A coordinated global campaign is actively exploiting critical zero-day vulnerabilities (CVE-2025-53770 and CVE-2025-53771) in Microsoft SharePoint Server. Microsoft and multiple security firms have confirmed that Chinese state-backed threat groups (Linen Typhoon, Violet Typhoon, Storm-2603) have breached high-value targets—including Western governments and, reportedly, the US nuclear weapons agency—since at least July 7. Emergency patches are out, but the incident highlights ongoing risks even after patching, and CISA has mandated urgent remediation across federal agencies. Organizations running on-premises SharePoint must patch immediately, rotate keys, and review for persistence mechanisms.
Source: Bloomberg Cyber
Cisco ISE Flaws Actively Exploited—Root Access Threat Across Enterprises
Cisco warns that attackers are actively exploiting three recently patched critical vulnerabilities in its Identity Services Engine (ISE), allowing unauthenticated remote code execution with root privileges. Security teams should urgently update all ISE and ISE-PIC deployments, as threat actors began targeting these bugs in July, enabling potential lateral movement and credential theft across enterprise environments. Organizations are urged to check for signs of compromise and apply Cisco’s latest advisories without delay.
Source: Bleeping Computer
UK to Ban Ransomware Payments by Public Sector and Critical Infrastructure
The UK government is moving forward with a ban prohibiting public sector organizations and critical national infrastructure from paying ransoms to criminals, alongside mandatory reporting of all ransomware incidents. The proposed measures follow a surge of attacks targeting British institutions and are designed to disrupt the ransomware payment model that fuels cybercriminal operations. Industry experts widely support the proposal, noting that rapid notification requirements will support law enforcement and response efforts.
Source: The Register
Russian APTs Sanctioned and Outed for “Authentic Antics” Microsoft Cloud Espionage
The UK has sanctioned three Russian GRU units and 18 individuals linked to the sophisticated “AUTHENTIC ANTICS” malware campaign, which targeted Microsoft cloud email users using highly stealthy credential hijacking and data exfiltration techniques. The APT28 (Fancy Bear) group blended credential theft, silent email forwarding, and OAuth token abuse to compromise target organizations in Western nations. The widespread use of Microsoft authentication libraries and minimal forensic footprints make this threat especially challenging to detect.
Source: Cyble
Coyote Banking Trojan Abuses Windows Accessibility—First Known Use of UI Automation for Attacks
Researchers have identified a new variant of the Coyote banking trojan that weaponizes Microsoft’s UI Automation framework—a Windows accessibility feature—for the first time in the wild. This adaptation lets Coyote stealthily monitor for banking and cryptocurrency websites and exfiltrate credentials, raising the bar for malware evasion. The campaign targets financial and crypto platforms, and defenders are urged to review endpoint monitoring for unusual UI interaction patterns.
Source: HackRead
Lumma Infostealer Returns as Law Enforcement Disruptions Prove Temporary
The Lumma Stealer malware operation has re-emerged after suffering a major takedown in May that seized over 2,000 domains and infrastructure nodes. Despite this disruption effort by Microsoft and law enforcement, threat actors have resumed operations using new infrastructure, underscoring the persistent and resilient nature of infostealer ecosystems. Security teams should update threat intelligence feeds and monitor for Lumma-associated activity.
Source: SecurityWeek
CISA Flags SysAid Vulnerabilities for Active Exploitation
CISA has added two new SysAid IT support software vulnerabilities—CVE-2025-2775 and CVE-2025-2776—to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation in the wild. The flaws enable attackers to perform remote file access and server-side request forgery, posing serious risks for organizations using affected SysAid versions. Federal agencies and all enterprises are strongly advised to patch promptly to block ongoing attack campaigns.
Source: SecurityWeek
You May Also Be Interested In...