Microsoft shipped security updates addressing more than 60 vulnerabilities across Windows and supported software, including at least one zero-day already being exploited. The release also resolves a glitch that blocked some Windows 10 customers from accessing an extra year of security updates—timely, as the patched flaws impact all supported Windows versions, including Windows 10.
Source: KrebsOnSecurity
Widespread exploitation of XWiki vulnerability spreads to botnets and cryptominers
Attackers are broadly abusing a recent XWiki flaw, with activity now observed from botnets, cryptocurrency miners, scanners, and bespoke tools. Organizations running XWiki should prioritize patching and increased monitoring, as opportunistic exploitation is actively scaling across the ecosystem.
Source: SecurityWeek
Logitech confirms data breach after appearance on Cl0p leak site
Logitech has disclosed a data breach following its listing on the Cl0p ransomware leak site in early November. The company’s statement confirms a compromise but does not reference Oracle, despite earlier external claims linking multiple victims to a broader campaign.
Source: SecurityWeek
Report: China-linked hackers used autonomous AI agents in large-scale cyber campaign
According to Anthropic, China-backed threat actors leveraged advanced “agentic” AI capabilities to automate and execute cyberattacks during a 2025 espionage operation. If validated, this marks a notable escalation in offensive AI, moving beyond guidance to end-to-end automated intrusion workflows.
Source: Security Affairs
Android’s Rust push drives memory-safety bugs below 20% for the first time
Google reports that adopting Rust in Android has cut memory-safety vulnerabilities to under 20%, with a 1000x reduction in memory-safety bug density compared to C/C++ code. The milestone underscores how safer languages can materially shrink exploitability across a massive mobile ecosystem.
Source: The Hacker News
Eurofiber breach exposes critical infrastructure data across Europe
A major supply chain incident at Eurofiber, a core digital infrastructure provider, has exposed sensitive data impacting thousands of public and private organizations. The breach highlights systemic third-party risk where provider-level compromises can ripple across essential services and networks.
Source: SOCRadar
ClickFix malware abuses Windows finger.exe and the decades-old Finger protocol
Researchers warn that the rarely used Finger protocol and Windows finger.exe are being exploited in “ClickFix” malware attacks. Defenders should audit and restrict use of legacy utilities and protocols where possible, and watch for unusual invocations of finger.exe in enterprise environments.
Source: SANS Internet Storm Center
You May Also Be Interested In...
The year ahead in cyber: What’s next for cybersecurity in 2026 (Symantec)
Jaguar Land Rover hack cost India’s Tata Motors around $2.4B and counting
AIPAC discloses data breach, says hundreds affected