
Daily Dose of Cybersecurity News - September 20, 2025
FBI Warns of Fake Crime Reporting Portals Exploiting Users
HighWhat happened
Cybercriminals are creating counterfeit versions of the FBI's Internet Crime Complaint Center (IC3) website to deceive users into providing personal information, which can be exploited for financial scams or identity theft.
Who is affected
Individuals attempting to report crimes online through the IC3 platform are at risk of being misled by these fraudulent sites.
Why it matters
These spoofed websites can lead to unauthorized access to sensitive personal data, resulting in financial loss and compromised personal security.
How it could have been prevented
Users should verify the authenticity of websites by directly entering the official URL (www.ic3.gov) into their browser and avoid clicking on links from unverified sources.
Relevant professional terms
- Phishing
- A cyberattack method where attackers impersonate legitimate entities to deceive individuals into providing sensitive information.
- Domain Spoofing
- The act of creating a website with a domain name similar to a legitimate one to mislead users.
Recommended reading: FBI Public Service Announcement on Spoofed Websites
CISA Analyzes Malware Exploiting Ivanti EPMM Vulnerabilities (CVE-2025-4427 & CVE-2025-4428)
CriticalWhat happened
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) released an analysis detailing malware used in attacks that exploit two vulnerabilities in Ivanti Endpoint Manager Mobile (EPMM): an authentication bypass (CVE-2025-4427) and a code injection flaw (CVE-2025-4428).
Who is affected
Organizations using Ivanti EPMM versions 11.12.0.4, 12.3.0.1, 12.4.0.1, and 12.5.0.0, as well as earlier releases, are impacted.
Why it matters
Exploitation of these vulnerabilities allows attackers to gain unauthorized access, execute arbitrary code, exfiltrate data, and establish persistence on affected systems, posing significant security risks.
How it could have been prevented
Timely application of security patches released by Ivanti on May 13, 2025, and treating mobile device management systems as high-value assets with enhanced security measures.
Relevant professional terms
- Authentication Bypass
- A security flaw that allows unauthorized users to gain access to a system without proper credentials.
- Code Injection
- A vulnerability that enables attackers to insert and execute malicious code within a system.
Recommended reading: CISA Releases Analysis of Malware Used in Ivanti EPMM Exploitation
Critical Vulnerability CVE-2025-10035 in Fortra's GoAnywhere MFT License Servlet
CriticalWhat happened
Fortra identified and patched a critical vulnerability (CVE-2025-10035) in the License Servlet component of its GoAnywhere Managed File Transfer (MFT) software. This flaw allows remote attackers to execute arbitrary commands via deserialization of untrusted data.
Who is affected
Organizations using GoAnywhere MFT versions prior to 7.8.4 or Sustain Release 7.6.3, especially those with the Admin Console accessible over the internet.
Why it matters
Exploitation of this vulnerability could lead to full system compromise, data exfiltration, and further lateral movement within the network. Given the software's role in secure file transfers, the risk to sensitive data is significant.
How it could have been prevented
Regular security audits to identify and patch vulnerabilities promptly, restricting internet exposure of administrative interfaces, and implementing strict access controls.
Relevant professional terms
- Deserialization of Untrusted Data
- A security flaw where an application deserializes data from untrusted sources without proper validation, potentially leading to code execution.
- Command Injection
- An attack technique where an attacker executes arbitrary commands on a host operating system via a vulnerable application.
Recommended reading: Fortra's Security Advisory on GoAnywhere MFT Vulnerability
Ransomware Attacks Continue to Evade Defenses
HighWhat happened
Despite significant investments in cybersecurity, organizations are experiencing a decline in their ability to prevent ransomware attacks, with overall prevention effectiveness dropping from 69% in 2024 to 62% in 2025. Notably, data exfiltration prevention has plummeted to a mere 3%, leaving organizations vulnerable to data theft and extortion.
Who is affected
Organizations across various sectors are impacted, as both known and emerging ransomware strains continue to bypass existing defenses.
