Academics disclosed “VMScape,” a new Spectre-class transient execution attack that can pierce VM isolation and leak arbitrary memory across cloud tenants. The technique exploits gaps in existing mitigations by targeting branch predictor state, raising urgent questions for cloud providers and customers about microcode, hypervisor, and workload hardening. Teams should monitor vendor advisories and evaluate isolation strategies for high-trust workloads.
Source: SecurityWeek
Akira ransomware still breaching orgs via SonicWall firewalls
Over a year after SonicWall patched CVE-2024-40766, Akira affiliates are still exploiting the flaw and migration missteps (like not resetting local passwords when moving from Gen 6 to Gen 7). The campaign underscores how “patched” isn’t the same as “remediated” when credentials persist and appliances remain exposed. Prioritize patching, rotate all local accounts, audit VPN access, and hunt for post-exploitation artifacts.
Source: Help Net Security
Google patches critical Chrome bug with code-execution impact
Google fixed a critical use-after-free vulnerability (CVE-2025-10200) in Chrome’s Serviceworker component that could lead to code execution. A researcher earned $43,000 for the report; admins should push the update immediately across managed fleets and consider tightening extension and site isolation policies to limit blast radius.
Source: SecurityWeek
AI code editor “Cursor” default setting enables silent code execution
Researchers warn an out-of-the-box setting in Cursor, an AI-augmented fork of VS Code, can be abused to run malicious code when opening booby-trapped repositories. The finding highlights supply-chain risk inside developer tools; teams should review Cursor’s trust settings, open unknown repos in sandboxes/containers, and enforce least privilege on developer endpoints.
Source: Help Net Security
CISA seeks new funding to safeguard the CVE program
After MITRE revealed the CVE program nearly lapsed in April, CISA says it’s weighing alternative funding sources to stabilize the vulnerability-tracking backbone. Any disruption to CVE would ripple across patch management, SBOMs, scanners, and threat intelligence; expect governance and funding reforms to keep the system resilient.
Source: NextGov
Senator urges FTC probe of Microsoft after Ascension ransomware
Sen. Ron Wyden asked the FTC to investigate Microsoft, citing attackers’ use of insecure RC4-based tech to compromise healthcare giant Ascension. The move intensifies scrutiny of legacy cryptography and enterprise defaults in Windows/AD environments, with potential regulatory implications for vendor security baselines.
Source: Recorded Future News (The Record)
Bulletproof host “Stark Industries” sidesteps EU sanctions
EU sanctions in May failed to stop notorious bulletproof hosting outfit Stark Industries, which Krebs reports has rebranded and shifted assets among related entities to continue operations. The service remains a key enabler of Kremlin-linked hacking and disinformation, underscoring how resilient cybercrime infrastructure can evade traditional enforcement.
Source: KrebsOnSecurity
You May Also Be Interested In...
CISA flags critical flaws in Rockwell Automation, ABB products
California passes bill forcing browsers to honor global opt-out for data sharing
Apple’s new iPhone memory protections target the most exploited bug class