{"id":2102,"date":"2025-06-16T14:29:00","date_gmt":"2025-06-16T11:29:00","guid":{"rendered":"https:\/\/trustcrypt.com\/weekly-security-analysis-iphone-spyware-microsoft-zero-day-vulnerability-tokenbreak-incident-ai-data-breaches-and-additional-insights\/"},"modified":"2025-06-16T14:29:00","modified_gmt":"2025-06-16T11:29:00","slug":"weekly-security-analysis-iphone-spyware-microsoft-zero-day-vulnerability-tokenbreak-incident-ai-data-breaches-and-additional-insights","status":"publish","type":"post","link":"https:\/\/trustcrypt.com\/ar\/weekly-security-analysis-iphone-spyware-microsoft-zero-day-vulnerability-tokenbreak-incident-ai-data-breaches-and-additional-insights\/","title":{"rendered":"Weekly Security Analysis: iPhone Spyware, Microsoft Zero-Day Vulnerability, TokenBreak Incident, AI Data Breaches, and Additional Insights"},"content":{"rendered":"<p>Some of the most significant security challenges emerge quietly, without alerts or warnings. Small actions that appear benign often mask deeper issues. Attackers have adapted their tactics to blend in, complicating the detection of anomalies.<\/p>\n<p>The recent news underscores not only the incidents themselves but also the ease with which they occur. If we focus solely on obvious warnings, we risk overlooking subtle indicators right in front of us.<\/p>\n<p>This analysis highlights various tactics and oversights that can go unnoticed yet pose considerable risks.<\/p>\n<p><strong>\u26a1 Threat of the Week<\/strong><\/p>\n<p><strong>Apple Zero-Click Flaw in Messages Exploited to Deliver Paragon Spyware<\/strong> \u2014 Apple has acknowledged an active security vulnerability in its Messages app, CVE-2025-43200, exploited to target members of civil society in sophisticated cyber attacks. Addressed in February through updates to iOS and macOS, the vulnerability paved the way for attackers to deploy Paragon&#8217;s Graphite spyware, successfully infecting notable journalists, including Italian journalist Ciro Pellegrino, as reported by the Citizen Lab.<\/p>\n<p><strong>\ud83d\udd14 Top News<\/strong><\/p>\n<ul>\n<li><strong>Microsoft Fixes WebDAV 0-Day Exploited in Targeted Attacks<\/strong> \u2014 Microsoft has resolved a zero-day vulnerability in Web Distributed Authoring and Versioning (WebDAV), exploited in targeted attacks by the threat actor Stealth Falcon. This vulnerability was leveraged to deliver Horus Agent, showcasing the threat actors&#8217; refined capabilities.<\/li>\n<li><strong>TokenBreak Attack Bypasses AI Moderation With a Single Character Change<\/strong> \u2014 Research has disclosed an attack technique named TokenBreak, capable of circumventing large language model (LLM) content moderation with minimal alterations in input.<\/li>\n<li><strong>Google Addresses Flaw Leaking Phone Numbers Linked to Accounts<\/strong> \u2014 Google has remediated a vulnerability allowing potential brute-force recovery of phone numbers tied to user accounts.<\/li>\n<li><strong>Rare Werewolf and DarkGaboon Leverage Readymade Tooling to Target Russia<\/strong> \u2014 Threat actors utilized legitimate tools and malware to breach Russian entities, illustrating how commonplace administrative tactics can complicate defense measures.<\/li>\n<li><strong>Zero-Click AI Flaw Allows Data Exfiltration Without User Interaction<\/strong> \u2014 A newly discovered vulnerability in Microsoft 365 could enable attackers to exfiltrate sensitive data via crafted emails without user awareness.<\/li>\n<li><strong>VexTrio Runs a Massive Affiliate Program to Propagate Malware, Scams<\/strong> \u2014 The VexTrio operation has been linked to extensive campaigns that compromise WordPress sites, transforming them into active participants in malware and scam distribution.