Ivanti released provisional patches for two critical code injection bugs in Endpoint Manager Mobile (EPMM), including CVE-2026-1281, which is being exploited in the wild and now sits in CISA’s KEV catalog. The flaws, tied to In‑House Application Distribution and Android File Transfer Configuration, can enable unauthenticated remote code execution on on‑prem EPMM. Admins should apply updates immediately and investigate for signs of compromise.
Source: Help Net Security
Microsoft ships out-of-band update for Office zero-day (CVE-2026-21509) exploited in the wild
Microsoft issued an emergency Office update to patch CVE-2026-21509, a vulnerability reportedly used to bypass document security checks and deliver malicious code. Cisco Talos notes the company has released three OOB updates in January, underscoring the need for rapid patching and hardening. Organizations should update Office suites now and reinforce email and macro controls.
Source: Cisco Talos
Google disrupts massive residential proxy network used by 550+ threat groups
Google’s takedown of the Ipidea proxy network degraded a “last‑mile” obfuscation layer leveraged by more than 550 threat groups in a single week, including state-sponsored actors. Attackers used Ipidea exit nodes to mask access to SaaS, on‑prem infrastructure, and password-spraying campaigns. Security teams should monitor for traffic from known residential proxy ranges and review egress controls and anomaly detections.
Source: Help Net Security
eScan antivirus update infrastructure compromised to push downloader, cripple protections
Attackers breached eScan AV’s update channel to deliver a persistent downloader and tamper with registry, files, and update configs—breaking endpoint protections and blocking future updates. Both enterprise and consumer installations were impacted, according to researchers. Affected users should isolate systems, validate integrity of eScan components, and follow vendor IR guidance before re-enabling updates.
Source: Help Net Security
SolarWinds Web Help Desk: four critical flaws allow unauthenticated RCE/auth bypass—patch now
SolarWinds patched multiple Web Help Desk vulnerabilities, including four critical issues that can enable remote code execution or authentication bypass without credentials. Given WHD’s broad use in IT ticketing and asset management, exposed instances pose high risk. Apply the latest release immediately and restrict network exposure.
Source: SecurityWeek
Sandworm-linked attack on Poland’s grid bricked ICS devices at 30 sites
New reporting shows the Russia-linked Sandworm/Electrum intrusion damaged communication and control systems across 30 energy sites, rendering some ICS devices inoperable. The incident highlights escalating OT targeting and the potential for life‑safety impacts during peak demand. OT defenders should tighten segmentation, harden remote access, and rehearse incident response tailored to industrial environments.
Source: SecurityWeek
Operation “Bizarre Bazaar” hijacks exposed LLM/MCP endpoints for profit
Researchers detail an LLMjacking campaign exploiting unauthenticated large language model endpoints and Model Context Protocol (MCP) services at scale, monetizing stolen compute and access. The operation underscores how AI infrastructure—often spun up without security reviews—creates new attack surfaces. Lock down AI endpoints with strong auth, network isolation, and supply‑chain controls on agent tools and connectors.
Source: SecurityWeek
You May Also Be Interested In...
Notorious Russia-based RAMP cybercrime forum apparently seized by FBI
Apple’s new privacy feature limits how precisely carriers track your location
NIST releases a new draft cybersecurity framework for systems that never stop moving