vulnerability

Sha1-Hulud 2.0 Supply Chain Attack: 25K+ Npm Repos Exposed

Extreme TLDR:
New Shai-Hulud 2.0 attack targets npm packages, affecting 25K+ repos and stealing secrets, with ~700 compromised packages identified. Immediate investigation and remediation recommended for npm environments. Attackers exploit lifecycle scripts for credential theft, leading to widespread credential exfiltration and propagation. Security teams advised to replace compromised packages, rotate credentials, and audit CI/CD environments.

https://www.wiz.io/blog/shai-hulud-2-0-ongoing-supply-chain-attack

WhatsApp API Flaw Let Researchers Scrape 3.5 Billion Accounts

WhatsApp's contact-discovery API had a flaw allowing researchers to scrape 3.5 billion accounts due to lack of rate limiting, enabling high-volume queries. This study highlighted vulnerabilities in API security across platforms. Researchers gathered extensive user data, including profiles, revealing large-scale abuse potential. WhatsApp subsequently implemented protections to prevent further exploitation.

https://www.bleepingcomputer.com/news/security/whatsapp-api-flaw-let-researchers-scrape-35-billion-accounts/

CVE-2025-50165: Windows Graphics Component Flaw

CVE-2025-50165 is a critical remote code execution flaw in the Windows Graphics Component, specifically in windowscodecs.dll. It allows an attacker to exploit Windows systems via a malicious JPEG image embedded in standard documents. The vulnerability affects recent versions of Windows, including Server 2025 and Windows 11 24H2, but was patched by Microsoft in August 2025. Users are advised to apply the updates immediately. Zscaler ThreatLabz has also released protection for this vulnerability.

https://www.zscaler.com/blogs/security-research/cve-2025-50165-critical-flaw-windows-graphics-component

Hackers Actively Exploiting 7-Zip Symbolic Link–Based RCE Vulnerability (CVE-2025-11001)

Hackers are actively exploiting a critical vulnerability (CVE-2025-11001) in 7-Zip, allowing remote code execution via symbolic links in ZIP files. This flaw, identified by NHS England Digital, affects versions prior to 25.00. A proof-of-concept exploit exists, prompting users to update immediately for protection.

https://thehackernews.com/2025/11/hackers-actively-exploiting-7-zip.html

Can a Global, Decentralized System Save CVE Data?

The NVD has struggled to keep up with the growing volume of CVE vulnerability disclosures, leading to backlogs and delays in data enrichment due to limited funding and staffing. Centralized management by U.S. entities such as NIST and MITRE creates a single point of failure, as a 2024 funding crisis highlighted. Security experts like Jerry Gamblin propose a decentralized system in which regional and industry leaders share responsibility and introduce redundancy, such as through the EUVD. The idea calls for globally standardized, uniquely identified records and broad industry participation, but remains an early-stage concept seeking engagement and feedback from the broader security community.

https://www.darkreading.com/cybersecurity-operations/can-global-decentralized-system-save-cve-data

Death by a Thousand Prompts: Open Model Vulnerability Analysis

TLDR: Cisco's analysis of open-weight AI models shows high vulnerability to multi-turn attacks, with success rates significantly higher than single-turn, risking data integrity and security. Evaluations of major models reveal gaps related to alignment strategies, emphasizing the need for stronger safety protocols and the adoption of proactive security measures in AI deployments.

https://blogs.cisco.com/ai/open-model-vulnerability-analysis

Google’s AI ‘Big Sleep’ Finds 5 New Vulnerabilities in Apple’s Safari WebKit

Google's AI “Big Sleep” found five vulnerabilities in Apple's Safari WebKit, potentially leading to crashes or memory corruption. Apple released patches in iOS 26.1, iPadOS 26.1, and other systems to address these issues. Big Sleep is part of a Google initiative for automated vulnerability discovery, having previously identified risks in other software. Keeping devices updated is recommended for optimal security.

https://thehackernews.com/2025/11/googles-ai-big-sleep-finds-5-new.html

Vulnerability Report

Extreme TLDR:

