Apple shipped emergency updates for iOS, iPadOS, macOS, and Safari to patch CVE-2025-14174 and CVE-2025-43529, WebKit flaws exploited in “extremely sophisticated” attacks. One bug traces back to an ANGLE issue first fixed in Chrome, and both can enable code execution via malicious web content. Patch immediately and consider updating Safari separately on macOS systems that don’t auto‑update the browser.
Source: Help Net Security
React2Shell (CVE-2025-55182) mass exploitation expands to nation‑state actors
Google reports at least five China‑linked clusters—and some Iranian activity—actively exploiting the React2Shell pre‑auth RCE in React Server Components/Next.js. With a CVSS 10.0 and widespread use of affected stacks, attackers are landing initial access quickly; organizations should patch frameworks, comb logs for web shells and anomalous child processes, and review WAF rules for Flight protocol abuse.
Source: SecurityWeek
Fortinet FortiGate authentication bypasses now under active attack
Threat actors began exploiting CVE-2025-59718 and CVE-2025-59719 to perform malicious SSO logins on FortiGate appliances, bypassing authentication in certain configurations. Fortinet customers should patch without delay, audit SAML SSO settings and authentication logs, and consider temporary controls (IP restrictions, MFA enforcement, disable external SSO) where patching lags.
Source: SecurityWeek
Atlassian ships fixes for max‑severity Apache Tika XXE (CVSS 10) across product line
Atlassian released updates for Bamboo, Bitbucket, Confluence, Crowd, Fisheye/Crucible, and Jira to remediate a critical Apache Tika XXE flaw (CVE-2025-66516). Successful exploitation can enable SSRF, sensitive file exposure, or code execution in some parsing paths—teams should update bundled Tika components and ensure content parsing occurs in sandboxed, least‑privileged contexts.
Source: SecurityWeek
AWS ties years‑long critical‑infrastructure intrusions to Russia’s GRU
Amazon Threat Intelligence details a GRU campaign pivoting to misconfigured edge devices as primary initial access, reducing reliance on 1‑day/0‑day exploits. The operation targeted energy, telecom, and tech providers to gain persistent, credentialed access. Defenders should harden and inventory edge devices, remove default creds, restrict management exposure, and continuously monitor for anomalous device‑to‑cloud traffic.
Source: AWS Security Blog
Nearly 20 million impacted in Prosper, 700Credit data breaches
Two finance sector incidents—at fintech Prosper Marketplace and auto‑services provider 700Credit—exposed sensitive PII for close to 20 million people, including SSNs and dates of birth. The events underscore third‑party risk in lending and dealership ecosystems; organizations should revisit vendor due diligence, data minimization, and rapid notification playbooks.
Source: The Record by Recorded Future
New MaaS info‑stealer “SantaStealer” targets credentials and wallets with in‑memory modules
Rapid7 analyzed leaked samples of “SantaStealer,” a malware‑as‑a‑service infostealer rebranded from “BluelineStealer,” featuring in‑memory collection, Chrome ABE credential decryption via a bundled injector, and exfiltration in 10 MB chunks over plaintext HTTP. Despite operator claims of stealth, current builds are noisy—defenders should hunt for clear‑text /upload posts to hard‑coded C2s and apply IOCs provided by researchers.
Source: Rapid7
You May Also Be Interested In...
PayPal closes loophole that let scammers send real emails with fake purchase notices
Cloudflare’s 2025 Internet review: attack clusters, outages, and traffic shifts
SoundCloud confirms breach affecting 20% of users; phishing risk rises