SANS honeypots are registering exploit attempts against CVE-2025-64446, signaling rapid attacker adoption following disclosure. If you run FortiWeb, prioritize vendor mitigations and patching, restrict internet exposure of management interfaces, and monitor for anomalous requests hitting FortiWeb endpoints.
Source: SANS ISC
Report: China-linked operators ran a large-scale autonomous AI cyber campaign
Security Affairs reports that China-backed actors leveraged Anthropic’s AI with agentic/autonomous capabilities to automate parts of a September 2025 espionage campaign, moving beyond simple “AI for guidance.” If accurate, this marks an inflection point for fully automated intrusion workflows and reinforces the need for AI-use policies, red-teaming of AI-enabled tools, and detection for high-velocity machine-driven TTPs.
Source: Security Affairs
Leak exposes Chinese hacking contractor’s tools and target lists
A major data leak reportedly sheds light on a Chinese contractor’s offensive toolkits and targeting, offering fresh intelligence on TTPs and infrastructure. Defenders should mine the released indicators for detections, refresh blocklists, and map exposed capabilities to their own attack surface for proactive hardening.
Source: Wired
RondoDox botnet exploiting critical XWiki flaw (CVE-2025-24893) for RCE
Researchers observed the RondoDox botnet targeting unpatched XWiki servers via an eval injection bug (CVSS 9.8) that lets guest users trigger arbitrary code execution through crafted requests. Patch immediately to fixed versions, disable guest access where possible, and add WAF rules to block malicious XWiki paths while monitoring for unusual outbound traffic from wiki hosts.
Source: The Hacker News
Pentagon invests millions in AI agents for offensive cyber operations
Forbes reports the U.S. government is contracting stealth startup Twenty to develop AI agents capable of large-scale automated hacking of foreign targets. The move underscores a rapid shift toward state-backed offensive AI, with direct implications for norms, attribution, and escalation—and for defenders, a need to detect faster, machine-driven attack cycles.
Source: Forbes Security
GoSign Desktop flaws enable remote code execution through insecure updates
Multiple vulnerabilities in Tinexta InfoCert’s GoSign Desktop include disabled TLS certificate validation and an unsigned update mechanism, creating a path for MITM and malicious update delivery. Given its use across public administrations and enterprises, organizations should apply vendor fixes, restrict update endpoints, and monitor for anomalous child processes spawned from the updater.
Source: Security Affairs
ClickFix campaigns abuse Windows finger.exe and the legacy Finger protocol
SANS highlights reports that ClickFix attackers are leveraging the decades-old Finger protocol via finger.exe to retrieve payloads, sidestepping common web/proxy controls. Block outbound traffic on port 79/tcp, add detections for uncommon process execution of finger.exe, and assess egress filtering gaps for legacy protocols.
Source: SANS ISC
You May Also Be Interested In...
DoorDash hit by data breach after an employee falls for social engineering scam
Logitech Data Breach — What We Know As 0-Day Hack Attack Confirmed
Five U.S. Citizens Plead Guilty to Helping North Korean IT Workers Infiltrate 136 Companies