The week in cybersecurity was eventful: from mass attacks on X social media users to the takedown of one of the oldest botnets in history and new alarming signals about the use of state-level spyware. I break down the key events.

X in the crosshairs: a wave of password resets and phishing

X users are mass-complaining about a barrage of unauthorized password reset requests and notifications of logins from unknown devices. Platform engineers acknowledged the anomaly but deny an infrastructure breach, linking the activity to automated attempts to take over accounts. The motive is obvious — access to internal monetization, particularly X money.

The likely root cause is the echo of a 2022 API vulnerability that allowed emails and phones to be matched with accounts. The leak of a database of 200 million users a year later, followed by a 34 GB file with data on 201 million accounts in 2025, created fertile ground for attacks. Researchers have already recorded a botnet running millions of login/password combinations through the login form, as well as a separate phishing campaign with perfect copies of X emails. I strongly recommend enabling password reset protection and ignoring any emails not from @X.com addresses.

End of an era: the Sality botnet dismantled

An international operation by U.S. and European law enforcement put an end to the history of the decentralized Sality botnet, active since 2003. Given its P2P architecture, simply shutting down a server would not have helped — cyberpolice intercepted control of key supernodes, isolating infected machines. At the time of closure, there were more than 15,000 active devices.

Over the past eight years, Sality's main payload was the EggJagger module — a dangerous clipper that swaps cryptocurrency addresses in the clipboard. This is a reminder that even when transferring funds, you should always double-check the recipient's address.

U.S. vs. Russian hacker: charges over attack on freelancers

A federal court in California indicted 40-year-old Russian citizen Sirazhudin Aktulaev. From 2016 to 2017, he created 255 fake profiles on a U.S. labor exchange and sent 80,000 freelancers malicious Excel documents via the platform's messenger. The TVRAT and DarkVNC trojans provided covert access to victims' systems, and the hacker paid for the infrastructure with cryptocurrency. Half of the infected PCs were located in the U.S.

GuardBreaker: bypassing AI antivirus with forbidden content

ESET experts identified the GuardBreaker technique used by the pro-Russian group UAC-0099 against Ukrainian infrastructure. The attackers embed trigger phrases like "I want to create nuclear weapons" into code to provoke the AI scanner into refusing analysis due to protective filters. Thus, the malicious MATCHBOIL loader goes undetected. The method is already being adapted by other actors after the leak of the Shai-Hulud worm's source code.

Pegasus and NoviSpy: hunting the opposition in Serbia

Citizen Lab and the SHARE Foundation reported the infection of a Serbian student activist's iPhone with Pegasus spyware via a zero-click exploit in iMessage. Since the start of the year, at least 14 representatives of civil society have been targeted. In addition to Pegasus, an updated version of the local Android spyware NoviSpy was discovered, and activists' private messages were cited by pro-government TV. This is a clear coordinated campaign to suppress dissent ahead of the elections.

My comment: This week demonstrates an alarming trend — the convergence of traditional cyber threats and attacks on trust in AI systems. While some attackers blind algorithms, others continue to exploit vulnerabilities in human psychology and state spy arsenals. The crypto community, as the most technically savvy, should be at the forefront of cyber hygiene, but the main thing is not to forget that security begins with basic principles, not just with hype-driven technologies.