$176M Crypto Fine, Hacking Formula 1, Chromium Vulns, AI Hijack & More

$176M Crypto Fine, Hacking Formula 1, Chromium Vulns, AI Hijack & More

Oct 23, 2025Ravie LakshmananCybersecurity / Hacking Information

Criminals don’t should be intelligent on a regular basis; they simply comply with the simplest path in: trick customers, exploit stale elements, or abuse trusted programs like OAuth and package deal registries. In case your stack or habits make any of these simple, you’re already a goal.

This week’s ThreatsDay highlights present precisely how these weak factors are being exploited — from missed misconfigurations to classy new assault chains that flip extraordinary instruments into highly effective entry factors.

  1. Starlink crackdown hits Southeast Asian rip-off hubs

    SpaceX said it has disabled greater than 2,500 Starlink units related to scam compounds in Myanmar. It is at present not clear when the units had been taken offline. The event comes shut on the heels of ongoing actions to crack down on on-line rip-off facilities, with Myanmar’s navy junta conducting raids on a rip-off hotspot in a rebel-held area of japanese Myanmar, detaining greater than 2,000 folks and seizing dozens of Starlink satellite tv for pc web units at KK Park, a sprawling cybercrime hub to the south of Myawaddy. In February 2025, the Thai authorities cut off power supply to a few areas in Myanmar, Myawaddy, Payathonzu, and Tachileik, which have grow to be havens for criminal syndicates who’ve coerced a whole bunch of hundreds of individuals in Southeast Asia and elsewhere into serving to run on-line scams, together with false romantic ploys, bogus funding alternatives, and unlawful playing schemes. These operations have been massively profitable, ensnaring a whole bunch of hundreds of staff and raking in tens of billions of {dollars} yearly from victims, per estimates from the United Nations. The rip-off facilities emerged out of Cambodia, Thailand, and Myanmar for the reason that COVID-19 pandemic, however have since unfold to different elements of the world equivalent to Africa. Employees on the “labor camps” are sometimes recruited and trafficked below the promise of well-paid jobs after which held captive with threats of violence. In latest months, legislation enforcement authorities have stepped up their efforts, arresting a whole bunch of suspects throughout Asia and deporting a number of of them. Based on the Global New Light of Myanmar, a complete of 9,551 international nationals who illegally entered Myanmar have been arrested between January 30 and October 19, 2025, with 9,337 deported to their respective international locations. Earlier this week, South Korean police officers formally arrested 50 South Koreans repatriated from Cambodia on accusations they labored for on-line rip-off organizations within the Southeast Asian nation. Cambodia and South Korea just lately agreed to companion in combating on-line scams following the demise of a South Korean scholar who was reportedly compelled to work in a rip-off heart in Cambodia. The demise of the 22-year-old has additionally prompted South Korea, which is reportedly readying sanctions in opposition to the teams working in Cambodia, to issue a “code black” journey ban to elements of the nation, citing latest will increase in circumstances of detention and “fraudulent employment.” Greater than 1,000 South Koreans are believed to be amongst round 200,000 folks of assorted nationalities working in Cambodia’s rip-off business.

Each one in all these incidents tells the identical story: attackers don’t break in — they log in, inject, or hijack what’s already trusted. The distinction between surviving and changing into a headline is how briskly you patch, isolate, and confirm.

Keep sharp, assessment your defenses, and hold watching ThreatsDay — as a result of subsequent week’s breaches are already being written in at the moment’s missed bugs.

Comments

No comments yet. Why don’t you start the discussion?

Leave a Reply

Your email address will not be published. Required fields are marked *