San Mateo, CA, September 29, 2025 — Stories, events, and developments that impacted the cybersecurity landscape last week, including emerging threats, policy changes, and industry responses.
Malicious AI server caught stealing thousands of emails
Security firm Koi has uncovered the first malicious Model-Context-Prompt (MCP) server in the wild. Embedded in a trojanized npm package named postmark-mcp, which was developed to allow AI assistants to automate email tasks, the package has been downloaded approximately 1,500 times weekly. While the package behaved normally for the first 15 versions, version 1.0.16 secretly added a Bcc field to exfiltrate every processed email to an attacker-controlled domain. The stolen data ranged from invoices and password resets to internal communications, possibly leaking thousands of emails daily from hundreds of organizations. Because MCP servers operate autonomously with broad access, the attack bypassed typical security controls. The malicious package has been deleted, but existing installations remain compromised. Read more.
Salesforce AI flaw lets attackers trick agents into spilling CRM data
Researchers at Noma Security uncovered a critical vulnerability in Salesforce’s Agentforce AI platform that could allow attackers to exfiltrate customer relationship management (CRM) data by manipulating web forms. Dubbed “ForcedLeak,” the exploit scores 9.4 on the CVSS scale and occurs when a threat actor inserts a malicious prompt into a Salesforce Web-to-Lead form, which, upon processing, triggers the agent to leak internal records. By exploiting an expired domain still whitelisted in Salesforce’s Content Security Policy, attackers could redirect sensitive sales data, customer details, and transaction records. Salesforce patched the domain issue and tightened URL restrictions, but acknowledged that broader prompt injection defenses remain unsolved. Read more.
Senate report slams DOGE for creating major cybersecurity risks
A Senate Homeland Security and Governmental Affairs Committee report released Thursday accuses Elon Musk’s Department of Government Efficiency (DOGE) of “operating outside federal law” and creating severe privacy and cybersecurity risks at the General Services Administration (GSA), the Office of Personnel Management (OPM), and the Social Security Administration (SSA). The report cites a whistleblower claim that an internal risk assessment indicated a 35–65% chance of a “catastrophic” SSA data breach after DOGE uploaded the sensitive Numident database without implementing safeguards. It alleges DOGE used Starlink to bypass IT oversight and attempted to pool agency data into a “master database.” “It is highly likely that foreign adversaries, such as Russia, China, and Iran, who regularly attempt cyber attacks on the U.S. government and critical infrastructure, are already aware of this new DOGE cloud environment,” reads the report. Read more.
LockBit 5.0 ransomware takes cross-platform attacks to new heights
Trend Micro has identified a new variant of LockBit ransomware, dubbed LockBit 5.0, which researchers warn is “significantly more dangerous” than its predecessors. “The existence of Windows, Linux, and ESXi variants confirms LockBit’s continued cross-platform strategy. This enables simultaneous attacks across entire enterprise networks, from workstations to critical servers hosting databases and virtualization platforms,” Trend Micro said. Their analysis revealed faster encryption, randomized file extensions, the removal of infection markers, and anti-forensic measures, including disabling Windows Event Tracing. The ESXi variant represents a significant escalation, enabling the encryption of entire virtualized infrastructures in a single strike. Researchers conclude that LockBit 5.0 is an evolutionary step built on the 4.0 codebase, underscoring the group’s resilience and continuous refinement. Read more.
Chinese hackers hijack IIS servers to poison search results
A new SEO poisoning campaign, dubbed “Operation Rewrite,” is targeting users in East and Southeast Asia through a malicious IIS module called BadIIS, according to a report from Palo Alto Networks’ Unit 42. Attributed to a financially motivated Chinese-speaking threat actor, the campaign hijacks legitimate servers and uses them as reverse proxies to serve keyword-stuffed, poisoned content to search engine crawlers. According to Unit 42 senior threat hunter Yoav Zemah, this allows the threat actor to exploit a site’s good standing as opposed to creating “a new website’s reputation from scratch, which is a slow and challenging process.” The compromised sites then redirect unsuspecting users to adult content and gambling platforms. Active since March 2025, the operation involves custom implants, lateral movement, web shells, DLL-based IIS modules, and data exfiltration. Read more.
