CVE Tools

In Other News: Zombie Card Attack, T-Mobile Cut Cable to Stop Hackers, GitHub Denies AI Caused Bug

SecurityWeekBy SecurityWeek News

Reported exploitedRondoDoxSalt TyphoonEvooo1Bot

Our summary

CISA has added CVE-2025-62593 in Ray-Project Ray to its Known Exploited Vulnerabilities catalog after observing active abuse by the RondoDox botnet, prompting a mandate for federal agencies to prioritize remediation. This development sits alongside several other high-profile incidents, including GitHub's clarification that a vulnerability exploited by Wiz's AI agent was human-authored rather than generated by Copilot, and reports of T-Mobile physically cutting a router cable to halt an intrusion by Salt Typhoon. Additionally, FortiGuard Labs identified Evooo1Bot, a Linux botnet leveraging multiple CVEs, while Medusa ransomware groups are actively targeting unpatched vulnerabilities in Fortra GoAnywhere and BeyondTrust.

Read at SecurityWeek

SecurityWeek publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store