Team of figures working around laptop displaying code with virus icons, shields, and DOS attack symbols

Daily Dose of Cybersecurity News - October 11, 2025

Aisuru Botnet Launches Record-Breaking DDoS Attacks Targeting U.S. ISPs

Critical

What happened

The Aisuru botnet executed a series of unprecedented Distributed Denial-of-Service (DDoS) attacks, peaking at nearly 30 terabits per second, primarily utilizing compromised Internet-of-Things (IoT) devices within U.S. Internet Service Providers (ISPs).

Who is affected

Major U.S. ISPs, including AT&T, Comcast, and Verizon, experienced significant network congestion due to the high volume of malicious traffic originating from infected devices on their networks.

Why it matters

The scale and intensity of these attacks not only disrupt targeted services but also degrade overall network performance, affecting a broad spectrum of users and highlighting vulnerabilities in IoT device security.

How it could have been prevented

Implementing robust security measures for IoT devices, such as changing default credentials, regularly updating firmware, and deploying network-level DDoS mitigation strategies, could reduce the risk of device compromise and subsequent attacks.

Relevant professional terms

Botnet
A network of private computers infected with malicious software and controlled as a group without the owners' knowledge.
Distributed Denial-of-Service (DDoS) Attack
A cyber-attack where multiple systems flood the bandwidth or resources of a targeted system, usually one or more web servers.

Recommended reading: KrebsOnSecurity Hit With Near-Record 6.3 Tbps DDoS

Zero-Day Vulnerability CVE-2025-11371 Exploited in Gladinet File Sharing Software

High

What happened

Threat actors are actively exploiting a zero-day vulnerability (CVE-2025-11371) in Gladinet's CentreStack and Triofox products, enabling unauthorized local file access and potential remote code execution.

Who is affected

Organizations utilizing any version of Gladinet's CentreStack and Triofox file-sharing solutions are at risk, with at least three companies already targeted.

Why it matters

Exploitation of this vulnerability can lead to unauthorized access to sensitive system files and potential remote code execution, posing significant security risks to affected organizations.

How it could have been prevented

Implementing strict access controls, regularly updating software, and promptly applying vendor-recommended mitigations can reduce the risk of exploitation.

Relevant professional terms

Local File Inclusion (LFI)
A vulnerability that allows attackers to include files on a server through the web browser, potentially leading to code execution.
Remote Code Execution (RCE)
The ability of an attacker to execute arbitrary code on a remote machine, often leading to full system compromise.

Recommended reading: Huntress Blog on Gladinet Vulnerability

Apple Increases Bug Bounty Rewards to $2 Million for Zero-Click RCE Vulnerabilities

High

What happened

Apple has expanded its bug bounty program, doubling the maximum reward to $2 million for zero-click remote code execution (RCE) vulnerabilities. The program now includes new research categories and a more transparent reward structure.

Who is affected

Security researchers and organizations involved in identifying and reporting vulnerabilities in Apple products.

Why it matters

By offering higher rewards, Apple aims to incentivize researchers to report critical vulnerabilities, thereby enhancing the security of its products and protecting users from potential exploits.

How it could have been prevented

Regular security audits, prompt patching of identified vulnerabilities, and fostering a strong collaboration with the security research community.

Relevant professional terms

Zero-click vulnerability
A security flaw that can be exploited without any user interaction, often through maliciously crafted data sent to the device.
Remote code execution (RCE)
The ability of an attacker to execute arbitrary code on a target system remotely, potentially leading to full system compromise.

Recommended reading: Apple now offers $2 million for zero-click RCE vulnerabilities

FBI Seizes BreachForums Domain Used for Salesforce Extortion

High

What happened

The FBI seized the BreachForums.hn domain, which was being used by the Scattered Lapsus$ Hunters group to extort companies affected by Salesforce data breaches. The group had threatened to leak stolen data unless ransoms were paid.

Who is affected

Organizations impacted by the Salesforce data breaches, including major companies like FedEx, Disney/Hulu, Home Depot, Marriott, Google, Cisco, Toyota, Gap, McDonald's, Walgreens, Instacart, Cartier, Adidas, Saks Fifth Avenue, Air France & KLM, TransUnion, HBO Max, UPS, Chanel, and IKEA.

