Category: Vulnerability News

  • Kohler’s Encrypted Smart Toilet Camera is not Actually end-to-end Encrypted

    Kohler’s Encrypted Smart Toilet Camera is not Actually end-to-end Encrypted Kohler’s $600 smart toilet camera system, marketed with promises of “end-to-end encryption,” does not actually implement the security standard as commonly understood in the cybersecurity industry, raising significant privacy concerns for users uploading intimate health data to the company’s servers. The Dekoda device, launched in…

  • Akamai Patches HTTP Request Smuggling Vulnerability in Edge Servers

    Akamai Patches HTTP Request Smuggling Vulnerability in Edge Servers A critical HTTP request smuggling vulnerability in Akamai’s edge server infrastructure has been successfully fixed. The vulnerability, identified as CVE-2025-66373, stemmed from improper processing of HTTP requests containing invalid chunk-encoded bodies, potentially exposing thousands of customers to sophisticated attacks. Understanding HTTP Chunked Transfer Encoding HTTP chunked…

  • Chrome 143 Released With Fix for 13 Vulnerabilities that Enable Arbitrary Code Execution

    Chrome 143 Released With Fix for 13 Vulnerabilities that Enable Arbitrary Code Execution Google has officially promoted Chrome 143 to the Stable channel, rolling out version 143.0.7499.40 for Linux and 143.0.7499.40/41 for Windows and Mac. This significant update addresses 13 security vulnerabilities, including several high-severity flaws that could allow attackers to execute arbitrary code or…

  • Multiple Django Vulnerabilities Enables SQL Injection and Denial-of-Service Attacks

    Multiple Django Vulnerabilities Enables SQL Injection and Denial-of-Service Attacks The development team has officially released essential security updates to address two significant vulnerabilities found in the popular web framework. These issues range from high to moderate severity. They could allow attackers to compromise database integrity or crash servers through resource exhaustion. The most critical flaw,…

  • OpenVPN Vulnerabilities Let Hackers Triggers Dos Attack and Bypass Security Checks

    OpenVPN Vulnerabilities Let Hackers Triggers Dos Attack and Bypass Security Checks OpenVPN has released critical security updates for its 2.6 stable and 2.7 development branches, addressing three vulnerabilities that could lead to local denial-of-service (DoS), security bypasses, and buffer over-reads. The patches, included in the newly released version 2.6.17 and 2.7_rc3, fix issues ranging from…

  • PoC Exploit Released for Critical Outlook 0-Click Remote Code Execution Vulnerability

    PoC Exploit Released for Critical Outlook 0-Click Remote Code Execution Vulnerability A Proof-of-Concept (PoC) exploit code has been released for a critical remote code execution (RCE) vulnerability in Microsoft Outlook, identified as CVE-2024-21413. Dubbed “MonikerLink,” this flaw allows attackers to bypass Outlook’s security mechanisms, specifically the “Protected View,” to execute malicious code or steal credentials.…

  • CISA Warns of OpenPLC ScadaBR cross-site scripting vulnerability Exploited in Attacks

    CISA Warns of OpenPLC ScadaBR cross-site scripting vulnerability Exploited in Attacks The Cybersecurity and Infrastructure Security Agency (CISA) has officially updated its Known Exploited Vulnerabilities (KEV) catalog to include a critical flaw in OpenPLC ScadaBR, confirming that threat actors are actively weaponizing it in the wild. The security defect, identified as CVE-2021-26829, is a Cross-Site…

  • Threat Actors Allegedly Listed iOS 26 Full‑Chain 0‑Day Exploit on Dark Web

    Threat Actors Allegedly Listed iOS 26 Full‑Chain 0‑Day Exploit on Dark Web A threat actor operating under the alias ResearcherX has posted what they claim to be a full‑chain zero‑day exploit targeting Apple’s recently released iOS 26 operating system. The listing, which appeared on a prominent dark web marketplace, alleges that the exploit leverages a…

  • HashiCorp Vault Vulnerability Allow Attackers to Authenticate to Vault Without Valid Credentials

    HashiCorp Vault Vulnerability Allow Attackers to Authenticate to Vault Without Valid Credentials A critical security flaw has been discovered in HashiCorp’s Vault Terraform Provider that could allow attackers to bypass authentication and access Vault without valid credentials. The vulnerability, tracked as CVE-2025-13357, affects organizations using LDAP authentication with Vault. The security issue stems from an…

  • Microsoft’s Update Health Tools Configuration Vulnerability Let Attackers Execute Arbitrary Code Remotely

    Microsoft’s Update Health Tools Configuration Vulnerability Let Attackers Execute Arbitrary Code Remotely A critical remote code execution (RCE) vulnerability in Microsoft’s Update Health Tools (KB4023057). A widely deployed Windows component designed to expedite security updates through Intune. The flaw stems from the tool connecting to dropped Azure Blob storage accounts that attackers could register and control.​ How…

  • DeepSeek-R1 Makes Code for Prompts With Severe Security Vulnerabilities

    DeepSeek-R1 Makes Code for Prompts With Severe Security Vulnerabilities A concerning vulnerability in DeepSeek-R1, a Chinese-developed artificial intelligence coding assistant. When the AI model encounters politically sensitive topics related to the Chinese Communist Party, it produces code with severe security flaws at rates up to 50% higher than usual. Released in January 2025 by Chinese…

  • Wireshark Vulnerabilities Let Attackers Crash by Injecting a Malformed Packet

    Wireshark Vulnerabilities Let Attackers Crash by Injecting a Malformed Packet The Wireshark Foundation has rolled out a crucial security update for its widely used network protocol analyzer, addressing multiple vulnerabilities that could lead to denial-of-service conditions. The latest release, version 4.6.1, specifically targets flaws discovered in the Bundle Protocol version 7 (BPv7) and Kafka dissectors.…

  • CISA Warns of Oracle’s Identity Manager RCE Vulnerability Actively Exploited in Attacks