<\/li>\n<\/ul>\n<p><strong>\u200e\ufe0f\u200d\ud83d\udd25 Trending CVEs<\/strong><\/p>\n<p>Software vulnerabilities remain the favored entry points for attackers. It&#8217;s critical to promptly address these flaws to maintain security. Key vulnerabilities identified this week include:<\/p>\n<ul>\n<li>CVE-2025-43200 (Apple),<\/li>\n<li>CVE-2025-32711 (Microsoft 365 Copilot),<\/li>\n<li>CVE-2025-33053 (Microsoft Windows),<\/li>\n<li>CVE-2025-47110 (Adobe Commerce and Magento),<\/li>\n<li>CVE-2025-43697, CVE-2025-43698, CVE-2025-43699, CVE-2025-43700, CVE-2025-43701 (Salesforce),<\/li>\n<li>CVE-2025-24016 (Wazuh),<\/li>\n<li>CVE-2025-5484, CVE-2025-5485 (SinoTrack),<\/li>\n<li>and numerous others across various platforms.<\/li>\n<\/ul>\n<p><strong>\ud83d\udcf0 Around the Cyber World<\/strong><\/p>\n<ul>\n<li><strong>Kazakh and Singapore Authorities Disrupt Criminal Networks<\/strong> \u2014 Authorities in Kazakhstan dismantled a network involved in selling citizen data through Telegram, arresting over 140 individuals. Concurrently, Singapore&#8217;s coordinated effort led to around 1,800 arrests linked to online scams.<\/li>\n<li><strong>Microsoft to Block .library-ms and .search-ms File Types in Outlook<\/strong> \u2014 In response to security concerns, Microsoft is updating the banned attachment file types in Outlook.<\/li>\n<li><strong>Meta and Yandex Misuse Tracking Code<\/strong> \u2014 Both companies reportedly exploited Android&#8217;s localhost ports to transmit tracking data between web browsers and native apps, potentially compromising user privacy.<\/li>\n<li><strong>Replay Attacks Bypass Deepfake Detection<\/strong> \u2014 Research indicates that re-recorded deepfake audio can successfully deceive detection models, increasing the risk for corporate environments.<\/li>\n<li><strong>Microsoft Defender Flaw Disclosed<\/strong> \u2014 A vulnerability in Microsoft Defender was detailed, allowing unauthorized spoofing on adjacent networks. The issue was promptly addressed with a patch.<\/li>\n<li><strong>Apple Updates Passwords App<\/strong> \u2014 New enhancements to Apple&#8217;s Passwords app aim to improve transparency and security for user credentials.<\/li>\n<\/ul>\n<p><strong>\ud83d\udd12 Tip of the Week<\/strong><\/p>\n<p>Understanding the hidden ways trackers collect data is essential for digital privacy. Methods like localhost tracking reveal user activity without consent. Measures to counteract these tactics include:<\/p>\n<ul>\n<li>Regularly uninstalling non-essential applications.<\/li>\n<li>Utilizing privacy-centric browsers and maintaining strict control over background data.<\/li>\n<li>Frequent clearing of browser data and employing incognito modes for sensitive sessions.<\/li>\n<\/ul>\n<p>In conclusion, many threats may not be invisible; rather, they are mischaracterized or underestimated. Vigilance in monitoring security alerts is paramount to safeguarding against evolving threats.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Some of the most significant security challenges emerge quietly, without alerts or warnings. Small actions that appear benign often mask&#8230;<\/p>\n","protected":false},"author":1,"featured_media":2103,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"Default","format":"standard","meta":{"inline_featured_image":false,"footnotes":""},"categories":[28],"tags":[79,102,108],"class_list":["post-2102","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-blog","tag-security","tag-spyware","tag-vulnerability"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v25.0 