X
Cisco ASA zero-day vulnerabilities exploited in sophisticated attacks
Mark Anderson | Security | September 26, 2025

Euclid Security Newsletter

September 26, 2025 

Cisco ASA zero-day vulnerabilities exploited in sophisticated attacks

A widespread campaign aimed at breaching organizations via zero-day vulnerabilities in Cisco Adaptive Security Appliances (ASA) has been revealed by the US, UK, Canadian and Australian cybersecurity agencies.

 

Security News

New macOS XCSSET Variant Targets Firefox

Cybersecurity researchers have discovered an updated version of a known Apple macOS malware called XCSSET that has been observed in limited attacks. This new variant of XCSSET brings key changes related to browser targeting, clipboard hijacking, and persistence mechanisms.

Salesforce AI Hack Enabled CRM Data Theft

Prompt injection and an expired domain could have been used to target Salesforce's Agentforce platform for data theft. Salesforce Agentforce enables businesses to build and deploy autonomous AI agents across functions such as sales, marketing, and commerce.

DDoS attack volumes surge 41% as threats rapidly evolve

Attack volumes increased by 41 percent compared to Q1-Q2 of 2024, evidencing dangerous long term growth trends predicted in prior Radar reports. The largest attack peaked at 2.2 Tbps in Q1-Q2, surpassing the 2 Tbps peak recorded in late 2024.

Teen suspected of Vegas casino cyberattacks released to parents

The Las Vegas Metropolitan Police Department did not name the casinos targeted, it noted that the attacks occurred between August and October 2023 and described them as "sophisticated network intrusions" attributed to Scattered Spider.

Microsoft adds Claude to Copilot, but cross-cloud AI could raise new governance challenges

While Claude boosts reasoning and resilience, its AWS-hosted architecture could introduce latency, egress costs, and data sovereignty concerns, forcing CIOs to build model-aware routing and monitoring frameworks.

Employees learn nothing from phishing security training, and this is why

A new study reveals that success is measured in the single digits in the best-case scenario. Here's what companies should do instead.

 

Important Updates & Patches

Cisco Patches Zero Day for ASA Firewalls

Cisco has released software updates that address this vulnerability and strongly recommends that customers upgrade to a fixed software release. There are no workarounds that address this vulnerability.

 

Dan's Corner

Spotify removes 75 million spam tracks

Spotify has removed more than 75 million spam tracks in the last year, a move it says is part of its response to the rapid growth of generative AI in music.

 

An archive of Euclid Security Newsletters can be found on the support website.

Euclid Technology Solutions, LLC
540 Devall Drive, Suite 301
Auburn, AL 36832

P: 301-657-8089
E: support@euclidtechnology.com

New Comment ...

Sort by: