Google confirmed that the OAuth token theft campaign tied to Salesloft’s Drift AI chat integration extended beyond Salesforce, enabling access to a small number of Google Workspace accounts as well. Organizations are urged to assume all tokens stored in or connected to Drift were compromised, revoke/rotate them, audit logs for abuse, and temporarily disable affected integrations until vendors complete remediation.
Source: SecurityWeek
WhatsApp issues emergency patches after zero-click spyware attacks on iOS and macOS
WhatsApp fixed CVE-2025-55177, a vulnerability exploited in targeted zero-day attacks that abused insufficient authorization in linked device sync messages—reportedly chained with a recent Apple flaw. Apple users should update WhatsApp on iOS and macOS immediately, review linked devices, and consider hardening high-risk targets with additional protections.
Source: The Hacker News
Actively exploited CVSS 10 FreePBX zero-day: patch now and lock down admin panels
Sangoma disclosed an actively exploited FreePBX zero-day (CVE-2025-57819, CVSS 10) impacting systems with an internet-exposed Administrator Control Panel. Apply the emergency fix, restrict the ACP to internal networks/VPN, and monitor for suspicious PowerShell or web shell activity linked to PBX hosts.
Source: The Hacker News
AWS disrupts APT29 watering‑hole abusing Microsoft device code to hijack accounts
Amazon’s threat intel team disrupted a Russia-linked APT29 campaign that used compromised sites to redirect victims to malicious infrastructure and trick them into approving attacker-controlled devices via Microsoft’s device code flow. Enterprises should review device code grant usage, enforce Conditional Access, and hunt for anomalous OAuth/device authorization events in sign-in logs.
Source: AWS Security Blog
Passwordstate patches authentication bypass granting Emergency Access admin — update immediately
Click Studios released Passwordstate 9.9 (Build 9972) to fix an authentication bypass that could grant access to an emergency admin account via a crafted URL, potentially affecting tens of thousands of orgs. Update right away, rotate sensitive credentials stored in Passwordstate, and review access logs for suspicious Emergency Access usage.
Source: The Register
Microsoft to enforce MFA for all Azure resource management in October
Starting in October, Microsoft will require multi-factor authentication for all Azure resource management actions to reduce unauthorized access. Admins should ensure accounts are enrolled in MFA, validate Conditional Access baselines, and test automation paths (e.g., service principals) to avoid disruption.
Source: BleepingComputer
Ransomware takedowns spawn wave of smaller crews and rebrands
Law enforcement actions are splintering the ransomware ecosystem, scattering affiliates and triggering a proliferation of smaller, fast-moving groups. Defenders should prioritize detecting shared TTPs and infrastructure reuse across “new” brands, rather than relying on operator-name threat models alone.
Source: The Record
You May Also Be Interested In...
TransUnion Data Breach Impacts 4.4 Million
Researchers Warn of Sitecore Exploit Chain Linking Cache Poisoning and Remote Code Execution
Almost all Americans likely compromised by Salt Typhoon, FBI official says