MSP cybersecurity news digest, October 28, 2025
ID: 969c402e-dfc8-5799-9347-310a809e4b27
STIX ID: report--969c402e-dfc8-5799-9347-310a809e4b27
Feed Name: TRU Security by Acronis
### Executive summary The report describes multiple concurrent, high-risk cyber threats: a wormable Windows Server WSUS remote code execution (CVE-2025-59287) actively exploited for SYSTEM-level access, a critical Lanscope Endpoint Manager flaw (CVE-2025-61932, CVSS 9.3) with reported exploitation, targeted LastPass-themed phishing that captures master passwords and passkeys, state-linked MuddyWater phishing operations delivering document loaders and data exfiltration tools, and a RedTiger-based infostealer harvesting Discord tokens, browser credentials, and crypto-wallet files. Organizations are advised to apply out-of-band patches, disable or block affected services until patched, validate update/package integrity, and monitor for lateral movement and credential theft.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
