← Terug naar nieuwsbrief

AI & Security Nieuws – 17 Oktober 2025

Nieuwsbrief

By Djimit* een overzicht voor AI cloud- en security professionals*

1. Tencent onthult ’training-vrije’ AI-modelverbetering

2. Claude geïntegreerd met Microsoft 365 ecosysteem

3. Big Tech investeert miljoenen in AI-training voor leraren

4. ‘Verbalized Sampling’ techniek verhoogt AI-creativiteit met 2x

5. Nebius lanceert enterprise-grade AI Cloud 3.0 “Aether”

6. Pew Research: Weinig vertrouwen in China’s AI-regulering

7. China publiceert uitgebreid AI Safety Governance Framework 2.0

Insight of the Day

China’s paradox van AI-ontwikkeling versus controle: Het Chinese AI Safety Governance Framework 2.0 toont de spanning tussen China’s ambitie om AI door de hele economie te verspreiden via het “AI+ Plan” en de behoefte aan controle over informatie en potentiële existentiële risico’s. Het framework erkent voor het eerst expliciet risico’s van open-source modellen en verlies van menselijke controle – een significante verschuiving die internationale AI-governance kan beïnvloeden, gezien China’s dominante positie in AI-ontwikkeling.

Kritieke Zero-Day Exploitaties

High-Impact Databreach & Ransomware

APT-campagnes en geavanceerde aanvallen

AI/LLM Misbruik & Regelgeving

Patch/Advies: Kernpunten Patch Tuesday

Sources[1] Actively exploited Gladinet CentreStack zero-day addressed https://www.scworld.com/brief/actively-exploited-gladinet-centrestack-zero-day-addressed[2] Hackers used Cisco zero-day to plant rootkits on network switches (CVE-2025-20352) https://www.helpnetsecurity.com/2025/10/17/hackers-used-cisco-zero-day-to-plant-rootkits-on-network-devices-cve-2025-20352/[3] Cybersecurity Snapshot: October 17, 2025 – Tenable https://www.tenable.com/blog/cybersecurity-snapshot-f5-breach-chagpt-abuse-llm-attacks-ai-governance-10-17-2025[4] F5 Cybersecurity Breach Sparks National Security Concerns, ASD … https://australiancybersecuritymagazine.com.au/f5-cybersecurity-breach-sparks-national-security-concerns-asd-issues-urgent-advisory/[5] Cyber News Roundup – October 17 2025 – Integrity360 https://www.integrity360.com/cyber-news-roundup-october-17-2025[6] Envoy Air targeted in Oracle-linked hacking campaign | Reuters https://www.reuters.com/sustainability/boards-policy-regulation/envoy-air-targeted-oracle-linked-hacking-campaign-2025-10-17/[7] Ransomware hits record highs: Healthcare, government, tech … https://industrialcyber.co/ransomware/ransomware-hits-record-highs-healthcare-government-tech-sectors-top-targets-in-blackfog-q3-2025-analysis/[8] APT28 Deploys BeardShell and Covenant Modules via Weaponized … https://gbhackers.com/weaponized-office-documents/[9] Scattered LAPSUS$ Hunters: 2025’s Most Dangerous Cybercrime … https://www.picussecurity.com/resource/blog/scattered-lapsus-hunters-2025s-most-dangerous-cybercrime-supergroup[10] Microsoft October 2025 Patch Tuesday fixes 6 zero-days, 172 flaws https://www.bleepingcomputer.com/news/microsoft/microsoft-october-2025-patch-tuesday-fixes-6-zero-days-172-flaws/[11] Microsoft’s October 2025 Patch Tuesday Addresses 167 CVEs (CVE … https://www.tenable.com/blog/microsofts-october-2025-patch-tuesday-addresses-167-cves-cve-2025-24990-cve-2025-59230[12] Patch Tuesday Update – October 2025 | Balbix https://www.balbix.com/blog/patch-tuesday-update-october-2025/[13] October 2025 Patch Tuesday: Updates and Analysis https://www.crowdstrike.com/en-us/blog/patch-tuesday-analysis-october-2025/[14] Patch Tuesday – October 2025 – Rapid7 https://www.rapid7.com/blog/post/em-patch-tuesday-october-2025/[15] A Decade-long Landscape of Advanced Persistent Threats – arXiv https://arxiv.org/html/2509.07457v1[16] Two New Windows Zero-Days Exploited in the Wild — One Affects Every Version Ever Shipped https://thehackernews.com/2025/10/two-new-windows-zero-days-exploited-in.html[17] Microsoft revokes 200+ certificates abused by Vanilla Tempest in … https://securityaffairs.com/183532/cyber-crime/microsoft-revokes-200-certificates-abused-by-vanilla-tempest-in-fake-teams-campaign.html[18] Russia-linked Secret Blizzard targets foreign embassies in Moscow … https://securityaffairs.com/180638/apt/russia-linked-apt-secret-blizzard-targets-foreign-embassies-in-moscow-with-apolloshadow-malware.html[19] H-ISAC TLP White: Daily Cyber Headlines – October 17, 2025 | AHA https://www.aha.org/h-isac-white-reports/2025-10-17-h-isac-tlp-white-daily-cyber-headlines-october-17-2025[20] Chinese APT hacker group Mustang Panda uses MQsTTang … https://industrialcyber.co/ransomware/chinese-apt-hacker-group-mustang-panda-uses-mqsttang-backdoor-to-target-european-entities/

DjimIT Nieuwsbrief

AI updates, praktijkcases en tool reviews — tweewekelijks, direct in uw inbox.