Attack on the Canadian House of Commons
Threat Actor exploited a recently discovered Microsoft vulnerability to access the Canadian Parliament's network and compromise employee data. Authorities are investigating, and an official statement is pending.
https://cybersecuritynews.com/canadas-house-of-commons-cyberattack
Critical vulnerabilities actively exploited in N‑able N‑Central
CISA has added two exploits (CVE-2025-8875 & CVE-2025-8876) in the popular RMM platform N-able N-Central to the Known Exploited Vulnerabilities (KEV) catalog. The vulnerabilities enable remote code execution and command injection, among other things. Security update to version 2025.3.1 is strongly recommended.
https://www.cisa.gov/known-exploited-vulnerabilities-catalog
WinRAR zero-day actively in use (CVE-2025-8088)
A critical directory traversal vulnerability in WinRAR is being actively exploited by the Russian-linked RomCom group. Backdoors such as SnipBot, RustyClaw, and Mythic Agent are being used to infiltrate systems via manipulated RAR archives. Users must manually update to version 7.13.
Microsoft Patch Tuesday: 111 vulnerabilities closed
Patch Tuesday August 2025 closes a total of 111 vulnerabilities, including a zero-day in Windows Kerberos (CVE-2025-53779) and other critical bugs, for example in Azure OpenAI and graphics components. Immediate patching is strongly recommended.
https://thehackernews.com/2025/08/microsoft-august-2025-patch-tuesday.html
160% increase in credential theft by 2025
According to Check Point, stolen login credentials have increased by 160% compared to last year. The problem affects platforms such as Discord, Microsoft, Facebook, and GitHub, among others. Recommendation: MFA, strong password policies, monitoring, and awareness programs.
https://www.itpro.com/security/cyber-attacks/credential-theft-has-surged-160-percent-in-2025
Those who are prepared are safe
This week's events make it clear that vulnerabilities in everyday software such as WinRAR, in remote management solutions such as N-able, or in central components such as Microsoft Kerberos are not only published but often actively exploited within a very short time. Even authorities such as the Canadian Parliament are targeted by targeted attacks due to unpatched systems.
With penetration tests, risk analyses, and awareness measures (e.g., phishing and ransomware simulations, training courses), we support companies in identifying vulnerabilities at an early stage and strengthening their security structure in the long term.
Do you have specific questions? Book your free initial consultation now. You will find the link in the first comment.


