SonicWall confirmed that threat actors accessed configuration backup files for all customers who used its MySonicWall cloud backup service, reversing earlier estimates that the impact was limited. The files include encrypted credentials and network configuration data, increasing the risk of targeted follow-on attacks. Organizations should rotate device passwords/keys, regenerate VPN certificates, audit access logs, and apply least-privilege hardening across managed firewalls.
Source: SecurityWeek
Oracle E‑Business Suite zero‑day exploited in mass extortion campaign linked to CL0P brand
Google Threat Intelligence and Mandiant detailed a widespread campaign that exploited Oracle EBS (CVE-2025-61882) as early as August 9, deploying multi‑stage Java implants (including a GOLDVEIN-based loader) and later sending extortion emails under the CL0P banner. Oracle issued emergency patches on October 4. Defenders are urged to apply updates immediately, hunt for malicious XDO templates in EBS databases, monitor for suspicious TemplatePreview requests, and restrict outbound internet access from EBS servers.
Source: Google Cloud Threat Intelligence
ZDI discloses 13 unpatched Ivanti Endpoint Manager flaws with RCE and privilege escalation
Trend Micro’s Zero Day Initiative published details on 13 vulnerabilities in Ivanti Endpoint Manager that remain unpatched, several of which could enable remote code execution and privilege escalation. With no fixes available, enterprises should restrict access to management consoles, increase monitoring for exploit attempts, and apply compensating controls such as network segmentation and WAF rules where feasible.
Source: SecurityWeek
Juniper patches more than 200 vulnerabilities in Junos Space and Security Director
Juniper Networks released fixes for over 200 vulnerabilities affecting Junos Space and Junos Space Security Director, including nine rated critical. Left unpatched, organizations risk remote code execution and compromise of central network management infrastructure. Immediate patching and validation of update success across all Space instances is strongly recommended.
Source: SecurityWeek
Ransomware operators co‑opt Velociraptor DFIR tool for covert access and control
Cisco Talos confirmed that ransomware actors are abusing Velociraptor, an open‑source DFIR platform, to establish persistence and maintain covert access during intrusions—marking the first definitive tie of the tool to ransomware incidents. Talos assesses with moderate confidence that Storm‑2603 is involved based on tooling overlaps. Security teams should inventory for unexpected Velociraptor deployments, tighten endpoint execution policies, and monitor for anomalous Velociraptor activity.
Source: Cisco Talos
Discord: 70,000 users’ government IDs exposed via third‑party vendor breach
Discord disclosed that about 70,000 users had ID images submitted for age‑verification exposed after a third‑party service was compromised, disputing larger breach claims by the attackers. The incident underscores growing identity theft risks tied to age‑verification and KYC processes and the importance of vendor due diligence and data minimization.
Source: SecurityWeek
Apple raises bug bounty top award to $2M, with $35M paid to researchers to date
Apple announced a major expansion of its Security Bounty program, introducing new targets and flags and raising the top payout to $2 million for the most severe exploit chains. The move signals growing competition for vulnerability research amid threats like mercenary spyware and aims to channel advanced findings into coordinated fixes.
Source: SecurityWeek
You May Also Be Interested In...
Active exploitation: WordPress Service Finder Bookings plugin auth bypass (CVE-2025-5947)
Senate push to extend cyber info‑sharing law by 10 years
Microsoft: “Payroll pirate” campaign diverts university paychecks