
Hello all,
Happy Fall! Another week of lots of excitement in our world of cyber defense. The biggest news is that Apple somehow lost versions 19 – 25 of their operating system, going right to version 26. And several firewall vendors have had a bad week with vulnerabilities, zero-days, and a data breach. There were also some nice wins by Cloudflare, Google, Microsoft and the US Government.
This email and video commentary is from the RedDotSecurity.news website that contains a plethora of links to other items, not mentioned here, that are worth skimming to see if they interest you or pertain to your particular environment or of those you support. There is a lot more than what is provided in these opening comments. So, on to the headline news.
Headline NEWS:
- Apple made the news several times this week. The first is that they backported the fix for their actively exploited zero-day image processing defect to many older devices. This applies to iOS 15.8.5 / 16.7.12, and iPadOS 15.8.5 / 16.7.12. Apple iOS 26 was unleashed onto the public, offering multiple security fixes for defects, and improved security via a new Memory Integrity Enforcement (MIE) process. Apple’s newest devices, such as the iPhone 17, will also receive something named Enhanced Memory Tagging Extension (EMTE). Not everyone is happy with this new operating system version, so read the reviews prior to upgrading, because downgrades are not easy.
- Chaos Mesh has four critical defects in Controller Manager, named Chaotic Deputy, which enable attackers to achieve Remote Code Execution (RCE), potentially resulting in takeover of the Kubernetes cluster. Patch to the latest version as soon as possible.
- Greenshot is a stalwart screen capture utility that is loved by millions. Recently it received an updated version, and it seems that someone immediately broke it, finding a defect which can enable malware to run in the context of the Greenshot process. Upgrade to the latest version to plug this hole.
- GoAnywhere is a file transfer utility by Fortra has been discovered to have a “deserialization vulnerability” which could result in command injection. The fix is to update to the latest version.
- Google Chrome V8 engine required another trip to the mechanic. A critical vulnerability was found which should be patched immediately since it is already under active exploitation. Since they share the underlying codebase, watch for updates in other Chromium based browsers, which should be coming soon.
- SonicWall apparently had a brick or two missing in their cloud backup’s wall. An unnamed threat actor managed to exfiltrate firewall configurations, including secrets and credentials. While the threat actor apparently didn’t make away with every configuration stored in the cloud, it is quite extensive. SonicWall, which is still investigating, has been contacting customers that they know were affected. Meanwhile, affected organizations must go through the fire-drill of resetting all of the secrets and local credentials on the affected units. Instructions are available at SonicWall’s support site. The vendor has a webinar scheduled for Monday afternoon to provide details and a question-and-answer time. I’m going to make some popcorn. This could be quite entertaining,
- TP-Link has some routers under zero-day exploitation attack. This defect is in the Customer Premises Equipment WAN Management Protocol (CWMP), also known as TR-069. If you have TP-Link routers anywhere in your care, check for updates and apply any you find. If your device is EOL, replace it as soon as is humanly possible.
- WatchGuard doesn’t make news too often, but when it does, it is a doozy. This past week they revealed a critical defect in Firebox firewalls. The vulnerability is in the IKEv2 VPN, however WatchGuard has warned that even if you don’t currently use this, if you’ve ever used it you could be vulnerable. If you have any Firebox firewalls that you manage, update as soon as you can. This Remote Code Execution defect is not currently known to be exploited, but ransomware operators love firewall flaws, so it is only a matter of time.
In Ransomware, Malware, and Vulnerabilities News:
- Jaguar Land Rover is now entering their third week of work stoppage due to a ransomware attack against them by Scattered Lapsus$ Hunters. The disruption is now having significant ripple effects on suppliers and vendors, forcing them to scale back or to halt operations. This underscores the truly evil, malevolent nature of the inhuman scum that perpetrate these terroristic acts upon hundreds, if not thousands of people who are just trying to earn a living, whose workplaces slow down or shut down as a result. In most cases, if you aren’t working you aren’t getting paid. I’m all for branding these groups as terrorists and treating them as such.
In Other News Events of Note and Interest:
- Tik Tok Sale appears to be back on track. Oracle, Silver Lake and Andreessen Horowitz are part of consortium that would purchase an 80% stake in the viral Chinese spyware firm, including their proprietary algorithms which enabled the service achieve such rabid popularity worldwide. It is unclear at this time who would control the other 20%.
Musings:
I’ve been told by some that all I ever bring is bad news, in that vein, I present what I’m considering nominating as the theme song for cyber defenders worldwide. This musical masterpiece was a trope that was a reoccurring bit on the show Hee-Haw.
Gloom, despair, and agony on me
Deep, dark depression, excessive misery
If it weren’t for bad luck, I’d have no luck at all
Gloom, despair, and agony on me
If you’ve been reading or watching RedDotSecurity.news for a while, you’ll know that the above isn’t true; every week we do have wins, sometimes big ones. However, it is important to always…

Keep the shields up!
