
Daily Dose of Cybersecurity News - September 6, 2025
Microsoft Enforces MFA for Azure Portal Sign-ins Across All Tenants
HighWhat happened
Microsoft has enforced multifactor authentication (MFA) for all Azure Portal sign-ins across all tenants as of March 2025.
Who is affected
All users and administrators accessing the Azure Portal are now required to use MFA.
Why it matters
This enforcement enhances security by mitigating unauthorized access risks, aligning with Microsoft's commitment to bolster customer protection against cyber threats.
How it could have been prevented
Organizations should proactively implement MFA policies and educate users on secure authentication practices to prevent unauthorized access.
Relevant professional terms
- Multifactor Authentication (MFA)
- A security process requiring multiple forms of verification to access an account, enhancing protection against unauthorized access.
- Azure Portal
- A web-based application provided by Microsoft for managing Azure services and resources.
Recommended reading: Microsoft to enforce MFA for Azure resource management in October
Wealthsimple Data Breach Exposes Client Personal Information
HighWhat happened
Wealthsimple, a Canadian online investment management service, experienced a data breach on August 30, 2025, due to a compromised third-party software package. This led to unauthorized access to personal information of less than 1% of its clients.
Who is affected
Less than 1% of Wealthsimple's client base, which equates to fewer than 30,000 individuals, had their personal data accessed without authorization.
Why it matters
The breach exposed sensitive personal information, including Social Insurance Numbers and government-issued IDs, increasing the risk of identity theft for affected clients. While no funds were stolen, the incident underscores the vulnerabilities associated with third-party software dependencies.
How it could have been prevented
Implementing rigorous security assessments and continuous monitoring of third-party software packages could have identified vulnerabilities before exploitation. Regular audits and prompt patching of third-party components are essential to mitigate such risks.
Relevant professional terms
- Third-Party Risk Management
- The process of identifying, assessing, and controlling risks associated with outsourcing to third-party vendors or service providers.
- Data Breach
- An incident where unauthorized individuals gain access to confidential data, leading to potential data theft or exposure.
Recommended reading: Wealthsimple Security and Privacy Measures
Critical Argo CD API Vulnerability (CVE-2025-55190) Exposes Repository Credentials
CriticalWhat happened
A critical vulnerability in Argo CD (CVE-2025-55190) allows API tokens with project-level permissions to access sensitive repository credentials through the project details API endpoint, even without explicit access to secrets.
Who is affected
Organizations using Argo CD versions up to 2.13.0 are impacted, including enterprises like Adobe, Google, IBM, Intuit, Red Hat, Capital One, and BlackRock.
Why it matters
Exploitation of this flaw could lead to unauthorized access to private codebases, injection of malicious manifests, downstream compromises, or lateral movement to other resources using the same credentials.
How it could have been prevented
Implementing strict access controls to ensure API tokens have only necessary permissions and promptly updating to patched versions of Argo CD.
Relevant professional terms
- API Token
- A unique identifier used to authenticate and authorize API requests.
- GitOps
- A set of practices that use Git repositories as the single source of truth for declarative infrastructure and applications.
Recommended reading: GitHub Security Advisory
Critical SAP S/4HANA Vulnerability (CVE-2025-42957) Exploited in Attacks
CriticalWhat happened
A critical code injection vulnerability (CVE-2025-42957) in SAP S/4HANA is being actively exploited by attackers to gain full control over unpatched systems.
Who is affected
Organizations using SAP S/4HANA (Private Cloud or On-Premise) versions S4CORE 102 through 108 that have not applied the August 2025 security updates.
Why it matters
Exploitation of this vulnerability can lead to unauthorized access, data theft, data manipulation, and operational disruptions, posing significant risks to business operations and data integrity.
How it could have been prevented
Timely application of SAP's security patches released on August 11, 2025, and regular system updates to address known vulnerabilities.
