
Hello all,
This week had so many critical and high value vulnerabilities that it didn’t make sense to list them all in the headline news section, so make sure that you check out the full list of links to see if something that you support is impacted. Microsoft patched 63 defects, with 1 zero-day in the mix. Adobe, SAP, and many other Patch Tuesday vendors unleashed a large slew of fixes as well. CISA was quite active in publishing warnings, quite a few firewall vendors had a bad week, and data breaches abounded. There’s so much news this week that I wonder if reporting what doesn’t have a patch might be easier.
This email and video commentary is from the RedDotSecurity.news website that contains a plethora of links to other items, not mentioned here, that are worth skimming to see if they interest you or pertain to your particular environment or of those you support. There is a lot more than what is provided in these opening comments. So, on to the headline news.
Headline NEWS:
- Cisco and Citrix both have had a very bad week with active exploitation against Cisco’s Identity Service Engine (ISE), enabling pre-authenticated Remote Code Execution (RCE). And Citrix NetScaler ADC and NetScaler Gateway products have a zero-day that is now also under active exploitation. Follow vendor guidance to patch and check for compromise.
- Fortinet has a critical zero-day defect in FortiWeb that targets the web application firewall (WAF). This one “allows an attacker with no existing level of access to gain administrator-level access to the FortiWeb Manager panel and websocket command-line interface”. If you have this in your environment, patch immediately. This has been under active exploitation since at least early in October.
- Google Chrome patched another V8-JavaScript engine defect. Since it seems that major vulnerabilities are being plugged several times a week lately, just restart and update any Chromium based browser at least weekly at this point to ensure you stay updated.
- Microsoft released 63 fixes, including 1 zero-day this past Tuesday. The actively exploited Windows Kernel zero-day which enables privilege escalation is on CISA’s Know exploited Vulnerability (KEV) catalgo now. So, don’t delay vetting and applying the patches.
- N-able has revealed two critical defects, one of which carries a maximum-severity rating, in their N-central RMM (Remote Monitoring and Management) system. These flaws can allow a threat actor to achieve remote code execution. While not currently known to be exploited, If you use self-hosted N-able, it is critical that you patch immediately to prevent compromise of your and your clients’ systems. It is only a matter of time before enterprising dirtbags weaponize these defects.
- SAP (Systems, Applications, and Products in Data Processing), unveiled their November patch releases. Contained within was a maximum severity defect for hard-coded credentials in their SQL Anywhere Monitor. Yeah, that needs fixing fast. There were a total of 18 items addressed, two of which are critical, the aforementioned SQL Monitor, and Solution Manager, which can be triggered to enable full takeover of the system. Make sure you check your various SAP systems for needed patches quickly.
In Ransomware, Malware, and Vulnerabilities News:
- Firewall, Router, and Remote Connection vendors had a bad week with ASUS, Citrix, Cisco, FortiGate, Ivanti, Palo Alto, and WatchGuard all being named in various news reports of vulnerabilities and patch releases. CISA has named a few of these as being under active exploitation, it would be wise of you to keep up with their Known Exploited Vulnerabilities catalog so that you can take appropriate action when they publish notices.
In Other News Events of Note and Interest:
- ConnectWise CEO Manny Rivelo Interview by CRN is a great insight into the current status and near-term direction of this massive company that services the Managed Service Provider (MSP) industry. ConnectWise’s main focus is their Asio platform that closely mirrors many of their acquisitions. However, Rivelo states, “Asio isn’t a collection of bolted-on tools, it’s a brand-new platform built from the ground up. At its core, it includes four main service areas: RMM, PSA, security and data backup. On top of that, we’re wrapping in AI and RPA capabilities along with a centralized data warehouse and shared services.” There’s a lot more in the article. It is worth your time.
Musings:
Why do we not have virtual patch modeling systems that run on every workstation and server? Most every system now has significantly more compute power and storage than is required for normal day-to-day functions. It should be possible to create a virtualized duplicate environment inside the base system where an AI agent lives that has a historical baseline of all normal and usual activity that is performed on that base system, including menus opened, and various vendor software interactions. When a patch is requested to be installed, the AI could ensure the virtual baseline is up-to-date and matches the base system, install the patch in the virtual environment, and then silently open and perform all of the normal and usual activity that is done on that system to search for defects and incompatibilities. Any problems found can be reported to the user, IT, and vendors. And if there are performance concerns with this process, this could be done after hours when the user is away from the computer, or when servers are less taxed with day-to-day operations. Hey, I can dream, can’t I?

Meanwhile, keep the shields up!
