Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

CVE-2025-25257: Critical Unauthenticated SQL Injection Vulnerability in FortiWeb

On July 8, 2025, Fortinet released fixes for a critical vulnerability in FortiWeb that could allow an unauthenticated threat actor to execute SQL commands via crafted HTTP or HTTPS requests, tracked as CVE-2025-25257. The flaw lies in the Graphical User Interface (GUI) component and stems from improper neutralization of special elements used in SQL statements. The vulnerability was discovered by a security researcher and responsibly disclosed to Fortinet.

CVE-2025-47812: Wing FTP Server Remote Code Execution Vulnerability Exploited in the Wild

On July 10, 2025, a technical article was published by Huntress revealing that a maximum severity remote code execution vulnerability in Wing FTP Server, CVE-2025-47812, had been actively exploited by threat actors as early as July 1, 2025. Details of the vulnerability had originally been published on June 30, 2025, providing a comprehensive breakdown of the flaw and how to exploit it.

Understanding Multi-Factor Authentication

Looking back at the early 2024 data breach at Change Healthcare — a provider of revenue and payment cycle management that connects payers, providers, and patients within the U.S. healthcare system — one key detail stands out: Initial access into the healthcare system’s network was much easier due to a lack of multi-factor authentication (MFA).

CVE-2025-20309: Cisco Unified Communications Manager Static SSH Credentials Maximum Severity Vulnerability

On July 2, 2025, Cisco released a security advisory detailing a maximum severity vulnerability (CVE-2025-20309) in Cisco Unified Communications Manager and Unified Communications Manager SME Engineering Special, caused by hard-coded root SSH credentials that cannot be changed or removed.

The Howler Episode 20: Matt Bykowski, SVP Global Acquisition Sales

This month, we sit down with Matt Bykowski, Senior Vice President of Global Acquisition Sales, as he shares how he works to enable & empower his team, learnings from leading an increasingly global team, his thoughts on the transition from high performer to people leader, and so much more! Matt Bykowski is a dynamic sales leader with over 15 years of experience driving growth in the technology sector.

Navigating Cyber Risks Amid Heightened Middle East Tensions

Recent escalations involving the U.S. and Iran highlight an important reality: geopolitical tensions frequently extend into cyberspace. Cyber threat actors affiliated with or sympathetic to Iran are intensifying their efforts, increasing risks not only for U.S.-based organizations but also for companies across allied nations, particularly those with diplomatic, military, or critical infrastructure ties. Reflecting this elevated threat landscape, the U.S.

Malvertising Campaign Delivers Oyster/Broomstick Backdoor via SEO Poisoning and Trojanized Tools

Since early June 2025, Arctic Wolf has observed a search engine optimization (SEO) poisoning and malvertising campaign promoting malicious websites hosting trojanized versions of legitimate IT tools such as PuTTY and WinSCP.

SOCAST LIVE ZERO ASSUMPTIONS: A Threat Intel Roundtable

The threat landscape is evolving faster than ever, and with geopolitical tensions rising globally, IT and security leaders need the latest information on how to remain ready and resilient. Join Arctic Wolf and the industry's leading experts to learn: Featuring: Ismael Valenzuela — VP, Threat Research and Intelligence, Arctic Wolf Markus Neis — Senior Principal Threat Intelligence Researcher, Arctic Wolf.