Cisco fixed CVE-2025-20265, a maximum-severity remote code execution flaw in Secure Firewall Management Center (FMC) that could let attackers run commands as admin and pivot across networks. Because FMC orchestrates policy for fleets of firewalls, compromise can quickly translate into widespread control and lateral movement. Admins should upgrade immediately, restrict FMC exposure, and monitor for anomalous admin actions.
Source: SC Media
Ransomware operators hide “PipeMagic” backdoor inside fake ChatGPT desktop app
Microsoft detailed PipeMagic, a modular backdoor masquerading as a legitimate ChatGPT desktop application and used by Storm-2460 to stage ransomware. The framework has evolved alongside exploitation of Windows CLFS (CVE-2025-29824), enabling stealthy persistence, data theft, and hands-on-keyboard operations. Block untrusted “ChatGPT” binaries, enforce code-signing checks, patch CLFS, and harden PowerShell/LOLBins to reduce blast radius.
Source: Microsoft Security Blog
Workday breach underscores growing SaaS identity and CRM supply-chain risk
Workday disclosed a data breach after a social engineering attack on a third-party CRM platform, with evidence it’s linked to a wider campaign targeting Salesforce environments. While core systems weren’t impacted, customer contact data and integrations may be. Enterprises should review OAuth tokens, API logs, and app-to-app trust, enable phishing-resistant MFA, and implement least-privilege across SaaS tenants.
Source: SecurityWeek
Allianz Life data theft hits 1.1 million people in Salesforce-related intrusion
Have I Been Pwned identified 1.1 million unique records exposed in Allianz Life’s July breach, part of a wave of Salesforce data theft incidents. Stolen data reportedly includes personal information; victims should expect targeted phishing and account takeover attempts. Organizations should rotate CRM credentials and tokens, tighten API access policies, and audit third-party app permissions.
Source: SecurityWeek
UK retreats from Apple encryption backdoor demand after US pressure
Britain has dropped plans that would have effectively forced Apple to weaken end-to-end encryption, following opposition from Washington and industry. The reversal eases immediate fears of mandated client-side scanning or key escrow, though broader crypto-policy battles continue. Security leaders should track knock-on effects for lawful access debates and cross-border data compliance.
Source: The Verge
Public exploit chains two critical SAP NetWeaver flaws for code execution
Researchers released a new exploit that combines two critical SAP NetWeaver vulnerabilities, exposing unpatched systems to remote code execution. Given NetWeaver’s role in ERP and business-critical workflows, successful exploitation can yield high-impact data access and operational disruption. Urgently apply SAP patches, restrict external exposure, and monitor for anomalous ABAP/J2EE activity.
Source: SecurityWeek
New “Sni5Gect” attack sniffs 5G traffic without a rogue base station
Academics disclosed Sni5Gect, a technique that exploits a timing gap in the device–network handshake to sniff traffic and potentially disrupt 5G sessions without deploying a fake base station. The research highlights protocol-level weaknesses that could affect mobile carriers and critical IoT deployments. Operators and vendors should assess mitigations, apply baseband/network patches as available, and tighten anomaly detection at the RAN core.
Source: SecurityWeek
You May Also Be Interested In...
Over 800 N-able servers left unpatched against critical exploited flaws
Git 2.51: Preparing for the future with SHA-256
PyPI blocks 1,800 expired-domain emails to prevent maintainer ATOs