Viscount Jan Broucinek
Red Dot Security News
Headline NEWS
- Apple backports zero-day patches to older iPhones and iPads
- Apple Backports Fix for CVE-2025-43300 Exploited in Sophisticated Spyware Attack
- iOS 26: Apple releases “most significant security upgrade” to better protect you against mercenary spyware attacks
- Apple Rolls Out iOS 26, macOS Tahoe 26 With Patches for Over 50 Vulnerabilities
- Chaos Mesh Critical GraphQL Flaws Enable RCE and Full Kubernetes Cluster Takeover
- Windows Screenshot Utility Greenshot Vulnerability Enable Malicious code execution – PoC Released
- Fortra warns of max severity flaw in GoAnywhere MFT’s License Servlet
- Google Patches Chrome Zero-Day CVE-2025-10585 as Active V8 Exploit Threatens Millions
- Attack on SonicWall’s cloud portal exposes customers’ firewall configurations
- TP-Link Router Zero-Day Lets Attackers Execute Code by Bypassing ASLR
- WatchGuard warns of critical vulnerability in Firebox firewalls
Ransomware, Malware, and Vulnerabilities News
- Microsoft seizes 340 websites linked to growing phishing subscription service
- Microsoft and Cloudflare teamed up to dismantle the RaccoonO365 phishing service
- Google nukes 224 Android malware apps behind massive ad fraud campaign
- US government charges British teenager accused of at least 120 ‘Scattered Spider’ hacks
- Rand Paul’s last-minute demands push key cybersecurity law to the brink
- CISA Warns of Two Malware Strains Exploiting Ivanti EPMM
- FBI Warns of Threat Actors Hitting Salesforce Customers
- FBI Issues Salesforce Instance Warning Over ‘ShinyHunters’ Data Theft
- Cyberattack hits check-in systems at some of Europe’s busiest airports
- Top Zero-Day Vulnerabilities Exploited in the Wild in 2025
- China tells its tech companies they can’t buy AI chips from Nvidia
- China: 1-hour deadline on serious cyber incident reporting
- The countdown is on – Chinese firms now have just an hour to report cybersecurity incidents
- 600 GB of Alleged Great Firewall of China Data Published in Largest Leak Yet
- Chinese TA415 Uses VS Code Remote Tunnels to Spy on U.S. Economic Policy Experts
- Security Industry Skeptical of Scattered Spider-ShinyHunters Retirement Claims
- CZ, Crypto ‘SEAL’ Team Sound Alarm On 60 North Korean Hackers
- UNC1549 Hacks 34 Devices in 11 Telecom Firms via LinkedIn Job Lures and MINIBIKE Malware
- FileFix attacks trick victims into executing infostealers
- Threat Actors Leverage Several RMM Tools in Phishing Attack to Maintain Remote Access
- SystemBC Powers REM Proxy With 1,500 Daily VPS Victims Across 80 C2 Servers
- Samsung Zero-Day Vulnerability Actively Exploited to Execute Remote Code
- LG WebOS TV Vulnerability Let Attackers Bypass Authentication and Enable Full Device Takeover
- OT security needs continuous operations, not one-time fixes
- Phoenix RowHammer Attack Bypasses Advanced DDR5 Memory Protections in 109 Seconds
- New Phoenix attack bypasses Rowhammer defenses in DDR5 memory
- BitlockMove Tool Enables Lateral Movement via Bitlocker DCOM & COM Hijacking
- Self-propagating worm fuels latest npm supply chain attack
- Hundreds of NPM packages hit in ongoing attack
- Decade-Old Pixie Dust Wi-Fi Hack Still Impacts Many Devices
- Mosyle uncovers new cross-platform malware undetected by antivirus tools
- Old file types, new tricks: Attackers turn everyday files into weapons
- Microsoft OneDrive Auto-Sync Exposes Enterprise Secrets in SharePoint Online
- LastPass Warns of Fake Repositories Infecting macOS with Atomic Infostealer
- Yellow.ai chatbot flaw could lead to cookie theft
- Hackers Using Generative AI ‘ChatGPT’ to Evade Anti-virus Defenses
- This ‘critical’ Cursor security flaw could expose your code to malware – how to fix it
- Linux CUPS Vulnerability Let Attackers Remote DoS and Bypass Authentication
- New FileFix Variant Delivers StealC Malware Through Multilingual Phishing Site
- New APT28 Attack Via Signal Messenger Delivers BeardShell and Covenant Malware
- New VoidProxy Phishing Service Bypasses MFA on Microsoft and Google Accounts
- 17,500 Phishing Domains Target 316 Brands Across 74 Countries in Global PhaaS Surge
- Cybercriminals now have SpamGPT, an AI-powered toolkit making phishing, ransomware campaigns, and email attacks dangerously simple and efficient
- Hackers Hide RMM Installs as Fake Chrome Updates and Teams Invites
- New Malware Loader ‘CountLoader’ Weaponized PDF File to Deliver Ransomware
