ESET researchers analyzed “HybridPetya,” a Petya/NotPetya copycat that can compromise UEFI-based systems and bypass Secure Boot by abusing CVE-2024-7344 on outdated systems. While not observed in the wild yet, the sample uploaded to VirusTotal shows attackers experimenting with pre-OS persistence again—underscoring the need to update firmware, OS bootloaders, and Secure Boot revocation lists (DBX) promptly.
Source: ESET Blog
Samsung patches actively exploited Android zero‑day (CVE‑2025‑21043)
Samsung issued its September Security Maintenance Release to fix an out‑of‑bounds write in libimagecodec.quram.so that was exploited in the wild for remote code execution. Enterprises should expedite updates across Galaxy fleets and caution users against opening unsolicited media, as image parsing flaws are a common initial access vector on mobile.
Source: The Hacker News
Critical DELMIA Apriso factory software flaw exploited; added to CISA KEV
A deserialization bug in Dassault Systèmes’ DELMIA Apriso MOM platform is being exploited for remote code execution, prompting CISA to add CVE‑2025‑5086 to its Known Exploited Vulnerabilities catalog. Manufacturers should patch immediately, review internet exposure of MOM/MES systems, and monitor for suspicious process spawns from application services.
Source: SecurityWeek
VMScape: New Spectre variant breaks cloud VM isolation
Academics disclosed “VMScape,” a Spectre-style attack that exploits incomplete mitigations and branch predictor state to leak arbitrary memory across the guest–host boundary. Cloud and data center operators should apply vendor microcode/hypervisor updates, re-evaluate co‑tenancy and scheduling policies, and enable side‑channel hardening where available.
Source: SecurityWeek
VoidProxy PhaaS bypasses MFA on Microsoft and Google accounts
Okta Threat Intelligence flagged “VoidProxy,” a phishing‑as‑a‑service platform using adversary‑in‑the‑middle techniques to steal credentials, MFA codes, and session tokens in real time. Reduce risk by enforcing phishing‑resistant MFA (FIDO2/WebAuthn), token binding/conditional access, strict domain controls (MTA‑STS/DMARC), and rapid token revocation playbooks.
Source: HackRead
SEO poisoning pushes Hiddengh0st and Winos via fake software sites
FortiGuard Labs uncovered a search‑engine poisoning campaign targeting Chinese‑speaking users with cloned software portals that deliver Hiddengh0st and Winos malware. Blocklists alone won’t stop it—harden endpoint controls, inspect downloads with reputation and sandboxing, and steer users to vendor‑verified domains via allowlists.
Source: Fortinet
CISA urges Congress to extend expiring cyber info‑sharing law
With the 2015 Cybersecurity Information Sharing Act set to sunset within weeks, CISA’s Nick Andersen called on lawmakers to renew the framework that incentivizes private‑sector threat intel sharing. The outcome will shape the legal and operational foundations for cross‑sector indicator exchange and government collaboration.
Source: Recorded Future News (The Record)
You May Also Be Interested In...
Meet Yurei: The New Ransomware Group Rising from Open-Source CodeApple Sends Fresh Wave of Spyware Notifications to French Users
FBI Warns of UNC6040 and UNC6395 Targeting Salesforce Platforms in Data Theft Attacks