Security news.
Critical enterprise infrastructure remains heavily targeted today, with vendors addressing CVSS 10.0 flaws and attackers actively exploiting edge appliances to lock out administrators. Federal authorities also intervened against major threat actors, issuing multimillion-dollar bounties and indictments for fraudulent ransomware recovery schemes. Meanwhile, supply chain risks and unpatched AI infrastructure vulnerabilities continue to demand rapid mitigation across engineering and IT teams.
SonicWall Patches Maximum-Severity CVSS 10.0 Flaw in SMA1000 Gateways
SonicWall issued hotfixes for four vulnerabilities across its SMA1000 remote access appliances, led by a pre-authentication server-side request forgery (SSRF) flaw that lets attackers reach internal network services.
Attackers Weaponize FortiBleed to Lock Administrators Out of Fortinet Devices
Active exploitation of Fortinet FortiGate appliances continues, with threat actors deleting existing admin credentials and provisioning rogue accounts to hijack firewall access.
Unpatched Critical RCE Flaw Disclosed in LMCache LLM Framework
A remote code execution vulnerability in LMCache's multiprocess mode allows unauthenticated attackers to execute arbitrary code on caching servers via crafted ZeroMQ messages, with no patch currently available.
Multiple ccTLD Registries Breached to Hijack Google Domains
Attackers compromised DNS registries for Ghana (.gh), Sierra Leone (.sl), and American Samoa (.as), modifying authoritative records to generate unauthorized TLS certificates for multiple Google web properties.
U.S. Offers $10 Million Bounty for Chinese HAFNIUM Hacker
The U.S. State Department announced a $10 million reward for information leading to Zhang Yu, charged for his alleged role in the widespread 2021 Microsoft Exchange Server compromises.
MonsterCloud CEO Indicted for $19M Fraudulent Ransomware Remediation
Federal prosecutors charged the head of MonsterCloud with wire fraud for claiming to use proprietary decryption tools while secretly paying ransoms and billing victims marked-up recovery costs.
Compromised 'tensorlake' npm Package Deploys Shai-Hulud Info-Stealer
Supply chain attackers published malicious version 0.5.144 of the Tensorlake SDK on npm to harvest credentials, exfiltrate sensitive secrets, and establish remote code execution.