    CISA Warns of Oracle’s Identity Manager RCE Vulnerability Actively Exploited in Attacks The Cybersecurity and Infrastructure Security Agency (CISA) is urging organizations to immediately address a critical security flaw in Oracle Identity Manager following reports of active exploitation. The vulnerability, tracked as CVE-2025-61757, allows unauthenticated remote attackers to execute arbitrary code on affected systems, posing…

  • Metasploit Adds Exploit Module for Recently Disclosed FortiWeb 0-Day Vulnerabilities

    Metasploit Adds Exploit Module for Recently Disclosed FortiWeb 0-Day Vulnerabilities The Metasploit Framework has introduced a new exploit module targeting critical vulnerabilities in Fortinet’s FortiWeb Web Application Firewall (WAF). This module chains two recently disclosed flaws, CVE-2025-64446 and CVE-2025-58034, to achieve unauthenticated Remote Code Execution (RCE) with root privileges. The release follows reports of active exploitation in the wild,…

  • SonicOS SSLVPN Vulnerability Let Attackers Crash the Firewall Remotely

    SonicOS SSLVPN Vulnerability Let Attackers Crash the Firewall Remotely SonicWall has disclosed a critical stack-based buffer overflow vulnerability in its SonicOS SSLVPN service. That allows remote unauthenticated attackers to crash firewalls through denial-of-service attacks. The vulnerability was internally discovered and reported by SonicWall’s security team. The flaw, tracked as CVE-2025-40601, carries a CVSS score of 7.5…

  • Ollama Vulnerabilities Let Attackers Execute Arbitrary Code by Parsing of Malicious Model Files

    Ollama Vulnerabilities Let Attackers Execute Arbitrary Code by Parsing of Malicious Model Files A severe vulnerability in Ollama, one of GitHub’s most popular open-source projects, with over 155,000 stars. The flaw enables attackers to execute arbitrary code on systems running vulnerable versions of the platform by exploiting weaknesses in the software’s parsing of model files.…

  • CISA Warns of Critical Lynx+ Gateway Vulnerability Exposes Data in Cleartext

    CISA Warns of Critical Lynx+ Gateway Vulnerability Exposes Data in Cleartext The Cybersecurity and Infrastructure Security Agency (CISA) has issued a critical warning about a severe vulnerability in Lynx+ Gateway devices that could expose sensitive information in clear text during transmission. The flaw allows attackers to catch network traffic and obtain plaintext credentials and other…

  • Hackers Use Rogue MCP Server to Inject Malicious Code and Control the Cursor’s Built-in Browser

    Hackers Use Rogue MCP Server to Inject Malicious Code and Control the Cursor’s Built-in Browser A critical vulnerability allowing attackers to inject malicious code into Cursor’s embedded browser through compromised MCP (Model Context Protocol) servers. Unlike VS Code, Cursor lacks integrity verification on its proprietary features, making it a prime target for tampering. The attack…

  • PoC Exploit Tool Released for FortiWeb WAF Vulnerability Exploited in the Wild

    PoC Exploit Tool Released for FortiWeb WAF Vulnerability Exploited in the Wild A proof-of-concept (PoC) exploit tool for CVE-2025-64446 has been publicly released on GitHub. This vulnerability, affecting FortiWeb devices from Fortinet, involves a critical path traversal flaw that has already been observed in real-world attacks, allowing unauthorized access to sensitive CGI endpoints. Security researchers…

  • Critical pgAdmin4 Vulnerability Lets Attackers Execute Remote Code on Servers

    Critical pgAdmin4 Vulnerability Lets Attackers Execute Remote Code on Servers A severe remote code execution (RCE) flaw has been uncovered in pgAdmin4, the popular open-source interface for PostgreSQL databases. Dubbed CVE-2025-12762, the vulnerability affects versions up to 9.9 and could allow attackers to run arbitrary commands on the hosting server, potentially compromising entire database infrastructures.…

  • Critical FortiWeb WAF Flaw Exploited in the Wild, Enabling Full Admin Takeover

    Critical FortiWeb WAF Flaw Exploited in the Wild, Enabling Full Admin Takeover Fortinet has issued an urgent advisory warning of a critical vulnerability in its FortiWeb web application firewall (WAF) product, which attackers are actively exploiting in the wild. Identified as CVE-2025-64446, the flaw stems from improper access control in the GUI component, allowing unauthenticated…

  • Critical Imunify360 AV Vulnerability Exposes 56 Million+ Linux-hosted Websites to RCE Attacks

    Critical Imunify360 AV Vulnerability Exposes 56 Million+ Linux-hosted Websites to RCE Attacks A severe remote code execution (RCE) vulnerability has been discovered in Imunify360 AV, a widely used malware scanner protecting approximately 56 million websites. The security flaw, recently patched by CloudLinux, allows attackers to execute arbitrary commands and potentially take complete control of hosting…

  • Critical Dell Data Lakehouse Vulnerability Let Remote Attacker Escalate Privileges

    Critical Dell Data Lakehouse Vulnerability Let Remote Attacker Escalate Privileges Dell Technologies has disclosed a critical security vulnerability in its Data Lakehouse platform that could allow remote attackers to escalate privileges and compromise system integrity. The flaw, tracked as CVE-2025-46608, affects all versions before 1.6.0.0 and has been assigned a CVSS score of 9.1, placing it in…

  • CISA Warns WatchGuard Firebox Out-of-Bounds Write Vulnerability Exploited Attacks

    CISA Warns WatchGuard Firebox Out-of-Bounds Write Vulnerability Exploited Attacks The Cybersecurity and Infrastructure Security Agency (CISA) has released a warning about a serious vulnerability affecting WatchGuard Firebox security appliances. This flaw, tracked as CVE-2025-9242, potentially allows remote attackers to take control of affected systems. The security issue involves an out-of-bounds write in the device’s operating…

  • OpenAI Sora 2 Vulnerability Exposes System Prompts via Audio Transcripts

    OpenAI Sora 2 Vulnerability Exposes System Prompts via Audio Transcripts A vulnerability in OpenAI’s advanced video generation model, Sora 2, that enables the extraction of its hidden system prompt through audio transcripts, raising concerns about the security of multimodal AI systems. This vulnerability, detailed in a blog post by AI security firm Mindgard, demonstrates how…

