Security researchers have discovered four vulnerabilities—collectively known as “PerfektBlue”—in the OpenSynergy BlueSDK Bluetooth stack, which is used in vehicles from Volkswagen, Mercedes-Benz, and Skoda. These flaws can be exploited via a simple pairing request to achieve remote code execution and compromise infotainment systems, raising the specter of widespread automobile hacking with potentially severe consequences for driver safety and privacy.
Source: Information Security Newspaper
CISA Orders Emergency Patch for ‘Citrix Bleed 2’ Vulnerability After Active Exploitation Discovered
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) issued an unprecedented 24-hour deadline to federal agencies to patch CVE-2025-5777 (“Citrix Bleed 2”) in Citrix NetScaler ADC and Gateway devices, following evidence of active exploitation. This memory leak flaw allows attackers to steal credentials and session tokens, posing an “unacceptable risk” to both government and private sector networks if left unaddressed.
Source: Bleeping Computer
Wing FTP Server Hit by Actively Exploited CVSS 10 Zero-Day (CVE-2025-47812): Immediate Patching Urged
A critical remote code execution flaw (CVE-2025-47812, CVSS 10.0) affecting Wing FTP Server is under active exploitation, with attackers leveraging the vulnerability mere hours after public disclosure. Exploitation grants root or system privileges, and given Wing FTP Server’s use by thousands of organizations, rapid patching is essential to prevent large-scale intrusions and data breaches.
Source: SecurityWeek
Supply Chain Attack Hits Popular WordPress Plugin Gravity Forms, Backdoors Distributed via Official Site
The developer of Gravity Forms, a widely-used WordPress plugin, suffered a compromise resulting in distribution of backdoored plugin files via manual downloads on the official website. This supply chain attack highlights the critical risks posed by compromised plugin providers, as attackers could leverage the backdoor to gain access to thousands of WordPress sites and their data.
Source: Bleeping Computer
Fake Visual Studio Code Plugin Steals $500,000 in Latest Extension Supply Chain Attack
A fraudulent Visual Studio Code extension for Solidity, distributed via the Open VSX registry in the Cursor developer tool, led to theft of more than $500,000 in cryptocurrency. This attack serves as a stark warning that extensions for developer tools are increasingly a massive supply chain risk, capable of silently compromising development environments and connected assets.
Source: SCMagazine
Fortinet FortiWeb Faces Active Exploitation After Critical Pre-Auth RCE Exploit Released (CVE-2025-25257)
Proof-of-concept exploit code has been released for CVE-2025-25257, a critical SQL injection vulnerability in Fortinet’s FortiWeb WAF that allows unauthenticated remote code execution. Organizations using affected FortiWeb instances must apply the urgently-released patch immediately, as attackers are actively targeting unpatched devices to gain footholds in enterprise networks.
Source: Bleeping Computer
Scattered Spider Ransomware Group Dismantled, Four Suspects Arrested in UK
Authorities in the UK have arrested four people alleged to be part of the notorious Scattered Spider cybercrime group, responsible for sophisticated ransomware and extortion attacks against major retailers like Marks & Spencer and Harrods, as well as victims in the insurance and aviation sectors. The disruption of this group signals growing international law enforcement cooperation targeting ransomware operators.
Source: Recorded Future
You May Also Be Interested In... Stealthy PHP Malware Uses ZIP Archive to Redirect WordPress Visitors
Hackers Could’ve Hijacked Systems Using Adobe Reader and ASUS Armoury Crate
McDonald’s Recruitment Platform Flaw Exposed 64 Million Job Applications