Cisco Talos is tracking UAT-8837, an APT with a China nexus, targeting high-value critical infrastructure across North America. Researchers note credential abuse and exploitation of internet-facing systems, underscoring the need for aggressive patching, segmentation, and monitoring of privileged access in OT/IT environments.
Source: Cisco Talos
Cisco fixes actively exploited Secure Email Gateway zero-day (CVE-2025-20393)
Cisco released patches for a maximum-severity flaw in AsyncOS impacting Secure Email Gateway and Secure Email and Web Manager after confirmed exploitation by a China-linked APT. Organizations should patch immediately, restrict management interfaces from the internet, and audit appliances for post-exploitation indicators.
Source: The Hacker News
Patch now: HPE OneView RCE (CVE-2025-37164) under mass exploitation
Check Point reports large-scale, automated exploitation of a critical remote code execution bug in HPE OneView attributed to the RondoDox botnet, with tens of thousands of attempts blocked. The flaw was added to CISA’s KEV catalog; teams should patch immediately, isolate management interfaces, and monitor for unusual OneView activity.
Source: Check Point Blog
FortiSIEM critical RCE PoC released (CVE-2025-64155) raises urgency
A publicly available proof-of-concept now exists for a critical unauthenticated command injection in FortiSIEM’s phMonitor service, enabling remote code execution via crafted TCP requests. Patch without delay, block/monitor TCP 7900, and review SIEM infrastructure for signs of compromise.
Source: Help Net Security
CodeBreach: AWS CodeBuild misconfiguration posed platform-wide supply chain risk
Wiz detailed “CodeBreach,” a critical AWS CodeBuild configuration issue that could have enabled takeover of AWS-maintained GitHub repositories, potentially endangering downstream customers at scale. AWS addressed the issue in 2025; defenders should harden service roles, enforce least privilege, lock down artifact egress, and continuously validate CI/CD trust boundaries.
Source: Wiz
‘Reprompt’ attack siphons Microsoft Copilot data with a single click
Researchers disclosed a novel one-click attack that bypasses Copilot’s data leak protections to exfiltrate session data—even after a chat is closed. Organizations should treat AI link-handling as untrusted content, enforce browser isolation and safe-link controls, and apply strict data access governance around AI assistants.
Source: SecurityWeek
Microsoft and partners disrupt RedVDS cybercrime infrastructure
Microsoft announced coordinated U.S./U.K. legal action to dismantle RedVDS, a subscription service powering large-scale phishing and fraud tied to significant financial losses. Enterprises should monitor for connections from low-cost VPS providers, enforce MFA for remote access, and block known malicious infrastructure associated with crimeware hosting.
Source: The Hacker News
You May Also Be Interested In...
WhisperPair attack leaves millions of Bluetooth accessories open to hijacking
China bans U.S. and Israeli cybersecurity software over security concerns