F5 disclosed a long-term intrusion now linked to a China-based actor, with fresh details on attribution and customer risk. The company has issued fixes for impacted BIG-IP components as governments warn organizations to patch, rotate credentials, and monitor for post-compromise activity. Teams should rapidly apply updates and review logs and configuration integrity across BIG-IP estates.
Source: SecurityWeek
Microsoft revokes 200+ certificates abused to sign fake Teams installers in Rhysida campaign
Microsoft invalidated more than 200 code-signing certificates used by the Vanilla Tempest (Vice Society) group to deliver the Oyster backdoor and ultimately deploy Rhysida ransomware via counterfeit Teams installers. Defenders should hunt for maliciously signed binaries, refresh trust stores, and validate application provenance in software deployment workflows.
Source: SecurityWeek
CISA adds actively exploited Adobe AEM Forms bug (CVE-2025-54253) to KEV list
A misconfiguration vulnerability in Adobe Experience Manager Forms (CVE-2025-54253, CVSS 10.0) is under active exploitation, leading CISA to add it to the Known Exploited Vulnerabilities catalog. Adobe patched the flaw in August, but a public PoC helped fuel attacks; organizations should apply fixes, validate configurations, and reduce public exposure of AEM Forms components.
Source: SecurityWeek
DPRK adopts ‘EtherHiding’: malware payloads concealed on Ethereum/BNB smart contracts
Google’s Threat Intelligence Group reports North Korean actor UNC5342 is using EtherHiding to store and retrieve malicious JavaScript from smart contracts, bolstering resilience against domain takedowns. The technique is tied to job-interview social engineering and crypto theft, and leverages centralized blockchain API services—offering defenders potential choke points for blocking and monitoring.
Source: Google Threat Intelligence (Google Cloud)
Cisco SNMP zero-day exploited to plant Linux rootkits on older networking gear
Threat actors are exploiting CVE-2025-20352, a Cisco IOS/IOS XE SNMP stack overflow, to deploy Linux rootkits on legacy and unprotected devices in a campaign dubbed “Operation Zero Disco.” Immediate actions include patching/upgrading, restricting SNMP exposure, and hunting for persistence artifacts on affected routers and switches.
Source: SecurityWeek
Critical WatchGuard Fireware OS bug (CVE-2025-9242) enables unauthenticated remote code execution
A newly disclosed out-of-bounds write in WatchGuard Fireware OS’s IKEv2 implementation (CVE-2025-9242, CVSS 9.3) allows unauthenticated attackers to execute code on vulnerable VPN devices. WatchGuard has issued patches; internet-exposed appliances should be updated urgently and monitored for exploitation attempts.
Source: The Hacker News
Microsoft assigns ‘highest ever’ severity to ASP.NET Core Kestrel request smuggling flaw
CVE-2025-55315 in the Kestrel web server carries a 9.9 “highest ever” severity score from Microsoft, enabling HTTP request smuggling that can lead to information leaks, content tampering, and server crashes. Apply patches immediately and review reverse proxy configurations and application request parsing logic for abuse paths.
Source: SecurityWeek
You May Also Be Interested In...
New Group on the Block: UNC5142 Leverages EtherHiding to Distribute Malware
TikTok Videos Promoting Malware Installation
Microsoft warns of a 32% surge in identity hacks, mainly driven by stolen passwords