  • ChatGPT Hacked Using Custom GPTs Exploiting SSRF Vulnerability to Expose Secrets

    ChatGPT Hacked Using Custom GPTs Exploiting SSRF Vulnerability to Expose Secrets A Server-Side Request Forgery (SSRF) vulnerability in OpenAI’s ChatGPT. The flaw, lurking in the Custom GPT “Actions” feature, allowed attackers to trick the system into accessing internal cloud metadata, potentially exposing sensitive Azure credentials. The bug, discovered by Open Security during casual experimentation, highlights…

  • SecureVibes – AI Tool Scans for Vulnerabilities in 11 Languages with Claude AI Agents

    SecureVibes – AI Tool Scans for Vulnerabilities in 11 Languages with Claude AI Agents In the fast-paced world of “vibecoding,” where developers use AI to build applications rapidly, a new open-source tool is stepping up to tackle security risks. SecureVibes, created by developer Anshuman Bhartiya, leverages Anthropic’s Claude AI through a multi-agent system to detect…

  • Windows Remote Desktop Services Vulnerability Let Attackers Escalate Privileges

    Windows Remote Desktop Services Vulnerability Let Attackers Escalate Privileges Microsoft has disclosed a significant vulnerability in Windows Remote Desktop Services (RDS) that could allow authorized attackers to escalate their privileges on affected systems. Tracked as CVE-2025-60703, the flaw stems from an untrusted pointer dereference, a classic memory safety issue that has plagued software for years, and…

  • Zoom Vulnerabilities Let Attackers Bypass Access Controls to Access Session Data

    Zoom Vulnerabilities Let Attackers Bypass Access Controls to Access Session Data Zoom has issued multiple security bulletins detailing patches for several vulnerabilities affecting its Workplace applications. The disclosures, published today, highlight two high-severity issues alongside medium-rated flaws, underscoring the ongoing challenges in securing video conferencing tools used by millions in hybrid work environments. These updates…

  • SAP Security Update – Patch for Critical Vulnerabilities Allowing Code Execution and Injection Attacks

    SAP Security Update – Patch for Critical Vulnerabilities Allowing Code Execution and Injection Attacks SAP released its monthly Security Patch Day updates, addressing 18 new security notes and providing two updates to existing ones, focusing on vulnerabilities that could enable remote code execution and various injection attacks across its product ecosystem. These patches are crucial…

  • Hackers Exploiting Triofox 0-Day Vulnerability to Execute Malicious Payload Abusing Anti-Virus Feature

    Hackers Exploiting Triofox 0-Day Vulnerability to Execute Malicious Payload Abusing Anti-Virus Feature Google Mandiant has disclosed active exploitation of CVE-2025-12480, a critical unauthenticated access vulnerability in Gladinet’s Triofox file-sharing platform. The threat cluster tracked as UNC6485 has been weaponizing this flaw since August 2025 to gain unauthorized administrative access and establish persistent remote control over compromised systems. The…

  • CISA Warns of Samsung Mobile Devices 0-Day RCE Vulnerability Exploited in Attacks

    CISA Warns of Samsung Mobile Devices 0-Day RCE Vulnerability Exploited in Attacks CISA has added a critical zero-day vulnerability affecting Samsung mobile devices to its Known Exploited Vulnerabilities catalog. Warning that threat actors are actively exploiting the flaw in real-world attacks. The vulnerability, tracked as CVE-2025-21042, is an out-of-bounds write vulnerability in the libimagecodec.quram.so library on…

  • Critical runc Vulnerabilities Put Docker and Kubernetes Container Isolation at Risk

    Critical runc Vulnerabilities Put Docker and Kubernetes Container Isolation at Risk Three critical vulnerabilities in runc, the container runtime powering Docker, Kubernetes, and other containerization platforms. These flaws could allow attackers to escape container isolation and gain root access to host systems. However, no active exploits have been detected yet. The vulnerabilities leverage race mount…

  • Monsta web-based FTP Remote Code Execution Vulnerability Exploited

    Monsta web-based FTP Remote Code Execution Vulnerability Exploited A critical remote code execution vulnerability in Monsta FTP, a popular web-based FTP client used by financial institutions and enterprises worldwide. The flaw, now tracked as CVE-2025-34299, affects multiple versions of the software and has been exploited in the wild. Monsta FTP is a browser-based file transfer client…

  • Seven QNAP Zero-Day Vulnerabilities Exploited at Pwn2Own 2025 Now Patched

    Seven QNAP Zero-Day Vulnerabilities Exploited at Pwn2Own 2025 Now Patched QNAP has addressed seven critical zero-day vulnerabilities in its network-attached storage (NAS) operating systems, following their successful exploitation by security researchers at Pwn2Own Ireland 2025. These flaws, identified as CVE-2025-62847, CVE-2025-62848, CVE-2025-62849, and associated ZDI canonical entries ZDI-CAN-28353, ZDI-CAN-28435, ZDI-CAN-28436, enable remote code execution (RCE)…

  • New Whisper Leak Toolkit Exposes User Prompts to Popular AI Agents within Encrypted Traffic

    New Whisper Leak Toolkit Exposes User Prompts to Popular AI Agents within Encrypted Traffic A sophisticated side-channel attack that exposes the topics of conversations with AI chatbots, even when traffic is protected by end-to-end encryption. Dubbed “Whisper Leak,” this vulnerability allows eavesdroppers such as nation-state actors, ISPs, or Wi-Fi snoopers to infer sensitive prompt details…

  • Hackers Hijack Samsung Galaxy Phones via 0-Day Exploit Using a Single WhatsApp Image

    Hackers Hijack Samsung Galaxy Phones via 0-Day Exploit Using a Single WhatsApp Image A sophisticated spyware operation targeting Samsung Galaxy devices, dubbed LANDFALL, which exploited a zero-day vulnerability to infiltrate phones through seemingly innocuous images shared on WhatsApp. This campaign, active since mid-2024, allowed attackers to deploy commercial-grade Android malware capable of full device surveillance…

