Microsoft shipped broad security updates addressing multiple high‑risk flaws, including an exploited Windows Cloud Files Mini Filter elevation-of-privilege (CVE-2025-62221) and a PowerShell zero‑day (CVE-2025-54100) that allowed code execution before Mark‑of‑the‑Web checks. Two Office remote code execution bugs are also notable because Outlook/Explorer Preview Pane can trigger them without user clicks. Prioritize endpoints running PowerShell 5.1 and Office, and review scripts that rely on Invoke‑WebRequest after Microsoft’s default-behavior change.
Source: Rapid7
React2Shell (CVE-2025-55182) under heavy exploitation, dropping miners and new malware
Attackers are mass‑exploiting the maximum‑severity React Server Components flaw to gain remote code execution in Node.js/Next.js apps. Campaigns observed deploy crypto miners alongside previously undocumented malware families and backdoors, underscoring the risk to internet‑exposed web stacks. Patch immediately, rotate credentials, and hunt for persistence on affected hosts.
Source: The Hacker News
Zero‑click “GeminiJack” bug in Google’s Gemini Enterprise could have exfiltrated corporate Gmail, Docs, and Calendar
Google fixed a flaw that enabled indirect prompt‑injection via crafted emails, calendar invites, or documents, allowing silent data exfiltration from Gemini‑connected enterprise apps. The case highlights the expanding attack surface as GenAI assistants gain privileged access to business data. Review Gemini configuration, apply updates, and enforce DLP/least‑privilege controls around AI integrations.
Source: SecurityWeek
Unpatched Gogs zero‑day (CVE-2025-8110) actively exploited; 700+ self‑hosted Git instances compromised
A file‑overwrite flaw in Gogs’ file update API enables remote code execution, and attackers are already abusing it at scale. With no upstream fix available yet, owners of internet‑exposed instances are urged to restrict access, audit for unauthorized users/files, and deploy compensating controls (WAF/reverse proxy) until patched.
Source: The Hacker News
Fortinet patches critical auth bypass in FortiOS, FortiWeb, FortiProxy, FortiSwitchManager
Two improper signature‑verification issues (CVE‑2025‑59718/59719, CVSS 9.1) allow authentication bypass when FortiCloud SSO is enabled, exposing network edges and management planes to takeover. Organizations should patch urgently, disable affected SSO paths if updates aren’t possible, and scrutinize admin logs for anomalous access.
Source: SecurityWeek
Chrome emergency update: Google fixes an in‑the‑wild high‑severity zero‑day
Google released a security update for Chrome to address a high‑severity flaw that is already being exploited; technical details and CVE are being withheld pending patch adoption. Enterprises should fast‑track browser updates and enforce auto‑updates/restarts to minimize exposure windows.
Source: SecurityWeek
HTTPS ecosystem tightening: CA/Browser Forum to sunset 11 email/phone‑based domain validation methods
Google’s Chrome Root Program and the CA/Browser Forum approved ballots to retire legacy Domain Control Validation methods (e.g., WHOIS/email/phone and reverse lookups) in favor of automated, cryptographically verifiable approaches like ACME/DNS. Phased deprecation through March 2028 aims to reduce mis‑issuance risks and improve certificate lifecycle agility across the web.
Source: Google Online Security Blog
You May Also Be Interested In...
DOJ, CISA warn of Russia‑linked attacks targeting critical infrastructure
WinRAR path traversal (CVE‑2025‑6218) added to CISA KEV amid active exploitation
WordPress auto‑login backdoor masquerades as a JavaScript data file