The US Cybersecurity and Infrastructure Security Agency added CVE-2025-61884 to its Known Exploited Vulnerabilities catalog, confirming in-the-wild attacks against Oracle EBS. Orgs running EBS should prioritize patching and hardening internet-exposed instances, as KEV inclusion typically signals active targeting and short timelines for remediation.
Source: SecurityWeek
Over 73,000 WatchGuard Firebox devices vulnerable to unauthenticated RCE
A critical flaw in the Fireware OS iked process can enable remote code execution without authentication on WatchGuard Firebox appliances. With more than 73,000 devices impacted, defenders should urgently apply vendor fixes, restrict management exposure, and monitor for anomalous VPN/IKE activity.
Source: SecurityWeek
Windows Cloud Files Minifilter race condition leads to privilege escalation (CVE-2025-55680)
Exodus Intelligence detailed a TOCTOU race in cldflt.sys (Cloud Files Minifilter) that can allow local privilege escalation on Windows. Discovered in March 2024 and patched October 2025, the bug resides in HsmpOpCreatePlaceholders() and underscores the need to deploy the latest Windows updates, especially on multi-user endpoints and VDI hosts.
Source: Exodus Intelligence
China-linked Salt Typhoon attempts intrusion at European telecom operator
Darktrace observed activity consistent with Salt Typhoon (China-linked APT) against a European telco, including DLL sideloading and abuse of legitimate software for stealth and execution. The report highlights the group’s targeting of telecom infrastructure and reinforces the importance of application allowlisting and anomaly-driven detection in sensitive networks.
Source: Help Net Security
Google flags new COLDRIVER malware families using “ClickFix” CAPTCHA lures
Google Threat Intelligence Group reports Russia-linked COLDRIVER rapidly retooled after prior exposure, deploying a chain featuring NOROBOT, YESROBOT, and MAYBEROBOT. The campaign uses a fake CAPTCHA to trick users into executing DLLs via rundll32, with frequent infrastructure and delivery changes to evade detection; Google published IOCs and YARA rules to aid defenders.
Source: Google Threat Intelligence
F5 breach raises alarm over 262,000 exposed BIG-IP systems
Following confirmation that nation-state attackers stole F5 source code and data on undisclosed flaws, Shadowserver found 262,269 BIG-IP devices exposed online. Operators should reduce internet exposure, tighten ACLs, and track vendor advisories closely given the elevated risk of exploits against undisclosed vulnerabilities.
Source: Security Affairs
Court bars NSO Group from targeting WhatsApp users; damages reduced
A US judge issued a permanent injunction preventing NSO Group from targeting WhatsApp users, while reducing punitive damages from $167.3 million to $4 million. The ruling tightens legal constraints on mercenary spyware operations and sets a notable precedent around harms to encrypted platforms and their users.
Source: CyberScoop
You May Also Be Interested In...
PassiveNeuron campaign targets servers with custom implants and Cobalt Strike — Securelist
High-severity Dolby Decoder bug enables potential zero-click attacks on Android — SecurityWeek