At least two groups—RomCom and Paper Werewolf—have been exploiting a newly disclosed WinRAR vulnerability in zero-day attacks. Paper Werewolf targeted Russian organizations, and campaigns rely on malicious archives to deliver payloads. Security teams should push WinRAR updates, tighten email/drive-by download controls, and hunt for suspicious archive extraction behavior tied to recent spear-phishing.
Source: Help Net Security
Workday discloses data breach after social engineering of third‑party CRM
HR giant Workday says attackers accessed a third-party CRM platform via social engineering, in an incident surfacing amid wider attacks on Salesforce-connected ecosystems. The breach underscores third‑party risk in CRM integrations—organizations should review access tokens, rotate credentials, and enforce phishing-resistant MFA and least-privilege on linked platforms.
Source: BleepingComputer
Cisco Secure Firewall Management Center: critical unauthenticated RCE via RADIUS (CVE-2025-20265)
Cisco warned of a critical flaw in FMC’s RADIUS subsystem that allows an unauthenticated, remote attacker to inject arbitrary shell commands executed by the device. Admins should upgrade per Cisco guidance immediately, restrict management-plane exposure, and monitor for anomalous RADIUS activity and unexpected command execution on FMC hosts.
Source: CISO2CISO
Chinese APT targets Taiwanese web hosting providers to reach high-value entities
Researchers report APT UAT‑7237 has been compromising Taiwanese web infrastructure to maintain long-term access into downstream, high‑value targets. The campaign highlights the strategic value of hosting and MSP supply chains; providers and customers should harden management interfaces, increase lateral movement detection, and validate integrity of hosted assets.
Source: SecurityWeek
PipeMagic backdoor evolves, leveraging CVE-2025-29824 in 2025 campaigns
Kaspersky traces the PipeMagic backdoor from its ties to the 2022 RansomExx incident through recent attacks in Brazil and Saudi Arabia, culminating in exploitation of CVE‑2025‑29824 this year. The operators’ TTPs show maturing persistence and lateral movement; defenders should map exposures tied to the CVE and tune detections for PipeMagic’s inter‑process communication and persistence artifacts.
Source: Securelist
Rockwell Automation patches critical flaws across FactoryTalk, Micro800, and ControlLogix
Rockwell released fixes for multiple critical and high‑severity issues, including CVE‑2025‑7972 in FactoryTalk Linx Network Browser, with additional impacts to Micro800 and ControlLogix products. OT operators should expedite patching cycles where possible, segment affected devices from enterprise networks, and monitor for exploitation attempts against industrial protocols and management services.
Source: CISO2CISO
ERMAC 3.0 Android banking trojan source code leaks, widening mobile fraud risk
Researchers obtained the full ERMAC 3.0 source code, showing its lineage from Cerberus and Hook and support for targeting 700+ banking, shopping, and crypto apps. While analysts spotted exploitable weaknesses, the leak lowers barriers for copycats and rapid variant development; enterprises should strengthen mobile app hardening and monitor for overlay and accessibility abuse.
Source: Security Affairs
You May Also Be Interested In...
U.S. seizes $2.8 million in crypto from Zeppelin ransomware operator
Xerox patches path traversal and XXE leading to unauth RCE in FreeFlow Core
The Week in Vulnerabilities: Patch Tuesday yields hundreds of vendor fixes