Large team surrounding central laptop with swirling lock vortex surrounded by shields, warning icons, code

Daily Dose of Cybersecurity News - August 11, 2025

Google Calendar Invite Exploit Allows Remote Control of Gemini Assistant

High

What happened

Researchers identified a vulnerability where maliciously crafted Google Calendar invites could exploit Google's Gemini assistant, enabling unauthorized access to user data and control over smart devices.

Who is affected

Users of Google's Gemini assistant integrated into Android, Google web services, and Google Workspace apps.

Why it matters

This exploit could lead to unauthorized data exfiltration, location tracking, and manipulation of smart home devices, posing significant privacy and security risks.

How it could have been prevented

Implementing stricter input validation and prompt filtering within Gemini to detect and neutralize malicious prompt injections.

Relevant professional terms

Prompt Injection
A technique where malicious inputs are crafted to manipulate the behavior of language models.
Exfiltration
The unauthorized transfer of data from a computer or network.

Recommended reading: SafeBreach: Invitation Is All You Need

BadCam: New BadUSB Attack Turns Linux Webcams Into Persistent Threats

Critical

What happened

Researchers have discovered a vulnerability in certain Lenovo webcams that allows attackers to remotely reprogram the device firmware, transforming them into malicious USB devices capable of executing unauthorized commands on connected systems.

Who is affected

Users of Lenovo 510 FHD and Lenovo Performance FHD webcams, particularly those integrated into corporate environments, are at risk.

Why it matters

This vulnerability enables attackers to establish persistent access to systems, even surviving operating system reinstalls, posing significant security risks to organizations relying on these devices.

How it could have been prevented

Implementing firmware signature validation to prevent unauthorized modifications and regularly updating device firmware to patch known vulnerabilities.

Relevant professional terms

BadUSB
A type of attack where USB devices are reprogrammed to act maliciously, often by emulating keyboard inputs to execute unauthorized commands.
Firmware
Permanent software programmed into a hardware device that provides low-level control for the device's specific hardware.

Recommended reading: SC Media: BadUSB: What’s the real threat? Is there a solution?

WinRAR Zero-Day Vulnerability (CVE-2025-8088) Under Active Exploitation

Critical

What happened

A critical zero-day vulnerability (CVE-2025-8088) in WinRAR has been actively exploited, allowing attackers to execute arbitrary code by crafting malicious archive files.

Who is affected

Users of WinRAR versions up to and including 7.12 on Windows platforms are affected.

Why it matters

Exploitation of this vulnerability can lead to unauthorized code execution, potentially resulting in data breaches, system compromise, and further malware deployment.

How it could have been prevented

Regularly updating software to the latest versions and exercising caution when opening files from untrusted sources can mitigate such vulnerabilities.

Relevant professional terms

Zero-Day Vulnerability
A software flaw unknown to the vendor, exploited by attackers before a fix is available.
Path Traversal
A security vulnerability that allows attackers to access directories and files stored outside the web root folder.

Recommended reading: thehackernews.com

Win-DDoS Vulnerability Enables Attackers to Exploit Public Domain Controllers for DDoS Attacks

High

What happened

Researchers have identified a technique, dubbed Win-DDoS, that allows attackers to exploit vulnerabilities in Windows domain controllers (DCs) to create a botnet capable of launching distributed denial-of-service (DDoS) attacks. This method leverages flaws in the Windows Lightweight Directory Access Protocol (LDAP) client code to manipulate URL referrals, directing DCs to overwhelm target servers.

Who is affected

Organizations operating Windows domain controllers that are publicly accessible are at risk. Attackers can exploit these systems without requiring code execution or credentials.

Why it matters

The Win-DDoS technique enables attackers to harness the resources of numerous public DCs to conduct powerful DDoS attacks without the need for dedicated infrastructure or breaching devices. This poses a significant threat to the availability and reliability of targeted services.

How it could have been prevented

- Apply security patches addressing the identified vulnerabilities in Windows LDAP and RPC services. - Restrict public access to domain controllers by configuring firewalls and access controls to limit exposure. - Monitor network traffic for unusual patterns indicative of DDoS attacks and implement rate limiting where appropriate.

Relevant professional terms

Domain Controller (DC)
A server that responds to security authentication requests within a Windows Server domain.
Lightweight Directory Access Protocol (LDAP)
A protocol used to access and manage directory information services over a network.

Recommended reading: thehackernews.com

Pentesting Becomes Integral to CISO Strategies Amid AI and Supply Chain Concerns

High

What happened

A survey of 225 security leaders revealed that 68% are concerned about risks from third-party software, and 60% acknowledge that attackers are evolving too rapidly to maintain resilience. Additionally, 32% of penetration tests on AI applications uncovered high-risk vulnerabilities.

Who is affected

Security leaders, including CISOs and VPs, across various organizations are impacted, especially those integrating third-party software and AI technologies into their systems.

Why it matters

The findings highlight a growing tension between regulatory compliance and actual security effectiveness. The high incidence of vulnerabilities in AI applications and the complexity of software supply chains underscore the need for proactive security measures like penetration testing to identify and mitigate risks before exploitation.

How it could have been prevented

Implementing regular, comprehensive penetration testing throughout the software development lifecycle and supply chain management can proactively identify vulnerabilities. Establishing stringent security controls and faster remediation processes are also essential to maintain resilience against evolving threats.

Relevant professional terms

Penetration Testing (Pentesting)
A proactive cybersecurity exercise where ethical hackers simulate cyberattacks to identify and address security vulnerabilities within an organization's IT infrastructure.
Model Poisoning
A type of attack on machine learning models where adversaries manipulate training data to introduce vulnerabilities or biases, compromising the model's integrity and performance.

Recommended reading: The Leading CISO Strategy to Pentest as a Service

Escalating Cyber Threats in Healthcare Despite Increased Budgets

High

What happened

A recent report highlights a surge in cyberattacks targeting the U.S. healthcare sector, with significant breaches exposing millions of records and extortion demands reaching up to $4 million in early 2025. Despite substantial investments in security tools and insurance, the sector remains highly vulnerable.

Who is affected

Healthcare organizations across the United States, including hospitals, clinics, and associated third-party vendors, are impacted by these escalating cyber threats.

Why it matters

The increasing frequency and severity of cyberattacks in healthcare not only compromise sensitive patient data but also disrupt critical medical services, potentially endangering patient safety and trust in the healthcare system.

How it could have been prevented

Implementing comprehensive backup strategies for all critical data, treating insurance policies as sensitive documents, continuous monitoring of third-party vendors, and regular testing of incident response plans under realistic conditions could mitigate such risks.

Relevant professional terms

Ransomware
Malicious software designed to block access to a computer system or data until a sum of money is paid.
Incident Response Plan
A structured approach outlining how an organization responds to and manages the aftermath of a security breach or cyberattack.

Recommended reading: Help Net Security