U.S. real estate and IT firms, Venezuelan financial organizations, and Saudi Arabian retail companies, as well as Spanish software provider have been subjected to Storm-0460 ransomware attacks exploiting the Windows Common Log File System Driver vulnerability, tracked as CVE-2025-29824, which Microsoft fixed as part of this month's Patch Tuesday, reports The Record, a news site by cybersecurity firm Recorded Future.
Google has addressed 62 Android security vulnerabilities, including two actively exploited zero-day flaws, as part of this month's security update, reports BleepingComputer.
BleepingComputer reports that Amazon Web Services, Google, Microsoft Azure, Hadoop, and other big data platforms could be subjected to significant compromise through the exploitation of a maximum-severity remote code execution vulnerability impacting the widely used open-source columnar storage format Apache Parquet, tracked as CVE-2025-30065.
Sensitive data compromise could have been achieved through the exploitation of the recently patched Google Cloud Run privilege escalation flaw dubbed "ImageRunner," according to SecurityWeek.
Immediate patching has been urged by Cisco for a critical flaw impacting its Smart Licensing Utility, tracked as CVE-2024-20439, following the discovery of its attempted exploitation last month, reports BleepingComputer.
Fast Five
Selected by the SC Media Editorial team every Tuesday.
Sign up now for the top five issues cybersecurity pros need to know this week.