Cyber Threat Intelligence — 22 Sept. 2025

A verified summary of cyber events disclosed or reported within the past 48 hours (Sept. 20–22, 2025 ET).

European airport disruptions from third-party ransomware attack

Turla piggybacks Gamaredon compromises (Ukraine)

SonicWall cloud backup incident

Microsoft Entra ID token validation flaw patched (CVE-2025-55241)

macOS campaign delivers AMOS (Atomic) stealer

Fortra GoAnywhere MFT critical RCE (CVE-2025-10035)

Jaguar Land Rover cyberattack disrupts production

DPRK (Lazarus cluster) deploys BeaverTail and InvisibleFerret

MalTerminal — GPT-4-powered malware proof of concept

ShadowLeak prompt-injection issue resolved

  • Incident date (ET): N/A (research finding)
  • Disclosure (ET): Sept. 20, 2025 (public report); responsibly disclosed June 18, 2025; fixed early Aug. 2025
  • Summary: Radware detailed an indirect prompt-injection technique that could exfiltrate Gmail data via ChatGPT’s Deep Research agent; the issue has been addressed.
  • Source: https://www.thehackernews.com/2025/09/shadowleak-zero-click-flaw-leaks-gmail.html
Edward Kiledjian @ekiledjian