CISA has warned that a critical (10/10) Cisco authentication bypass vulnerability is being exploited in the wild, allowing attackers to downgrade or bypass security controls. Cisco has issued guidance and mitigations, with fixes expected or rolling out; organizations should immediately restrict access to management interfaces, apply Cisco’s recommended mitigations, and hunt for anomalous logins or configuration changes.
Source: Forbes Security
Thousands of public Google Cloud API keys expose access to Gemini endpoints
Researchers at Truffle Security found nearly 3,000 publicly exposed Google API keys (“AIza…”) embedded in client-side code that could be abused to authenticate to sensitive Gemini AI endpoints and access private data once relevant APIs are enabled. Teams should treat these keys as secrets: rotate any exposed keys, enforce referrer/IP restrictions and least-privilege scopes, and proxy sensitive requests through secured backends.
Source: TheHackerNews
CVE‑2025‑64328 mass‑exploited: 900 Sangoma FreePBX servers backdoored with web shells
Attackers have been exploiting a command injection flaw in Sangoma FreePBX since December 2025, leaving roughly 900 instances infected with persistent web shells. Admins should urgently patch to a fixed version, audit for web shells and unauthorized admin users, and rotate credentials and keys that may have been exposed.
Source: Security Affairs
Trojanized gaming utilities drop stealthy RAT via PowerShell and LOLBins, Microsoft warns
Microsoft researchers report threat actors are seeding trojanized gaming tools through browsers and chat platforms to deliver a remote access trojan. The campaign leans on PowerShell and living‑off‑the‑land binaries to blend in and employs Defender evasion tactics; restrict scripting where possible, monitor for unusual PowerShell activity, and only obtain game utilities from trusted publishers.
Source: Security Affairs
Canadian Tire breach impacts 38 million accounts
Canadian Tire disclosed that names, addresses, email addresses, phone numbers, and encrypted passwords were exposed in an October 2025 incident affecting 38 million accounts. Customers should reset passwords (and avoid reuse), enable MFA, and remain vigilant for targeted phishing; enterprises can expect credential stuffing attempts leveraging the stolen data.
Source: SecurityWeek
Krebs probes ‘Dort,’ alleged Kimwolf botnet boss behind DDoS, doxing, and swatting
KrebsOnSecurity examines public breadcrumbs around “Dort,” the controller of the Kimwolf botnet that coalesced after a disclosed vulnerability was weaponized. Since January, Dort has led sustained DDoS, doxing, email flooding, and even a swatting attack on a researcher—offering investigators fresh leads on the botnet’s infrastructure and operator persona.
Source: KrebsOnSecurity
Hacked prayer app pushes ‘surrender’ messages to Iranians in live psyops campaign
As strikes hit Tehran, Iranians received push notifications promising amnesty if they surrendered—apparently sent from a compromised prayer app. The incident underscores how mobile apps and push-notification keys can be hijacked for real‑time influence operations; developers should harden notification credentials with MFA and rotation, while users treat in‑app alerts during crises with caution.
Source: WIRED
You May Also Be Interested In...
ClawJacked flaw lets malicious sites hijack local OpenClaw AI agents via WebSocket
Check your Gmail account security now as hackers continue attacks
Iran plunges into ‘near‑total internet blackout’ amid regional strikes