Cisco fixed a high‑severity flaw in the SNMP subsystem of IOS and IOS XE that attackers are already exploiting in the wild. Under certain configurations, remote attackers can execute code as root or trigger a DoS. Organizations should patch immediately, restrict SNMP to management networks, prefer SNMPv3, and monitor for unusual SNMP activity and device restarts.
Source: SecurityWeek
Mass npm supply-chain compromise: CISA urges reviews after ‘Shai-Hulud’ worm infects 500+ packages
CISA is urging organizations to audit their software after a self‑replicating worm (“Shai‑Hulud”) spread through more than 500 npm packages. The campaign highlights how developer tokens and CI systems can be abused to propagate malware. Teams should freeze and verify dependencies, rotate tokens, enable mandatory 2FA, and inspect build logs for anomalous package publishes.
Source: Recorded Future News (The Record)
BRICKSTORM espionage: China‑linked backdoor lurks on appliances for 393 days on average
Google Threat Intelligence/Mandiant detailed the BRICKSTORM campaign (attributed to UNC5221), which plants stealthy Go‑based backdoors on network and virtualization appliances that lack EDR coverage. Targets include legal services, SaaS, BPO, and tech, with lateral movement to VMware vCenter/ESXi and bulk email access via Entra ID app permissions. Defenders should inventory and egress‑restrict appliances, forward logs, hunt for anomalous outbound DNS/DoH, enforce MFA on vSphere/M365, and scan backups and appliances with provided YARA rules.
Source: Google Threat Intelligence (Mandiant)
Libraesva Email Security Gateway zero‑day exploited in the wild (CVE-2025-59689)
Suspected state‑sponsored actors abused a command‑injection flaw in Libraesva ESG triggered by specially crafted compressed email attachments that bypass sanitization logic. The vendor released fixes; exploitation shows attackers will target the very filters meant to protect mail. Patch immediately, temporarily quarantine high‑risk compressed attachments until updated, and monitor ESG systems for anomalous processes and outbound connections.
Source: Help Net Security
SolarWinds Web Help Desk critical unauthenticated RCE fixed (CVE-2025-26399)
SolarWinds issued a hotfix for a critical RCE in Web Help Desk’s AjaxProxy component that could allow unauthenticated takeover. While no exploitation is reported yet, researchers warn adversaries are likely to reverse‑engineer the patch. Apply the hotfix now, restrict WHD exposure, add WAF rules, and monitor for suspicious requests hitting AjaxProxy endpoints.
Source: Help Net Security
Record‑breaking DDoS peaks at 22.2 Tbps and 10.6 Bpps
Cloudflare mitigated the largest known DDoS to date, linked to the Aisuru botnet and aimed at a European network infrastructure firm. The surge in both bandwidth and packet‑rate underscores the need for anycast architectures, layered L3/4/7 defenses, BGP Flowspec, and automated surge controls. Validate your runbooks for multi‑vector attacks and rehearse failover.
Source: SecurityWeek
UK arrest in airport check‑in ransomware attack tied to HardBit
British authorities arrested a suspect after a ransomware hit on Collins Aerospace disrupted check‑in systems and caused delays across European airports. Researchers linked the incident to the lesser‑known HardBit strain, again spotlighting third‑party and supply‑chain risks in travel operations. Aviation and critical‑infrastructure operators should reassess vendor access, segmentation, and incident containment plans for shared platforms.
Source: SecurityWeek
You May Also Be Interested In...
Feds tie ‘Scattered Spider’ duo to $115M in ransoms (KrebsOnSecurity)
New framework sets baseline for SaaS security controls (Help Net Security)
Malicious Rust crates steal Solana and Ethereum keys (The Hacker News)