A maximum-severity flaw in React Server Components (CVE-2025-55182, “React2Shell”) is being actively exploited within hours of disclosure. CISA has added the bug to its Known Exploited Vulnerabilities catalog, compelling rapid patching. Organizations should upgrade to React 19.0.1/19.1.2/19.2.1 and the latest affected framework versions, and deploy WAF rules and enhanced logging around suspicious Flight protocol requests.
Source: The Hacker News
CISA: China-linked ‘BRICKSTORM’ backdoor enables long-term persistence in US networks
US organizations are warned that Warp Panda has used BRICKSTORM, along with Junction and GuestConduit, to persist in VMware vSphere and Windows environments. The campaign abuses vCenter and edge devices, emphasizing the need to audit hypervisor admin paths, harden management interfaces, and hunt for stealthy persistence mechanisms.
Source: SecurityWeek
Leaks show Intellexa burning zero-days to keep Predator spyware effective
New reporting details how Intellexa sustained Predator spyware operations by acquiring and deploying high-value zero-days, allowing infections to bypass platform protections. The revelations highlight the ongoing commercialization of exploitation against civil society and government targets, underscoring the need for rapid patching and device hardening.
Source: Malwarebytes Labs
Record 29 Tbps DDoS attack mitigated as Aisuru botnet peaks at 14.1 Bpps
Cloudflare reports the largest recorded DDoS to date, with Aisuru surging to 29 Tbps and 14.1 billion packets per second. The event underscores escalating volumetric attacks and the need for resilient anycast architectures, automated mitigation pipelines, and L7 rate limiting and anomaly detection.
Source: SecurityWeek
Apache Tika hit by critical XXE (CVE-2025-66516) impacting core, PDF, and parser modules
A CVSS 10.0 XXE flaw in Apache Tika could enable data exfiltration, SSRF, or worse through crafted files such as PDFs with malicious XFA. Because Tika often sits in ingestion pipelines for search, e‑discovery, and analytics, organizations should patch immediately, sandbox parsers, and review content-processing exposure.
Source: The Hacker News
JPCERT/CC: Array Networks AG gateway flaw under widespread exploitation since August
A command injection bug affecting Array Networks AG Series DesktopDirect, patched in May 2025, has been actively exploited since August. Unpatched edge gateways risk remote command execution and internal pivoting—prioritize updates, rotate credentials, and review logs for post-exploitation activity.
Source: Security Affairs
Trump’s national security strategy tasks spy agencies with watching global supply chains
The new strategy prioritizes the Western Hemisphere and calls for deeper cyber collaboration with regional partners and the private sector. Expanded intelligence focus on supply chains signals more public‑private information sharing and potential impacts on procurement security baselines.
Source: Nextgov/FCW
You May Also Be Interested In...
Novel clickjacking attack relies on CSS and SVG
AutoIT3 Compiled Scripts Dropping Shellcodes
North Korean hacker infected by malware, exposing ties to $1.4B Bybit heist