ESET researchers uncovered a network implant used by the PlushDaemon APT to perform adversary‑in‑the‑middle attacks by redirecting DNS on compromised routers and other gear. The operation hijacks software update traffic to attacker‑controlled infrastructure, creating a stealthy path to deploy malware at scale. Security teams should lock down egress DNS, audit network devices for unauthorized config changes, and verify update channels via certificate pinning and allowlists.
Source: ESET Blog
Stealth‑patched FortiWeb flaw under active exploitation (CVE‑2025‑58034)
Fortinet confirmed in‑the‑wild exploitation of an OS command injection bug in FortiWeb that was fixed without prior public disclosure. The vulnerability allows authenticated attackers to execute unauthorized code via crafted HTTP requests or CLI commands and is the second exploited FortiWeb zero‑day disclosed in a week. Patch immediately and review appliance logs for anomalous admin activity and suspicious command execution.
Source: Help Net Security
7‑Zip RCE (CVE‑2025‑11001) is being actively exploited
NHS England warns that attackers are exploiting a high‑severity path traversal bug in 7‑Zip to achieve remote code execution. The flaw, introduced in v21.02, is fixed in 7‑Zip v25.00; a related directory traversal (CVE‑2025‑11002) was also addressed. Organizations should upgrade to 25.00+ across endpoints, hunt for suspicious archive extraction activity, and restrict execution from temp/unpack locations.
Source: Help Net Security
Operation “WrtHug” hijacks tens of thousands of EoL ASUS routers
A global campaign dubbed WrtHug is exploiting multiple ASUSWRT flaws to compromise more than 50,000 end‑of‑life ASUS routers, largely in Taiwan, the U.S., and Russia. Researchers say the botnet appears geared toward stealthy cyber‑espionage, highlighting the systemic risk of unmanaged consumer and SMB edge devices. Replace unsupported routers, disable remote administration, and isolate/home‑office gear from corporate networks.
Source: The Hacker News
Amazon details “cyber‑enabled kinetic targeting” by Iran‑linked actors
Amazon threat intelligence documented cases where Iranian groups used cyber operations to map targets and enable real‑world missile strike attempts. The findings underscore the blurring line between state cyber activity and physical conflict, with commercial sectors like shipping, transportation, and electronics caught in the crossfire. Organizations with OT, maritime, or logistics exposure should elevate threat modeling, tighten telemetry around AIS and other operational data, and rehearse cross‑domain incident response.
Source: SecurityWeek
Cloudflare outage doubles as an unplanned security “roadmap”
A widespread Cloudflare incident briefly took top sites offline and forced some customers to bypass the platform—exposing origins directly to the internet. As Krebs notes, the failover acted like an impromptu penetration test for organizations that lean on Cloudflare to absorb DDoS and filter abuse. Teams should harden origin infrastructure, plan for equivalent protection during CDN/CDN‑WAF failover, and test fail‑open vs. fail‑closed behaviors.
Source: KrebsOnSecurity
US and allies sanction Russian bulletproof hosting used by ransomware gangs
The U.S., U.K., and Australia sanctioned Media Land and related entities accused of providing “bulletproof” hosting to ransomware operations, including LockBit and BlackSuit. The action targets infrastructure that underpins extortion and data theft, increasing compliance pressure on organizations to avoid tainted services. Security teams should update blocklists, scrutinize provider dependencies, and monitor for connections to sanctioned networks.
Source: Recorded Future News (The Record)
You May Also Be Interested In...
Google addresses Chrome zero‑day leveraged in attacks
Two‑year‑old Ray AI framework flaw exploited in ongoing campaign