Google has urgently patched a fifth zero-day in Chrome this year (CVE-2025-6558), following reports of active exploitation. Simultaneously, security experts warn that a critical Fortinet FortiWeb SQL injection flaw (CVE-2025-25257, CVSS 9.6) is being weaponized just hours after PoC code was published, leading to dozens of compromises. Organizations using FortiWeb are advised to prioritize immediate patching to prevent breach. This uptick in high-profile vulnerabilities signals an aggressive threat landscape targeting widely deployed platforms.
Source: Help Net Security
Microsoft SharePoint Zero-Day Breached 75+ Global Organizations
A newly discovered zero-day vulnerability (CVE-2025-53770, CVSS 9.8) in Microsoft SharePoint Server is being actively exploited in a large-scale campaign, resulting in at least 75 global organizations suffering breaches. The flaw, related to a spoofing bug, remains unpatched at the time of reporting, underscoring the urgent need for mitigation and increased vigilance. This incident highlights the continued focus of attackers on critical enterprise collaboration tools.
Source: The Hacker News
Popular npm Packages Hijacked: Supply Chain Attack Drops Malware
Threat actors executed a sophisticated supply chain attack by phishing npm maintainers and stealing tokens, using the credentials to inject malware into popular JavaScript linter packages such as eslint-config-prettier and eslint-plugin-prettier. These malicious versions were directly published to the npm registry, bypassing standard code review processes. The incident underscores persistent risks in the open-source ecosystem and the importance of credential security for package maintainers.
Source: Bleeping Computer
China’s Salt Typhoon Hackers Breached US National Guard for Nearly a Year
Salt Typhoon, a Chinese state-sponsored hacking group, infiltrated systems belonging to the US National Guard and maintained clandestine access for almost a year. The breach, which remained undetected for an extended period, highlights the sophistication and persistence of state-backed cyber-espionage operations targeting sensitive government infrastructure.
Source: Wired
Two Major Healthcare Data Breaches Impact Over 3 Million Patients
Anne Arundel Dermatology and Radiology Associates of Richmond have each disclosed significant data breaches, impacting approximately 1.9 million and 1.4 million individuals, respectively. Sensitive personal and health information was exposed in both incidents, raising concerns about medical sector resilience against cyberattacks and the ongoing threats to patient privacy nationwide.
Source: CISO2CISO, Security Affairs
Global Cyberattack Volume Surges 143% in Europe and North America
Research shows a dramatic 143% rise in cyberattacks over the past four years, with North America and Europe experiencing the sharpest increases. Geopolitical tensions and strategic targeting by threat actors have driven the wave, calling for intensified defensive postures in both public and private sectors.
Source: CyberNews
Malware Injected Into 6 npm Packages After Maintainer Tokens Stolen
Researchers are warning about a wave of malware uploads targeting six npm packages, made possible after attackers phished for and captured the maintainers’ tokens. The packages were updated with malicious code directly, illustrating risks in token-based distribution systems and the increasing focus of attackers on the software supply chain.
Source: The Hacker News
You May Also Be Interested In...