San Mateo, CA, November 24, 2025 — Stories, events, and developments that impacted the cybersecurity landscape last week, including emerging threats, policy changes, and industry responses.
FCC drops telecom security rules
The Federal Communications Commission voted along party lines Thursday to repeal minimum cybersecurity requirements for U.S. phone and internet providers, undoing rules adopted under the Biden administration. Republican commissioners Brendan Carr and Olivia Trusty backed the rollback, arguing the rules were overly prescriptive. In contrast, Democratic commissioner Anna Gomez dissented, calling them the “only meaningful effort” the FCC had put in place since the China-backed Salt Typhoon hacker group infiltrated over 200 U.S. telecoms. “Handshake agreements without teeth will not stop state-sponsored hackers in their quest to infiltrate our networks,” said Gomez. “They won’t prevent the next breach. They do not ensure that the weakest link in the chain is strengthened. If voluntary cooperation were enough, we would not be sitting here today in the wake of Salt Typhoon.” The telecommunications trade group NCTA supported the repeal, calling the regulations counterproductive. Read more.
Salesforce data exposed via Gainsight
Salesforce said it is investigating a breach affecting “certain customers’ Salesforce data,” tracing the intrusion to Gainsight-published applications that customers installed and managed themselves. Gainsight acknowledged only a “Salesforce connection issue” as its internal probe continued. ShinyHunters claimed responsibility for the breach and threatened to publish stolen data if Salesforce does not negotiate. The incident mirrors August’s Salesloft breach, where attackers accessed customers’ connected Salesforce environments and stole sensitive tokens from firms including Allianz Life, Cloudflare, Google, Qantas, and TransUnion. Gainsight had already been named in that wave, raising questions about whether this new activity stems from the earlier compromise. Read more.
New C2 abuses browser notifications
A new C2 framework called Matrix Push is letting attackers weaponize native browser notifications with almost no effort, turning legitimate alerts into phishing lures. BlackFog researchers say the tool offers templates mimicking PayPal, MetaMask, Cloudflare, TikTok, and Netflix, then tracks victims’ IPs, locations, browsers, OS types, wallet activity, and real-time status to time attacks for maximum engagement. Once users grant notification permission to a site that has been compromised, it then “registers a service worker, creates a Push API subscription, and sends that data back to the Matrix Push command-and-control (C2) tool. And because these APIs and processes are standard across all major browsers, Matrix Push works equally well no matter what browser or operating system (OS) the victim connects from.” Sold via tiered subscriptions, Matrix Push is positioned for broad financial cybercrime campaigns. Read more.
NSO fights WhatsApp injunction
NSO Group asked the court to pause the permanent injunction blocking it from targeting WhatsApp while it appeals, arguing that “the deletion and destruction of computer code and technologies cannot be undone or remedied by money damages — once these are gone, they are gone.” The company said the deletion of code that allows it to access WhatsApp would bar it from developing or selling tools for “authorized government investigations,” harming U.S. law-enforcement capabilities and leaving competitors unaffected. NSO also claimed the injunction conflicts with the Computer Fraud and Abuse Act’s exemption for U.S. investigative and intelligence activity and argued a stay is in the public interest because Pegasus aids counterterrorism. The company warned the order would prevent agencies like the FBI from licensing Pegasus in the future. Read more.
SonicWall flaw enables firewall crash
SonicWall warned administrators to immediately patch CVE-2025-40601, a high-severity stack-based buffer overflow in the SonicOS SSLVPN service that allows remote, unauthenticated attackers to crash Gen7 and Gen8 firewalls. “SonicWall PSIRT is not aware of active exploitation in the wild,” said the company. “No reports of a PoC have been made public and malicious use of this vulnerability has not been reported to SonicWall.” However, SonicWall stressed that vulnerable appliances can be taken offline with a simple DoS request. Fixed firmware is available for Gen7 and Gen8 hardware and virtual firewalls, while Gen6 devices and SMA 100/1000 products are unaffected. SonicWall also patched two serious flaws in its Email Security appliances that enabled persistent code execution and data access, urging immediate upgrades. The alerts follow recent breaches involving stolen SSLVPN credentials and rootkit infections on SMA devices. Read more.
