A critical pair of zero-day vulnerabilities (CVE-2025-53770 & CVE-2025-53771) in Microsoft SharePoint Server are being actively exploited in the wild, allowing unauthenticated remote code execution and widespread breaches across government, academic, and corporate networks. Emergency security updates have been rushed out, but researchers warn hundreds of on-premises SharePoint servers remain exposed—many of which underpin core business operations and sensitive data. All organizations running on-prem SharePoint deployments are urged to patch immediately, rotate cryptographic keys, and monitor for signs of compromise. Attackers are deploying backdoors for long-term access even after patching.
Source: SecurityWeek
CrushFTP Zero-Day (CVE-2025-54309) Actively Exploited—Thousands of Enterprise File Servers at Risk
A newly discovered vulnerability in CrushFTP (CVE-2025-54309) is under active exploitation, granting attackers administrator access to vulnerable file transfer servers. At least 1,000 publicly exposed, unpatched instances are at risk, with data theft being the most likely malicious outcome. Administrators are strongly advised to patch immediately, verify system integrity, and monitor for suspicious logins or file transfers.
Source: Help Net Security
HPE Aruba Instant On Wi-Fi Devices Exposed by Critical Hardcoded Credentials Flaw (CVE-2025-37103)
HPE has disclosed a critical vulnerability affecting Aruba Instant On access points, caused by hardcoded administrative passwords (CVE-2025-37103, CVSS 9.8). Attackers can bypass authentication and take over device management interfaces, posing a risk for remote compromise and lateral movement. All organizations using impacted models with firmware v3.2.0.1 or lower must upgrade and check for unauthorized device changes.
Source: Security Affairs
Major JavaScript Supply Chain Attack: Fake npm Website and Phishing Result in Malware in Widely Used Packages
Attackers set up a phishing website mimicking npm’s login page to steal a maintainer’s token, enabling the insertion of malware into popular JavaScript libraries (such as eslint-config-prettier). The incident highlights persistent challenges with identity security in open-source ecosystems and the critical need for maintainers to use strong authentication and monitor package provenance.
Source: Google Online Security Blog
UK Retreats on Encryption Backdoor Plans for Apple Services Amid International Pressure
UK officials are reportedly backing off plans to force Apple to implement encryption backdoors, concerned about jeopardizing tech and trade relations with the US. This shift follows intense lobbying from the tech industry and represents a significant development in global encryption policy and privacy rights debates.
Source: Financial Times
Iran-Linked MuddyWater APT Deploys Updated DCHSpy Android Spyware in Regional Espionage Surge
New versions of the DCHSpy Android surveillance tool, attributed to Iran’s MuddyWater group, have been observed since the latest Israel-Iran conflict began. The spyware steals WhatsApp data, records audio/video, exfiltrates device files, and impersonates VPN and Starlink apps, highlighting rising mobile and regional APT threats.
Source: The Hacker News
Indian Crypto Exchange CoinDCX Loses $44 Million in Sophisticated Attack
Indian cryptocurrency exchange CoinDCX confirmed it lost $44 million in digital assets due to a major hack, though customer funds were reportedly untouched. The attack appears linked to server compromise and highlights continuing risks for crypto platforms managing large pools of reserve funds.
Source: RecordedFuture
You May Also Be Interested In...