  • Cisco Identity Services Engine Vulnerability Allows Attackers to Restart ISE Unexpectedly

    Cisco Identity Services Engine Vulnerability Allows Attackers to Restart ISE Unexpectedly A critical vulnerability in Cisco Identity Services Engine (ISE) could allow remote attackers to crash the system through a crafted sequence of RADIUS requests. The flaw CVE-2024-20399, lies in how ISE handles repeated authentication failures from rejected endpoints, creating a denial-of-service condition that forces…

  • NVIDIA NVApp for Windows Vulnerability Let Attackers Execute Malicious Code

    NVIDIA NVApp for Windows Vulnerability Let Attackers Execute Malicious Code NVIDIA has patched a critical vulnerability in its App for Windows that could allow local attackers to execute arbitrary code and escalate privileges on affected systems. Tracked as CVE-2025-23358, the flaw exists in the installer component. It poses a significant security risk to Windows users…

  • Chrome Emergency Update to Patch Multiple Vulnerabilities that Enable Remote Code Execution

    Chrome Emergency Update to Patch Multiple Vulnerabilities that Enable Remote Code Execution Google has rolled out an urgent security patch for its Chrome browser, addressing five vulnerabilities that could enable attackers to execute malicious code remotely. The update, version 142.0.7444.134/.135 for Windows, 142.0.7444.135 for macOS, and 142.0.7444.134 for Linux, targets critical flaws in core components…

  • Windows Cloud Files Mini Filter Driver Vulnerability Exploited to Escalate Privileges

    Windows Cloud Files Mini Filter Driver Vulnerability Exploited to Escalate Privileges A privilege escalation flaw in Windows Cloud Files Mini Filter Driver has been discovered, allowing local attackers to bypass file write protections and inject malicious code into system processes. Security researchers have uncovered CVE-2025-55680, a high-severity privilege-escalation vulnerability in the Windows Cloud Files Mini…

  • Jupyter Misconfiguration Flaw Allow Attackers to Escalate Privileges as Root User

    Jupyter Misconfiguration Flaw Allow Attackers to Escalate Privileges as Root User A significant security flaw in Jupyter notebook deployments could allow attackers to gain complete system control by exploiting default configurations and unauthenticated API access. Security researchers discovered that improperly configured Jupyter servers running with root privileges and disabled authentication can be leveraged to execute…

  • Apple Patches Multiple Critical Vulnerabilities in iOS 26.1 and iPadOS 26.1

    Apple Patches Multiple Critical Vulnerabilities in iOS 26.1 and iPadOS 26.1 Apple released iOS 26.1 and iPadOS 26.1, addressing multiple vulnerabilities that could lead to privacy breaches, app crashes, and potential data leaks for iPhone and iPad users. The update targets devices starting from the iPhone 11 series and various iPad models, including the iPad…

  • Hackers Actively Scanning for TCP Port 8530/8531 Linked to WSUS Vulnerability CVE-2025-59287

    Hackers Actively Scanning for TCP Port 8530/8531 Linked to WSUS Vulnerability CVE-2025-59287 Cybersecurity researchers and firewall monitoring services have detected a dramatic surge in reconnaissance activity targeting Windows Server Update Services (WSUS) infrastructure. Network sensors collected from security organizations, including data from Shadowserver, show a significant increase in scans directed at TCP ports 8530 and…

  • Windows Graphics Vulnerabilities Allow Remote Attackers to Execute Arbitrary Code

    Windows Graphics Vulnerabilities Allow Remote Attackers to Execute Arbitrary Code Multiple vulnerabilities in Microsoft’s Graphics Device Interface (GDI), a core component of the Windows operating system responsible for rendering graphics. These flaws, discovered by Check Point through an intensive fuzzing campaign targeting Enhanced Metafile (EMF) formats, could enable remote attackers to execute arbitrary code or…

  • OpenAI’s New Aardvark GPT-5 Agent that Detects and Fixes Vulnerabilities Automatically

    OpenAI’s New Aardvark GPT-5 Agent that Detects and Fixes Vulnerabilities Automatically OpenAI has unveiled Aardvark, an autonomous AI agent powered by its cutting-edge GPT-5 model, designed to detect software vulnerabilities and automatically propose fixes. This tool aims to entrust developers and security teams by scaling human-like analysis across vast codebases, addressing the escalating challenge of…

  • CISA Warns of Linux Kernel Use-After-Free Vulnerability Exploited in Attacks to Deploy Ransomware

    CISA Warns of Linux Kernel Use-After-Free Vulnerability Exploited in Attacks to Deploy Ransomware The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent alert about a critical use-after-free vulnerability in the Linux kernel, tracked as CVE-2024-1086. This vulnerability, hidden within the netfilter: nf_tables component, allows local attackers to escalate their privileges and potentially…

  • Hackers Exploiting Windows Server Update Services Flaw to Steal Sensitive Data from Organizations

    Hackers Exploiting Windows Server Update Services Flaw to Steal Sensitive Data from Organizations Windows Server Update Services (WSUS) vulnerability is actively exploited in the wild. Criminals are using this vulnerability to steal sensitive data from organizations in various industries. The vulnerability, tracked as CVE-2025-59287, was patched by Microsoft on October 14, 2025, but attackers quickly…

  • Hackers Exploiting Cisco IOS XE Vulnerability in the Wild to Deploy BADCANDY Web Shell

    Hackers Exploiting Cisco IOS XE Vulnerability in the Wild to Deploy BADCANDY Web Shell Cybercriminals and state-sponsored actors are ramping up attacks on unpatched Cisco IOS XE devices across Australia, deploying a persistent Lua-based web shell known as BADCANDY to maintain unauthorized access. This implant, first spotted in variations since October 2023, has seen renewed…

  • CISA Warns of XWiki Platform Injection vulnerability Exploited to Execute Remote Code

