Today’s top stories include critical supply chain malware campaigns, pre-auth remote code execution threats, and blended social engineering attacks via popular platforms. Defenders must move rapidly to patch, inventory exposed systems, and educate users about evolving impersonation risks.