ZeroHour

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2024-13972
A vulnerability related to registry permissions in the Intercept X for Windows updater prior to Core Agent version 2024.3.2 can lead to a local user gaining SYS

A vulnerability related to registry permissions in the Intercept X for Windows updater prior to Core Agent version 2024.3.2 can lead to a local user gaining SYSTEM level privileges during a product upgrade.

NVD description · AI analysis pending
8.8<1%
CVE-2025-20337
Unauthenticated Injection Flaw Allows Root RCE in Cisco ISE and ISE-PIC

CVE-2025-20337 is a critical (CVSS 3.1: 10.0) injection vulnerability (CWE-74) in a specific API of Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC), caused by insufficient validation of user-supplied input. An unauthenticated, remote attacker can trigger it by submitting a crafted request to the affected API, with no valid credentials required. Successful exploitation allows arbitrary code execution on the underlying operating system with root privileges, giving the attacker full control of the affected device, consistent with the changed-scope, high-impact CVSS score. Any organization running Cisco ISE or ISE-PIC is potentially affected; CISA added the flaw to the Known Exploited Vulnerabilities catalog on 2025-07-28, and press reports indicate active exploitation, including zero-day use per Amazon threat intelligence coverage. EPSS assigns a 67% probability of exploitation within 30 days (99th percentile), and no public proof-of-concept is known.

Do: Upgrade Cisco ISE and ISE-PIC to the fixed releases identified in Cisco's security advisory (fixed version details are not included in this data set), and check management/API logs for unauthenticated crafted API requests indicating exploitation. As an interim mitigation, restrict network access to the affected API and the ISE administration interface. Organizations covered by BOD 22-01 must apply vendor mitigations per Cisco's instructions or discontinue use of the product by the KEV remediation deadline.

10.068% KEV
  • Cisco Identity Services Engine (ISE)
  • Cisco Identity Services Engine Passive Identity Connector (ISE-PIC)
moderatelikely on the order of tens of thousands of enterprise deployments worldwide (deployment-pattern estimate; no public install or scan counts)
CVE-2025-23266
NVIDIA Container Toolkit for all platforms contains a vulnerability in some hooks used to initialize the container, where an attacker could execute arbitrary co

NVIDIA Container Toolkit for all platforms contains a vulnerability in some hooks used to initialize the container, where an attacker could execute arbitrary code with elevated permissions. A successful exploit of this vulnerability might lead to escalation of privileges, data tampering, information disclosure, and denial of service.

NVD description · AI analysis pending
9.03%
CVE-2025-23267
NVIDIA Container Toolkit for all platforms contains a vulnerability in the update-ldcache hook, where an attacker could cause a link following by using a specia

NVIDIA Container Toolkit for all platforms contains a vulnerability in the update-ldcache hook, where an attacker could cause a link following by using a specially crafted container image. A successful exploit of this vulnerability might lead to data tampering and denial of service.

NVD description · AI analysis pending
8.5<1%
CVE-2025-2500
A vulnerability exists in the SOAP Web services of the Asset Suite versions listed below.

A vulnerability exists in the SOAP Web services of the Asset Suite versions listed below. If successfully exploited, an attacker could gain unauthorized access to the product and the time window of a possible password attack could be expanded.

NVD description · AI analysis pending
9.1<1%
CVE-2025-27209
The V8 release used in Node.js v24.0.0 has changed how string hashes are computed using rapidhash.

The V8 release used in Node.js v24.0.0 has changed how string hashes are computed using rapidhash. This implementation re-introduces the HashDoS vulnerability as an attacker who can control the strings to be hashed can generate many hash collisions - an attacker can generate collisions even without knowing the hash-seed. * This vulnerability affects Node.js v24.x users.

NVD description · AI analysis pending
7.51%
CVE-2025-27210
An incomplete fix has been identified for CVE-2025-23084 in Node.js, specifically affecting Windows device names like CON, PRN, and AUX.

An incomplete fix has been identified for CVE-2025-23084 in Node.js, specifically affecting Windows device names like CON, PRN, and AUX. This vulnerability affects Windows users of `path.join` API.

NVD description · AI analysis pending
7.515%
CVE-2025-27212
An Improper Input Validation in certain UniFi Access devices could allow a Command Injection by a malicious actor with access to UniFi Access management network.

An Improper Input Validation in certain UniFi Access devices could allow a Command Injection by a malicious actor with access to UniFi Access management network. Affected Products: UniFi Access Reader Pro (Version 2.14.21 and earlier) UniFi Access G2 Reader Pro (Version 1.10.32 and earlier) UniFi Access G3 Reader Pro (Version 1.10.30 and earlier) UniFi Access Intercom (Version 1.7.28 and earlier) UniFi Access G3 Intercom (Version 1.7.29 and earlier) UniFi Access Intercom Viewer (Version 1.3.20 and earlier) Mitigation: Update UniFi Access Reader Pro Version 2.15.9 or later Update UniFi Access G2 Reader Pro Version 1.11.23 or later Update UniFi Access G3 Reader Pro Version 1.11.22 or later Update UniFi Access Intercom Version 1.8.22 or later Update UniFi Access G3 Intercom Version 1.8.22 or later Update UniFi Access Intercom Viewer Version 1.4.39 or later

NVD description · AI analysis pending
9.81%
CVE-2025-2884
TCG TPM2.0 Reference implementation's CryptHmacSign helper function is vulnerable to Out-of-Bounds read due to the lack of validation the signature scheme with

TCG TPM2.0 Reference implementation's CryptHmacSign helper function is vulnerable to Out-of-Bounds read due to the lack of validation the signature scheme with the signature key's algorithm. See Errata Revision 1.83 and advisory TCGVRT0009 for TCG standard TPM2.0

NVD description · AI analysis pending
6.6<1%
CVE-2025-3052
An arbitrary write vulnerability in Microsoft signed UEFI firmware allows for code execution of untrusted software.

An arbitrary write vulnerability in Microsoft signed UEFI firmware allows for code execution of untrusted software. This allows an attacker to control its value, leading to arbitrary memory writes, including modification of critical firmware settings stored in NVRAM. Exploiting this vulnerability could enable security bypasses, persistence mechanisms, or full system compromise.

NVD description · AI analysis pending
8.2<1%
CVE-2025-30751
Vulnerability in the Oracle Database component of Oracle Database Server.

Vulnerability in the Oracle Database component of Oracle Database Server. Supported versions that are affected are 19.27 and 23.4-23.8. Easily exploitable vulnerability allows low privileged attacker having Create Session, Create Procedure privilege with network access via Oracle Net to compromise Oracle Database. Successful attacks of this vulnerability can result in takeover of Oracle Database. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).

NVD description · AI analysis pending
8.8<1%
  • oracle database server
CVE-2025-31019
Authentication Bypass Using an Alternate Path or Channel vulnerability in miniOrange Password Policy Manager password-policy-manager allows Authentication Abuse

Authentication Bypass Using an Alternate Path or Channel vulnerability in miniOrange Password Policy Manager password-policy-manager allows Authentication Abuse.This issue affects Password Policy Manager: from n/a through <= 2.0.4.

NVD description · AI analysis pending
8.8<1%
  • WordPress
CVE-2025-33043
APTIOV contains a vulnerability in BIOS where an attacker may cause an Improper Input Validation locally.

APTIOV contains a vulnerability in BIOS where an attacker may cause an Improper Input Validation locally. Successful exploitation of this vulnerability can potentially impact of integrity.