Why it matters

The takedown disrupts a significant extortion campaign targeting numerous high-profile organizations, potentially preventing the public release of sensitive customer information and mitigating further financial and reputational damage.

How it could have been prevented

Implementing robust access controls and monitoring systems to detect unauthorized access, conducting regular security audits, and ensuring timely patching of vulnerabilities could have mitigated the risk of such data breaches.

Relevant professional terms

Data Leak Site
A website used by cybercriminals to publish or sell stolen data, often as part of extortion schemes.
Extortion Group
A collective of cybercriminals that threaten to release stolen data or disrupt services unless a ransom is paid.

Recommended reading: FBI Seizes BreachForums Hacking Forum Used to Leak Stolen Data

1Password Introduces Secure Agentic Autofill to Mitigate AI Browser Agent Credential Risks

Medium

What happened

1Password has launched "Secure Agentic Autofill," a feature designed to allow AI browser agents to authenticate without directly accessing user credentials, thereby reducing the risk of credential exposure.

Who is affected

Organizations utilizing AI browser agents for automated tasks are directly impacted, as these agents often require access to sensitive credentials.

Why it matters

As AI agents become more prevalent in enterprise environments, ensuring they operate without compromising credential security is crucial to prevent potential data breaches and unauthorized access.

How it could have been prevented

Implementing secure methods for AI agents to access necessary credentials without direct exposure, such as using tools like Secure Agentic Autofill, can mitigate these risks.

Relevant professional terms

Agentic Browser
A browser controlled by AI agents to perform automated tasks on behalf of users.
Credential Exposure
The unintended release or leakage of authentication information, such as usernames and passwords.

Recommended reading: 1Password Blog: Closing the Credential Risk Gap for AI Agents Using a Browser

RondoDox Botnet Exploits Multiple Edge Device Vulnerabilities

High

What happened

A new botnet named RondoDox has been identified exploiting 56 known vulnerabilities in various edge devices, including routers, digital video recorders (DVRs), and network video recorders (NVRs). The botnet employs a broad-spectrum attack strategy, attempting multiple exploits to compromise devices.

Who is affected

Owners and operators of edge devices such as routers, DVRs, NVRs, web servers, and CCTV systems are at risk, particularly those with unpatched vulnerabilities.

Why it matters

The widespread nature of RondoDox's attacks increases the risk of device compromise, leading to potential data breaches, unauthorized surveillance, and the use of these devices in further cyberattacks.

How it could have been prevented

Regularly updating device firmware to patch known vulnerabilities and implementing robust network monitoring to detect and respond to unusual activities.

Relevant professional terms

Botnet
A network of private computers infected with malicious software and controlled as a group without the owners' knowledge.
Command Injection
A security vulnerability that allows an attacker to execute arbitrary commands on a host operating system via a vulnerable application.

Recommended reading: Trend Micro Analysis of RondoDox Botnet

Escalating Ransomware Threats in the Manufacturing Sector

High

What happened

Ransomware attacks targeting the manufacturing industry have intensified, with the sector accounting for 22% of all reported attacks between April 2024 and March 2025. Cybercriminals exploit vulnerabilities in legacy systems and the integration of operational technology (OT) with information technology (IT) to disrupt operations and demand ransoms.

Who is affected

Manufacturing companies of all sizes, particularly those with outdated systems and insufficient cybersecurity measures, are at heightened risk.

Why it matters

The manufacturing sector's critical role in global supply chains makes it a prime target for ransomware attacks. Disruptions can lead to significant financial losses, operational downtime, and cascading effects throughout the supply chain.

How it could have been prevented

Implementing timely patch management protocols, segmenting networks to isolate critical systems, and conducting regular cybersecurity assessments can mitigate risks.

Relevant professional terms

Ransomware-as-a-Service (RaaS)
A business model where cybercriminals lease ransomware tools to affiliates, lowering the barrier to entry for conducting attacks.
Operational Technology (OT)
Hardware and software that detects or causes changes through direct monitoring and control of physical devices, processes, and events in industrial environments.

Recommended reading: Cybersecurity Dive: Ransomware attacks hit manufacturing hard in 2023