A newly discovered zero-day vulnerability (CVE-2025-53770) in Microsoft SharePoint Server has been weaponized in a large-scale attack, with incidents confirmed at dozens of organizations worldwide. Until just hours ago, no patch was available; Microsoft has now begun rolling out emergency security updates, but defenders are urged to hunt for signs of compromise immediately due to widespread exploitation and the possibility of security key theft.
Source: Bleeping Computer
CrushFTP Zero-Day Enables Full Administrative Server Takeover
Active exploitation of a critical zero-day in CrushFTP (CVE-2025-54309) is granting attackers administrator access via HTTPS, affecting both version 10 and early version 11 servers not using the DMZ proxy feature. Organizations using vulnerable CrushFTP deployments are strongly advised to apply patches immediately and review for suspicious activity, as attackers are bypassing normal authentication controls to seize remote control.
Source: The Hacker News
HPE Aruba Access Points Threatened by Hardcoded Password Vulnerability
Hewlett-Packard Enterprise has disclosed a critical vulnerability (CVE-2025-37103) in Aruba Instant On access points due to hardcoded admin credentials, enabling attackers to bypass authentication and remotely gain administrative access. The flaw, with a CVSS score of 9.8, underscores the urgent need for users to upgrade firmware and re-examine access controls on their affected network devices.
Source: Bleeping Computer
3,500 Websites Hijacked in Return of Browser-Based Crypto Mining Attacks
Researchers warn that over 3,500 websites have been secretly compromised to mine cryptocurrency via JavaScript and WebSocket-based cryptojacking scripts, representing a resurgence of browser mining threats once thought contained. The attack campaign hijacks visitor computing resources and may be challenging to detect, urging site operators to regularly monitor for unauthorized code changes and review client-side activity.
Source: The Hacker News
PoisonSeed Hackers Bypass FIDO Authentication with Cross-Device Phishing Tricks
A novel threat actor, PoisonSeed, is circumventing FIDO key protections by luring users into approving malicious logins using sophisticated QR phishing and abuse of cross-device sign-in features. This campaign demonstrates the evolving risk of social engineering to defeat even hardware-backed authentication, highlighting the importance of user vigilance alongside technical controls.
Source: The Hacker News
Chinese GenAI Use in Western Workplaces Poses Data Leakage Risk
Nearly 8% of U.S. and U.K. employees have accessed Chinese-developed generative AI tools at work, exposing sensitive corporate data in the process, according to new research. The unsanctioned use of such platforms raises the threat of data exfiltration and underscores the urgent need for policy, monitoring, and user education regarding third-party AI technologies in the business environment.
Source: Help Net Security
Surveillance Firm Bypasses SS7 Defenses to Track Mobile User Locations
A surveillance company has been found using an SS7 bypass technique, tricking wireless carriers into disclosing the real-time locations of mobile users despite existing network protections. While SS7 attacks have been a known risk for years, this incident highlights the effectiveness—and continued exploitation—of legacy telecom protocol vulnerabilities for location tracking and espionage.
Source: SecurityWeek
You May Also Be Interested In...