NVD description · AI analysis pending
6.1<1%
  • ami aptio v
CVE-2025-37103
Hard-coded login credentials were found in HPE Networking Instant On Access Points, allowing anyone with knowledge of it to bypass normal device authentication.

Hard-coded login credentials were found in HPE Networking Instant On Access Points, allowing anyone with knowledge of it to bypass normal device authentication. Successful exploitation could allow a remote attacker to gain administrative access to the system.

NVD description · AI analysis pending
9.81%
CVE-2025-40776
A `named` caching resolver that is configured to send ECS (EDNS Client Subnet) options may be vulnerable to a cache-poisoning attack.

A `named` caching resolver that is configured to send ECS (EDNS Client Subnet) options may be vulnerable to a cache-poisoning attack. This issue affects BIND 9 versions 9.11.3-S1 through 9.16.50-S1, 9.18.11-S1 through 9.18.37-S1, and 9.20.9-S1 through 9.20.10-S1.

NVD description · AI analysis pending
8.6<1%
CVE-2025-40777
If a `named` caching resolver is configured with `serve-stale-enable` `yes`, and with `stale-answer-client-timeout` set to `0` (the only allowable value other t

If a `named` caching resolver is configured with `serve-stale-enable` `yes`, and with `stale-answer-client-timeout` set to `0` (the only allowable value other than `disabled`), and if the resolver, in the process of resolving a query, encounters a CNAME chain involving a specific combination of cached or authoritative records, the daemon will abort with an assertion failure. This issue affects BIND 9 versions 9.20.0 through 9.20.10, 9.21.0 through 9.21.9, and 9.20.9-S1 through 9.20.10-S1.

NVD description · AI analysis pending
7.5<1%
CVE-2025-41236
VMware ESXi, Workstation, and Fusion contain an integer-overflow vulnerability in the VMXNET3 virtual network adapter.

VMware ESXi, Workstation, and Fusion contain an integer-overflow vulnerability in the VMXNET3 virtual network adapter. A malicious actor with local administrative privileges on a virtual machine with VMXNET3 virtual network adapter may exploit this issue to execute code on the host. Non VMXNET3 virtual adapters are not affected by this issue.

NVD description · AI analysis pending
9.32%
CVE-2025-4657
A buffer overflow vulnerability was reported in the Lenovo Protection Driver, prior to version 5.1.1110.4231, used in Lenovo PC Manager, Lenovo Browser, and Len

A buffer overflow vulnerability was reported in the Lenovo Protection Driver, prior to version 5.1.1110.4231, used in Lenovo PC Manager, Lenovo Browser, and Lenovo App Store could allow a local attacker with elevated privileges to execute arbitrary code.

NVD description · AI analysis pending
8.4<1%
CVE-2025-48384
Exploited Link-Following RCE in Git via Malicious Submodule Paths

CVE-2025-48384 is a high-severity (CVSS 8.0) link-following/path-interpretation flaw (CWE-59, CWE-436) in Git's config handling: trailing carriage returns are written unquoted into config files and stripped when the value is later read, so a submodule path containing a trailing CR resolves to a different location during submodule initialization. If an attacker crafts a repository whose submodule path ends in a CR and a symlink maps the altered path to the submodule's hooks directory, an executable post-checkout hook inside the submodule is unintentionally run after checkout, yielding arbitrary code execution on the machine running Git (network vector, user interaction required, scope changed, high C/I/A impact). Any user or CI/CD system running an affected Git release when cloning an untrusted repository with maliciously crafted submodule configuration is exposed; CISA lists Git as the affected product, with CPEs also covering Git as packaged by Debian and bundled with Apple's Xcode. The flaw is being exploited in the wild: CISA added it to the KEV catalog on 2025-08-25, news outlets report active exploitation leading to RCE, EPSS is 4.1% (90th percentile), ransomware association is unknown, and no public proof-of-concept is known.

Do: Upgrade Git immediately to 2.50.1 or to the fixed release matching your maintenance line (2.43.7, 2.44.4, 2.45.4, 2.46.4, 2.47.3, 2.48.2, or 2.49.1); on Debian apply the distribution security update and on macOS update Xcode/Command Line Tools via Apple's security update. As an interim check, inspect .gitmodules and repo configuration for submodule paths containing trailing carriage-return characters before initializing submodules from untrusted repositories. Federal agencies must patch per the KEV listing (added 2025-08-25) and BOD 22-01 guidance.

8.04% KEV
  • git-scm Git All releases prior to the fixed versions in each maintenance line: before 2.43.7, 2.44.4, 2.45.4, 2.46.4, 2.47.3, 2.48.2, 2.49.1, and 2.50.1 (fixed in 2.43.7, 2
  • Debian Linux (Git package)
  • apple Xcode (Git bundled with macOS developer tools)
masstens of millions of installations (Git is preinstalled or bundled on nearly all Linux servers, macOS developer machines via Xcode/Command Line Tools, and CI/CD…
CVE-2025-4919
An attacker was able to perform an out-of-bounds read or write on a JavaScript object by confusing array index sizes.

An attacker was able to perform an out-of-bounds read or write on a JavaScript object by confusing array index sizes. This vulnerability was fixed in Firefox 138.0.4, Firefox ESR 128.10.1, Firefox ESR 115.23.1, Thunderbird 128.10.2, and Thunderbird 138.0.2.

NVD description · AI analysis pending
8.89%
  • mozilla firefox
  • mozilla thunderbird
CVE-2025-49704
+1 in the same advisory: …49706
Authenticated Code Injection RCE in Microsoft SharePoint

CVE-2025-49704 is a code injection vulnerability (CWE-94) in Microsoft SharePoint that allows an authorized (authenticated) attacker to execute arbitrary code on the server over the network, by sending requests whose attacker-controlled input SharePoint executes as code. It can be chained with CVE-2025-49706, and Microsoft subsequently issued CVE-2025-53770 as a patch bypass of the original CVE-2025-49704 fix, meaning the CVE-2025-53770 updates provide stronger protection and should be treated as the definitive remediation. Successful exploitation yields remote code execution on the SharePoint server, and CISA added the flaw to the KEV on 2025-07-22 with known ransomware use. Organizations running on-premises SharePoint Server are affected; CISA directs owners of public-facing servers running EOL/EOS versions (SharePoint Server 2013 and earlier) to disconnect them, and operators of supported versions to apply the CISA and vendor mitigations and updates, with cloud SharePoint services governed by BOD 22-01. Exploitation is confirmed in the wild and EPSS assigns a 100% probability of exploitation within 30 days (top percentile), although no public proof-of-concept code is documented.

Do: Apply Microsoft's SharePoint Server updates for CVE-2025-53770, which supersede the original CVE-2025-49704 fixes with more robust protection, prioritizing internet-facing servers. Disconnect public-facing SharePoint servers running EOL/EOS versions (SharePoint Server 2013 and earlier), and for supported versions follow the CISA and vendor mitigations, with cloud services handled per BOD 22-01. Because in-the-wild exploitation and ransomware use are confirmed, hunt for indicators of compromise and ransomware activity on exposed SharePoint servers.

