[CRITICAL] – AI-Orchestrated PaperCut Campaign Compromises 395 Organizations
GreyNoise reports an AI-orchestrated PaperCut campaign compromised at least 440 instances across 395 organizations.
[CRITICAL] – JFrog Artifactory Flaws Actively Exploited to Gain Administrative Control
Wiz reports active exploitation of three Artifactory vulnerabilities, including chains that yield administrative control.
[HIGH] – Trezor Warns of Phishing After Email-Provider Breach
Trezor says attackers breached its email provider and sent phishing messages from its legitimate domain.
[HIGH] – Veradigm Discloses Vendor-Credential Data Exposure
Veradigm says stolen vendor credentials were used to download patient personal data, including some Social Security numbers.
[HIGH] – Check Point Issues Patches for Two Critical VPN Certificate Flaws
Check Point released fixes for two CVSS 9.8 VPN certificate flaws that may permit unauthenticated remote code execution.
[HIGH] – Android September Updates Address 180 Vulnerabilities
Android's September updates address 180 vulnerabilities, including critical System-component issues that may allow remote code execution.
[HIGH] – Wiz Finds Exposed LiteLLM Gateways Accept Default Admin Credentials
Wiz found 9.6% of sampled public LiteLLM instances accepted default or no authentication, enabling severe AI-gateway compromise paths.
[HIGH] – Fortinet CVE-2025-25249 Exploited to Deploy PivotC2
Attackers are exploiting Fortinet CVE-2025-25249 to deploy PivotC2; update affected FortiOS and FortiSwitchManager releases.
[CRITICAL] – NetScaler Authentication Bypass Added to CISA KEV
CISA added an actively exploited NetScaler authentication bypass to KEV; exposed gateway and AAA deployments need urgent updates.
[CRITICAL] – Cisco Talos Tracks Active Secure FMC Exploitation
Cisco reports active exploitation of two Secure FMC flaws, including a CVSS 10 authentication bypass enabling root access.
