The U.S. Secret Service seized more than 300 servers and 100,000 SIM cards in the New York tri-state area, disrupting a covert telecom infrastructure allegedly used to threaten senior government officials during the U.N. General Assembly. Officials say the network could overwhelm mobile systems and disrupt cell service across the region, underscoring the growing national security risks of industrial-scale SIM farms.
Source: SecurityWeek
Record-breaking DDoS attack peaks at 22 Tbps and 10 Bpps
Cloudflare mitigated the largest DDoS attack observed to date, a 22.2 Tbps, 10.6 Bpps deluge aimed at a European network infrastructure company and linked to the Aisuru botnet. The scale and packet rate highlight attackers’ ability to blend massive volumetric floods with packet-per-second saturation, challenging both transit capacity and inline mitigation.
Source: SecurityWeek
GitHub tightens npm publishing security after high-profile supply-chain attacks
In response to recent npm compromises, GitHub will require local publishing with mandatory 2FA, introduce granular, short-lived tokens that expire after seven days, and expand trusted publishing. The changes aim to reduce token theft and worm-like package propagation seen in incidents such as Shai-Hulud, raising the bar for attacker persistence in the JavaScript ecosystem.
Source: SecurityWeek
SonicWall issues SMA 100 firmware to detect and remove OVERSTEP rootkit
SonicWall released updates for SMA 100 series appliances that add file checks and help eradicate OVERSTEP, a user-mode rootkit deployed in a recent campaign. Organizations should apply the update immediately, audit for persistence, and rotate credentials, as threat actors (UNC6148) previously leveraged stolen admin accounts to maintain access.
Source: SecurityWeek
Supermicro BMC vulnerability patch bypassed, enabling malicious firmware installs
Researchers found a way to bypass Supermicro’s fix for a previously disclosed Baseboard Management Controller flaw, re-opening paths to implant malicious firmware at the hardware management layer. Because BMC compromise grants deep, persistent control, operators should apply the newest updates, isolate management networks, and verify firmware integrity.
Source: SecurityWeek
SolarWinds issues third fix attempt for critical Web Help Desk RCE
SolarWinds released another hotfix for CVE-2025-26399, a critical deserialization flaw in Web Help Desk that follows multiple patch bypasses of earlier vulnerabilities. Admins should patch immediately and consider removing internet exposure until updated, as repeated bypasses indicate active adversary interest and reliable exploitation paths.
Source: SecurityWeek
In-the-wild exploitation of Pandoc SSRF targets AWS IMDS to steal EC2 credentials
Attackers are exploiting CVE-2025-51591 in the Pandoc utility to reach AWS Instance Metadata Service, enabling theft of temporary IAM credentials from EC2 instances. Teams should update Pandoc, enforce IMDSv2, restrict egress to metadata endpoints, and monitor for anomalous token use in cloud environments.
Source: The Hacker News
You May Also Be Interested In...
Libraesva Email Security Gateway vulnerability exploited by nation-state hackersNew PlugX variant overlaps with RainyDay/Turian; abuses DLL search order hijacking
Fake Malwarebytes and LastPass on GitHub deliver Mac malware