Talk With an Expert

Internet Storm Center Tech Corner

SANS Internet Storm Center StormCast Tuesday, August 19, 2025

MFA Bombing; Cisco Firewall Management Vuln; F5 Access for Android Vuln

https://isc.sans.edu/podcastdetail/9576

Keeping an Eye on MFA Bombing Attacks

Attackers will attempt to use authentication fatigue by “bombing” users with MFA authentication requests. Rob is talking in this diary about how to investigate these attacks in a Microsoft ecosystem.

https://isc.sans.edu/diary/Keeping+an+Eye+on+MFABombing+Attacks/32208

Critical Cisco Secure Firewall Management Center Software RADIUS Remote Code Execution Vulnerability

An OS command injection vulnerability may be abused to gain access to the Cisco Secure Firewall Management Center software.

https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-fmc-radius-rce-TNBKf79

F5 Access for Android vulnerability

An attacker with a network position that allows them to intercept network traffic may be able to read and/or modify data in transit. The attacker would need to intercept vulnerable clients specifically, since other clients would detect the man-in-the-middle (MITM) attack.

https://my.f5.com/manage/s/article/K000152049 SANS Internet Storm Center StormCast Monday, August 18, 2025

5G Attack Framework; Plex Vulnerability; FortiWeb Exploit; Flowise Vuln

https://isc.sans.edu/podcastdetail/9574

SNI5GECT: Sniffing and Injecting 5G Traffic Without Rogue Base Stations

Researchers from the Singapore University of Technology and Design released a new framework, SNI5GECT, to passively sniff and inject traffic into 5G data streams, leading to DoS, downgrade and other attacks.

https://isc.sans.edu/diary/SNI5GECT+Sniffing+and+Injecting+5G+Traffic+Without+Rogue+Base+Stations/32202

Plex Vulnerability

Plex patched a vulnerability in the Plex Media Server. Make sure you have updated to at least 1.42.1.

https://forums.plex.tv/t/plex-media-server-security-update/928341

FortiWeb Exploit Public

A security researcher published details about the recent FortiWeb vulnerability, including demonstrating a PoC exploit.

https://www.bleepingcomputer.com/news/security/researcher-to-release-exploit-for-full-auth-bypass-on-fortiweb/

Flowise OS vulnerability

https://research.jfrog.com/vulnerabilities/flowise-os-command-remote-code-execution-jfsa-2025-001380578/

View Older Issues

Catch up on recent editions of NewsBites or browse our full archive of expert-curated cybersecurity news.

Browse Archive