8.8
group max
100% KEV ransomware
  • Microsoft SharePoint CISA lists 'Microsoft SharePoint' without enumerating specific version ranges; the CISA KEV guidance targets on-premises SharePoint Server, calling out SharePoi
masstens of thousands of internet-exposed SharePoint servers per public scans, within a total on-premises install base plausibly exceeding 100,000 deployments…
CVE-2025-50067
Vulnerability in Oracle Application Express (component:

Vulnerability in Oracle Application Express (component: Strategic Planner Starter App). Supported versions that are affected are 24.2.4 and 24.2.5. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Application Express. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Application Express, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Application Express. CVSS 3.1 Base Score 9.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H).

NVD description · AI analysis pending
9.0<1%
  • oracle application express
CVE-2025-5333
Remote attackers can execute arbitrary code in the context of the vulnerable service process.

Remote attackers can execute arbitrary code in the context of the vulnerable service process.

NVD description · AI analysis pending
9.5<1%
CVE-2025-53506
Uncontrolled Resource Consumption vulnerability in Apache Tomcat if an HTTP/2 client did not acknowledge the initial settings frame that reduces the maximum per

Uncontrolled Resource Consumption vulnerability in Apache Tomcat if an HTTP/2 client did not acknowledge the initial settings frame that reduces the maximum permitted concurrent streams. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.8, from 10.1.0-M1 through 10.1.42, from 9.0.0.M1 through 9.0.106. The following versions were EOL at the time the CVE was created but are known to be affected: 8.5.0 through 8.5.100. Other EOL versions may also be affected. Users are recommended to upgrade to version 11.0.9, 10.1.43 or 9.0.107, which fix the issue.

NVD description · AI analysis pending
7.52%
  • apache tomcat
CVE-2025-53770
Unauthenticated Deserialization RCE in Microsoft SharePoint Server on-premises

CVE-2025-53770 is a deserialization of untrusted data vulnerability (CWE-502) in Microsoft SharePoint Server on-premises that allows an unauthorized attacker to execute code over a network. It is triggered when the server deserializes attacker-controlled data, can be chained with CVE-2025-53771, and it bypasses the fixes issued for CVE-2025-49704, meaning the earlier patches are insufficient. Successful exploitation yields remote code execution on the SharePoint server, and ransomware operators are known to be using it. Any organization running SharePoint Server on-premises is affected, particularly internet-facing deployments and end-of-life versions such as SharePoint Server 2013 and earlier that can no longer be patched. The flaw is being actively exploited — it was added to CISA's KEV on 2025-07-20 with known ransomware use — and EPSS assigns it a 100% probability of exploitation within 30 days.

Do: Apply Microsoft's updated SharePoint Server security updates that fix CVE-2025-53770 — these include more robust protection than the earlier CVE-2025-49704 updates — and ensure the companion CVE-2025-53771 is also addressed, following CISA and vendor mitigation instructions for supported versions. Disconnect public-facing SharePoint Server 2013 or earlier (EOL/EOS) instances, minimize internet exposure of supported servers, and hunt for signs of compromise given the known ransomware exploitation.

9.8100% KEV ransomware PoC ×3
  • Microsoft SharePoint Server (on-premises) Specific version ranges not enumerated in the source data; Microsoft SharePoint on-premises is affected. CISA notes SharePoint Server 2013 and earlier are EOL/E
mass≈25,000–100,000 internet-exposed on-premises SharePoint servers (public internet-wide scans); total on-prem installed base plausibly >1M users
CVE-2025-53771
Improper Authentication in Microsoft SharePoint Server Enables Network Spoofing

CVE-2025-53771 is an improper authentication flaw (CWE-287) in Microsoft's on-premises SharePoint Server that allows an unauthenticated remote attacker to conduct spoofing over the network. Per the CVSS vector, exploitation requires no privileges and no user interaction, so an attacker who can reach the SharePoint server over the network can trigger it directly. Successful exploitation lets the attacker impersonate an authenticated user or component, producing limited but real impact on confidentiality and integrity (CVSS 6.5, medium). Any organization running on-premises SharePoint Server is affected, particularly those exposing it to the internet; no specific version numbers are provided in the source data, so defenders should consult Microsoft's advisory for their edition. No public PoC exists and it is not yet in CISA's KEV, but exploitation likelihood is near-certain (EPSS 99.7%, 100th percentile), and Microsoft has confirmed active China-linked nation-state exploitation of the closely related SharePoint ToolShell vulnerability chain, which has hit roughly 400 organizations including U.S. federal agencies.

Do: Apply Microsoft's SharePoint Server security updates that ship this fix as soon as possible, prioritizing internet-facing servers, and treat this as urgent because it was patched alongside the actively exploited ToolShell chain. While patching, review authentication and web-server logs on SharePoint hosts for unexpected successful logons or anomalous requests that could indicate spoofing or compromise, and restrict network access to SharePoint (VPN, firewall rules, segmentation) if patching must be delayed.

6.5100%
  • Microsoft SharePoint Server (on-premises)
largeTens of thousands of internet-facing SharePoint Server deployments, with a total on-prem installed base plausibly in the hundreds of thousands (estimate)
CVE-2025-53833
LaRecipe is an application that allows users to create documentation with Markdown inside a Laravel app.

LaRecipe is an application that allows users to create documentation with Markdown inside a Laravel app. Versions prior to 2.8.1 are vulnerable to Server-Side Template Injection (SSTI), which could potentially lead to Remote Code Execution (RCE) in vulnerable configurations. Attackers could execute arbitrary commands on the server, access sensitive environment variables, and/or escalate access depending on server configuration. Users are strongly advised to upgrade to version v2.8.1 or later to receive a patch.

NVD description · AI analysis pending
10.09%
CVE-2025-53906
Vim is an open source, command line text editor.

Vim is an open source, command line text editor. Prior to version 9.1.1551, a path traversal issue in Vim’s zip.vim plugin can allow overwriting of arbitrary files when opening specially crafted zip archives. Impact is low because this exploit requires direct user interaction. However, successfully exploitation can lead to overwriting sensitive files or placing executable code in privileged locations, depending on the permissions of the process editing the archive. The victim must edit such a file using Vim which will reveal the filename and the file content, a careful user may suspect some strange things going on. Successful exploitation could results in the ability to execute arbitrary commands on the underlying operating system. Version 9.1.1551 contains a patch for the vulnerability.

NVD description · AI analysis pending
4.1<1% PoC
  • vim vim
CVE-2025-54309
Unauthenticated Admin Access Bypass in CrushFTP (CVE-2025-54309)

CVE-2025-54309 is a critical authentication flaw (CWE-420, an "unprotected alternate channel" issue) in CrushFTP in which AS2 validation is mishandled, allowing unauthenticated HTTPS requests to reach the server's administrative interface through an alternate channel. It is triggered on deployments that do not use the CrushFTP DMZ proxy (perimeter) feature, so any vulnerable instance whose HTTPS service is reachable is exposed; attackers gain full administrative access to the file transfer server and the data it holds. CrushFTP 10 before 10.8.5 and 11 before 11.3.4_23 are affected, while deployments fronted by the DMZ proxy feature are not. The flaw has been exploited in the wild since at least July 18, 2025, was added to CISA's Known Exploited Vulnerabilities catalog on 2025-07-22, and carries a 94.7% EPSS probability of exploitation within 30 days.

Do: Upgrade to CrushFTP 10.8.5 (v10 line) or 11.3.4_23 (v11 line) or later; if patching is delayed, enable the DMZ proxy feature or restrict HTTPS access to the server. Because attackers gain admin access, review administrative accounts and HTTPS logs for unexplained activity since at least July 18, 2025, and rotate exposed credentials. Federal agencies must apply vendor mitigations or follow BOD 22-01 guidance, including for cloud service use of the product.

