Microsoft addressed a wormable remote code execution (RCE) bug in Windows (CVE-2025-47981) as part of July’s Patch Tuesday, among 130 vulnerabilities patched. Meanwhile, exploitation has been reported for CitrixBleed 2 (CVE-2025-5777), with proof-of-concept (PoC) exploits now public—raising the urgency for organizations to check for signs of exploitation, even on recently patched systems.
Source: Help Net Security
Active Attacks Exploit Critical Wing FTP and Fortinet FortiWeb Flaws—Immediate Patching Advised
Attackers are actively exploiting a critical vulnerability (CVE-2025-47812) in Wing FTP Server, enabling remote code execution (RCE) with root or system privileges shortly after technical details were made public. In a parallel threat, public PoC code for a severe SQL injection flaw in Fortinet FortiWeb (CVE-2025-25257, CVSS 9.8) allows unauthenticated RCE; Fortinet strongly urges users to patch without delay.
Source: Security Affairs, Security Affairs
Ransomware Incidents Dip, But Overall Malware and Zero-Day Threats Hit Record Highs in Q1 2025
Despite a modest decrease in ransomware encounters, the latest WatchGuard Internet Security Report underscores a 171% surge in unique malware detections—the most recorded by their Threat Lab. The research also notes a steep rise in zero-day malware, signaling adversaries’ growing capacity to evade conventional defenses.
Source: Help Net Security
Google Gemini Feature Abused to Deliver Convincing Phishing Messages
Attackers have found a way to exploit Google Gemini for Workspace, leveraging its AI-generated email summaries to present users with seemingly legitimate content that includes embedded malicious instructions or phishing attempts—without the need for attachments or obvious links. This inventive tactic complicates detection and raises the stakes for organizations relying on AI-powered productivity solutions.
Source: Bleeping Computer
Gravity Forms WordPress Plugin Targeted in Supply Chain Malware Attack
Two available versions of the popular Gravity Forms plugin for WordPress were found to have been backdoored with malware via a supply chain attack. Organizations leveraging Gravity Forms are urged to check their installations and update immediately to protect against potential compromise and data theft.
Source: SecurityWeek
eSIM Vulnerability in Kigen Cards Puts Billions of IoT Devices at Risk
Researchers at Security Explorations disclosed a significant vulnerability in Kigen's eUICC eSIM cards, a technology underpinning more than two billion IoT devices. The flaw could allow malicious actors to compromise affected devices, with broad implications for IoT security across the globe.
Source: TheHackerNews
Legal and Security Gaps in AI Governance Pose Major Risks to Enterprises
A new report highlights the business risks for companies deploying artificial intelligence tools without robust governance frameworks, with only 23% of surveyed organizations feeling adequately prepared. Data privacy, model bias, and—most critically—lack of customer trust surface as top concerns as AI adoption accelerates across industries.
Source: Help Net Security
You May Also Be Interested In... Free VPN malware on GitHub was stealing data
Securing Against Phishing Beyond Email
Google’s Gmail Warning—If You See This, You’re Being Hacked