CISA directed federal agencies to rapidly patch a critical vulnerability in Fortra’s GoAnywhere MFT, rating the flaw a 10.0 severity. The file transfer platform has a history of mass exploitation by ransomware groups, and experts criticized the vendor for not clarifying whether the new bug is under active attack. Agencies and enterprises should patch immediately, restrict internet exposure, and review logs for abnormal file transfers.
Source: The Record
Broadcom under fire as VMware zero‑day exploitation revealed; patch Aria/Tools now
Security researchers say a privilege‑escalation bug affecting VMware Aria Operations and VMware Tools was exploited as a zero‑day since 2024, while Broadcom failed to disclose the active abuse in its advisories. The flaw enables elevation of privileges on guest VMs, making it attractive for cloud and data center intrusion chains. Organizations should prioritize the latest VMware fixes, expand monitoring of hypervisor and guest telemetry, and validate EDR coverage inside VMs.
Source: SecurityWeek
Apple patches critical font processing flaw (CVE‑2025‑43400); update ASAP
Apple released fixes for a serious font handling vulnerability that could lead to crashes or memory corruption when a malicious font is processed. The issue affects multiple Apple platforms; users should install the latest iOS, iPadOS, and macOS updates immediately. Enterprises should expedite mobile and desktop patch rollouts and consider tightening font rendering exposure in high‑risk environments.
Source: Malwarebytes Blog
Western Digital My Cloud NAS fixed for unauthenticated RCE (CVE‑2025‑30247)
Western Digital patched a critical unauthenticated remote code execution flaw impacting My Cloud NAS devices widely used by homes and small offices. Internet‑exposed appliances are at particular risk of takeovers and data theft. Apply the firmware update now, remove direct WAN exposure, and enforce strong administrative controls and backups.
Source: Help Net Security
Sudo flaw actively exploited to gain root; prioritize Linux patching
Organizations are being warned that attackers are exploiting a Sudo vulnerability to escalate privileges from low‑privileged accounts to root, enabling full system compromise. With evidence of in‑the‑wild abuse and KEV listings growing, Linux fleets should be patched quickly. In the interim, tighten sudoers policies and monitor for anomalous privilege escalation attempts.
Source: SecurityWeek
North Korean fake IT workers expand beyond tech into healthcare, finance and AI
Okta’s new research shows DPRK‑linked contractors are increasingly infiltrating hiring pipelines across dozens of countries and sectors, using forged identities and sophisticated interview tactics. Beyond insider access, the scheme risks code poisoning, data exfiltration, and sanctions exposure. Strengthen identity proofing, vendor onboarding, device attestation, and continuous authentication tied to workforce and contractor accounts.
Source: The Record
$50 “Battering RAM” attack breaks Intel and AMD enclave protections (with physical access)
Academics demonstrated a low‑cost interposer that can bypass trust checks and undermine Intel and AMD trusted enclave tech used for confidential computing. While chipmakers note the attack requires physical access and is outside their threat model, the work highlights that TEEs aren’t a silver bullet for high‑assurance scenarios. Teams relying on enclaves should enforce tamper‑evident controls, secure supply chains, and layered key protection (e.g., HSMs and remote attestation with continuous checks).
Source: SecurityWeek
You May Also Be Interested In...
Nationwide internet shutdown in Afghanistan extends localized disruptions
CISA says it will fill the gap as some federal funding for MS‑ISAC dries up
Phantom Taurus: China‑linked APT hits governments with stealth malware