
Hello all,
This was not a good week for some of the major players in the industry. Microsoft had portions, if not their entire network, go down several times, Oracle E-Business suite came under attack, SonicWall’s recent breach got worse, Salesforce extortion is astronomic, and dozens of other high-profile companies were reported about.
Headline NEWS:
- Discord warns users after data is stolen in a third-party breach. Reports are that the breach was via their Zendesk portal. Zendesk has responded to the report and has said that this was not done via a vulnerability in their systems. Quite a lot of data appears to have been taken. If you’re a Discord user, rotate your credentials and check what information may have been exposed.
- Juniper Networks wins for the greatest number of vulnerabilities this week with their October 2025 security advisories, unleashing patches for 220 defects, nine of which are critical. In scanning the CVE numbers, it seems that some may have been out there since at least 2019, so patch quickly.
- Oracle has released emergency updates to fix a critical defect in E-Business Suite that the evil group named Cl0p has been actively exploiting. The software and hosting giant discovered the flaw when their customers started receiving emails demanding ransom payments to not expose stolen data. This particular defect allows unauthenticated remote compromise and may have been exposed since July or August. Since this is a retroactive fix, clients need to investigate whether they’ve been compromised already, and if so, determine what was taken. Oracle has released IoC’s and is highly recommending that customers apply the patch as soon as possible.
- Redis 13-year-old defect found and patched. This open-source product that’s used by 75% of cloud environments for in-memory database, caching, efficient communication between servers, and more, has a vulnerability that allows an attacker to escape the Lua sandbox and gain remote code execution access. Once that’s achieved, the dirt bags can do anything they want on the compromised system. Redis urges any internet-exposed systems to prioritize applying the updates. Wiz researchers, which dubbed this exploit RediShell, found at least 60,000 Redis instances online that required no authentication, making them a prime target for this defect.
- SonicWall: 100% of Firewall Backups Were Breached. It was not a good day for SonicWall administrators on Wednesday when the firewall company reported the results of Mandiant’s investigation into their Cloud Backup breach. Initial reports from September 17th were that only 5% of their cloud backup customers had their backup files exfiltrated. It is now known that 100% of were affected. While the backups are theoretically encrypted, threat actors are financially motivated evil geniuses, so it is likely just a matter of time before they find a way to crack open their ill-gotten treasure chests of secrets. Any and every SonicWall that was ever backed up to SonicWall’s Cloud Backup, that is still in active use, now needs to have all credentials reset, and should have additional hardening performed. SonicWall, and many others have guidance on next steps. This will keep admins busy for a while. And if that wasn’t enough, Huntress Labs is reporting that they’re seeing increasing successful intrusions into corporate networks via SSL VPNs on what appear to be fully-patched SonicWall firewalls.
In Ransomware, Malware, and Vulnerabilities News:
- Salesforce breach by Scattered LAPSUS$ Hunters claims 1 billion records. The evil entities’ leak site lists FexEd, Hulu, and Toyota motors. Other companies known to have been hit via a recent third-party breach are Alianz Life, Google, Kering, Stellanis, TransUnion, Quantas, and Workday. The sheer amount of data is mind-boggling. For their part, Salesforce has asserted that they will not pay any ransoms. The lack of some known affected companies in the leak site being listed is leading to speculation that some may have paid for data suppression. We’ve linked to an article named “The Salesloft-Drift Breach: Analyzing the Biggest SaaS Breach of 2025”, while it is a sales-pitch for their product, it also is a great breakdown of this massive win by the threat actors.
In Other News Events of Note and Interest:
- Microsoft is endorsing the use of personal Copilot in workplaces. In a yet another “you’ve got to be kidding me” move, Microsoft is encouraging corporate users that have their own Copilot plan through their Microsoft 365 Family Plan to use the AI in their workplace. So even if the corporation hasn’t purchased an AI license for the user, Microsoft wants them to be able to use their personal one. Naturally, this “multiple account” functionality is on by default and IT Admins must disable it if they don’t want it in their enterprise. Yet another potential hole to plug.
Musings:
I find that I’m still surprised by the lack of cyber hygiene of many people. People reuse passwords. They willingly give up their password reset questions in online surveys. They’ll eagerly click on the first link that shows up in a search engine advertising incredible deals or fail to check if their “friend” actually did send them that email asking, “Did you see what your husband did?”. They just seem to be willingly ignorant. But if I just look around at the non-cyber world, I see the exact same dynamic at play. Have you watched people leaving a public restroom? How many wash their hands? How many people use a paper towel or their shoe to open the door? And what about regular showers? And don’t get me started on postal mail scams for solar panels, home refinance, and the latest rebate program. Sigh, you can’t fix it if people aren’t willing to do their part. But that’s why I’m here, and you’re here. We’re doing our part. Keep it up and…

Keep the shields up!
