Microsoft’s November Patch Tuesday fixed 63 vulnerabilities across Windows, Office, Edge, SQL Server, and more, including an actively exploited Windows kernel elevation-of-privilege zero-day. Four bugs are rated Critical, with many others enabling remote code execution or privilege escalation. Organizations should prioritize the kernel zero-day and high-impact RCEs and deploy updates quickly across fleets.
Source: SecurityWeek
CISA adds Samsung Galaxy zero-day to KEV after spyware deployment (CVE-2025-21042)
CISA added a Samsung mobile vulnerability (CVE-2025-21042) to its Known Exploited Vulnerabilities catalog, ordering US federal agencies to remediate by early December. The flaw has been exploited in the wild to deliver spyware to high-end Samsung devices, underscoring the risk to enterprise and government users alike. Patch guidance is available via Samsung advisories.
Source: Help Net Security
Attackers exploited Gladinet Triofox zero-day to seize admin and run RATs (CVE-2025-12480)
A critical improper access control flaw in Gladinet Triofox was exploited as a zero-day, allowing unauthenticated access to setup pages, creation of admin accounts, and deployment of remote access tools. Organizations using Triofox should patch immediately and review logs for unauthorized configuration access and suspicious AV configuration changes.
Source: SecurityWeek
SAP fixes critical hardcoded-credentials flaw enabling RCE in SQL Anywhere Monitor
SAP’s November notes addressed multiple issues, including a maximum-severity bug in SQL Anywhere Monitor that used hardcoded credentials, enabling remote code execution on vulnerable deployments. Additional critical fixes landed for Solution Manager. Enterprises running affected SAP components should prioritize updates and rotate credentials where applicable.
Source: SecurityWeek
ICS Patch Tuesday: Siemens, Rockwell, Aveva, Schneider issue security updates
Major industrial vendors released coordinated advisories addressing vulnerabilities across ICS/OT products, with one Aveva issue also impacting Schneider Electric offerings. Operators of critical infrastructure should assess exposure, apply vendor mitigations, and plan maintenance windows for rapid patch deployment to reduce OT risk.
Source: SecurityWeek
OWASP Top 10 2025: Broken access control still #1; supply chain and AI risks rise
OWASP’s refreshed Top 10 keeps Broken Access Control at the top and elevates Security Misconfiguration to #2, while adding Software Supply Chain Failures and Mishandling of Exceptional Conditions. The update also calls out prompt injection in AI applications, signaling a growing need for controls around AI-assisted development and runtime defenses.
Source: The Register
‘Whisper Leak’ side-channel exposes LLM conversation topics despite encryption
Researchers showed that adversaries intercepting network traffic can infer chatbot conversation topics even over end-to-end encrypted channels. The finding highlights a blind spot in AI privacy and suggests the need for traffic-shaping, padding, and architectural mitigations to prevent topic leakage from model interactions.
Source: SecurityWeek
You May Also Be Interested In...
Adobe Patches 29 Vulnerabilities
Google Launches ‘Private AI Compute’ for secure cloud-based AI processing
Global Cyber Attacks Surge in October 2025 Amid Ransomware Growth and GenAI Risks