Last week’s cybersecurity news included Apple releasing emergency security updates for two zero-day vulnerabilities, and a Windows NTLM hash disclosure vulnerability being exploited in attacks against institutions in Poland and Romania. Meanwhile, Hertz suffered a data breach affecting customers worldwide and cyberattacks against the energy sector are on the rise. Lastly, cybercriminal groups are now adopting corporate structures and the future of MITRE’s Common Vulnerabilities and Exposures program is uncertain due to funding issues.

400+ SAP NetWeaver Devices Vulnerable to 0-Day Attacks that Exploited in the Wild
Shadow Servers have identified 454 vulnerable SAP NetWeaver systems affected by a critical zero-day flaw, CVE-2025-31324, allowing unauthenticated file uploads and potential system compromise. Discovered