Critical Security Update: October 10, 2025 (Android Devices, Oracle, SonicWall)
Critical Security Update
Android Devices, Oracle, SonicWall
Risk 1: Low
Issue: A new spyware application on Android-based devices allows their code to mimic TikTok, YouTube, WhatsApp, as well as multiple Google Apps. These replicas appear to be legitimate but ultimately infect the host machine with spyware that collects on-machine data, on-screen data, and passwords; the data is then leveraged to gain deeper access to the machine or is transferred back to a host for collection.
Resolution: Android should be extra cautious when installing new apps, particularly focusing on the publisher and only download apps directly from the source. Using links provided to download an app is extremely risky.
Risk 2: High
Issue: SonicWall, a hardware firewall manufacturer, has reported a breach on their cloud backup environment. If you use a SonicWall device and rely upon their cloud backup solution to backup your configuration and data, you may have been put at risk for your credentials being shared.
Resolution: Any SonicWall cloud backup users should immediately change their passwords, enable multi-factor authentication, and (if possible) change their IP address to ensure their the released information is not able to be utilized.
Keep in mind, if you recycle passwords, then your password may have just be released and you should start the process to change all systems that use the same password.
Risk 3: Medium
Issue: Oracle has a zero-day (known vulnerability) that is currently being exploited in their E-Business Suite. At the moment, Oracle is fully working on a fix. A fix has been released, but multiple businesses are expressing challenges updating to the fix.
Resolution: E-Business Suite users should apply added caution until a full correction can be applied. Please consult your IT professional for more exact next steps as this is still an on-going concern.
Announced Data Breaches
SonicWall
Qilin
Red Hat
LinkedIn (third-party API scraper)
Upcoming Live CE
Brad will be presenting to the New Jersey Chapter of NATP on October 21 the topic AI, specifically in Simplifying Tax Topics for Clients and Making Tax Research for Efficient.
Financial Guardians is a proud member of InCite, the recently launched online community exclusively for tax professionals, bookkeepers, and accountants. InCite members receive a 30% discount.
Join today at www.incite.tax.
Financial Guardians has partnered with the California Society of Tax Consultants to provide a 30% access discount as well as many other offers. More info can be found at www.cstcsociety.org