    CISA Warns of XWiki Platform Injection vulnerability Exploited to Execute Remote Code The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent warning about a severe injection vulnerability in the XWiki Platform, designated as CVE-2025-24893. This flaw allows unauthenticated attackers to execute arbitrary remote code, posing significant risks to organizations using the open-source…

  • CISA Shares New Threat Detections for Actively Exploited WSUS Vulnerability

    CISA Shares New Threat Detections for Actively Exploited WSUS Vulnerability In a critical update issued on October 29, 2025, the Cybersecurity and Infrastructure Security Agency (CISA) has provided organizations with enhanced guidance on detecting and mitigating threat activity related to the actively exploited CVE-2025-59287 vulnerability in Microsoft’s Windows Server Update Services (WSUS). This remote code…

  • Google Wear OS Message App Vulnerability Let Any Installed App To Send SMS Behalf Of User

    Google Wear OS Message App Vulnerability Let Any Installed App To Send SMS Behalf Of User A vulnerability in Google Messages on Wear OS devices allows any installed app to silently send SMS, MMS, or RCS messages on behalf of the user. Dubbed CVE-2025-12080, the issue stems from improper handling of ACTION_SENDTO intents using URI…

  • Magento Input Validation Vulnerability Exploited In Wild To Hijack Session And Execute Malicious Codes

    Magento Input Validation Vulnerability Exploited In Wild To Hijack Session And Execute Malicious Codes A critical vulnerability in Magento, the popular e-commerce platform, is now rebranded as Adobe Commerce. Dubbed SessionReaper and tracked as CVE-2025-54236, this improper input validation flaw allows attackers to hijack user sessions and, in some cases, execute malicious code remotely. The…

  • Apache Tomcat Security Vulnerabilities Expose Servers to Remote Code Execution Attacks

    Apache Tomcat Security Vulnerabilities Expose Servers to Remote Code Execution Attacks The Apache Software Foundation has highlighted critical flaws in Apache Tomcat, a widely used open-source Java servlet container that powers numerous web applications. On October 27, 2025, Apache disclosed two vulnerabilities, CVE-2025-55752 and CVE-2025-55754, affecting multiple versions of Tomcat. While the first poses a…

  • OpenVPN Vulnerability Exposes Linux, macOS Systems to Script Injection Attacks

    OpenVPN Vulnerability Exposes Linux, macOS Systems to Script Injection Attacks A new vulnerability in early versions of OpenVPN has been disclosed, potentially allowing malicious servers to execute arbitrary commands on client machines. The flaw affects OpenVPN releases from 2.7_alpha1 to 2.7_beta1, enabling script-injection attacks on POSIX-based systems such as Linux, macOS, and BSD variants. The…

  • Critical Dell Storage Manager Vulnerabilities Let Attackers Compromise System

    Critical Dell Storage Manager Vulnerabilities Let Attackers Compromise System Dell Technologies has disclosed three critical vulnerabilities in its Storage Manager software that could allow attackers to bypass authentication, disclose sensitive information, and gain unauthorized access to systems. Announced on October 24, 2025, these flaws affect versions of Dell Storage Manager up to 20.1.21 and pose…

  • New EDR-Redir Tool Breaks EDR Exploiting Bind Filter and Cloud Filter Driver

    New EDR-Redir Tool Breaks EDR Exploiting Bind Filter and Cloud Filter Driver A new tool called EDR-Redir has emerged, allowing attackers to redirect or isolate the executable folders of popular Endpoint Detection and Response (EDR) solutions. Demonstrated by cybersecurity researcher TwoSevenOneT, the technique leverages Windows’ Bind Filter driver (bindflt.sys) and Cloud Filter driver (cldflt.sys) to…

  • 706,000+ BIND 9 Resolver Instances Vulnerable to Cache Poisoning Exposed Online – PoC Released

    706,000+ BIND 9 Resolver Instances Vulnerable to Cache Poisoning Exposed Online – PoC Released A high-severity vulnerability in BIND 9 resolvers has been disclosed, potentially allowing attackers to poison caches and redirect internet traffic to malicious sites. Tracked as CVE-2025-40778, the flaw affects over 706,000 exposed instances worldwide, as identified by internet scanning firm Censys.…

  • CISA Warns of Hackers Actively Exploiting Windows Server Update Services RCE Vulnerability in the Wild

    CISA Warns of Hackers Actively Exploiting Windows Server Update Services RCE Vulnerability in the Wild The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has warned organizations worldwide about active exploitation of a critical remote code execution (RCE) vulnerability in Microsoft’s Windows Server Update Services (WSUS). Tracked as CVE-2025-59287, the flaw carries a CVSS score of…

  • HP OneAgent Update Brokes Trust And Disconnect Devices From Entra ID

    HP OneAgent Update Brokes Trust And Disconnect Devices From Entra ID The HP OneAgent software update has disconnected Windows devices from Microsoft Entra ID. As a result, users can no longer access their corporate identities. Version 1.2.50.9581 of the agent, pushed silently to HP’s Next Gen AI systems like the EliteBook X Flip G1i, deleted…

  • Microsoft Releases Emergency Patch For Windows Server Update Service RCE Vulnerability

    Microsoft Releases Emergency Patch For Windows Server Update Service RCE Vulnerability Microsoft has rolled out an out-of-band emergency patch for a remote code execution (RCE) vulnerability affecting the Windows Server Update Services (WSUS). Identified as CVE-2025-59287, the issue stems from the deserialization of untrusted data in a legacy serialization mechanism, allowing unauthorized attackers to execute…

  • Multiple BIND 9 DNS Vulnerabilities Enable Cache Poisoning and Denial of Service Attacks

    Multiple BIND 9 DNS Vulnerabilities Enable Cache Poisoning and Denial of Service Attacks The Internet Systems Consortium (ISC) disclosed three high-severity vulnerabilities in BIND 9 on October 22, 2025, potentially allowing remote attackers to conduct cache poisoning attacks or cause denial-of-service (DoS) conditions on affected DNS resolvers. These flaws, tracked as CVE-2025-8677, CVE-2025-40778, and CVE-2025-40780,…

