Cisco has released urgent patches for two maximum-severity vulnerabilities in its Identity Services Engine (ISE) and ISE Passive Identity Connector (ISE-PIC). These flaws (CVE-2025-20281 and CVE-2025-20282) allow unauthenticated attackers to execute arbitrary code with root privileges, representing an immediate threat to enterprise networks. All users are strongly urged to update systems without delay.
Source: TheHackerNews
Active Exploitation of AMI MegaRAC Vulnerability Puts Thousands of Servers at Risk
A maximum-severity flaw in the AMI MegaRAC Baseboard Management Controller (BMC) firmware (CVE-2024-54085) is now being actively exploited, enabling attackers to hijack or brick servers from major vendors. CISA has added the bug to its Known Exploited Vulnerabilities catalog, urging immediate patching, as incomplete vendor updates and widespread usage in servers from AMD, ARM, Fujitsu, and others amplify the risk.
Source: ArsTechnica
CitrixBleed 2: New Zero-Day Vulnerability Being Actively Exploited
A newly disclosed vulnerability, dubbed CitrixBleed 2 (CVE-2025-5777), affects Citrix NetScaler ADC and Gateway products and is being exploited for initial access as a zero-day. Attackers can steal session cookies without authentication, echoing previous major Citrix vulnerabilities—prompting urgent vendor patches and calls for immediate remediation.
Source: SecurityWeek
BreachForums Crackdown: Major Arrests Disrupt Global Hacking Marketplace
Authorities in the U.S. and France have arrested several key cybercriminals tied to the infamous BreachForums underground market. Among those charged is "IntelBroker" (Kai West), who is accused of causing over $25 million in damages through a spree of corporate data breaches—portending increased law enforcement focus on cybercrime forums worldwide.
Source: TechCrunch
Supply Chain Threat: Critical Vulnerability in Open VSX Extension Registry
Researchers revealed a supply chain vulnerability in the Open VSX Registry that could have allowed attackers to take control of the Visual Studio Code extensions marketplace. Successful exploitation would grant attackers the ability to tamper with or distribute malicious extensions to millions of developers globally, posing severe risks to software supply chains.
Source: TheHackerNews
‘ClickFix’ Social Engineering Attacks Surge Over 500% in 2025
A wave of ClickFix social engineering attacks—where fake CAPTCHA prompts trick victims into executing malicious commands—has surged 517% in the first half of 2025, now ranking as the second most common attack vector after phishing. These campaigns are increasingly linked to infostealers, ransomware, and other dangerous payloads, highlighting the evolving landscape of user-targeted threats.
Source: HelpNetSecurity
Iranian APT42 Intensifies AI-Powered Phishing Against Israeli Tech Experts
Researchers have uncovered spear-phishing campaigns by Iran-linked APT42 (a.k.a. Charming Kitten, Educated Manticore), targeting Israeli journalists, cybersecurity professionals, and academics. The attackers, using AI-powered techniques, impersonate trusted contacts to steal login credentials and two-factor authentication codes, underscoring escalating sophistication in state-backed social engineering.
Source: The Record
You May Also Be Interested In... Microsoft 365 Direct Send Abused for Phishing
Android and iPhone SMS Attacks No Longer Need Your Phone Number
Citrix Bleed 2 Opens Old Wounds – ReliaQuest Blog