This Week in Cybersecurity: Looking Back at Week 50
This week’s intelligence confirms a critical surge in maximum severity RCE flaws and the systemic risk posed by AI governance failures. We track two CVSS 10.0 RCE flaws in React/Next.js, the active exploitation of the popular WinRAR archiver by nation state APTs and a dangerous new corporate data leak vector via Microsoft 365 Copilot. These technical failures, combined with a major, four year old health sector ransomware breach coming to a head, demand that organisations focus immediately on application supply chain integrity and robust AI governance policies.