SonicWall confirmed that attackers exfiltrated firewall configuration backup files from its MySonicWall cloud backup service in early September, impacting all users of the feature. Exposed configs can reveal network architecture and policy details, potentially aiding follow-on attacks. Organizations should rotate credentials and API keys, regenerate VPN/shared secrets and certificates, review and harden policies, and hunt for anomalous changes and connections.
Source: SecurityWeek
Critical Redis “RediShell” RCE in 13‑Year‑Old Lua Path — Patch Immediately
Redis disclosed CVE-2025-49844 (CVSS 10), a use‑after‑free flaw in Lua scripting that allows remote code execution via malicious scripts. Exploitation requires authenticated access, but the ubiquity of Redis and common misconfigurations make this highly risky. Upgrade to patched releases, disable or restrict Lua where possible, harden auth, and isolate Redis instances from untrusted networks.
Source: Security Affairs
Figma MCP Server Vulnerability Enables Remote Code Execution
A command injection vulnerability in the figma-developer-mcp Model Context Protocol server (CVE-2025-53967, CVSS 7.5) could let attackers execute arbitrary code by abusing unsanitized user input. The issue is patched; admins should update immediately, review logs for suspicious commands, restrict network egress for MCP workers, and rotate impacted tokens.
Source: The Hacker News
Actively Exploited Auth Bypass in WordPress Service Finder Theme
Threat actors are exploiting CVE-2025-5947 (CVSS 9.8) in the Service Finder Bookings theme/plugin to bypass authentication and take over any account, including admins. Site owners should apply available fixes or disable the component, audit admin logins and user changes, and restore known-good backups if compromise is suspected.
Source: The Hacker News
Chaos-C++ Ransomware Evolves with Destructive Encryption and Clipboard Hijacking
FortiGuard Labs profiled Chaos-C++, a faster and more capable variant that blends destructive encryption with clipboard hijacking to steal or redirect sensitive data (e.g., cryptocurrency addresses). Expect accelerated dwell-to-impact timelines and broader data theft; harden endpoints with EDR, enforce least privilege, restrict script execution, and maintain offline, tested backups.
Source: Fortinet
LockBit, Qilin, and DragonForce Form Ransomware Alliance
Three prolific crews announced a strategic partnership to share tools and infrastructure, aiming to increase attack velocity and success rates. Defenders should anticipate overlapping TTPs and re-used IOCs across incidents, prioritize patching of high-impact edge vulnerabilities, and strengthen third‑party risk controls and segmentation to blunt blast radius.
Source: The Hacker News
China‑Linked Intrusions Turn Nezha Monitoring Tool into Delivery Mechanism
Huntress observed China‑nexus actors abusing the open-source Nezha monitoring framework to maintain persistence and deliver Gh0st RAT, using log poisoning to plant web shells on vulnerable web apps. Patch and harden internet-facing applications, monitor for anomalous log entries and unexpected Nezha beacons, and isolate management tooling from public access.
Source: Huntress
You May Also Be Interested In...
Exploitation of Oracle EBS Zero‑Day Started 2 Months Before PatchingGermany Slams Brakes on EU’s ‘Chat Control’ Message Scanning
Salesforce Says It Won’t Pay Extortion Demand in Claimed Billion‑Record Breach