Fortinet disclosed CVE-2025-25256, a critical OS command injection flaw (CVSS 9.8) in FortiSIEM that allows unauthenticated remote code execution. The company says practical exploit code is already circulating, urging immediate upgrades and lockdown of management interfaces. The alert lands amid a wider spike in hostile activity against Fortinet gear, raising the risk for SOC visibility and response.
Source: The Hacker News
Microsoft patches “BadSuccessor” Kerberos bug affecting Windows Server 2025
Microsoft fixed CVE-2025-53779 (“BadSuccessor”), a relative path traversal flaw in Windows Kerberos that could let an authorized attacker elevate privileges over the network via delegated Managed Service Accounts (dMSA). Domain controllers and Server 2025 deployments should be prioritized for patching as part of August’s broad update cycle.
Source: Help Net Security
Matrix messaging protocol issues “high-severity” fixes that break compatibility
The Matrix Foundation released urgent patches for two high-severity protocol vulnerabilities that require breaking changes to servers and clients. Federated deployments face the highest risk, and operators are advised to coordinate upgrades to avoid federation disruption and exposure.
Source: Recorded Future News (The Record)
New HTTP/2 “MadeYouReset” attack turns servers against themselves
Researchers detailed a new denial-of-service technique that abuses HTTP/2’s stream reset behavior, echoing 2023’s Rapid Reset but with fresh twists that can overwhelm large services. Operators should apply vendor mitigations, tune rate limits, and monitor anomalous reset patterns to blunt the impact.
Source: Imperva
Leaked CFE logs could risk power outages across Mexico
Mexico’s Comisión Federal de Electricidad exposed 600GB of sensitive logs for more than three years, potentially revealing information that could help attackers disrupt operations. Researchers warn the leak could enable attacks capable of blacking out up to 99% of the country if exploited.
Source: CyberNews
CISA adds N‑able N‑central zero-days to KEV amid active exploitation
CISA added two N‑able N‑central vulnerabilities to its Known Exploited Vulnerabilities catalog, citing evidence of in-the-wild attacks against the MSP-grade RMM platform. Managed service providers should patch immediately, audit access, and rotate credentials and tokens that could be abused for lateral movement.
Source: The Hacker News
Researchers demonstrate passkey bypass via WebAuthn manipulation
Security researchers showed how an attacker can impersonate users by manipulating parts of the WebAuthn flow, effectively bypassing passkey protection in certain conditions. The findings underscore the need for hardened browser and IdP flows, strict origin and RP ID validation, and phishing-resistant configurations.
Source: SecurityWeek
You May Also Be Interested In...
New ‘Charon’ ransomware targets Middle East with APT-style tradecraft
Spike in Fortinet SSL VPN brute-force attacks raises zero-day concerns
Hackers leak 2.8M Allianz Life records in Salesforce data breach