DragonForce Ransomware Hits MSP via RMM Exploit

Sophos recently uncovered a targeted cyberattack on a Managed Service Provider (MSP) after detecting suspicious activity involving the MSP’s remote monitoring and management (RMM) tool SimpleHelp. The investigation revealed that a threat actor had compromised the RMM platform and used it to deploy DragonForce ransomware across multiple customer environments, exfiltrate sensitive data, and launch a … Continued

Adidas Confirms Customer Data Breach via Third-Party Service Provider

In a statement published on its official website, Adidas has confirmed a data breach involving customer information accessed by an “unauthorised external party.” The sportswear giant clarified that the incident occurred not within its own systems, but through a third-party customer service provider. According to Adidas, the exposed information may include: Full names Email addresses … Continued

Microsoft Issues Emergency Patch for Windows Server 2022 Hyper-V Freezing Bug Impacting Azure Confidential VMs

Microsoft has released an out-of-band (OOB) emergency update to address a critical issue causing some Hyper-V virtual machines (VMs) running on Windows Server 2022 to freeze or restart unexpectedly. The problem primarily affects Azure Confidential VMs, a specialized class of virtual machines designed to secure data during processing, transmission, and storage. The issue stems from … Continued

How a Public Issue Can Breach GitHub Private Repos

Invariant has discovered a critical vulnerability in GitHub’s Model-Centric Programming (MCP) integration—one that allows attackers to hijack AI agents using a malicious GitHub issue and leak sensitive data from private repositories. This vulnerability demonstrates a growing concern in the intersection of AI agents and developer workflows: indirect prompt injection, or what invariant calls them toxic … Continued

npm Malware Map Developer Networks for Supply Chain Attack

Socket’s Threat Research Team has identified a coordinated and ongoing malicious campaign targeting the npm ecosystem, involving at least 60 packages designed to quietly exfiltrate sensitive system information to a threat actor-controlled Discord webhook. What Does it Do? The malicious packages  published under three separate npm accounts deploy post-install scripts that activate during npm install … Continued

Bipartisan Senators Renew Push for NIST Standards Among Federal Contractors

A bipartisan group of lawmakers is making a renewed effort to bolster cybersecurity requirements for federal government contractors. Senators Mark Warner (D-Va.) and James Lankford (R-Okla.) have reintroduced the Federal Contractor Cybersecurity Vulnerability Reduction Act, which would require contractors to adhere to guidelines set by the National Institute of Standards and Technology (NIST) for vulnerability … Continued

AI Models Are Learning to Defy Commands

Just last week, the fictional Ethan Hunt outwitted a rogue AI to save world in Mission: Impossible. But in real life, a new set of experiments from Palisade Research is raising serious concerns about how some AI systems are beginning to act in ways that directly defy human instructions. Palisade Research recently made waves with … Continued

High Severity DoS Vulnerability CVE-2025-47947 Identified in ModSecurity2

A newly disclosed vulnerability in ModSecurity2 firewall, tracked as CVE-2025-47947, has raised concerns over potential Denial of Service (DoS) attacks under specific, rare conditions. The issue was officially published on May 21, 2025, and is rated 7.5 (High) on the CVSS scale. The vulnerability was initially reported privately by a customer in March 2025. After … Continued

PoC Released for Fortinet Vulnerability CVE-2025-3275

FortinGuard Labs issued an advisory for CVE-2025-32756, a critical vulnerability affecting multiple Fortinet products. Just a day later, CVE-2025-32756 was added to CISA’s Known Exploited Vulnerabilities (KEV) catalog. Today researchers at Horizon3.ai released a proof-of-concept (PoC) demonstrating exploitation of the vulnerability. Their analysis focused on comparing the patched and unpatched versions of FortiMail. CVE-2025-32756 According to … Continued

Cisco Discloses Critical RADIUS Vulnerability CVE-2025-20152 in Identity Services Engine

Cisco has issued a high-severity security advisory for a vulnerability affecting its Identity Services Engine (ISE), warning that the flaw could allow unauthenticated remote attackers to trigger a denial of service (DoS) condition on affected devices. CVE-2025-20152 The vulnerability, tracked as CVE-2025-20152, stems from improper handling of certain RADIUS authentication requests within Cisco ISE, a widely … Continued

Newsletter line