Microsoft released out-of-band updates to address a security feature bypass in Office that attackers are actively exploiting. The flaw stems from reliance on untrusted inputs in security decisions and affects multiple Office versions, including Microsoft 365 Apps. Admins should apply the emergency updates or Microsoft’s mitigations immediately to reduce exposure to targeted attacks.
Source: HelpNet Security
Poland thwarts data‑wiping attacks on energy systems; Sandworm suspected
Poland said it repelled late-December attacks using new wiper malware that targeted two CHP plants and systems managing wind and solar generation. Investigators and outside researchers link the activity to Russia-aligned Sandworm, underscoring persistent OT/ICS targeting and the need for network segmentation, tested incident response, and offline backups.
Source: HelpNet Security
Door access systems at major firms exposed by 20+ Dormakaba flaws
Researchers disclosed more than 20 vulnerabilities in Dormakaba enterprise access control systems that could let attackers remotely unlock doors. Patches are available; organizations should update affected exos 9300-based systems, isolate controllers from the internet, and review audit logs for suspicious access events.
Source: SecurityWeek
OMB reverses federal software attestation order, pivots to SBOMs
The White House Office of Management and Budget rescinded a Biden-era universal software attestation requirement, allowing agencies to lean on software bills of materials instead. The shift could reduce compliance friction but raises questions about consistency in software assurance and how effectively agencies will validate SBOM data at scale.
Source: NextGov Cyber
Malicious VS Code ‘AI’ extensions with 1.5M installs exfiltrate developer code
Two Visual Studio Code extensions posing as AI coding assistants siphoned source code and sensitive data to servers in China, yet remained available in the official marketplace. Teams should inventory installed extensions, remove suspicious add-ons, restrict marketplace access, and rotate any credentials or tokens that may have been exposed.
Source: TheHackerNews
MCP’s insecure defaults widen AI agent risk as Clawdbot spreads
New research warns the Model Context Protocol shipped without mandatory authentication, leaving thousands of MCP servers exposed and several critical CVEs enabling code execution. With viral AI agents like Clawdbot riding MCP into enterprises, security teams should enforce OAuth 2.1, bind servers to localhost, require human approval for high‑risk actions, and inventory MCP exposure now.
Source: VentureBeat Sec
EU opens formal probe into X’s Grok over illegal sexual imagery risks
The European Commission launched a Digital Services Act investigation into whether X’s AI tool Grok adequately assessed and mitigated risks tied to illegal content, including manipulated sexually explicit images and potential CSAM. The case signals rising regulatory scrutiny on AI content generation and platform governance, with significant compliance and enforcement implications.
Source: HelpNet Security
You May Also Be Interested In...