Microsoft shipped fixes for more than 170 vulnerabilities across Windows, Office, and other products, including at least three flaws already under active exploitation. The update coincides with the final month of security updates for Windows 10; organizations that can’t migrate immediately should enroll affected PCs in Microsoft’s Extended Security Updates (ESU) program and fast-track patching of zero-days and critical bugs. Prioritize testing for server components and remote-code-execution paths that could be chained for domain compromise.
Source: KrebsOnSecurity
Oracle E-Business Suite zero-day exploited; Harvard confirmed victim
Oracle issued an emergency fix for CVE-2025-61884 affecting E-Business Suite after attackers, linked to the Cl0p group, abused the flaw in the wild. Harvard University is the first confirmed victim, with over 1 TB of data posted to a leak site—underscoring the urgency to apply Oracle’s security alert, rotate credentials, and scrutinize EBS integrations and logs for signs of compromise.
Source: SecurityWeek
“Pixnapping” attack can steal Android 2FA codes without permissions
Researchers detailed a side-channel attack on Google and Samsung Android devices that lets a malicious app infer screen content—such as 2FA codes and Google Maps timelines—pixel by pixel, without requesting sensitive permissions. Google has released a partial patch with more fixes pending; defenders should tighten app vetting, advise users to avoid sideloading, and favor hardware-based or app-based OTP generators with notification hygiene.
Source: SecurityWeek
Suspected China-linked hackers breach Russian tech firm in rare supply-chain foray
Symantec reported a rare intrusion into a Russian technology company by a suspected China-nexus group, with access to software build and code-repository systems between January and May 2025. The activity suggests a potential software supply-chain attack aimed at downstream customers, reinforcing the need for hardened CI/CD pipelines, code-signing key protection, and build environment segmentation.
Source: The Record by Recorded Future
US seizes $15B in Bitcoin tied to massive forced-labor scam; sanctions issued
US authorities seized approximately $15 billion in Bitcoin and sanctioned Cambodia’s Prince Group and 146 related entities over a vast fraud and human trafficking operation. The crackdown highlights the industrial scale of scam operations and the role of financial infrastructure; enterprises should strengthen brand abuse monitoring, KYC/AML controls, and takedown workflows to protect customers from imposter schemes.
Source: The Record by Recorded Future
100K-node botnet pelts US RDP services in large-scale campaign
GreyNoise observed a botnet of more than 100,000 IPs from multiple countries attempting to brute-force and exploit Remote Desktop Protocol services in the US since October 8. Organizations should enforce MFA on RDP, disable or gate RDP behind VPN/ZTNA, apply account lockouts and geo-blocking, and monitor for credential-stuffing and anomalous login patterns.
Source: Security Affairs
Critical SAP NetWeaver flaw (CVSS 10) enables takeover without login
SAP’s October updates include additional hardening for a maximum-severity insecure deserialization bug (CVE-2025-42944) in NetWeaver AS Java that can lead to arbitrary command execution. Given the prevalence of SAP in core business processes, teams should patch immediately, validate mitigations, restrict exposure of management interfaces, and monitor for deserialization exploitation patterns.
Source: The Hacker News
You May Also Be Interested In...
High-Severity Vulnerabilities Patched by Fortinet and Ivanti
Operation Zero Disco: Attackers Exploit Cisco SNMP Vulnerability to Deploy Rootkits
Qantas confirms cybercriminals released stolen customer data via Salesforce exploit