Microsoft closed out 2025 with patches for 54+ new CVEs, including an in‑the‑wild elevation bug in the Windows Cloud Files minifilter (CVE-2025-62221), a PowerShell Invoke‑WebRequest change to thwart a Mark‑of‑the‑Web bypass (CVE-2025-54100), and a cross‑prompt injection in GitHub Copilot for JetBrains (CVE-2025-64671). Multiple Office RCEs are also patched, with Preview Pane as a vector in some cases. Prioritize the Cloud Files zero‑day, account for new PowerShell behavior in automation, and review IDE/agentic AI restrictions.
Source: Rapid7
North Korea-linked actors exploit React2Shell to drop new EtherRAT using Ethereum smart contracts
Adversaries are weaponizing the critical React Server Components flaw (CVE-2025-55182, CVSS 10) to deploy “EtherRAT,” a previously unseen RAT that resolves C2 via Ethereum smart contracts and establishes robust Linux persistence. The activity underscores rapid exploitation of modern web app supply chain issues; teams should patch affected RSC packages immediately and hunt for anomalous blockchain lookups and new persistence artifacts.
Source: The Hacker News
Ivanti EPM critical unauthenticated stored XSS (CVE-2025-10573) enables admin session hijack; patch now
Rapid7 disclosed a CVSS 9.6 stored XSS in Ivanti Endpoint Manager where unauthenticated attackers can submit malicious device scan data to poison admin dashboards, leading to JavaScript execution and control of administrator sessions. Ivanti released EPM 2024 SU4 SR1 on Dec. 9, 2025; organizations should upgrade urgently and monitor for suspicious use of the ‘incomingdata’ API.
Source: Rapid7
New PCIe flaws impact Intel and AMD processors, enabling info leak, EoP, and DoS
Researchers (from Intel) disclosed multiple PCIe vulnerabilities affecting CPUs from Intel and AMD that could be abused for information disclosure, privilege escalation, or denial‑of‑service. Remediation may require firmware, microcode, BIOS, or platform updates; enterprises should track vendor advisories for affected platforms and apply updates in maintenance windows.
Source: SecurityWeek
DeadLock ransomware campaign wields new BYOVD loader to kill EDR via vulnerable Baidu AV driver
Cisco Talos reports a DeadLock ransomware wave using a previously unknown bring‑your‑own‑vulnerable‑driver (BYOVD) loader to exploit a Baidu Antivirus driver, letting attackers disable EDR and escalate privileges. The campaign highlights continued abuse of signed yet vulnerable kernel drivers; defenders should enforce driver blocklists, enable HVCI/Kernel-Mode Code Integrity, and monitor for driver tampering attempts.
Source: Cisco Talos
‘Broadside’ Mirai variant targets TBK DVRs on ships, threatening maritime logistics
A new Mirai-based botnet dubbed Broadside is exploiting CVE‑2024‑3721 in TBK Vision DVRs, devices common on vessels, to build DDoS capability and steal credentials. Shipping and port operators should urgently inventory TBK DVR exposure, apply vendor fixes, isolate video gear from operational networks, and enforce strong credentials.
Source: SecurityWeek
ICS Patch Tuesday: Siemens, Rockwell, Schneider fix dozens of industrial flaws
Major OT vendors released coordinated updates addressing multiple vulnerabilities across product lines, with potential impacts ranging from unauthorized access to code execution. Asset owners should review vendor advisories, prioritize patches for internet‑exposed or critical process assets, and validate change windows with engineering teams.
Source: SecurityWeek
You May Also Be Interested In...
SAP Patches Critical Vulnerabilities With December 2025 Security Updates
Shai‑Hulud 2.0: Guidance for Defending Against a Major Supply Chain Attack