Heroes, thanks for staying on your post on a Saturday. Here's a detailed look at the current cybersecurity landscape for September 20, 2025.
Critical Threats
Other Noteworthy
Executive Briefing
AWS has enhanced Service Control Policies (SCPs) in AWS Organizations to support the full IAM policy language, including conditions and individual resource specifications. This allows security leaders to implement more granular, preventative guardrails across their entire cloud environment, significantly improving governance and reducing the risk of critical misconfigurations.
The Atlantic Council has released its second annual report on the global spyware market, detailing the proliferation and capabilities of commercial surveillance tools. This report is crucial for understanding the evolving corporate and nation-state espionage landscape and the associated risks to sensitive communications and intellectual property.
This article discusses the critical importance of scalable secrets management for protecting Non-Human Identities (NHIs) as technology environments expand. It provides a strategic framework for security leaders to consider when securing machine-to-machine communication and automated workflows, which are frequent targets for attackers seeking to escalate privileges.
Vendor Spotlight
Spotlight Rationale: Selected due to the critical need for network-level detection and prevention capabilities in response to today's reported threats, specifically the remote code execution vulnerability in GoAnywhere MFT ([CVE-2025-10035](https://nvd.nist.gov/vuln/detail/CVE-2025-10035)) and the malware kits deployed in Ivanti EPMM attacks.
Threat Context: Fortra GoAnywhere MFT RCE Vulnerability
Platform Focus: Cisco Secure Firewall (with Intrusion Prevention System)
Cisco Secure Firewall provides a critical layer of defense against threats like CVE-2025-10035 by using its Intrusion Prevention System (IPS) to inspect traffic for exploit signatures. For the Ivanti EPMM attacks, it can block connections to known command-and-control infrastructure and use file policies to identify and block the specific malware kits analyzed by CISA, preventing initial payload delivery and subsequent malicious activity.
Actionable Platform Guidance: The following steps can help configure Cisco Secure Firewall to mitigate the threats detailed in today's rundown.
Source: cisco.com/security ↗