Russian intelligence services are conducting systematic cyber-espionage against NATO and Ukrainian military infrastructure, indicating escalated cyber-warfare operations in the immediate geographic context of the DACH region.
A critical, unauthenticated RCE vulnerability in HTTP.sys enables attackers to execute kernel-level code or trigger denial-of-service conditions by sending crafted HTTP packets to affected servers.
GigaWiper combines remote-access functionality with data-destruction capabilities in a modular platform and has been observed in active intrusions since October 2025.
BSI advisory on an Edge vulnerability with security-bypass potential requires immediate prioritization of patches and browser updates across the estate.
BSI alerts on multiple vulnerabilities in Firefox/ESR enabling RCE and security bypass , no specific CVE disclosed, indicating coordination with vendor for responsible disclosure.
The BSI warns of multiple vulnerabilities in Microsoft developer tools that can lead to remote code execution, privilege escalation, and DoS attacks , a summary of multiple updates without specific CVE details.
The BSI alert addresses multiple OpenSSH vulnerabilities generically without naming specific CVE-IDs or affected versions, making precise risk assessment difficult.
BSI advisory on multiple RCE and disclosure vulnerabilities in Adobe Acrobat/Reader without specific CVE details in the alert; patch status and PoC availability unclear from the notice.
BSI warns of multiple unspecified Chrome vulnerabilities with potential for code execution; specific CVE numbers and version information are absent from the advisory.
BaFin penalty against TeamViewer indicates inadequate security measures in a widely-used remote-access tool that is critical for IT support in manufacturing.
The malware leverages legitimate Microsoft Graph API to obfuscate command-and-control traffic through manipulated calendar events, bypassing traditional network monitoring.
The campaign exploits fake GitHub repositories disguised as AI tools and MCP servers to deceive developers and inject malware into supply chains , a significant risk for organizations whose engineers pull dependencies directly from GitHub.
Attackers combine fileless techniques and low-detection loaders to deploy multiple RATs and stealers in BEC campaigns, bypassing traditional malware detection mechanisms.
An authenticated vulnerability in Microsoft Edge enables local code execution with elevated privileges; specific CVE and CVSS metrics are required for prioritization.
The digest highlights a surge of zero-days and pre-authentication RCEs in the current week, including evidence that threat actor UTA0533 exploited multiple SonicWall SMA vulnerabilities as zero-days before public disclosure.