Redis patched a maximum-severity flaw that allows authenticated attackers to use malicious Lua scripts to escape the sandbox and execute arbitrary code on the host. Researchers estimate roughly 60,000 internet-exposed Redis servers could be at risk; admins should patch immediately, restrict exposure, and monitor for suspicious Lua activity.
Source: SecurityWeek
Leaked Oracle EBS exploit scripts fuel active RCE attacks (CVE-2025-61882)
Exploit scripts for a critical Oracle E-Business Suite vulnerability have leaked on Telegram, and attackers reportedly began exploiting the flaw months before patches landed. Researchers warn the issue chains multiple weaknesses for unauthenticated RCE; organizations should patch now, audit internet-facing EBS, and hunt for signs of compromise.
Source: Help Net Security
Medusa ransomware exploiting GoAnywhere MFT zero-day (CVE-2025-10035)
The Medusa ransomware group leveraged a critical deserialization bug in Fortra’s GoAnywhere MFT to achieve unauthenticated command execution, with exploitation observed before patches were released. Enterprises should upgrade to fixed versions immediately, review MFT access logs for License Servlet abuse, and isolate file transfer infrastructure.
Source: SecurityWeek
ShinyHunters launch mass extortion site, claim Fortune 500 data and Red Hat theft
ShinyHunters resurfaced with an extortion portal threatening to leak data from dozens of major firms, after earlier vishing-led theft of Salesforce customer records. The crew also tied themselves to the Discord third‑party breach and alleged multi-terabyte theft from Red Hat, signaling a coordinated pressure campaign on corporate victims.
Source: KrebsOnSecurity
Zimbra stored XSS actively exploited; CISA adds to KEV (CVE-2025-27915)
A stored cross-site scripting flaw in Zimbra Collaboration Suite is being exploited in the wild, including via malicious iCalendar invites, prompting CISA to add it to the Known Exploited Vulnerabilities catalog. Mail admins should apply vendor fixes, sanitize calendar content, and harden webmail to limit script execution.
Source: Security Affairs
Microsoft: Threat actors abusing Teams across the entire attack chain
Microsoft warns adversaries are weaponizing Teams features for everything from reconnaissance and initial access to data exfiltration. Redmond recommends tightening external access, enforcing strong identity controls, hardening endpoints, and adding DLP and network policies to blunt Teams-enabled intrusion paths.
Source: Microsoft Security Blog
“Hidden text salting” via CSS helps phishing evade email AI detection
Cisco Talos highlights a rising evasion tactic where attackers hide “salted” text in messages using CSS, fooling ML- and LLM-based email filters while preserving human readability. Defenders should normalize/strip styling, flag hidden or off-screen text, and tune models to detect salting patterns in inbound mail.
Source: Cisco Talos
You May Also Be Interested In...
Polymorphic Python malware spotted with self-modifying codeOpenAI disrupts state-linked actors misusing ChatGPT for cyberattacks
Researchers: Y2K38 is an exploit vector today for ICS and devices