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>Weekly Security Analysis: iPhone Spyware, Microsoft Zero-Day Vulnerability, TokenBreak Incident, AI Data Breaches, and Additional Insights - Trustcrypt<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/trustcrypt.com\/ar\/weekly-security-analysis-iphone-spyware-microsoft-zero-day-vulnerability-tokenbreak-incident-ai-data-breaches-and-additional-insights\/\" \/>\n<meta property=\"og:locale\" content=\"ar_AR\" \/>\n<meta property=\"og:locale:alternate\" content=\"en_GB\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Weekly Security Analysis: iPhone Spyware, Microsoft Zero-Day Vulnerability, TokenBreak Incident, AI Data Breaches, and Additional Insights\" \/>\n<meta property=\"og:description\" content=\"Some of the most significant security challenges emerge quietly, without alerts or warnings. Small actions that appear benign often mask...\" \/>\n<meta property=\"og:url\" content=\"https:\/\/trustcrypt.com\/ar\/weekly-security-analysis-iphone-spyware-microsoft-zero-day-vulnerability-tokenbreak-incident-ai-data-breaches-and-additional-insights\/\" \/>\n<meta property=\"og:site_name\" content=\"Trustcrypt\" \/>\n<meta property=\"article:published_time\" content=\"2025-06-16T11:29:00+00:00\" \/>\n<meta name=\"author\" content=\"Trustscrypt\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"\u0643\u064f\u062a\u0628 \u0628\u0648\u0627\u0633\u0637\u0629\" \/>\n\t<meta name=\"twitter:data1\" content=\"Trustscrypt\" \/>\n\t<meta name=\"twitter:label2\" content=\"\u0648\u0642\u062a \u0627\u0644\u0642\u0631\u0627\u0621\u0629 \u0627\u0644\u0645\u064f\u0642\u062f\u0651\u0631\" \/>\n\t<meta name=\"twitter:data2\" content=\"3 \u062f\u0642\u0627\u0626\u0642\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\/\/trustcrypt.com\/weekly-security-analysis-iphone-spyware-microsoft-zero-day-vulnerability-tokenbreak-incident-ai-data-breaches-and-additional-insights\/\",\"url\":\"https:\/\/trustcrypt.com\/weekly-security-analysis-iphone-spyware-microsoft-zero-day-vulnerability-tokenbreak-incident-ai-data-breaches-and-additional-insights\/\",\"name\":\"Weekly Security Analysis: iPhone Spyware, Microsoft Zero-Day Vulnerability, TokenBreak Incident, AI Data Breaches, and Additional Insights\",\"isPartOf\":{\"@id\":\"https:\/\/trustcrypt.com\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/trustcrypt.com\/weekly-security-analysis-iphone-spyware-microsoft-zero-day-vulnerability-tokenbreak-incident-ai-data-breaches-and-additional-insights\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/trustcrypt.com\/weekly-security-analysis-iphone-spyware-microsoft-zero-day-vulnerability-tokenbreak-incident-ai-data-breaches-and-additional-insights\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/trustcrypt.com\/wp-content\/uploads\/2025\/06\/weekly-security-analysis-iphone-spyware-microsoft-zero-day-vulnerability-tokenbreak-incident-ai-data-breaches-and-additional-insights.webp\",\"datePublished\":\"2025-06-16T11:29:00+00:00\",\"author\":{\"@id\":\"https:\/\/trustcrypt.com\/#\/schema\/person\/469b1cf97b9f7ea4e4d7fa31689dfa9f\"},\"inLanguage\":\"ar\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/trustcrypt.com\/weekly-security-analysis-iphone-spyware-microsoft-zero-day-vulnerability-tokenbreak-incident-ai-data-breaches-and-additional-insights\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"ar\",\"@id\":\"https:\/\/trustcrypt.com\/weekly-security-analysis-iphone-spyware-microsoft-zero-day-vulnerability-tokenbreak-incident-ai-data-breaches-and-additional-insights\/#primaryimage\",\"url\":\"https:\/\/trustcrypt.com\/wp-content\/uploads\/2025\/06\/weekly-security-analysis-iphone-spyware-microsoft-zero-day-vulnerability-tokenbreak-incident-ai-data-breaches-and-additional-insights.webp\",\"contentUrl\":\"https:\/\/trustcrypt.com\/wp-content\/uploads\/2025\/06\/weekly-security-analysis-iphone-spyware-microsoft-zero-day-vulnerability-tokenbreak-incident-ai-data-breaches-and-additional-insights.webp\",\"width\":1792,\"height\":1024,\"caption\":\"Weekly