Mishcon de Reya page structure
Site header
Menu
Main content section

Monthly Cyber Threats Report - November 2025

Issue 11: November 2025

Monthly Cyber Threats Report - November 2025

Editor's note

Mark Tibbs
Mark Tibbs

Our monthly report prepares cybersecurity practitioners to make better tactical, operational and strategic decisions. We have distilled analysis of key events from the previous month which have learning points that can be actioned to improve security.

News
a blue squares in a black background

Aging SMB flaw continues to threaten Windows security

Back in June 2025, Microsoft released a critical security update for a vulnerability in the Windows Server Message Block (SMB) client. This vulnerability, tracked as CVE-2025-330731, is rated 8.8 on the Common Vulnerability Scoring System (CVSS), and considered high severity as it affects all supported versions of Windows 10, Windows 11 (up to and including 24H2), and Windows Server.

News
a close up of lines and dots

Newly discovered WSUS bug under active attack

Microsoft has issued emergency security updates to address a high-risk vulnerability in Windows Server Update Service (WSUS), for which proof-of-concept exploit code has been made publicly accessible, further emphasising the urgent need to update any affected servers without delay.

News
a computer screen with green text

Microsoft reports limited malware activity using AI platform

In November 2025, Microsoft reported a new malware campaign called SesameOp, which uses a legitimate artificial intelligence (AI) service to secretly communicate with attackers. The malware was hidden inside modified developer software which, once installed, connected to the OpenAI platform using valid credentials controlled by the attacker.

Subscribe

Never miss a publication by signing up to our mailing list

Monthly Cyber Threats Report - November 2025 Issues

How can we help you?
Help

How can we help you?

Subscribe: I'd like to keep in touch

If your enquiry is urgent please call +44 20 3321 7000

I'm a client

I'm looking for advice

Something else