Red Hat has confirmed a compromise of a self-managed GitLab instance used for its consulting business, following hacker claims of stealing data from 28,000 private repositories. The incident raises supply-chain exposure concerns because consulting artifacts can contain customer environment details. Organizations working with Red Hat consulting should review shared assets, rotate tokens/keys, and monitor for misuse.
Source: SecurityWeek
Oracle execs hit by extortion wave tied to E‑Business Suite; known bugs may be involved
Attackers claiming affiliation with the Cl0p group are emailing executives to extort payment, alleging theft of data from Oracle E‑Business Suite. Oracle says its investigation indicates vulnerabilities patched in July 2025 may have been exploited. Enterprises should urgently apply all Oracle EBS updates from July onward, rotate credentials, and scrutinize access logs for suspicious activity.
Source: SecurityWeek
Chrome 141 and Firefox 143 fix high-severity flaws—patch now
Google and Mozilla shipped security updates addressing high-severity vulnerabilities, including issues in Chrome’s WebGPU and Video components and Firefox’s Graphics and JavaScript Engine. Rapid enterprise rollout is recommended, as browser bugs are frequently chained in drive-by attacks and malvertising campaigns.
Source: SecurityWeek
Actively exploited Meteobridge flaw allows unauthenticated root command execution
A command injection vulnerability in Smartbedded Meteobridge, patched in mid-May, is being exploited in the wild. The bug enables remote, unauthenticated attackers to execute arbitrary commands with root privileges, making immediate patching and network isolation essential for exposed devices.
Source: SecurityWeek
WireTap attack undermines Intel SGX attestation
New research details “WireTap,” an attack that uses a passive interposer to manipulate SGX enclaves and extract the DCAP attestation key, breaking SGX’s attestation mechanism. The findings pose serious implications for trusted execution environments that rely on SGX for remote trust guarantees.
Source: SecurityWeek
Android spyware campaigns impersonate Signal and ToTok
ESET uncovered two spyware families—ProSpy and ToSpy—spread via fake websites and social engineering, masquerading as Signal add‑ons and the discontinued ToTok app. Researchers say ToSpy’s campaign remains active, with live C2 infrastructure. Users should only install apps from official stores and verify publishers.
Source: Help Net Security
ENISA: Attacks in the EU increasingly target OT systems
ENISA’s 2025 Threat Landscape report highlights notable activity against operational technology across the EU. The trend underscores the need for tighter IT/OT segmentation, asset visibility, and incident response preparedness in industrial environments.
Source: SecurityWeek
You May Also Be Interested In...
Self‑propagating malware spreads via WhatsApp, targets Brazilian users
Chinese-speaking cybercrime group targets high-value IIS for SEO fraud
Malicious PyPI package “soopsocks” infects systems before takedown