Team surrounding central hacker at laptop with shields, locks, warning icons, and vulnerability labels displayed

Daily Dose of Cybersecurity News - September 6, 2025

Microsoft Enforces MFA for Azure Portal Sign-ins Across All Tenants

High

What happened

Microsoft has enforced multifactor authentication (MFA) for all Azure Portal sign-ins across all tenants as of March 2025.

Who is affected

All users and administrators accessing the Azure Portal are now required to use MFA.

Why it matters

This enforcement enhances security by mitigating unauthorized access risks, aligning with Microsoft's commitment to bolster customer protection against cyber threats.

How it could have been prevented

Organizations should proactively implement MFA policies and educate users on secure authentication practices to prevent unauthorized access.

Relevant professional terms

Multifactor Authentication (MFA)
A security process requiring multiple forms of verification to access an account, enhancing protection against unauthorized access.
Azure Portal
A web-based application provided by Microsoft for managing Azure services and resources.

Recommended reading: Microsoft to enforce MFA for Azure resource management in October

Wealthsimple Data Breach Exposes Client Personal Information

High

What happened

Wealthsimple, a Canadian online investment management service, experienced a data breach on August 30, 2025, due to a compromised third-party software package. This led to unauthorized access to personal information of less than 1% of its clients.

Who is affected

Less than 1% of Wealthsimple's client base, which equates to fewer than 30,000 individuals, had their personal data accessed without authorization.

Why it matters

The breach exposed sensitive personal information, including Social Insurance Numbers and government-issued IDs, increasing the risk of identity theft for affected clients. While no funds were stolen, the incident underscores the vulnerabilities associated with third-party software dependencies.

How it could have been prevented

Implementing rigorous security assessments and continuous monitoring of third-party software packages could have identified vulnerabilities before exploitation. Regular audits and prompt patching of third-party components are essential to mitigate such risks.

Relevant professional terms

Third-Party Risk Management
The process of identifying, assessing, and controlling risks associated with outsourcing to third-party vendors or service providers.
Data Breach
An incident where unauthorized individuals gain access to confidential data, leading to potential data theft or exposure.

Recommended reading: Wealthsimple Security and Privacy Measures

Critical Argo CD API Vulnerability (CVE-2025-55190) Exposes Repository Credentials

Critical

What happened

A critical vulnerability in Argo CD (CVE-2025-55190) allows API tokens with project-level permissions to access sensitive repository credentials through the project details API endpoint, even without explicit access to secrets.

Who is affected

Organizations using Argo CD versions up to 2.13.0 are impacted, including enterprises like Adobe, Google, IBM, Intuit, Red Hat, Capital One, and BlackRock.

Why it matters

Exploitation of this flaw could lead to unauthorized access to private codebases, injection of malicious manifests, downstream compromises, or lateral movement to other resources using the same credentials.

How it could have been prevented

Implementing strict access controls to ensure API tokens have only necessary permissions and promptly updating to patched versions of Argo CD.

Relevant professional terms

API Token
A unique identifier used to authenticate and authorize API requests.
GitOps
A set of practices that use Git repositories as the single source of truth for declarative infrastructure and applications.

Recommended reading: GitHub Security Advisory

Critical SAP S/4HANA Vulnerability (CVE-2025-42957) Exploited in Attacks

Critical

What happened

A critical code injection vulnerability (CVE-2025-42957) in SAP S/4HANA is being actively exploited by attackers to gain full control over unpatched systems.

Who is affected

Organizations using SAP S/4HANA (Private Cloud or On-Premise) versions S4CORE 102 through 108 that have not applied the August 2025 security updates.

Why it matters

Exploitation of this vulnerability can lead to unauthorized access, data theft, data manipulation, and operational disruptions, posing significant risks to business operations and data integrity.

How it could have been prevented

Timely application of SAP's security patches released on August 11, 2025, and regular system updates to address known vulnerabilities.

