CyberNews: 25/09/2025 Edition

Published by Dunateo on 2025-09-25

Today’s roundup

  • Urgent: Cisco ASA Zero-Day Duo Under Attack; CISA Triggers Emergency Mitigation Directive
  • Salesforce Patches Critical ForcedLeak Bug Exposing CRM Data via AI Prompt Injection
  • North Korean Hackers Use New AkdoorTea Backdoor to Target Global Crypto Developers
  • UNC5221 Uses BRICKSTORM Backdoor to Infiltrate U.S. Legal and Technology Sectors
  • Malicious Rust Crates Steal Solana and Ethereum Keys — 8,424 Downloads Confirmed
  • CISA: Attackers Breach Federal Agency via Critical GeoServer Flaw
  • Cisco Warns of Actively Exploited SNMP Vulnerability Allowing RCE or DoS in IOS Software
  • Chinese Hackers RedNovember Target Global Governments Using Pantegana and Cobalt Strike
  • Vane Viper Generates 1 Trillion DNS Queries to Power Global Malware and Ad Fraud Network
  • Cyberattack on British retailer Co-op shaved about $275 million from revenues, company says
  • Summary

    Cisco confirmed active exploitation of two zero-day vulnerabilities (CVE-2025-20333/CVE-2025-20362) in ASA and FTD firewall software, prompting CISA to issue an emergency directive requiring federal agencies to patch by September 26. Salesforce addressed critical ForcedLeak vulnerability (CVSS 9.4) enabling CRM data theft through AI agent prompt injection. North Korean actors deployed new AkdoorTea backdoor against crypto developers, combining TsunamiKit and Tropidoor malware. Chinese state-linked UNC5221 targeted US tech firms with BRICKSTORM backdoor via compromised network appliances. Malicious Rust crates 'faster_log' and 'async_println' stole cryptocurrency keys from 8,424 developers. Attackers breached a US federal agency by exploiting critical GeoServer flaw CVE-2024-36401 within two weeks of disclosure. Cisco warned of widespread exploitation of SNMP flaw (CVE-2025-20352) allowing root-level RCE in IOS/XE devices. Chinese APT RedNovember used Cobalt Strike and custom Pantegana malware in global government espionage. Vane Viper's decade-long DNS infrastructure facilitated malvertising and ad fraud via 1 trillion queries. UK retailer Co-op reported £206M revenue loss from April cyberattack requiring system shutdowns.

    Want to dig deeper?

    Vulnerabilities

    CVE-2025-20333 High
    CVE-2025-20362 Medium
    CVE-2024-36401 Critical
    CVE-2025-20352 High