A newly disclosed vulnerability in MongoDB Server, CVE-2025-14847 (“MongoBleed”), allows unauthenticated remote memory disclosure when zlib network compression is enabled. Attackers can potentially leak credentials, session tokens, and sensitive data, with the US, China, and EU among the most targeted regions. Organizations should patch immediately, disable zlib compression where possible, and hunt for suspicious database activity.
Source: Security Affairs
SmarterMail flaw (CVSS 10) enables unauthenticated RCE; Singapore CSA issues alert
Singapore’s Cyber Security Agency warns of CVE-2025-52691, a maximum-severity vulnerability in SmarterMail that permits unauthenticated remote code execution via arbitrary file upload. The ease of exploitation and exposed mail servers make this a high-priority patch. Admins should update immediately, restrict public access to admin interfaces, and monitor for webshell indicators.
Source: Security Affairs
Trust Wallet $8.5M theft tied to Shai-Hulud supply chain compromise
A supply chain attack known as Shai-Hulud exposed Trust Wallet’s developer GitHub secrets, enabling attackers to publish a backdoored browser extension that drained funds from 2,520 wallets. The incident underscores risks from stolen CI/CD credentials and developer tokens, especially in browser extension ecosystems. Teams should rotate secrets, audit extension code paths, and enforce least-privilege automation.
Source: SecurityWeek
European Space Agency confirms breach after hacker offers “200GB” of data for sale
ESA says external science servers were compromised following claims by a threat actor offering a large trove of stolen documents, credentials, and source code. While ESA reports the impact is limited to external systems, the breach highlights ongoing targeting of the space sector and the sensitive research and IP it holds. Incident response and containment efforts are underway.
Source: SecurityWeek
DarkSpectre: Massive malicious browser extension campaigns hit 8.8 million users
Researchers linked the Chinese threat actor “DarkSpectre” to large-scale Chrome, Edge, and Firefox extension campaigns (ShadyPanda, GhostPoster, and DarkSpectre) that exfiltrate data and manipulate browser sessions. The campaigns collectively impacted millions of users worldwide and exploited lax extension governance. Enterprises should restrict extensions, enforce allowlists, and audit installed add-ons across managed endpoints.
Source: The Hacker News
RondoDox botnet hijacks IoT and web servers via React2Shell (CVE-2025-55182) mega-flaw
A nine-month campaign has been enrolling IoT devices and web apps into the RondoDox botnet by abusing the critical React2Shell vulnerability (CVSS 10.0). The operators use the bug as an initial access vector to take over exposed systems at scale. Patch React2Shell immediately, segment IoT networks, and monitor for anomalous outbound traffic indicative of botnet activity.
Source: The Hacker News
Iranian APT ‘Prince of Persia’ retools with three new malware strains for critical infrastructure
SC researchers report that an Iranian state-aligned actor has developed three new malware families and is likely to use them against energy, water, and transportation systems. The renewed toolkit suggests a focus on operational disruption and espionage in the critical infrastructure sector. OT defenders should tighten segmentation, validate logging/alerting in ICS environments, and rehearse incident response playbooks.
Source: SC Media
You May Also Be Interested In...
IBM warns of critical API Connect auth bypass (CVE-2025-13915)
Finland seizes ship suspected of Baltic subsea cable sabotage
Mustang Panda deploys kernel rootkit to stealth TONESHELL malware