9.895% KEV
  • CrushFTP 10 before 10.8.5; 11 before 11.3.4_23 (when the DMZ proxy feature is not used)
moderateseveral thousand internet-exposed CrushFTP servers (order of magnitude 10^3–10^4); total deployments likely higher
CVE-2025-6023
Unauthenticated Open Redirect Leading to XSS in Grafana OSS

An open redirect vulnerability in Grafana OSS can be chained with path traversal issues to achieve cross-site scripting (XSS) attacks against Grafana users. The flaw was introduced in Grafana v11.5.0 per the advisory, and it is triggered when an attacker induces an unauthenticated user (user interaction required per the CVSS vector) to follow a crafted URL that redirects through a vulnerable Grafana instance. By chaining the open redirect with path traversal, an attacker can execute script in the victim's browser context, with potential theft of session tokens or in-browser actions, reflected in the high confidentiality and low integrity/availability impact of the 7.6 CVSS score. Anyone running affected Grafana OSS versions is exposed, with internet-facing instances at greatest risk. As of now there is no public proof of concept and no confirmed in-the-wild exploitation, although EPSS assigns a high 42.1% probability of exploitation within 30 days.

Do: Upgrade Grafana OSS to the patched security release for your branch: 12.0.2+security-01, 11.6.3+security-01, 11.5.6+security-01, 11.4.6+security-01, or 11.3.8+security-01. Until patched, restrict internet exposure of Grafana instances and caution users against clicking unsolicited links pointing to your Grafana domain. Review web/proxy logs for crafted redirect URLs that may indicate exploitation attempts, given the elevated EPSS score.

7.642%
  • Grafana Labs Grafana OSS Introduced in v11.5.0; all releases prior to the patched builds in each branch: versions below 12.0.2+security-01, 11.6.3+security-01, 11.5.6+security-01, 11.4.
mass≈100,000–200,000 internet-exposed Grafana instances (order of 10^5)
CVE-2025-6197
Open Redirect in Grafana OSS Organization Switching

CVE-2025-6197 is an open redirect (CWE-601) in the organization switching functionality of Grafana OSS. Exploitation requires two conditions: the Grafana instance must contain multiple organizations, and the victim must currently be on a different organization than the one specified in the attacker-crafted URL. The impact is limited — the CVSS vector scores low confidentiality and integrity impact with no availability impact — and is typical of open redirects that let attackers phish users or bounce them through a trusted Grafana domain. Only Grafana OSS deployments that use multiple organizations are affected; single-organization instances are not exploitable. No public proof of concept, in-the-wild exploitation, or CISA KEV listing is known yet, but the EPSS score of 70.1% (99th percentile) indicates an elevated likelihood of exploitation within the next 30 days.

Do: Upgrade Grafana OSS to the patched release identified in Grafana's advisory for CVE-2025-6197, checking the advisory for the exact fixed version for your release branch. In the meantime, audit instances where multiple organizations are enabled (single-org deployments are not exploitable) and advise users to avoid clicking untrusted links that point to your Grafana domain. Given the elevated EPSS score of 70.1%, prioritize patching internet-facing Grafana instances.

4.270%
  • Grafana Labs Grafana OSS
largeon the order of tens of thousands of Grafana OSS instances (a subset of roughly 100k+ internet-exposed Grafana instances that run multiple organizations)
CVE-2025-6231
+2 in the same advisory: …6232 …6230
An improper validation vulnerability was reported in Lenovo Vantage that under certain conditions could allow a local attacker to execute code with elevated per

An improper validation vulnerability was reported in Lenovo Vantage that under certain conditions could allow a local attacker to execute code with elevated permissions by modifying an application configuration file.

NVD description · AI analysis pending
8.5
group max
<1%
  • lenovo commercial vantage
  • lenovo vantage
CVE-2025-6558
Actively Exploited Input Validation Flaw in Chrome ANGLE/GPU Allows Sandbox Escape

CVE-2025-6558 is an improper input validation flaw (CWE-20) in the ANGLE graphics translation layer and GPU processing code of Google Chrome/Chromium prior to version 138.0.7204.157. A remote attacker can trigger it by convincing a user to open a crafted HTML page (user interaction is required), and successful exploitation potentially enables a sandbox escape from the browser's renderer with high impact on confidentiality, integrity, and availability. Per the CPE data, exposure extends beyond Chrome to Debian's Chromium package, Apple Safari and its operating systems (iOS, iPadOS, macOS, visionOS, watchOS), and the WebKitGTK and WPE WebKit ports, consistent with the shared ANGLE/WebKit code. Google fixed the issue in Chrome 138.0.7204.157, and CISA added the flaw to the KEV catalog on 2025-07-22, confirming active exploitation in the wild (ransomware use: unknown). EPSS assigns a 9.6% probability of exploitation within 30 days (95th percentile); no public proof-of-concept is known.

Do: Upgrade Google Chrome/Chromium to 138.0.7204.157 or later immediately, as the flaw is being actively exploited and is KEV-listed. Debian users should install the distribution's patched Chromium package, and operators of Apple platforms, WebKitGTK, or WPE WebKit deployments should apply the corresponding vendor security updates. Federal agencies must apply vendor mitigations per BOD 22-01 within the required timeframe or discontinue use if mitigations are unavailable.

8.810% KEV
  • Google Chrome prior to 138.0.7204.157
  • Google Chromium prior to 138.0.7204.157
  • Debian Linux (Chromium package)
  • +8 more
massbillions of users/installations (Chrome and Chromium-derived browsers)
CVE-2025-6965
Memory Corruption in SQLite < 3.50.2 Affecting Apple and Siemens Products

CVE-2025-6965 is a numeric handling flaw (CWE-197) in SQLite versions before 3.50.2 in which the number of aggregate terms in a query can exceed the number of available columns, resulting in memory corruption. An attacker triggers it by getting an application that embeds SQLite to execute crafted SQL: the vector is network-based and requires only low privileges, but with high attack complexity (CVSS 4.0 base 7.2), and successful corruption carries high integrity impact on the running process. Because SQLite is embedded in countless applications and operating systems, every deployment running SQLite older than 3.50.2 is affected, including Apple's iPhone OS, iPadOS, macOS, tvOS, visionOS and watchOS and Siemens' RUGGEDCOM CROSSBOW and SIDIS Prime, which bundle the library. The flaw is not on the CISA KEV list and no public proof-of-concept is known, but Google reported that its Big Sleep AI discovered the bug as hackers were preparing to exploit it, and EPSS assigns a 75.8% probability of exploitation within 30 days.

Do: Upgrade SQLite to version 3.50.2 or later in every bundled or embedded deployment, and apply the corresponding Apple OS and Siemens RUGGEDCOM CROSSBOW/SIDIS Prime updates as vendors publish fixed releases. Inventory which applications, devices and internet-facing services ship vulnerable SQLite and prioritize anything that processes untrusted SQL, given the very high EPSS score (75.8% within 30 days) and Google's report that attackers were preparing to exploit this bug. Where patching is delayed, review aggregate SQL queries for cases where aggregate terms exceed available columns as a triage measure.