Why it matters
The decline in prevention effectiveness underscores the evolving sophistication of ransomware tactics, including double extortion and data theft without encryption. This trend highlights the critical need for organizations to continuously validate and enhance their cybersecurity measures to protect sensitive data and maintain operational integrity.
How it could have been prevented
Implementing continuous Breach and Attack Simulation (BAS) to regularly test and validate defenses against both known and emerging ransomware strains. Additionally, enhancing data exfiltration detection mechanisms and adopting a proactive approach to cybersecurity can mitigate risks.
Relevant professional terms
- Double Extortion
- A ransomware attack strategy where attackers encrypt the victim's data and also exfiltrate sensitive information, threatening to release it publicly unless a ransom is paid.
- Breach and Attack Simulation (BAS)
- A cybersecurity testing method that simulates real-world attack scenarios to assess the effectiveness of an organization's security measures.
Recommended reading: Ransomware isn’t going away – the problem is only getting worse
Critical Command Injection Vulnerability in Fortra GoAnywhere MFT (CVE-2025-10035)
CriticalWhat happened
A critical vulnerability (CVE-2025-10035) was discovered in Fortra's GoAnywhere Managed File Transfer (MFT) software, specifically within its License Servlet. This flaw allows threat actors to execute arbitrary commands through deserialization of malicious objects.
Who is affected
Organizations utilizing GoAnywhere MFT versions prior to 7.8.4 or 7.6.3 are vulnerable, especially if their systems are exposed to the public internet.
Why it matters
Exploitation of this vulnerability could lead to unauthorized command execution, potentially compromising sensitive data and system integrity. Given the software's role in secure file transfers, the impact could be significant.
How it could have been prevented
Regularly updating software to the latest versions and ensuring administrative interfaces are not exposed to the public internet can mitigate such vulnerabilities.
Relevant professional terms
- Deserialization
- The process of converting data from a stored format back into its original structure. Insecure deserialization can allow attackers to execute arbitrary code.
- Command Injection
- A security vulnerability where an attacker can execute arbitrary commands on a host operating system via a vulnerable application.
Recommended reading: arcticwolf.com
ShadowLeak Exploit in ChatGPT Enables Undetectable Email Data Theft
HighWhat happened
Researchers identified a vulnerability, termed "ShadowLeak," in ChatGPT integrations with email services, allowing attackers to exfiltrate email data without detection.
Who is affected
Users who have integrated ChatGPT with their email services, such as Gmail, are susceptible to this exploit.
Why it matters
The exploit enables attackers to steal sensitive email content without leaving any trace on the victim's network, posing significant security and privacy risks.
How it could have been prevented
Implementing strict input validation and sanitization within AI integrations and monitoring AI agent activities for unauthorized actions.
Relevant professional terms
- Prompt Injection
- A technique where malicious inputs are crafted to manipulate an AI model's behavior.
- Data Exfiltration
- Unauthorized transfer of data from a computer or network.
Recommended reading: Beyond ChatGPT: Organizations Must Protect Themselves Against the Power of AI
Synthetic Identity Fraud Escalates in Financial and Lending Sectors
HighWhat happened
Financial institutions, particularly those in the automotive lending sector, are experiencing a surge in fraud involving synthetic identities. Cybercriminals are leveraging data from various breaches to create convincing fake profiles, leading to significant financial losses.
Who is affected
U.S. financial lenders, especially those offering auto loans, are the primary targets of this fraudulent activity.
Why it matters
The financial risk associated with synthetic identity fraud has escalated to $3.3 billion in 2024, up from $1.9 billion in 2020. This trend underscores the increasing sophistication of fraudsters and the pressing need for enhanced security measures in the financial sector.
How it could have been prevented
Implementing advanced identity verification processes and utilizing comprehensive data analytics can help detect and prevent synthetic identity fraud. Regularly updating security protocols and employee training are also crucial.
Relevant professional terms
- Synthetic Identity Fraud
- The creation of a fictitious identity by combining real and fabricated information to open fraudulent accounts.
- Data Breach
- An incident where unauthorized individuals gain access to confidential data, often leading to information being used for fraudulent purposes.
Recommended reading: Cyberthreats, Regulations Mount for Financial Industry