Viscount Jan Broucinek
Red Dot Security News
Headline NEWS
- Discord warns users after data stolen in third-party breach
- Juniper Networks Patches Critical Junos Space Vulnerabilities
- Oracle Rushes Patch for CVE-2025-61882 After Cl0p Exploited It in Data Theft Attacks
- Oracle issues emergency patch for zero-day flaw exploited by Cl0p ransomware gang
- Oracle EBS Under Fire as Cl0p Exploits CVE-2025-61882 in Real-World Attacks
- Oracle E-Business Suite Zero-Day Exploited in Widespread Extortion Campaign
- Redis warns of critical flaw impacting thousands of instances
- SonicWall: 100% of Firewall Backups Were Breached
- MySonicWall Cloud Backup File Incident gets way worse after Mandiant investigation
- Hackers Access SonicWall Cloud Firewall Backups, Spark Urgent Security Checks
- Huntress Threat Advisory: Widespread SonicWall SSLVPN Compromise
Ransomware, Malware, and Vulnerabilities News
- Good News, Government News, and Interesting
- Cybersecurity Awareness Month 2025: Prioritizing Identity to Safeguard Critical Infrastructure
- CISA adds Oracle, Mozilla, Microsoft Windows, Linux Kernel, and Microsoft IE flaws to its Known Exploited Vulnerabilities catalog
- FBI takes down BreachForums portal used for Salesforce extortion
- California enacts law giving consumers ability to universally opt out of data sharing
- CISA Warns of Windows Privilege Escalation Vulnerability Exploited in Attacks
- $4.6M warning shot: DOJ ramps up cyber enforcement on defense contractors
- Security Firm Exposes Role of Beijing Research Institute in China’s Cyber Operations
- Vulnerabilities and Exploits
- Zeroday Cloud hacking contest offers $4.5 million in bounties
- DDoS Botnet Aisuru Blankets US ISPs in Record DDoS
- Multiple Chrome Vulnerabilities Expose Users to Arbitrary Code Execution Attacks
- Severe Framelink Figma MCP Vulnerability Lets Hackers Execute Code Remotely
- Employees regularly paste company secrets into ChatGPT
- US AI standards institute sounds alarm over DeepSeek
- HackerOne paid $81 million in bug bounties over the past year
- OpenSSH Vulnerability Exploited Via ProxyCommand to Execute Remote Code
- Old authentication habits die hard
- 13-year-old level-10 bug in Redis could allow RCE
- Investigating active exploitation of CVE-2025-10035 GoAnywhere Managed File Transfer vulnerability
- Microsoft: Critical GoAnywhere bug exploited in ransomware attacks
- Google Chrome RCE Vulnerability Details Released Along with Exploit Code
- Zabbix Agent and Agent 2 for Windows Vulnerability Let Attackers Escalate Privileges
- PRC Gov’t Fronts Trick the West to Obtain Cyber Tech
- North Korean hackers stole over $2 billion in crypto so far in 2025, researchers say
- Hundreds of free VPNs offer ‘no real privacy at all,’ researchers warn
- Patch Now: Dell UnityVSA Flaw Allows Command Execution Without Login
- Hackers exploit auth bypass in Service Finder WordPress theme
- 7-Zip Vulnerabilities Let Attackers Execute Arbitrary Code Remotely
- Phishing, Malware, and similar
- Cisco, Fortinet, Palo Alto Networks Devices Targeted in Coordinated Campaign
- XWorm malware resurfaces with ransomware module, over 35 plugins
- BatShadow Group Uses New Go-Based ‘Vampire Bot’ Malware to Hunt Job Seekers
- Chinese Hackers Weaponize Open-Source Nezha Tool in New Attack Wave
- APT Hackers Exploit ChatGPT to Create Sophisticated Malware and Phishing Emails
- New Shuyal Stealer Targets 17 Web Browsers for Login Data and Discord Tokens
- New ClayRat Spyware Targets Android Users via Fake WhatsApp and TikTok Apps
- DraftKings warns of account breaches in credential stuffing attacks
- Investigating targeted “payroll pirate” attacks affecting US universities
- RondoDox botnet targets 56 n-day flaws in worldwide attacks
- Microsoft Teams exploitation in cyberattacks ramp up
- Breaches, Leaks, and Ransomware
- Zero-day lets nation-state spies cross-examine US law firm
- Data Breach at Doctors Imaging Group Impacts 171,000 People
- Rainwalk Pet Insurance Exposes 158 GB of US Customer and Pet Data
- The Salesloft-Drift Breach: Analyzing the Biggest SaaS Breach of 2025
- Hacking group claims theft of 1 billion records from Salesforce customer databases
- Salesforce Tells Clients It Won’t Pay Hackers for Extortion
- Hackers claim to have stolen over a billion Salesforce records – and are demanding nearly $1 billion not to leak them
- Ransomware Gangs Leverage Remote Access Tools to Gain Persistence and Evade Defenses