WhatsApp flaw exposed 3.5B numbers
WhatsApp’s contact discovery system contained a flaw that allowed researchers to confirm 3.5 billion active mobile numbers on the platform, a scale enabled by abusing its enumeration mechanism without effective rate limiting. The team from the University of Vienna and SBA Research said this exposed public keys, timestamps, profile photos, and About text, which allowed them to infer operating systems, account age, and linked devices. “Knowing whether a specific mobile phone number is linked to a messaging app is highly sensitive,” the researchers warned, especially in regions where WhatsApp use carries risks. Meta thanked the team but responded slowly, raising concerns about its handling of security issues. The flaw echoes past leaks of WhatsApp numbers and shows metadata remains exposed. Read more.
Fortinet disclosure delay sparks attacks
Federal authorities and researchers warned Friday that a critically exploited Fortinet FortiWeb vulnerability has been under active attack for weeks, with many organizations blindsided after the vendor delayed disclosure of the flaw. Fortinet quietly patched CVE-2025-64446 on October 28, but didn’t assign a CVE or acknowledge the flaw until 17 days later. By that point, unpatched customers faced widespread exploitation of a path-traversal bug that allows full device takeover. CISA added the flaw to its KEV catalog and ordered agencies to patch within seven days. “Fortinet’s silent patching of the vulnerability — intentional or not — likely led many users not to apply the patch that actually fixed the vulnerability,” said Ben Harris, founder and CEO at watchTowr. “FortiWeb customers weren’t told about the critical, immediate risk of not applying these patches. Had they known, they would have likely updated right away. Now, anyone who didn’t patch is likely compromised.” Read more.
JPMorgan Chase launches major anti-scam push
JPMorgan Chase launched its largest fraud and scam-prevention initiative, pairing nationwide consumer education with new security measures to reduce attacks. The bank is hosting more than 20 free workshops during International Fraud Awareness Week, working with law enforcement and community groups to teach people how to spot scams. Chase said it invests billions each year in fraud prevention and blocked $12 billion in attempted scams last year. New and existing tools include in-app scam warnings, payment interruption for suspicious transactions, a trusted contact option, a real-time Scam Interruption team, and dedicated support for older customers through its partnership with AARP. “Protecting our customers from fraud and scams requires a united front — banks, technology companies, social media platforms and law enforcement all have a role to play,” said Jennifer Roberts, CEO of Chase Consumer Banking. Read more.
Android to penalize battery hog apps
Google will begin penalizing Android apps that drain batteries through excessive background wake locks by introducing a new Android Vitals metric that flags apps exceeding a bad behavior threshold and may limit their visibility across the ecosystem. Developers have until March 1, 2026, to reduce non-exempt partial wake locks, which Google measures as the time an app keeps a device awake while the screen is off. A single user session that exceeds 2 hours of wake-lock time within 24 hours counts as excessive, and any app with more than 5% of sessions exceeding that limit will be flagged. Although the system targets inefficient or abusive resource use, Google said it is not designed to detect spyware or malware. Read more.
JLR attack becomes costliest in U.K.
Jaguar Land Rover reported steep Q2 losses after a September ransomware attack shut down production for weeks, pushing revenue down 24 percent year over year and turning last year’s profit into a £485 million loss. The incident alone generated £196 million in cyber-related costs, covering response work, legal activity, notifications, and other fallout. The broader economic impact reached an estimated £1.9 billion, as more than 5,000 organizations felt the supply chain shock. The attack was claimed by the Scattered Lapsus$ Hunters, a group linked to compromises at other major U.K. companies. CEO Adrian Mardell said JLR “made strong progress in recovering its operations safely and at pace” and confirmed production has fully resumed. Read more.
More cybersecurity news
- Last week’s news
- More cybersecurity news
- All articles sponsored by NetworkTigers
About NetworkTigers

NetworkTigers is the leader in the secondary market for Grade A, seller-refurbished networking equipment. Founded in January 1996 as Andover Consulting Group, the company originally built and re-architected data centers for Fortune 500 firms. Today, NetworkTigers provides consulting and network equipment to global government agencies, Fortune 2000 companies, and healthcare companies. Visit www.networktigers.com
