Two critical unauthenticated command injection vulnerabilities (CVE-2025-54948, CVE-2025-54987) in Trend Micro’s Apex One endpoint security platform are being actively probed by attackers. A patch is promised by mid-August, but organizations running on-premises Apex One should immediately deploy the vendor’s interim “fix tool” to mitigate exploitation risk, as these zero-days offer remote code execution and have a CVSS score of 9.4.
Source: Help Net Security
Google Confirms Data Breach Following Supply Chain Attack on Salesforce Instance
Google acknowledged that customer data was stolen after hackers—linked to the ShinyHunters group—successfully breached one of its corporate Salesforce databases. The breach is part of a wider campaign targeting cloud-based CRM systems at several major organizations, raising alarms about third-party risk and supply chain exposures in critical business data platforms.
Source: Security Week
Critical Dell Firmware Flaws Enable Login Bypass and Implants on Over 100 Models
Researchers detailed “ReVault” vulnerabilities (CVE-2025-24311, CVE-2025-25215, CVE-2025-24922, CVE-2025-25050, CVE-2025-24919) in Dell’s ControlVault3 firmware affecting more than 100 laptop models. With physical access, attackers can plant persistent firmware malware or bypass Windows logins—highlighting ongoing risks with device firmware and the need for vigilant patch management at the hardware level.
Source: Security Week
WhatsApp Shuts Down 6.8M Scam Accounts; New Security Features Announced
WhatsApp has removed 6.8 million accounts tied to global scam centers—primarily in Cambodia—via a joint crackdown with Meta and OpenAI. At the same time, WhatsApp is rolling out a new anti-scam alert to warn users when they’re added to group chats by unknown numbers, as social engineering and fraud campaigns surge.
Source: Security Week
Critical Adobe Experience Manager Forms Flaws Patched—Exploit Code Already Public
Adobe released emergency patches for two critical vulnerabilities (CVE-2025-54253, CVE-2025-54254) in its Experience Manager Forms product, following the disclosure of public proof-of-concept exploits. With attackers likely to attempt exploitation, organizations running AEM Forms on Java Enterprise Edition (JEE) are urged to prioritize patching due to the high risk of remote code execution.
Source: Security Week
Microsoft Exchange Hybrid Exploit Draws Emergency CISA Directive
A high-severity vulnerability in Microsoft Exchange’s hybrid deployments was disclosed, enabling privilege escalation from on-premises servers to Exchange Online with no trace left behind. CISA is preparing an emergency directive in response, with federal and enterprise users advised to act quickly as attackers could exploit this to compromise cloud-based email environments.
Source: NextGov Cyber
Major U.S. Ransomware Hack Exposes Personal Data of Nearly 1 Million DaVita Patients
U.S. dialysis provider DaVita suffered a ransomware attack in April, leading to the breach of sensitive information belonging to 915,952 individuals. The attack, attributed to the Interlock ransomware group, resulted in 1.51 TB of data being stolen—underscoring persistent healthcare sector vulnerabilities and operational impacts of large-scale ransomware.
Source: Security Week
You May Also Be Interested In...