ESET uncovered CVE-2025-8088, a path traversal zero-day in WinRAR actively exploited by the Russia‑aligned RomCom group and others via weaponized “job application” archives. Targets included financial, manufacturing, defense, and logistics firms in Europe and Canada. Users of WinRAR, its Windows CLI tools, and UnRAR components should update immediately to the latest release.
Source: ESET Blog
Citrix NetScaler flaw (CVE-2025-6543) abused to breach critical Dutch organizations
The Netherlands’ NCSC warned that threat actors are exploiting a critical NetScaler ADC vulnerability to compromise multiple “critical organizations.” The advisory urges rapid patching, compromise checks, and hardening of external ADCs, as active exploitation is confirmed in the wild.
Source: BleepingComputer
‘Win‑DDoS’: Public Windows domain controllers can be weaponized
SafeBreach detailed multiple flaws, including CVE-2025-32724, that allow attackers to crash Active Directory domain controllers and coerce exposed DCs into participating in DDoS attacks by redirecting them to attacker‑controlled LDAP servers. Organizations with internet‑facing DCs should patch immediately and restrict LDAP/LDAPS egress to untrusted hosts.
Source: Help Net Security
OT networks targeted via Erlang/OTP SSH auth bypass (CVE-2025-32433)
A critical, now‑patched Erlang/OTP vulnerability (CVSS 10.0) has been actively exploited since early May, with roughly 70% of detections observed on firewalls protecting operational technology environments. The flaw enables unauthenticated access via OTP SSH; defenders should patch promptly and review OT perimeter logs for anomalous SSH activity.
Source: SecurityWeek
ICE disrupts BlackSuit ransomware infrastructure
US Homeland Security Investigations (ICE) announced a takedown of BlackSuit ransomware infrastructure, a win that could blunt near‑term operations by a group linked to significant extortion activity. Experts caution that durable impact requires arrests and continued pressure, as ransomware crews often rebrand and retool.
Source: SC Media
Car dealer portal bug exposed personal data and allowed remote vehicle unlock
A researcher found a major automaker’s dealership portal flaw that exposed customer information and could let anyone remotely unlock cars. The issue underscores the growing risk at the intersection of cloud portals and connected vehicles, and the need for strict auth, segmentation, and least‑privilege access.
Source: Malwarebytes
BadCam: Linux webcams abused as persistent BadUSB threats
Eclypsium researchers demonstrated “BadCam,” turning certain Linux‑based webcams (shown on Lenovo models, with others potentially affected) into persistent, host‑level threats via BadUSB techniques. Because the compromise lives on the device, it can survive OS reinstalls, emphasizing the importance of device provenance, firmware updates, and USB trust controls.
Source: SecurityWeek
You May Also Be Interested In...
EntraGoat: Vulnerable Microsoft Entra ID to simulate identity misconfigurations
New ‘Charon’ ransomware borrows APT tradecraft to target enterprises
Rusty Pearl: Remote Code Execution paths in PostgreSQL via PL/Perl and PL/Rust