The U.S. Cybersecurity and Infrastructure Security Agency added CVE-2025-61757 (CVSS 9.8) to its Known Exploited Vulnerabilities catalog. The Oracle Fusion Middleware bug stems from missing authentication for a critical function, enabling unauthenticated access; organizations should prioritize patching and apply compensating controls where immediate updates aren’t possible.
Source: Security Affairs
Wireshark 4.6.1 Ships with Fixes for 2 Vulnerabilities and 20 Bugs
The latest Wireshark release resolves two security vulnerabilities alongside 20 additional defects. Network analysts and incident responders should update promptly to reduce the risk of malformed packet crashes or potential info leaks when inspecting untrusted traffic captures.
Source: SANS ISC
China-Linked APT24 Scales Cyberespionage via Supply Chain; “BadAudio” Deployed
Google’s Threat Intelligence Group reports APT24 used supply chain intrusions and varied techniques over three years to deliver the BadAudio downloader and follow-on payloads. The campaign highlights persistent third‑party risk and the need for tighter vendor monitoring, code-signing validation, and EDR visibility across partner integrations.
Source: Security Affairs
APT31 Targets Russian IT Contractors with Stealthy Cloud-Backed Operations
APT31 has been attributed to long-running attacks on Russia’s IT sector, especially contractors and integrators serving government agencies, from 2024 into 2025. The group leveraged cloud services to blend in and remain undetected, underscoring the importance of cloud telemetry, identity controls, and anomaly detection for service-to-service traffic.
Source: The Hacker News
CrowdStrike Fires Insider Who Sold Internal Screenshots to “Scattered Lapsus$ Hunters”
CrowdStrike terminated an employee who allegedly sold internal screenshots for $25,000, with the company stating its security team detected and contained the incident without customer impact. The case is a fresh reminder to enforce least-privilege access, monitor for data exfiltration, and run insider threat programs with rapid investigation playbooks.
Source: HackRead
North Korea’s Latest Ruse: Fake Jobs at Major AI and Crypto Firms
Researchers warn that North Korea is now targeting applicants to high-profile U.S. AI and cryptocurrency companies using convincing fake roles, including posts tied to well-known products. Security teams and recruiters should harden hiring workflows, verify domains and recruiters, and educate candidates on vetting job communications.
Source: CyberNews
Salesforce Warns of Gainsight-Linked Incident Affecting Connected Environments
Salesforce notified customers after detecting unusual activity tied to the Gainsight app across connected environments. The incident spotlights SaaS-to-SaaS supply chain exposure; organizations should review third-party app permissions, rotate tokens, and check audit logs for anomalous API access.
Source: SOCRadar
You May Also Be Interested In...
US Border Patrol Is Spying on Millions of American Drivers
YARA-X 1.10.0 Release: Fix Warnings
Week in review: FortiWeb vuln under active exploitation, Logitech data breach