Hackers exploit SAP NetWeaver to deploy Linux Auto-Color malware.

Hackers exploit SAP NetWeaver to deploy Linux Auto-Color malware.

Security researchers have uncovered an advanced cyberattack campaign leveraging a critical vulnerability in SAP NetWeaver (CVE-2025-31324) to deploy a stealthy Linux backdoor known as Auto-Color. The campaign, which surfaced after a targeted attack on a US-based chemicals company in April 2025, highlights the growing threat landscape facing enterprise software platforms.
SAP releases 27 new security updates, including 6 that address critical vulnerabilities.

SAP releases 27 new security updates, including 6 that address critical vulnerabilities.

SAP announced the release of 27 new and four updated security notes as part of its July 2025 Security Patch Day on Tuesday, July 8, 2025. This comprehensive update addresses a range of vulnerabilities across SAP’s product portfolio, including six critical flaws that could have significant security implications for organizations worldwide.