Fake password manager on macOS pushes Atomic info-stealer
LastPass is warning macOS users of a large-scale malware campaign distributing the Atomic (AMOS) info-stealer through fake GitHub repositories that pose as popular software, including Dropbox, 1Password, Robinhood, and Adobe After Effects. Attackers lure victims with SEO-boosted Google and Bing results, leading them to fraudulent repositories featuring download buttons that redirect to secondary sites with “ClickFix” instructions. Users are then tricked into pasting Terminal commands that install the malware. Security experts advise users to download software only from official vendor sites. Read more.
Secret Service takes down NYC network tied to telecom threats
The U.S. Secret Service said Tuesday it dismantled a network of more than 300 servers and 100,000 SIM cards in the New York City area that posed imminent threats to government officials and potentially the U.N. General Assembly. Officials stated that the devices enabled encrypted communications between foreign actors and criminals, and could have disabled cell towers, potentially affecting regional networks. Secret Service Director Sean Curran warned that “the potential for disruption to our country’s telecommunications posed by this network of devices cannot be overstated.” Briefed news outlets said that the network was being used to communicate assassination threats against senior U.S. officials and that “the investigation uncovered empty electronic safehouses rented around the area and that hackers, terrorists, spies and human traffickers could’ve made use of the network.” Read more.
GitHub tightens npm supply chain security after malware surge
GitHub announced it will overhaul authentication and publishing in “the near future” in response to recent npm ecosystem supply chain attacks, such as the sophisticated Shai-Hulud self-replicating worm. Planned changes include local publishing with mandatory two-factor authentication, seven-day granular tokens, and trusted publishing via OpenID Connect, which replaces npm tokens with short-lived credentials. GitHub will also deprecate legacy tokens, phase out TOTP 2FA in favor of FIDO-based methods, and remove options to bypass two-factor authentication (2FA). “Every package published via trusted publishing includes cryptographic proof of its source and build environment,” GitHub noted in late July of 2025. “Your users can verify where and how your package was built, increasing trust in your supply chain.” Read more.
Teen hacker charged in $115 million Scattered Spider spree
The U.S. Department of Justice has unsealed federal charges against 19-year-old British citizen Thalha Jubair, accused of conducting at least 120 cyberattacks and extorting U.S. companies for more than $115 million. Arrested in East London, Jubair appeared in court alongside 18-year-old Owen Flowers, both linked to the Scattered Spider group and a 2024 breach of Transport for London’s IT systems. Prosecutors allege that Jubair hacked into company networks using social engineering and encrypted servers, with one critical infrastructure company in New Jersey among his victims. He is also accused of breaching the U.S. court system to gain access to sensitive accounts, including one belonging to a federal judge. The FBI seized a server allegedly operated by Jubair containing evidence of the hacks and a cryptocurrency wallet holding $36 million. Scattered Spider’s English-speaking, financially motivated hackers are mostly teenagers, sometimes referred to as “Advanced Persistent Teenagers.” Read more.
FBI warns of spoofed IC3 sites targeting cybercrime victims
The FBI is warning cybercrime victims to be cautious of spoofed websites that imitate its Internet Crime Complaint Center (IC3) portal. In a public service announcement, the bureau explained that attackers are creating fake IC3 sites by slightly altering domain names to steal personal and financial information, such as names, addresses, phone numbers, emails, and banking data. Beyond phishing, scammers may impersonate FBI or IC3 staff, even offering to recover stolen funds in exchange for a fee. The FBI confirmed that it has already received over 100 such reports between late 2023 and early 2025. To avoid falling victim, the bureau advises typing ic3.gov directly into a browser, avoiding sponsored search results, and steering clear of fake links or IC3-branded social media pages. Victims should report impersonation attempts with as much detail as possible. Read more.
More cybersecurity news
- Last week’s news
- More cybersecurity news
- All articles sponsored by NetworkTigers
About NetworkTigers

NetworkTigers is the leader in the secondary market for Grade A, seller-refurbished networking equipment. Founded in January 1996 as Andover Consulting Group, the company originally built and re-architected data centers for Fortune 500 firms. Today, NetworkTigers provides consulting and network equipment to global government agencies, Fortune 2000 companies, and healthcare companies. Visit www.networktigers.com