  • Multiple Oracle VM VirtualBox Vulnerabilities Enables Complete Takeover Of VirtualBox

    Multiple Oracle VM VirtualBox Vulnerabilities Enables Complete Takeover Of VirtualBox Oracle has disclosed multiple critical vulnerabilities in its Oracle VM VirtualBox virtualization software, potentially allowing attackers to achieve complete control over the VirtualBox environment. These flaws, detailed in the October 2025 Critical Patch Update (CPU), affect the Core component of VirtualBox versions 7.1.12 and 7.2.2,…

  • TARmageddon Vulnerability In Rust Library Let Attackers Replace Config Files And Execute Remote Codes

    TARmageddon Vulnerability In Rust Library Let Attackers Replace Config Files And Execute Remote Codes A severe vulnerability in the async-tar Rust library and its popular forks, including the widely used tokio-tar. Dubbed TARmageddon and tracked as CVE-2025-62518, the bug carries a CVSS score of 8.1, classifying it as high severity. It allows attackers to manipulate…

  • Chrome V8 JavaScript Engine Vulnerability Let Attackers Execute Remote Code

    Chrome V8 JavaScript Engine Vulnerability Let Attackers Execute Remote Code Google has swiftly addressed a high-severity flaw in its Chrome browser’s V8 JavaScript engine, releasing an emergency update to thwart potential remote code execution attacks. The vulnerability, tracked as CVE-2025-12036, stems from an inappropriate implementation within V8, the open-source JavaScript and WebAssembly engine powering Chrome’s…

  • Critical ASP.NET Vulnerability Allows Attacker To Bypass Security Feature Remotely

    Critical ASP.NET Vulnerability Allows Attacker To Bypass Security Feature Remotely Microsoft has disclosed a serious security flaw in ASP.NET Core that enables authenticated attackers to smuggle HTTP requests and evade critical protections. Tracked as CVE-2025-55315, the vulnerability stems from inconsistent handling of HTTP requests, a classic issue known as HTTP request/response smuggling. Released on October…

  • ZYXEL Authorization Bypass Vulnerability Let Attackers View and Download System Configuration

    ZYXEL Authorization Bypass Vulnerability Let Attackers View and Download System Configuration A critical vulnerability in Zyxel’s ATP and USG series firewalls that allows attackers to bypass authorization controls and access sensitive system configurations. Dubbed CVE-2025-9133, this flaw affects devices running firmware versions up to V5.40(ABPS.0) and enables unauthorized viewing and downloading of configs even during…

  • Hackers Attacking Remote Desktop Protocol Services With 30,000+ New IP Addresses Daily

    Hackers Attacking Remote Desktop Protocol Services With 30,000+ New IP Addresses Daily A persistent campaign targeting Microsoft Remote Desktop Protocol (RDP) services, with attackers deploying over 30,000 new IP addresses daily to exploit timing-based vulnerabilities. This coordinated effort, linked to a global botnet, has seen unique IPs surge past 500,000 since September 2025, primarily aiming…

  • Dolby Digital Plus 0-Click Vulnerability Enables RCE Attack via Malicious Audio on Android

    Dolby Digital Plus 0-Click Vulnerability Enables RCE Attack via Malicious Audio on Android A critical zero-click vulnerability in Dolby Digital Plus (DDP) audio decoding software has been disclosed, allowing attackers to execute malicious code remotely via seemingly innocuous audio messages. Google Project Zero’s Ivan Fratric and Natalie Silvanovich have identified an out-of-bounds write flaw in…

  • PoC Exploit for 7-Zip Vulnerabilities that Allows Remote Code Execution

    PoC Exploit for 7-Zip Vulnerabilities that Allows Remote Code Execution A proof-of-concept exploit for two critical vulnerabilities in the popular file archiver 7-Zip, potentially allowing attackers to execute arbitrary code remotely through malicious ZIP files. The flaws, tracked as CVE-2025-11001 and CVE-2025-11002, were disclosed by the Zero Day Initiative (ZDI) on October 7, 2025, and…

  • Critical Zimbra SSRF Vulnerability Let Attackers Access Sensitive Data

    Critical Zimbra SSRF Vulnerability Let Attackers Access Sensitive Data A newly disclosed Server-Side Request Forgery (SSRF) flaw in Zimbra Collaboration Suite has raised major security concerns, prompting administrators to patch systems immediately. The issue, identified in the chat proxy configuration component, could allow attackers to gain unauthorized access to internal resources and sensitive user data.…

  • Cisco IOS and IOS XE Software Vulnerabilities Let Attackers Execute Remote Code

    Cisco IOS and IOS XE Software Vulnerabilities Let Attackers Execute Remote Code Cisco has disclosed a severe vulnerability in its widely used IOS and IOS XE Software, potentially allowing attackers to crash devices or seize full control through remote code execution. The flaw, rooted in the Simple Network Management Protocol (SNMP) subsystem, stems from a…

  • F5 Released Security Updates Covering Multiple Products Following Recent Hack

    F5 Released Security Updates Covering Multiple Products Following Recent Hack F5 Networks, a leading provider of application security and delivery solutions, has disclosed a significant security breach involving a nation-state threat actor, prompting the release of critical updates for its core products. Detected in August 2025, the incident exposed internal systems to prolonged unauthorized access,…

  • Over 269,000 F5 Devices Exposed Online After Major Breach: U.S. Faces Largest Risk

    Over 269,000 F5 Devices Exposed Online After Major Breach: U.S. Faces Largest Risk Over 269,000 F5 devices are reportedly exposed to the public internet daily, according to data from The Shadowserver Foundation. This exposure comes at a critical time following F5’s disclosure of a sophisticated nation-state attack that compromised its development environment, stealing source code…

  • Windows BitLocker Vulnerabilities Let Attackers Bypass Security Feature

    Windows BitLocker Vulnerabilities Let Attackers Bypass Security Feature Microsoft has disclosed two critical vulnerabilities in its Windows BitLocker encryption feature, allowing attackers with physical access to bypass security protections and access encrypted data. Released on October 14, 2025, as part of the latest Patch Tuesday updates, these flaws, tracked as CVE-2025-55338 and CVE-2025-55333, pose a…

