ZeroHour
Security Affairspublished ()ingested @securityaffairs

Security Affairs newsletter Round 542 by Pierluigi Paganini

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2020-9273
In ProFTPD 1.3.7, it is possible to corrupt the memory pool by interrupting the data transfer channel.

In ProFTPD 1.3.7, it is possible to corrupt the memory pool by interrupting the data transfer channel. This triggers a use-after-free in alloc_pool in pool.c, and possible remote code execution.

NVD description · AI analysis pending
8.812%
  • proftpd proftpd
  • proftpd debian linux
  • proftpd fedora
  • +1 more
CVE-2025-10585
Actively Exploited V8 Type Confusion in Google Chrome (Heap Corruption)

CVE-2025-10585 is a type confusion flaw (CWE-843) in the V8 JavaScript engine in Google Chrome and Chromium prior to version 140.0.7339.185. A remote attacker can trigger it via a crafted HTML page processed by the browser, causing V8 to mishandle object types and potentially exploit heap corruption, which can yield code execution in the browser. Any user or system running an affected Chrome/Chromium build is exposed, and Siemens Cadra is also listed as affected in the CPE data. The flaw is being actively exploited in the wild: Google patched it as a zero-day, CISA added it to the Known Exploited Vulnerabilities catalog on 2025-09-23, and reporting describes it as the sixth actively exploited Chrome zero-day of 2025.

Do: Update Google Chrome to 140.0.7339.185 or later immediately (verify via Settings > About Chrome or through enterprise browser management); because the flaw is in CISA's KEV catalog, federal agencies must apply vendor mitigations per BOD 22-01 guidance or discontinue use if mitigations are unavailable. Organizations running products that embed Chromium, including Siemens Cadra per the CPE listing, should contact those vendors for patched builds. No public PoC is known, but in-the-wild exploitation is confirmed, so do not defer patching.

9.85% KEV
  • Google Chrome all versions prior to 140.0.7339.185
  • Google Chromium (V8 engine) Chromium-based builds prior to 140.0.7339.185 (per CISA affected list: Google Chromium V8)
  • Siemens Cadra
mass≈3+ billion Chrome users/installations worldwide, plus an unknown number of Chromium-embedded deployments (e.g., Siemens Cadra)
Full article478 words · extracted from securityaffairs.com · click to collapse

Pierluigi Paganini September 21, 2025

A new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email box.

Enjoy a new round of the weekly SecurityAffairs newsletter, including the international press.

International Press – Newsletter

Cybercrime

Gucci, Balenciaga and Alexander McQueen private data ransomed by hackers 

Hackers claim access to law enforcement portals, but do they really have access?

Founder of One of World’s Largest Hacker Forums Resentenced to Three Years in Prison

RaccoonO365: An Active Campaign and New Features  

FileFix in the wild! New FileFix campaign goes beyond POC and leverages steganography

Microsoft seizes 338 websites to disrupt rapidly growing ‘RaccoonO365’ phishing service

United Kingdom National Charged in Connection with Multiple Cyber Attacks, Including on Critical Infrastructure

Two charged for TfL cyber attack     

Inside the Lighthouse and Lucid PhaaS Campaigns Targeting 316 Global Brands

SystemBC – Bringing the Noise     

Evolution Cybercrime—Key Trends, Cybersecurity Threats, and Mitigation Strategies from Historical Data

Malware

SmokeLoader Rises From the Ashes 

Popular Tinycolor npm Package Compromised in Supply Chain Attack Affecting 40+ Packages 

Satori Threat Intelligence Alert: SlopAds Covers Fraud with Layers of Obfuscation  

Prompts as Code & Embedded Keys | The Hunt for LLM-Enabled Malware

Large-Scale Attack Targeting Macs via GitHub Pages Impersonating Companies to Attempt to Deliver Stealer Malware      

Hacking

A learning approach on exploiting CVE-2020-9273

Rowhammer Attack Demonstrated Against DDR5 

6 Browser-Based Attacks Security Teams Need to Prepare For Right Now

Google Patches Chrome Zero-Day CVE-2025-10585 as Active V8 Exploit Threatens Millions

SonicWall Prompts Password Resets After Hackers Obtain Firewall Configurations 

ShadowLeak: A Zero-Click, Service-Side Attack Exfiltrating Sensitive Data Using ChatGPT’s Deep Research Agent 

CISA Releases Malware Analysis Report on Malicious Listener Targeting Ivanti Endpoint Manager Mobile Systems

Intelligence and Information Warfare

APT Down – The North Korea Files

Hive0154, aka Mustang Panda, drops updated Toneshell backdoor and novel SnakeDisk USB worm  

Israel announces seizure of $1.5M from crypto wallets tied to Iran 

Ukraine claims cyberattacks on Russian election systems; Moscow confirms disruptions 

THREE IRANIAN CYBER ACTORS 

SEC targets US firms tied to suspected Chinese ‘pump and dump’ scams   

Minding the drone gap: Drone warfare and the EU  

Gamaredon X Turla collab 

Modus Operandi of Subtle Snail  

Cybersecurity

AI Agents are Eroding the Foundations of Cybersecurity

Kids in the UK are hacking their own schools for dares and notoriety    

Cloudflare participates in global operation to disrupt RaccoonO365   

JLR could face disruption until November after hack 

Fortra Sheds Light on GoAnywhere MFT Zero-Day Exploit Used in Ransomware Attacks

Palo Alto Networks Unit 42 Recognised by UK’s NCSC as an Enhanced Level Cyber Incident Response Assured Service Provider 

Germany approves new rules to protect critical infrastructure

Passengers stranded at Heathrow, other European airports after cyberattack  

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, newsletter)



you might also like

leave a comment

Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/182390/breaking-news/security-affairs-newsletter-round-542-by-pierluigi-paganini-international-edition.html