Daily Recap, Microsoft addressed 421 CVEs in Patch Tuesday, including a Windows driver zero-day under active attack, while Adobe and multiple ICS vendors also shipped critical fixes for ColdFusion and Campaign Classic-related issues. The day also highlighted exploited zero-days impacting Microsoft Defender (ShieldBreak), Cisco ASA/FTD VPN devices, and a fresh Windows flaw tied to North Korean cyberattacks, alongside reported breaches involving Ceva Logistics and Wesco, plus active abuse such as malicious Kimwolf and trojanized WireGuard activity. #PatchTuesday #Microsoft #Windows #ShieldBreak #Cisco #ASA #FTD #ColdFusion #CampaignClassic #Siemens #Schneider #PhoenixContact #NorthKorea #CevaLogistics #Wesco #ExfilSquad #DeadLock #Kimwolf #Sandworm #WireGuard #WhatsApp #Signal #Zoom #Chrome #Delta #DEFCON #NIST #NSA #DHS
Patch Tuesday
- Microsoft shipped fixes for 421 CVEs and a Windows driver zero-day under active attack, while related updates also landed for Intel and AMD with over 80 vulnerabilities combined. β Patch Roundup, Chip Fixes, Windows Flaws
- Adobe urged immediate patching for critical ColdFusion and Campaign Classic flaws, while ICS vendors Siemens, Schneider, and Phoenix Contact also released security fixes. β Adobe Fixes, ICS Fixes
Exploited Zero-Days
- Microsoft Defender faced a new ShieldBreak zero-day that can grant SYSTEM privileges, adding to the monthβs wave of exploited flaws. β ShieldBreak
- Cisco patched an ASA/FTD VPN zero-day abused to crash devices and another firewall flaw exploited for DoS attacks. β Firewall Zero-Day, VPN Crash Bug
- Researchers reported a fresh Windows zero-day used in North Korean cyberattacks, underscoring ongoing active exploitation. β NK Exploits
Ransomware & Breaches
- Ceva Logistics confirmed a cyberattack disrupting operations and affecting retailers and Steam customers across Europe. β Ceva Attack, Retail Impact
- Wesco confirmed a security incident after ExfilSquad claimed data theft, while a ransomware group also hijacked a hospital systemβs Facebook page during response efforts. β Wesco Incident, Hospital Hijack
- DeadLock ransomware is using blockchain to resist takedown efforts, showing how threat actors are hardening their infrastructure. β DeadLock Tactics
Malware & Botnets
- Kimwolf botnet operators rebuilt the malware to survive takedowns, and the newer Kimwolf v7 variant disguises HTTP/2 DDoS traffic as legitimate browsing. β Kimwolf Rebuild, Kimwolf v7
- Sandworm targeted IT professionals with a trojanized WireGuard VPN client, reinforcing the groupβs focus on supply-chain-style lures. β Trojanized WireGuard
Apps & Collaboration
- WhatsApp launched a new scam alert feature, while Signal added protections against man-in-the-middle attacks. β WhatsApp Alert, Signal Defense
- Zoom patched a zero-click code execution bug and separate annotation flaws that could let one meeting participant hijack another attendeeβs client. β Zoom Patch, Zoom Flaws
Browser & Mobile Abuse
- Investigators found 737 Chrome VPN extensions routing traffic through proxies, while Google said Chrome blocks 7 billion unwanted Android notifications per day to curb abuse. β Chrome VPNs, Android Abuse
Network & Travel Security
- Delta is investigating alleged in-flight Wi-Fi spoofing and deauthentication attacks on a flight carrying DEF CON attendees from Las Vegas. β Delta Probe, Wi-Fi Attack
Policy & Research
- NIST plans to overhaul its vulnerability database for the AI era, as analysts warn the AI governance gap is fundamentally a leadership problem. β NIST Overhaul, AI Governance
- NSA named a new general counsel from DHS, amid broader federal cybersecurity leadership changes. β NSA Counsel