MongoDB disclosed a high‑severity bug that allows unauthenticated users to read uninitialized heap memory, potentially exposing sensitive data from affected servers. Admins should patch immediately, restrict network exposure, and audit logs for suspicious access to reduce potential data leakage.
Source: TheHackerNews
Critical LangChain Core vulnerability exposes secrets via serialization injection (CVE-2025-68664)
A critical flaw in langchain-core enables attackers to exfiltrate secrets and manipulate LLM responses via serialization injection and prompt injection paths. Teams building agentic AI apps should upgrade promptly, rotate exposed credentials, and harden integrations that pass untrusted data into toolchains.
Source: TheHackerNews
CISA adds Digiever NVR RCE to Known Exploited Vulnerabilities catalog
CISA added a high‑severity missing-authorization flaw in Digiever DS-2105 Pro network video recorders (CVE-2025-52163) to its KEV list amid active exploitation. Agencies—and any enterprise using these NVRs—should prioritize patching, isolate internet exposure, and monitor for compromise given the devices’ role in physical security.
Source: SCMagazine
Mass compromises hit React/Next.js servers in “Operation PCPcat”
Over 59,000 servers running React frameworks like Next.js were reportedly breached in just 48 hours as part of an automated cyberespionage campaign dubbed Operation PCPcat. The speed and scale highlight the need to patch promptly, review server-side rendering configurations, and rotate exposed API keys and tokens.
Source: SCMagazine
Attackers revive exploitation of old Fortinet FortiOS SSL VPN bug (CVE-2020-12812)
Threat actors are actively exploiting a five-year-old improper authentication flaw in Fortinet FortiOS SSL VPN, underscoring how legacy edge vulnerabilities continue to yield access. Organizations should ensure appliances are upgraded beyond vulnerable versions, enforce MFA, and scrutinize VPN login anomalies.
Source: SCMagazine
Malicious npm package “lotusbail” stole WhatsApp credentials, installed backdoor
Researchers found that the npm package “lotusbail” (a fork of a WhatsApp Web API library) covertly stole WhatsApp credentials, hid activity, and deployed a backdoor—amassing over 56,000 downloads. Teams should remove the package, rotate any affected tokens/sessions, and review dependency hygiene and lockfiles.
Source: Security Affairs
Trust Wallet Chrome extension bug led to ~$7M in losses—update now
Trust Wallet warned users to update its Chrome extension after a security incident impacted version 2.68, contributing to roughly $7 million in losses. Users should upgrade immediately, verify extension integrity, and consider moving funds and revoking risky approvals as a precaution.
Source: TheHackerNews
You May Also Be Interested In...
Advanced NtKiller tool touts antivirus, EDR evasion on dark web
China-linked Evasive Panda used DNS poisoning to deliver MgBot
Aflac confirms June data breach affecting over 22 million customers