Google released Chrome 140 to fix a type confusion bug in the V8 JavaScript engine that is already being exploited in the wild, marking the browser’s sixth zero‑day of 2025. Admins should prioritize updates and ensure users fully restart the browser to apply the patch, especially in high-risk environments using web-exposed workflows.
Source: SecurityWeek
SonicWall breach exposes customer firewall configurations; password resets urged
SonicWall disclosed that attackers obtained some customers’ firewall configuration backups, prompting the company to push a new preferences file to a subset of customers and advise password resets. Organizations should import the updated preferences, rotate credentials and API keys, and review access policies for any anomalous changes.
Source: SecurityWeek
Self-propagating “Shai-Hulud” worm hits NPM ecosystem, steals secrets from developers
A supply chain attack injected malicious code into 180+ NPM packages, using a worm-like mechanism to harvest secrets, flip private repos public, and cascade downstream compromises. Teams should freeze affected dependencies, rotate tokens and credentials, and add provenance checks and SBOM validation to CI/CD pipelines.
Source: SecurityWeek
Microsoft and Cloudflare dismantle RaccoonO365 phishing-as-a-service, seize 338 sites
Authorities disrupted RaccoonO365, a subscription kit used to steal Microsoft 365 credentials at scale, and identified its alleged leader. Despite the takedown, copycat kits persist; enterprises should enforce phishing-resistant MFA (FIDO2/WebAuthn), harden conditional access, and monitor for lookalike domains.
Source: SecurityWeek
Severe Chaos Mesh flaws enable full Kubernetes cluster takeover
Researchers detailed four high-impact “Chaotic Deputy” vulnerabilities in Chaos Mesh, an open-source chaos engineering tool, that can lead to total cluster compromise. Operators should patch promptly, restrict service account permissions, isolate chaos tooling, and audit for abuse in CI/CD and test namespaces.
Source: SCMagazine
Scattered Spider targets financial sector despite “retirement” claims
Fresh activity linked to Scattered Spider shows the group pivoting to banks and financial services, leveraging social engineering and identity compromise. Financial firms should tighten identity verification for IT requests, enforce strong MFA and least privilege, and implement out-of-band callbacks before granting access.
Source: SCMagazine
Airline data broker reportedly sells 5 billion passenger records to U.S. government
A data broker is allegedly offering a searchable trove of at least 5 billion airline passenger records to government agencies, far exceeding earlier estimates. The revelation underscores escalating data broker risk; organizations should reassess data-sharing with intermediaries, enforce minimization, and scrutinize vendor contracts for secondary use.
Source: Malwarebytes Blog
You May Also Be Interested In...
Decade-Old Pixie Dust Wi-Fi Hack Still Impacts Many Devices
North Korean Operation Uses ChatGPT to Forge Military IDs in Phishing Campaign
Insight Partners Confirms Data Breach Result of Ransomware Attack