Mandiant’s investigation concluded a state-sponsored threat actor accessed SonicWall’s cloud backup environment via API calls and exfiltrated firewall configuration files for all customers who used the service. SonicWall said the incident was isolated to backups and unrelated to Akira ransomware activity. Organizations should assume configuration exposure, rotate credentials/keys, and review firewall/VPN policies that may now be known to attackers.
Source: SecurityWeek
Cisco patches critical UCCX flaws enabling auth bypass and root (CVE-2025-20358, CVE-2025-20354)
Cisco fixed two critical vulnerabilities in Unified Contact Center Express that could let remote attackers bypass authentication, compromise systems, and escalate privileges to root. There are no workarounds and no signs of active exploitation yet, so rapid upgrades to fixed versions are strongly advised.
Source: Help Net Security
Cisco warns of new attack variant battering ASA/FTD firewalls (CVE-2025-20333, CVE-2025-20362)
Cisco disclosed a fresh attack variant hitting Secure Firewall ASA and FTD devices vulnerable to two previously reported flaws, causing unpatched systems to unexpectedly reload (DoS). Admins should urgently apply fixed releases and monitor for abnormal reloads and related attacker activity.
Source: The Hacker News
Russian wipers expand to Ukraine’s grain sector amid broader APT activity
Russian state-aligned groups, including destructive operators, have widened targeting to Ukraine’s grain industry and European countries supporting Kyiv. The campaign features data-wiping attacks and espionage, underscoring continued critical infrastructure risk and spillover potential for regional partners.
Source: SecurityWeek
Chrome 142 fixes high-severity WebGPU flaw that could enable RCE
Google’s Chrome 142 patches multiple high-severity bugs, including an out-of-bounds write in WebGPU (CVE-2025-12725) that could be exploited for remote code execution. Enterprises should prioritize updates for Windows, macOS, and Linux endpoints to close this widely exposed browser risk.
Source: SecurityWeek
US Congressional Budget Office confirms data breach
The Congressional Budget Office said it was hacked and has implemented new security measures following the incident. As the CBO models the economic impact of federal legislation, any compromise raises concerns over exposure of sensitive government data and threat actor interest in policy processes.
Source: SecurityWeek
Researchers chain seven flaws to compromise ChatGPT features and exfiltrate data
Tenable researchers disclosed seven vulnerabilities affecting ChatGPT’s Memories and web search features, including issues impacting the latest GPT model. The findings show how model extensions can become a data exfiltration path; security teams should limit connectors, enforce least privilege, and audit AI tool permissions.
Source: SecurityWeek
You May Also Be Interested In...
Android malware steals your card details and PIN to make instant ATM withdrawals
EU Parliament committee votes to advance controversial Europol data sharing proposal