Attackers are exploiting two critical authentication bypass flaws (CVE-2025-59718, CVE-2025-59719) in FortiGate appliances just days after disclosure, enabling malicious SAML SSO logins without valid credentials. CISA has added at least one to its Known Exploited Vulnerabilities catalog. Urgently apply Fortinet patches, audit SSO logs for anomalous sign-ins, rotate admin/API credentials, and review downstream trust with IdPs.
Source: SecurityWeek
GRU shifts to misconfigurations to target critical infrastructure, Amazon warns
Russian state-backed operators are increasingly abusing misconfigured network edge and cloud-hosted devices rather than burning zero-days, with years-long activity hitting energy and other critical sectors. The pivot lowers attacker cost and defender visibility, emphasizing hardening, external attack surface management, and configuration drift control across OT/IT boundaries.
Source: The Record by Recorded Future
China-linked “Ink Dragon” expands into Europe, uses victims as relay nodes
Check Point says the Ink Dragon espionage group (aka Earth Alux/REF7707) moved from Asia and South America into European government networks, co-opting compromised servers as covert relays. A new FINALDRAFT variant blends into Microsoft cloud activity to persist, and overlapping exploitation with other actors shows how single perimeter flaws can draw multiple APTs.
Source: Check Point Research
Study: Most parked domains now funnel users to scams and malware
Direct-navigation “parked” domains—expired holdings and typosquats—are increasingly weaponized to auto-redirect visitors into scam pages and malicious downloads. The shift turns casual URL guessing into a high-risk behavior; organizations should step up domain monitoring/defensive registrations and users should favor bookmarks or search over typed guesses.
Source: KrebsOnSecurity
GhostPoster: 17 Firefox add-ons hid malware in icon files, 50,000+ installs
Researchers uncovered a campaign that embedded malicious JavaScript inside extension logo assets across 17 Mozilla add-ons, hijacking affiliate links, injecting iframes, stripping security headers, and committing ad/click fraud. The extensions have been pulled, but users should review installed add-ons, remove unknown publishers, and rotate credentials if affected.
Source: The Hacker News
AWS: Ongoing crypto-mining campaign abusing compromised IAM credentials
GuardDuty detected an operation starting Nov. 2 targeting Amazon EC2/ECS via stolen IAM creds, adding novel persistence and evasion tactics to sustain illicit mining. AWS urges credential rotation, least-privilege IAM, service control policies, and continuous monitoring with GuardDuty/CloudTrail to spot anomalous resource launches and network patterns.
Source: AWS Security Blog
SoundCloud breach exposes emails for 20% of users amid follow-on DoS
SoundCloud confirmed a breach in which attackers accessed user email addresses for roughly one-fifth of its user base, warning of likely phishing waves. The platform also weathered denial-of-service attacks and made temporary configuration changes that affected some VPN traffic while mitigation was underway.
Source: SecurityWeek
You May Also Be Interested In...
Microsoft will finally kill RC4 for admin auth after decades of abuse
Rapid7 unwraps new SantaStealer malware-as-a-service
Popular Chrome extension caught harvesting AI chatbot prompts