A security researcher disclosed three Microsoft Defender flaws—BlueHammer, RedSun, and UnDefend—that enable local privilege escalation and, in some cases, block signature updates or disable Defender entirely. Huntress reports all three techniques are being exploited in active attacks, with two still lacking patches. Enterprises should monitor for Defender tampering, restrict local admin rights, and apply Microsoft mitigations as they become available.
Source: Help Net Security
NVD pivots to selective CVE enrichment as vulnerability volume surges
NIST’s National Vulnerability Database will stop enriching every CVE and instead focus on a subset, including CISA KEV entries, software used by the federal government, and designated critical software. The shift reflects a massive rise in CVE submissions and will push security teams to rely more on KEV, vendor advisories, and commercial intel for prioritization. Plan for internal triage processes and tooling that don’t depend solely on NVD enrichment metadata.
Source: Flashpoint
CISA adds critical Apache ActiveMQ RCE to Known Exploited Vulnerabilities
CISA added CVE-2026-34197, a critical Apache ActiveMQ remote code execution flaw (CVSS 8.8), to its KEV catalog, signaling confirmed exploitation. Federal agencies face an accelerated remediation timeline, and enterprises should urgently patch affected brokers, review exposed management endpoints, and hunt for post-exploitation activity.
Source: Security Affairs
Global ‘PowerOFF’ crackdown seizes DDoS-for-hire platforms; four arrested
Authorities in more than 20 countries coordinated a new Operation PowerOFF action, arresting four suspects and disrupting cheap “booter” services that sold on-demand DDoS attacks. Investigators also obtained extensive user data, which may fuel follow-on actions against customers. Expect temporary disruption in the DDoS marketplace and watch for service rebrands.
Source: The Record
Ukraine confirms APT28 campaign abusing Roundcube zero-click mail exploit
Ukrainian authorities validated a suspected APT28 operation targeting prosecutors and anti‑corruption agencies via Roundcube webmail vulnerabilities that execute code when a victim merely opens an email. The tradecraft highlights continued exploitation of server-side webmail platforms for initial access. Roundcube users should patch urgently, disable remote content, and monitor for anomalous mailbox processes.
Source: The Record
New Mirai variant ‘Nexcorium’ hijacks TBK DVRs for DDoS
Fortinet tracked a multi-architecture Mirai offshoot dubbed Nexcorium that chains exploitation of TBK DVRs (CVE-2024-3721), persistence, and brute-force tactics into a single campaign, while also reusing older bugs like CVE-2017-17215. The botnet targets widely deployed, rarely updated video recorders to amass DDoS firepower. Segment and patch IoT, disable WAN management, and rotate default credentials.
Source: Fortinet
ZionSiphon malware tailored to water-treatment ICS environments
Researchers detailed ZionSiphon, malware configured to operate on systems tied to Israeli water treatment and desalination facilities. The discovery underscores persistent OT targeting and the risk of process manipulation. Operators should harden HMIs and controllers, restrict USB and removable media, and increase network monitoring between IT and OT.
Source: SecurityWeek
You May Also Be Interested In...
CISA resources ‘more limited than I would like’ amid DHS shutdownGitHub user attachments abused to spread novel infostealer
Ransomware continues to disrupt London healthcare nearly two years later