Microsoft and CISA have issued urgent warnings about a critical vulnerability (CVE-2025-53786) impacting on-premises Exchange servers in hybrid deployments with Exchange Online. If exploited, attackers with initial access to an on-prem Exchange server could escalate privileges in the connected cloud tenant, potentially without leaving obvious traces. All organizations are urged to patch immediately, with federal agencies under a Monday deadline to comply. This vulnerability presents a major risk to enterprises integrating on-prem and cloud email systems.
Source: Bleeping Computer
Google, Adidas, Others Breached in Sophisticated Salesforce Voice-Phishing Scam
Google, Adidas, Chanel, and several other major organizations have confirmed breaches of their Salesforce databases following a clever voice-phishing (vishing) campaign linked to the ShinyHunters group. Attackers tricked employees over the phone to approve malicious app connections, resulting in exposure of business and customer data. These incidents spotlight the growing effectiveness of social engineering techniques targeting business-critical SaaS platforms.
Source: Ars Technica
Bouygues Telecom Breach: 6.4 Million French Customers Exposed
Bouygues Telecom, France’s third-largest cellular provider, has suffered a massive data breach affecting over 6 million customer accounts. The incident, which follows a string of telecom attacks in France, occurred due to unauthorized access to a third-party platform, underscoring persistent supply chain risks for critical infrastructure providers.
Source: SecurityWeek
Akira Ransomware Exploits Old SonicWall VPN Flaw—Not Zero-Day
SonicWall has clarified that the ongoing surge in Akira ransomware incidents targeting its Gen 7 firewalls is due to the exploitation of CVE-2024-40766, an older vulnerability with available patches, and not a new zero-day. The attacks also highlight risks from poor password practices. SonicWall and security experts urge immediate updates and improved credential hygiene for all customers with SSL VPN enabled.
Source: Bleeping Computer
Massive Columbia University Breach Exposes Nearly 870,000 Students and Staff
Columbia University has disclosed a major data breach impacting approximately 870,000 individuals, including students, applicants, and employees. Attackers accessed sensitive personal, financial, and health data in the May breach, making this one of the largest higher education security incidents in recent years and raising urgent questions about data protections in academic institutions.
Source: SecurityWeek
150+ Malicious Firefox Extensions Used to Steal Over $1 Million in Crypto
A newly uncovered campaign dubbed “GreedyBear” saw more than 150 fake extensions—impersonating wallets like MetaMask and TronLink—uploaded to Firefox’s add-on store, draining over $1 million in victims’ cryptocurrency. Add-on marketplaces remain a significant vector for large-scale cryptocurrency theft as attackers refine their impersonation and distribution methods.
Source: TheHackerNews
Linux Kernel Sandbox Escape: Chrome Renderer Bug (CVE-2025-38236) Fixed
Google Project Zero has detailed a now-patched security flaw (CVE-2025-38236) in the Linux kernel arising from the MSG_OOB feature, which allowed attackers to escape the Chrome renderer sandbox. The bug, affecting Linux >=6.9 and exposed in Chrome’s sandbox, demonstrates ongoing risks from esoteric kernel features and the importance of rapid vendor patching and sandbox containment improvements.
Source: Google Project Zero
You May Also Be Interested In…
CISA Issues Urgent Microsoft CVE-2025-53786 Security WarningTop Ransomware Threat Actors of H1 2025
Malicious Go, npm Packages Deliver Cross-Platform Malware