- Cyber Threat Intelligence, Emergency Announcement
Cisco confirms active exploitation of three zero-days by advanced threat actors
Cisco confirmed on September 26 a sophisticated attack campaign against ASA 5500-X series devices since May 2025.
- Cyber Threat Intelligence, Emergency Announcement
Emergency Notice – Cisco fixes actively exploited zero-day and multiple vulnerabilities in IOS and IOS XE
Cisco has disclosed 14 security vulnerabilities in its IOS and IOS XE systems, including a critical zero-day that is already being actively exploited by cybercriminals.
- Cyber Threat Intelligence, Emergency Announcement
SonicWall releases urgent update against rootkit in SMA 100 devices
SonicWall released a critical firmware update (version 10.2.2.2-92sv) to eliminate the OVERSTEP rootkit that compromises end-of-life SMA 100 devices.
- Cyber Threat Intelligence, Notificação de Vulnerabilidades OT/ICS
OT-ICS Monthly NDV – September/2025
Critical OT/ICS vulnerabilities identified, impacting vendors such as ABB, Siemens, Honeywell, and Rockwell.
- Cyber Threat Intelligence, Trending Vulnerabilities List
HVL – High-Risk Vulnerabilities List – 09/03 to 09/17
The HVL highlights the top 10 most exploited vulnerabilities, affecting SonicWall, SAP, Cisco, Windows, DELMIA, Sitecore, Linux, Android, Samsung, and Apple.
- Cyber Threat Intelligence, Vulnerability Notification
NDV Monthly – September/2025
Critical and high vulnerabilities identified in SAP, FreePBX, Cisco, Argo CD, Microsoft, Docker, Citrix, Adobe, Windows, and Apple. Immediate patching is required to reduce risk.
- Cyber Threat Intelligence, Intelligence Bulletin
Intelligence Bulletin – How Murky Panda has revolutionized cloud attacks through Microsoft Entra ID
Chinese group Murky Panda exploits cloud trust relationships and abuses Microsoft Entra ID, compromising suppliers and SaaS to steal data.
- Cyber Threat Intelligence, Vulnerability Notification
VN Extraordinary – Windows Server Message Block (SMB)
Microsoft patched CVE-2025-55234 (CVSS 8.8) in Windows SMB, a flaw enabling relay attacks and privilege escalation. Classified as a zero-day, it was disclosed before the official patch.
- Cyber Threat Intelligence, Emergency Announcement
Largest npm supply chain attack in history hits packages with 2.6 billion weekly downloads
🔴 Largest npm supply chain attack compromised 18 critical packages (chalk, debug, ansi-styles), impacting billions of installs and targeting cryptocurrency theft.