The US government issued an emergency directive for federal agencies to remediate a Windows Server Update Services (WSUS) remote code execution bug after researchers found the prior fix “did not fully mitigate” the issue. The flaw is under active exploitation, raising the risk of attackers hijacking enterprise patch infrastructure to push malicious updates. Organizations should apply Microsoft’s out-of-band update immediately and audit WSUS servers for signs of compromise.
Source: Recorded Future News
Chrome zero-day tied to Italian spyware vendor Memento Labs
Investigators linked exploitation of a Chrome sandbox escape zero-day (CVE-2025-2783) to delivery of LeetAgent, an espionage tool associated with Memento Labs (formerly Hacking Team). The campaign highlights the continued use of commercial surveillanceware and supply chains to target high-value users across platforms. Update Chrome to the latest version and consider EDR protections that detect post-exploitation behaviors.
Source: The Hacker News
Swedish power grid operator hit by data breach; operations unaffected
Sweden’s national grid operator confirmed data theft via a file transfer solution after a ransomware group claimed responsibility, but emphasized the power supply was not impacted. The incident underscores third-party and data-movement risks in critical infrastructure, where exfiltration and extortion are increasingly favored over encryption. Energy-sector defenders should harden file-transfer tools, enforce least-privilege access, and monitor for anomalous data egress.
Source: SecurityWeek
Ransomware payments fall to historic lows as victims resist
Only 23% of ransomware victims paid in Q3 2025, and for data-theft-only incidents the rate fell to 19%, according to Coveware’s latest analysis. As enterprises invest in resilience and legal guidance, threat actors are adapting with higher-pressure tactics and multi-stage extortion. Bolstering backup integrity, incident playbooks, and legal/PR coordination continues to pay dividends for victim organizations.
Source: SecurityWeek
US declines to sign UN cybercrime treaty as 70+ countries join
More than 70 nations signed the first global UN Convention against Cybercrime, but the United States opted out at this stage. The pact aims to improve cross-border cooperation and enforcement, while critics warn about potential overreach and civil liberties concerns. The decision has implications for how evidence-sharing and international investigations will proceed over the next several years.
Source: Recorded Future News
Mass exploitation resumes against year-old WordPress plugin flaws
Attackers reignited large-scale exploitation of critical vulnerabilities in the GutenKit and Hunk Companion WordPress plugins, with roughly 9 million exploit attempts observed this month. The bugs enable unauthenticated arbitrary plugin installation leading to remote code execution. Site admins should update or disable affected plugins, scan for rogue plugins/backdoors, and rotate credentials.
Source: SecurityWeek
New Atlas browser exploit plants persistent hidden commands
Researchers disclosed a flaw in OpenAI’s ChatGPT Atlas browser that allows attackers to inject instructions into the agent’s memory, persist across sessions, and run arbitrary code. Coming on the heels of other prompt-injection vectors, the finding spotlights the risks of “agentic” browsing that intermixes user commands, navigation, and automation. Organizations trialing Atlas should restrict its use, apply strict tenant controls, and monitor agent actions until fixes are available.
Source: The Hacker News
You May Also Be Interested In...
Massive China-Linked Smishing Campaign Leveraged 194,000 Domains
Crypto wasted: BlueNoroff’s ghost mirage of funding and jobs
Phishing scam uses fake death notices to trick LastPass users