Huntress reports rapid, coordinated logins across more than 100 SonicWall SSL VPN accounts, indicating attackers possess valid credentials rather than brute‑forcing access. Organizations should enforce MFA across all VPN users, rotate credentials, audit recent authentication activity for anomalous patterns, and review device configurations and firmware for hardening.
Source: TheHackerNews
Actively Exploited Zero-Day Hits Gladinet CentreStack and Triofox (CVE-2025-11371)
Threat actors are abusing an unpatched local file inclusion flaw to access sensitive system files on exposed CentreStack and Triofox instances without authentication. Until a vendor fix is available, restrict external access, place instances behind VPN/WAF, monitor for suspicious file access patterns, and apply any temporary mitigations from the vendor.
Source: Security Affairs
New Oracle E‑Business Suite Bug Allows Unauthenticated Network Exploitation (CVE-2025-61884)
Oracle disclosed a remotely exploitable flaw in the Oracle Configurator Runtime UI affecting EBS 12.2.3–12.2.14, allowing unauthenticated exploitation over HTTP. Admins should immediately restrict EBS exposure, enforce network segmentation, apply vendor guidance as released, and monitor for anomalous requests targeting Configurator endpoints.
Source: HelpNet Security
LockBit Operators Weaponize Velociraptor DFIR Tool
Investigators observed threat actors linked to Storm‑2603 using the open‑source Velociraptor DFIR tool during intrusions associated with Warlock and LockBit ransomware. The abuse underscores how “living‑off‑the‑land” now extends to security tooling; defenders should tighten application allowlisting, verify code signing, monitor for atypical DFIR agent activity, and restrict outbound control channels.
Source: TheHackerNews
Wireshark 4.4.10 and 4.6.0 Ship with Security Fix in Mongo Dissector
The latest Wireshark releases fix six bugs and one vulnerability in the MONGO protocol dissector. Users should update promptly and avoid opening untrusted capture files, as dissector flaws can sometimes be triggered by maliciously crafted packets or pcaps.
Source: SANS ISC
CISA Priorities Revisited for FY2026 Under New Leadership
GovTech examines where CISA is heading as a new fiscal year and leadership shifts reshape the agency’s focus. Public‑sector and critical‑infrastructure security teams should watch for updates that signal strategic emphasis and funding direction for resilience, incident response, and risk reduction programs.
Source: GovTech
Spain Dismantles “GXC Team” Cybercrime Ring Selling AI Phishing Kits and Malware
Spain’s Guardia Civil arrested the 25‑year‑old Brazilian leader of the GXC Team, which allegedly sold AI‑powered phishing kits, Android malware, and voice‑scam tools across Telegram and Russian forums. The takedown removes a major supplier of credential‑theft tooling, but defenders should expect rebrands and copycats recycling the same tradecraft.
Source: Security Affairs
You May Also Be Interested In...