If you read nothing else
If you run WSUS, patch it first. Microsoft shipped an out-of-band fix on October 23, 2025, and CISA added the flaw to its catalog the next day.
Eight items from the week of October 20 to 26, 2025, each with its source.
1. WSUS remote code execution flaw, CVE-2025-59287
CVE-2025-59287 is a remote code execution flaw in Windows Server Update Services (WSUS), rated CVSS 9.8. Microsoft released an out-of-band update on October 23, 2025, and CISA added the flaw to its catalog on October 24, with a November 14 deadline for federal agencies. Source: The Hacker News. CISA's catalog is at cisa.gov.
What this means for you: WSUS is the server that pushes updates to your Windows machines, so a compromised WSUS reaches every machine it manages.
Do this: confirm the WSUS server has the October 23 update, or if you do not use WSUS, confirm the role is turned off.
2. Adobe Commerce and Magento flaw added to CISA's catalog
CISA added CVE-2025-54236, an Adobe Commerce and Magento Open Source flaw that lets an attacker take over customer accounts through the Commerce REST API, to its catalog on October 24, 2025. Source: CISA KEV catalog.
What this means for you: if you run an online store on Adobe Commerce or Magento, a customer account takeover is the risk to close now.
Do this: confirm your store's platform build is current, and ask your developer to confirm it in writing.
3. Motex LANSCOPE Endpoint Manager flaw added to CISA's catalog
CISA added CVE-2025-61932, a Motex LANSCOPE Endpoint Manager flaw that lets an attacker run code by sending specially crafted packets, to its catalog on October 22, 2025. Source: CISA KEV catalog.
What this means for you: endpoint management tools reach every machine they manage, so a flaw in one is a flaw across the fleet.
Do this: if you use LANSCOPE, confirm its version and patch status with your IT provider.
4. Pwn2Own Ireland demonstrates 73 zero-day vulnerabilities
Researchers demonstrated 73 unique zero-day vulnerabilities at Pwn2Own Ireland 2025, a contest that ended in October 2025. Source: CyberInsider.
What this means for you: the devices that rarely receive updates are the ones most likely to still carry these flaws.
Do this: list network devices that never receive firmware updates, and plan replacements for them.
5. CoPhish abuses Microsoft Copilot Studio to steal OAuth tokens
Datadog Security Labs disclosed CoPhish in late October 2025. The technique uses Copilot Studio's demo website feature to host a sign-in page on a Microsoft domain and send the access token to an attacker's server. Microsoft says it plans fixes in a future update. Source: BleepingComputer.
What this means for you: a consent request you did not start is a red flag, even when it points at a Microsoft domain.
Do this: restrict who can consent to apps in Microsoft 365, and tell staff never to approve a request they did not start.
6. LastPass phishing uses fake death-certificate claims
Emails told recipients that a family member had uploaded a death certificate to access their vault, and linked to a fake LastPass recovery page that asked for the master password. In some cases, people posing as LastPass staff phoned victims. LastPass linked the campaign to CryptoChameleon, also tracked as UNC5356. Source: BleepingComputer.
What this means for you: the master password for a password manager must never be typed into a link from an email or a text.
Do this: tell staff that LastPass and other password managers never need the master password entered through a link.
7. Lazarus Operation DreamJob targets European defense contractors
ESET reported on October 23, 2025 that North Korea-linked Lazarus ran a new wave of Operation DreamJob against European defense contractors, including firms in drone and UAV work. The lure was a fake job offer bundled with a PDF reader that is malware, and the payload was the ScoringMathTea remote-access trojan. Source: Help Net Security.
What this means for you: a recruiter email with a PDF reader attached matches the lure used against defense contractors in October 2025.
Do this: tell staff never to open a file attached to a job offer, and check the recruiter by calling a number you already have.
8. Have I Been Pwned adds 183 million unique email addresses
Have I Been Pwned added about 183 million unique email addresses on October 21, 2025, from an infostealer dataset collected by Synthient. The first release contains stealer logs, and a credential stuffing set is expected later. Source: CyberInsider.
What this means for you: a password reused on any website may now be in this set, so reused passwords are the risk to fix.
Do this: check work email addresses at haveibeenpwned.com, change any reused passwords, and turn on MFA for work accounts.
Not sure where you stand? Cyber Grants Alliance offers in-kind CMMC Level 1 and CMMC Level 2 gap assessment grants, at no cost to you. See every program on Grant Programs.
