Researchers disclosed a design issue across multiple HTTP/2 implementations that lets attackers bypass the usual 100-request-per-connection cap, enabling high-impact denial-of-service attacks reminiscent of 2023’s Rapid Reset. Hundreds of vendors were notified; some major providers say existing Rapid Reset mitigations help, but enterprises should still review edge protections, update stacks, and tighten rate-limiting and anomaly detection.
Source: SecurityWeek
Cisco fixes CVSS 10.0 RCE in Secure Firewall Management Center
Cisco patched a critical RADIUS subsystem flaw (CVE-2025-20265) in Secure Firewall Management Center that allows unauthenticated remote code execution. Admins should urgently update FMC and review RADIUS exposure, apply least-privilege on management planes, and monitor for abnormal authentication traffic; Cisco also shipped additional advisories for ASA and FTD in its August bundle.
Source: SecurityWeek
CISA: N‑able N‑central zero‑days exploited against MSPs
Two N‑central vulnerabilities (CVE-2025-8875, CVE-2025-8876) were added to CISA’s KEV catalog after in-the-wild exploitation was observed on patch day. Given RMM platforms’ central role, MSPs should patch immediately, rotate credentials and tokens, audit logs for post-exploitation activity, and assess downstream customer impact.
Source: SecurityWeek
Norway blames pro‑Russian hackers for dam takeover that opened floodgates
Norway’s security service says pro‑Russian actors breached a dam’s control systems in April, opening valves for hours and releasing large volumes of water before operators regained control. The incident underscores rising OT/ICS risk: segment control networks, lock down remote access, enforce MFA and strong passwords, and test incident response for physical-process scenarios.
Source: The Record
Researchers show passkey logins can be bypassed via WebAuthn flow manipulation
New research demonstrates that attackers can impersonate users by manipulating parts of the WebAuthn process, undermining passkey protections in certain scenarios. Organizations should ensure strict RP ID/origin checks, enforce phishing‑resistant MFA settings, and verify browser and IdP configurations to prevent downgrade or process‑tampering attacks.
Source: SecurityWeek
Chinese‑speaking APT ‘UAT‑7237’ targets Taiwanese web hosting infrastructure
Cisco Talos tracks UAT‑7237, active since at least 2022 with overlaps to UAT‑5918, focusing on compromising Taiwanese hosting providers as a springboard into tenant environments. Targeting shared infrastructure magnifies blast radius; hosting firms should harden management interfaces, audit cross‑tenant isolation, and instrument lateral‑movement detection.
Source: Cisco Talos
Malvertising campaign spreads PS1Bot framework to steal crypto and data
A widespread malvertising operation is pushing PS1Bot, a modular PowerShell‑based framework that steals credentials and crypto wallets, logs keystrokes, and captures screens. Defenders should clamp down on ad‑driven download flows, block PowerShell abuse via application control and constrained language mode, and monitor for suspicious script execution chains.
Source: HackRead
You May Also Be Interested In... - Canada’s House of Commons investigating data breach after cyberattack - For $40, you can buy stolen police and government email accounts - NIST concept paper outlines AI‑specific cybersecurity framework