Hooded hacker at laptop with glowing hands surrounded by shields, locks, code, and threat diagrams

Daily Dose of Cybersecurity News - September 20, 2025

FBI Warns of Fake Crime Reporting Portals Exploiting Users

High

What happened

Cybercriminals are creating counterfeit versions of the FBI's Internet Crime Complaint Center (IC3) website to deceive users into providing personal information, which can be exploited for financial scams or identity theft.

Who is affected

Individuals attempting to report crimes online through the IC3 platform are at risk of being misled by these fraudulent sites.

Why it matters

These spoofed websites can lead to unauthorized access to sensitive personal data, resulting in financial loss and compromised personal security.

How it could have been prevented

Users should verify the authenticity of websites by directly entering the official URL (www.ic3.gov) into their browser and avoid clicking on links from unverified sources.

Relevant professional terms

Phishing
A cyberattack method where attackers impersonate legitimate entities to deceive individuals into providing sensitive information.
Domain Spoofing
The act of creating a website with a domain name similar to a legitimate one to mislead users.

Recommended reading: FBI Public Service Announcement on Spoofed Websites

CISA Analyzes Malware Exploiting Ivanti EPMM Vulnerabilities (CVE-2025-4427 & CVE-2025-4428)

Critical

What happened

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) released an analysis detailing malware used in attacks that exploit two vulnerabilities in Ivanti Endpoint Manager Mobile (EPMM): an authentication bypass (CVE-2025-4427) and a code injection flaw (CVE-2025-4428).

Who is affected

Organizations using Ivanti EPMM versions 11.12.0.4, 12.3.0.1, 12.4.0.1, and 12.5.0.0, as well as earlier releases, are impacted.

Why it matters

Exploitation of these vulnerabilities allows attackers to gain unauthorized access, execute arbitrary code, exfiltrate data, and establish persistence on affected systems, posing significant security risks.

How it could have been prevented

Timely application of security patches released by Ivanti on May 13, 2025, and treating mobile device management systems as high-value assets with enhanced security measures.

Relevant professional terms

Authentication Bypass
A security flaw that allows unauthorized users to gain access to a system without proper credentials.
Code Injection
A vulnerability that enables attackers to insert and execute malicious code within a system.

Recommended reading: CISA Releases Analysis of Malware Used in Ivanti EPMM Exploitation

Critical Vulnerability CVE-2025-10035 in Fortra's GoAnywhere MFT License Servlet

Critical

What happened

Fortra identified and patched a critical vulnerability (CVE-2025-10035) in the License Servlet component of its GoAnywhere Managed File Transfer (MFT) software. This flaw allows remote attackers to execute arbitrary commands via deserialization of untrusted data.

Who is affected

Organizations using GoAnywhere MFT versions prior to 7.8.4 or Sustain Release 7.6.3, especially those with the Admin Console accessible over the internet.

Why it matters

Exploitation of this vulnerability could lead to full system compromise, data exfiltration, and further lateral movement within the network. Given the software's role in secure file transfers, the risk to sensitive data is significant.

How it could have been prevented

Regular security audits to identify and patch vulnerabilities promptly, restricting internet exposure of administrative interfaces, and implementing strict access controls.

Relevant professional terms

Deserialization of Untrusted Data
A security flaw where an application deserializes data from untrusted sources without proper validation, potentially leading to code execution.
Command Injection
An attack technique where an attacker executes arbitrary commands on a host operating system via a vulnerable application.

Recommended reading: Fortra's Security Advisory on GoAnywhere MFT Vulnerability

Ransomware Attacks Continue to Evade Defenses

High

What happened

Despite significant investments in cybersecurity, organizations are experiencing a decline in their ability to prevent ransomware attacks, with overall prevention effectiveness dropping from 69% in 2024 to 62% in 2025. Notably, data exfiltration prevention has plummeted to a mere 3%, leaving organizations vulnerable to data theft and extortion.

Who is affected

Organizations across various sectors are impacted, as both known and emerging ransomware strains continue to bypass existing defenses.

