> InfoSec News Nuggets 10/07/2025
[AUTHOR: Mary]
[DATE: 07/10/2025 14:34]
[LANGUAGE: EN]
Thieves steal IDs and payment info after data leaks from Discord support vendor
Discord has confirmed customers’ data was stolen – but says the culprit wasn’t its own servers, just a compromised support vendor. The chat platform revealed late last week that an unnamed customer service vendor had been compromised, exposing support tickets and personal details submitted by users who had contacted Discord’s help or Trust & Safety teams. The company stressed that its own systems were not directly accessed. However, stolen data may include names, email addresses, billing information such as payment type and the last four digits of credit cards, and – in some cases – images of government IDs provided for age verification purposes.
13-year-old Critical Redis RCE Vulnerability Let Attackers Gain Full Access to Host System
A 13-year-old critical remote code execution (RCE) vulnerability in Redis, dubbed RediShell, allows attackers to gain full access to the underlying host system. The flaw, tracked as CVE-2025-49844, was discovered by Wiz Research and has been assigned the highest possible CVSS severity score of 10.0, a rating reserved for the most severe security issues. The vulnerability is a Use-After-Free (UAF) memory corruption bug that has existed in the Redis source code for approximately 13 years. A post-authentication attacker can exploit this flaw by sending a specially crafted Lua script.
Security Firm Exposes Role of Beijing Research Institute in China’s Cyber Operations
Recorded Future has uncovered ties between the Beijing Institute of Electronics Technology and Application (BIETA) and China’s Ministry of State Security (MSS), the country’s primary civilian intelligence service. BIETA, the cybersecurity firm says, was likely established in some form in 1983, the same year the MSS was created, and supports, together with its subsidiary Beijing Sanxin Times Technology Co (CIII), MSS operations across various activities. Most likely led by the MSS and headquartered in the ministry compound, BIETA is believed to research, create, and sell technology in support of the country’s intelligence, counterintelligence, and military operations, Recorded Future’s report shows.
Hackers launch data leak site to extort 39 victims, or Salesforce
Scattered Lapsus$ Hunters launched a data leak site over the weekend, aiming to pressure organizations whose Salesforce databases they have plundered into paying to prevent the stolen data from being released. Scattered Lapsus$ Hunters is a hacker collective that reportedly brings together members of the Scattered Spider, Lapsus$, and ShinyHunters cybercrime groups. The dark web data leak site currently lists 39 companies whose data was apparently stolen by compromising their corporate Salesforce instances via social engineering: Toyota, FedEx, Disney/Hulu, Republic Services, UPS, AeroMexico, Home Depot, Marriott, Vietnam Airlines, Walgreens, Stellantis, McDonald’s, KFC, ASICS, GAP, MHM, Fujifilm, Instructure.com – Canvas, Albertsons, Engie Resources, Kering (Gucci, Balenciaga, Brioni, AlexanderMcQ), HBO Max, Instacart, Petco, Puma, Cartier, Adidas, TripleA, Qantas Airways, CarMax, Saks Fifth (Avenue), 1-800Accountant, AirFrance & KLM, Google Adsense, Cisco, Pandora, TransUnion, Chanel, and IKEA.
Google DeepMind launches an AI agent to fix code vulnerabilities automatically
Google DeepMind has introduced an AI agent that automatically found and fixed software vulnerabilities in open source projects, submitting 72 security patches over the past six months to codebases including some as large as 4.5 million lines of code. The tool, called CodeMender, uses Gemini Deep Think models to create an autonomous agent capable of debugging and fixing complex security flaws, Raluca Ada Popa, senior staff research scientist at Google’s DeepMind, and Fionn Flynn, VP of Security and Privacy at Google DeepMind, wrote in a blog post.
The post InfoSec News Nuggets 10/07/2025 appeared first on AboutDFIR - The Definitive Compendium Project.