Threat Intelligence

6 October 2025: Threat Intelligence Brief

Threat Intelligence Brief

If you read nothing else

  • Patch Cisco IOS and IOS XE, Fortra GoAnywhere MFT, Sudo and Libraesva email gateways if you run them. CISA's catalog lists them as exploited.
  • Ask every vendor that holds your data what it would tell you after a breach, and how fast.
  • Treat any data-theft notice that arrives by email as a likely lure until the vendor confirms it by phone.

Six things from the week of September 29 to October 5, 2025. Each one says what happened, what it means for a small business or defense supplier, and one thing to do.

1. Clop sent extortion emails about Oracle E-Business Suite

Mandiant's Charles Carmakal said the Clop gang had been sending extortion emails to several victims since Monday, September 29. Clop had exploited an Oracle E-Business Suite flaw before Oracle issued a patch, and the flaw affects versions 12.2.3 through 12.2.14. Source: Help Net Security, October 6.

What this means for you: if you run Oracle E-Business Suite, expect extortion email as well as technical alerts.

Do this: ask your finance or ERP administrator to confirm, in writing, that every current Oracle security update is applied.

2. Asahi's ransomware attack shut factories in Japan

Japanese beverage maker Asahi Group Holdings confirmed a ransomware attack that forced it to shut down factories this week. The company, which employs 30,000 people, said traces suggest a potential unauthorized transfer of data, and it is still assessing what was involved. Source: BleepingComputer, October 3.

What this means for you: when central IT goes down, production can stop even if the plant floor is never touched.

Do this: write down how your team would take orders and ship product with the systems offline, and keep a paper copy of key customer and supplier contacts.

3. Red Hat confirmed a breach of its consulting GitLab

Red Hat said an unauthorized third party accessed and copied some data from a GitLab instance managed by its consulting group, and that it notified law enforcement. The Crimson Collective group claims to have taken about 28,000 repositories, including hundreds of Customer Engagement Reports. Red Hat has not confirmed those numbers. Source: The Register, October 3.

What this means for you: a consultant's own repositories can hold details of your systems, so that vendor's breach can become your exposure.

Do this: ask each outside IT or consulting firm where it stores documents about your systems, and whether it would notify you within a set number of days.

4. Motility's ransomware attack exposed data of 766,000 people

Motility Software Solutions, which provides software to more than 7,000 dealerships across automotive, marine, RV and heavy equipment retail, disclosed a ransomware attack. The attack occurred on August 19, and the exposed data includes names, birth dates, Social Security numbers and driver's license information for about 766,000 people. Source: Bitdefender.

What this means for you: a software vendor's breach can put your customers' Social Security and license numbers in the open, even if your own network was never hit.

Do this: list every vendor that stores customer Social Security or license numbers, and ask each one how it encrypts them and how fast it would notify you.

5. CISA added four flaws to its exploited list on September 29

CISA added Cisco IOS and IOS XE (CVE-2025-20352), Fortra GoAnywhere MFT (CVE-2025-10035), Sudo (CVE-2025-32463) and Libraesva Email Security Gateway (CVE-2025-59689) to its Known Exploited Vulnerabilities catalog. The catalog set October 20 as the patch deadline for federal agencies. Source: CISA KEV catalog; the dates are in the KEV feed.

What this means for you: these products sit at the edge of many networks, and federal deadlines are a fair benchmark for a small business too.

Do this: ask your IT provider to confirm, in writing, whether any Cisco, GoAnywhere, Sudo or Libraesva product in your environment is patched.

6. Medusa claims 834 GB was taken from Comcast

The Medusa ransomware group claimed on September 30 that it had stolen more than 834 GB of data from Comcast and demanded a ransom. Comcast had not confirmed or denied the incident. Source: THAICERT, September 30.

What this means for you: a gang's claim is only a claim until the company confirms it, so do not repeat it as fact.

Do this: when a large provider you use is named in a leak, ask it what it has confirmed and whether your account data is involved.

Not sure where you stand? Cyber Grants Alliance offers in-kind CMMC Level 1 and CMMC Level 2 gap assessment grants, at no cost to you, to show where your gaps are. See every program on Grant Programs.

Concerned about your cybersecurity posture?

CGA offers grants to help defense contractors assess and improve their compliance with CMMC and NIST SP 800-171.