Threat Intelligence

20 October 2025: Threat Intelligence Brief

Threat Intelligence Brief

If you read nothing else

Check F5 BIG-IP management interfaces and any Adobe AEM Forms server first. CISA added both to its catalog during the week of October 13 to 20, 2025.

Six items from the week of October 13 to 20, 2025, each with its source.

1. F5 BIG-IP nation-state breach and CISA emergency directive

F5 disclosed on October 15, 2025 a nation-state intrusion that it first learned of on August 9, and CISA ordered federal agencies to apply F5 fixes by October 22. Shadowserver tracked 266,978 IP addresses with an F5 BIG-IP fingerprint, a count of reachable devices, not confirmed vulnerable ones. Source: The Record. Source: BleepingComputer.

What this means for you: an F5 device with a management page on the internet is the first thing to check.

Do this: find every BIG-IP device you run and confirm none of its management interfaces is reachable from the internet.

2. Adobe Experience Manager Forms flaw added to CISA's catalog

CISA added CVE-2025-54253, an Adobe Experience Manager Forms flaw on JEE, to its Known Exploited Vulnerabilities catalog on October 15, 2025, with a November 5 deadline for federal agencies. Help Net Security reports that unauthenticated attackers can run expressions the Struts framework evaluates, which can lead to remote code execution. Source: Help Net Security.

What this means for you: a public-facing AEM Forms server can be attacked without a login, so treat it as urgent.

Do this: confirm whether you run AEM Forms, and if you do, get the vendor's current patch in place before anything else.

3. October Patch Tuesday fixes 172 flaws, six zero-days

Microsoft's October 14, 2025 update fixed 172 flaws, including six zero-days. Three of those zero-days were exploited in attacks, and three were publicly disclosed. Source: BleepingComputer. CISA's catalog lists CVE-2025-24990 as added October 14, 2025.

What this means for you: every Windows workstation and server in your environment was in scope, so the three exploited flaws matter most.

Do this: confirm the October Windows updates are installed on every machine, and list any that are behind.

4. Prosper breach: 17.6 million people

Have I Been Pwned added a Prosper dataset on October 16, 2025 covering 17.6 million people. The data includes Social Security numbers. Prosper had acknowledged the breach on September 18, 2025. Source: CyberInsider.

What this means for you: exposed Social Security numbers stay useful to criminals for years, so treat this as a long-term identity risk.

Do this: if any of your staff had a Prosper account, tell them to check their credit reports and turn on account alerts.

5. SimonMed Imaging breach: over 1.2 million patients

SimonMed Imaging disclosed that unauthorized access between January 21 and February 5, 2025 affected over 1.2 million individuals. Source: Security Affairs.

What this means for you: a single vendor breach can expose records you never stored yourself.

Do this: list the vendors that hold personal or health information for your staff or clients, and ask each one for its breach history.

6. Microsoft revokes over 200 certificates used to sign fake Teams installers

Microsoft revoked more than 200 code-signing certificates used to sign malicious Teams installers, and announced the action on October 16, 2025. Source: BleepingComputer.

What this means for you: an installer with a valid-looking signature can still be malicious.

Do this: install Teams only from your managed software catalog.

Not sure where you stand? Cyber Grants Alliance offers in-kind CMMC Level 1 and CMMC Level 2 gap assessment grants, at no cost to you. See every program on Grant Programs.

Concerned about your cybersecurity posture?

CGA offers grants to help defense contractors assess and improve their compliance with CMMC and NIST SP 800-171.