Relevant professional terms

ABAP (Advanced Business Application Programming)
A high-level programming language created by SAP for developing business applications.
RFC (Remote Function Call)
A protocol used to execute functions in a remote system, enabling communication between SAP systems.

Recommended reading: SAP Community Blog on CVE-2025-42957

TAG-150's 'CastleRAT' Malware Targets U.S. Government Agencies

High

What happened

A clandestine malware-as-a-service (MaaS) group, identified as TAG-150, has developed and deployed a novel remote access Trojan (RAT) named 'CastleRAT.' This malware has been used in over 1,600 attacks, with nearly 470 successful infections, primarily targeting U.S. government agencies.

Who is affected

U.S. government agencies and critical organizations have been the primary targets of TAG-150's 'CastleRAT' malware.

Why it matters

The high success rate of 'CastleRAT' infections poses a significant threat to national security, as it grants unauthorized access to sensitive government systems. The stealthy nature of TAG-150's operations, without visible presence on the Dark Web, complicates detection and mitigation efforts.

How it could have been prevented

Implementing robust endpoint detection and response (EDR) solutions, conducting regular security audits, and educating personnel on recognizing phishing attempts and malicious links could mitigate the risk of such infections.

Relevant professional terms

Malware-as-a-Service (MaaS)
A business model where cybercriminals provide malware tools and services to other attackers for a fee.
Remote Access Trojan (RAT)
A type of malware that allows unauthorized remote control over an infected computer.

Recommended reading: darkreading.com

Federal Budget Cuts Increase Cybersecurity Risks for State and Local Agencies

High

What happened

Recent federal budget cuts have reduced funding and staffing for key cybersecurity agencies, including the Cybersecurity and Infrastructure Security Agency (CISA) and the Multi-State Information Sharing and Analysis Center (MS-ISAC). Concurrently, state and local governments have experienced significant ransomware attacks, such as those in Nevada and St. Paul, Minnesota, leading to service disruptions and data breaches.

Who is affected

State and local government agencies across the United States, particularly those with limited cybersecurity resources, are directly impacted by these developments.

Why it matters

The combination of increased cyberattacks and decreased federal support heightens the vulnerability of state and local agencies. This situation poses significant risks to critical infrastructure and public services, potentially leading to prolonged service outages and compromised sensitive data.

How it could have been prevented

Maintaining or increasing federal funding and staffing for cybersecurity agencies like CISA and MS-ISAC would have provided essential support to state and local governments. Additionally, implementing comprehensive cybersecurity strategies, including regular risk assessments, employee training, and incident response planning, could mitigate the impact of such attacks.

Relevant professional terms

Ransomware
A type of malicious software designed to block access to a computer system or data until a ransom is paid.
Incident Response Plan
A structured approach outlining the procedures to detect, respond to, and recover from cybersecurity incidents.

Recommended reading: State & Local Leaders Lobby Congress for Cyber Resources

US Manufacturing Companies Targeted in 'ZipLine' Cyberattack Campaign

High

What happened

A sophisticated cyberattack campaign named 'ZipLine' targeted US manufacturing companies, where attackers engaged in prolonged email exchanges using fake domains to deliver custom malware called MixShell.

Who is affected

Manufacturing companies in the United States were the primary targets of this campaign.

Why it matters

The campaign's use of legitimate-looking business interactions and prolonged engagement increases the likelihood of successful infiltration, posing significant risks to the operational integrity and intellectual property of manufacturing firms.

How it could have been prevented

Implementing robust email verification processes, conducting regular employee training on phishing tactics, and deploying advanced threat detection systems to identify and block malicious communications.

Relevant professional terms

Phishing
A cyberattack method where attackers impersonate legitimate entities to deceive individuals into providing sensitive information.
Malware
Malicious software designed to disrupt, damage, or gain unauthorized access to computer systems.

Recommended reading: Assessing Cyber and Physical Risks to Manufacturers