CISA Mandates Patches for Exploited Flaws; Nation-State Actors Breach F5 and Prosper Suffers Massive Data Leak

Publication Date: October 20, 2025

Summary

This cybersecurity brief for October 20, 2025, covers a series of high-impact events. CISA has added five actively exploited vulnerabilities to its KEV catalog, mandating urgent patching. In a significant supply-chain threat, a nation-state actor breached F5, stealing BIG-IP source code. Meanwhile, the Prosper lending platform disclosed a massive data breach affecting 17.6 million users, and the Cl0p ransomware gang is exploiting a new zero-day in Oracle E-Business Suite. These incidents highlight escalating threats across patch management, supply chain security, and data protection.

Today New Articles

CISA Mandates Patching for 5 New Actively Exploited Flaws in Apple, Microsoft, Oracle, and Kentico

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added five new vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation in the wild. The flaws affect a range of widely used products, incl...


AWS Outage in us-east-1 Knocks Major Global Services Offline

A significant infrastructure fault within Amazon Web Services' (AWS) us-east-1 region in North Virginia on October 20, 2025, triggered a global outage affecting numerous major online services. Platforms including Snapchat, Fortnite, Disney Plus, and various ba...


Anubis Ransomware Hits Australian Engineering Firm Aussie Fluid Power

The Australian industrial engineering company, Aussie Fluid Power, has confirmed it was hit by a ransomware attack claimed by the emerging 'Anubis' ransomware group. The incident, which has impacted company operations and stakeholder data, aligns with warnings...


EU and Ukraine Deepen Cyber Defense Alliance in Face of Russian Aggression

The European Union and Ukraine have reaffirmed their strategic partnership on cybersecurity during their 4th Cyber Dialogue held in Kyiv. Against the backdrop of Russia's ongoing war, both parties committed to deepening cooperation on cyber defense, policy ali...

Article Updates

Clop Ransomware Claims Harvard University Breach, Threatens Data Leak

Update:The Clop ransomware attack on Harvard University has been confirmed to stem from the exploitation of a critical zero-day vulnerability, CVE-2025-61882, in Oracle's E-Business Suite. This complex RCE flaw served as the initial access vector for the breach. The...


F5 Breached by Nation-State Actor; BIG-IP Source Code Stolen, CISA Issues Emergency Directive

Update:A new report further emphasizes the F5 breach as a critical supply-chain attack preparation by a nation-state actor. The analysis reiterates the severe future risk of new zero-day vulnerabilities being discovered and exploited due to the stolen BIG-IP source c...


Massive Airline Data Breach Hits 13 Million Vietnam Airlines and Qantas Customers

Update:New details reveal the 'Scattered Lapsus$ Hunters' group demanded a ransom from Qantas, setting an October 11 deadline. Upon non-payment, the group proceeded to leak the personal information of 5.7 million Qantas customers. This confirms the use of double-exto...


Lending Platform Prosper Breached, 17.6 Million Accounts Exposed

Update:Further investigation into the Prosper data breach has revealed that the compromised data set is far more extensive and sensitive than initially reported. In addition to names, emails, and phone numbers, the breach now includes the exposure of Social Security...


Microsoft Report: AI-Generated Phishing Now 4.5x More Effective, Bypassing Traditional Defenses

Update:A new ISACA report reveals that 63% of IT and cybersecurity professionals now consider AI-driven social engineering the top cyber threat for 2026, surpassing ransomware. Despite this consensus, only 13% of organizations feel 'very prepared' to manage generativ...