This week, the cyber threat landscape delivered several landmark events, from massive attacks on users of the largest social network to the dismantling of one of the oldest botnets in history and new rounds of espionage scandals. I break down the key incidents that will shape the balance of power in digital security in the near future.

Anomalous activity around X: an attack or an echo of old problems?

Users of the X platform faced a real deluge of unauthorized password reset requests and notifications about logins from unfamiliar devices. The social network's engineers acknowledged the anomaly but categorically deny any breach of infrastructure. In my view, this is a classic sign of a credential stuffing campaign, where attackers use previously compromised databases.

The situation is compounded by the fact that in April of this year, researchers detected a botnet that ran millions of accounts through X's login form. Although two-factor authentication blocks most attempts, phishing campaigns disguised as official emails from the service remain a serious threat. I recommend that everyone, without exception, enable password reset protection and use authenticator apps rather than SMS.

End of an era: the Sality botnet is put to rest

An international law enforcement operation put an end to the history of Sality, a decentralized botnet active since 2003. At the time of its takedown, it comprised more than 15,000 infected devices. The uniqueness of this network lay in its P2P architecture, which made it invulnerable to targeted strikes on command servers.

The key success was seizing control of supernodes, which made it possible to isolate infected machines from each other. Of particular interest is the fact that in recent years, Sality evolved into a specialized tool for stealing cryptocurrencies, using clipboard theft to swap wallet addresses. This once again confirms that even the old guard of malware is actively adapting to the realities of digital assets.

AI in the service of evil: a new tactic for evading antivirus software

ESET experts discovered an elegant and dangerous technique called GuardBreaker, used by the group UAC-0099 against Ukrainian infrastructure. The attackers learned to "blind" AI scanners by embedding trigger phrases into code that provoke protective filters to activate. The AI interrupts its analysis without ever reaching the core of the malicious program.

This is a wake-up call for the entire cybersecurity industry. We are witnessing an arms race where AI-based protection is becoming vulnerable to prompt engineering. The fact that the source code of such worms has already been made publicly available means this tactic will quickly become widespread.

Digital espionage in Serbia: Pegasus reaches activists

International human rights organizations confirmed that the iPhone of a member of the Serbian student movement was infected with Pegasus spyware via a zero-click exploit. This is just the tip of the iceberg: since the beginning of the year, at least 14 representatives of civil society, including opposition politicians, have been targeted.

Of particular concern is the combination of commercial spyware with local developments such as the Android trojan NoviSpy. We are witnessing a convergence of state and private surveillance tools, creating unprecedented risks for democratic institutions and freedom of speech. This situation demands an immediate response from both technology giants and the international community.