Weekly Cybersecurity Briefing (8 – 15 September 2025)
Researchers disclosed multiple large supply-chain intrusions, notably GhostAction exfiltrating 3,325 GitHub secrets and an npm compromise that pushed malicious updates to high-download packages. The Salesloft GitHub breach afforded long-dwell access later leveraged in Salesforce-related intrusions. Several cloud and developer ecosystems reported downstream impacts.
Vendors released broad advisories and emergency fixes during the week, with Microsoft addressing 81 vulnerabilities including two zero-days. Adobe patched the critical SessionReaper flaw in Commerce/Magento, and SAP warned of active exploitation against S/4HANA CVE-2025-42957. Multiple Linux kernel and hypervisor issues also prompted vendor updates.
New malware and espionage activity appeared across platforms, including HybridPetya samples with a UEFI Secure Boot bypass, the modular macOS backdoor ChillyHell, and the fileless EggStreme framework used against a Philippine military contractor. Ransomware groups such as Akira continued to exploit known appliance vulnerabilities.
Phishing and tooling advances were observed, including the Salty2FA kit with multi-stage evasion and the Axios user-agent abuse enabling highly automated credential-theft campaigns. Researchers also reported Docker API abuse for cryptojacking over TOR and evolving remote-access trojans like MostereRAT.