Why it matters

The decline in prevention effectiveness underscores the evolving sophistication of ransomware tactics, including double extortion and data theft without encryption. This trend highlights the critical need for organizations to continuously validate and enhance their cybersecurity measures to protect sensitive data and maintain operational integrity.

How it could have been prevented

Implementing continuous Breach and Attack Simulation (BAS) to regularly test and validate defenses against both known and emerging ransomware strains. Additionally, enhancing data exfiltration detection mechanisms and adopting a proactive approach to cybersecurity can mitigate risks.

Relevant professional terms

Double Extortion
A ransomware attack strategy where attackers encrypt the victim's data and also exfiltrate sensitive information, threatening to release it publicly unless a ransom is paid.
Breach and Attack Simulation (BAS)
A cybersecurity testing method that simulates real-world attack scenarios to assess the effectiveness of an organization's security measures.

Recommended reading: Ransomware isn’t going away – the problem is only getting worse

Critical Command Injection Vulnerability in Fortra GoAnywhere MFT (CVE-2025-10035)

Critical

What happened

A critical vulnerability (CVE-2025-10035) was discovered in Fortra's GoAnywhere Managed File Transfer (MFT) software, specifically within its License Servlet. This flaw allows threat actors to execute arbitrary commands through deserialization of malicious objects.

Who is affected

Organizations utilizing GoAnywhere MFT versions prior to 7.8.4 or 7.6.3 are vulnerable, especially if their systems are exposed to the public internet.

Why it matters

Exploitation of this vulnerability could lead to unauthorized command execution, potentially compromising sensitive data and system integrity. Given the software's role in secure file transfers, the impact could be significant.

How it could have been prevented

Regularly updating software to the latest versions and ensuring administrative interfaces are not exposed to the public internet can mitigate such vulnerabilities.

Relevant professional terms

Deserialization
The process of converting data from a stored format back into its original structure. Insecure deserialization can allow attackers to execute arbitrary code.
Command Injection
A security vulnerability where an attacker can execute arbitrary commands on a host operating system via a vulnerable application.

Recommended reading: arcticwolf.com

ShadowLeak Exploit in ChatGPT Enables Undetectable Email Data Theft

High

What happened

Researchers identified a vulnerability, termed "ShadowLeak," in ChatGPT integrations with email services, allowing attackers to exfiltrate email data without detection.

Who is affected

Users who have integrated ChatGPT with their email services, such as Gmail, are susceptible to this exploit.

Why it matters

The exploit enables attackers to steal sensitive email content without leaving any trace on the victim's network, posing significant security and privacy risks.

How it could have been prevented

Implementing strict input validation and sanitization within AI integrations and monitoring AI agent activities for unauthorized actions.

Relevant professional terms

Prompt Injection
A technique where malicious inputs are crafted to manipulate an AI model's behavior.
Data Exfiltration
Unauthorized transfer of data from a computer or network.

Recommended reading: Beyond ChatGPT: Organizations Must Protect Themselves Against the Power of AI

Synthetic Identity Fraud Escalates in Financial and Lending Sectors

High

What happened

Financial institutions, particularly those in the automotive lending sector, are experiencing a surge in fraud involving synthetic identities. Cybercriminals are leveraging data from various breaches to create convincing fake profiles, leading to significant financial losses.

Who is affected

U.S. financial lenders, especially those offering auto loans, are the primary targets of this fraudulent activity.

Why it matters

The financial risk associated with synthetic identity fraud has escalated to $3.3 billion in 2024, up from $1.9 billion in 2020. This trend underscores the increasing sophistication of fraudsters and the pressing need for enhanced security measures in the financial sector.

How it could have been prevented

Implementing advanced identity verification processes and utilizing comprehensive data analytics can help detect and prevent synthetic identity fraud. Regularly updating security protocols and employee training are also crucial.

Relevant professional terms

Synthetic Identity Fraud
The creation of a fictitious identity by combining real and fabricated information to open fraudulent accounts.
Data Breach
An incident where unauthorized individuals gain access to confidential data, often leading to information being used for fraudulent purposes.

Recommended reading: Cyberthreats, Regulations Mount for Financial Industry