  • CISA Warns Of Adobe Experience Manager Forms 0-Day Vulnerability Exploited In Attacks

    CISA Warns Of Adobe Experience Manager Forms 0-Day Vulnerability Exploited In Attacks The Cybersecurity and Infrastructure Security Agency (CISA) has issued a critical alert regarding a severe code execution vulnerability in Adobe Experience Manager Forms, urging organizations to patch immediately. Tracked as CVE-2025-54253, this flaw affects the Java Enterprise Edition (JEE) version of the software…

  • Windows Agere Modem Driver 0-Day Vulnerabilities Actively Exploited To Escalate Privileges

    Windows Agere Modem Driver 0-Day Vulnerabilities Actively Exploited To Escalate Privileges Microsoft has disclosed two critical zero-day vulnerabilities in the Agere Modem driver bundled with Windows operating systems, confirming active exploitation to escalate privileges. The flaws, tracked as CVE-2025-24990 and CVE-2025-24052, affect the ltmdm64.sys driver and could allow low-privileged attackers to gain full administrator access.…

  • Windows Remote Desktop Client Vulnerability Let Attackers Execute Remote Code

    Windows Remote Desktop Client Vulnerability Let Attackers Execute Remote Code Microsoft has patched a critical flaw in its Remote Desktop Client that could allow attackers to execute malicious code on victims’ systems. Disclosed on October 14, 2025, as CVE-2025-58718, the vulnerability stems from a use-after-free error, earning an “Important” severity rating. While not yet exploited…

  • Critical Veeam Backup RCE Vulnerabilities Let Attackers Execute Malicious Code Remotely

    Critical Veeam Backup RCE Vulnerabilities Let Attackers Execute Malicious Code Remotely Veeam Software has disclosed three serious security flaws in its Backup & Replication suite and Agent for Microsoft Windows, which enable remote code execution and privilege escalation, potentially compromising enterprise backup infrastructures. These vulnerabilities, patched in recent updates, primarily affect domain-joined systems in version…

  • Elastic Cloud Enterprise Vulnerability Let Attackers Execute Malicious Commands

    Elastic Cloud Enterprise Vulnerability Let Attackers Execute Malicious Commands Elastic has disclosed a critical vulnerability in its Elastic Cloud Enterprise (ECE) platform that allows administrators with malicious intent to execute arbitrary commands and exfiltrate sensitive data. Tracked as CVE-2025-37729 under advisory ESA-2025-21, the flaw stems from improper neutralization of special elements in the Jinjava template…

  • New PoC Exploit Released for Sudo Chroot Privilege Escalation Vulnerability

    New PoC Exploit Released for Sudo Chroot Privilege Escalation Vulnerability A critical vulnerability in the widely used Sudo utility has come under scrutiny following the public release of a proof-of-concept exploit, raising alarms for Linux system administrators worldwide. CVE-2025-32463 targets the chroot feature in Sudo versions 1.9.14 through 1.9.17, enabling local attackers to escalate privileges…

  • SonicWall SSLVPN Under Attack Following the Breach of All Customers’ Firewall Backups

    SonicWall SSLVPN Under Attack Following the Breach of All Customers’ Firewall Backups A surge in attacks targeting SonicWall SSLVPN devices, affecting numerous customer networks, just weeks after a major breach exposed sensitive firewall data. Starting October 4, 2025, threat actors have rapidly authenticated into over 100 accounts across 16 environments, using what appear to be…

  • Oracle E-Business Suite RCE Vulnerability Exposes Sensitive Data to Hackers Without Authentication

    Oracle E-Business Suite RCE Vulnerability Exposes Sensitive Data to Hackers Without Authentication Oracle has disclosed a critical vulnerability in its E-Business Suite that enables unauthenticated attackers to remotely access sensitive data, raising alarms for enterprises relying on the platform for core operations. Tracked as CVE-2025-61884, the flaw affects the Oracle Configurator component and was detailed…

  • Hackers Can Inject Malicious Code into Antivirus Processes to Create a Backdoor

    Hackers Can Inject Malicious Code into Antivirus Processes to Create a Backdoor A new technique enables attackers to exploit antivirus software by injecting harmful code directly into the antivirus processes. This approach makes it easier for them to evade detection and compromise the security that antivirus software is designed to provide. This method, detailed by…

  • Gladinet CentreStack And Triofox 0-Day RCE Vulnerability Actively Exploited In Attacks

    Gladinet CentreStack And Triofox 0-Day RCE Vulnerability Actively Exploited In Attacks An active in-the-wild exploitation of a zero-day vulnerability in Gladinet CentreStack and Triofox products. Tracked as CVE-2025-11371, the unauthenticated Local File Inclusion (LFI) flaw allows attackers to achieve remote code execution (RCE) on affected systems. The vulnerability is currently unpatched, but a mitigation has…

  • GitLab Security Update – Patch For Multiple Vulnerabilities That Enables DoS Attack

    GitLab Security Update – Patch For Multiple Vulnerabilities That Enables DoS Attack GitLab has released important security updates. The new versions are 18.4.2, 18.3.4, and 18.2.8 for both Community Edition (CE) and Enterprise Edition (EE). These updates fix several vulnerabilities that could lead to denial-of-service (DoS) attacks and allow unauthorized access. All self-managed GitLab installations…

  • Multiple Chrome Vulnerabilities Expose Users to Arbitrary Code Execution Attacks

    Multiple Chrome Vulnerabilities Expose Users to Arbitrary Code Execution Attacks Google has released Chrome version 141.0.7390.65/.66 for Windows and Mac, along with 141.0.7390.65 for Linux, addressing multiple critical security vulnerabilities that could allow attackers to execute arbitrary code on affected systems.  The update, announced on October 7, 2025, includes three significant security fixes that pose…