7.276%
  • SQLite all versions before 3.50.2
  • Apple iPhone OS (iOS) versions bundling SQLite before 3.50.2 (Apple-specific fixed versions not specified in source data)
  • Apple iPadOS versions bundling SQLite before 3.50.2 (Apple-specific fixed versions not specified in source data)
  • +6 more
massbillions of devices worldwide (SQLite ships embedded in virtually every operating system, browser and application; Apple's active device base alone exceeds 1…
CVE-2025-7433
A local privilege escalation vulnerability in Sophos Intercept X for Windows with Central Device Encryption 2025.1 and older allows arbitrary code execution.

A local privilege escalation vulnerability in Sophos Intercept X for Windows with Central Device Encryption 2025.1 and older allows arbitrary code execution.

NVD description · AI analysis pending
8.8<1%
CVE-2025-7472
A local privilege escalation vulnerability in the Intercept X for Windows installer prior version 1.22 can lead to a local user gaining system level privileges,

A local privilege escalation vulnerability in the Intercept X for Windows installer prior version 1.22 can lead to a local user gaining system level privileges, if the installer is run as SYSTEM.

NVD description · AI analysis pending
7.5<1%
Full article2,905 words · extracted from thehackernews.com · click to collapse

Even in well-secured environments, attackers are getting in—not with flashy exploits, but by quietly taking advantage of weak settings, outdated encryption, and trusted tools left unprotected.

These attacks don’t depend on zero-days. They work by staying unnoticed—slipping through the cracks in what we monitor and what we assume is safe. What once looked suspicious now blends in, thanks to modular techniques and automation that copy normal behavior.

The real concern? Control isn’t just being challenged—it’s being quietly taken. This week’s updates highlight how default settings, blurred trust boundaries, and exposed infrastructure are turning everyday systems into entry points.

⚡ Threat of the Week

Critical SharePoint Zero-Day Actively Exploited (Patch Released Today) — Microsoft has released fixes to address two security flaws in SharePoint Server that have come under active exploitation in the wild to breach dozens of organizations across the world. Details of exploitation emerged over the weekend, prompting Microsoft to issue an advisory for CVE-2025-53770 and CVE-2025-53771, which are now assessed to be patch bypasses for two other SharePoint flaws tracked as CVE-2025-49704 and CVE-2025-49706, an exploit chain dubbed ToolShell that could be leveraged to achieve remote code execution on on-premises SharePoint servers. The two vulnerabilities were addressed by Microsoft earlier this month as part of its Patch Tuesday update. It's currently not known who is behind the mass-exploitation activity.

🔔 Top News

  • Google Ships Patch for Actively Exploited Chrome Flaw — Google out patches to resolve a high-severity vulnerability in Chrome browser (CVE-2025-6558) that has come under active exploitation in the wild, making it the fifth zero-day to be either actively abused or demonstrated as a proof-of-concept (PoC) since the start of the year. The vulnerability is an incorrect validation of untrusted input in the browser's ANGLE and GPU components that could allow an attacker to potentially perform a sandbox escape via a crafted HTML page. The issue has been addressed in versions 138.0.7204.157/.158 for Windows and Apple macOS, and 138.0.7204.157 for Linux.
  • Critical NVIDIA Container Toolkit Flaw Disclosed — A critical vulnerability in NVIDIA Container Toolkit (CVE-2025-23266) could be exploited to achieve code execution with elevated permissions. "A successful exploit of this vulnerability might lead to escalation of privileges, data tampering, information disclosure, and denial-of-service," the GPU maker said. Wiz, which disclosed the flaw, said the shortcoming could be trivially exploited to access, steal, or manipulate the sensitive data and proprietary models of all other customers running on the same shared hardware by means of a three-line exploit.
  • New CrushFTP Bug Comes Under Attack — CrushFTP revealed that a critical flaw in its file transfer software (CVE-2025-54309) has been exploited in the wild, with unknown threat actors reverse engineering its source code to discover the bug and target devices that are yet to be updated to the latest versions. The issue affects all versions of CrushFTP 10 before 10.8.5 and 11 before 11.3.4_23. "The attack vector was HTTP(S) for how they could exploit the server," CrushFTP said. "We had fixed a different issue related to AS2 in HTTP(S) not realizing that a prior bug could be used like this exploit was. Hackers apparently saw our code change, and figured out a way to exploit the prior bug."
  • Golden dMSA Attack in Windows Server 2025 Enables Cross-Domain Attacks — Cybersecurity researchers disclosed a "critical design flaw" in delegated Managed Service Accounts (dMSAs) introduced in Windows Server 2025 that could enable cross-domain lateral movement and persistent access to all managed service accounts and their resources across Active Directory indefinitely. "The attack leverages a critical design flaw: A structure that's used for the password-generation computation contains predictable time-based components with only 1,024 possible combinations, making brute-force password generation computationally trivial," Semperis researcher Adi Malyanker said.
  • Google Big Sleep AI Agent Flags Critical SQLite Flaw Before Exploitation — Big Sleep, an artificial intelligence (AI) agent launched by Google last year as a collaboration between DeepMind and Google Project Zero, facilitated the discovery of a critical security flaw in SQLite (CVE-2025-6965) that was previously only known to attackers as a zero-day and was on the verge of exploitation. Google described it as the first time an AI agent has been used to "directly foil efforts to exploit a vulnerability in the wild."
  • Threat Actors Target EoL SonicWall SMA 100 Devices — Unknown intruders codenamed UNC6148 are targeting fully patched end-of-life SonicWall Secure Mobile Access (SMA) 100 series appliances and deploying a novel, persistent backdoor and rootkit called OVERWATCH. Many key details about the campaign are currently unknown. For starters, Google said it does not have enough data to determine where the threat actors are based, or what their motives are. Second, the attacks are exploiting leaked local administrator credentials on the targeted devices for initial access. But it has been unable to pinpoint how the attackers managed to obtain the credentials used in the attack. While it's possible that they were sourced from infostealer logs or credential marketplaces, the company noted it's more likely that the attackers leveraged a known vulnerability. It's also unclear precisely what the attackers are trying to accomplish after they take control of a device. The lack of information largely stems from how OVERWATCH functions, which allows the attackers to selectively remove log entries to hinder forensic investigation. The investigation also found that UNC6148 also managed to deploy a reverse shell on infected devices, something that should not normally be possible, leading to speculations that a zero-day might have been in play. The findings once again show network appliances are popular attacker targets, as they offer a way to gain access to high-value networks.

‎️‍🔥 Trending CVEs

Hackers are quick to jump on newly discovered software flaws – sometimes within hours. Whether it’s a missed update or a hidden bug, even one unpatched CVE can open the door to serious damage. Below are this week’s high-risk vulnerabilities making waves. Review the list, patch fast, and stay a step ahead.

