Category: Vulnerability

  • F5 Patches Critical Vulnerabilities in BIG-IP, NGINX, and Related Products

    F5 Patches Critical Vulnerabilities in BIG-IP, NGINX, and Related Products F5 released its February 2026 Quarterly Security Notification on February 4, announcing several medium and low-severity CVEs, plus a security exposure affecting BIG-IP, NGINX, and container services. These issues primarily stem from denial-of-service (DoS) risks and configuration weaknesses, potentially disrupting high-traffic environments like web application…

  • Chrome Vulnerabilities Let Attackers Execute Arbitrary Code and Crash System

    Chrome Vulnerabilities Let Attackers Execute Arbitrary Code and Crash System Google has released a critical security update for the Chrome Stable channel, addressing two high-severity vulnerabilities that expose users to potential arbitrary code execution (ACE) and denial-of-service (DoS) attacks. The update pushes the browser version to 144.0.7559.132/.133 for Windows and macOS, and 144.0.7559.132 for Linux.…

  • Critical Johnson Controls Products Vulnerabilities Enables Remote SQL Injection Attacks

    Critical Johnson Controls Products Vulnerabilities Enables Remote SQL Injection Attacks A critical advisory addressing a severe SQL injection vulnerability affecting multiple Johnson Controls industrial control system products. The vulnerability, tracked as CVE-2025-26385, carries a maximum CVSS v3 severity score of 10.0, indicating the highest level of risk to affected infrastructure. The flaw stems from improper…

  • SCADA Vulnerability Triggers DoS, Potentially Disrupting Industrial Operations

    SCADA Vulnerability Triggers DoS, Potentially Disrupting Industrial Operations A medium-severity vulnerability in the Iconics Suite SCADA system that could allow attackers to trigger denial-of-service conditions on critical industrial control systems. The flaw, tracked as CVE-2025-0921, affects supervisory control and data acquisition infrastructure widely deployed across automotive, energy, and manufacturing sectors. Vulnerability Overview CVE-2025-0921 stems from…

  • Critical Solarwinds Web Vulnerability Allows Remote Code Execution and Security Bypass

    Critical Solarwinds Web Vulnerability Allows Remote Code Execution and Security Bypass Multiple critical vulnerabilities in SolarWinds Web Help Desk (WHD), culminating in unauthenticated remote code execution (RCE) via Java deserialization in CVE-2025-40551, were uncovered by Horizon3.ai researchers. These flaws chain static credentials, security bypasses, and deserialization weaknesses, affecting versions prior to 2026.1. SolarWinds WHD, an…

  • Smashing Security podcast #452: The dark web’s worst assassins, and Pegasus in the dock

    Smashing Security podcast #452: The dark web’s worst assassins, and Pegasus in the dock In episode 452, a London-based YouTuber wins a landmark court case against Saudi Arabia after his phone was hacked with Pegasus spyware — exposing how a single, seemingly harmless text message can turn a smartphone into a round-the-clock surveillance device. Plus,…

  • New Instagram Vulnerability Exposes Private Posts to Anyone

    New Instagram Vulnerability Exposes Private Posts to Anyone A critical server-side vulnerability in Instagram’s infrastructure allowed unauthenticated attackers to access private photos and captions without a login or follower relationship, according to a disclosure released this week by security researcher Jatin Banga. The vulnerability, which was reportedly patched silently by Meta in October 2025, relied…

  • Hackers Exploiting telnetd Vulnerability for Root Access – Public PoC Released

    Hackers Exploiting telnetd Vulnerability for Root Access – Public PoC Released Active exploitation of a critical authentication bypass vulnerability in the GNU InetUtils telnetd server (CVE-2026-24061) has been observed in the wild, allowing unauthenticated attackers to gain root access to Linux systems. The vulnerability, which affects GNU InetUtils versions 1.9.3 through 2.7, enables remote code…

  • Cisco Unified Communications 0-day RCE Vulnerability Exploited in the Wild to Gain Root Access

    Cisco Unified Communications 0-day RCE Vulnerability Exploited in the Wild to Gain Root Access Cisco has disclosed a critical zero-day remote code execution (RCE) vulnerability, CVE-2026-20045, actively exploited in the wild. Affecting key Unified Communications products, this flaw allows unauthenticated attackers to run arbitrary commands on the underlying OS, potentially gaining root access. The Cisco…

  • Fortinet SSO Vulnerability Actively Exploited to Hack Firewalls and Gain Admin Access

    Fortinet SSO Vulnerability Actively Exploited to Hack Firewalls and Gain Admin Access A critical vulnerability in Fortinet’s Single Sign-On (SSO) feature for FortiGate firewalls, tracked as CVE-2025-59718, is under active exploitation. Attackers are leveraging it to create unauthorized local admin accounts, granting full administrative access to internet-exposed devices. Multiple users have reported identical attack patterns,…

