Microsoft shipped fixes for 114 vulnerabilities, including an actively exploited information disclosure in Desktop Window Manager (CVE-2026-20805) likely used as part of exploit chains. The release also introduces a Secure Boot certificate transition (CVE-2026-21265) that requires careful planning to avoid unbootable systems, and removes legacy Agere modem drivers tied to public elevation-of-privilege research (CVE-2023-31096). Admins should prioritize the zero‑day, plan Secure Boot certificate updates, and address high‑impact Windows/Office RCEs.
Source: Rapid7
VoidLink: Cloud‑native Linux malware framework targets stealth persistence in cloud infrastructure
Check Point Research detailed “VoidLink,” an advanced, modular malware framework engineered to maintain long‑term, covert access to Linux systems that underpin cloud services. Its plug‑in design, adaptive stealth, and shift away from endpoint‑centric tactics signal attacker focus on cloud runtime and control planes—raising the bar for detection and response in containerized and server environments.
Source: Check Point Blog
CISA adds exploited Gogs path traversal flaw to KEV, urges immediate mitigation
A high‑severity path traversal vulnerability in the self‑hosted Git service Gogs (CVE-2025-8110) is under active attack and now listed in CISA’s Known Exploited Vulnerabilities catalog. The bug can enable code execution via the repository file editor; U.S. federal agencies must remediate or remove affected instances, and enterprises running Gogs should patch or lock them down immediately.
Source: The Hacker News
Critical Node.js bug can crash servers across “virtually every” production app
Node.js released patches for a critical issue in async_hooks stack handling that can trigger denial‑of‑service across most production deployments. Because many frameworks rely on recoverable stack exhaustion behavior for availability, teams should fast‑track updates to the latest fixed versions and review DoS controls protecting Node stacks exposed to untrusted input.
Source: The Hacker News
Fortinet patches critical pre‑auth flaws in FortiFone and FortiSIEM
Fortinet addressed two critical vulnerabilities that are exploitable without authentication, leading to configuration disclosure and remote code execution. Given the prevalence of Fortinet gear in hybrid networks and SOC stacks, organizations should patch immediately and review exposure of management interfaces to the internet.
Source: SecurityWeek
ServiceNow fixes critical AI Platform bug allowing unauthenticated user impersonation
ServiceNow disclosed and patched CVE-2025-12420 (CVSS 9.3), a flaw in its AI Platform that could let an unauthenticated attacker impersonate users and perform arbitrary actions. Customers should apply updates promptly and audit recent activity for anomalous actions executed via AI workflows.
Source: The Hacker News
Long‑running Magecart campaign skims cards from enterprise checkout flows
Researchers uncovered a global web‑skimming (Magecart) operation active since January 2022 that targets major payment networks and enterprise e‑commerce sites via third‑party scripts. Because these attacks execute in the browser and evade traditional server‑side controls, defenders should enforce script integrity (e.g., SRI), strict Content Security Policy, and continuous third‑party script monitoring.
Source: Silent Push
You May Also Be Interested In...
Chrome 144, Firefox 147 Patch High‑Severity Vulnerabilities
Hack shuts down hospital IT, dozens of surgeries postponed
Target source code for sale on dark web as employees confirm it’s authentic