ZeroHour
Security Affairspublished ()ingested @securityaffairs

Security Affairs newsletter Round 546 by Pierluigi Paganini

criticalRansomware exploited in the wildimportance 60CVE-2025-61884CVE-2025-9242CVE-2025-49844

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2025-49844
Use-After-Free (RediShell) RCE in Redis Lua Scripting

CVE-2025-49844, dubbed "RediShell," is a use-after-free (CWE-416) in Redis's embedded Lua scripting engine that per vendor and press coverage has existed for roughly 13 years in all Redis versions with Lua scripting enabled. An authenticated user triggers it by submitting a specially crafted Lua script (via EVAL/EVALSHA) that manipulates the garbage collector and causes a use-after-free condition. Successful exploitation can lead to remote code execution in the context of the redis-server process; the CVSS 3.1 score of 9.9 (critical) reflects network reachability, low required privileges, and changed scope. Redis versions up to and including 8.2.1 are affected, with 8.2.2 containing the fix, and the CPE data also lists the Valkey fork as affected. No confirmed in-the-wild exploitation is reported (not in CISA KEV), but a public proof-of-concept exists and EPSS assigns an 82.3% probability of exploitation within 30 days (100th percentile).

Do: Upgrade redis-server to version 8.2.2 or later; for Valkey, apply the vendor's corresponding Lua fix when available. If patching is not immediately possible, restrict the EVAL and EVALSHA commands using Redis ACLs so users cannot execute Lua scripts, and verify that any internet-exposed instances require authentication. Review logs for unexpected or anomalous EVAL/EVALSHA usage from authenticated clients.

9.982% PoC
  • Redis All versions with Lua scripting support, up to and including 8.2.1; fixed in 8.2.2
  • LF Projects Valkey
large≈60,000+ internet-exposed Redis servers; total Redis/Valkey deployments including private and cloud-hosted instances are likely in the millions
CVE-2025-61884
Unauthenticated SSRF in Oracle E-Business Suite Configurator

Oracle Configurator, a component of Oracle E-Business Suite, is affected by a server-side request forgery (SSRF) flaw in its Runtime UI component (CVE-2025-61884). The flaw is easily exploitable: an unauthenticated attacker with network access over HTTP can trigger the server to make attacker-controlled requests, compromising Oracle Configurator and gaining unauthorized access to critical data or complete access to all data accessible to Oracle Configurator. The CVSS 3.1 score is 7.5 (high) with confidentiality-only impact, meaning the flaw primarily exposes sensitive data rather than altering or destroying it. All supported Oracle E-Business Suite 12.2.x releases from 12.2.3 through 12.2.14 are affected, and Oracle has issued an emergency security update in response. Exploitation is confirmed in the wild: the flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2025-10-20 with known ransomware use, and EPSS assigns a 97.8% probability of exploitation in the next 30 days (100th percentile).

Do: Apply the fixes from Oracle's emergency security update for CVE-2025-61884 across all E-Business Suite 12.2.3-12.2.14 environments, prioritizing internet-exposed instances; U.S. federal agencies must remediate per BOD 22-01 or follow applicable cloud-service guidance by the KEV due date. Until patched, restrict untrusted network access to the Configurator Runtime UI (HTTP) and monitor EBS logs and outbound server-side requests for signs of exploitation. Given the confirmed ransomware association, hunt for follow-on activity such as unusual data access or lateral movement originating from EBS servers.

7.596% KEV ransomware PoC
  • Oracle E-Business Suite - Oracle Configurator (Runtime UI component) 12.2.3 through 12.2.14
largetens of thousands of enterprise deployments overall; several thousand Oracle E-Business Suite instances exposed to the internet
CVE-2025-9242
Out-of-Bounds Write in WatchGuard Fireware OS iked Enables Unauthenticated RCE

