Microsoft rushes an emergency patch after last week's update broke Remote Desktop and hypervisor stability, Revolut discloses a process breach affecting 680+ high-net-worth clients, and Cisco scores another perfect 10 CVSS.


This week's Risk Radar: Microsoft rushes out an emergency fix after last week's record-breaking Patch Tuesday introduced two new bugs and broke production systems, Revolut discloses a breach rooted in a spoofed government email rather than a technical exploit, and Cisco scores another perfect CVSS 10 in a vulnerability already being exploited in the wild.
An update on the record-breaking Microsoft Patch Tuesday we covered last week. Since then, it has emerged that while 974 CVEs were patched, two new vulnerabilities were introduced by the update itself. The patch also broke production systems worldwide, particularly Remote Desktop and hypervisor functionality, heavily affecting cloud users. Microsoft released an out-of-band patch on Monday to address both issues.
What to do:
Apply Microsoft's out-of-band patch as soon as possible, particularly on production systems or anywhere you have seen instability with Remote Desktop or hypervisor services since last month's update.
Revolut suffered a breach that started with a process failure rather than a direct cyberattack. An employee received an email that appeared to come from a legitimate government domain and, believing the request genuine, disclosed sensitive customer information to the attacker. More than 680 high-net-worth individuals across Europe were affected, including well-known footballers, tennis players and business figures with sizeable incomes.
This is an important lesson for CISOs at banks, financial institutions, or any organisation holding significant amounts of PII: authenticating a request is not the same as authorising it.
What to do:
Put side-channel confirmation and senior management sign-off in place for any request that involves disclosing PII, regardless of how legitimate the sender appears.
Another vulnerability in Cisco's platform has scored a perfect CVSS 10. This one allows unauthenticated attackers to perform remote code execution. The affected product is Cisco Identity Services Engine (ISE), and Cisco has already confirmed the vulnerability is being actively exploited in the wild.
What to do:
Patch any ISE deployment in your organisation immediately. Cisco has confirmed active exploitation, so this cannot wait for a routine patch cycle.
Stay safe, and share this with your team.
We protect your on-premise/cloud/OT environments - 24x7x365