This week's list includes — CVE-2025-53770, CVE-2025-53771 (Microsoft SharePoint Server), CVE-2025-37103 (HPE Instant On Access Points), CVE-2025-54309 (CrushFTP), CVE-2025-23266, CVE-2025-23267 (NVIDIA Container Toolkit), CVE-2025-20337 (Cisco Identity Services Engine and ISE Passive Identity Connector), CVE-2025-6558 (Google Chrome), CVE-2025-6965 (SQLite), CVE-2025-5333 (Broadcom Symantec Endpoint Management Suite), CVE-2025-6965 (SQLite), CVE-2025-48384 (Git CLI), CVE-2025-4919 (Mozilla Firefox), CVE-2025-53833 (LaRecipe), CVE-2025-53506 (Apache Tomcat), CVE-2025-41236 (Broadcom VMware ESXi, Workstation, and Fusion), CVE-2025-27210, CVE-2025-27209 (Node.js), CVE-2025-53906 (Vim), CVE-2025-50067 (Oracle Application Express), CVE-2025-30751 (Oracle Database), CVE-2025-6230, CVE-2025-6231, CVE-2025-6232 (Lenovo Vantage), CVE-2024-13972, CVE-2025-7433, CVE-2025-7472 (Sophos Intercept X for Windows), CVE-2025-27212 (Ubiquiti UniFi Access), CVE-2025-4657 (Lenovo Protection Driver), CVE-2025-2500 (Hitachi Energy Asset Suite), CVE-2025-6023, CVE-2025-6197 (Grafana), CVE-2025-40776, CVE-2025-40777 (BIND 9), CVE-2025-33043, CVE-2025-2884, CVE-2025-3052 (Gigabyte), and CVE-2025-31019 (Password Policy Manager plugin).

