CVE-2025-62593 Exploitation and Other Cybersecurity News
CISA has mandated that all federal civilian agencies prioritize fixing a severe code injection vulnerability (CVE-2025-62593) in Ray-Project Ray. The flaw was added to the Known Exploited Vulnerabilities catalog after threat actors were observed actively abusing it in the wild.
BitSight saw the vulnerability being exploited by RondoDox, a Mirai-inspired botnet utilizing a staggering 174 distinct exploits to compromise vulnerable edge devices. This is a significant concern, as the exploitation of this vulnerability can lead to severe consequences, including data breaches and unauthorized access to sensitive information.
GitHub Denies AI Caused Bug
An autonomous AI tool developed by Wiz successfully identified and exploited a critical GitHub Actions workflow vulnerability in a public Snowflake repository, gaining unauthorized access to the company’s internal Jira tickets. However, GitHub has clarified that the vulnerable code snippet was entirely human-authored, and not introduced by GitHub Copilot.
T-Mobile Stops Hackers by Cutting Router Cable
To stop an active network intrusion by the Chinese state-sponsored hacking group Salt Typhoon in 2024, T-Mobile’s cybersecurity staff physically cut a compromised router’s network cable with scissors at a Bellevue data center. This drastic measure was taken to prevent further unauthorized access and protect sensitive information.
Other Cybersecurity News
Threema, an encrypted messaging provider, recently endured significant service disruptions following a series of sophisticated, sustained DDoS attacks targeting its infrastructure and colocation partner. The company quickly implemented specialized upstream traffic filtering to block the malicious requests and stabilize operations.
FortiGuard Labs is tracking Evooo1Bot, a highly modular Linux botnet that targets internet-facing devices by exploiting over a dozen known CVEs. This botnet is equipped with an SSH brute-forcer, credential sniffer, and a SOCKS5 relay module designed to convert infected hosts into persistent proxy nodes for attackers.
Data Breaches and Ransomware Attacks
Alation, a data catalog provider, confirmed an unauthorized intrusion into its internal network following a recent cyberattack. The hacking group TeamPCP has publicly claimed responsibility for the breach, alleging they successfully exfiltrated 73 gigabytes of sensitive data from the enterprise software company.
Sakura Internet, a Japanese hosting provider, discovered a severe data breach in its sales management system, potentially compromising contract and membership information for up to 1.36 million users. The massive exposure was identified while security teams were investigating a completely separate malware infection that impacted a small subset of the company’s rental server accounts.
A joint advisory from CISA, the FBI, and HHS cautions that Medusa ransomware affiliates are rapidly exploiting newly disclosed vulnerabilities in Fortra GoAnywhere and BeyondTrust to compromise critical infrastructure. The updated alert highlights the group’s evolving evasion toolkit, which now includes utilizing Minidump for credential theft and Interactsh dynamic URLs to verify successful network exploitation.
Zombie Card Attack and Post-Quantum Hardware Module
Academic researchers have demonstrated a new Zombie Card attack that bypasses cryptographic checks to complete contactless payments using physically expired Visa credit cards. By leveraging a smartphone relay setup to alter the expiration date fed to the POS terminal, attackers can exploit a communication gap between the local hardware and the issuing bank.
Crypto4A has become the first company globally to achieve FIPS 140-3 Level 3 validation for an HSM supporting all NIST-approved post-quantum cryptographic algorithms. The newly certified QASM module delivers a tamper-resistant foundation to protect sensitive cryptographic keys from the future threat of advanced quantum computing attacks.
Source: SecurityWeek