Attack on the Canadian House of Commons

Threat Actor exploited a recently discovered Microsoft vulnerability to access the Canadian Parliament's network and compromise employee data. Authorities are investigating, and an official statement is pending.

https://cybersecuritynews.com/canadas-house-of-commons-cyberattack

Critical vulnerabilities actively exploited in N‑able N‑Central

CISA has added two exploits (CVE-2025-8875 & CVE-2025-8876) in the popular RMM platform N-able N-Central to the Known Exploited Vulnerabilities (KEV) catalog. The vulnerabilities enable remote code execution and command injection, among other things. Security update to version 2025.3.1 is strongly recommended.

https://www.cisa.gov/known-exploited-vulnerabilities-catalog

WinRAR zero-day actively in use (CVE-2025-8088)

A critical directory traversal vulnerability in WinRAR is being actively exploited by the Russian-linked RomCom group. Backdoors such as SnipBot, RustyClaw, and Mythic Agent are being used to infiltrate systems via manipulated RAR archives. Users must manually update to version 7.13.

https://www.techradar.com/pro/security/winrar-has-a-serious-security-flaw-worrying-zero-day-issue-lets-hackers-plant-malware-so-patch-right-away

Microsoft Patch Tuesday: 111 vulnerabilities closed

Patch Tuesday August 2025 closes a total of 111 vulnerabilities, including a zero-day in Windows Kerberos (CVE-2025-53779) and other critical bugs, for example in Azure OpenAI and graphics components. Immediate patching is strongly recommended.

https://thehackernews.com/2025/08/microsoft-august-2025-patch-tuesday.html

160% increase in credential theft by 2025

According to Check Point, stolen login credentials have increased by 160% compared to last year. The problem affects platforms such as Discord, Microsoft, Facebook, and GitHub, among others. Recommendation: MFA, strong password policies, monitoring, and awareness programs.

https://www.itpro.com/security/cyber-attacks/credential-theft-has-surged-160-percent-in-2025

Those who are prepared are safe

This week's events make it clear that vulnerabilities in everyday software such as WinRAR, in remote management solutions such as N-able, or in central components such as Microsoft Kerberos are not only published but often actively exploited within a very short time. Even authorities such as the Canadian Parliament are targeted by targeted attacks due to unpatched systems.

With penetration tests, risk analyses, and awareness measures (e.g., phishing and ransomware simulations, training courses), we support companies in identifying vulnerabilities at an early stage and strengthening their security structure in the long term.

Do you have specific questions? Book your free initial consultation now. You will find the link in the first comment.


Related news

Blog

Never click on links in emails! Never open an email that seems strange to you! Never reply to an…
Blog

Cyber risks in the financial sector The digitization of the industry is advancing rapidly and…
WAS IST DIESE WOCHE IN DER HACKING-WELT PASSIERT?
Blog

US court system hacked - witness information compromised A targeted attack on the US federal court…