📰 Around the Cyber World

  • Russian Sentenced to 3 Years in Prison in the Netherlands for Sharing Data — A Rotterdam court sentenced a 43-year-old Russian to three years in prison for breaching international sanctions by sharing sensitive ASML information from Dutch semiconductor chip machine maker ASML and NXP with a person in Russia. At his trial on June 26, the suspect admitted to copying files last year and sending them to a person in Russia using the Signal messaging app. While the name of the defendant was not disclosed, Reuters reported in February 2025 that the perpetrator was German Aksenov, and that he had contact with Russia's FSB intelligence service. He was charged with IP theft and sanctions violations in December 2024.
  • U.K. NCSC Launches Vulnerability Research Initiative — The U.K. National Cyber Security Centre (NCSC) announced a new Vulnerability Research Initiative (VRI) that aims to strengthen relations with external cybersecurity experts. "The VRI's mission is to strengthen the UK's ability to carry out VR," the NCSC said. "We work with the best external vulnerability researchers to deliver a deep understanding of security on a wide range of  technologies we care about.​ The external VRI community also supports us in having tools and tradecraft for vulnerability discovery."
  • Storm-1516 Spreads Disinformation in Europe — A Kremlin-linked disinformation group tracked as Storm-1516 has been masquerading as real journalists and publishing fake articles on spoofed news websites to spread false narratives in France, Armenia, Germany, Moldova, and Norway. The threat actors used the names and photos of legitimate reporters to lend credibility to the bogus articles, per the Gnida Project. Another pro-Russia disinformation campaign known as Operation Overload (aka Matryoshka or Storm-1679) has been observed leveraging consumer-grade artificial intelligence tools to fuel a "content explosion" focused around exacerbating existing tensions around global elections, Ukraine, and immigration, among other controversial issues. The activity, operating since 2023, has a track record of disseminating false narratives by impersonating media outlets with the apparent aim of sowing discord in democratic countries. "This marks a shift toward more scalable, multilingual, and increasingly sophisticated propaganda tactics," Reset Tech and Check First said. "The campaign has substantially amped up the production of new content in the past eight months, signalling a shift toward faster, more scalable content creation methods." Some of the images used in the campaign are believed to have been generated using Flux AI, a text-to-image generator developed by Black Forest Labs. The company told WIRED that it has built "multiple layers of safeguards" to prevent abuse and that it's committed to working with social media platforms and authorities to ward off unlawful misuse.
  • SLOW#TEMPEST Campaign's Evolving Techniques Detailed — The threat actors behind a malware campaign called SLOW#TEMPEST have been observed using DLL-sideloading techniques to launch a malicious DLL, while relying on Control Flow Graph (CFG) obfuscation and dynamic function calls to conceal the code in the loader DLL. The primary goal of the DLL is to unpack and launch an embedded payload directly in memory only if the target machine has at least 6 GB of RAM. "The SLOW#TEMPEST campaign's evolution highlights malware obfuscation techniques, specifically dynamic jumps and obfuscated function calls," Palo Alto Networks Unit 42 said. "The success of the SLOW#TEMPEST campaign using these techniques demonstrates the potential impact of advanced obfuscation on organizations, making detection and mitigation significantly more challenging."
  • Abacus Market Shutters After Likely Exit Scam — The darknet marketplace known as Abacus Market has suddenly closed its operations, rendering all its infrastructure, including its clearnet mirror, inaccessible. The development comes after Abacus Market users began reporting withdrawal issues in late June 2025. Blockchain intelligence firm TRM Labs said the marketplace's creators may have possibly pulled off an exit scam and disappeared with users' funds, although the possibility of a law enforcement seizure hasn't been ruled out. Abacus's exit follows the June 16, 2025, seizure of Archetyp Market by Europol. Abacus Market launched in September 2021 as Alphabet Market, before it rebranded to its current name two months later. The marketplace is estimated to have generated anywhere between $300 million and $400 million in cryptocurrency sales, spanning illicit drugs, counterfeit items, and stolen cards. ​​According to data from Chainlysis, Abacus Market's revenue has increased significantly, growing by 183.2% YoY in 2024.
  • MITRE Announces AADAPT for Cryptocurrency Security — The MITRE Corporation launched Adversarial Actions in Digital Asset Payment Technologies, aka AADAPT, a cybersecurity framework for addressing vulnerabilities in digital financial systems such as cryptocurrency. It's modeled after the MITRE ATT&CK framework. "AADAPT provides developers, policymakers, and financial organizations with a structured methodology for identifying, analyzing, and mitigating potential risks associated with digital asset payments," MITRE said. "By using insights derived from real-world attacks as cited by more than 150 sources from government, industry, and academia, the AADAPT framework identifies adversarial tactics, techniques, and procedures linked to digital asset payment technologies, including consensus algorithms and smart contracts."
  • U.S. Ex-Army Soldier Pleads Guilty to Hacking 10 Telcos — Former U.S. Army soldier Cameron John Wagenius (aka kiberphant0m and cyb3rph4nt0m) pleaded guilty to hacking and extorting at least 10 telecommunications companies between April 2023 and December 2024. The 21-year-old "conspired with others to defraud at least 10 victim organizations by obtaining login credentials for the organizations' protected computer networks," the U.S. Department of Justice (DoJ) said. "The conspirators obtained these credentials using a hacking tool that they called SSH Brute, among other means. They used Telegram group chats to transfer stolen credentials and discuss gaining unauthorized access to victim companies' networks." The threat actors behind the scheme then extorted the victim organizations both privately and on cybercrime forums such as BreachForums and XSS.is by offering to sell the stolen data for thousands of dollars. Some of the data was eventually sold and used to perpetuate other frauds, including SIM-swapping. Wagenius et al are said to have attempted to extort at least $1 million from victim data owners. The attacks took place while Wagenius was on active duty, the DoJ said. Court documents show that the defendant Googled for phrases like "can hacking be treason" and "U.S. military personnel defecting to Russia." In February 2025, Wagenius pleaded guilty to conspiracy to commit wire fraud, extortion in relation to computer fraud, aggravated identity theft, and unlawful transfer of confidential phone records information. He is scheduled for sentencing on October 6, 2025. His alleged co-conspirators, Connor Moucka and John Binns, were indicted in November 2024.
  • Signed Drivers in Malicious Campaigns — Since 2020, no less than 620 signed drivers, 80 certificates, and 60 Windows Hardware Compatibility Program (WHCP) accounts have been associated with threat actor campaigns. The majority of drivers have been signed by 131 Chinese companies. In 2022 alone, over 250 drivers and roughly 34 certificates and WHCP accounts were identified as potentially compromised. The findings show that "kernel-level attacks remain highly attractive to threat actors despite Microsoft's improved defenses, due to the highest level of privileges on the compromised system and control they offer to attackers," Group-IB said, adding it found overlap in the signing infrastructure across different malware campaigns, such as those using POORTRY and RedDriver. Some of the notable malware strains using kernel loaders for added stealth include Festi, FiveSys, FK_Undead, and BlackMoon. "Attackers leverage many signing certificates and WHCP accounts by exploiting legitimate processes like the WHCP and Extended Validation (EV) certificates. This includes those belonging to compromised or fraudulently registered organizations, signing malicious drivers, bypassing established security measures, and exploiting the trust model inherent in signed kernel drivers," the company noted.
  • TeleMessage SGNL Flaw Seeing Exploitation Activity — Threat actors are actively attempting to exploit a security flaw in TeleMessage SGNL, an enterprise messaging system modeled after Signal, used by government agencies and enterprises alike to achieve secure communications. The vulnerability, CVE-2025-48927, can be used to leak sensitive information, including plaintext usernames, passwords, and other data. According to GreyNoise, exploitation efforts are coming from 25 IP addresses over the past 30 days. The majority of the IP addresses are from France, followed by Singapore, Germany, Hong Kong, and India. The attacks target the United States, Singapore, India, Mexico, and Brazil.
  • Microsoft Stops Relying on Chinese Engineers for Defense Cloud Support — Microsoft changed its practices to ensure that engineers in China no longer provide technical support to U.S. defense clients using the company's Azure cloud services. The revamps came after a ProPublica investigation revealed that Microsoft has been using Chinese engineers to help maintain U.S. Department of Defense systems, potentially exposing sensitive data to the Chinese government. "In response to concerns raised earlier this week about US-supervised foreign engineers, Microsoft has made changes to our support for US Government customers to assure that no China-based engineering teams are providing technical assistance for DoD Government cloud and related services," the company said.
  • Japan Authorities Release Free Phobos and 8Base Decryptor — Japan's National Police Agency published a free decryption tool and a guide in English for organizations impacted by the Phobos and 8Base ransomware attacks. Earlier this February, two Russian nationals accused of using the Phobos ransomware to attack more than 1,000 entities were charged as part of a global law enforcement takedown. Phobos launched in December 2018, with a modified version called 8Base gaining prominence in 2023.
  • Android Allows Gemini Access Third-Party Apps — Google has implemented a change that will allow its Gemini artificial intelligence (AI) chatbot to interact with other apps installed on Android devices, such as Phone, Messages, and others, even if users have turned off "Gemini Apps Activity." According to a support document from the company, "Even when Gemini Apps Activity is off, your conversations will be saved with your account for up to 72 hours. This lets Google provide the service and process any feedback. This activity won't appear in your Gemini Apps Activity." The update went into effect this month.
  • EvilPanel Phishing Toolkit Detailed — Cybersecurity researchers have discovered a new phishing toolkit called EvilPanel that's built on Evilginx and provides a web interface for launching multi-factor authentication (MFA)-bypassing attacks. "EvilPanel wraps all of Evilginx's powerful AiTM capabilities into a sleek, user-friendly web interface, eliminating the need for manual configuration and lowering the barrier to entry for would-be attackers," Abnormal AI said. "EvilPanel's core phishing functionality follows the Evilginx model – i.e., it maintains the login flow by acting as a transparent proxy."
  • Katz Stealer and Octalyn Stealer Detailed — Cybersecurity company SentinelOne is warning that threat actors are increasingly adopting an information stealer called Katz Stealer owing to its "robust credential and data discovery with theft capabilities as well as modern evasion and anti-analysis features." It described the stealer as a "combination of credential theft and modern malware design." Offered under a Malware-as-a-Service (MaaS) model for a mere $50 per month (or $360 for a whole year), stealers such as Katz are turnkey tools that lower the barrier to entry for pulling off malicious attacks. A notable feature of Katz Stealer is its ability to defeat Chromium's app-bound encryption to gain access to and extract credentials and cookies. "Katz Stealer is not a 'one shot' infostealer; it is designed to continually exfiltrate the victim's data," SentinelOne said. "The malware not only extracts data found on a targeted system at the point of infection but also as data updated, changed, or freshly introduced." Another new stealer masquerades as an educational tool called Octalyn Forensic Toolkit, but acts as a credential stealer, harvesting browser data, Discord and Telegram tokens, VPN configurations, gaming accounts, and cryptocurrency wallet artifacts. "Its modular C++ payload, Delphi-based builder, Telegram-based C2, and secondary payload delivery capability make it a potent tool for threat actors," CYFIRMA said. "The use of obfuscation, Windows persistence techniques, and structured data theft highlights a deliberate effort to evade detection and maximize impact."
  • Armenia Passes Use of Facial Recognition Technology by Police — Armenia's parliament has passed controversial amendments to the country's Law on Police, granting the Ministry of Internal Affairs access to a nationwide network of real-time surveillance cameras that are equipped with facial recognition technology. The cameras will operate across state and municipal buildings, public transport, airports, and parking areas. The law is set to take effect on August 9, 2025. The CSO Meter said the law "lacks clear legal safeguards, public oversight, and proper regulation of artificial intelligence (AI) technologies," posing a risk to citizens' privacy.
  • Scammers Using MaisonReceipts to Create Fake Receipts — Fraudsters are using tools like MaisonReceipts to generate counterfeit receipts for over 21 well-known retail brands in multiple currencies (USD, EUR, GBP). They are used by groups that resell counterfeit or stolen items, presenting them as authentic using bogus receipts. "The service is marketed through subscription-based websites, social media accounts, and encrypted messaging platforms, with features that make the fraudulent receipts appear convincing enough to deceive consumers and online marketplaces," Group-IB said.
  • PyPI Blocks inbox.ru Email Domain — A recent spam campaign against PyPI has prompted the maintainers of the Python Package Index (PyPI) repository to ban the use of the "inbox.ru" email domain during new registrations as well as adding extra email addresses. "The campaign created over 250 new user accounts, publishing over 1,500 new projects on PyPI, leading to end-user confusion, abuse of resources, and potential security issues," PyPI said. "All relevant projects have been removed from PyPI, and accounts have been disabled."
  • Silver Fox Actor Creates Fake Websites for Malware Delivery — The threat actor known as Silver Fox, which is known for targeting Chinese-speaking individuals and entities, has created over 2,800 domains since June 2023, with 266 of the over 850 identified domains since December 2024 actively distributing malware. These fake websites act as a delivery vector for Windows-specific malware and masquerade as application download sites and software update prompts. "The consistent operational timing across all hours with high influxes during Chinese working hours, in addition to other factors, suggests a combination of automated and likely human-driven approach to their activities," DomainTools said.
  • Arrested Scattered Spider Members Released on Bail — A British court has released four members of the Scattered Spider group on bail. They were arrested last week on suspicion of Computer Misuse Act offenses, blackmail, money laundering, and participating in the activities of an organized crime group. They've been charged with hacking U.K. retailers Marks & Spencer, Co-op, and Harrods.
  • Armenian National Charged with Ryuk Ransomware Attacks — An Armenian man extradited from Ukraine to the United States has been charged over his alleged role in Ryuk ransomware attacks between March 2019 and September 2020. Karen Serobovich Vardanyan was arrested in Kyiv in April, and was extradited to the United States on June 18. Vardanyan has been charged with conspiracy, fraud in connection with computers, and extortion in connection with computers. He has been charged alongside Levon Georgiyovych Avetisyan, 45, who is also an Armenian national facing the same charges. He is currently detained in France and is expected to be extradited as well. Vardanyan and his accomplices received about 1,610 bitcoins from victims, valued at more than $15 million at the time of payment. Two Ukrainians — 53-year-olds Oleg Nikolayevich Lyulyava and Andrii Leonydovich Prykhodchenko — were also charged in connection with Ryuk activity but remain at large.
  • $2.17B Stolen from Crypto Services in 2025 — Hackers and scammers have stolen over $2.17 billion in crypto assets in the first half of this year, with North Korea's $1.5 billion hack of Bybit accounting for the majority of the assets. Data from TRM Labs shows that $2.1 billion was stolen across at least 75 distinct hacks and exploits. A total of $801,315,669 was lost across 144 incidents in Q2 2025, per CertiK. Wallet compromise emerged as the most costly attack vector in H1 2025, with $1,706,937,700 stolen across 34 incidents. "So far in 2025, significant concentrations of stolen fund victims have emerged in the U.S., Germany, Russia, Canada, Japan, Indonesia, and South Korea," Chainalysis said. "Personal wallet compromises make up a growing share of total ecosystem value stolen over time."
  • Japan Targeted by North Korea and China in 2024 — Japanese organizations have been targeted by North Korean threat actors to distribute malware families like BeaverTail, InvisibleFerret, and RokRAT, as well as by Chinese hacking groups such as Mustang Panda, Stone Panda, MirrorFace, Teleboyi, and UNC5221. The China-linked attacks led to the deployment of backdoors and trojans like ANEL and PlugX, Macnica said.
  • Rainbow Hyena Goes After Russian Firms — The threat actor known as Rainbow Hyena targeted Russian healthcare and IT organizations using phishing emails containing malicious attachments to distribute a C++-based custom backdoor called PhantomRemote. "The backdoor collects information about the compromised system, loads other executables from the C2 server, and runs commands via the cmd.exe interpreter," BI.ZONE said.
  • Migration to Post-Quantum Cryptography is Uneven — About 6% of all 186 million SSH servers on the internet already use quantum-safe encryption, according to a new report from Forescout Research - Vedere Labs. "Three quarters of OpenSSH versions on the internet still run versions released between 2015 and 2022 that do not support quantum-safe encryption," the company said. "If regulators mandate quantum-safe encryption in the near future, organizations will face serious gaps. Outdated infrastructure will become a compliance and security risk."
  • Brazilian Police Arrest IT Worker for $100 Million Cyber Theft — Authorities in Brazil arrested a suspect in connection with a cyber attack that diverted more than $100 million from the country's banking systems. Per a report from Associated Press, the suspect has been identified as João Roque, an IT employee of a software company named C&M and he allegedly helped unknown threat actors gain unauthorized access to Brazil's instant payment system, known as PIX, by selling his credentials to them earlier this year for about $2,700 in two separate cash payments. Once the cybercriminals breached the company's network, they carried out fraudulent PIX transactions. It's believed that the losses could go up further, as the loss refers to just one financial institution that contracted with C&M.
  • Italian Police Arrest Diskstation Ransomware Gang — Italian police have arrested a 44-year-old Romanian for carrying out cyber attacks against Italian companies as part of a law enforcement effort called Operation Elicius. The unidentified man is alleged to be the leader of the DiskStation Security ransomware group, which has targeted Synology network-attached storage (NAS) devices since 2021. He faces charges of unauthorized access to computer systems and extortion.
  • Samsung Announces KEEP to Store Sensitive Data — Samsung announced a number of security and privacy updates to its Galaxy smartphones with One UI 8, including support for quantum-resistant Wi-Fi connections using ML‑KEM and a new architecture called Knox Enhanced Encrypted Protection (KEEP) that creates encrypted, app-specific storage environments for storing data. KEEP also integrates with Samsung's Personal Data Engine (PDE) and Knox Vault, the company's hardware security environment, to enable personalized artificial intelligence (AI) features by analyzing users' data on-device.
  • Cambodia Arrests Over 1,000 Amid Crackdown on Online Scams — Cambodian authorities have arrested more than 1,000 suspects linked to online scams in an effort to crack down on cybercrime operations in the country. Those detained included over 200 Vietnamese, 27 Chinese, and 75 suspects from Taiwan and 85 Cambodians in the capital Phnom Penh and the southern city of Sihanoukville. About 270 Indonesians, including 45 women, were arrested in Poipet. In a related development, Thai officials raided properties connected to a Cambodian senator and business tycoon, Kok An, in relation to a local network of cyber scam call centers.

