The U.S. Federal Judiciary disclosed a cyberattack on its electronic case management service, prompting urgent hardening of digital defenses. Officials fear sensitive filings may have been accessed, including documents that could expose confidential informants in ongoing criminal cases. Courts are tightening access controls and monitoring for misuse of stolen data.
Source: BleepingComputer
CISA orders rapid patching of critical Microsoft Exchange hybrid flaw (CVE-2025-53786)
Federal agencies were directed to remediate a high-severity Exchange Server vulnerability in hybrid environments by Monday morning due to the risk of privilege escalation into Microsoft 365. Organizations running on‑prem Exchange configured for hybrid should prioritize patching and review cloud identity and token hygiene for signs of abuse.
Source: SC Media
DARPA unveils AI models to auto-find and fix bugs in critical infrastructure code
Winners of the AI Cyber Challenge released open-source models designed to automatically identify and patch vulnerabilities in software that underpins utilities such as power and water systems. The next phase will test these tools in the real world, aiming to compress time-to-patch and reduce exposure windows across critical infrastructure.
Source: CyberScoop
WinRAR zero-day exploited in phishing to deploy RomCom malware
Threat actors abused a directory traversal flaw in WinRAR (CVE-2025-8088) as a zero-day to install RomCom via malicious email campaigns. Users should immediately update to WinRAR 7.13 or later and treat compressed attachments from untrusted sources as high risk.
Source: BleepingComputer
Compromised credentials surge 160% in 2025, driving account takeover risk
Check Point reports a 160% year-over-year spike in leaked employee credentials, underscoring how password reuse and data broker markets are fueling intrusions. Organizations should accelerate rollout of phishing-resistant MFA, continuous credential exposure monitoring, and rapid credential revocation workflows.
Source: Check Point Blog
Bouygues Telecom data breach impacts 6.4 million customers
The French telecom firm disclosed a cyberattack that exposed personal information tied to millions of mobile and broadband subscriptions. Operators and large consumer brands should revisit supplier access, data minimization, and breach response playbooks to limit downstream fraud and credential stuffing.
Source: SecurityWeek
North Korea’s ScarCruft espionage group adds ransomware to its playbook
Researchers observed ScarCruft deploying a “newly observed” ransomware tool alongside spying operations against South Korean targets. The blending of espionage and financial extortion increases operational risk and complicates attribution and response, particularly for entities with regional exposure.
Source: Recorded Future News (The Record)
You May Also Be Interested In...
EU law to protect journalists from spyware takes effect
Embargo ransomware gang has handled at least $34 million in about a year
15,000 Jenkins servers at risk from RCE vulnerability (CVE-2025-53652)