Apple released iOS 26.1 and macOS Tahoe 26.1 with patches for more than 100 flaws, including 19 WebKit issues that could lead to code execution. While Apple did not report active exploitation, the breadth of fixes across iPhone, iPad, and Mac makes rapid updating essential for enterprises managing mixed Apple fleets.
Source: SecurityWeek
Teams trust abused: quartet of bugs enabled executive impersonation and message tampering
Check Point researchers detailed four now-patched Microsoft Teams vulnerabilities that allowed attackers to impersonate executives, manipulate chat history, and spoof notifications/calls. With more than 320 million users, the flaws highlight how collaboration platforms’ trust mechanisms can be turned into social engineering launchpads if not rigorously validated.
Source: Check Point Blog
New “SesameOp” backdoor abuses OpenAI Assistants API for stealthy C2
Microsoft uncovered a backdoor dubbed SesameOp that uses OpenAI’s Assistants API to store and relay attacker commands, blending malicious traffic into legitimate AI service use. The technique complicates detection and takedown, underscoring how adversaries are co‑opting AI infrastructure as covert command-and-control channels.
Source: SecurityWeek
CISA flags actively exploited CWP RCE; patch management urgency rises
CISA added a critical Control Web Panel vulnerability (CVE-2025-48703) enabling unauthenticated remote command execution to its Known Exploited Vulnerabilities catalog. Federal agencies must expedite remediation, and all administrators should prioritize patching or isolating exposed management interfaces to reduce mass exploitation risk.
Source: SecurityWeek
From keyboard to cargo: RMM tool abuse helps hijack physical shipments
Threat actors are tricking logistics and trucking firms into installing remote monitoring and management tools, then abusing access to reroute or steal real-world freight. Proofpoint-tracked campaigns dating back to at least June 2025 leverage tools like ScreenConnect and SimpleHelp, illustrating the growing convergence of cyber intrusion and physical theft.
Source: SecurityWeek
Android November update fixes critical System RCE
Google’s November 2025 security bulletin patches two System component vulnerabilities, including a critical remote code execution bug. Organizations should push the 2025-11-01 patch level as soon as available from OEMs, and assess device fleets that no longer receive updates for compensating controls.
Source: SecurityWeek
U.S. sanctions North Korean network laundering stolen crypto for weapons program
The U.S. Treasury sanctioned bankers, financial institutions, and facilitators accused of laundering proceeds from cybercrime and IT worker schemes tied to North Korea. The move targets the financial backbone that converts hacked and extorted cryptocurrency into funds for the regime’s nuclear ambitions, raising compliance stakes for global intermediaries.
Source: SecurityWeek
You May Also Be Interested In...
Critical flaw in React Native CLI exposes developers to remote attacks
European authorities dismantle €600 million crypto scam network
Russian spies hide custom malware in covert Hyper‑V Linux VMs