Microsoft’s latest Patch Tuesday addresses roughly 60 vulnerabilities, including six zero‑days already exploited in the wild across Windows, Office components, and core services. High‑impact issues include security feature bypasses in Windows Shell, MSHTML, and Word, plus local privilege escalations in Desktop Window Manager and Remote Desktop Services. Security teams should prioritize rapid deployment and monitor for post‑patch exploitation attempts on internet‑facing and high‑value endpoints.
Source: SecurityWeek
Singapore telcos breached in China‑linked UNC3886 cyber‑espionage campaign
Singapore’s four major telecom providers faced a coordinated intrusion by UNC3886, prompting “Operation Cyber Guardian” to limit the actor’s movement and harden networks. Authorities say no services were disrupted and no customer data was accessed, but the operation underscores persistent, stealthy targeting of core communications infrastructure.
Source: Help Net Security
Ivanti EPMM zero‑days exploited against Dutch government bodies
Dutch authorities confirmed that attackers exploited recently disclosed Ivanti Endpoint Manager Mobile (EPMM) flaws to breach the Data Protection Authority and the Council for the Judiciary, exposing employee contact data. The incidents highlight rapid weaponization of EPMM vulnerabilities and the urgency of patching or isolating affected devices.
Source: The Hacker News
New SSHStalker botnet hijacks 7,000 Linux systems using IRC C2 and legacy exploits
Researchers detail SSHStalker, a Linux botnet estimated to have compromised 7,000 hosts by chaining mass scanning, old kernel exploits, and IRC‑based command‑and‑control. The campaign blends log tampering, rootkit‑class tooling, and rapid propagation—reminding defenders that unpatched legacy weaknesses remain a high‑yield target at scale.
Source: SecurityWeek
Unpatched SolarWinds Web Help Desk instances under active attack
Internet‑exposed SolarWinds Web Help Desk (WHD) systems are being actively targeted for initial access, with intruders deploying legitimate remote access and DFIR tools, using living‑off‑the‑land techniques, and setting up reverse SSH shells to exfiltrate data. Organizations should urgently remediate WHD vulnerabilities and audit for silent persistence.
Source: Help Net Security
Critical pre‑auth RCE patched in BeyondTrust Remote Support and PRA
BeyondTrust fixed a critical vulnerability that allows unauthenticated remote code execution via crafted requests on Remote Support (RS) and Privileged Remote Access (PRA). Given the privileged nature of these tools and their exposure in many environments, immediate patching and review of access logs are strongly advised.
Source: SecurityWeek
Google–Intel audit flags severe Intel TDX flaw enabling full compromise
A joint Google–Intel security review uncovered dozens of issues, including a severe vulnerability in Intel’s Trust Domain Extensions (TDX) that could allow full compromise of protected environments. The findings raise important questions for confidential computing users around threat models, update hygiene, and cloud platform readiness.
Source: SecurityWeek
You May Also Be Interested In...
Trojanized 7‑Zip downloads turn home computers into proxy nodes
New threat actor, UAT‑9221, leverages VoidLink framework in campaigns
CISA adds six actively exploited Microsoft zero‑days to KEV list