Intrusions involving a Microsoft SharePoint vulnerability were noted by the Center for Internet Security to have compromised over 90 state and local governments across the U.S., Reuters reports.
Observed intrusions exploiting a pair of maximum severity injection flaws impacting Cisco's Identity Services Engine, tracked as CVE-2025-20281 and CVE-2025-20337, and another cross-site request forgery bug affecting PaperCut NG/MF, tracked as CVE-2025-2533, have prompted their inclusion in the Cybersecurity and Infrastructure Security Agency's Known Exploited Vulnerabilities catalog, reports Security Affairs.
Honeywell subsidiary Tridium's Niagara Framework has been impacted by over a dozen security flaws, which could be leveraged to facilitate significant compromise of building systems, according to Facilities Dive.
Threat actors could compromise over 200,000 WordPress sites' admin accounts by exploiting a high-severity Post SMTP plugin vulnerability, tracked as CVE-2025-24000, BleepingComputer reports.
Widespread intrusions compromising vulnerable on-premises Microsoft SharePoint servers are believed by Trend Micro Zero Day Initiative Head of Threat Awareness Dustin Childs to have been facilitated by the exposure of bug details from the Microsoft Active Protections Program, where security vendors were able to obtain advanced access to the flaw earlier this month after being discovered in May, The Register reports.
Fast Five
Selected by the SC Media Editorial team every Tuesday.
Sign up now for the top five issues cybersecurity pros need to know this week.