A critical command injection vulnerability in SAP S/4HANA (CVE-2025-42957, CVSS 9.9) is being actively exploited, allowing attackers to take full control of affected systems. Organizations should urgently apply available patches, review access logs for suspicious activity, and isolate exposed instances to reduce blast radius.
Source: HackRead
GhostAction Supply-Chain Attack Exfiltrates 3,325 Secrets from GitHub Projects
A widespread supply-chain campaign dubbed “GhostAction” compromised 817 GitHub repositories and siphoned 3,325 secrets, including npm, PyPI, and DockerHub tokens. The attack abused malicious GitHub Actions workflows to harvest CI/CD credentials—teams should audit workflows, revoke exposed tokens, and enforce least-privilege for automation.
Source: HackRead
Salesloft Breach Hits Multiple Security Vendors; Sitecore Zero‑Day (CVE-2025-53690) Exploited
Fallout from a breach at Salesloft—attributed by Google to UNC6395—continues as Zscaler, Palo Alto Networks, PagerDuty, Tanium, and SpyCloud confirmed unauthorized access to their Salesforce instances. Separately, attackers are exploiting a Sitecore zero‑day (CVE-2025-53690), underscoring the need to review SaaS integrations, OAuth scopes, and web CMS patch posture.
Source: Help Net Security
‘Noisy Bear’ Targets Kazakhstan’s Energy Sector in Operation BarrelFire
A new threat group tracked as Noisy Bear, possibly of Russian origin, is conducting phishing campaigns against Kazakhstan’s energy sector, including employees of KazMunaiGas (KMG). Active since at least April 2025, the operation blends social engineering and tailored lures to gain footholds in critical energy infrastructure.
Source: The Hacker News
MeetC2: Serverless C2 Over Google Calendar Shows How Attackers Blend in with Cloud Traffic
Researchers released MeetC2, a proof‑of‑concept command‑and‑control framework that uses Google Calendar APIs as its communications channel. The tool is designed to help red and blue teams emulate modern adversaries who hide C2 inside ubiquitous cloud services, and to validate detection, logging, and response coverage for SaaS APIs.
Source: Security Affairs
Scammers Abuse Grok on X to Slip Malicious Links Past Ad Policies
Attackers are “grokking” on X—leveraging Grok to embed malicious links and circumvent the platform’s ban on URLs in promoted posts. The tactic boosts reach for scam content, signaling that adversaries are adapting quickly to AI‑driven content tools and ad policy guardrails.
Source: Dark Reading
Report: ICE Has Spyware Now
Wired reports that US Immigration and Customs Enforcement (ICE) now has spyware capabilities, highlighting a growing expansion of government surveillance tooling. The development raises oversight and privacy concerns for civil society and underscores the need for transparent governance around powerful monitoring technologies.
Source: Wired
You May Also Be Interested In...
Google Confirms Android Attacks—No Fix For 1 Billion Phones
Malicious npm Packages Impersonate Flashbots, Steal Ethereum Wallet Keys