Google Warns That China-Linked Malware Will Haunt Networks for Years
Companies may uncover traces of a Chinese-linked hacking campaign lurking in their networks for at least the next two years, Google warns. On Wednesday, Google’s Threat Intelligence Group reported that it is tracking a backdoor malware known as BRICKSTORM, which has been used by hackers to maintain access to organizations and companies in the U.S. for an average of 393 days. Google’s cybersecurity consulting arm, Mandiant, has been responding to these intrusions since March 2025.
CISA Details That Hackers Gained Access to a U.S. Federal Agency Network Via GeoServer RCE Vulnerability
CISA has released a comprehensive cybersecurity advisory detailing how threat actors successfully compromised a U.S. federal civilian executive branch agency’s network by exploiting CVE-2024-36401, a critical remote code execution vulnerability in GeoServer. The incident, which remained undetected for three weeks, highlights significant gaps in vulnerability management and incident response preparedness within federal agencies.
Nikon revokes all C2PA image authenticity certificates after major vulnerability exposed
Nikon has confirmed that it will revoke all C2PA certificates issued to date after a major vulnerability in its authenticity feature was uncovered. The flaw, first detected by long-time Nikon Rumors contributor Horshack, showed that images could be fraudulently signed by Nikon’s new C2PA-enabled cameras, raising serious questions about digital provenance and image verification. Nikon has now paused the service while it works on a fix, with further updates promised through the Nikon Imaging Cloud.
Co-op chief executive ‘very proud’ of cyber attack response despite huge financial losses
The chief executive of the Co-op said they’re “very proud” of the retailer’s response to a cyber attack earlier this year despite huge financial losses. In a statement reacting to the company’s recent earnings report, Shrine Khoury-Haq said the company’s “financial strength allowed us to respond as a member-owned organization”. “I’m very proud of how we reacted: we kept trading, prioritized colleagues and vulnerable communities, and launched a partnership with The Hacking Games to tackle youth disenfranchisement – the root of many cyber threats,” Khoury-Haq said.
CSA Unveils SaaS Security Controls Framework to Ease Complexity
Security for SaaS is delivered by the shared responsibility model. The provider is responsible for the security of the cloud – it secures the core application and the infrastructure it runs on. The customer is responsible for security in the cloud – their own data, user accounts and access, and correctly configuring the security settings offered by the individual provider. The problem is little conformity from the providers. Each may offer different settings in a different manner requiring a different level of effort from the customer – and this applies to each SaaS in use, placing a heavy load on the customer.