CISA added a Windows SMB Client privilege escalation bug to its Known Exploited Vulnerabilities catalog, confirming in-the-wild attacks. The flaw can grant SYSTEM privileges and is being targeted months after Microsoft issued a fix in June. Organizations should patch immediately, restrict outbound SMB, and monitor for suspicious NTLM/SMB authentication attempts.
Source: Help Net Security
Envoy Air confirms breach tied to Oracle E‑Business Suite 0‑day exploited by Cl0p
Envoy Air, a subsidiary of American Airlines, confirmed a cyberattack linked to Cl0p’s exploitation of an Oracle EBS zero‑day (CVE‑2025‑61882). The incident underscores active targeting of enterprise ERP stacks and the urgency of rapidly applying Oracle’s emergency patches and limiting external exposure of EBS components.
Source: HackRead
VS Code supply-chain hit: ‘GlassWorm’ malware hides with invisible Unicode, blockchain infra
A supply-chain attack targeted Visual Studio Code extensions with malware dubbed GlassWorm, which uses invisible Unicode characters to obfuscate code and blockchain-based infrastructure to resist takedowns. Developer environments are in scope—review extension provenance, pin trusted versions, and enforce code signing and allowlisting for IDE plugins.
Source: SecurityWeek
Official Xubuntu site compromised to serve Windows malware instead of Linux distro
The Xubuntu website briefly delivered a “Safe-Download” ZIP containing a suspicious Windows executable in place of legitimate torrent links. This website compromise highlights the risk of hijacked download flows; users should verify checksums and only obtain ISOs from authenticated mirrors.
Source: Help Net Security
‘TARmageddon’: RCE flaw in async‑tar Rust library threatens downstream projects
Researchers disclosed a high-severity remote code execution vulnerability in the popular async‑tar Rust library and multiple forks, impacting a widely used archive component embedded in other projects. Teams should inventory Rust dependencies, update to patched versions, and review any tar handling paths exposed to untrusted input.
Source: CyberScoop
TP‑Link patches critical Omada gateway bugs enabling remote code execution
TP‑Link released fixes for four Omada gateway vulnerabilities, including two critical issues that could allow arbitrary code execution. Network edge devices remain high-value targets—apply firmware updates quickly, restrict management plane access, and monitor for anomalous device behavior.
Source: The Hacker News
Google: Russia‑linked COLDRIVER rapidly retools with three new malware families
Google’s threat intel team says COLDRIVER (aka Callisto) accelerated malware development after its LOSTKEYS toolset was exposed, rolling out three new families within months. The pace of iteration complicates detections—keep threat intel feeds current, tune behavioral controls, and hunt for evolving TTPs rather than static IOCs.
Source: The Hacker News
You May Also Be Interested In...
Reducing abuse of Microsoft 365 Exchange Online’s Direct Send (Cisco Talos)
Hackers earn $520,000 on Day 1 of Pwn2Own Ireland (SecurityWeek)