A long-running Windows shortcut vulnerability (CVE-2025-9491, aka ZDI-CAN-25373) continues to be leveraged by state-backed and criminal groups, with recent activity attributed to UNC6384. Active since at least 2017, the bug enables execution via malicious .LNK chains against diplomatic and government targets. With no vendor patch available, defenders should harden against shortcut-borne payloads, restrict script execution, and intensify detection around PowerShell/LNK abuse.
Source: HelpNet Security
Chinese hackers are scanning and exploiting Cisco ASA firewalls worldwide
Unit 42 observed Storm-1849, a China-based threat group, actively targeting Cisco ASA devices used by governments and sensitive organizations around the world. Compromise of perimeter firewalls can provide durable footholds and enable stealthy lateral movement. Patch to fixed ASA releases, limit and monitor management exposure, enforce MFA for VPNs, and scrutinize configs/logs for persistence and traffic manipulation.
Source: RecordedFuture
CISA and partners warn: Exchange on‑prem risks mount after final updates
CISA and the NSA, with international partners, released best practices for securing on‑prem Microsoft Exchange as Microsoft shipped the final security updates for Exchange 2016/2019. Many servers will remain exposed unless organizations restrict admin access, enforce MFA and strict transport security, minimize internet exposure, and accelerate migration or compensating controls.
Source: HelpNet Security
VMware and XWiki bugs added to CISA KEV amid active exploitation
CISA added exploited vulnerabilities in XWiki and Broadcom VMware Tools/VMware Aria Operations (CVE-2025-41244) to its Known Exploited Vulnerabilities catalog, noting in-the-wild attacks. With exploitation tied to sophisticated actors, enterprises should patch immediately, restrict management interfaces, and hunt for suspicious guest/automation activity and anomalous service behavior.
Source: SecurityWeek
Nation-state hackers hid in Ribbon Communications’ network for months
Telecom tech supplier Ribbon said government-backed attackers maintained access to its systems since at least December 2024 before discovery. Given Ribbon’s role across global carrier networks, the incident elevates supply-chain risk for downstream telco and ISP customers. Carriers should review vendor access, rotate credentials and keys, and proactively hunt for shared TTPs.
Source: TechCrunch Security
FCC moves to scrap telecom cyber rules, favoring voluntary commitments
The FCC signaled plans to rescind Biden-era telecom security rulemakings, arguing they were an ineffective response to intrusions like Salt Typhoon. A vote is slated for next month, shifting emphasis toward ISP self-regulation—raising questions about baseline protections for critical communications infrastructure.
Source: ArsTechnica
Ransomware gangs exploit old Linux kernel bug (CVE-2024-1086)
CISA warned that ransomware operators are actively abusing a high-severity Linux netfilter (nf_tables) vulnerability introduced in 2014 and patched in January 2024. Successful exploitation can enable privilege escalation and takeover. Admins should update kernels, consider disabling unprivileged user namespaces, and monitor for anomalous nftables activity and post-exploitation behaviors.
Source: Security Affairs
You May Also Be Interested In...
Cloud Abuse at Scale: TruffleNet BEC campaign abuses AWS SES — Fortinet
Update Chrome now: 20 security fixes just landed — Malwarebytes
Nation-state hackers deploy new Airstalk malware in suspected supply chain attack — The Hacker News