Pentesting Weekly Digest - September 27 - October 3, 2025
This week brought critical zero-days in GoAnywhere, a CISA emergency directive on Cisco, ransomware extortion tied to Oracle systems, and urgent VMware patches.
๐น GoAnywhere MFT Critical Zero-Day (CVE-2025-10035)
A deserialization flaw in the License Servlet is actively exploited; CVSS 10.0.
Patch versions: 7.8.4 or Sustain 7.6.3. Watch for logs containing SignedObject.getObject.
๐ TechRadar: Experts Warn GoAnywhere Zero-Day
๐น VMware / Broadcom Patches -Local Privilege Escalation (CVE-2025-41244)
A high-severity vulnerability in VMware Aria / Tools was patched after observed exploitation (by UNC5174).
๐ TechRadar: VMware Patches Exploited Zero-Day
๐น Oracle / Cl0p Extortion Campaign
Extortion emails to executives claiming data theft from Oracle E-Business Suite. Google / Mandiant are investigating.
๐ Reuters: Oracle Says Hackers Are Trying to Extort Its Customers
๐น CISA KEV Catalog Updates
On September 29, CISA added five CVEs to its Known Exploited Vulnerabilities list to push higher prioritization of patching.
๐ CISA: Adds Five Known Exploited Vulnerabilities to Catalog




