CyberSecBrief

Curated cybersecurity briefings on active threats, vulnerabilities, and emerging risks


Daily Cybersecurity Briefing (10 November 2025)

Published: Loading…

At a Glance

  • A breach at Chinese security firm Knownsec exposed cyber weapon data and target lists The U.S.
  • plans to ban TP-Link devices over national security concerns.
  • Microsoft detailed a 'Whisper Leak' side-channel attack exposing AI chat topics.
  • New runc vulnerabilities threaten Docker container isolation.
  • GlassWorm malware resurfaced on OpenVSX with malicious VSCode extensions.

Summary

A data breach at Chinese security company Knownsec exposed information about cyber-weapons and target lists reportedly linked to Beijing and the military.

The U.S. government is reportedly preparing to prohibit sales of TP-Link networking equipment, citing security concerns tied to the company’s Chinese links.

Microsoft disclosed a new side-channel method dubbed “Whisper Leak”, which allows attackers monitoring encrypted traffic to infer topics of AI conversations.

Three newly discovered runc vulnerabilities affecting Docker and Kubernetes could permit container escape and access to the host environment.

The GlassWorm malware campaign re-emerged on OpenVSX and the Visual Studio Code marketplace, spreading through three malicious extensions downloaded over 10,000 times.

Other developments include warnings from Switzerland’s NCSC about iPhone phishing scams, continuing CISA staff reductions, and Microsoft’s reminders for users to join the Windows 10 ESU programme before the next Patch Tuesday deadline.

Several critical and high-severity advisories were released, including flaws in Xen and libxml2 on Mageia systems, and a high-risk vulnerability in Amazon WorkSpaces client for Linux. Updates also addressed container runtime issues across multiple runc-based distributions.

Highlights of the day:

  • Microsoft reveals “Whisper Leak” side-channel attack: new technique infers sensitive AI chatbot topics from encrypted traffic, exposing privacy risks despite TLS protection; mitigations deployed by major vendors.
  • Critical runc flaws enable Linux container escapes: three vulnerabilities (CVE-2025-31133, CVE-2025-52565, CVE-2025-52881) could grant root access via race conditions and procfs manipulation; patches issued in latest releases.
  • U.S. plans TP-Link sales ban over security fears: government move follows concerns about Chinese influence and router misuse in cyber operations; TP-Link denies links and claims full operational independence.

Highlights of the Day

Microsoft Uncovers “Whisper Leak” Side-Channel Attack on AI Models

Microsoft researchers have revealed a new side-channel attack, dubbed Whisper Leak, capable of inferring sensitive conversation topics from encrypted language model traffic. By analysing packet sizes and timing patterns in streaming AI responses, attackers could classify user prompts despite Transport Layer Security (TLS) protection. Microsoft and several AI vendors, including OpenAI and Mistral, have deployed mitigations to limit the risk.

New runc Flaws Enable Container Escapes on Linux Hosts

Three newly disclosed vulnerabilities in runc, the container runtime used by Docker and Kubernetes, could let attackers escape containers and gain root access to host systems. Identified by a SUSE researcher and detailed by Sysdig, the flaws exploit race conditions and procfs manipulations in mount operations. All known runc versions before 1.2.8, 1.3.3, and 1.4.0-rc.3 are affected, though no active exploitation has been reported.

U.S. Considers Ban on TP-Link Networking Equipment

The U.S. government is reportedly preparing to prohibit sales of TP-Link routers and networking gear, citing national security concerns linked to the company’s historic ties to China. The proposed ban follows investigations revealing TP-Link devices’ use in cyber operations by Chinese state-backed groups. TP-Link disputes the claims, asserting its independence from Chinese control and compliance with U.S. standards.

Daily Coverage

Vulnerabilities
CVE-2025-31133Runc 1.2.8 (High)CVE-2025-52565CVE-2025-52881CVE-2025-12480Triofox 16.7.10368.56560 (Critical)CVE-2025-62229A Flaw Was Found In The X.org X Server And Xwayland When Processing X11 Present Extension Notifications. Improper Error Handling During Notification Creation Can Leave Dangling Pointers That Lead To A Use-After-Free Condition. This Can Cause Memory Corruption Or A Crash, Potentially Allowing An Attacker To Execute Arbitrary Code Or Cause A Denial Of Service.CVE-2025-62230A Flaw Was Discovered In The X.org X Server’s X Keyboard (Xkb) Extension When Handling Client Resource Cleanup. The Software Frees Certain Data Structures Without Properly Detaching Related Resources, Leading To A Use-After-Free Condition. This Can Cause Memory Corruption Or A Crash When Affected Clients Disconnect.CVE-2025-62231A Flaw Was Identified In The X.org X Server’s X Keyboard (Xkb) Extension Where Improper Bounds Checking In The Xkbsetcompatmap() Function Can Cause An Unsigned Short Overflow. If An Attacker Sends Specially Crafted Input Data, The Value Calculation May Overflow, Leading To Memory Corruption Or A Crash.CVE-2025-12725Chrome 142.0.7444.137 (High)CVE-2025-12726Chrome 142.0.7444.134 (High)CVE-2025-12727Chrome 142.0.7444.134 (High)