Cisco has patched a maximum-severity vulnerability (CVE-2025-20309) in its Unified Communications Manager (Unified CM) platforms, caused by hardcoded root credentials. The flaw allows unauthenticated remote attackers to gain root access and execute arbitrary commands, posing a severe risk to enterprise communications systems. Organizations should apply the patches immediately, as exploitation is straightforward and could result in full system compromise.
Source: Help Net Security
Chinese "Houken" APT Exploits Multiple Ivanti Zero-Days to Breach French Organizations
France's cyber agency ANSSI has revealed that a China-linked advanced persistent threat (APT) group, dubbed Houken, used several Ivanti Cloud Services Appliance (CSA) zero-day vulnerabilities to infiltrate French government, telecom, media, finance, and transport sectors. The campaign, actively targeting these critical sectors since September 2024, highlights the urgent need for patch management and monitoring in organizations using affected Ivanti products.
Source: Security Affairs
Hunters International Ransomware Group Shuts Down, Issues Free Decryptors
The prolific Hunters International ransomware gang announced its shutdown, offering decryption keys to all its victims as a parting gesture. While this may provide relief to recent breach victims, security researchers caution this may just be a rebranding tactic often seen among ransomware operators, who are likely to return under a new name or affiliate with another group.
Source: Bleeping Computer
Over 40 Malicious Firefox Extensions Steal Cryptocurrency Wallets
Researchers have identified over 40 trojanized Firefox browser extensions targeting cryptocurrency wallets. These malicious extensions, often disguised as legitimate wallet tools, exfiltrate wallet keys and seed phrases, allowing attackers to drain digital assets from unsuspecting users. The campaign underscores the ongoing risk posed by malicious third-party browser add-ons, especially as the number of browser-based crypto users continues to expand.
Source: The Hacker News
Amazon Prime Day Sparks Surge in Phishing: 87% of "Amazon"-Related Domains Are Malicious
Ahead of Amazon Prime Day 2025, researchers observed over 1,000 new domains mimicking Amazon, with 87% flagged as malicious or suspicious. Cybercriminals are leveraging Prime Day hype to deploy phishing attacks, create fake checkout pages, and steal customer payment details. Both consumers and organizations should remain vigilant against targeted scams during high-profile shopping events.
Source: Checkpoint Blog
CatWatchful "Stalkerware" Leak Exposes 62,000 User Credentials—and Victim Data
A vulnerability in the CatWatchful child monitoring/stalkerware app led to a massive data exposure, leaking logins and plaintext passwords for more than 62,000 users, alongside victim information. The breach adds to growing concerns over stalkerware tools’ inability to secure highly sensitive personal data and highlights the ethical and security risks these apps pose.
Source: ArsTechnica
Massive Android Ad Fraud and Spyware Operations Uncovered
A global mobile ad fraud operation comprising 352 Android apps, dubbed IconAds, was disrupted after being found to deliver out-of-context ads and evade user detection. In parallel, nearly 100,000 Android devices were compromised in a widespread malware campaign ("Qwizzserial") delivered through Telegram channels masquerading as financial aid outlets, emphasizing the persistent risk from mobile malware and fraud on Android platforms.
Source: The Hacker News
You May Also Be Interested In...