Attackers are actively exploiting CVE-2025-54236, a critical improper input validation bug in Adobe Commerce and Magento Open Source, to hijack customer accounts via the REST API. Researchers observed more than 250 attack attempts against multiple stores in 24 hours, underscoring the urgency to patch now, restrict API access, and monitor for anomalous account behavior.
Source: The Hacker News
BIND updates fix cache poisoning flaws that threaten core DNS
ISC released patches for high‑severity vulnerabilities that let attackers predict BIND’s source ports and query IDs, enabling cache poisoning. The bugs risk reviving Kaminsky‑style DNS attacks; admins should update immediately and reinforce defenses with DNSSEC, 0x20 name randomization, and response policy tuning.
Source: SecurityWeek
CISA flags Lanscope Endpoint Manager zero‑day exploited in the wild
A critical Lanscope Endpoint Manager vulnerability (CVE-2025-61932) has been added to CISA’s Known Exploited Vulnerabilities catalog after confirmed in‑the‑wild abuse. On‑prem deployments are affected; organizations should apply vendor fixes, isolate exposed management consoles, and hunt for post‑exploitation activity.
Source: SecurityWeek
Zero‑click Dolby audio bug allows RCE on Android and Windows
A newly disclosed vulnerability in Dolby audio processing (CVE-2025-54957) could enable remote code execution via malicious audio files on Android and Windows devices. Until patches are broadly available, limit playback from untrusted sources, scan email/media attachments, and prioritize vendor updates as they land.
Source: Malwarebytes
TP‑Link Omada gateways patched for critical remote command execution
TP‑Link has issued updates for four severe flaws affecting Omada gateway devices across ER, G, and FR models, including a bug allowing unauthenticated remote command execution. Branch networks and SMBs should upgrade firmware immediately and review WAN exposure and admin access controls.
Source: SecurityWeek
Chinese actors weaponize SharePoint “ToolShell” bug to breach governments
Threat actors linked to China rapidly exploited a recently patched Microsoft SharePoint vulnerability tied to ToolShell, compromising a Middle East telecom and government agencies in Africa and South America. The campaign highlights fast patch-to-exploit cycles—apply July SharePoint fixes, audit for suspicious ToolShell activity, and segment on‑prem collaboration servers.
Source: The Hacker News
Lazarus “DreamJob” resurfaces, targets Europe’s drone and defense sector
ESET uncovered a fresh Operation DreamJob wave by North Korea’s Lazarus Group targeting European defense contractors—particularly firms involved in UAV development—via polished fake job lures. Organizations should harden recruiting workflows, train staff to spot social engineering, and enforce application whitelisting and macro restrictions for candidate documents.
Source: Help Net Security
You May Also Be Interested In...
Canada fines cybercrime-friendly Cryptomus $176MVerizon: Mobile attacks soar as AI-powered threats rise
100+ Chrome extensions abused WhatsApp Web for mass spam