A maintainer’s account was hijacked and at least 18 widely used npm packages were briefly trojanized with code that intercepts Web3 activity and rewrites wallet destinations. Researchers say the malware reached roughly 10% of cloud environments during a two-hour window, underscoring how fast dependency compromises can propagate. Teams should lock dependencies, audit build pipelines for suspicious token use, and rotate credentials.
Source: SecurityWeek
Microsoft Patch Tuesday: HPC Pack RCE and NTLM EoP Top a Busy Month
Microsoft’s September updates address ~80+ CVEs, including eight Critical issues; none are known to be actively exploited. Standouts include a wormable Remote Code Execution in High Performance Compute Pack (CVE-2025-55232), a GDI+ RCE reachable via web content, and an NTLM Elevation of Privilege bug. Prioritize patching HPC Pack clusters, harden/segment management interfaces, and consider temporarily disabling Office Preview Pane features.
Source: Zero Day Initiative
SAP Ships Critical Fixes: NetWeaver CVSS 10 and Previously Exploited S/4HANA Flaws
SAP released multiple critical patches, including CVE-2025-42944 (CVSS 10.0) in NetWeaver that can enable unauthenticated code execution, plus other high-severity issues and fixes for previously exploited S/4HANA bugs. SAP customers should apply updates immediately, restrict access to RMI and management interfaces, and monitor for suspicious deserialization or file-upload activity.
Source: The Hacker News
DoD Finalizes CMMC Rule: New Cyber Requirements for Defense Contractors
The US Department of Defense has finalized its Cybersecurity Maturity Model Certification (CMMC) rule, making third-party-validated security controls a prerequisite for many Pentagon contracts. The move tightens oversight of contractor cyber hygiene and supply-chain risk, aligning more closely with NIST 800-171 and elevating consequences for noncompliance.
Source: The Register
Mitsubishi Electric to Acquire Nozomi Networks in Major OT Security Deal
Mitsubishi Electric will acquire Nozomi Networks for nearly $1 billion, folding the OT/IoT security leader into its portfolio while keeping Nozomi’s San Francisco HQ. The deal signals continued consolidation in industrial cybersecurity and could accelerate integration of threat detection and asset visibility across automation ecosystems.
Source: SecurityWeek
Exposed Docker APIs Exploited to Build Botnet and Deploy Miners
Attackers are abusing internet-exposed Docker APIs to spin up containers, mount host file systems, pull payloads over Tor, and even block further API access. Activity points to cryptomining and botnet formation. Defenders should disable public Docker APIs, enforce TLS and authentication, restrict daemon access by firewall, and continuously audit container sprawl.
Source: SecurityWeek
Plex Breach Prompts Password Resets; Company Urges 2FA
Plex disclosed unauthorized access to a database containing emails, usernames, password hashes, and authentication data for a subset of users. The streaming platform is forcing password resets and recommending two-factor authentication to reduce the risk of account takeover and credential stuffing.
Source: SecurityWeek
You May Also Be Interested In...
Cisco puts agentic AI at the core of Splunk Enterprise SecurityNearly 500 researchers urge EU to rethink controversial CSAM scanning proposal
Signal adds secure backup option for chat history