🎥 Cybersecurity Webinars

  • From Autofill to Alarm Bells: Securing Identity in the Age of AI — Logins got easier—but trust got harder. As AI reshapes digital identity, users are questioning how their data is used and who’s really behind the screen. In this session, discover how top brands are tackling AI-driven identity risks while rebuilding trust with smarter, privacy-first authentication strategies.
  • How Attackers Hijack Your Dependencies—and What DevSecOps Teams Must Do Now — Your Python environment is under attack—quietly, and from within. In 2025, repo hijacks, poisoned packages, and typosquatting aren’t rare edge cases—they’re part of the threat landscape. This webinar shows developers and DevSecOps leaders how to lock down the Python supply chain before compromised dependencies take down your systems.
  • Your AI Copilot May Be Letting Attackers In — Learn How to Lock Down the Identity Layer — AI copilots are boosting productivity—and attackers are using the same power to break your identity perimeter. From API abuse to synthetic logins, the identity layer is under siege. Join Okta to learn how to secure AI-powered workflows, detect AI-driven threats, and make identity your strongest line of defense in 2025.

🔒 Tip of the Week

Map Known Vulnerabilities Automatically Across Your Stack — Attackers often use Windows Scheduled Tasks to stay hidden on systems. Some go a step further by removing key registry values like SD (Security Descriptor) or Index, making their tasks invisible to common tools like Task Scheduler, schtasks, or even Autoruns. These hidden tasks still run in the background and can be used for persistence or malware delivery.

To check for visible tasks, tools like Autoruns (by Sysinternals) and TaskSchedulerView (by NirSoft) are great starting points. They show active tasks and let you spot unusual ones. But hidden tasks require deeper digging. You can use PowerShell to scan the registry path HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree and look for tasks with missing SD values.

For more advanced checks, use Sysmon to track changes in the TaskCache registry and ProcMon to monitor registry activity in real time. Look for suspicious task names, missing values, or tasks with an Index of 0. Also, set alerts for Event ID 4698, which logs new scheduled task creation.

In short: use both visual tools and registry checks to uncover hidden scheduled tasks. Regular scans, baseline comparisons, and basic alerting can help catch threats early—before they do damage.

Conclusion

What’s becoming clearer each week is that attacker sophistication isn’t the exception—it’s the baseline. AI-driven reconnaissance, credential abuse, and signal mimicry are no longer advanced—they’re routine.

And as coordination gaps persist across security teams, the boundary between low-level noise and high-impact intrusions continues to blur. The result isn’t just a faster compromise—it’s a deeper erosion of trust. If trust was once a strength, it’s now a surface that attackers exploit.

Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.

Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2025/07/weekly-recap-sharepoint-0-day-chrome.html