A newly disclosed vulnerability in the open-source workflow automation platform n8n could let an authenticated attacker execute arbitrary system commands on the host. Organizations should update immediately, restrict who can create/modify code nodes, and review logs for unusual command execution to reduce blast radius.
Source: The Hacker News
IBM API Connect hit by critical auth bypass (CVE-2025-13915, CVSS 9.8)
Singapore’s cyber agency and IBM warned of a critical authentication bypass in IBM API Connect that enables remote, unauthorized access without credentials. Interim fixes (iFixes) are available for affected versions (including 10.0.8.0–10.0.8.5 and 10.0.11.0); IBM also advises disabling developer portal self-service sign-up where patching can’t be immediate. No in-the-wild exploitation has been reported yet.
Source: Cyble
Kimwolf Android botnet surges past 2 million devices via residential proxies
The Kimwolf botnet is leveraging exposed Android surfaces and residential proxy networks to amass more than 2 million compromised devices. Operators monetize through DDoS-for-hire, app installs, and selling proxy bandwidth—blurring consumer and criminal traffic and complicating detection for enterprises.
Source: SecurityWeek
Phishing campaign abuses Google Cloud Application Integration to bypass defenses
Attackers are exploiting Google Cloud’s Application Integration features to deliver convincing phishing flows through trusted infrastructure. Because the traffic routes through legitimate cloud services, traditional email and URL filters are more easily evaded, underscoring the need for granular cloud app controls and identity-aware inspection.
Source: SC Magazine
‘Blue Screen of Death’ lure hits Europe’s hospitality sector
A Russian-linked campaign impersonates a major booking platform to send fake reservation cancellations, then pushes victims into downloading malware via an error prompt and a fake BSOD page. Hotels and travel businesses should verify cancellations within the booking platform, harden email defenses against brand impersonation, and sandbox suspicious attachments.
Source: The Record
CISA’s KEV list grew 20% in 2025 to 1,484 entries; ransomware exploited 24 new bugs
CISA expanded the Known Exploited Vulnerabilities catalog by 20% last year, adding 1,484 total flaws, including two dozen newly tied to ransomware operations. Security teams should align patching SLAs and validation with the KEV list to prioritize fixes for what adversaries are actively weaponizing.
Source: SecurityWeek
EU signals potential action against X after Grok generated sexualized images of a minor
The European Commission is examining whether to take enforcement action against X following an incident where its Grok AI tool created sexually explicit images of a minor. The move highlights growing regulatory scrutiny of generative AI guardrails and platform accountability when safety systems fail.
Source: The Record
You May Also Be Interested In...
NordVPN denies breach after hacker posts purported data
New VVS Stealer malware targets Discord accounts via obfuscated Python code
UK launches £210M Government Cyber Action Plan to raise Whitehall’s security baseline