Cybersecurity agencies in the US, UK, Canada, and Australia warned that a suspected nation-state actor has been exploiting two zero-day flaws in Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD). The campaign—linked to prior ArcaneDoor activity—used custom malware including RayInitiator and LINE VIPER to gain persistence and impair logging. Organizations should patch immediately, hunt for signs of tampering on edge devices, and review access controls and logging on ASA/FTD appliances.
Source: Help Net Security
Fortra GoAnywhere CVSS 10 flaw exploited as a zero-day before disclosure
Attackers actively exploited a critical deserialization vulnerability (CVE-2025-10035) in Fortra GoAnywhere MFT days before patches were released on September 15. The flaw in the License Servlet allowed forged license responses to be deserialized, enabling backdoor admin creation and takeover. Fortra urges upgrading to 7.8.4 or 7.6.3 (Sustain Release) and taking services offline until fully remediated and logs reviewed.
Source: Help Net Security
Prompt injection and a $5 domain trick Salesforce Agentforce into data leaks
Researchers showed how indirect prompt injections hosted on an attacker-controlled, previously trusted domain could force Salesforce’s Agentforce AI agents to exfiltrate private CRM data. The “ForcedLeak” issue, now fixed by Salesforce, highlights the growing risk from AI agents that browse or consume third-party content. Security teams should restrict agent permissions, sanitize external content, and apply robust egress controls for AI workflows.
Source: The Register
New XCSSET macOS variant targets developers, hijacks crypto, and hits Firefox
Microsoft researchers uncovered a more sophisticated XCSSET strain using a four-stage infection chain, new persistence techniques, and expanded browser targeting that includes Firefox. The malware can hijack clipboard contents to redirect cryptocurrency transactions and exfiltrate browser data. macOS developers should harden Xcode projects, validate dependencies, and monitor for unusual launch agents and network activity.
Source: SecurityWeek
Malicious open-source MCP server package caught stealing emails
A copycat of a legitimate Model Context Protocol (MCP) server was published to an open-source repository and surreptitiously exfiltrated email data, amassing roughly 1,500 weekly downloads before discovery. The incident underscores the persistent risk of package impersonation in developer ecosystems. Teams should pin trusted maintainers, enable package signing/verification where available, and routinely scan build pipelines and dependencies.
Source: SC Media
North Korean group plants multiple backdoors in crypto developer attacks
DeceptiveDevelopment (aka Famous Chollima/UNC5342/Tenacious Pungsan) is conducting “Contagious Interview” campaigns against cryptocurrency developers worldwide, deploying a suite of backdoors. The operation leverages social engineering and developer-focused lures to compromise build environments and siphon sensitive code and keys. Developer shops should isolate build systems, enforce code signing and MFA, and treat unsolicited recruiter or collaboration outreach with high suspicion.
Source: SC Media
US cyber threat‑sharing law at risk as government shutdown looms
The 2015 Cybersecurity Information Sharing Act (CISA) is set to lapse if a US federal government shutdown begins on October 1, threatening a key mechanism for public‑private cyber threat exchange. A lapse could delay indicators and best‑practice dissemination at a volatile time for enterprise defenders. Organizations should prepare to lean on ISACs/ISAOs and commercial intel feeds if federal channels are disrupted.
Source: The Register
You May Also Be Interested In...
Neon call‑recording app shut down after data exposure
Google and Flo to pay $56 million after misusing users’ health data
Google warns of Brickstorm backdoor targeting U.S. legal and tech sectors