Cloudflare said it was impacted by the Salesloft Drift supply chain incident, with attackers accessing 104 Cloudflare API tokens that have since been rotated. The Drift exploitation campaign has hit numerous Salesforce instances by abusing OAuth tokens and third‑party integrations, underscoring the need to inventory and restrict SaaS-to-SaaS access and monitor CRM app tokens.
Source: Help Net Security
Android patches two exploited flaws amid massive monthly update
Google fixed 120 Android vulnerabilities this month, including two exploited elevation-of-privilege bugs in Android Runtime (CVE-2025-48543) and the Linux kernel (CVE-2025-38352). Enterprises should fast‑track OTA updates and plan mitigations for devices stuck on older builds due to OEM fragmentation.
Source: SecurityWeek
Sitecore zero‑day: ViewState deserialization RCE traced to old sample keys
Attackers are exploiting CVE-2025-53690 to achieve RCE on Sitecore deployments by leveraging sample machine keys published in older deployment guides. Google/Mandiant observed post‑exploitation tool staging (EARTHWORM tunneling, DWAgent, SharpHound) and advise immediate key rotation, enabling ViewState MAC, and following Sitecore remediation guidance.
Source: SecurityWeek
Cloudflare mitigates record 11.5 Tbps DDoS as hyper‑volumetric attacks surge
Cloudflare neutralized the largest recorded volumetric DDoS attack, peaking at 11.5 Tbps in a short burst, part of a broader wave of “hyper‑volumetric” events in recent weeks. The incident highlights attackers’ growing capacity to briefly overwhelm targets and the importance of auto‑mitigation and anycast architectures.
Source: BleepingComputer
Mis‑issued TLS certificates for 1.1.1.1 raise Internet trust concerns
Three mistakenly issued certificates covering Cloudflare’s 1.1.1.1 DNS service came to light, posing potential risks if abused to impersonate services and intercept traffic. The episode spotlights persistent challenges in the public CA ecosystem and the need for vigilant issuance monitoring and rapid revocation.
Source: Ars Technica
US and allies push SBOM adoption to harden software supply chains
US and partner nations urged broader, standardized use of software bills of materials (SBOMs) to improve transparency, reduce risk, and lower lifecycle costs. The guidance emphasizes interoperable formats and automated exchange so buyers can map dependencies and respond faster to newly discovered component flaws.
Source: SecurityWeek
Report: Attackers weaponize Salesforce trust; detections up 20× in 2025
WithSecure research shows a sharp rise in malicious activity inside Salesforce environments, with adversaries abusing trusted CRM channels and ordinary documents/QR codes to deliver payloads. The findings reinforce the need for stricter access controls, app allow‑listing, and continuous monitoring within SaaS platforms.
Source: Help Net Security
You May Also Be Interested In...
With less than a month to go, House panel votes to extend popular cyber programs
European Court rejects challenge to EU-US data transfer agreement
Exploit Attempts for Dassault DELMIA Apriso. CVE-2025-5086