Large group of hackers at laptops with central shield displaying hacker icon surrounded by locks and threats

Daily Dose of Cybersecurity News - August 19, 2025

ERMAC v3 Android Banking Trojan Source Code Leaked

High

What happened

The source code for ERMAC v3, an Android banking trojan, was leaked online, revealing the malware's infrastructure and functionalities.

Who is affected

Android users of over 700 banking, shopping, and cryptocurrency apps targeted by ERMAC v3.

Why it matters

The leak provides cybercriminals with the tools to create and distribute customized versions of the trojan, potentially increasing attacks on Android users.

How it could have been prevented

Regular security audits and restricting access to sensitive directories could have prevented the unintentional exposure of the source code.

Relevant professional terms

Malware-as-a-Service (MaaS)
A business model where malware developers sell or lease their malicious software to others.
Trojan
A type of malware that disguises itself as legitimate software to deceive users into installing it.

Recommended reading: New ERMAC 2.0 Android malware steals accounts, wallets from 467 apps

Critical Vulnerabilities in N-able N-central (CVE-2025-8875 & CVE-2025-8876) Exploited in the Wild

Critical

What happened

Over 800 N-able N-central servers remain unpatched against two critical vulnerabilities, CVE-2025-8875 and CVE-2025-8876, which are currently being actively exploited by attackers.

Who is affected

Organizations utilizing N-able N-central for remote monitoring and management, particularly those with on-premises deployments, are at risk.

Why it matters

Exploitation of these vulnerabilities can lead to unauthorized command execution, potentially compromising entire networks managed by the affected N-central servers.

How it could have been prevented

Timely application of the security patch provided in N-central version 2025.3.1 and ensuring multi-factor authentication (MFA) is enabled for all administrative accounts.

Relevant professional terms

Insecure Deserialization
A vulnerability that occurs when untrusted data is used to abuse the logic of an application, leading to remote code execution.
Command Injection
A security flaw that allows an attacker to execute arbitrary commands on a host operating system via a vulnerable application.

Recommended reading: CISA warns of N-able N-central flaws exploited in zero-day attacks

Workday Data Breach Linked to Salesforce Social Engineering Attacks

Medium

What happened

Workday experienced a data breach when attackers accessed a third-party customer relationship management (CRM) platform through social engineering tactics. The attackers obtained business contact information, including names, email addresses, and phone numbers.

Who is affected

Workday's business contacts, including customer data, were exposed. The breach is part of a broader campaign targeting multiple organizations' Salesforce instances.

Why it matters

The exposure of business contact information can facilitate further social engineering attacks, potentially leading to unauthorized access to sensitive systems and data. This incident underscores the effectiveness of social engineering tactics in compromising organizational security.

How it could have been prevented

Implementing multi-factor authentication (MFA) for CRM access and conducting regular employee training on recognizing and responding to social engineering attempts could have mitigated the risk.

Relevant professional terms

Social Engineering
Manipulative tactics used by attackers to deceive individuals into divulging confidential information or granting unauthorized access.
Customer Relationship Management (CRM)
Software systems that manage a company's interactions with current and potential customers, often storing sensitive business data.

Recommended reading: SecurityWeek

High

What happened

Cybercriminals are distributing the Noodlophile infostealer malware through spear-phishing emails that falsely allege copyright violations on corporate Facebook pages. These emails contain malicious links leading to malware installation.

Who is affected

Organizations with active corporate Facebook pages, particularly those in the US, Europe, Baltic countries, and the Asia-Pacific region, are targeted by this campaign.

Why it matters

The campaign demonstrates advanced social engineering tactics, exploiting organizations' reliance on social media for business operations. Successful attacks can lead to significant data breaches, including the theft of credentials, financial information, and sensitive corporate data.

How it could have been prevented

Implementing comprehensive employee training on recognizing phishing attempts, especially those involving social media platforms, can mitigate risk. Additionally, enforcing strict email verification processes and utilizing advanced email filtering solutions can help prevent such attacks.

Relevant professional terms

Infostealer
A type of malware designed to gather sensitive information from a victim's system, such as login credentials, financial data, and personal information.
Spear-phishing
A targeted phishing attack aimed at a specific individual or organization, often involving personalized information to increase credibility and effectiveness.

Recommended reading: Morphisec Blog on Noodlophile Stealer Campaign

Critical HTTP/2 Vulnerability 'MadeYouReset' Enables Massive DDoS Attacks (CVE-2025-8671)

High

What happened

Researchers from Tel Aviv University have discovered a critical vulnerability in the HTTP/2 protocol, termed "MadeYouReset" (CVE-2025-8671), which allows attackers to bypass previous DDoS mitigations and potentially launch large-scale attacks.

Who is affected

Web servers and applications utilizing HTTP/2 implementations are at risk, potentially impacting up to one-third of all websites globally.

Why it matters

This vulnerability undermines existing DDoS defenses, enabling attackers to exploit HTTP/2's concurrent stream processing to overwhelm servers, leading to significant service disruptions.

How it could have been prevented

Implementing stricter validation of control frames and ensuring that backend processes terminate immediately upon stream cancellation could mitigate this vulnerability.

Relevant professional terms

HTTP/2
The second major version of the HTTP network protocol, designed to improve web performance by allowing multiple concurrent streams over a single connection.
DDoS (Distributed Denial-of-Service)
A cyberattack where multiple systems flood the bandwidth or resources of a targeted system, usually one or more web servers.

Recommended reading: Internet-Wide Zero-Day Bug Fuels Largest-Ever DDoS Event