A data breach at Chinese security company Knownsec exposed information about cyber-weapons and target lists reportedly linked to Beijing and the military.
The U.S. government is reportedly preparing to prohibit sales of TP-Link networking equipment, citing security concerns tied to the company’s Chinese links.
Microsoft disclosed a new side-channel method dubbed “Whisper Leak”, which allows attackers monitoring encrypted traffic to infer topics of AI conversations.
Three newly discovered runc vulnerabilities affecting Docker and Kubernetes could permit container escape and access to the host environment.
The GlassWorm malware campaign re-emerged on OpenVSX and the Visual Studio Code marketplace, spreading through three malicious extensions downloaded over 10,000 times.
Other developments include warnings from Switzerland’s NCSC about iPhone phishing scams, continuing CISA staff reductions, and Microsoft’s reminders for users to join the Windows 10 ESU programme before the next Patch Tuesday deadline.
Several critical and high-severity advisories were released, including flaws in Xen and libxml2 on Mageia systems, and a high-risk vulnerability in Amazon WorkSpaces client for Linux. Updates also addressed container runtime issues across multiple runc-based distributions.
Highlights of the day:
- Microsoft reveals “Whisper Leak” side-channel attack: new technique infers sensitive AI chatbot topics from encrypted traffic, exposing privacy risks despite TLS protection; mitigations deployed by major vendors.
- Critical runc flaws enable Linux container escapes: three vulnerabilities (CVE-2025-31133, CVE-2025-52565, CVE-2025-52881) could grant root access via race conditions and procfs manipulation; patches issued in latest releases.
- U.S. plans TP-Link sales ban over security fears: government move follows concerns about Chinese influence and router misuse in cyber operations; TP-Link denies links and claims full operational independence.