Security Analysis: iPhone Spyware, Microsoft Zero-Day Vulnerability, TokenBreak Incident, AI Data Breaches, and Additional Insights\"},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/trustcrypt.com\/#website\",\"url\":\"https:\/\/trustcrypt.com\/\",\"name\":\"Trustcrypt\",\"description\":\"\u0627\u0644\u0623\u0645\u0646 \u0647\u0648 \u0627\u0633\u0645\u0646\u0627 \u0627\u0644\u062b\u0627\u0646\u064a\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/trustcrypt.com\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"ar\"},{\"@type\":\"Person\",\"@id\":\"https:\/\/trustcrypt.com\/#\/schema\/person\/469b1cf97b9f7ea4e4d7fa31689dfa9f\",\"name\":\"Trustscrypt\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"ar\",\"@id\":\"https:\/\/trustcrypt.com\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/4c36ff3376565a0f4981e9397667feb08d5e09acacce32a52ea4a3f628e03692?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/4c36ff3376565a0f4981e9397667feb08d5e09acacce32a52ea4a3f628e03692?s=96&d=mm&r=g\",\"caption\":\"Trustscrypt\"},\"sameAs\":[\"http:\/\/trustcrypt.com\"],\"url\":\"https:\/\/trustcrypt.com\/ar\/author\/trustscrypt\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Weekly Security Analysis: iPhone Spyware, Microsoft Zero-Day Vulnerability, TokenBreak Incident, AI Data Breaches, and Additional Insights - Trustcrypt","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/trustcrypt.com\/ar\/weekly-security-analysis-iphone-spyware-microsoft-zero-day-vulnerability-tokenbreak-incident-ai-data-breaches-and-additional-insights\/","og_locale":"ar_AR","og_type":"article","og_title":"[:en]Weekly Security Analysis: iPhone Spyware, Microsoft Zero-Day Vulnerability, TokenBreak Incident, AI Data Breaches, and Additional Insights[:] - Trustcrypt","og_description":"Some of the most significant security challenges emerge quietly, without alerts or warnings. Small actions that appear benign often mask...","og_url":"https:\/\/trustcrypt.com\/ar\/weekly-security-analysis-iphone-spyware-microsoft-zero-day-vulnerability-tokenbreak-incident-ai-data-breaches-and-additional-insights\/","og_site_name":"Trustcrypt","article_published_time":"2025-06-16T11:29:00+00:00","author":"Trustscrypt","twitter_card":"summary_large_image","twitter_misc":{"\u0643\u064f\u062a\u0628 \u0628\u0648\u0627\u0633\u0637\u0629":"Trustscrypt","\u0648\u0642\u062a \u0627\u0644\u0642\u0631\u0627\u0621\u0629 \u0627\u0644\u0645\u064f\u0642\u062f\u0651\u0631":"3 \u062f\u0642\u0627\u0626\u0642"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/trustcrypt.com\/weekly-security-analysis-iphone-spyware-microsoft-zero-day-vulnerability-tokenbreak-incident-ai-data-breaches-and-additional-insights\/","url":"https:\/\/trustcrypt.com\/weekly-security-analysis-iphone-spyware-microsoft-zero-day-vulnerability-tokenbreak-incident-ai-data-breaches-and-additional-insights\/","name":"Weekly Security Analysis: iPhone Spyware, Microsoft Zero-Day Vulnerability, TokenBreak Incident, AI Data Breaches, and Additional