- Hackers now use Velociraptor DFIR tool in ransomware attacks
- From risk to resilience: 2025 ransomware trends and proactive strategies
- Threat Actors Claim Breach Of Huawei Technologies Source Code and Internal Tools
- JLR cybercrime shows costs to automakers, suppliers, jobs
- ShinyHunters Launches Data Leak Site: Trinity of Chaos Announces New Ransomware Victims
- Electronics giant Avnet confirms breach, says stolen data unreadable
- Ecommerce giant VTEX leaks details of six million shoppers
- Paying ransoms fails to guarantee recovery as cyber criminals demand more while firms burn cash and struggle with rising losses
- Red Hat breach escalates as Crimson Collective recruits help
- Ransomware attack on Ohio county impacts over 45,000 residents, employees
- Qilin ransomware claims Asahi brewery attack, leaks data
- 3 infamous ransomware crews collab to ‘maximize income’
Other News Events of Note and Interest
- Cool Tool: DidMySettingsChange is a tool that checks whether settings have been changed after a Windows update
- Cool Tool: CCleaner 7 arrives with a new design and smarter PC cleaning features
- Cool Tool: LibreOffice 25.8.2 Office Suite Is Now Available for Download with 70 Bug Fixes
- Research Identifies the Right Way to Write
- Proxmox Mail Gateway: Open-source email security solution reaches version 9.0
- Google CodeMender can automatically fix security vulnerabilities in your code
- Google’s new AI bug bounty program pays up to $30,000 for flaws
- Chrome will turn off notifications from sites you don’t often visit
- LinkedIn sues ProAPIs for using 1M fake accounts to scrape user data
- AMD, OpenAI Announce Massive AI-Chip Deal
- Passkeys aren’t scary – passwords are. Let’s bust some security myths
- Synology comes to its senses, removes all HDD limitations from 2025 DiskStation models
- Docker makes Hardened Images Catalog affordable for small businesses
- How to turn a Windows 10 laptop into a Chromebook
- A digital dark age? The people rescuing forgotten knowledge trapped on old floppy disks
- Billy Bass Gets New Job As A Voice Assistant
- AI, LLM’s, and Skynet
- Anthropic Deloitte Partnership
- The State of AI report 2025
- Deloitte will refund Australian government for AI hallucination-filled report
- Six companies pushing the legal world into the AI era
- Sora hit 1M downloads faster than ChatGPT
- Figure AI’s New Humanoid Robot Can Fold Your Clothes, Do the Dishes
- Google details Gemini bug bounties for epic AI-breaking attacks
- Copilot on Windows can now create Office documents and connect to Gmail
- The role of Artificial Intelligence in today’s cybersecurity landscape
- AI gets more ‘meh’ the more you use it, researchers find
- Insurers balk at paying out huge settlements for claims against AI firms
- Enabling meaningful AI adoption at Microsoft with a Microsoft 365 Copilot Expo
- Microsoft
- New Microsoft 365 outage hits as Teams Outlook and more Office apps down
- Apple Mail breaks Outlook sign-ins, but only if you’re unlucky
- Microsoft 365 outage blocks access to Teams, Exchange Online
- Microsoft enables Exchange Online auto-archiving by default
- Microsoft delays Exchange Online feature after major backlash from frustrated IT admins
- Microsoft really wants IT admins to enable web search in Microsoft 365 Copilot
- Employees can bring Copilot from their personal Microsoft 365 plans to work – what it means for IT
- Microsoft suggests new bug breaks Windows Outlook so bad there’s no way to ‘fix’ it
- Microsoft: Windows Backup now available for enterprise users
- Microsoft confirms Windows 11 25H2 releases widely soon, via WSUS
- Microsoft confirms Windows 11 version 25H2 bugs and issues
- Microsoft once again blocks online account bypass on Windows 11
- Microsoft fixes famous “update and shut down” Windows 11 bug
- Microsoft Admits OneDrive Syncing Slows Windows 11 PCs
- Microsoft is endorsing the use of personal Copilot in workplaces, frustrating IT admins
- OneDrive’s dark theme is now available to free and personal accounts
- OneDrive is getting a new Windows app and an AI photo agent
- Windows 11’s dark mode is getting more consistent in File Explorer
- Microsoft fixes weird bug that’s been messing with Windows 11 updates for years
- Microsoft Defender mistakenly flags SQL Server as end-of-life
- Microsoft issues urgent warning ahead of Windows 10 support end