- How a Plaintext File On Users’ Desktops Exposed Secrets Leads to Akira Ransomware Attacks
- Mustang Panda Uses SnakeDisk USB Worm and Toneshell Backdoor to Target Air-Gap Systems
- HybridPetya ransomware bypasses UEFI Secure Boot echoing Petya/NotPetya
- New HybridPetya ransomware can bypass UEFI Secure Boot
- Malware spread on Google as WhatsApp and Chrome
- Google confirms fraudulent account created in law enforcement portal
- Unmasking The Gentlemen Ransomware: Tactics, Techniques, and Procedures Revealed
- Gucci, Balenciaga and Alexander McQueen Breach Linked to ShinyHunters
- Tiffany Data Breach Impacts Thousands of Customers
- Kering Confirms Data Breach Exposing Customer Information
- Nearly 250,000 Impacted by Data Breach at Medical Associates of Brevard, FL
- Union County, NC town government hacked in recent cyber attack
- Uvalde CISD closes schools after ransomware attack on district systems
- JLR faces production issues, mounting costs following cyberattack
- Jaguar Land Rover extends shutdown after cyberattack by another week
- Jaguar Land Rover suppliers’ output hit by cybersecurity attack
- Qilin ransomware gang claims attack on Orleans Parish Sheriff’s Office
- BlackNevas Ransomware Encrypts Files and Steals Sensitive Data From Affected Companies
- New ‘shinysp1d3r’ Ransomware-as-a-service in Active Development to Encrypt VMware ESXi Environments
- Researchers Uncover GPT-4-Powered MalTerminal Malware Creating Ransomware, Reverse Shell
Other News Events of Note and Interest
- Cool Tool: I absolutely love the new Phone Link on Windows 11
- NIST Awards More Than $3 Million to Support Cybersecurity Workforce Development Across 13 States
- Bridging humanity and technology: Brené Brown on leadership’s new challenge
- Engineer turned a vape into a web server
- Windows lives on the C: drive, and the reason it’s not called A: or B: goes back to the 1970s
- Consumer Reports calls Microsoft ‘hypocritical’ for stranding millions of Windows 10 PCs
- US and China Reach ‘Framework’ for a TikTok Sale
- TikTok Buyers to Include Oracle, Silver Lake and Andreessen
- TikTok deal will be signed soon, with US control of algorithm: White House
- Meta Connect 2025: the 6 biggest announcements
- The double-sided brilliance of Google’s new native Windows app
- What the Google Password Manager app means for Chrome users
- Google Chrome is finally getting native vertical tabs
- Google adds Gemini to Chrome in push to bolster AI search
- Announcing Agent Payments Protocol (AP2)
- YouTube announces new generative AI tools for Shorts creators
- Internet Archive, UMG settle Great 78 Project lawsuit
- Here are all the new features in iOS 26, iPadOS 26, macOS Tahoe
- Should you upgrade to iOS 26? Some iPhones owners are already regretting it – here’s why
- Salesforce launches ‘Missionforce,’ a national security-focused business unit
- OpenAI’s research on AI models deliberately lying is wild
- It Turns Out That Google’s AI Is Being Trained by an Army of Poorly Treated Human Grunts
- Amateurs Using AI to “Vibe Code” Are Now Begging Real Programmers to Fix Their Botched Software
- Hugging Face Releases FinePDFs: A 3-Trillion-Token Dataset Built from PDFs
- AMD details fixes for various Windows 11/10 chipset, graphics driver install issues
- Old But Gold, Dumping LSASS With Windows Error Reporting On Modern Windows 11
- Windows Secure Boot certificates are expiring, here is everything you need know
- ChatGPT may soon require ID verification from adults, CEO says
- Office 2016 and 2019 face October 14 execution date
- Microsoft: Exchange 2016 and 2019 reach end of support in 30 days
- Microsoft: WMIC will be removed after Windows 11 25H2 upgrade
- Microsoft shares new way to enroll older Windows 11 PCs so they don’t break
- Microsoft is simplifying its Copilot offerings with reduced prices
- Microsoft says Windows September updates break SMBv1 shares
- Microsoft to force install the Microsoft 365 Copilot app in October
- Microsoft fixes Windows 11 audio issues confirmed in December
- Microsoft is giving Notepad free AI features
- Windows 11 23H2 Home and Pro reach end of support in 60 days
- Windows 11 KB5065426 won’t install, issues in Windows 11 September 2025 Update affect some users
- Microsoft fixes Windows Update error 0x80070002 and other issues in new Windows 11 builds
- Windows 11 to show full-screen alerts for Microsoft 365 subscription expiry
