Attackers are exploiting CVE-2025-14847 (“MongoBleed”), a critical memory-leak flaw in MongoDB’s zlib-based network compression, to expose secrets from server memory. More than 87,000 internet-exposed instances could be compromised as intrusions continue, underscoring the urgency of patching and reducing exposure of management interfaces.
Source: SC Media
Mustang Panda deploys signed kernel-mode rootkit to stealthily load TONESHELL
Kaspersky researchers observed Chinese APT Mustang Panda using a signed kernel driver containing user‑mode shellcode to deploy a new TONESHELL backdoor variant. The technique improves stealth and persistence, signaling continued escalation in driver-based tradecraft in espionage operations.
Source: SecurityWeek
Official EmEditor download button abused in software supply chain attack
The EmEditor website’s “download” button briefly served a malicious installer delivering an infostealer, turning a trusted update path into an infection vector. The incident highlights how small compromises in web distribution can ripple into large-scale compromise for software users.
Source: SecurityWeek
Evasive Panda used DNS poisoning to install MgBot backdoor
A China-linked APT leveraged DNS poisoning to intercept requests and quietly deliver the MgBot backdoor to targets in Türkiye, China, and India. The campaign shows how subverting name resolution can bypass perimeter defenses and deliver payloads without traditional phishing.
Source: Security Affairs
Air-gapped embedded devices can still “hear” radio commands, study warns
New research demonstrates that even embedded devices without radios or sensors can receive wireless commands once an attacker gains code execution, eroding assumptions about air-gap safety. The finding raises the stakes for hardware and firmware hardening and tight control over what code runs on critical systems.
Source: Help Net Security
Old FortiOS bug resurfaces: attackers bypass 2FA via CVE-2020-12812
Fortinet reports fresh exploitation of a 2020 FortiOS flaw that allows bypassing two-factor authentication, reminding defenders that long-patched issues remain potent when systems lag behind. Organizations should verify patch status and review access logs for suspicious authentications.
Source: SecurityWeek
Aflac breach impacts 22 million, exposing highly sensitive personal and medical data
Aflac is notifying roughly 22 million people after attackers stole names, addresses, Social Security and ID numbers, and medical and health insurance information. The scope and sensitivity of the data elevate risks of identity theft and fraud, with downstream compliance and notification obligations likely to follow.
Source: SecurityWeek
You May Also Be Interested In...
CISA adds MongoBleed to Known Exploited Vulnerabilities catalogNon-human identities push identity security into uncharted territory
French software company fined $2 million for cyber failings leading to data breach