A maximum‑severity flaw in React Server Components can allow unauthenticated remote code execution on application servers, and AWS reports multiple China‑nexus actors began probing and exploiting within hours of disclosure. Projects using RSC with Server Actions/Functions (e.g., Next.js) are at immediate risk—admins should upgrade to fixed versions and restrict exposure of RSC endpoints.
Source: SecurityWeek
US, Canada warn on BRICKSTORM: stealthy China-linked backdoor targeting vSphere and Windows
CISA, NSA and Canada’s cyber center released technical details on BRICKSTORM, a sophisticated backdoor used by China state actors to maintain long‑term persistence across VMware vSphere and Windows environments. The advisory, based on eight samples from victim orgs, provides detection guidance and highlights the broader campaign’s dwell time and tradecraft.
Source: Recorded Future News (The Record)
Record-shattering DDoS: Aisuru botnet peaks at 29 Tbps and 14.1 Bpps
Cloudflare mitigated the largest hyper‑volumetric DDoS attack observed to date, signaling an escalation in botnet scale and capability. The surge underscores the need for provider‑level mitigation, resilient anycast architectures and upstream coordination as attackers weaponize massive, short‑burst floods.
Source: SecurityWeek
Malicious Rust crates target Web3 developers to steal crypto
Two crates—“evm-units” and a dependent “uniswap-utils”—were downloaded over 14,000 times before removal from crates.io, aiming to exfiltrate cryptocurrency via developer environments. The campaign highlights package‑ecosystem supply chain risk and dependency hijacking tactics that can quietly compromise wallets and build pipelines.
Source: Help Net Security
Third‑party breach at Marquis hits banks: data on 780,000+ individuals exposed
Fintech vendor Marquis Software Solutions disclosed a breach exposing names, addresses, Social Security numbers and card data, affecting hundreds of community banks and credit unions. The incident reinforces the systemic risk of vendor compromise across financial services and the need for robust third‑party risk management and data segmentation.
Source: SecurityWeek
Global cyber agencies publish AI‑in‑OT security guidance for critical infrastructure
CISA and international partners issued a 25‑page guide outlining four principles for safely integrating AI into operational technology environments. The recommendations stress risk assessments, robust governance, secure-by-design deployment and continuous monitoring to prevent automation from introducing new failure modes in critical systems.
Source: SecurityWeek
Microsoft quietly mitigates long‑abused Windows .LNK attack vector
After years of espionage and crimeware campaigns abusing shortcut files to hide malicious commands, Microsoft has silently shipped mitigations in its latest updates. The change reduces a common initial access technique, though defenders should continue monitoring for fallback delivery methods and signed binary abuse.
Source: SC Media
You May Also Be Interested In...
UDPGangster Campaigns Target Multiple Countries
Intellexa remotely accessed Predator spyware customer systems, investigation finds
U.S. CISA adds OpenPLC ScadaBR flaw to its Known Exploited Vulnerabilities catalog