Attackers abused customer-managed Gainsight-published applications to access data from Salesforce instances, in a growing supply chain incident tied to the ShinyHunters group. Salesforce and Gainsight have revoked affected tokens and connectors; customers should rotate OAuth secrets, audit connected apps, and review logs for anomalous API calls and data exports.
Source: SecurityWeek
CISA flags Oracle Identity Manager zero-day under active exploitation
CISA added CVE-2025-61757 to its Known Exploited Vulnerabilities catalog, a critical pre-authentication flaw in Oracle Identity Manager that can enable full compromise. Organizations should patch immediately or implement compensating controls by isolating OIM endpoints, tightening access controls, and monitoring for suspicious identity provisioning and admin actions.
Source: The Hacker News
Grafana fixes CVSS 10.0 SCIM bug enabling impersonation and privilege escalation
A maximum-severity vulnerability (CVE-2025-41115) in Grafana’s SCIM implementation could allow attackers to impersonate users or elevate privileges under certain configurations. Admins should upgrade to the patched versions, disable SCIM if not required, and review audit logs for anomalous user provisioning or role changes.
Source: The Hacker News
Thousands of ASUS routers reportedly under control of suspected China-state hackers
Researchers say a China-linked actor has quietly taken control of thousands of ASUS routers and is likely maintaining access for future operations. Network defenders should update firmware, disable remote administration, change credentials, and monitor egress traffic for unusual C2 patterns.
Source: Ars Technica
Chinese APT24 uses “BadAudio” malware in long-running supply chain campaign
APT24 has shifted to more sophisticated vectors, using the BadAudio downloader delivered via supply chain techniques to compromise Windows environments over nearly three years. Once inside, the group deploys additional payloads for persistence and espionage, underscoring the need for third-party risk controls and application integrity checks.
Source: SecurityWeek
New Matrix Push C2 abuses browser notifications for fileless, cross-platform phishing
Adversaries are leveraging a browser-native, fileless command-and-control framework to push malicious links via notifications, fake alerts, and redirects across operating systems. Mitigations include restricting notification permissions by policy, hardening browser settings, and educating users to deny prompts on untrusted sites.
Source: The Hacker News
SEC drops SolarWinds case; industry debates breach disclosure standards
The SEC has voluntarily dismissed its lawsuit tied to the 2020 SolarWinds breach, including charges against the company’s CISO. While the move eases legal pressure on security leaders, experts note continued ambiguity over what constitutes a “material” cyber incident for timely disclosure.
Source: SC Media
You May Also Be Interested In...
CrowdStrike fires ‘suspicious insider’ who passed information to hackers
SonicWall patches high-severity flaws in firewalls and email security appliance
FCC scraps telecom cybersecurity rules, prompting security concerns