Software company Elastic has released security updates for a critical flaw, CVE-2025-25012, in its Kibana data visualization tool. The prototype pollution vulnerability, which allows manipulation of an application’s JavaScript objects, could lead to unauthorized data access or remote code execution. The flaw affects Kibana versions 8.15.0 to 8.17.3 and has been addressed in version 8.17.3. Users are advised to apply patches or disable the Integration Assistant feature for protection.

M&S issues update as crippling nationwide IT outage still ongoing – The Sun
Marks & Spencer (M&S) halted online orders in the UK and Ireland following a cyber attack, leading to a 5% drop in share price. Physical