Daily Recap, Cisco patched an actively exploited Secure Email Gateway zero-day that enables command execution as root, while China-linked actors chained a Chrome-Windows zero-day to deploy GRIMWEDGE. Attackers also targeted WooCommerce/WordPress via a third-party plugin, abused exposed Vite dev servers for AWS/Azure secrets, and leveraged a Telegram Desktop HTML export flaw to exfiltrate messages, alongside ongoing ransomware exploitation of a VMware vCenter RCE flaw.
#Cisco #GRIMWEDGE #WooCommerce #WordPress #Vite #AWS #Azure #TelegramDesktop #VMwarevCenter #ClickFix #PasteSwitch #DDROP #BlackAxe
#Cisco #GRIMWEDGE #WooCommerce #WordPress #Vite #AWS #Azure #TelegramDesktop #VMwarevCenter #ClickFix #PasteSwitch #DDROP #BlackAxe
Exploits & Malware
- Cisco patched an actively exploited Secure Email Gateway zero-day that lets attackers run commands as root, while China-linked threat actors chained a Chrome-Windows zero-day to deploy GRIMWEDGE. β Cisco Zero-Day, Chrome Chain
- Attackers are abusing a third-party WooCommerce plugin to hit WordPress sites, targeting exposed Vite dev servers for AWS/Azure secrets, and using a hidden JavaScript flaw in Telegram Desktop HTML exports to exfiltrate messages. β WooCommerce Attack, Vite Secrets, Telegram Flaw
- A Fortinet vulnerability was used to compromise a Thai broadband provider, and a separate 3BB intrusion involved a MeshCentral backdoor to gain root access and steal subscriber credentials. β Fortinet Breach, 3BB Backdoor
- Researchers say a new DDROP attack can break confidential computing on Intel TDX and AMD SEV-SNP, undermining protected workloads. β DDROP Attack
Ransomware & Critical Infrastructure
- CISA warned that a critical VMware vCenter RCE flaw is now being exploited by ransomware gangs, highlighting continued attacks on enterprise virtualization. β VMware RCE
- HBO Max and a compromised Reddit account were used in ClickFix ad campaigns tied to a massive PasteSwitch malware operation that pushed users toward malicious downloads. β HBO Max Ads, PasteSwitch Ops
- A pro-Ukraine hacking group known as Cat is deploying new malware against Russian targets amid the ongoing cyber conflict. β Cat Malware
Identity, Tokens & Data Exposure
- A Twitch extension with 30K installs exposed usersβ OAuth tokens, while Japanβs Digital Agency said a VPN flaw exposed 246,000 personnel records. β Twitch Tokens, Japan VPN Leak
- Hundreds of fake government sites are targeting users in Central Asia, while a compromised HBO Max Reddit account was also used to spread malware through deceptive ads. β Fake Gov Sites, Reddit Abuse
- OpenAI is investigating reports that AI agents may have been linked to the RubyGems attack, adding more scrutiny to autonomous tooling in supply-chain incidents. β RubyGems Probe
Law Enforcement & Geopolitics
- Five alleged leaders of Black Axe were extradited from South Africa to the US to face cybercrime charges tied to the groupβs broader fraud and intrusion operations. β Black Axe Charges, Black Axe Extradition
- Beijing pushed back against Anthropic CEO warnings on Chinaβs AI development, as broader concerns about AI risks and governance continue to intensify. β China AI Row, AI Risk Debate
Vulnerabilities & Patch Notes
- Microsoft issued emergency Windows updates to fix RDS failures caused by September security patches, restoring RDP access and addressing issues in Windows Server, Windows 11, and some Hyper-V/USB Audio setups. β Windows Fix
- Microsoft also confirmed the KB5002914 Excel update breaks copy-and-paste behavior, creating an unexpected productivity issue for users. β Excel Bug
- Homebrew 7.0.0 shipped with a built-in GUI and stronger security controls, while Apple is adding parental controls in iOS 27 so kids can ask before opening new websites. β Homebrew 7.0, iOS Parental Controls
AI, Governance & Security Trends
- Security leaders say employees are already using unapproved AI tools, and many audit executives still struggle to quantify what AI is worth. β Shadow AI, AI Value
- New product updates from Entrust, Bitsight, and Dataminr focus on turning cryptographic inventory, exposure data, and threat intelligence into faster security action. β Entrust CBOM, Bitsight Beacon, Dataminr AI