Fortinet says a five-year-old FortiOS SSL VPN flaw is seeing “recent abuse” in the wild. Under certain configurations, attackers can log in without being prompted for a second factor, undermining MFA protections on exposed VPN portals. Organizations should audit SSL VPN settings, upgrade to fixed releases, and enforce true MFA for all remote access.
Source: The Hacker News
High-severity MongoDB bug (CVE-2025-14847) could enable server takeover
MongoDB patched a high-severity vulnerability (CVSS 8.7) that could allow unauthenticated remote code execution on vulnerable servers. The flaw involves the server’s zlib implementation and may expose uninitialized heap memory as part of exploitation. Admins should apply vendor updates immediately and limit public exposure of database services.
Source: Security Affairs
Critical RCE in n8n automation platform may affect 100,000+ servers
A CVSS 9.9 vulnerability in the open-source n8n automation tool allows an authenticated attacker to execute arbitrary code with elevated permissions. Given n8n’s popularity in self-hosted workflows, the blast radius could be significant if internet-exposed instances lack hardening. Patch promptly, restrict admin interfaces, and rotate credentials and tokens integrated with n8n.
Source: SC Media
Popular “Urban VPN” Chrome extension caught intercepting AI chats
Research shows the Urban VPN Proxy extension quietly captures conversations across leading AI platforms (ChatGPT, Claude, Gemini, Copilot, Perplexity, and more). Data harvesting is enabled by default, cannot be disabled via settings, and runs regardless of VPN connectivity—uninstalling is the only mitigation. The case underscores rising risks from malicious or over-permissive browser extensions.
Source: Schneier on Security
FBI and DOJ dismantle $14.6M bank credential theft operation
US authorities shuttered a platform used to hoard stolen banking passwords and facilitate large-scale account takeovers. The takedown highlights how industrialized credential theft ecosystems fuel direct financial fraud, often via malvertising and phishing. Enterprises should bolster brand monitoring and takedown processes, tighten email/web defenses, and enforce strong MFA at login.
Source: The Register
ServiceNow to acquire Armis for $7.75B to build AI-native exposure management
ServiceNow will buy Armis in a cash deal aimed at unifying asset intelligence, risk prioritization, and automated remediation across IT, OT, IoT, and medical devices. The move signals further consolidation around AI-driven security workflows and exposure management, promising tighter detection-to-response integrations for large enterprises.
Source: Help Net Security
DDoS knocks France’s La Poste offline; pro-Russian group claims responsibility
Central systems at La Poste were disrupted by a DDoS attack, impacting digital banking and online services for millions. The incident, claimed by pro-Russian hackers, underscores continuing pressure on critical national services and the need for resilient DDoS protection and rapid failover plans.
Source: SecurityWeek
You May Also Be Interested In...
OpenAI admits prompt injection is here to stay as enterprises lag on defenses
Official Google domain exploited in sweeping phishing campaign
National security worries prompt FCC prohibition of foreign drones