CyberNews: 26/09/2025 Edition

Published by Dunateo on 2025-09-26

Today’s roundup

  • Fortra GoAnywhere CVSS 10 Flaw Exploited as 0-Day a Week Before Public Disclosure
  • Cisco ASA Firewall Zero-Day Exploits Deploy RayInitiator and LINE VIPER Malware
  • Urgent: Cisco ASA Zero-Day Duo Under Attack; CISA Triggers Emergency Mitigation Directive
  • Salesforce Patches Critical ForcedLeak Bug Exposing CRM Data via AI Prompt Injection
  • New macOS XCSSET Variant Targets Firefox with Clipper and Persistence Module
  • Vane Viper Generates 1 Trillion DNS Queries to Power Global Malware and Ad Fraud Network
  • Chinese APT Drops 'Brickstorm' Backdoors on Edge Devices
  • New LockBit Ransomware Variant Emerges as Most Dangerous Yet
  • Interpol Cracks Down on Large-Scale African Scamming Networks
  • Hackers reportedly steal pictures of 8,000 children from Kido nursery chain
  • Summary

    Fortra's GoAnywhere MFT software suffered exploitation of a CVSS 10.0 vulnerability (CVE-2025-10035) starting September 10, 2025, a week before public disclosure. The UK NCSC confirmed Cisco ASA firewalls were compromised via zero-days (CVE-2025-20333/CVE-2025-20362) to deploy RayInitiator and LINE VIPER malware, prompting CISA to issue an emergency directive for federal agencies to mitigate by September 26. Salesforce patched a critical AI Agentforce vulnerability (CVSS 9.4) allowing CRM data theft via indirect prompt injection. Microsoft reported a macOS XCSSET malware variant targeting Firefox with enhanced encryption and clipboard hijacking. Vane Viper's infrastructure generated 1 trillion DNS queries to support global malvertising and ad fraud. Chinese APT UNC5221 deployed new Brickstorm backdoor variants on network edge devices lacking EDR protection. A LockBit ransomware variant with cross-platform capabilities emerged as its most dangerous iteration. Interpol's Operation Contender 3.0 led to 260 arrests targeting African BEC and romance scam networks. Attackers exfiltrated personal data of 8,000 children from Kido nurseries, with ransom demands confirmed by the BBC.

    Want to dig deeper?

    Vulnerabilities

    CVE-2025-10035 Critical
    CVE-2025-20333 High
    CVE-2025-20362 Medium