Medical technology giant Stryker is restoring systems after a cyberattack that remotely wiped thousands of employee devices and caused widespread operational disruption. The incident, linked by researchers to pro-Iran actors amid rising geopolitical tensions, underscores how quickly destructive playbooks can pivot from espionage to mass device impact across healthcare supply chains.
Source: TechCrunch Security
Critical telnetd flaw allows unauthenticated root RCE (CVE-2026-32746)
A newly disclosed vulnerability in the GNU InetUtils telnet daemon enables remote code execution as root over port 23 with no authentication required. With a CVSS score of 9.8 and telnet still present on some legacy Linux and embedded systems, defenders should immediately disable telnetd, restrict access, and monitor for inbound Telnet traffic while awaiting vendor guidance.
Source: The Hacker News
Ubuntu Desktop privilege escalation to root affects default installs (CVE-2026-3888)
A high-severity bug in Ubuntu Desktop 24.04 and later can let a local, unprivileged user escalate privileges to full root via a systemd cleanup timing issue. Organizations should prioritize patching, tighten local account controls on shared machines, and monitor for anomalous privilege changes until updates are fully deployed.
Source: The Hacker News
AI sandbox escapes: DNS-based data exfiltration hits Amazon Bedrock and more
Researchers showed multiple AI code execution environments—including Amazon Bedrock’s sandbox—permit outbound DNS queries that can be abused to exfiltrate sensitive data and, in some cases, enable interactive shells. The findings highlight that “safe” AI sandboxes still need strict egress controls, DNS monitoring, and network isolation to prevent covert data leaks and runtime abuse.
Source: The Hacker News
EU sanctions Chinese and Iranian actors over major cyberattacks
The EU Council imposed asset freezes, travel bans, and funding prohibitions on companies in China and Iran and two individuals tied to campaigns impacting member states and partners, including a China-based firm linked to hacking 65,000 devices. The move expands the EU’s cyber sanctions regime and signals heightened consequences for cross-border operations against critical infrastructure.
Source: Help Net Security
UK Companies House flaw exposed data for millions of firms, enabled record tampering
Companies House confirmed a WebFiling vulnerability could have allowed logged-in users to access sensitive company information and alter official records before the service was taken offline for fixes. Given the registry’s centrality to KYC and anti-fraud checks, organizations should validate their company records and watch for suspicious changes that could aid business email compromise or shell-company fraud.
Source: SecurityWeek
Ransomware adopts “ClickFix” social engineering to bypass controls
The LeakNet operation is leveraging “ClickFix” lures delivered via compromised websites to trick users into manually executing attacker-supplied commands, deploying a Deno in-memory loader to evade traditional defenses. The trend shows social engineering converging with living-off-the-land techniques—security teams should block script execution from user-writable paths, flag suspicious command invocations, and harden browser-to-shell handoffs.
Source: The Hacker News
You May Also Be Interested In...
Tech giants fund $12.5M to bolster open-source security via Linux Foundation
RondoDox botnet now targets 174 vulnerabilities, peaking at 15k exploits/day
Japan authorizes ‘proactive cyber-defense’ operations starting Oct 1