Researchers at Noma Labs disclosed “ForcedLeak” (CVSS 9.4), a vulnerability in Salesforce Agentforce that allows indirect prompt injection to siphon sensitive CRM records. The flaw shows how embedded AI agents can be coerced via untrusted content, turning trusted systems into data-leaking conduits. Organizations using Agentforce should review agent permissions, tighten data scopes, and monitor for anomalous AI-driven queries and exports.
Source: Security Affairs
Beijing-linked ‘RedNovember’ campaign hit government and critical networks via internet-facing appliances
The Register reports that the RedNovember cyberspy group ran a year-long operation (June 2024–July 2025) against government and critical private-sector networks worldwide. Intruders exploited buggy edge appliances to plant a Go-based backdoor dubbed Pantegana and leveraged Cobalt Strike and SparkRAT, underscoring persistent abuse of perimeter devices. Rapid patching of internet-facing gear and hunting for unusual Go binaries and RAT beacons are essential.
Source: The Register
Actively exploited Cisco ASA zero-days and Fortra GoAnywhere risks headline the week’s top vulnerabilities
Help Net Security’s roundup flags active exploitation of Cisco ASA zero-day flaws and renewed risk to Fortra GoAnywhere MFT instances. Both highlight the continuing exposure of widely deployed network and file-transfer appliances, where a single weak point can offer broad access. Teams should prioritize isolation and rapid remediation of perimeter systems and restrict external access paths.
Source: Help Net Security
China-linked PlugX and ‘Bookworm’ malware variants target Asian telecom and ASEAN networks
Telecom and manufacturing organizations across Central and South Asia face an ongoing espionage campaign using a new PlugX variant. The malware overlaps with RainyDay and Turian backdoors and abuses legitimate applications for DLL side-loading, complicating detection in enterprise environments. Defenders should audit for suspicious side-loading chains and outbound C2 activity characteristic of PlugX-family implants.
Source: TheHackerNews
Fake invoice lures are dropping XWorm RAT via malicious Office files
Attackers are distributing invoice-themed phishing emails carrying Office attachments that deploy XWorm RAT on Windows systems. The infection uses shellcode and process injection to gain persistent remote access and steal data, highlighting the continued efficacy of business-themed lures. Block risky document macros by default, scrutinize invoice senders, and ensure EDR can detect process injection patterns.
Source: HackRead
Airport cyber incidents surge across Europe—why 2025 attacks look different
GovTech examines a growing wave of cyber incidents affecting European airports and why this year’s attacks stand apart. The analysis cites aviation’s tightly connected systems, third-party dependencies, and cross-border impacts as drivers of heightened operational risk, reinforcing the need for sector-specific resilience and incident playbooks.
Source: GovTech
‘Retired’ Sattered Spider, LAPSUS$, and ShinyHunters are likely regrouping for new waves of attacks
A short-lived alliance of high-profile cybercrime crews has “retired,” but researchers say the announcement is likely a smokescreen. CyberNews reports signs the groups are reorganizing and planning fresh campaigns, meaning data theft, extortion, and intrusion activity could ramp up again. Maintain elevated monitoring for their TTPs and harden identity and third-party access pathways.
Source: CyberNews
You May Also Be Interested In...
Ohio’s Union County suffers ransomware attack impacting 45,000 people
Ransomware’s favorite targets in 2025 and how to protect your business
Google Starts Tracking Your Phone As Chrome And Gemini Change