OpenSSL shipped updates addressing three vulnerabilities that could enable private key recovery, remote code execution, and denial-of-service attacks. The widely used crypto library underpins servers, clients, and embedded devices, making timely patching essential to reduce exposure across internet-facing and supply chain components. Prioritize inventorying OpenSSL versions and updating dependent packages and containers.
Source: SecurityWeek
Broadcom under fire for not disclosing in-the-wild VMware zero-day exploitation
A privilege-escalation flaw impacting VMware Aria Operations and VMware Tools was exploited as a zero-day, but Broadcom failed to inform customers about active exploitation, SecurityWeek reports. The bug allows attackers to elevate privileges within virtual machines, raising concerns for sensitive workloads hosted on shared infrastructure. Organizations should accelerate patching, review hypervisor and guest VM hardening, and comb logs for suspicious privilege changes.
Source: SecurityWeek
Critical Red Hat OpenShift AI bug could allow full cluster takeover
Researchers disclosed a severe vulnerability in Red Hat OpenShift AI that, under certain conditions, enables attackers to escalate privileges and seize control of hybrid cloud infrastructure. As enterprises scale predictive and generative AI, the flaw underscores how ML platforms expand the attack surface beyond traditional Kubernetes risks. Apply vendor fixes immediately and restrict access to control-plane services and AI pipelines.
Source: The Hacker News
48,000 Cisco ASA/FTD devices remain exposed amid active zero-day exploitation
Months after warnings about active exploitation of CVE-2025-20333 and CVE-2025-20362 in Cisco ASA/FTD, tens of thousands of internet-facing appliances are still vulnerable. Most affected systems are in the U.S., with significant exposure in the UK, Japan, Russia, Germany, and Canada. Verify mitigations, upgrade to fixed releases, and remove unnecessary external access to management interfaces.
Source: Help Net Security
30,000-website DNS hijacking network funnels millions to scams and malware
A covert infrastructure of 30,000 websites is abusing DNS filtering to steer visitors, with 9% landing on scams and 1% receiving malware such as StrelaStealer. The long-running operation evades detection by selectively redirecting traffic and abusing server-side DNS logic. Defenders should monitor DNS anomalies, enforce protective DNS, and block known indicators tied to the campaign.
Source: CyberNews
Android spyware campaigns impersonate Signal plugins and ToTok to target UAE users
ESET uncovered “ProSpy” and “ToSpy” Android spyware families distributed via fake websites as Signal add-ons and ToTok clones, respectively. Once installed, the apps harvest device data and communications, highlighting the persistent risk of sideloaded apps and social engineering. Advise users to install only from official stores, enable Google Play Protect, and block unknown sources.
Source: The Hacker News
WestJet confirms breach of 1.2M passengers’ data, including passports and IDs
Canadian airline WestJet said attackers stole personal information tied to reservations, including names, contact details, and identity documents. The incident underscores the high value of travel documents to fraudsters and the lasting identity risks for victims. Impacted customers should monitor for identity misuse and consider passport/ID replacement guidance from authorities.
Source: SecurityWeek
You May Also Be Interested In...
NIST issues guidance to mitigate USB-borne threats in industrial control systems
UK government renews push to access encrypted iCloud backups
Researchers demonstrate $50 “Battering RAM” attack against Intel/AMD security features