Digital figures attacking laptop with fire and malware

October 18, 2025 - Daily Cybersecurity News

Massive Email Bombing Campaign Exploits Zendesk's Lax Authentication

High

What happened

Cybercriminals exploited a lack of authentication in Zendesk's customer service platform to flood targeted email inboxes with thousands of malicious messages from various corporate customers.

Who is affected

Organizations using Zendesk with configurations allowing anonymous support requests, including companies like CapCom, CompTIA, Discord, GMAC, NordVPN, The Washington Post, and Tinder.

Why it matters

This abuse can tarnish the reputation of affected organizations, disrupt operations, and potentially expose sensitive information through overwhelming email floods.

How it could have been prevented

Implementing authentication for support request submissions and disabling anonymous ticket creation would mitigate such abuse.

Relevant professional terms

Email Bombing
A type of attack where an overwhelming number of emails are sent to a target to disrupt their email service.
Anonymous Ticket Creation
Allowing support tickets to be submitted without verifying the identity of the requester.

Recommended reading: Cyberheist Smokescreen: Email, Phone, SMS Floods

ConnectWise Automate Vulnerability CVE-2025-11492 Allows AiTM Attacks

Critical

What happened

ConnectWise released a security update for its Automate product to address a critical vulnerability (CVE-2025-11492) that allowed agents to communicate over unencrypted HTTP, exposing sensitive data to potential interception and modification through adversary-in-the-middle (AiTM) attacks.

Who is affected

Organizations using ConnectWise Automate, particularly those with agents configured to use HTTP instead of HTTPS, are at risk.

Why it matters

The vulnerability could allow attackers to intercept or alter communications between Automate agents and servers, potentially leading to unauthorized access, data breaches, or deployment of malicious updates across managed systems.

How it could have been prevented

Ensuring all agent communications are configured to use encrypted HTTPS connections and regularly updating software to patch known vulnerabilities.

Relevant professional terms

Adversary-in-the-Middle (AiTM) Attack
A type of cyberattack where an attacker secretly intercepts and possibly alters the communication between two parties who believe they are directly communicating with each other.
Remote Monitoring and Management (RMM)
A type of software used by IT service providers to remotely monitor and manage client endpoints, networks, and computers.

Recommended reading: ConnectWise Automate 2023.1 Security Bulletin

Envoy Air's Oracle E-Business Suite Compromised by Clop Ransomware Gang

Medium

What happened

Envoy Air, a subsidiary of American Airlines, confirmed that its Oracle E-Business Suite application was compromised by the Clop ransomware gang, leading to the exposure of certain business information and commercial contact details.

Who is affected

Envoy Air, a regional airline operating under the American Eagle brand, and its parent company, American Airlines, are involved. No sensitive or customer data was reported as affected.

Why it matters

This incident highlights the persistent threat posed by ransomware groups targeting critical business applications, emphasizing the need for robust cybersecurity measures to protect sensitive corporate data.

How it could have been prevented

Regularly updating and patching enterprise software to address known vulnerabilities, implementing comprehensive monitoring systems to detect unauthorized access, and conducting regular security audits to identify and mitigate potential risks.

Relevant professional terms

Ransomware
Malicious software designed to block access to a computer system or data until a sum of money is paid.
Oracle E-Business Suite
A comprehensive suite of integrated business applications for automating customer relationship management, enterprise resource planning, and supply chain management processes.

Recommended reading: BleepingComputer

Critical HTTP Request Smuggling Vulnerability in ASP.NET Core (CVE-2025-55315)

Critical

What happened

Microsoft has patched a critical HTTP request smuggling vulnerability (CVE-2025-55315) in the Kestrel web server component of ASP.NET Core, which could allow authenticated attackers to hijack user credentials or bypass security controls.

Who is affected

Developers and organizations utilizing ASP.NET Core applications with the Kestrel web server are impacted by this vulnerability.

Why it matters

Exploitation of this flaw could lead to unauthorized access to sensitive information, modification of server files, or server crashes, posing significant security risks to affected applications.

