Well, it is Friday, once again! As the week closes, I thought it would be wise to do a quick review of what happened in cyber security this week. Knowing what is happening is half the battle.
“To know your enemy, you must become your enemy.” Sun Tzu, The Art of War.
First up is the usual Microsoft patch Tuesday! The patch addressed 114 security flaws, one of which was being used int eh wild. See here: https://thehackernews.com/2026/01/microsoft-fixes-114-windows-flaws-in.html. Knowing that attackers are actively exploiting this vulnerability should move IT staff to update their Windows system as soon as possible.
The vulnerability is CVE-2026-20805 and is an information disclosure flaw that affects Windows Desktop Window Manager. The Microsoft Threat Intelligence Center (MTIC) and Microsoft Security Response Center (MSRC) have been credited with identifying and reporting this flaw. Read up on it if you haven’t already! Then PATCH!!!
Second, is several security appliances or applications have disclosed vulnerabilities in their products. These include Fortinet, SonicWall, Cisco and WatchGuard. All have been exploited by attackers in real-world attacks!
Of these vulnerabilities, Cisco’s discovery that CVE-2025-20393, a critical flaw in AsyncOS, was under attack by a Chinese nexus advanced persistent threat actor (APT), with the code name of UAT-9686. The flaw is as of this blog unpatched! So keep an eye on your Cisco Systems and make sure you are threat hunting.
Third, the uber popular ServiceNow AI platform disclosed a critical vulnerability. CVE-2025-12420, with a CVSS score of 9.3. This vulnerability could enable an unauthenticated user to impersonate another user and then perform different actions. It is called “BodySnatcher,” very catchy in my humble opinion!
The common theme this week is the exploitation of network security and edge devices, which continues to be a major attack vector for sophisticated threat actors looking to gain deeper visibility into organizational networks.
Leave a Reply