Oracle released an out-of-band patch for CVE-2025-61884, an information disclosure bug in E‑Business Suite’s Runtime UI, as organizations grapple with an active extortion campaign exploiting EBS weaknesses. The emergency fix follows weeks of reports tying EBS-targeted breaches and coercive emails to a blend of previously patched issues and likely zero-day techniques, with downstream impact already surfacing at some institutions. EBS customers should apply the update immediately, audit administrative access, and review integrations/exposed interfaces for abuse.
Source: Security Affairs
Attackers rapidly compromise SonicWall SSL VPN accounts across multiple organizations
Threat actors have breached more than 100 SonicWall SSL VPN accounts across over a dozen entities since October 4, underscoring the enduring risk to edge access infrastructure. The campaign highlights gaps in MFA coverage, password hygiene, and monitoring on remote access portals. Organizations should enforce MFA everywhere, rotate credentials, review logs for anomalous logins, and ensure devices run current firmware.
Source: SecurityWeek
175 malicious npm packages and a CDN abused to power large-scale phishing infrastructure
Researchers uncovered a campaign that automated the creation of 175 npm packages and abused the unpkg CDN to host over 630 HTML lures targeting more than 135 industrial and electronics firms. The operation shows how public package ecosystems and their CDNs can be repurposed as disposable phishing delivery networks at scale. Teams should tighten allowlists for developer registries/CDNs, deploy package integrity monitoring, and block known malicious namespaces.
Source: SecurityWeek
Android ‘Pixnapping’ attack can steal on-screen 2FA codes — no permissions, no fix yet
A newly disclosed Android technique dubbed “Pixnapping” lets a malicious app without permissions capture sensitive on-screen content, including one-time passcodes. With a platform fix still pending, users and enterprises should avoid sideloading, restrict Accessibility usage, prefer hardware security keys or app-based authenticators with device-bound protections, and rapidly apply OS updates when available.
Source: Ars Technica
Coordinated probes hit Cisco, Palo Alto, and Fortinet devices from a single subnet
Multiple networking vendors’ edge devices have been targeted by a coordinated campaign originating from the same subnet, pointing to more than random scanning. Consolidated reconnaissance and exploitation against widely deployed appliances raise the risk of multi-vendor footholds. Security teams should prioritize patching ASA/AnyConnect, GlobalProtect, and FortiOS stacks, disable internet-exposed management, and geo-/IP-restrict access where possible.
Source: SC Media
Extortion group posts data from alleged Salesforce-related breaches affecting major brands
An extortion outfit published millions of records purportedly stolen via Salesforce-related intrusions, naming large enterprises across retail, aviation, and energy. The episode underscores third‑party SaaS risks and the need to harden API tokens, connected apps, and identity controls around CRM data. Salesforce customers should audit OAuth apps, enforce least privilege, and monitor for anomalous API usage.
Source: SecurityWeek
Windows 10 nears end of support — still runs on 40%+ of devices
As Windows 10 reaches end of support, more than 40% of devices remain on the aging OS, creating a broad attack surface for unpatched vulnerabilities. Enterprises unable to complete migrations should enroll in Microsoft’s ESU program, accelerate hardware and application readiness plans, and ringfence legacy systems with strict segmentation and application control.
Source: SecurityWeek
You May Also Be Interested In... UK hit by record number of ‘nationally significant’ cyberattacks
Microsoft locks down IE mode after hackers turned legacy feature into a backdoor
Astaroth Trojan uses GitHub images to stay active after takedowns