Malicious actors could exploit a trio of already patched Windows Graphics Device Interface vulnerabilities, tracked as CVE-2025-30388, CVE-2025-47984, and CVE-2025-53766, to facilitate remote code execution and information disclosures, Infosecurity Magazine reports.
Malicious actors have escalated intrusions exploiting the critical untrusted data flaw in Windows Server Update Service, tracked as CVE-2025-59287, following the release of a proof-of-concept flaw last week, Cybersecurity Dive reports.
BleepingComputer reports that QNAP has urged users to patch a critical ASP.NET Core vulnerability tracked as CVE-2025-55315, which also affects its NetBak PC Agent software for Windows.