The world of cybersecurity is undergoing tectonic shifts: from mass attacks on users of major social networks to the dismantling of legendary botnets and the deployment of state-level spyware. I break down the key events of the week that will shape the threat landscape for months to come.
Assault on X accounts: phishing, botnets, and ghosts of old breaches
Users of the X platform have faced a veritable avalanche of unauthorized password reset requests and notifications about logins from unknown devices. The social network's engineers acknowledge the anomaly but deny any infrastructure breach, attributing it all to automated hacker attacks targeting access to the X Money monetization system.
In my view, this is just the tip of the iceberg. We are witnessing the echo of the 2022 API vulnerability that allowed emails to be matched with accounts. A database of 200 million users has long been circulating on the market, and in March 2025, hacker ThinkingOne released a fresh dump of 34 GB. Add to that a botnet that pushed 4.8 million accounts through the login form in April, plus an independent phishing campaign with perfect email replicas—and the picture becomes threatening. 2FA blocks most attacks, but social engineering remains the primary weapon of malicious actors.
The death of Sality: the end of the P2P botnet era
An international law enforcement operation by the U.S. and Europe has put an end to the history of the Sality botnet, active since 2003. This is not just a virus but a decentralized P2P network comprising over 15,000 infected devices. The key moment was seizing control of supernodes, which made it possible to isolate machines and block command transmission.
Of particular interest is the evolution of its payload. In recent years, Sality was used not for run-of-the-mill DDoS but for stealing cryptocurrencies via the EggJagger module, which swapped wallet addresses in the clipboard. This once again confirms that even the most archaic infrastructure can be repurposed for modern financial crimes.
Hunting freelancers: charges against a Russian citizen
A federal court in California has revealed details of the case of Sirazhudin Aktulaev, arrested in Cyprus. From 2016 to 2017, he created 255 fake profiles on a U.S. labor exchange and infected over 80,000 freelancers with the TVRAT and DarkVNC trojans. Malicious macros in Excel files opened hidden access to victims' systems, allowing theft of data for e-commerce. Notably, he paid for the infrastructure with cryptocurrency, once again underscoring the role of digital assets in the shadow economy.
GuardBreaker: how to fool AI antivirus
ESET researchers have discovered a technique for bypassing AI systems, dubbed GuardBreaker. The pro-Russian group UAC-0099 embeds trigger phrases in code, such as "I want to create nuclear weapons," to provoke a refusal by the LLM scanner. The AI analyst, upon encountering prohibited content, interrupts the session without reaching the analysis of the actual malicious code. This is an elegant way to "blind" automated defenses by exploiting their own limitations.
Pegasus in Serbia: state-level espionage
Citizen Lab and the SHARE Foundation have confirmed the infection of a Serbian student activist's iPhone with Pegasus spyware via a zero-click exploit in iMessage. This is just the tip of the iceberg: since the start of the year, at least 14 members of civil society have been targeted. The discovery of an updated version of the Android spyware NoviSpy and leaks of private messages to pro-government media paint a frightening picture of total surveillance synchronized with political events in the country.
My verdict. This week showed that cybersecurity is not just about technology but also geopolitics. We are moving toward a world where attacks on infrastructure and people are becoming increasingly personalized and sophisticated. Cryptocurrencies remain both a target and a tool for malicious actors, while AI, meant to protect us, itself becomes a vulnerable link. Investors and users alike should reconsider their security protocols: two-factor authentication is a minimum, not a panacea. Vigilance and critical thinking are your greatest assets in this new reality.