Attackers are abusing a ViewState deserialization flaw in Sitecore deployments where a sample ASP.NET machine key from older guides was left in place, enabling remote code execution and malware delivery. Organizations running Sitecore XM, XP, XC, or Managed Cloud with the sample key are at risk and should immediately replace keys, harden configurations, and hunt for post-exploitation activity.
Source: SecurityWeek
Google patches two Android flaws already under targeted exploitation
Google shipped fixes for CVE-2025-48543 (Android Runtime) and CVE-2025-38352 (Linux kernel) that have been exploited in the wild in limited, targeted attacks. Admins should prioritize deploying September 2025 Android updates across fleets and verify OEM patch levels, especially for high-risk users.
Source: SecurityWeek
Critical SAP S/4HANA code injection bug (CVE-2025-42957) exploited in the wild
A recently disclosed SAP S/4HANA vulnerability allowing full system takeover is being actively exploited. Organizations should apply SAP’s patches without delay and review systems for signs of compromise, given the potential for deep business process impact.
Source: SecurityWeek
Salesforce-Salesloft Drift supply chain attack widens, hits more cybersecurity vendors
Proofpoint, SpyCloud, Tanium, and Tenable joined a growing list of companies disclosing exposure via stolen OAuth tokens tied to Salesloft Drift, with attackers accessing data stored in Salesforce instances. The campaign’s blast radius remains under assessment; rotate tokens, review app integrations, and enforce least privilege on connected SaaS platforms.
Source: SecurityWeek
GhostRedirector: New group hijacks search results with custom IIS module and C++ backdoor
ESET uncovered “GhostRedirector,” a likely China-linked actor compromising at least 65 Windows servers and deploying a passive C++ backdoor (Rungan) plus a malicious IIS module (Gamshen) to manipulate Google search results. Targeted servers were primarily in Brazil, Thailand, Vietnam, and the U.S., highlighting a blend of SEO fraud and stealthy persistence.
Source: ESET Blog
New TP-Link router zero-day emerges as CISA flags active exploitation of other TP-Link flaws
TP-Link confirmed an unpatched zero-day impacting multiple router models, while CISA warned that other TP-Link vulnerabilities have been exploited in attacks. Until patches are available, defenders should disable remote management, segment or replace EoL hardware, and monitor for suspicious outbound traffic from SOHO gear.
Source: BleepingComputer
AI supply chain risk: “Model Namespace Reuse” enables malicious model swaps
Researchers demonstrated an AI supply chain weakness dubbed Model Namespace Reuse that allows attackers to publish malicious models under trusted names and achieve code execution in products from major vendors. The finding underscores the need for model signing, strict provenance checks, and runtime isolation in AI pipelines.
Source: SecurityWeek
You May Also Be Interested In...
Addressing the unauthorized issuance of multiple TLS certificates for 1.1.1.1 (Cloudflare)
Russian APT28 Deploys “NotDoor” Outlook Backdoor (The Hacker News)
Czech cyber agency warns against services that send data to China (The Record)