Insights","isPartOf":{"@id":"https:\/\/trustcrypt.com\/#website"},"primaryImageOfPage":{"@id":"https:\/\/trustcrypt.com\/weekly-security-analysis-iphone-spyware-microsoft-zero-day-vulnerability-tokenbreak-incident-ai-data-breaches-and-additional-insights\/#primaryimage"},"image":{"@id":"https:\/\/trustcrypt.com\/weekly-security-analysis-iphone-spyware-microsoft-zero-day-vulnerability-tokenbreak-incident-ai-data-breaches-and-additional-insights\/#primaryimage"},"thumbnailUrl":"https:\/\/trustcrypt.com\/wp-content\/uploads\/2025\/06\/weekly-security-analysis-iphone-spyware-microsoft-zero-day-vulnerability-tokenbreak-incident-ai-data-breaches-and-additional-insights.webp","datePublished":"2025-06-16T11:29:00+00:00","author":{"@id":"https:\/\/trustcrypt.com\/#\/schema\/person\/469b1cf97b9f7ea4e4d7fa31689dfa9f"},"inLanguage":"ar","potentialAction":[{"@type":"ReadAction","target":["https:\/\/trustcrypt.com\/weekly-security-analysis-iphone-spyware-microsoft-zero-day-vulnerability-tokenbreak-incident-ai-data-breaches-and-additional-insights\/"]}]},{"@type":"ImageObject","inLanguage":"ar","@id":"https:\/\/trustcrypt.com\/weekly-security-analysis-iphone-spyware-microsoft-zero-day-vulnerability-tokenbreak-incident-ai-data-breaches-and-additional-insights\/#primaryimage","url":"https:\/\/trustcrypt.com\/wp-content\/uploads\/2025\/06\/weekly-security-analysis-iphone-spyware-microsoft-zero-day-vulnerability-tokenbreak-incident-ai-data-breaches-and-additional-insights.webp","contentUrl":"https:\/\/trustcrypt.com\/wp-content\/uploads\/2025\/06\/weekly-security-analysis-iphone-spyware-microsoft-zero-day-vulnerability-tokenbreak-incident-ai-data-breaches-and-additional-insights.webp","width":1792,"height":1024,"caption":"Weekly Security Analysis: iPhone Spyware, Microsoft Zero-Day Vulnerability, TokenBreak Incident, AI Data Breaches, and Additional Insights"},{"@type":"WebSite","@id":"https:\/\/trustcrypt.com\/#website","url":"https:\/\/trustcrypt.com\/","name":"Trustcrypt","description":"\u0627\u0644\u0623\u0645\u0646 \u0647\u0648 \u0627\u0633\u0645\u0646\u0627 \u0627\u0644\u062b\u0627\u0646\u064a","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/trustcrypt.com\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"ar"},{"@type":"Person","@id":"https:\/\/trustcrypt.com\/#\/schema\/person\/469b1cf97b9f7ea4e4d7fa31689dfa9f","name":"Trustscrypt","image":{"@type":"ImageObject","inLanguage":"ar","@id":"https:\/\/trustcrypt.com\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/4c36ff3376565a0f4981e9397667feb08d5e09acacce32a52ea4a3f628e03692?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/4c36ff3376565a0f4981e9397667feb08d5e09acacce32a52ea4a3f628e03692?s=96&d=mm&r=g","caption":"Trustscrypt"},"sameAs":["http:\/\/trustcrypt.com"],"url":"https:\/\/trustcrypt.com\/ar\/author\/trustscrypt\/"}]}},"_links":{"self":[{"href":"https:\/\/trustcrypt.com\/ar\/wp-json\/wp\/v2\/posts\/2102","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/trustcrypt.com\/ar\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/trustcrypt.com\/ar\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/trustcrypt.com\/ar\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/trustcrypt.com\/ar\/wp-json\/wp\/v2\/comments?post=2102"}],"version-history":[{"count":0,"href":"https:\/\/trustcrypt.com\/ar\/wp-json\/wp\/v2\/posts\/2102\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/trustcrypt.com\/ar\/wp-json\/wp\/v2\/media\/2103"}],"wp:attachment":[{"href":"https:\/\/trustcrypt.com\/ar\/wp-json\/wp\/v2\/media?parent=2102"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/trustcrypt.com\/ar\/wp-json\/wp\/v2\/categories?post=2102"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/trustcrypt.com\/ar\/wp-json\/wp\/v2\/tags?post=2102"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}