Fortra released a fix for CVE-2025-10035, a maximum‑severity deserialization vulnerability in GoAnywhere MFT that allows arbitrary command execution via the product’s License Servlet. Researchers warn this class of issue is ripe for rapid mass exploitation, especially in file‑transfer infrastructure historically targeted by ransomware. Security teams should patch immediately, lock down external exposure, and hunt for anomalous admin activity and new scheduled tasks on MFT hosts.
Source: The Hacker News
OpenAI patches “ShadowLeak” zero‑click attack on ChatGPT Deep Research
Radware disclosed a zero‑click technique dubbed ShadowLeak that used a single crafted email to silently prompt‑inject ChatGPT’s Deep Research agent and exfiltrate Gmail inbox data. OpenAI addressed the flaw in early August, but the incident underscores AI agent supply‑chain risks from untrusted content and hidden prompts. Teams using AI agents should restrict data access, apply outbound egress controls, and add content sanitization and domain allow‑listing.
Source: The Hacker News
CISA details malware used in Ivanti EPMM intrusions
Attackers chained Ivanti EPMM vulnerabilities to profile systems, dump credentials, and deploy two distinct malware sets at an unnamed organization, according to new CISA analysis. The report highlights post‑exploitation persistence and listener components that enable remote code execution. Organizations should urgently patch EPMM, rotate credentials, review management server logs, and scan for the IOCs and persistence mechanisms in CISA’s advisory.
Source: SecurityWeek
Turla and Gamaredon team up in coordinated operations against Ukraine
ESET observed instances where FSB‑linked groups Gamaredon and Turla compromised the same Ukrainian machines, with Turla deploying its Kazuar backdoor after Gamaredon’s initial access. The collaboration blends speed and reach (Gamaredon) with stealthy, long‑term espionage (Turla), raising the bar for detection and response. Defenders should assume multi‑team tooling in incident scopes and prioritize layered containment and telemetry across email, endpoints, and lateral movement paths.
Source: Recorded Future News (The Record)
DOJ: Scattered Spider netted $115M in ransoms, breached U.S. court network
U.S. authorities unsealed charges against a Scattered Spider suspect, alleging the group extorted at least $115 million over three years and compromised a federal court system. The case details a prolific social‑engineering‑driven operation that mixed SIM‑swaps, MFA fatigue, and help‑desk manipulation to gain access. Expect continued arrests and intelligence sharing; enterprises should harden identity workflows, implement number matching and phishing‑resistant MFA, and rehearse crisis comms for extortion events.
Source: Recorded Future News (The Record)
Cyberattack disrupts check‑in and boarding at multiple European airports
Collins Aerospace reported a “cyber‑related disruption” affecting airline check‑in and boarding systems, causing delays and operational headaches across European airports. The incident highlights aviation’s dependence on shared third‑party platforms and the ripple effects of vendor outages. Operators should review business continuity playbooks for ground operations and validate contingency integrations for DCS and passenger processing systems.
Source: Politico
Future of CVE Program uncertain amid CISA–board debate
CISA released draft plans for the CVE Program, sparking debate among board members on governance, scope, and the path to scale vulnerability identification. With CVE underpinning global patching and risk management workflows, any shift could affect automation, CNA participation, and data quality. Stakeholders should track the discussion and prepare to adapt tooling that relies on CVE metadata and timelines.
Source: Recorded Future News (The Record)
You May Also Be Interested In... One token to pwn them all: Entra ID bug could have granted access to every tenant
WatchGuard patches 9.3 flaw in Firebox firewalls
MI6 launches darkweb portal to recruit foreign spies