Threat actors exploited a recently patched Cisco IOS/IOS XE vulnerability to deploy Linux rootkits on network devices, according to Trend Micro research. The operation set a “universal password” containing the string “disco” and hooked the IOSd process memory to hide fileless components after reboot, focusing on older Linux-based systems lacking EDR. Immediate patching, config audits for unauthorized accounts, and forensic checks for IOSd hooks are advised.
Source: Help Net Security
Microsoft revokes 200 code-signing certs abused to ship malicious “Teams” installers
Microsoft dismantled a Vanilla Tempest campaign that used 200+ stolen/abused software-signing certificates to legitimize fake MSTeamsSetup.exe downloads hosted on look‑alike domains (e.g., teams-download[.]buzz). Lures driven by SEO poisoning delivered malware used in ransomware operations such as Rhysida. Defenders should block identified domains, verify signer trust chains, and enforce application control to prevent sideloaded installers.
Source: Help Net Security
Actively exploited CVSS 10 flaw in Adobe Experience Manager Forms added to CISA KEV
A critical Adobe Experience Manager Forms vulnerability (CVE-2025-54253) enabling authentication bypass and remote code execution is being exploited in the wild. With the bug now on CISA’s KEV list, agencies and enterprises should prioritize patching, review exposed AEM endpoints, and hunt for post‑exploitation webshells and anomalous admin actions.
Source: SC Magazine
Zendesk email-bombing wave abuses lax authentication to deluge targets
Criminals are exploiting weak authentication across many organizations’ Zendesk instances to send coordinated floods of harassing emails that appear to originate from legitimate corporate customers. The attack both overwhelms inboxes and can mask concurrent fraud. Organizations should harden ticket-creation controls, require verification, rate‑limit and filter inbound tickets, and coordinate with Zendesk on authentication settings.
Source: KrebsOnSecurity
Envoy Air confirms compromise tied to Oracle E-Business Suite targeting
Regional carrier Envoy Air said its IT environment was impacted amid a broader hacking campaign against Oracle E-Business Suite. The incident underscores ongoing exploitation of Oracle EBS vulnerabilities; organizations should urgently apply vendor fixes, follow CISA KEV guidance where applicable, and review EBS integrations and logs for lateral movement.
Source: The Record
Microsoft flags Russia and China’s growing use of AI to scale attacks on U.S. targets
Microsoft reports that Russia and China are increasingly using AI to boost the speed, scale, and sophistication of cyber operations against U.S. public and private sectors. Expect more convincing spear‑phishing, content generation, and automated reconnaissance. Defenders should strengthen identity protections, phishing-resistant MFA, and content-authenticity checks while tuning detections for AI‑assisted tradecraft.
Source: SecurityWeek
Microsoft assigns ‘highest ever’ severity to ASP.NET Core request smuggling flaw (CVE-2025-55315)
A severe HTTP request smuggling vulnerability in ASP.NET Core can lead to information leakage, file content tampering, and server crashes, earning what Microsoft called its “highest ever” severity score. Organizations should apply patches immediately, consider interim WAF rules for smuggling patterns, and review reverse‑proxy and load balancer configs for inconsistent parsing behaviors.
Source: SecurityWeek
You May Also Be Interested In...
European police bust network selling thousands of phone numbers to scammers