How it could have been prevented

Regularly updating software components and promptly applying security patches can mitigate such vulnerabilities. Implementing thorough input validation and monitoring for unusual HTTP request patterns are also effective preventive measures.

Relevant professional terms

HTTP Request Smuggling
A technique where an attacker sends specially crafted HTTP requests to bypass security controls or manipulate server behavior.
Kestrel Web Server
A cross-platform web server for ASP.NET Core applications, designed for high performance and scalability.

Recommended reading: Microsoft Security Response Center Advisory on CVE-2025-55315

Over 266,000 F5 BIG-IP Instances Exposed to Remote Attacks

High

What happened

A security breach at F5 led to the theft of BIG-IP source code and undisclosed vulnerabilities. Subsequently, over 266,000 F5 BIG-IP instances were found exposed online, increasing the risk of remote attacks.

Who is affected

Organizations utilizing F5 BIG-IP devices are at risk, especially those with internet-exposed instances.

Why it matters

The exposure of a significant number of BIG-IP instances heightens the potential for remote exploitation, which could lead to unauthorized access, data breaches, and service disruptions.

How it could have been prevented

Regularly updating BIG-IP devices with the latest security patches and limiting internet exposure of management interfaces can mitigate such risks.

Relevant professional terms

Source Code
The original code written by developers that defines how a software program operates.
Undisclosed Vulnerabilities
Security flaws in software that are known to certain parties but have not been publicly revealed or patched.

Recommended reading: F5 releases BIG-IP patches for stolen security vulnerabilities

Microsoft Disrupts Ransomware Campaign Abusing Azure Certificates

High

What happened

Microsoft revoked over 200 digital certificates that were exploited by threat actors to sign malicious Microsoft Teams binaries, facilitating the deployment of Rhysida ransomware.

Who is affected

Organizations targeted by the cybercriminal group Vanilla Tempest, also known as Vice Society, which has a history of attacking healthcare institutions and public schools.

Why it matters

The misuse of legitimate digital certificates to sign malware undermines trust in software authenticity, increasing the risk of successful ransomware attacks and data breaches.

How it could have been prevented

Implementing strict certificate management policies, regularly auditing digital certificates, and monitoring for unauthorized use can help prevent such abuses.

Relevant professional terms

Digital Certificate
An electronic credential used to verify the identity of an entity and to secure communication through encryption.
Code-Signing
The process of digitally signing software to confirm its authenticity and integrity.

Recommended reading: Microsoft Disrupts Ransomware Campaign Abusing Azure Certificates

Nation-State Actors Leverage AI to Intensify Cyberattacks on the US

High

What happened

Nation-state actors from Russia, China, Iran, and North Korea have significantly increased their use of artificial intelligence (AI) to conduct cyberattacks and disseminate disinformation targeting the United States. In July 2025, over 200 instances of AI-generated fake content were identified, more than doubling the figures from July 2024 and exceeding ten times the number observed in 2023.

Who is affected

U.S. government agencies, businesses, and critical infrastructure sectors, including healthcare and transportation networks, are primary targets of these AI-enhanced cyber operations.

Why it matters

The integration of AI into cyberattacks allows adversaries to automate and enhance their operations, leading to more sophisticated phishing campaigns, realistic deepfake content, and efficient system intrusions. This escalation poses a heightened risk to national security, economic stability, and public trust.

How it could have been prevented

Implementing robust cybersecurity measures, including AI-driven threat detection systems, regular security audits, and comprehensive employee training on recognizing and responding to sophisticated phishing and disinformation campaigns, can mitigate the risks associated with AI-enhanced cyberattacks.

Relevant professional terms

Deepfake
A synthetic media in which a person's likeness is replaced with someone else's, often used to create deceptive videos or images.
Phishing
A cyberattack method involving fraudulent communications that appear to come from a reputable source, typically to steal sensitive data.

Recommended reading: Cyber Insights 2025: Artificial Intelligence