Heroes, here's a detailed look at the current cybersecurity landscape for September 13, 2025.
Critical Threats
Critical CVE-2025-5086 in DELMIA Apriso Actively Exploited, CISA Issues Warning
CISA has added a critical vulnerability in Dassault Systèmes DELMIA Apriso software to its Known Exploited Vulnerabilities (KEV) catalog, confirming active exploitation in the wild. This flaw impacts Manufacturing Operations Management (MOM) software, posing a significant risk to industrial and manufacturing sectors. Organizations using this software must patch immediately to prevent potential operational disruption or data compromise.
Yurei & The Ghost of Open Source Ransomware
A new ransomware group, Yurei, has emerged, claiming a Sri Lankan food manufacturer as its first victim on September 5. The group employs a double-extortion model, encrypting victim data and threatening to leak it. The emergence of a new, active ransomware operator signals a continued and evolving threat to organizations globally.
Cisco fixes high-severity IOS XR flaws enabling image bypass and DoS
Cisco has patched multiple high-severity vulnerabilities in its IOS XR software, which is used in carrier-grade routers and network infrastructure. The flaws could allow an attacker to bypass ISO image verification or trigger a denial-of-service (DoS) condition. A successful exploit could severely impact the availability and integrity of critical network services.
High Severity
Trusted Connections, Hidden Risks: Token Management in the Third-Party Supply Chain
Researchers highlight the growing risk of supply chain attacks stemming from poorly managed OAuth tokens. Dormant integrations, insecure token storage, and a lack of key rotation create opportunities for attackers to gain unauthorized access to sensitive systems. This underscores the need for stringent security controls over third-party application integrations.
Chinese Guarantee Syndicates and the Fruit Machine
This report details the mechanics of large-scale phishing operations using "machine rooms" filled with iPhones to send iMessage spam. These operations represent a sophisticated and scalable threat for credential harvesting and malware distribution targeting Apple users. The analysis provides insight into the infrastructure behind modern, high-volume smishing campaigns.
Apple Sends Fresh Wave of Spyware Notifications to French Users
Apple has issued another round of notifications to users in France who may have been targeted by commercial spyware. This marks at least the fourth wave of such warnings this year, indicating a persistent and targeted surveillance campaign against specific individuals. The notifications highlight the ongoing threat posed by sophisticated state-sponsored or commercial spyware actors.
Reports of HybridPetya Malware Variant Surface
A news roundup mentions the emergence of a malware variant referred to as HybridPetya. While details are limited in this source, any malware associated with the Petya family is a significant concern due to the destructive, wiper-like capabilities of its predecessors. Security teams should monitor for further intelligence on this potential threat.
Executive Briefing
This analysis from Bruce Schneier discusses the critical need for a standardized framework for notifying victims of cyber incidents in a timely manner. For executives and security leaders, this piece provides strategic perspective on incident response, legal obligations, and public relations. Establishing clear, effective notification policies is crucial for managing reputational damage and regulatory risk following a breach.
Detection & Response
⚠️ Disclaimer: Test all detection logic in non-production environments before deployment.
1. YARA Rule for Yurei Ransomware Indicators
2. SIEM Query — Detecting Potential Ransomware C2 Activity
3. PowerShell Script — Check for CVE-2025-5086 IOCs
This rundown should provide a solid overview of the current threat landscape. Thank you to all our cyberheroes for your diligence and hard work. Stay vigilant!