Viscount Jan Broucinek
Red Dot Security News
Headline NEWS
- Active Exploitation of Cisco and Citrix 0-Day Vulnerabilities Allows Webshell Deployment
- Citrix NetScaler ADC and Gateway Vulnerability Enables Cross-Site Scripting Attacks
- Hackers turn Cisco and Citrix zero-days into a malware nightmare
- Critical Vulnerability in Fortinet FortiWeb Exploited in the Wild
- Suspected Fortinet Zero Day Exploited in the Wild
- PoC Exploit Tool Released for FortiWeb WAF Vulnerability Exploited in the Wild
- Chrome Patches High-severity Implementation Vulnerability in V8 JavaScript engine
- Microsoft November 2025 Patch Tuesday fixes 1 zero-day, 63 flaws
- N‑able Discloses Maximum-Severity N‑central RMM Vulnerability
- SAP fixes hardcoded credentials flaw in SQL Anywhere Monitor
Ransomware, Malware, and Vulnerabilities News
- Good News, Government News, and Interesting
- CISA Warns of Active Exploitation of Windows Kernel 0-Day Enabling Privilege Escalation
- CISA orders feds to patch Samsung zero-day used in spyware attacks
- CISA warns of Akira ransomware Linux encryptor targeting Nutanix VMs
- CISA Flags Critical WatchGuard Fireware Flaw Exposing 54,000 Fireboxes to No-Login Attacks
- WatchGuard Firebox Firewall Vulnerability Let Attackers Gain Unauthorized SSH Access
- Russian broker pleads guilty to assisting US cyberattacks
- Russian national pleads guilty to breaking into networks for Yanluowang ransomware attacks
- 18 Arrested in Crackdown on Credit Card Fraud Rings
- Rhadamanthys infostealer disrupted as cybercriminals lose server access
- New Strike Force Set to Target Overseas ‘Pig Butchering’ as U.S. Hits Burma Operation
- 4 Americans plead guilty to helping North Korean scammers earn over $2 million from dozens of companies
- Cybersecurity breach at Congressional Budget Office remains a live threat
- Data Leak Exposes Chinese State-Sponsored Cyber Arsenal and Target Database
- Jensen Huang’s Stark Warning: China’s 1 Million AI Workers vs America’s 20,000
- FBI Wants to Know Who Runs Archive.ph
- Vulnerabilities and Exploits
- Windows Kernel 0‑day Vulnerability Actively Exploited in the Wild to Escalate Privilege
- Windows Remote Desktop Services Vulnerability Let Attackers Escalate Privileges
- Microsoft Patches Critical ASP.NET Core Vulnerability with 9.9 Severity Score
- Microsoft SQL Server Vulnerability Allows Privilege Escalation
- Millions at risk of critical PC security vulnerability, Dell warns
- Hackers Exploit Triofox 0-Day to Deploy Malicious Payloads Using Anti-Virus Feature
- Palo Alto PAN-OS Firewall Vulnerability Let Attackers Reboot Firewall by Sending Malicious Packet
- Now-Patched Fortinet FortiWeb Flaw Exploited in Attacks to Create Admin Accounts
- ASUS warns of critical auth bypass flaw in DSL series routers
- SAP fixed a maximum severity flaw in SQL Anywhere Monitor
- Critical pgAdmin4 Vulnerability Lets Attackers Execute Remote Code on Servers
- Lost iPhone? Don’t fall for phishing texts saying it was found
- Intel Releases New CPU Microcode, Publishes 30 New Security Advisories
- Threat Actors Actively Hacking Websites to Inject Malicious Links and Boost their SEO
- Firefox Releases Security Update to Fix Multiple Vulnerabilities Allowing Arbitrary Code Execution
- America’s cybersecurity defenses are cracking
- Synology fixes BeeStation zero-days demoed at Pwn2Own Ireland
- Hackers Exploiting Triofox Flaw to Install Remote Access Tools via Antivirus Feature
- APT Groups Attacking Construction Industry Networks to Steal RDP, SSH and Citrix Logins
- Threat Actors Attacking Outlook and Google Bypassing Traditional Email Defenses
- APT37 hackers abuse Google Find Hub in Android data-wiping attacks
- High-Severity Vulnerabilities Patched by Ivanti and Zoom
- Zoom Workplace for Windows Vulnerability Allow Users to Escalate Privilege
- Zoom Vulnerabilities Let Attackers Bypass Access Controls to Access Session Data
- Online age checking is creating a treasure trove of data for hackers
- MastaStealer Exploits Windows LNK to Launch PowerShell and Bypass Defender
- Anthropic disrupts AI cyberattack by China-based hackers
- New ‘IndonesianFoods’ worm floods npm with 100,000 packages
- Phishing, Malware, and similar
- Large-Scale ClickFix Phishing Attacks Target Hotel Systems with PureRAT Malware
- Android Trojan ‘Fantasy Hub’ Malware Service Turns Telegram Into a Hub for Hackers
- Google launches a lawsuit targeting text message scammers
- Google says group behind E-ZPass, USPS text scam has been ‘shut down’
- Hackers breach texting services, send hundreds of thousands of scam texts
- Google issues security alert: Your VPN app could be spyware in disguise
- Quantum Route Redirect PaaS targets Microsoft 365 users worldwide
- DanaBot malware is back to infecting Windows after 6-month break
- New LandFall spyware exploited Samsung zero-day via WhatsApp messages
- Hackers Weaponizing Calendar Files as a New Attack Vector Bypassing Traditional Email Defenses
- Hackers Weaponize AppleScript to Creatively Deliver macOS Malware Mimic as Zoom/Teams Updates
- Popular Android-based photo frames download malware on boot
- facebookmail . com Invites Exploited to Phish Facebook Business Users
- PDF report from Anthropic about disrupting the first reported AI orchestrated cyber espionage campaign
- Decades-old ‘Finger’ protocol abused in ClickFix malware attacks
- Kraken Cross-Platform Ransomware Attacking Windows, Linux, and VMware ESXi Systems in Enterprise Environments
- Breaches, Leaks, and Ransomware
- What Makes Ransomware Groups Successful?
