Daily Recap, Oracle patching urgency follows active SSRF exploitation in E-Business Suite as researchers flag 94+ n-day Chromium vulnerabilities impacting IDE tooling. Also highlighted are Bitter APTβs WinRAR zero-day, PolarEdge expanding to new routers, and Passiveneuron/Neursite backdoors detected in campaigns.
#Oracle #SSRF #BitterAPT #WinRAR #PolarEdge #PassiveNeuron
#Oracle #SSRF #BitterAPT #WinRAR #PolarEdge #PassiveNeuron
Vulnerabilities & Patches
- Oracle released its October 2025 security updates while CISA confirmed active exploitation of an Oracle E-Business Suite SSRF flaw, underscoring urgent patching β Oracle Patches, Oracle SSRF
- TP-Link patched four Omada gateway flaws including two allowing remote code execution and warned of a critical command injection in Omada gatewaysβapply updates β TP-Link Omada, TP-Link Warning
- Researchers disclosed the TARmageddon flaw in the abandoned async-tar Rust library that could enable remote code execution via crafted archives β TARmageddon, Async-Tar Flaw
- Active exploitation detected for a critical Windows SMB flaw CVE-2025-33073, prompting immediate mitigation β SMB Flaw
- Cursor and Windsurf IDEs were found riddled with over 94 n-day Chromium vulnerabilities affecting developer tooling β IDE Chromium
- Microsoftβs recent Windows updates caused login issues on some PCs sharing security IDs, and a separate patch fixed a bug preventing users from opening classic Outlook β Windows Login Issues, Outlook Fix
Malware & APTs
- Researchers tracked the PassiveNeuron APT deploying Neursite and NeuralExecutor backdoors and abusing MS SQL servers for stealthy deployments β PassiveNeuron, PassiveNeuron Report
- The Bitter APT used a WinRAR zero-day and a new C# backdoor delivered via Office macros to target China and Pakistan β Bitter APT
- Russian state-sponsored COLDRIVER actors are replacing burned toolsets (including LOSTKEYS) with new malware, according to Google and reporting β COLDRIVER Tools, COLDRIVER Follow-up
- Attackers evolved malicious ClickFix/PhantomCaptcha βI am not a robotβ flows to push malware and recently targeted Ukraine war-relief organizations β Captcha Malware, Captcha Evolution
- The Brazilian Caminho Loader hides a malware delivery chain inside image files to bypass defenses β Caminho Loader
- Vidar Stealer 2.0 adds multi-threaded data theft and improved evasion to accelerate credential and data exfiltration β Vidar Stealer
- A doxxing campaign exposed Lumma Stealer developers and has slowed the malwareβs operations and ecosystem activity β Lumma Doxxed, Lumma Slowed
- PolarEdge botnet expanded to target Cisco, ASUS, QNAP, and Synology routers to recruit devices at scale β PolarEdge Botnet
- ToolShell SharePoint attacks targeted organizations across four continents using SharePoint-based toolsets to maintain access β ToolShell SharePoint
Ransomware & Incidents
- A cyberattack disrupted operations at Heywood and Athol hospitals in Massachusetts, affecting services and patient care β Hospital Attack
- Jewett-Cameron fencing and pet company reported a ransomware incident impacting business operations β Jewett Ransom
- Ransomware activity is escalating in APAC, exploiting VPN flaws, Microsoft 365 logins and custom Python scripts, while overall ransom payments rose larger even as fewer victims pay β Ransomware APAC, Ransomware Payments
Events & Research
- On day one of Pwn2Own Ireland 2025 researchers exploited 34 zero-days and earned over $520,000 in payouts, highlighting ongoing exploit research value β Pwn2Own Earnings, Pwn2Own Zero-Days
- βUnseeableβ prompt injection techniques were described as a new threat that can stealthily manipulate AI agents and chain malicious actions β Prompt Injection
Policy & Disinformation
- Google exposed a Russian disinformation blitz over a Poland airspace incursion using the Portal Kombat network to amplify false narratives β Disinfo Poland
- Russia is pressuring Apple to set Russian search engines as the default on locally sold iPhones, raising privacy and market concerns β Russia Apple
Industry Moves
- Gravwell closed a $15.4M funding round to expand its data analytics and security platform β Gravwell Funding
- SBOM pioneer Allan Friedman joined NetRise to advance software supply chain visibility and SBOM adoption β Allan Friedman
- Defakto raised $30M for its non-human identity and access management platform to secure machine identities β Defakto Raise
- Meta rolled out new protections to help shield WhatsApp and Messenger users from scams and social engineering β Meta Tools
Security Guidance & Breaches
- The FinWise data breach underscores why strong encryption is often the last line of defense when other controls fail β FinWise Breach
- Security guidance now favors longer, memorable passphrases over complex passwords to reduce helpdesk tickets and improve resistance to brute-force attacks per NIST recommendations β Passphrases
- A guide stresses going beyond basic configuration to harden gateway devices and reduce attack surface across network edge devices β Gateway Security