Attackers are actively weaponizing CVE-2025-55182, a critical remote code execution flaw in React Server Components caused by unsafe deserialization. With reports of large-scale scanning and compromises, CISA ordered federal agencies to patch by December 12; all organizations should urgently upgrade React/Next.js, restrict internet exposure, and deploy WAF rules to block malicious RSC payloads.
Source: The Hacker News
Google ships fix for mystery Chrome zero-day under active attack
Google released emergency updates for Chrome to fix three bugs, including a high-severity zero-day being exploited in the wild. Details remain withheld (no CVE yet), so enterprises should push the latest version immediately and ensure browsers are restarted to load the patched build.
Source: SecurityWeek
Unpatched Gogs zero-day abused for RCE; months-long exploitation
An unpatched file overwrite vulnerability in Gogs allows attackers to write outside repositories and achieve remote code execution. Researchers say the bug has been exploited for months; until an official fix is available, limit exposure, apply mitigations/workarounds, and monitor for suspicious file changes on Gogs hosts.
Source: SecurityWeek
CISA adds actively exploited GeoServer XXE to KEV; patch now
CVE-2025-58360, an unauthenticated XML External Entity flaw impacting OSGeo GeoServer, has been added to CISA’s Known Exploited Vulnerabilities catalog. The KEV designation signals confirmed in-the-wild attacks; organizations should upgrade to patched releases, remove unnecessary public exposure, and audit logs for XXE indicators.
Source: The Hacker News
New ‘DroidLock’ Android malware locks users out and demands ransom
Researchers warn of DroidLock, a strain targeting Spanish-speaking users that enforces a ransom lock screen and applies changes that can render devices unusable. Avoid sideloading APKs, keep Play Protect enabled, and use MDM policies to block unknown sources and remote control features.
Source: Recorded Future News
UK fines LastPass £1.2M over 2022 breach affecting 1.6M people
Britain’s ICO penalized LastPass for “failing to implement sufficiently robust technical and security measures,” following the breach that exposed customer data. The action underscores expectations for strong secrets management, hardened developer environments, and rapid detection/response in custodians of sensitive credentials.
Source: Recorded Future News
MITRE’s 2025 Top 25 software weaknesses: XSS, SQLi, CSRF lead
MITRE’s latest list keeps cross-site scripting at number one, followed by SQL injection and cross-site request forgery, with buffer overflows and improper access control also in the top 25. The ranking offers a practical roadmap for secure coding, prioritizing code reviews, SAST/DAST, framework hardening, and memory-safe languages.
Source: SecurityWeek
You May Also Be Interested In...
Trump Signs Executive Order to Block State AI Regulations
React and Next.js urge patching again: two more severe vulnerabilities discovered
Microsoft Bug Bounty Program Expanded to Third-Party Code