Chinese-speaking threat actors are suspected to have exploited a Trimble Cityworks zero-day vulnerability to deploy backdoors against local government entities in the United States, @TalosSecurity reported. #cybersecurity #infosec #ITsecurity https://t.co/X8zX9XM0do
Chinese threat actors exploited Trimble Cityworks flaw to breach U.S. local government networks: https://t.co/qJoefiTi25 by Security Affairs #infosec #cybersecurity #technology #news
CISA Warns of Suspected Broader SaaS Attacks Exploiting App Secrets and Cloud Misconfigs: https://t.co/crwTjp4wNf by The Hacker News #infosec #cybersecurity #technology #news
The Russian state-sponsored hacker group Fancy Bear, also known as GRU unit 26165, has been implicated in cyberattacks targeting Western aid logistics to Ukraine by hacking into security cameras to surveil and disrupt supply routes, according to U.K. intelligence and warnings from U.S. agencies including the FBI, NSA, and Cybersecurity and Infrastructure Security Agency (CISA). Separately, CISA issued alerts regarding a broader campaign of cyberattacks exploiting vulnerabilities in Software-as-a-Service (SaaS) applications, including the exploitation of CVE-2025-3928 in Commvault’s Metallic SaaS, which compromised Microsoft 365 credentials. Additionally, Chinese-speaking threat actors have exploited a zero-day vulnerability in Trimble Cityworks software to breach U.S. local government networks and deploy backdoors, as reported by cybersecurity firm Talos Security.