- DoorDash hit by new data breach in October exposing user information
- Conduent data breach exposes 10 million people’s personal information
- Hyundai Data Breach Puts 2.7 Million Americans at Risk of Identity Theft
- Logitech confirms data breach after Clop extortion attack
- Intel sues former engineer accused of stealing 18,000 files labeled “top secret”
- Russian hackers host secret VMs on Windows
- Hitachi-owned GlobalLogic admits data stolen by Clop
- Washington Post admits Clop crew lifted bank and SSN data
- Nearly 30 Alleged Victims of Oracle EBS Hack Named on Cl0p Ransomware Site
- Hackers hit University of St. Thomas 12 days after IT changeover
- How a CPU spike led to uncovering a RansomHub ransomware attack
- Ransomed CTO falls on sword, refuses to pay extortion demand
- Kraken ransomware benchmarks systems for optimal encryption choice
- Ransomware’s Fragmentation Reaches a Breaking Point While LockBit Returns
Other News Events of Note and Interest
- Cool Tool: Kode Dot Wants to Dethrone the Flipper Zero
- HackGPT: AI-Powered Penetration Testing Platform Includes GPT-4 and Other AI Engines
- One missing feature stops me from switching to Samsung Internet
- Mozilla Unveils Kit, a (Cute) New Mascot for Firefox
- Mozilla Firefox gets new anti-fingerprinting defenses
- ‘Vibe coding’ named word of the year by Collins Dictionary
- Google Urges Gmail Users To Abandon Passwords For Passkeys
- New UK laws to strengthen critical infrastructure cyber defenses
- A curated list of annual cyber security reports
- UK ruling says that Windows and Office licenses can be resold
- Samsung hikes memory chip prices by up to 60% as shortage worsens, sources say
- AI, LLM’s, and Skynet
- Robotics Company Builds Straight-Up Terminator
- Judge Blasts Lawyer Caught Using ChatGPT in Divorce Court, Orders Him to Take Remedial Law Classes
- Microsoft pursues solo AGI with a humanist twist
- Early look at images generated by Nano Banana 2 via Media AI
- OpenAI releases GPT-5.1 to all ChatGPT users
- ConnectWise CEO On $100M Push To Complete AI-Powered Asio Platform, 2026 Plans And Thoma Bravo’s ‘Value Creation’ Role
- Microsoft
- AMD releases Windows 11 25H2 RAID drivers for many chipsets, warns about installation issues
- Microsoft teases agents that become ‘independent users’
- Microsoft brings native support for 1Password and Bitwarden passkeys to Windows 11
- No Exchange Server Security Updates for November 2025
- The Microsoft Zero Trust Assessment: Helping you operationalize the hardening of your Microsoft security products
- Microsoft: Windows 11 23H2 Home and Pro reach end of support
- Microsoft Discontinued One Of Its Oldest Office Apps After 35 Years
- The ‘worst-selling Microsoft product of all time’ sold just 11 times, and eight people returned it
- Microsoft fixes Windows 10 Extended Security Update enroll bug
- First major Windows 10 ESU update is here – with 66 fixes (some critical)
- Microsoft Patch Tuesday security updates for November 2025 fixed an actively exploited Windows Kernel bug
- Here are the major Windows bugs resolved in the latest Patch Tuesday updates
- Windows 11 KB5068861 & KB5068865 cumulative updates released
- Windows 11 Update Includes More Colorful Battery Indicators, Overhauled Start Menu
