View Ridge Security
Back to Cyber HoseActive Exploits & Incidents

Lantronix serial-to-IP converter flaw exploited in OT attacks

🚨 ACTIVE EXPLOITS & INCIDENTS

  • Lantronix Serial-to-IP Converter Flaw (CVE-2025-67038) Actively Exploited — SecurityWeek Following an April disclosure via the BRIDGE:BREAK research project, attackers are exploiting CVE-2025-67038 in Lantronix devices used in OT environments. This vulnerability enables remote code execution and has been observed in active campaigns targeting industrial networks. Immediate patching is advised.
  • Gaslight macOS Malware Uses Prompt Injection to Evade AI Analysis — The Hacker News A newly discovered Rust-based macOS implant embeds prompt injection payloads designed to confuse AI-driven malware analysis tools, causing them to abort or refuse analysis. This novel evasion technique complicates detection and forensic efforts, signaling a new wave of AI-targeted malware.
  • Cal Water Investigates Iranian Hack Group Handala Claims — SecurityWeek Mandiant assisted Cal Water in investigating claims by Iranian threat actor Handala about disrupting water supply OT systems. No evidence of OT compromise was found, but the incident underscores ongoing targeting of critical infrastructure by nation-state actors.

🕵️ THREAT RESEARCH & DEEP DIVES

  • Research: Prompt Injection Attacks Exploit LLM Role Confusion — Schneier on Security New academic work reveals that LLMs’ reliance on role tags as a security boundary is fundamentally flawed. Attackers exploit the continuous nature of role boundaries to subtly shift model states with innocuous text, making prompt injection a persistent threat without genuine role perception in LLMs.
  • COM Usage by Windows Threats: A Technical Overview — Cisco Talos This deep dive explains how threat actors abuse Windows Component Object Model (COM) technology—originally designed for legitimate inter-process communication—to evade detection, execute code, and persist. Understanding COM abuse is critical for detecting sophisticated Windows malware.
  • Surviving the Mythos Era: The Case for Network Detection and Response (NDR) — The Hacker News Richard Bejtlich discusses the limitations of alert-based triage and the need for context-rich NDR solutions to answer fundamental incident response questions. This approach is vital as attackers increasingly blend into normal telemetry and workflows.

📋 VENDOR BULLETINS & ADVISORIES

💼 INDUSTRY NEWS, M&A & DEALS

📰 LESSER-KNOWN / UNDER-REPORTED

Need help assessing your exposure?

Start with the free Posture Self-Check to see where you stand against the current threat landscape.

Free Posture Self-Check