Cybersecurity News | Daily Recap [07 Oct 2025]

Cybersecurity News | Daily Recap [07 Oct 2025]

Daily Recap, Researchers disclosed a 13-year Redis vulnerability (CVE-2025-49844) that could allow sandbox escapes and native code execution, impacting about 330,000 instances. The month-round of patches includes OpenSSL in Zabbix Agent, Unity CVE-2025-59489, Y2K38 time manipulation risks, and Microsoft tightening Windows 11 setup flows, with Copilot issues in Office apps.
#Redis #Unity #Zabbix-Agent #Y2K38 #Windows11 #Copilot

Vulnerabilities & Patches

  • Researchers disclosed a 13-year-old Redis vuln (CVE-2025-49844) that lets attackers escape the Lua sandbox and execute native code, impacting nearly 330,000 instances – Redis Flaw, Redis Flaw
  • A misconfigured OpenSSL file in Zabbix Agent for Windows (CVE-2025-27237) can allow local attackers to escalate to SYSTEM—update immediately – Zabbix Agent
  • A critical Unity vulnerability (CVE-2025-59489) permits arbitrary code via malicious command-line args and prompted coordinated fixes from Microsoft/Steam/Unity – Unity Bug
  • Researchers warn the Y2K38 issue is exploitable today through time‑manipulation, posing risks to critical infrastructure and connected devices – Y2K38 Bug
  • Microsoft removed installer tricks that allowed skipping Microsoft Account setup in Windows 11 to enforce secure device configuration – Win11 Setup
  • Microsoft is fixing a bug that causes Copilot and other Office features to fail when multiple Office apps run, resulting in Outlook crashes and related issues – Copilot Bug

Exploits & Ransomware

APTs & Malware Campaigns

  • Modular malware XWorm 6.0 resurfaced with over 35 plugins and expanded data‑theft features, keeping it a persistent global threat – XWorm 6.0
  • A Chinese APT used fake Cloudflare lures to spear‑phish European government and aviation targets and deliver PlugX for espionage operations – PlugX Campaign
  • APT SideWinder launched “Operation SouthNet,” abusing Netlify/Pages.dev to steal credentials and conduct maritime and government espionage across South Asia – SouthNet Ops
  • Scattered Spider has evolved into an insider‑powered access market targeting firms like Microsoft and Apple, monetizing insider access and extortion schemes – Scattered Spider
  • Investigations link Beijing institute BIETA to the MSS, alleging work on steganography and malware that supports Chinese intelligence cyber operations – BIETA Links, BIETA Links
  • New WhatsApp‑based campaign in Brazil spreads Sorvepotel, delivering banking trojans to government and business targets via infected contacts – Sorvepotel

Data Breaches & Incidents

  • Hackers stole support tickets and sensitive user data from a third‑party provider used by Discord, including IDs and messages, and tried to extort the company – Discord Breach, Discord Breach, Discord Breach
  • ShinyHunters has escalated an extortion campaign against Red Hat, leaking samples of stolen customer reports as pressure to pay ransom increases – Red Hat Breach
  • Public‑safety firm BK Technologies reported an intrusion exposing employee data with minor operational impact and most costs covered by insurance – BK Technologies
  • Jaguar Land Rover is restarting global production after a cyberattack that halted manufacturing, supported by government‑backed loans to stabilize operations – JLR Restart

AI, Research & Events

  • New research shows AI is already the top enterprise data‑exfiltration channel—surpassing shadow SaaS—and calls for immediate AI governance and controls – AI Exfil
  • AI‑powered Breach and Attack Simulation platforms convert threat intel into validated attack runs to prioritize fixes and demonstrate measurable ROI to leadership – AI BAS
  • Experts outline 5 critical questions organizations must ask before adopting AI‑SPM solutions to secure AI pipelines, data, and compliance posture – AI Security
  • The Zeroday Cloud hacking contest offers $4.5 million in bounties for bugs in open‑source cloud and AI stacks to harden critical projects – Zeroday Cloud

Funding & M&A

  • French threat‑prevention startup Filigran closed a $58 million Series C to expand globally and scale products like OpenCTI/OpenBAS – Filigran $58M
  • September 2025 saw 40 cybersecurity M&A deals as the sector continues consolidation following 405 deals in 2024—highlighting interest in AI, identity, and IoT security – M&A Roundup

Policy & Telecom

  • Russia is enforcing 24‑hour mobile internet blocks for foreign SIM users citing drone threats, risking travel and cross‑border business connectivity – Russia SIM Block
  • The Signal Foundation warned it will leave the EU market if forced to comply with proposed “Chat Control” mass‑scanning rules that undermine end‑to‑end encryption and privacy – Chat Control

Cybersecurity News | Daily Recap – hendryadrian.com