Oracle rushed an emergency patch for a critical EBS flaw after Cl0p operators began exploiting it in August to steal sensitive data and send extortion emails to victims. Security agencies and researchers urge immediate patching and threat hunting around EBS internet exposure, API logs, and anomalous data egress.
Source: SecurityWeek
Medusa ransomware leverages GoAnywhere MFT zero-day (CVE-2025-10035) for pre-auth command execution
Microsoft and incident responders report Medusa affiliates exploited a critical deserialization bug in Fortra’s GoAnywhere MFT about a week before patches were released. Organizations should upgrade immediately, rotate credentials/keys integrated with MFT, and review for suspicious job executions or unusual outbound transfer activity.
Source: SecurityWeek
Critical Redis RCE (CVE-2025-49844) threatens 60,000 internet-exposed servers
A maximum-severity flaw enables authenticated attackers to abuse crafted Lua scripts to trigger a use-after-free and potentially execute code on hosts. Patch urgently, restrict Redis network exposure, disable or constrain Lua where possible, and enforce strong auth and TLS to reduce exploitation risk.
Source: SecurityWeek
Unity engine vulnerability puts games at risk across Windows, Android, and more
A widely used Unity flaw can enable local code execution via affected apps, prompting Microsoft and Steam to enforce mitigations and developer patches. Game publishers should ship fixes fast and players should update titles promptly, as the attack surface spans desktops and mobile devices running Unity-built apps.
Source: SecurityWeek
New leak site targets 39 organizations tied to Salesforce data theft
A collective dubbed Scattered Lapsus$ Hunters launched a data leak portal to pressure victims—purportedly via compromised Salesforce environments—into paying ransoms. The campaign underscores SaaS supply-chain risk; defenders should audit Salesforce integrations, access tokens, third-party apps, and data export activity.
Source: Help Net Security
Discord discloses third-party breach exposing user support data, including some ID images
Discord confirmed a compromise at a customer support vendor that exposed names, contact details, IPs, limited billing info, and a subset of government ID images for users interacting with support. Users should be alert to targeted phishing, and enterprises should reassess vendor data minimization and breach response SLAs.
Source: SecurityWeek
CSS “hidden text salting” helps phishing bypass AI-powered email defenses
Cisco Talos warns of a surge in attackers abusing CSS to “salt” hidden text in emails, degrading the accuracy of ML and LLM-based filters without changing human-visible content. Security teams should harden pipelines against style-based obfuscations and supplement content inspection with robust sender, URL, and behavior signals.
Source: Cisco Talos
You May Also Be Interested In...
FBI, UK Gov’t urge immediate patching of Oracle EBS after Cl0p campaign
Microsoft links Storm-1175 to GoAnywhere exploit deploying Medusa ransomware
Phishers target 1Password users with convincing fake breach alerts