{"id":16718,"date":"2025-06-16T11:29:45","date_gmt":"2025-06-16T08:29:45","guid":{"rendered":"https:\/\/digitrendz.blog\/?p=16718"},"modified":"2025-06-16T11:29:49","modified_gmt":"2025-06-16T08:29:49","slug":"microsoft-patches-zero-day-flaw-as-mirai-botnets-hit-wazuh-servers","status":"publish","type":"post","link":"https:\/\/digitrendz.blog\/z\/newswire\/technology\/16718\/microsoft-patches-zero-day-flaw-as-mirai-botnets-hit-wazuh-servers\/","title":{"rendered":"Microsoft patches zero-day flaw as Mirai botnets hit Wazuh servers"},"content":{"rendered":"<details class=\"wp-block-details ticss-586932b6 is-layout-flow wp-block-details-is-layout-flow\"><summary>\u25bc Summary<\/summary>\n<p class=\"ticss-0c48f427 has-small-font-size wp-block-paragraph\">&#8211; Microsoft fixed 66 CVEs in June 2025 Patch Tuesday, including an exploited zero-day (CVE-2025-33053).<br>&#8211; Unpatched Wazuh servers are being targeted by Mirai botnets exploiting a critical RCE vulnerability (CVE-2025-24016).<br>&#8211; Kali Linux 2025.2 was released, featuring Bloodhound CE, CARsenal, and 13 new tools for penetration testing.<br>&#8211; Attackers are brute-forcing Microsoft Entra ID accounts using the TeamFiltration framework, as reported by Proofpoint.<br>&#8211; LockBit ransomware operations netted $2.3 million in 5 months, with Chinese organizations among the most targeted.<br><\/p>\n<\/details>\n\n<p class=\"wp-block-paragraph\"><\/p>\n\n<p class=\"has-drop-cap wp-block-paragraph\"><strong><mark style=\"background-color:rgba(0, 0, 0, 0);color:#f34c3e\" class=\"has-inline-color\">M<\/mark>icrosoft addresses critical <a href=\"https:\/\/digitrendz.blog\/z\/trending-news\/218444\/apple-says-ex-employee-stole-files-using-rare-bug-after-jumping-to-openai\/\" class=\"acp-article-link\" data-article-id=\"218444\" title=\"Apple says ex-employee stole files using rare bug after jumping to OpenAI\" target=\"_blank\" rel=\"noopener noreferrer\">zero-day vulnerability<\/a> while Mirai botnets exploit unpatched <a href=\"https:\/\/digitrendz.blog\/z\/entity\/wazuh\/\" class=\"acp-entity-link\" data-entity-id=\"27960\" data-entity-category=\"Technology\" title=\"Learn more about Wazuh\" target=\"_blank\" rel=\"noopener noreferrer\">Wazuh<\/a> servers, highlighting the escalating challenges in cybersecurity defense.<\/strong><\/p>\n\n<p class=\"wp-block-paragraph\">The tech giant rolled out fixes for <strong>66 security flaws<\/strong> in its June 2025 <a href=\"https:\/\/digitrendz.blog\/z\/trending-news\/233994\/microsoft-patches-400-flaws-including-zero-day-under-attack\/\" class=\"acp-article-link\" data-article-id=\"233994\" title=\"Microsoft patches 400+ flaws, including zero-day under attack\" target=\"_blank\" rel=\"noopener noreferrer\">Patch Tuesday<\/a> update, including a <strong><a href=\"https:\/\/digitrendz.blog\/z\/trending-news\/233914\/microsoft-patches-nearly-400-security-flaws\/\" class=\"acp-article-link\" data-article-id=\"233914\" title=\"Microsoft Patches Nearly 400 Security Flaws\" target=\"_blank\" rel=\"noopener noreferrer\">zero-day exploit<\/a> (CVE-2025-33053)<\/strong> actively used in cyber espionage campaigns. Meanwhile, security researchers at <a href=\"https:\/\/digitrendz.blog\/z\/entity\/akamai\/\" class=\"acp-entity-link\" data-entity-id=\"12293\" data-entity-category=\"Organization\" title=\"Learn more about Akamai\" target=\"_blank\" rel=\"noopener noreferrer\">Akamai<\/a> uncovered two <strong>Mirai botnets<\/strong> targeting unpatched <strong>Wazuh XDR\/SIEM platforms<\/strong> through a <strong>critical <a href=\"https:\/\/digitrendz.blog\/z\/tech-news\/219637\/microsoft-fixes-record-570-security-flaws-in-one-patch\/\" class=\"acp-article-link\" data-article-id=\"219637\" title=\"Microsoft Fixes Record 570 Security Flaws in One Patch\" target=\"_blank\" rel=\"noopener noreferrer\">remote code execution<\/a> flaw (CVE-2025-24016)<\/strong>.<\/p>\n\n<p class=\"wp-block-paragraph\"><strong>Threat modeling remains undervalued despite its critical role in proactive security.