A suspected China‑nexus actor has been exploiting CVE-2026-22769 (CVSS 10.0) in Dell RecoverPoint for VMs since at least mid‑2024, deploying stealthy backdoors and pivoting into virtual infrastructure. Following coordinated advisories from Dell, Google/Mandiant, and others, U.S. federal agencies were ordered to patch by Saturday, underscoring the urgency for all defenders to remediate, isolate appliances, and hunt for persistence (e.g., web shells, anomalous admin accounts).
Source: Recorded Future News
Critical RCE in Grandstream GXP1600 VoIP phones enables silent call interception (CVE‑2026‑2329)
Rapid7 disclosed an unauthenticated stack buffer overflow in the web API of Grandstream GXP1600‑series desk phones that allows remote code execution as root. Attackers can reconfigure SIP settings to route calls via malicious proxies for transparent eavesdropping; admins should upgrade to firmware 1.0.7.81+, remove phones from direct internet exposure, and segment VoIP networks.
Source: Rapid7
125M‑install VS Code extensions patched for bugs enabling file theft and remote code execution
Researchers detailed critical flaws in four hugely popular Visual Studio Code extensions (Live Server, Code Runner, Markdown Preview Enhanced, Microsoft Live Preview) that could let attackers exfiltrate local files and execute code via crafted projects or content. Developers should update the affected extensions immediately, review workspace trust settings, and harden build systems to reduce IDE‑driven supply chain risk.
Source: The Hacker News
Keenadu Android backdoor found preinstalled on thousands of devices
A new Android malware family dubbed Keenadu has been discovered on numerous devices—sometimes preinstalled in firmware and also distributed via app stores—enabling ad fraud and broad device control. The findings highlight persistent mobile supply chain risks; enterprises should vet OEMs, enforce MDM controls, monitor for anomalous app behavior, and block sideloading where possible.
Source: SecurityWeek
Ivanti exploitation surges, with zero‑day activity traced back to July 2025
Security researchers report a spike in Ivanti device exploitation, including zero‑day attacks dating to mid‑2025, used to drop shells, conduct recon, and deliver malware. Organizations should prioritize patching, perform compromise assessments for long‑lived backdoors, and validate device configurations and access logs for signs of lateral movement.
Source: SecurityWeek
Microsoft says Office bug exposed customers’ confidential emails to Copilot AI
Microsoft confirmed a bug that allowed Copilot to read and summarize confidential emails, bypassing intended data protection policies. The incident underscores the need for rigorous AI governance and testing—review tenant isolation, app access scopes, DLP policies, and run pre‑production validations before connecting assistants to live mailboxes and files.
Source: TechCrunch
Predator spyware hits Angolan journalist, showing mercenary tools remain active despite sanctions
A report indicates Intellexa’s Predator spyware infected the phone of Angolan journalist Teixeira Cândido via a WhatsApp link in 2024, demonstrating ongoing abuse of commercial surveillanceware. High‑risk users should enable mobile lockdown protections, apply rapid OS updates, and use out‑of‑band channels to verify links and attachments.
Source: Recorded Future News
You May Also Be Interested In...
Notepad++ Fixes Hijacked Update Mechanism Used to Deliver Targeted Malware
Scammers exploit trust in Atlassian Jira to target organizations
German Rail Giant Deutsche Bahn Hit by Large-Scale DDoS Attack