Fortinet has begun releasing fixes for a critical authentication bypass in FortiOS SSO that allowed attackers to log into FortiGate devices registered to other FortiCloud accounts. The flaw has been exploited in the wild via malicious FortiCloud accounts; admins should patch affected FortiOS/FortiManager/FortiAnalyzer versions immediately, review FortiCloud audit activity, reset tokens/passwords, and hunt for rogue local admin accounts.
Source: Help Net Security
Emergency update: Microsoft Office zero-day (CVE-2026-21509) under active exploitation
Microsoft issued out-of-band security updates for a high-severity Office security feature bypass that attackers are exploiting in the wild. The bug stems from reliance on untrusted inputs; organizations should deploy the update or apply mitigations now and consider tightening attack surface controls (e.g., Protected View, macro restrictions, Attack Surface Reduction rules) until fully patched.
Source: Help Net Security
‘PackageGate’ flaws expose JavaScript ecosystems to supply chain attacks
New “PackageGate” vulnerabilities in major JavaScript package managers (npm, pnpm, vlt, Bun) can bypass existing protections and enable arbitrary code execution during installs. Teams should lock down install scripts, enforce provenance and scoped registries, pin dependencies with lockfiles, and monitor CI/CD for anomalous package behavior while vendors roll out fixes.
Source: SecurityWeek
WinRAR CVE-2025-8088 widely exploited by APTs and cybercriminals
Google Threat Intelligence reports ongoing, broad exploitation of a WinRAR path traversal bug that drops payloads into the Windows Startup folder via Alternate Data Streams. Russian- and Chinese-aligned actors and crime groups are using it for initial access; upgrade WinRAR to 7.13+, block risky archive types, and monitor for suspicious writes in Startup folders.
Source: Google Cloud Threat Intelligence Blog
OpenSSL patches high-severity RCE and 11 additional vulnerabilities
The OpenSSL project released fixes for 12 issues, including a high-severity remote code execution vulnerability. Update to the latest OpenSSL releases across servers, containers, and appliances, and inventory any statically linked copies in applications to ensure they’re rebuilt and redeployed.
Source: SecurityWeek
WhatsApp introduces ‘Strict Account Settings’ to blunt spyware and targeted attacks
WhatsApp is rolling out a lockdown-style toggle that can block attachments/media and silence calls from unknowns, adding a defensive layer for at-risk users. Pair this with device-level hardening and WhatsApp’s two-step verification to reduce account takeover and spyware delivery paths.
Source: SecurityWeek
Attackers abuse Windows App‑V scripts to slip infostealer past enterprise defenses
Researchers detail a campaign delivering the Amatera Stealer using signed Microsoft App‑V scripts and fake human-verification pages that trick users into pasting commands. Mitigate by disabling App‑V where unused, restricting LOLBIN/script interpreter execution, tightening browser download policies, and enhancing EDR detections for Run dialog and script-abuse patterns.
Source: Help Net Security
You May Also Be Interested In...
CERT UEFI Parser: Open-source tool exposes UEFI architecture to uncover vulnerabilitiesThreat Actors Using AWS WorkMail in Phishing Campaigns
Android Theft Protection Feature Updates: Smarter, Stronger