A critical vulnerability in the Windows Common Log File System Driver (CVE-2025-32713) allows attackers to escalate privileges to SYSTEM level. Applicable to various Windows OS versions, it poses significant risks due to its local exploitation potential. Microsoft has released updates to mitigate the threat and urges organizations to prioritize immediate deployment of these security patches.

Apache ActiveMQ Flaw Exploited to Deploy DripDropper Malware on Cloud Linux Systems
Threat actors are exploiting a nearly two-year-old security flaw in Apache ActiveMQ to gain persistent access to cloud Linux systems and deploy malware called DripDropper.