  • Attacks on Palo Alto PAN-OS Global Protect Login Portals Surge from 2,200 IPs

    Attacks on Palo Alto PAN-OS Global Protect Login Portals Surge from 2,200 IPs A massive escalation in attacks targeting Palo Alto Networks PAN-OS GlobalProtect login portals, with over 2,200 unique IP addresses conducting reconnaissance operations as of October 7, 2025.  This represents a significant surge from the initial 1,300 IPs observed just days earlier, marking…

  • CISA Warns of Zimbra Collaboration Suite (ZCS) XSS Zero-Day Vulnerability Actively Exploited in Attacks

    CISA Warns of Zimbra Collaboration Suite (ZCS) XSS Zero-Day Vulnerability Actively Exploited in Attacks CISA has issued a critical warning regarding a zero-day cross-site scripting (XSS) vulnerability in Synacor’s Zimbra Collaboration Suite (ZCS), designated as CVE-2025-27915.  This vulnerability has been actively exploited in attacks and poses significant risks to organizations using the popular email and…

  • CISA Warns of Windows Privilege Escalation Vulnerability Exploited in Attacks

    CISA Warns of Windows Privilege Escalation Vulnerability Exploited in Attacks CISA has issued an urgent security advisory, adding Microsoft Windows privilege escalation vulnerability CVE-2021-43226 to its Known Exploited Vulnerabilities (KEV) catalog on October 6, 2025.  The vulnerability affects the Microsoft Windows Common Log File System (CLFS) Driver and poses significant security risks to enterprise environments.…

  • Kibana Crowdstrike Connector Vulnerability Exposes Protected Credentials

    Kibana Crowdstrike Connector Vulnerability Exposes Protected Credentials Elastic has released a security advisory detailing a medium-severity vulnerability in the Kibana CrowdStrike Connector that could allow for the exposure of sensitive credentials. The flaw, tracked as CVE-2025-37728, affects multiple versions of Kibana and could allow a malicious user to access cached CrowdStrike credentials from other users…

  • Cl0p Ransomware Actively Exploiting Oracle E-Business Suite 0-Day Vulnerability in the Wild

    Cl0p Ransomware Actively Exploiting Oracle E-Business Suite 0-Day Vulnerability in the Wild Oracle has issued an emergency security alert for a critical zero-day vulnerability (CVE-2025-61882) in its E-Business Suite after the notorious Cl0p ransomware group began extorting customers who failed to patch their systems.  The vulnerability, carrying a maximum CVSS score of 9.8, affects the…

  • OpenSSH Vulnerability Exploited Via ProxyCommand to Execute Remote Code – PoC Released

    OpenSSH Vulnerability Exploited Via ProxyCommand to Execute Remote Code – PoC Released A new command injection vulnerability in OpenSSH, tracked as CVE-2025-61984, has been disclosed, which could allow an attacker to achieve remote code execution on a victim’s machine. The vulnerability is a bypass of a previous fix for a similar issue (CVE-2023-51385) and exploits…

  • QNAP NetBak Replicator Vulnerability Let Attackers Execute Unauthorized Code

    QNAP NetBak Replicator Vulnerability Let Attackers Execute Unauthorized Code QNAP has released a security advisory detailing a vulnerability in its NetBak Replicator utility that could allow local attackers to execute unauthorized code. The flaw, identified as CVE-2025-57714, has been rated as “Important” and affects specific versions of the backup and restore software. The company has…

  • Redis Server Vulnerability use-after-free Vulnerability Enables Remote Code Execution

    Redis Server Vulnerability use-after-free Vulnerability Enables Remote Code Execution A critical use-after-free vulnerability, identified as CVE-2025-49844, has been discovered in Redis servers, enabling authenticated attackers to achieve remote code execution. This high-severity flaw affects all versions of Redis that utilize the Lua scripting engine, presenting a significant threat to a wide range of deployments that…

  • PoC Exploit Released for Sudo Vulnerability that Enables Attackers to Gain Root Access

    PoC Exploit Released for Sudo Vulnerability that Enables Attackers to Gain Root Access A publicly available proof-of-concept (PoC) exploit has been released for CVE-2025-32463, a local privilege escalation (LPE) flaw in the Sudo utility that can grant root access under specific configurations.  Security researcher Rich Mirch is credited with identifying the weakness, while a functional…

  • Unity Real-Time Development Platform Vulnerability Let Attackers Execute Arbitrary Code

    Unity Real-Time Development Platform Vulnerability Let Attackers Execute Arbitrary Code Unity Technologies has issued a critical security advisory warning developers about a high-severity vulnerability affecting its widely used game development platform.  The flaw, designated CVE-2025-59489, exposes applications built with vulnerable Unity Editor versions to unsafe file loading attacks that could enable local code execution and…

  • Multiple Splunk Enterprise Vulnerabilities Let Attackers Execute Unauthorized JavaScript code

    Multiple Splunk Enterprise Vulnerabilities Let Attackers Execute Unauthorized JavaScript code Splunk has released patches for multiple vulnerabilities in its Enterprise and Cloud Platform products, some of which could allow attackers to execute unauthorized JavaScript code, access sensitive information, or cause a denial-of-service (DoS) condition. The advisories, published on October 1, 2025, detail six security flaws,…

  • Chrome Security Update – Patch for 21 Vulnerabilities that Allows Attackers to Crash Browser

    Chrome Security Update – Patch for 21 Vulnerabilities that Allows Attackers to Crash Browser Google has released Chrome 141 to address 21 security vulnerabilities, including critical flaws that could allow attackers to crash browsers and potentially execute malicious code. The update, rolling out across Windows, Mac, and Linux platforms, patches several high-severity vulnerabilities that pose…

  • 48+ Cisco Firewalls Vulnerable to Actively Exploited 0-Day Vulnerability in the Wild

    48+ Cisco Firewalls Vulnerable to Actively Exploited 0-Day Vulnerability in the Wild A critical zero-day vulnerability affecting thousands of Cisco firewalls is being actively exploited by threat actors in the wild.  The vulnerability, tracked as CVE-2025-20333, poses an immediate risk to organizations worldwide with a CVSS score of 9.9, representing one of the most severe…