A widespread Amazon Web Services disruption knocked major apps and platforms offline, underscoring the concentration risk of cloud dependencies. For several hours, users reported outages across consumer and enterprise services, reminding teams to revisit multi-region designs, failover testing, and third-party SLA contingencies.
Source: TheVerge
Zero-click attacks possible via Dolby decoder vulnerability on Android
A newly disclosed out-of-bounds write flaw in the Dolby decoder can be triggered during media processing on Android without user interaction. The bug raises the risk of RCE via crafted audio/video, making prompt OEM/OS patching and disabling auto-fetch of untrusted media critical interim mitigations.
Source: SecurityWeek
Xubuntu site compromised, serving malware via fake downloads
Attackers breached the Xubuntu website and directed users to malicious downloads masquerading as legitimate OS images. Linux users should re-verify SHA256 checksums/signatures and obtain ISOs only from trusted mirrors or official torrents until integrity is confirmed.
Source: CyberNews
ConnectWise Automate flaws allow fake updates (CVE-2025-11492, CVE-2025-11493)
Two high-impact vulnerabilities in ConnectWise Automate could enable adversaries to push fraudulent updates—an acute risk for MSPs and their downstream clients. Immediate patching is advised, alongside auditing update channels, code-signing validation, and EDR detections for lateral movement via RMM tooling.
Source: SOCRadar
China accuses NSA of multi-stage cyberattack on Beijing’s National Time Service Center
China’s Ministry of State Security alleged a premeditated, multi-stage intrusion using 42 cyber tools against the NTSC, escalating geopolitical tensions in cyberspace. While technical evidence has not been independently verified, defenders should anticipate retaliatory narratives, attribution disputes, and potential policy fallout impacting cross-border incident response and intel sharing.
Source: TheHackerNews
American Airlines subsidiary Envoy Air impacted by Oracle-related hack
Envoy Air confirmed that business information was stolen in a breach linked to a wider Oracle compromise. Aviation supply chain exposure continues to be a prime target; organizations should map third-party data flows, enforce least-privilege access, and require rapid compromise notifications in vendor contracts.
Source: SecurityWeek
Court orders NSO to stop hacking WhatsApp; damages reduced to $4M
A judge upheld injunctive relief restricting NSO Group from targeting WhatsApp users, but slashed punitive damages from $167 million to $4 million. The ruling reinforces legal constraints on commercial spyware while signaling courts’ willingness to narrow financial penalties.
Source: SecurityWeek
You May Also Be Interested In...
Data breach hits security company Verisure
Nodepass: Open-source TCP/UDP tunneling solution
Odido fined €1.5M for poor security