Cisco confirmed two zero-day flaws in the VPN web server of Cisco Secure Firewall ASA and FTD are being exploited in the wild, prompting CISA to issue an emergency directive to federal agencies. The bugs enable remote code execution and credential theft; defenders should patch immediately, restrict/disable web VPN access where possible, and hunt for indicators of compromise.
Source: The Hacker News
New Cisco IOS/IOS XE zero‑day (CVE‑2025‑20352) under active attack; millions exposed
A high‑severity SNMP vulnerability in Cisco IOS and IOS XE (CVE‑2025‑20352) is being exploited, with internet scans showing roughly 2 million exposed SNMP interfaces. Prioritize vendor fixes, restrict SNMP to trusted management networks, rotate credentials, and monitor for anomalous SNMP activity.
Source: Ars Technica
Fortra GoAnywhere CVSS 10 flaw exploited as a zero‑day to create backdoor admin accounts
Attackers weaponized CVE‑2025‑10035 at least eight days before patches to stealthily create admin users on GoAnywhere MFT, a platform long targeted by APTs and ransomware groups. Upgrade to 7.8.4 or later, audit user/admin accounts and access logs, and rotate secrets integrated with the MFT immediately.
Source: SecurityWeek
Massive npm supply‑chain event: “Shai‑Hulud” worm infects 500 packages
Kaspersky detailed a widespread npm compromise in which hundreds of packages—collectively tallying millions of downloads—were infected by the Shai‑Hulud worm. Organizations should pin and verify dependencies, enforce provenance checks, scan build pipelines, and consider curated repos or allowlists to reduce ecosystem risk.
Source: Securelist (Kaspersky)
BrickStorm espionage: Chinese operators dwelled 393 days hunting zero‑day intel
Google’s Threat Intelligence Group and Mandiant describe a long‑running BrickStorm/UNC5221 campaign that persisted in networks for over a year, targeting legal and tech firms and collecting vulnerability intelligence. The operation underscores the need to harden edge appliances, segment management networks, and increase detection around low‑and‑slow data staging.
Source: SecurityWeek
Microsoft flags phishing campaign using LLM‑obfuscated attachments
Microsoft Threat Intelligence observed threat actors using large language models to obfuscate malicious content inside attachments, aiming to bypass scanners and deliver payloads for data theft and extortion. Expect cleaner, more convincing lures and harder‑to‑detect code; tighten attachment policies, enable advanced content disarm/sandboxing, and train users to verify unexpected documents.
Source: Help Net Security
Ransomware at record pace: 3,734 victims listed in H1 2025 as groups multiply
Searchlight Cyber’s mid‑year report shows a 20% rise in publicly listed victims compared to late 2024 and a surge in new ransomware crews. With more affiliates and tooling in circulation, defenders should double down on identity protections, rapid patching of edge services, immutable backups, and dark‑web monitoring for early extortion signals.
Source: Help Net Security
You May Also Be Interested In...
European Windows 10 users get an extra year of free security updates
New XCSSET macOS malware variant hijacks crypto and targets Firefox
AWS Instance Metadata Service targeted via Pandoc SSRF (CVE‑2025‑51591)