Tuesday Morning Threat Report: Oct 14, 2025
Google’s AI Agent fixes 72 vulnerabilities in open-source projects and Cl0p hacks dozens of organizations through an Oracle vulnerability
Tuesday Morning Threat Report: Oct 14, 2025
Where the news is always bad, but the analysis is always good.

Image by Markus Spiske on Pixabay
Good morning everybody! Happy Tuesday!
Google’s AI Agent fixes 72 vulnerabilities in open-source projects and Cl0p hacks dozens of organizations through an Oracle vulnerability. Let’s dive in!
Top Stories:
This week’s biggest headlines. Analysis section below.
**Google DeepMind Unveils AI Agent to Fix Vulnerable Code**: DeepMind, Google’s AI research team, has created a new AI agent called “CodeMender.” CodeMender proactively finds and fixes vulnerabilities, and has already pushed 72 patches to open-source projects.
**OpenAI Bans ChatGPT Accounts Linked to State-Sponsored Hackers**: OpenAI announced it had banned multiple ChatGPT accounts tied to Chinese and North Korean state-sponsored hacking groups, which were using AI to aid in creating malware and phishing emails.
**Germany to Oppose EU’s Proposed “Chat Control” Regulation**: Germany has pledged to oppose the EU’s proposed “Chat Control” legislation, which would require messaging apps like WhatsApp and Signal to monitor users’ messages for illegal content.
**FBI Seizes BreachForums Site Used for Salesforce Data Leaks**: The FBI, working with French authorities, seized a BreachForums domain used by Scattered Lapsus$ Hunters, the hacking group that breached hundreds of companies’ Salesforce instances via the Salesloft Drift vulnerability.
**Two Teenagers Arrested for Hacking London’s Kido Nursery**: U.K. police report arresting two 17-year-olds in Hertfordshire for hacking the Kido Nursery, posting images of children on the dark web, and attempting to blackmail the nursery by threatening to release more photos.
**Employee HR Accounts Hacked to Steal Salary Payments**: Microsoft is warning that a hacking group is targeting organizations’ HR platforms, such as Workday, to compromise employee accounts and redirect salary payments to accounts they control.
**Jeep Software Update Forces Vehicles into Limp Mode While Driving**: An over-the-air (OTA) update for Jeep’s UConnect infotainment system caused vehicles to enter “limp mode,” trigger warning lights, and become stuck in drive.
**70K Government IDs Exposed in Discord Data Breach**: Discord experienced a data breach through 5CA, a third-party customer service provider. The breach exposed images of 70,000 customers’ government IDs that had been uploaded for age verification.
My Takeaways
Analysis based on this week’s news and my experience in the industry. More headlines below in the Lower Echelon.
The Wrong Debate: Discord’s leak of 70,000 government identifiers, including many images of users who took selfies next to their ID for age verification, has sparked a debate, with opponents of age verification laws pointing to it as evidence of the risks of age-gated internet content regulation. Unfortunately, that argument misses the point and misframes an important discussion.
There are numerous services, including Yoti and OnAge, that provide online age verification without storing images or biometric data. If Discord had used a service like this, it could have verified users’ ages without putting government IDs at risk in a data breach.
Intentionally or unintentionally, opponents of age verification laws often frame a false dichotomy: “Do you want privacy and security, or do you want to enable government overreach and jeopardize privacy through age verification?” The truth is, society doesn’t have to choose between these extremes. Solutions exist that allow age verification while protecting privacy.
Given the many dark corners of the internet and companies that profit from them, I support age verification laws requiring adult sites to prevent children under a societally agreed-upon age from accessing them. Also, I think supporters of these laws have an obligation to call out false dichotomies when they appear, and regulators have an obligation to design age verification laws to maximize privacy. Privacy maximization requirements should include bans on storing biometrics and rules against tracking which websites the age-verified individual went to.
The Lower Echelon:
Interesting cybersecurity news that didn’t quite make the cut to be a top story.
**Cl0p Hacks Dozens of Companies Through Oracle Vulnerability**: Google’s Threat Intelligence Group reports that it believes the hacking group Cl0p exploited a vulnerability in Oracle’s E-Business Suite to breach dozens of organizations.
**NIST Drops Recommendation for Special Characters in Passwords**: After years of research and discussion, the NIST is finalizing its password policy recommendations. They advise using long passwords but recommend against frequent mandatory changes and the use of special character requirements.
**5M Qantas Customers’ Records Leaked Online**: Australia’s largest airline, Qantas, experienced a data breach affecting 5 million customers. After the company refused to pay the ransom, the stolen data, including names and birth dates, was released on the dark web.
**Shuyal Infostealing Malware Targets 19 Different Browsers**: Shuyal Stealer is malware that can exfiltrate data from 19 browser types, including Chrome, Edge, Tor, and Brave, and disables Windows Task Manager so victims are less likely to notice it running.
**GitHub Copilot Vulnerability Leaks Code from Private Repositories**: A researcher from Legit Security revealed a vulnerability in GitHub Copilot’s chat feature, called “CamoLeak,” which can be exploited to trick the AI into exfiltrating code from private repositories through malicious prompts.
**Open-Source Forensics Tool Used in LockBit Hacks**: The hacking group Storm-2603 is using Velociraptor, an open-source digital forensics tool, in cyberattacks by installing an outdated version on victims’ devices and exploiting it to gain elevated privileges.
**Severe Figma MCP Vulnerability Enables Hackers to Execute Code**: A vulnerability in Figma’s Model Context Protocol (MCP) server allows attackers to execute code remotely. It arises from the server’s failure to properly sanitize user input.
**60K Redis Servers at Risk from Critical Vulnerability**: Redis, an open-source in-memory database known for speed, has a newly discovered vulnerability rated 10/10 in severity. The flaw affects 60,000 Redis servers and can be exploited without authentication.
On the right side of this page, you can follow and subscribe to receive this newsletter to your inbox weekly (no Medium account needed, just sign in with Google)!
Thanks for reading! See everyone next week!
메타데이터
- post_id
- 4d0e1984cd3e
- slug
- tuesday-morning-threat-report-oct-14-2025-4d0e1984cd3e
- url
- https://medium.com/@cyber_securiti/tuesday-morning-threat-report-oct-14-2025-4d0e1984cd3e
- canonical_url
- https://medium.com/@cyber_securiti/tuesday-morning-threat-report-oct-14-2025-4d0e1984cd3e
- author_url
- https://medium.com/@cyber_securiti
- status
- ok
- fetched_at
- 2026-07-13 13:12:13