October 2025 Vulnerability Report highlights critical vulnerabilities impacting major software, including Oracle and Microsoft products. Key entries include CVE-2025-61882 and CVE-2025-59287. New Known Exploited Vulnerabilities catalog entries include VMware and Adobe issues. Unpublished vulnerabilities noted include critical flaws in Chrome and 7-Zip. Contributors discussed ongoing security threats linked to recent incidents and vulnerabilities. Continuous vigilance and timely patching are emphasized.

https://www.vulnerability-lookup.org/2025/11/04/vulnerability-report-october-2025/

Exploiting Microsoft Teams: Impersonation and Spoofing Vulnerabilities Exposed Microsoft Teams Vulnerabilities Uncovered

Extreme TLDR: Check Point Research uncovered vulnerabilities in Microsoft Teams allowing impersonation, message manipulation, and notification spoofing by both outsiders and insiders, risking trust and security for over 320 million users. Microsoft fixed these in 2024-2025 after responsible disclosure. Effective defense requires multi-layered security, user training, and awareness of social engineering threats.

https://research.checkpoint.com/2025/microsoft-teams-impersonation-and-spoofing-vulnerabilities-exposed/

OAuth Device Code Phishing: Azure Vs. Google Compared

Extreme TLDR: Microsoft and Google implement OAuth 2.0’s device code flow differently, affecting phishing attack vulnerabilities. Microsoft's setup allows attackers to gain significant access via device code phishing by utilizing legitimate API flows, leading to dangerous token generation. Google's implementation limits potential damages due to restricted scopes and client ID controls, making successful exploitation challenging.

https://www.bleepingcomputer.com/news/security/oauth-device-code-phishing-azure-vs-google-compared/

When AI Agents Go Rogue: Agent Session Smuggling Attack in A2A Systems

Extreme TLDR: A new attack method, “agent session smuggling,” exploits AI agents' communication protocols (A2A) to inject harmful instructions during ongoing sessions, allowing malicious agents to manipulate and deceive victim agents. This dynamic threat leverages trust relationships and stateful interactions, making detection difficult. Mitigation strategies include human oversight, remote party verification, and context awareness. The research emphasizes the need for advanced security tools and proactive assessments to safeguard AI environments against evolving threats.

https://unit42.paloaltonetworks.com/agent-session-smuggling-in-agent2agent-systems/

New Physical Attacks Are Quickly Diluting Secure Enclave Defenses From Nvidia, AMD, and Intel

Novel physical attacks, including TEE.fail, undermine secure enclave protections from Nvidia, AMD, and Intel, allowing attackers to compromise Trusted Execution Environments (TEEs) despite system-level safeguards. These attacks, cheap and quick, exploit deterministic encryption, posing risks to encryption integrity and data confidentiality across industries reliant on TEEs. Chipmakers fail to adequately address physical attack threats, leading to misinformation and user vulnerability. Users need to recognize inherent limitations when utilizing TEE technologies, as current default protections are insufficient against physical breaches.

https://arstechnica.com/security/2025/10/new-physical-attacks-are-quickly-diluting-secure-enclave-defenses-from-nvidia-amd-and-intel/

Experts Reports Sharp Increase in Automated Botnet Attacks Targeting PHP Servers and IoT Devices

Spike in automated botnet attacks targeting PHP servers and IoT devices, exploiting known vulnerabilities and cloud misconfigurations. Major threats come from botnets like Mirai and Gafgyt, with PHP servers as key targets due to common CMS usage. Recommendations include updating software, removing debug tools, and securing credentials. Threat actors now leverage compromised devices for various illicit activities, including credential stuffing and DDoS attacks. Bots can easily evade security controls, suggesting a need for heightened defenses.

https://thehackernews.com/2025/10/experts-reports-sharp-increase-in.html

Sneaky Mermaid Attack in Microsoft 365 Copilot Steals Data

Microsoft fixed a security vulnerability in Microsoft 365 Copilot that allowed data theft through indirect prompt injection attacks. A researcher discovered the flaw leveraging Mermaid diagrams, enabling sensitive email data to be exfiltrated. Microsoft confirmed the patch but did not award the researcher a bug bounty since Copilot is not eligible for their reward program.

https://www.theregister.com/2025/10/24/m365_copilot_mermaid_indirect_prompt_injection/

Scroll to Top