Cybersecurity Weekly Recap – PornHub Breach, Cisco 0-Day, Amazon Detains DPRK IT Worker, and more
Recent developments in cybersecurity have highlighted several significant threats and vulnerabilities affecting global networks and enterprises.
Recent developments in cybersecurity have highlighted several significant threats and vulnerabilities affecting global networks and enterprises.
Nation-State Espionage and Vulnerabilities
Attackers have compromised over 1.2 million accounts by stealing usernames, emails, and encrypted passwords, raising concerns about third-party risk management and the effectiveness of legacy encryption. Cisco identified a critical zero-day vulnerability (CVE-2025-20393) in its IOS XE software, exploited by APT actors. The flaw, known as "Storm-1252," allows unauthenticated remote code execution on enterprise routers, impacting networks worldwide.
Amazon identified a North Korean IT worker embedded within its cloud infrastructure, linked to the Lazarus Group. This incident underscores the need for stringent vetting in remote hiring processes.
CISA Advisory on Sierra Wireless Routers
CISA has added a vulnerability in legacy Sierra Wireless AirLink ALEOS routers (CVE-2018-4063) to its catalog of Known Exploited Vulnerabilities. The flaw permits remote code execution via unrestricted file uploads. CISA advises the decommissioning of these devices due to their end-of-life status.
Critical vulnerabilities (CVE-2025-59718 and CVE-2025-59719) in Fortinet's FortiGate firewalls allow unauthenticated access to network configurations. Fortinet has released patches, urging users to update systems and restrict management interface access.
Recent developments in cybersecurity have highlighted several significant threats and vulnerabilities affecting global networks and enterprises.
The "Frogblight" Trojan targets Turkish users by impersonating official apps to steal banking credentials. It utilizes extensive permissions and WebView injections to appear legitimate and evade detection.
The GhostPairing attack allows account takeover without password theft by exploiting WhatsApp's device linking flow. Users are tricked into approving unauthorized device access, compromising chat privacy.
Jaguar Land Rover Employee Data Breach
An August cyberattack exposed sensitive data of Jaguar Land Rover employees, impacting payroll and benefits information. The incident significantly affected manufacturing operations and financial performance.
Pornhub Premium Data Exposure via Mixpanel
ShinyHunters breached Mixpanel, affecting Pornhub Premium user analytics. The incident involved legacy session data but excluded sensitive information like passwords and payment details.
For daily cybersecurity updates, follow us on Google News , LinkedIn , and X . Contact us to feature your stories.
Based on reporting by Cyber Security News.