WatchGuard Fireware OS contains an out-of-bounds write (CWE-787) in the iked process that a remote, unauthenticated attacker can trigger to execute arbitrary code on the appliance. The flaw is reachable via the mobile user VPN with IKEv2 and via branch office VPNs using IKEv2 to a dynamic gateway peer; devices whose IKEv2 configurations were deleted may remain vulnerable if a branch office VPN to a static gateway peer is still configured. Successful exploitation yields full system compromise, reflected in the CVSS v4.0 base score of 9.3 (network vector, no privileges or user interaction, high impact on confidentiality, integrity and availability). WatchGuard Firebox appliances with IKEv2 VPN services are affected, with public reporting citing roughly 54,000 internet-exposed Fireboxes; the issue was added to CISA's Known Exploited Vulnerabilities catalog on 2025-11-12, a public proof-of-concept exploit exists, and headlines indicate use in ransomware attacks (KEV ransomware field is listed as unknown). EPSS assigns a 91.3% probability of exploitation within 30 days (100th percentile), so remediation urgency is high.

Do: Apply the patched Fireware OS release per WatchGuard's security advisory immediately (exact fixed version numbers are not provided in the source data); the KEV listing makes BOD 22-01 remediation timelines mandatory for U.S. federal agencies. As an interim mitigation, restrict or disable IKEv2 VPN exposure — mobile user VPN with IKEv2 and branch office VPN IKEv2, including residual static-peer BOVPN configurations on devices that previously had IKEv2 configured — to trusted sources only. Administrators should audit configuration history to identify Fireboxes with prior IKEv2 mobile VPN or dynamic-peer BOVPN setups, since these may remain vulnerable even after the configs were deleted.

9.391% KEV PoC
  • WatchGuard Firebox appliances running Fireware OS (iked process)
large≈54,000 internet-exposed Fireboxes (public scan figure cited in coverage)
Full article917 words · extracted from securityaffairs.com · click to collapse

Pierluigi Paganini October 19, 2025

A new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email box.

Enjoy a new round of the weekly SecurityAffairs newsletter, including the international press.

Winos 4.0 hackers expand to Japan and Malaysia with new malware
From Airport chaos to cyber intrigue: Everest Gang takes credit for Collins Aerospace breach
SIMCARTEL operation: Europol takes down SIM-Box ring linked to 3,200 scams
A critical WatchGuard Fireware flaw could allow unauthenticated code execution
Prosper disclosed a data breach impacting 17.6 million accounts
Microsoft revokes 200+ certificates abused by Vanilla Tempest in fake Teams campaign
PowerSchool hacker got four years in prison
Auction house Sotheby’s disclosed a July data breach
Operation Zero Disco: Threat actors targets Cisco SNMP flaw to drop Linux rootkits
U.S. CISA adds Adobe Experience Manager Forms flaw to its Known Exploited Vulnerabilities catalog
China-linked APT Jewelbug targets Russian IT provider in rare cross-nation cyberattack
U.S. CISA adds SKYSEA Client View, Rapid7 Velociraptor, Microsoft Windows, and IGEL OS flaws to its Known Exploited Vulnerabilities catalog
Spanish fashion retailer MANGO disclosed a data breach
Qilin Ransomware announced new victims
A sophisticated nation-state actor breached F5 systems, stealing BIG-IP source code and data on undisclosed flaw
200,000 Linux systems from Framework are shipped with signed UEFI components vulnerable to Secure Boot bypass
SAP fixed maximum-severity bug in NetWeaver
Unencrypted satellites expose global communications
Flax Typhoon APT exploited ArcGIS server for over a year as a backdoor
Researchers warn of widespread RDP attacks by 100K-node botnet
Harvard University hit in Oracle EBS cyberattack, 1.3 TB of data leaked by Cl0p group
UK NCSC Reports 429 cyberattacks in a year, with nationally significant cases more than doubling
Unverified COTS hardware enables persistent attacks in small satellites via SpyChain
Oracle issued an emergency security update to fix new E-Business Suite flaw CVE-2025-61884
Customer payment data stolen in Unity Technologies’s SpeedTree website compromise
SimonMed Imaging discloses a data breach impacting over 1.2 million people
Microsoft revamps Internet Explorer Mode in Edge after August attacks
Astaroth Trojan abuses GitHub to host configs and evade takedowns
Google, Mandiant expose malware and zero-day behind Oracle EBS extortion
Stealit Malware spreads via fake game & VPN installers on Mediafire and Discord
Clop Ransomware group claims the hack of Harvard University

