IT Security Newsletter

IT Security Newsletter - 9/4/25

Written by Cadre | Thu, Sep 4, 2025

The Ongoing Fallout from a Breach at AI Chatbot Maker Salesloft

The recent mass-theft of authentication tokens from Salesloft, whose AI chatbot is used by a broad swath of corporate America to convert customer interaction into Salesforce leads, has left many companies racing to invalidate the stolen credentials before hackers can exploit them. Now Google warns the breach goes far beyond access to Salesforce data, noting the hackers responsible also stole valid authentication tokens for hundreds of online services that customers can integrate with Salesloft. READ MORE...

FBI warns seniors are being targeted in three-phase Phantom Hacker scams

The FBI's Internet Crime Complaint Center (IC3) says that the elderly are more at risk from falling victim to online fraud and internet scammers than ever before. In fact, according to the IC3's latest published annual report, seniors suffered a staggering US $4.885 billion dollars worth of losses last year - a 43% increase from 2023. With an average loss of US $83,000 and an astonishing 7,500 complainants reporting that they have lost in excess of US $100,000, it's clearly essential that more is done to raise awareness amongst those who are vulnerable. READ MORE...

Microsoft says recent Windows updates cause app install issues

Microsoft says the August 2025 security updates are triggering unexpected User Account Control (UAC) prompts and app installation issues for non-admin users across all supported Windows versions. This known issue is caused by a security patch that addresses the CVE-2025-50173 Windows Installer privilege escalation vulnerability, which can allow authenticated attackers to gain SYSTEM privileges due to a weak authentication issue. READ MORE...

TamperedChef infostealer delivered through fraudulent PDF Editor

Threat actors have been using multiple websites promoted through Google ads to distribute a convincing PDF editing app that delivers an info-stealing malware called TamperedChef. The campaign is part of a larger operation with multiple apps that can download each other, some of them tricking users into enrolling their system into residential proxies. More than 50 domains have been identified to host deceiving apps signed with fraudulent certificates issued by at least four different companies. READ MORE...

Hackers Exploit Sitecore Zero-Day for Malware Delivery

Adversaries used a sample machine key that was included in Sitecore deployment guides from 2017 and earlier and executed a ViewState deserialization attack against internet-accessible Sitecore instances. The issue, tracked as CVE-2025-53690 (CVSS score of 9.0), is described as a deserialization of untrusted data bug affecting Sitecore Experience Manager (XM) and Experience Platform (XP) prior to version 9.0 that were deployed using the sample key exposed in the guides. READ MORE...

Popular Android VPN apps found to have security flaws and China links

People use VPNs for different security and privacy reasons, to access content anonymously, or to bypass content controls and age verification by pretending to be in different places. But not all VPNs are created equal. A recent report has revealed that many of them might allow others to sniff your data-and they're not being honest about who's behind them. The report, called Hidden Links: Analyzing Secret Families of VPN Apps, comes from researchers at the University of Toronto's Citizen Lab, and Arizona State University. READ MORE...

WhatsApp Bug Anchors Targeted Zero-Click iPhone Attacks

Attackers are exploiting a WhatsApp security vulnerability affecting iPhone iOS in a "sophisticated" zero-click attack against targeted Apple users. The campaign also uses a previously discovered and patched iOS flaw, CVE-2025-43300, known to be used in other attacks. The incidents, which have affected about 200 people so far, have spurred the US government to urge users across its federal workforce to update their devices immediately. READ MORE...

  • ...in 1888, George Eastman receives a patent for his roll film camera and registers the trademark "Kodak".
  • ...in 1957, The Ford Motor Company introduces the Edsel, which was touted as the car of the future, but ended up a commercial flop.
  • ...in 1972, CBS premieres "The Price Is Right", currently the longest running game show on American TV.
  • ...in 1998, Google is founded by two Stanford University students, Larry Page and Sergey Brin.