Oracle links mass extortion emails to bugs patched in July
Oracle, along with Mandiant and Google Threat Intelligence Group, warned of an extortion campaign abusing vulnerabilities fixed in the July 2025 Critical Patch Update. The activity, potentially linked to Clop, targets Oracle E‑Business Suite customers with ransom demands and unproven data theft claims. Organizations should urgently apply the July patches, restrict internet exposure of Oracle portals, and monitor for suspicious authentication attempts.
Source: RecordedFuture
Scattered Spider posts new leak site, claims theft via Salesforce; Salesforce aids affected customers
The Scattered Spider group published a new extortion site listing dozens of major organizations, claiming data theft through Salesforce environments. The gang threatened Salesforce directly while offering to withdraw demands if Salesforce pays, as Salesforce says it’s supporting customers and investigating. Expect copycat extortion, attempted social engineering against Salesforce admins, and increased credential‑stuffing pressure on SaaS identity.
Source: RecordedFuture
Red Hat confirms GitLab breach tied to consulting instance; 28,000 repos reportedly affected
Red Hat disclosed a breach of its consulting team’s GitLab instance after attackers claimed access to over 28,000 repositories and data from 800 organizations, including prominent enterprises and U.S. agencies. While core products weren’t impacted, the scale underscores software supply chain risks from third‑party and consulting environments. Customers should rotate credentials, review access tokens and webhooks, and audit integrations sourced from affected repos.
Source: SCMagazine
Critical unauthenticated RCE patched in DrayTek Vigor routers
DrayTek released fixes for a high‑severity flaw allowing remote, unauthenticated code execution via crafted HTTP/S requests to the router’s web UI. Internet‑exposed devices are particularly at risk of takeover and botnet enrollment. Admins should patch immediately, disable remote administration where possible, and monitor for anomalous config changes or unexpected outbound connections.
Source: Security Week
Rhadamanthys 0.9.2 info‑stealer adds PNG‑based delivery, anti‑analysis, and crypto wallet targeting
The latest Rhadamanthys release introduces PNG steganography for payload delivery, updated encryption, enhanced sandbox checks, configurable process injection, and new targeting of Ledger Live crypto wallets. The operator’s rebrand and polished product lineup signal ongoing professionalization, while breaking changes may evade legacy detections. Defenders should update detections with new IOCs and techniques and review endpoint controls for credential and wallet protection.
Source: Checkpoint Blog
Research warns: Loading shared AI models can execute attacker code
Researchers at Politecnico di Milano found that loading machine learning models from public repositories can be as dangerous as running untrusted executables, uncovering six previously unknown flaws across popular ML ecosystems. The findings highlight supply chain exposure where model deserialization, custom ops, and plugin hooks can enable code execution. Teams should treat models as code: pin and verify sources, sandbox model loading, and apply least privilege.
Source: HelpNet Security
Report: 180,000+ ICS/OT devices exposed online, raising safety and ransomware risks
BitSight analysis shows a 12% year‑over‑year increase in publicly exposed ICS/OT systems, with more than 180,000 critical infrastructure devices reachable from the internet. Expanded exposure, combined with new malware strains, widens the attack surface for disruptive and safety‑impacting intrusions. Asset owners should eliminate direct internet access, enforce network segmentation and MFA for remote access, and prioritize patching for externally visible OT services.
Source: HackRead
You May Also Be Interested In...
Chrome 141 and Firefox 143 Patches Fix High-Severity Vulnerabilities
CISA Flags Meteobridge CVE-2025-4008 Flaw as Actively Exploited in the Wild
Phoenix: Rowhammer that works on DDR5 | Kaspersky official blog