A maximum‑severity bug (CVE-2025-55182) in React Server Components can enable unauthenticated remote code execution in affected apps, including popular frameworks like Next.js. Researchers warn in‑the‑wild exploitation is likely; however, impact is limited to instances using a newer RSC feature. Organizations should patch React and framework updates immediately, review server function exposure, and rotate secrets possibly exposed via server actions.
Source: SecurityWeek
Cloudflare blocks record 29.7 Tbps DDoS from AISURU “botnet‑for‑hire”
Cloudflare mitigated the largest recorded DDoS attack at 29.7 Tbps, traced to the AISURU botnet that has fueled a series of hyper‑volumetric attacks. The 69‑second blast underscores growing access to turnkey DDoS services and the need for always‑on network‑layer protection, automatic traffic engineering, and upstream coordination with providers.
Source: The Hacker News
Shai Hulud 2.0 npm worm adds wiper capabilities; mass secret leakage follows
Kaspersky reports a new Shai Hulud 2.0 variant propagating via npm with added “wiper” functionality alongside its supply‑chain worming behavior. Follow‑on reporting shows hundreds of thousands of unique secrets exposed from compromised repos, highlighting the urgency of tightening package publishing controls, pinning dependencies, and enforcing CI/CD signing and secret scanning.
Source: Securelist (Kaspersky)
Oracle E‑Business Suite campaign hits universities; more victims expected
The University of Pennsylvania and the University of Phoenix disclosed data breaches tied to a broader campaign exploiting Oracle E‑Business Suite, with threat actors exfiltrating sensitive data at scale. The incidents reinforce third‑party/ERP risk: EBS customers should apply vendor fixes, monitor for anomalous ERP access, and validate segmentation and egress controls.
Source: SecurityWeek
Mercenary spyware vendor Intellexa continues prolific zero‑day use despite sanctions
Google’s Threat Intelligence Group details Intellexa’s sustained zero‑day exploitation (15 unique 0‑days since 2021) and novel delivery tactics, including malicious ads for fingerprinting and exploit delivery. Google issued government‑backed attack warnings to hundreds of targets and added indicators to Safe Browsing; at‑risk orgs should harden mobile fleets, accelerate patching, and consider high‑risk protections like iOS Lockdown Mode.
Source: Google Cloud Threat Intelligence
Sprawling Indonesian gambling network moonlights as hidden C2/anonymity service
Researchers uncovered a 14‑year‑old infrastructure spanning 328,000+ domains—including tens of thousands of hacked sites and hijacked subdomains, some on government domains—used for illegal gambling, malware delivery, and likely command‑and‑control and anonymity services. The scale and longevity suggest durable adversary infrastructure; defenders should monitor for traffic to associated domains, enforce strict subdomain controls, and leverage domain takedown where possible.
Source: Help Net Security
Actively exploited Fortinet FortiWeb bugs affect older, unsupported versions too
Recent exploitation of FortiWeb OS command injection (CVE-2025-58034) and path traversal (CVE-2025-64446) extends beyond documented 7.x/8.x releases to older 6.x instances, broadening exposure. Fortinet customers should urgently patch supported versions, isolate or retire unsupported appliances, and audit for indicators of compromise on internet‑exposed WAFs.
Source: SC Media
You May Also Be Interested In...
Microsoft silently mitigated an LNK flaw exploited since 2017
Android Framework bugs added to CISA’s KEV list amid active attacks
CIS, Astrix, and Cequence partner on new AI security guidance