The eSentire Threat Response Unit reports ongoing exploitation of CVE-2019-18935, a six-year-old IIS vulnerability in Progress Telerik UI, allowing attackers to execute arbitrary code on unpatched servers. Threat actors use a reverse shell via w3wp.exe to gather system information, deploying tools like JuicyPotatoNG. Organizations should enhance patch management and utilize Endpoint Detection and Response solutions to mitigate these risks.

M&S issues update as crippling nationwide IT outage still ongoing – The Sun
Marks & Spencer (M&S) halted online orders in the UK and Ireland following a cyber attack, leading to a 5% drop in share price. Physical