Cisco confirmed active exploitation of CVE-2025-20393 (CVSS 10.0) in Secure Email Gateway and Secure Email/Web Manager, enabling attackers to execute commands with root privileges. The activity, attributed to China-linked actors, underscores the risk of management-plane exposure; organizations should apply Cisco’s latest advisories, restrict management interfaces, and hunt for post-exploitation indicators immediately.
Source: SecurityWeek
HPE OneView CVSS 10.0 unauthenticated RCE threatens data center control planes
HPE patched CVE-2025-37164, a maximum-severity flaw allowing unauthenticated remote code execution on OneView versions prior to 11.0. Rapid7’s analysis indicates the hotfix blocks a publicly reachable endpoint (/rest/id-pools/executeCommand), reinforcing urgency to upgrade or hotfix and to treat OneView as an assumed-breach target given its centralized control over servers and firmware.
Source: Rapid7
UEFI flaw enables early-boot DMA attacks on major motherboard vendors
Researchers disclosed a vulnerability affecting select ASRock, Asus, Gigabyte, and MSI motherboards that permits early-boot DMA attacks, bypassing IOMMU protections before the OS and many security tools are active. Organizations should apply vendor firmware updates as released, enforce Secure Boot and kernel DMA protection, and limit untrusted peripherals in sensitive environments.
Source: SecurityWeek
Microsoft 365 device code phishing bypasses MFA via OAuth abuse
Proofpoint observed attackers abusing Microsoft’s OAuth 2.0 device authorization grant to trick users into entering device codes that grant access tokens, enabling account compromise without stealing passwords. To mitigate, disable the device code flow where unnecessary, tighten Conditional Access, monitor and revoke suspicious OAuth grants, and require reconsent for risky applications.
Source: Help Net Security
“ClickFix” copy-paste attacks deliver StealC infostealer and Qilin ransomware
Sophos warns that fake “I am not a robot” human-verification pages coax users into copying and running malicious scripts, leading to StealC and later-stage ransomware. Defenses include browser and email hardening, disabling PowerShell/Script execution for standard users, application control, and user training focused on copy-paste–based social engineering.
Source: Naked Security (Sophos)
LongNosedGoblin APT abuses Group Policy to deploy espionage tools in Asia
ESET uncovered a China-aligned group, LongNosedGoblin, leveraging Windows Group Policy to distribute malware across government networks in Southeast Asia and Japan for long-term surveillance. Admins should audit GPO changes, restrict who can edit GPOs, enable change-control and signing where possible, and increase domain controller telemetry to catch policy-based lateral movement.
Source: ESET
North Korea tops crypto theft again: $2B stolen in 2025 as fake IT worker schemes multiply
Chainalysis data shows DPRK-linked groups stole roughly $2.02 billion in cryptocurrency this year, increasingly targeting large-scale services for maximum payout. Amazon separately blocked 1,800 suspected North Korean “IT worker” accounts, highlighting dual threats of direct theft and workforce infiltration; crypto and tech firms should tighten vendor onboarding and workforce verification controls.
Source: SecurityWeek
You May Also Be Interested In...
SonicWall Patches Exploited SMA 1000 Zero-Day