reporter
Medusa ransomware actors attempted to entice a BBC journalist to become an insider threat by offering a substantial cut of a potential ransom. The hackers sought to exploit the reporter’s access and laptop to breach the broadcaster’s network, steal data, and demand a multi-million dollar ransom.
For more incidents, click here!
📢 Cyber News
7. Scattered Spider And ShinyHunters Shift
A new report from Resecurity reveals a widespread and expanding cybercrime campaign led by the alliance of LAPSUS$, ShinyHunters, and Scattered Spider. Despite rumors they’d retired, this group, dubbed the “Trinity of Chaos,” continues to execute coordinated hacks and extortion schemes against major companies, with numerous data breaches yet to be publicly revealed.
8. UK Convicts Chinese Crypto Fraudster
In the largest crypto seizure ever, a Chinese national was convicted in the UK for a massive fraud scheme, with police seizing £5.5 billion in Bitcoin. The UK has taken possession of the funds, which will be used for government purposes.
9. Microsoft Sentinel Unveils AI SIEM
Microsoft is introducing a new agentic security platform in Microsoft Sentinel to help organizations combat increasingly fast and complex cyberattacks. This platform uses AI agents to unify data, automate workflows, and enable security teams to detect and respond to threats at AI speed.
For more news click here
📈Cyber Stocks
On Wednesday, 1st October, cybersecurity stocks showed mixed performance. Optimism around AI-driven security innovation and ongoing demand for cloud and endpoint protection pushed some names higher, while competitive pressures, valuation concerns, and caution over growth guidance weighed on others. Overall, the sector remains resilient against geopolitical cyber risks but investors are becoming more selective.
CrowdStrike closed at $490.38, up 0.4%, supported by enthusiasm for its AI-augmented Falcon platform and recent acquisitions aimed at strengthening threat intelligence.
Zscaler ended at $299.66, up 0.95%, as accelerating enterprise cloud adoption and stronger zero-trust demand reinforced investor confidence.
Palo Alto Networks finished at $203.62, down 0.16%, with slight caution over its forward guidance despite longer-term optimism from the CyberArk acquisition.
Okta settled at $91.70, down 2.3%, pressured by stiff competition in identity management and valuation concerns overshadowing its AI-driven security initiatives.
Fortinet closed at $84.08, down 0.67%, as questions over firewall upgrade cycles and near-term growth visibility offset geopolitical tailwinds for network security.
💡 Cyber Tip
📱 Apple Pushes iPhone and Mac Updates
Apple has released urgent updates for iOS and macOS to fix a critical vulnerability in how devices process fonts. The flaw could let attackers use a malicious font file to crash apps, corrupt memory, or in some cases, run their own code. Since fonts are handled quietly in the background, this makes the risk especially serious.
✅ What you should do
Update all iPhones, iPads, and Macs to the latest versions now
Enable automatic updates so you receive fixes quickly in the future
Avoid opening files from unknown or suspicious sources
🔒 Why this matters
Even something as simple as a font can be turned into an attack. Apple’s fix closes a hole that could allow hackers to crash your device or take control of it. Keeping your devices updated is the best defense against this kind of hidden threat.
📚 Cyber Book
The Little Book of Cloud Computing Security by Lars Nielsen
That concludes today’s briefing . You can check the top headlines here!
Copyright © 2025 CyberMaterial. All Rights Reserved.
Follow CyberMaterial on:
Substack, LinkedIn, Twitter, Reddit, Instagram, Facebook, YouTube, and Medium.