International Press – Newsletter

Cybercrime

Investigating targeted “payroll pirate” attacks affecting US universities  

Oracle E-Business Suite Zero-Day Exploited in Widespread Extortion Campaign  

Police are asking kids to stop pulling AI homeless man prank 

SimonMed Imaging Data Breach Impacts 1.2 Million 

When the monster bytes: tracking TA585 and its arsenal  

Harvard Is First Confirmed Victim of Oracle EBS Zero-Day Hack  

Qantas confirms cybercriminals released stolen customer data

Qilin Ransomware and the Ghost Bulletproof Hosting Conglomerate  

PowerSchool hacker sentenced to 4 years in prison 

Extortion and ransomware drive over half of cyberattacks 

Microsoft Revokes 200 Fraudulent Certificates Used in Rhysida Ransomware Campaign

Cybercrime-as-a-service takedown: 7 arrested  

Bitcoin worth $14bn seized in US-UK crackdown on alleged scammers  

Malware

Astaroth: Banking Trojan Abusing GitHub for Resilience 

New Rust Malware “ChaosBot” Uses Discord for Command and Control 

New Group on the Block: UNC5142 Leverages EtherHiding to Distribute Malware      

Operation Zero Disco: Attackers Exploit Cisco SNMP Vulnerability to Deploy Rootkits 

Hacking

Pro-Russian hackers caught bragging about attack on fake water utility 

One Token to rule them all – obtaining Global Admin in every Entra ID tenant via Actor tokens  

100,000+ IP Botnet Launches Coordinated RDP Attack Wave Against US Infrastructure  

Eavesdropping on Internal Networks via Unencrypted Satellites  

RMPocalypse  

BombShell: The Signed Backdoor Hiding in Plain Sight on Framework Devices

Data Exfiltration via ChatGPT Agent Mode  

Pixnapping Attack  

yIKEs (WatchGuard Fireware OS IKEv2 Out-of-Bounds Write CVE-2025-9242)  

Intelligence and Information Warfare

SOE-phisticated Persistence: Inside Flax Typhoon’s ArcGIS Compromise 

Taiwan reports surge in Chinese cyber activity and disinformation efforts

Ukraine takes steps to launch dedicated cyber force for offensive strikes     

K000154696: F5 Security Incident 

Weaponizing Perception: China and Russia’s Cognitive Warfare Against Democracies

Jewelbug: Chinese APT Group Widens Reach to Russia

Taiwan flags rise in Chinese cyberattacks, warns of ‘online troll army’   

‘Categorically untrue’ that China hacked UK intelligence systems, say officials  

Italian businessman’s phone reportedly targeted with Paragon spyware 

DPRK Adopts EtherHiding: Nation-State Malware Hiding on Blockchains

Operation MotorBeacon : Threat Actor targets Russian Automotive Sector using .NET Implant  

BeaverTail and OtterCookie evolve with a new Javascript module

Operation Silk Lure: Scheduled Tasks Weaponized for DLL Side-Loading (drops ValleyRAT)  

Tracking Malware and Attack Expansion: A Hacker Group’s Journey across Asia

Cybersecurity

Homeland Security reassigns ‘hundreds’ of CISA cyber staffers to support Trump’s deportation crackdown 

Employees are unknowingly leaking company secrets through ChatGPT, new report warns  

Space Force Building Tools to Detect Cyberattacks on Satellites  

Securing the Future: Changes to Internet Explorer Mode in Microsoft Edge 

Oracle releases emergency patch for new E-Business Suite flaw

RediShell: Critical Remote Code Execution Vulnerability (CVE-2025-49844) in Redis, 10 CVSS score  

Elevating Cybersecurity: Ensuring Strategic and Sustainable Impact for CISOs 

UK experiencing four ‘nationally significant’ cyber attacks every week  

New SAP NetWeaver Bug Lets Attackers Take Over Servers Without Login

Jeep software update bricks vehicles, leaves owners stranded  

ChatGPT safety systems can be bypassed to get weapons instructions  

Evaluation of DeepSeek AI Models 

404 Accountability not found: Spyware accountability through software liability   

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, newsletter)



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/183591/breaking-news/security-affairs-newsletter-round-546-by-pierluigi-paganini-international-edition.html