<\/strong> While <a href=\"https:\/\/digitrendz.blog\/z\/entity\/cisos\/\" class=\"acp-entity-link\" data-entity-id=\"21000\" data-entity-category=\"Person\" title=\"Learn more about CISOs\" target=\"_blank\" rel=\"noopener noreferrer\">CISOs<\/a> recognize its importance for early risk identification, competing priorities like new tools or reactive measures often overshadow it in budget discussions.<\/p>\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/digitrendz.blog\/z\/entity\/offensive-security\/\" class=\"acp-entity-link\" data-entity-id=\"27971\" data-entity-category=\"Organization\" title=\"Learn more about Offensive Security\" target=\"_blank\" rel=\"noopener noreferrer\">Offensive Security<\/a> released <strong><a href=\"https:\/\/digitrendz.blog\/z\/entity\/kali-linux\/\" class=\"acp-entity-link\" data-entity-id=\"27962\" data-entity-category=\"Technology\" title=\"Learn more about Kali Linux\" target=\"_blank\" rel=\"noopener noreferrer\">Kali Linux<\/a> 2025.2<\/strong>, packed with <strong>13 new tools<\/strong>, including <strong><a href=\"https:\/\/digitrendz.blog\/z\/entity\/bloodhound-ce\/\" class=\"acp-entity-link\" data-entity-id=\"27963\" data-entity-category=\"Technology\" title=\"Learn more about Bloodhound CE\" target=\"_blank\" rel=\"noopener noreferrer\">Bloodhound CE<\/a><\/strong> and <strong><a href=\"https:\/\/digitrendz.blog\/z\/entity\/carsenal\/\" class=\"acp-entity-link\" data-entity-id=\"27964\" data-entity-category=\"Technology\" title=\"Learn more about CARsenal\" target=\"_blank\" rel=\"noopener noreferrer\">CARsenal<\/a><\/strong>, reinforcing its position as a leading platform for penetration testing.<\/p>\n\n<p class=\"wp-block-paragraph\">In identity security, <strong><a href=\"https:\/\/digitrendz.blog\/z\/entity\/proofpoint\/\" class=\"acp-entity-link\" data-entity-id=\"26162\" data-entity-category=\"Organization\" title=\"Learn more about Proofpoint\" target=\"_blank\" rel=\"noopener noreferrer\">Proofpoint<\/a> researchers<\/strong> detected an ongoing <strong>Entra ID account takeover campaign<\/strong> leveraging the <strong><a href=\"https:\/\/digitrendz.blog\/z\/entity\/teamfiltration\/\" class=\"acp-entity-link\" data-entity-id=\"26157\" data-entity-category=\"Technology\" title=\"Learn more about TeamFiltration\" target=\"_blank\" rel=\"noopener noreferrer\">TeamFiltration<\/a> framework<\/strong> for brute-force attacks. Meanwhile, <strong><a href=\"https:\/\/digitrendz.blog\/z\/entity\/citizen-lab\/\" class=\"acp-entity-link\" data-entity-id=\"4892\" data-entity-category=\"Organization\" title=\"Learn more about Citizen Lab\" target=\"_blank\" rel=\"noopener noreferrer\">Citizen Lab<\/a><\/strong> exposed a <strong>zero-click iOS exploit (CVE-2025-43200)<\/strong> delivering <strong><a href=\"https:\/\/digitrendz.blog\/z\/entity\/graphite\/\" class=\"acp-entity-link\" data-entity-id=\"4907\" data-entity-category=\"Technology\" title=\"Learn more about Graphite\" target=\"_blank\" rel=\"noopener noreferrer\">Graphite<\/a> spyware<\/strong> to journalists\u2019 iPhones.<\/p>\n\n<p class=\"wp-block-paragraph\">The <strong>LockBit ransomware<\/strong> operation reportedly amassed <strong>$2.3 million in five months<\/strong>, with Chinese organizations among the most targeted, according to leaked affiliate panel data.<\/p>\n\n<p class=\"wp-block-paragraph\"><strong>ConnectWise<\/strong> initiated emergency <strong>code-signing certificate rotations<\/strong> for ScreenConnect, Automate, and RMM solutions, urging customers to update systems by <strong>June 13<\/strong> to avoid disruptions.<\/p>\n\n<p class=\"wp-block-paragraph\">The <strong>EU launched DNS4EU<\/strong>, a <strong>privacy-focused DNS resolution service<\/strong>, to bolster digital sovereignty. Meanwhile, <strong>INTERPOL\u2019s Operation Secure<\/strong> dismantled <strong>20,000 malicious IPs and domains<\/strong> linked to infostealer malware.<\/p>\n\n<p class=\"wp-block-paragraph\"><strong>AI adoption is surging<\/strong>, with <strong>86% of security teams<\/strong> increasing AI usage to counter AI-driven threats. However, <strong>84% of organizations<\/strong> now using AI in the cloud face new attack vectors, per <strong>Orca Security<\/strong>.<\/p>\n\n<p class=\"wp-block-paragraph\"><strong>API security remains a blind spot<\/strong>, with legacy tools failing to detect risks in thousands of repositories. <strong>StackHawk\u2019s CEO<\/strong> emphasized the need for <strong>pre-deployment API visibility<\/strong> to prevent breaches.