A recently patched flaw in Microsoft Windows Server Update Services (WSUS), tracked as CVE-2025-59287, is being actively exploited to push ShadowPad malware. Attackers target WSUS-enabled Windows servers to gain full system access and distribute payloads, underscoring the risk of compromised update channels. Admins should patch immediately, audit WSUS configurations, and scrutinize update logs for anomalies.
Source: TheHackerNews
Cox confirms Oracle EBS breach as hackers dump 1.6 TB and name 100 alleged victims
Cox acknowledged that its Oracle E‑Business Suite environment was compromised, with more than 1.6 terabytes of data allegedly stolen and published by attackers. The crew behind the intrusion also named 100 alleged victims, signaling a broader campaign. Impacted organizations should review Oracle EBS exposure, rotate credentials, and check for unauthorized data access.
Source: SecurityWeek
SonicWall warns of SSLVPN bug (CVE-2025-40601) that can crash Gen7 and Gen8 firewalls
A high‑severity buffer overflow in SonicOS SSLVPN, CVE‑2025‑40601 (CVSS 7.5), allows remote attackers to crash SonicWall Gen7 and Gen8 firewalls. SonicWall urges immediate patching to prevent denial-of-service and potential cascading outages across perimeter devices.
Source: Security Affairs
Critical 7‑Zip flaw with public exploit requires manual update to v25.01
A critical vulnerability in 7‑Zip (CVE‑2025‑11001) now has a publicly available exploit, and fixes are only available via a manual update to version 25.01. Given 7‑Zip’s ubiquity in enterprise tooling and user endpoints, teams should prioritize the upgrade and validate that automated updaters haven’t left older builds in place.
Source: HackRead
Shai‑Hulud 2.0: Malicious npm packages fuel ongoing supply chain attack
Wiz reports an active campaign distributing malicious npm packages in a Shai‑Hulud–style operation impacting organizations including Zapier and ENS Domains. Teams should immediately inventory and audit dependencies, pin trusted versions, and remove suspect packages across projects and build systems.
Source: Wiz
FCC scraps telecom cyber rules introduced after ‘Salt Typhoon’ espionage campaign
The FCC has terminated cybersecurity requirements for U.S. telecommunications providers that were enacted in response to the Salt Typhoon nation‑state exploit. The rollback arrives amid persistent China‑linked activity against networks, raising concerns about baseline protections and incident preparedness across carriers.
Source: InfosecurityMagazine
Report: CVE/NVD delays and inconsistencies are undermining vuln management
Sonatype’s new analysis warns that the CVE program and the NVD no longer provide the consistency and speed the modern software ecosystem requires. With scoring and enrichment lagging the pace of change, security teams should augment official feeds with vendor advisories, exploit intel, and SBOM‑driven context to prioritize remediation.
Source: Help Net Security
You May Also Be Interested In...
Wireshark 4.6.1 fixes 2 vulnerabilities and 20 bugs
Operation Endgame disrupts Rhadamanthys, VenomRAT, and Elysium infrastructure
Research: DeepSeek-R1 AI generates more insecure code on politically sensitive prompts