Security Affairs newsletter Round 515 by Pierluigi Paganini – INTERNATIONAL EDITION

A new round of the weekly SecurityAffairs newsletter arrived! Every week the best security articles from Security Affairs are free in your email box.—————————————————————————————————————————————————–Enjoy a new round of the weekly SecurityAffairs newsletter, including the international press.[New MassJacker clipper targets pirated software seekers](https://securityaffairs.com/175433/malware/new-massjacker-clipper-targets-pirated-software-seekers.html) [Cisco IOS XR flaw allows attackers to crash BGP process on routers](https://securityaffairs.com/175421/security/cisco-ios-xr-flaw-cve-2025-20115.html) [LockBit ransomware developer Rostislav Panev was extradited from Israel to the U.S.](https://securityaffairs.com/175413/cyber-crime/lockbit-ransomware-developer-rostislav-panev-extradited-to-us.html) [SuperBlack Ransomware operators exploit Fortinet Firewall flaws in recent attacks](https://securityaffairs.com/175402/cyber-crime/superblack-ransomware-exploited-fortinet-firewall-flaws.html) [U.S. CISA adds Apple products and Juniper Junos OS flaws to its Known Exploited Vulnerabilities catalog](https://securityaffairs.com/175381/security/u-s-cisa-adds-apple-juniper-junos-os-flaws-known-exploited-vulnerabilities-catalog.html) [GitLab addressed critical auth bypass flaws in CE and EE](https://securityaffairs.com/175370/security/gitlab-addressed-critical-flaws-in-ce-and-ee.html) [North Korea-linked APT group ScarCruft spotted using new Android spyware KoSpy](https://securityaffairs.com/175357/malware/scarcruft-used-a-new-android-spyware-dubbed-kospy.html) [Experts warn of a coordinated surge in the exploitation attempts of SSRF vulnerabilities](https://securityaffairs.com/175344/hacking/coordinated-surge-exploitation-attempts-ssrf-vulnerabilities.html) [Meta warns of actively exploited flaw in FreeType library](https://securityaffairs.com/175337/hacking/meta-warned-actively-exploited-cve-2025-27363.html) [Medusa ransomware hit over 300 critical infrastructure organizations until February 2025](https://securityaffairs.com/175319/cyber-crime/medusa-ransomware-hit-over-300-critical-infrastructure-organizations-until-february-2025.html) [China-linked APT UNC3886 targets EoL Juniper routers](https://securityaffairs.com/175308/apt/china-linked-apt-unc3886-targets-eol-juniper-routers.html) [U.S. CISA adds six Microsoft Windows flaws to its Known Exploited Vulnerabilities catalog](https://securityaffairs.com/175298/hacking/u-s-cisa-adds-six-microsoft-windows-flaws-to-its-known-exploited-vulnerabilities-catalog.html) [Microsoft Patch Tuesday security updates for March 2025 fix six actively exploited zero-days](https://securityaffairs.com/175289/hacking/microsoft-patch-tuesday-security-updates-for-march-2025.html) [New Ballista Botnet spreads using TP-Link flaw. Is it an Italian job?](https://securityaffairs.com/175278/malware/ballista-botnet-exploits-unpatched-tp-link-flaw.html) [Apple fixed the third actively exploited zero-day of 2025](https://securityaffairs.com/175269/hacking/apple-third-zero-day-2025.html) [Switzerland’s NCSC requires cyberattack reporting for critical infrastructure within 24 hours](https://securityaffairs.com/175260/laws-and-regulations/switzerlands-ncsc-requires-cyberattack-reporting-for-critical-infrastructure-within-24-hours.html) [SideWinder APT targets maritime and nuclear sectors with enhanced toolset](https://securityaffairs.com/175247/apt/sidewinder-apt-targets-maritime-nuclear-sectors.html) [U.S. CISA adds Advantive VeraCore and Ivanti EPM flaws to its Known Exploited Vulnerabilities catalog](https://securityaffairs.com/175232/breaking-news/u-s-cisa-adds-advantive-veracore-and-ivanti-epm-flaws-to-its-known-exploited-vulnerabilities-catalog.html) [Cybersecurity Challenges in Cross-Border Data Transfers and Regulatory Compliance Strategies](https://securityaffairs.com/175223/security/cybersecurity-challenges-in-cross-border-data-transfers-and-regulatory-compliance-strategies.html) [Elon Musk blames a massive cyberattack for the X outages](https://securityaffairs.com/175209/hacking/elon-musk-x-ddos-attack-dark-dark-storm-team.html) [Experts warn of mass exploitation of critical PHP flaw