Relevant professional terms
- ABAP (Advanced Business Application Programming)
- A high-level programming language created by SAP for developing business applications.
- RFC (Remote Function Call)
- A protocol used to execute functions in a remote system, enabling communication between SAP systems.
Recommended reading: SAP Community Blog on CVE-2025-42957
TAG-150's 'CastleRAT' Malware Targets U.S. Government Agencies
HighWhat happened
A clandestine malware-as-a-service (MaaS) group, identified as TAG-150, has developed and deployed a novel remote access Trojan (RAT) named 'CastleRAT.' This malware has been used in over 1,600 attacks, with nearly 470 successful infections, primarily targeting U.S. government agencies.
Who is affected
U.S. government agencies and critical organizations have been the primary targets of TAG-150's 'CastleRAT' malware.
Why it matters
The high success rate of 'CastleRAT' infections poses a significant threat to national security, as it grants unauthorized access to sensitive government systems. The stealthy nature of TAG-150's operations, without visible presence on the Dark Web, complicates detection and mitigation efforts.
How it could have been prevented
Implementing robust endpoint detection and response (EDR) solutions, conducting regular security audits, and educating personnel on recognizing phishing attempts and malicious links could mitigate the risk of such infections.
Relevant professional terms
- Malware-as-a-Service (MaaS)
- A business model where cybercriminals provide malware tools and services to other attackers for a fee.
- Remote Access Trojan (RAT)
- A type of malware that allows unauthorized remote control over an infected computer.
Recommended reading: darkreading.com
Federal Budget Cuts Increase Cybersecurity Risks for State and Local Agencies
HighWhat happened
Recent federal budget cuts have reduced funding and staffing for key cybersecurity agencies, including the Cybersecurity and Infrastructure Security Agency (CISA) and the Multi-State Information Sharing and Analysis Center (MS-ISAC). Concurrently, state and local governments have experienced significant ransomware attacks, such as those in Nevada and St. Paul, Minnesota, leading to service disruptions and data breaches.
Who is affected
State and local government agencies across the United States, particularly those with limited cybersecurity resources, are directly impacted by these developments.
Why it matters
The combination of increased cyberattacks and decreased federal support heightens the vulnerability of state and local agencies. This situation poses significant risks to critical infrastructure and public services, potentially leading to prolonged service outages and compromised sensitive data.
How it could have been prevented
Maintaining or increasing federal funding and staffing for cybersecurity agencies like CISA and MS-ISAC would have provided essential support to state and local governments. Additionally, implementing comprehensive cybersecurity strategies, including regular risk assessments, employee training, and incident response planning, could mitigate the impact of such attacks.
Relevant professional terms
- Ransomware
- A type of malicious software designed to block access to a computer system or data until a ransom is paid.
- Incident Response Plan
- A structured approach outlining the procedures to detect, respond to, and recover from cybersecurity incidents.
Recommended reading: State & Local Leaders Lobby Congress for Cyber Resources
US Manufacturing Companies Targeted in 'ZipLine' Cyberattack Campaign
HighWhat happened
A sophisticated cyberattack campaign named 'ZipLine' targeted US manufacturing companies, where attackers engaged in prolonged email exchanges using fake domains to deliver custom malware called MixShell.
Who is affected
Manufacturing companies in the United States were the primary targets of this campaign.
Why it matters
The campaign's use of legitimate-looking business interactions and prolonged engagement increases the likelihood of successful infiltration, posing significant risks to the operational integrity and intellectual property of manufacturing firms.
How it could have been prevented
Implementing robust email verification processes, conducting regular employee training on phishing tactics, and deploying advanced threat detection systems to identify and block malicious communications.
Relevant professional terms
- Phishing
- A cyberattack method where attackers impersonate legitimate entities to deceive individuals into providing sensitive information.
- Malware
- Malicious software designed to disrupt, damage, or gain unauthorized access to computer systems.
Recommended reading: Assessing Cyber and Physical Risks to Manufacturers