A Türkiye-linked advanced persistent threat (APT) group known as Marbled Dust has exploited a zero-day vulnerability (CVE-2025-27920) in Output Messenger, a communication app used in India, to conduct espionage targeting Kurdish military users operating in Iraq. The attackers deployed Golang backdoors on Kurdish servers to facilitate stealthy surveillance. This cyber operation represents a targeted effort to infiltrate Kurdish military communications in the region. Separately, China-linked APTs have exploited another vulnerability (CVE-2025-31324) in SAP systems, breaching 581 critical systems worldwide. In the broader cybersecurity landscape, 265 cyber attacks were recorded across 33 countries in the week leading to May 13, 2025, with India being the most affected country, accounting for 22.3% of incidents. The most active threat actor during this period was NoName057(16), responsible for 70 attacks.
Turkey-Aligned Hackers Targeted Iraq-Based Kurds with Zero-Day Exploit https://t.co/fl6uMNnnsQ
China-Linked APTs Exploit SAP CVE-2025-31324 to Breach 581 Critical Systems Worldwide: https://t.co/yc9EaUbjXU by The Hacker News #infosec #cybersecurity #technology #news
🟧 #HackTuesday 🟧 Hack Tuesday: Week 07 - 13 May 2025 ⚠️265 cyber attacks across 33 countries ⚠️ ➡️The most active threat actor last week was NoName057(16) claiming responsibility for 70 cyber attacks. ➡️India is the most affected country, accounting for 22.3% of incidents, https://t.co/uz9YIltzLj