10/14

Oracles silently fixes zero-day exploit leaked by ShinyHunters

https://www.bleepingcomputer.com/news/security/oracles-silently-fixes-zero-day-exploit-leaked-by-shinyhunters/
Oracles silently fixes zero-day exploit leaked by ShinyHunters

Researchers Expose TA585's MonsterV2 Malware Capabilities and Attack Chain

https://thehackernews.com/2025/10/researchers-expose-ta585s-monsterv2.html
Researchers Expose TA585's MonsterV2 Malware Capabilities and Attack Chain

Secure Boot bypass risk threatens nearly 200,000 Linux Framework laptops

https://www.bleepingcomputer.com/news/security/secure-boot-bypass-risk-on-nearly-200-000-linux-framework-sytems/
Secure Boot bypass risk threatens nearly 200,000 Linux Framework laptops

Security firms dispute credit for overlapping CVE reports

https://www.bleepingcomputer.com/news/security/security-firms-debate-cve-credit-in-overlapping-vulnerability-reports/
Security firms dispute credit for overlapping CVE reports

Chinese hackers abuse geo-mapping tool for year-long persistence

https://www.bleepingcomputer.com/news/security/chinese-hackers-abuse-geo-mapping-tool-for-year-long-persistence/
Chinese hackers abuse geo-mapping tool for year-long persistence

New PoC Exploit Released for Sudo Chroot Privilege Escalation Vulnerability

https://cybersecuritynews.com/poc-exploit-sudo-chroot/
New PoC Exploit Released for Sudo Chroot Privilege Escalation Vulnerability

RMPocalypse: Single 8-Byte Write Shatters AMD's SEV-SNP Confidential Computing

https://thehackernews.com/2025/10/rmpocalypse-single-8-byte-write.html
RMPocalypse: Single 8-Byte Write Shatters AMD's SEV-SNP Confidential Computing

npm, PyPI, and RubyGems Packages Found Sending Developer Data to Discord Channels

https://thehackernews.com/2025/10/npm-pypi-and-rubygems-packages-found.html
npm, PyPI, and RubyGems Packages Found Sending Developer Data to Discord Channels

SonicWall VPN accounts breached using stolen creds in widespread attacks

https://www.bleepingcomputer.com/news/security/sonicwall-vpn-accounts-breached-using-stolen-creds-in-widespread-attacks/
SonicWall VPN accounts breached using stolen creds in widespread attacks

Blinding EDRs: A deep dive into WFP manipulation – SCRT Team Blog

https://blog.scrt.ch/2025/08/25/blinding-edrs-a-deep-dive-into-wfp-manipulation/
Blinding EDRs: A deep dive into WFP manipulation – SCRT Team Blog

When the monster bytes: tracking TA585 and its arsenal | Proofpoint US

https://www.proofpoint.com/us/blog/threat-insight/when-monster-bytes-tracking-ta585-and-its-arsenal
When the monster bytes: tracking TA585 and its arsenal | Proofpoint US

Finding Critical Bugs in Adobe Experience Manager › Searchlight Cyber

https://slcyber.io/assetnote-security-research-center/finding-critical-bugs-in-adobe-experience-manager
Finding Critical Bugs in Adobe Experience Manager › Searchlight Cyber

ChkTag: x86 Memory Safety - Intel Community

https://community.intel.com/t5/Blogs/Tech-Innovation/open-intel/ChkTag-x86-Memory-Safety/post/1721490
ChkTag: x86 Memory Safety - Intel Community

Final Windows 10 Patch Tuesday update rolls out as support ends

https://www.bleepingcomputer.com/news/microsoft/final-windows-10-patch-tuesday-update-rolls-out-as-support-ends/
Final Windows 10 Patch Tuesday update rolls out as support ends

US seizes $15 billion in crypto from 'pig butchering' kingpin

https://www.bleepingcomputer.com/news/security/us-seizes-15-billion-in-crypto-from-pig-butchering-kingpin/
US seizes $15 billion in crypto from 'pig butchering' kingpin

Chinese Hackers Exploit ArcGIS Server as Backdoor for Over a Year

https://thehackernews.com/2025/10/chinese-hackers-exploit-arcgis-server.html
Chinese Hackers Exploit ArcGIS Server as Backdoor for Over a Year

Exploring GrapheneOS secure allocator: Hardened Malloc

https://www.synacktiv.com/en/publications/exploring-grapheneos-secure-allocator-hardened-malloc
Exploring GrapheneOS secure allocator: Hardened Malloc

PolarEdge Backdoor on QNAP (CVE-2023-20118) – Full Analysis

https://blog.sekoia.io/polaredge-backdoor-qnap-cve-2023-20118-analysis/
PolarEdge Backdoor on QNAP (CVE-2023-20118) – Full Analysis

Oracle releases emergency patch for new E-Business Suite flaw

https://www.bleepingcomputer.com/news/security/oracle-releases-emergency-patch-for-new-e-business-suite-flaw/
Oracle releases emergency patch for new E-Business Suite flaw

RMPocalypse: New Attack Breaks AMD Confidential Computing - SecurityWeek

https://www.securityweek.com/rmpocalypse-new-attack-breaks-amd-confidential-computing/
RMPocalypse: New Attack Breaks AMD Confidential Computing - SecurityWeek

Microsoft October 2025 Patch Tuesday fixes 6 zero-days, 172 flaws

https://www.bleepingcomputer.com/news/microsoft/microsoft-october-2025-patch-tuesday-fixes-6-zero-days-172-flaws/
Microsoft October 2025 Patch Tuesday fixes 6 zero-days, 172 flaws

Massive multi-country botnet targets RDP services in the US

https://www.bleepingcomputer.com/news/security/massive-multi-country-botnet-targets-rdp-services-in-the-us/
Massive multi-country botnet targets RDP services in the US

Microsoft warns that Windows 10 reaches end of support today

https://www.bleepingcomputer.com/news/microsoft/microsoft-warns-that-windows-10-reaches-end-of-support-today/
Microsoft warns that Windows 10 reaches end of support today

MalwareBazaar | SHA256 541f119804e12e2edd80a9e9307e6dbf562e4e7da01a612bc08dd56524c6913c (RemcosRAT)

https://bazaar.abuse.ch/sample/541f119804e12e2edd80a9e9307e6dbf562e4e7da01a612bc08dd56524c6913c/
MalwareBazaar | SHA256 541f119804e12e2edd80a9e9307e6dbf562e4e7da01a612bc08dd56524c6913c (RemcosRAT)