<\/p>\n\n<p class=\"wp-block-paragraph\">A <strong>critical Roundcube flaw (CVE-2025-49113)<\/strong> is being actively exploited, with dark web sales of exploits signaling imminent attacks.<\/p>\n\n<p class=\"wp-block-paragraph\">For defenders, <strong>OWASP Nettacker<\/strong> offers an <strong>open-source network scanner<\/strong>, while <strong>fiddleitm<\/strong> helps detect malicious web traffic via <strong>mitmproxy<\/strong>.<\/p>\n\n<p class=\"wp-block-paragraph\"><strong>Cybersecurity hiring remains robust<\/strong>, with new roles emerging weekly. Additionally, <strong>CIS Hardened Images<\/strong> provide cloud security enhancements, particularly for public sector organizations.<\/p>\n\n<p class=\"wp-block-paragraph\">As threats evolve, the key takeaway is clear: <strong>more data isn\u2019t the solution, reducing noise and prioritizing actionable intelligence is critical for effective defense.<\/strong><\/p>\n\n<p class=\"wp-block-paragraph\"><em>(Source: <\/em><a href=\"https:\/\/www.helpnetsecurity.com\/2025\/06\/15\/week-in-review-microsoft-fixes-exploited-zero-day-mirai-botnets-target-unpatched-wazuh-servers\/\" target=\"_blank\" rel=\"noreferrer noopener\">HelpNet Security<\/a><em>)<\/em><\/p>\n\n<p class=\"wp-block-paragraph\"><\/p>","protected":false},"excerpt":{"rendered":"<p>Microsoft patched 66 security flaws, including a zero-day exploit (CVE-2025-33053), while Mirai botnets targeted unpatched Wazuh servers via a critical RCE flaw (CVE-2025-24016). Threat modeling is undervalued despite its importance, as competing priorities like new tools often overshadow it in b&#8230;<\/p>\n","protected":false},"author":1,"featured_media":16717,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_themeisle_gutenberg_block_has_review":false,"cybocfi_hide_featured_image":"","footnotes":""},"categories":[6579,3297,3327,3254],"tags":[12462,19722,15299,16329,19721],"entities":[7233,19746,19743,19744,19750,14296,3556,15108,16060,2311,15698,3563,1769,19742,14621,904,18399,19741,15699,19745,19003,16254,19749,18402,19747,14130,15109,19748,18398,19740],"class_list":["post-16718","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-bigtech-companies","category-cybersecurity","category-newswire","category-technology","tag-cybersecurity-threats","tag-microsoft-patch-tuesday","tag-mirai-botnet","tag-wazuh-vulnerability","tag-zero-day-exploit","entity-akamai","entity-automate","entity-bloodhound-ce","entity-carsenal","entity-cis-hardened-images","entity-cisos","entity-citizen-lab","entity-connectwise","entity-dns4eu","entity-eu","entity-fiddleitm","entity-graphite","entity-ios","entity-kali-linux","entity-lockbit","entity-microsoft","entity-microsoft-entra-id","entity-mirai","entity-mitmproxy","entity-offensive-security","entity-operation-secure","entity-orca-security","entity-owasp-nettacker","entity-proofpoint","entity-rmm","entity-roundcube","entity-screenconnect","entity-stackhawk","entity-teamfiltration","entity-wazuh"],"_links":{"self":[{"href":"https:\/\/digitrendz.blog\/z\/wp-json\/wp\/v2\/posts\/16718","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/digitrendz.blog\/z\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/digitrendz.blog\/z\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/digitrendz.blog\/z\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/digitrendz.blog\/z\/wp-json\/wp\/v2\/comments?post=16718"}],"version-history":[{"count":0,"href":"https:\/\/digitrendz.blog\/z\/wp-json\/wp\/v2\/posts\/16718\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/digitrendz.blog\/z\/wp-json\/wp\/v2\/media\/16717"}],"wp:attachment":[{"href":"https:\/\/digitrendz.blog\/z\/wp-json\/wp\/v2\/media?parent=16718"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/digitrendz.blog\/z\/wp-json\/wp\/v2\/categories?post=16718"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/digitrendz.blog\/z\/wp-json\/wp\/v2\/tags?post=16718"},{"taxonomy":"entity","embeddable":true,"href":"https:\/\/digitrendz.blog\/z\/wp-json\/wp\/v2\/entities?post=16718"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}