1. Top Action Item

Shut down ShareFile Storage Zone Controllers immediately. Progress Software has confirmed a "credible external security threat" against the Windows servers running ShareFile Storage Zone Controllers and has temporarily disabled affected accounts. If you operate a ShareFile Storage Zone Controller, power it down now and await official patching guidance from Progress.


2. Exploited This Week

jscrambler npm package — compromised 8.14.0 release

Injective Labs GitHub compromise — @injectivelabs/sdk-ts@1.20.21


3. Critical Patch Roundup

Zimbra Classic Web Client — unpatched stored XSS (no CVE yet)

Chromium browser vulnerabilities (multiple CVEs)

WolfSSL, GeoVision, VTK-DICOM vulnerabilities

OpenClaw AI assistant — three high-severity flaws (GHSA-hjr6-g723-hmfm and others)

U-Boot bootloader — six new flaws

XQUIC (Alibaba's QUIC/HTTP/3 library) — unpatched XRING flaw


4. Home / SOHO Impact


5. Enterprise Impact


6. What To Patch First

  1. ShareFile Storage Zone Controllers — Shut down immediately (credible external security threat, no patch yet)
  2. jscrambler 8.14.0 — Remove and treat machine as compromised (supply-chain infostealer, exploited in the wild)
  3. @injectivelabs/sdk-ts 1.20.21 — Remove and rotate wallet keys (supply-chain wallet theft, exploited in the wild)
  4. Zimbra Classic Web Client — Apply latest updates (critical stored XSS, arbitrary code execution)
  5. Microsoft Edge / Google Chrome — Update to latest version (12 CVEs including use-after-free, exploited in the wild)
  6. OpenClaw AI assistant — Update to latest version (three high-severity flaws, CVSS 8.8)
  7. WolfSSL, GeoVision, VTK-DICOM — Apply vendor patches (multiple vulnerabilities)
  8. U-Boot devices — Apply firmware updates from device vendors (six flaws, code execution at boot)

Sources