CVE-2024-4577](https://securityaffairs.com/175198/hacking/experts-warn-of-mass-exploitation-of-critical-php-flaw-cve-2024-4577.html) [RansomHouse gang claims the hack of the Loretto Hospital in Chicago](https://securityaffairs.com/175187/cyber-crime/ransomhouse-gang-claims-the-hack-of-the-loretto-hospital-in-chicago.html) [North Korea-linked APT Moonstone used Qilin ransomware in limited attacks](https://securityaffairs.com/175178/apt/north-korea-linked-apt-moonstone-used-qilin-ransomware.html) [Large-scale cryptocurrency miner campaign targets Russian users with SilentCryptoMiner](https://securityaffairs.com/175169/breaking-news/miner-campaign-targeting-russian-users-with-silentcryptominer.html) [Feds seized $23 million in crypto stolen using keys from LastPass breaches](https://securityaffairs.com/175156/cyber-crime/feds-seized-23-million-in-crypto-stolen-using-keys-from-lastpass-breaches.html) [Undocumented hidden feature found in Espressif ESP32 microchip](https://securityaffairs.com/175102/hacking/undocumented-hidden-feature-espressif-esp32-microchip.html)**International Press — Newsletter****Cybercrime**[Texas Man Convicted of Sabotaging his Employer’s Computer Systems and Deleting Data](https://www.justice.gov/opa/pr/texas-man-convicted-sabotaging-his-employers-computer-systems-and-deleting-data)[CYBERCRIME CREW CHARGED WITH STEALING AND RESELLING CONCERT TICKETS, INCLUDING FOR TAYLOR SWIFT’S ERAS TOUR](https://queensda.org/cybercrime-crew-charged-with-stealing-and-reselling-concert-tickets-including-for-taylor-swifts-eras-tour/)[Feds Link $150M Cyberheist to 2022 LastPass Hacks](https://krebsonsecurity.com/2025/03/feds-link-150m-cyberheist-to-2022-lastpass-hacks/)[Garantex administrator arrested in India at request of US authorities](https://techcrunch.com/2025/03/12/garantex-administrator-arrested-in-india-under-extradition-law/)[Phishing campaign impersonates Booking .com, delivers a suite of credential-stealing malware](https://www.microsoft.com/en-us/security/blog/2025/03/13/phishing-campaign-impersonates-booking-com-delivers-a-suite-of-credential-stealing-malware/)[SuperBlack Ransomware operators exploit Fortinet Firewall flaws in recent attacks](https://securityaffairs.com/175402/cyber-crime/superblack-ransomware-exploited-fortinet-firewall-flaws.html)[Dual Russian And Israeli National Extradited To The United States For His Role In The LockBit Ransomware Conspiracy](https://www.justice.gov/usao-nj/pr/dual-russian-and-israeli-national-extradited-united-states-his-role-lockbit-ransomware)[Coinbase phishing email tricks users with fake wallet migration](https://www.bleepingcomputer.com/news/security/coinbase-phishing-email-tricks-users-with-fake-wallet-migration/)[Ransomware attack takes down health system network in Micronesia](https://therecord.media/ransomware-attack-micronesia-health-system)**Malware**[Undercover miner: how YouTubers get pressed into distributing SilentCryptoMiner as a restriction bypass tool](https://securelist.com/silentcryptominer-spreads-through-blackmail-on-youtube/115788/)[Ragnar Loader](https://catalyst.prodaft.com/public/report/ragnar-loader/overview)[Desert Dexter. Attacks on Middle Eastern countries](https://global.ptsecurity.com/analytics/pt-esc-threat-intelligence/desert-dexter-attacks-on-middle-eastern-countries)[Ballista — New IoT Botnet Targeting Thousands of TP-Link Archer Routers](https://www.catonetworks.com/blog/cato-ctrl-ballista-new-iot-botnet-targeting-thousands-of-tp-link-archer-routers/)[Captain MassJacker Sparrow: Uncovering the Malware’s Buried Treasure](https://www.cyberark.com/resources/threat-research-blog/captain-massjacker-sparrow-uncovering-the-malwares-buried-treasure)[Enhancing Malware Fingerprinting through Analysis of Evasive Techniques](https://arxiv.org/abs/2503.06495)**Hacking**[Tarlogic detects a hidden feature in the mass-market ESP32 chip that could infect millions of IoT devices](https://www.tarlogic.com/news/backdoor-esp32-chip-infect-ot-devices/)[GreyNoise Detects Mass Exploitation of Critical PHP-CGI Vulnerability (CVE-2024-4577), Signaling Broad Campaign](https://www.greynoise.io/blog/mass-exploitation-critical-php-cgi-vulnerability-cve-2024-457)[Unmasking the new persistent attacks on Japan](https://blog.talosintelligence.com/new-persistent-attacks-japan/)[Musk blames X outages on alleged ‘massive’ cyberattack](https://therecord.media/cyberattack-twitter-musk-massive-outages)[Apple fixes WebKit zero-day exploited in ‘extremely sophisticated’ attacks](https://www.bleepingcomputer.com/news/apple/apple-fixes-webkit-zero-day-exploited-in-extremely-sophisticated-attacks/)[Android Deserialization Deep Dive](https://www.hacktivesecurity.com/blog/2025/03/13/android-deserialization-deep-dive/)[Meta Warns of FreeType Vulnerability (CVE-2025-27363) With Active Exploitation Risk](https://thehackernews.com/2025/03/meta-warns-of-freetype-vulnerability.html)[New Evidence Suggests Attackers Are Mapping Infrastructure Before Exploitatio](https://www.greynoise.io/blog/new-ssrf-exploitation-surge)[Jailbreaking is (Mostly) Simpler Than You Think](https://arxiv.org/pdf/2503.05264)[Eavesdropping on Black-box Mobile Devices via Audio Amplifier’s EMR](https://t.co/I5A0NXjbPM)**Intelligence and Information Warfare**[Canadian intelligence agency warns of threat AI poses to upcoming elections](https://therecord.media/canada-cyber-agency-elections-warning-ai-)[SideWinder targets the maritime and nuclear sectors with an updated toolset](https://securelist.com/sidewinder-apt-updates-its-toolset-and-targets-nuclear-sector/115847/)[Ghost in the Router: China-Nexus Espionage Actor UNC3886 Targets Juniper Routers](https://cloud.google.com/blog/topics/threat-intelligence/china-nexus-espionage-targets-juniper-routers)[Lazarus Strikes npm Again with New Wave of Malicious Packages](https://socket.dev/blog/lazarus-strikes-npm-again-with-a-new-wave-of-malicious-packages)[Blind Eagle: …And Justice for All](https://research.checkpoint.com/2025/blind-eagle-and-justice-for-all/)[Lookout Discovers New Spyware by North Korean APT37](https://www.lookout.com/threat-intelligence/article/lookout-discovers-new-spyware-by-north-korean-apt37)[Former top NSA cyber official: Probationary firings ‘devastating’ to cyber, national security](https://cyberscoop.com/joyce-china-probationary-firings-devastating-congress/)[Hunting Active Threats in Littleton’s Grid with the Dragos Platform and OT Watch](https://www.dragos.com/wp-content/uploads/2025/03/Dragos_Littleton_Electric_Water_CaseStudy.pdf)**Cybersecurity**[Accelerated Takedowns: Limiting Dwell Time and Damage](https://www.cobaltstrike.com/blog/update-stopping-cybercriminals-from-abusing-cobalt-strike)[ESP32 Undocumented Bluetooth Commands: Clearing the Air](https://developer.espressif.com/blog/2025/03/esp32-bluetooth-clearing-the-air/)[Reducing the Cybersecurity Risks of Connected BMS](https://nexusconnect.io/articles/reducing-the-cybersecurity-risks-of-connected-bms)[Reporting cyberattacks on critical infrastructure mandatory from 1 April 2025](https://www.ncsc.admin.ch/ncsc/en/home/aktuell/im-fokus/2025/meldepflicht-2025.html)[The March 2025 Security Update Review](https://www.zerodayinitiative.com/blog/2025/3/11/the-march-2025-security-update-review)[Apple’s Lockdown Mode is good for security — but its notifications are baffling](https://techcrunch.com/2025/03/13/apples-lockdown-mode-is-good-for-security-but-its-notifications-are-baffling/)[Sign in as anyone: Bypassing SAML SSO authentication with parser differentials](https://github.blog/security/sign-in-as-anyone-bypassing-saml-sso-authentication-with-parser-differentials/)[Saudi Arabia Buys Pokémon Go, and Probably All of Your Location Data](https://www.404media.co/saudi-arabia-buys-pokemon-go-and-probably-all-of-your-location-data/)Follow me on Twitter: [**@securityaffairs**](https://twitter.com/securityaffairs) and [**Facebook**](https://www.facebook.com/sec.affairs) and [**Mastodon**](https://infosec.exchange/@securityaffairs)[**Pierluigi Paganini**](http://www.linkedin.com/pub/pierluigi-paganini/b/742/559)**(** [**SecurityAffairs**](http://securityaffairs.co/wordpress/)**–** **hacking, newsletter)**

Related Tags:
CVE-2024-4577

NAICS: 551 – Management Of Companies And Enterprises

NAICS: 55 – Management Of Companies And Enterprises

NAICS: 921 – Executive

Legislative

Other General Government Support

NAICS: 334 – Computer And Electronic Product Manufacturing

NAICS: 519 – Web Search Portals

Libraries

Archives

Other Information Services

NAICS: 62 – Health Care And Social Assistance

NAICS: 52 – Finance And Insurance

NAICS: 622 – Hospitals

Associated Indicators: