Microsoft shipped an out-of-band patch for CVE-2025-59287, a critical WSUS remote code execution bug (CVSS 9.8) that is already being exploited in the wild. Reported by MEOW and Markus Wulftange of CODE WHITE GmbH, the flaw puts patch management infrastructure at risk, potentially amplifying impact across managed endpoints. Organizations should urgently apply updates, lock down WSUS network exposure, and review server hardening and monitoring.
Source: Security Affairs
DDoS on Russia’s food safety agency disrupts nationwide shipments
A sustained DDoS attack knocked offline Rosselkhoznadzor’s VetIS and Saturn tracking systems, delaying food and chemical shipments across Russia. The incident underscores how availability attacks on centralized regulatory platforms can trigger immediate real-world supply chain disruption. Critical service operators should revisit DDoS resilience, traffic scrubbing, and continuity workflows for essential portals.
Source: Security Affairs
OpenAI Atlas Omnibox vulnerable to prompt-jailbreaks
Researchers found that a malicious prompt can be disguised as a URL and accepted by Atlas’s omnibox, enabling jailbreak-style safety bypasses. The finding highlights the fragility of input validation in AI-powered browsing tools and the need for stronger isolation and trust boundaries. Enterprises piloting such agents should limit capabilities, enforce least privilege, and monitor for policy-evasion patterns.
Source: Security Week
The bigger picture: Security risks with AI browser agents
New AI browsers from OpenAI and Perplexity promise productivity gains but simultaneously expand the attack surface through prompt injection, over-permissioned automation, and data leakage. The piece urges vendors and adopters to implement robust sandboxing, permission scoping, and provenance checks for AI-driven actions. Treat these agents like high-risk automation with rigorous controls, not ordinary browsers.
Source: TechCrunch Security
Pwn2Own Ireland 2025 cracks printers, routers, NAS—over $1M awarded
Researchers at Pwn2Own Ireland earned more than $1 million by compromising popular printers, routers, NAS devices, and more, with Summoning Team taking “Master of Pwn.” The results reinforce persistent weaknesses across SOHO and edge devices that often sit unpatched on enterprise networks. Watch for vendor advisories stemming from the contest and prioritize updates as patches land.
Source: HackRead
WordPress sites hit by 8.7 million attacks in 48 hours
Wordfence reports a surge of automated exploitation attempts targeting critical WordPress vulnerabilities at scale. Site owners should immediately update core, themes, and plugins, enable a web application firewall, and review access logs for indicators of compromise. Rapid patching and least-privilege access for admin accounts remain essential.
Source: Forbes Security
LastPass warns of ongoing attacks abusing legacy inheritance process
LastPass cautioned users about an active campaign exploiting the legacy user vault access inheritance mechanism, tied to so-called “Are You Dead?” social-engineering lures. Users should review inheritance settings, rotate master passwords, and enforce strong MFA across accounts. Organizations should also audit recovery and delegate-access workflows to minimize abuse.
Source: Forbes Security
You May Also Be Interested In...
MPs urge government to stop Britain's phone theft wave through tech
Amazon Explains How Its AWS Outage Took Down the Web
Half a terabyte of personal records exposed from youth non-profit