  • Smashing Security podcast #451: I hacked the government, and your headphones are next

    Smashing Security podcast #451: I hacked the government, and your headphones are next In episode 451 of “Smashing Security,” we meet the cybercriminal who hacked the US Supreme Court, Veterans Affairs, and more – and then helpfully posted screenshots (and even someone’s blood type) on an account called “I hacked the government.” Plus we discuss…

  • Critical Oracle WebLogic Server Proxy Vulnerability Lets Attackers Compromise the Server

    Critical Oracle WebLogic Server Proxy Vulnerability Lets Attackers Compromise the Server Oracle has disclosed a severe security vulnerability affecting its Fusion Middleware suite, specifically targeting the Oracle HTTP Server and the Oracle WebLogic Server Proxy Plug-in. Assigned CVE-2026-21962, this flaw carries the maximum severity rating and poses an immediate threat to enterprise environments that use…

  • Azure Private Endpoint Deployments Exposes Azure Resources to DoS Attack

    Azure Private Endpoint Deployments Exposes Azure Resources to DoS Attack A critical architectural flaw in Microsoft Azure’s Private Endpoint implementation that enables denial-of-service (DoS) attacks against production Azure resources. The vulnerability affects over 5% of Azure storage accounts, exposing organizations to service disruptions across Key Vault, CosmosDB, Azure Container Registry, Function Apps, and OpenAI accounts.…

  • Windows SMB Client Vulnerability Enables Attacker to Own Active Directory

    Windows SMB Client Vulnerability Enables Attacker to Own Active Directory A critical vulnerability in Windows SMB client authentication that enables attackers to compromise Active Directory environments through NTLM reflection exploitation. Classified as an improper access control vulnerability, this vulnerability allows authorized attackers to escalate privileges via carefully orchestrated authentication relay attacks over network connections. Seven…

  • Mandiant Releases Rainbow Tables Enabling NTLMv1 Admin Password Hacking

    Mandiant Releases Rainbow Tables Enabling NTLMv1 Admin Password Hacking Google-owned Mandiant has publicly released a comprehensive dataset of Net-NTLMv1 rainbow tables, marking a significant escalation in demonstrating the security risks of legacy authentication protocols. The release underscores an urgent message: organizations must immediately migrate away from Net-NTLMv1, a deprecated protocol that has been cryptographically broken…

  • Go 1.25.6 and 1.24.12 Patch Critical Vulnerabilities Lead to DoS and Memory Exhaustion Risks

    Go 1.25.6 and 1.24.12 Patch Critical Vulnerabilities Lead to DoS and Memory Exhaustion Risks The Go programming language team has rolled out emergency point releases, Go 1.25.6 and 1.24.12, to address six high-impact security flaws. These updates fix denial-of-service (DoS) vectors, arbitrary code execution risks, and TLS mishandlings that could expose developers to remote attacks.…

  • Fortinet FortiSIEM Vulnerability CVE-2025-64155 Actively Exploited in Attacks

    Fortinet FortiSIEM Vulnerability CVE-2025-64155 Actively Exploited in Attacks Fortinet FortiSIEM vulnerability CVE-2025-64155 is under active exploitation, as confirmed by Defused through their honeypot deployments. This critical OS command injection flaw enables unauthenticated remote code execution, posing severe risks to enterprise security monitoring systems. CVE-2025-64155 stems from improper neutralization of special elements in OS commands within…

  • Microsoft SQL Server Vulnerability Allows Attackers to Elevate Privileges over a Network

    Microsoft SQL Server Vulnerability Allows Attackers to Elevate Privileges over a Network Microsoft released security updates on January 13, 2026, addressing a critical elevation of privilege vulnerability in SQL Server that enables authorized attackers to bypass authentication controls and gain elevated system privileges remotely. Tracked as CVE-2026-20803, the vulnerability stems from missing authentication mechanisms for…

  • New Angular Vulnerability Enables an Attacker to Execute Malicious Payload

    New Angular Vulnerability Enables an Attacker to Execute Malicious Payload A critical Cross-Site Scripting (XSS) vulnerability has been discovered in Angular’s Template Compiler, affecting multiple versions of both @angular/compiler and @angular/core packages. Tracked as CVE-2026-22610, this vulnerability allows attackers to bypass Angular’s built-in security protections and execute arbitrary JavaScript code within victim browsers. The Vulnerability…

  • Multiple Hikvision Vulnerabilities Let Attackers Cause Device Malfunction Using Crafted Packets

    Multiple Hikvision Vulnerabilities Let Attackers Cause Device Malfunction Using Crafted Packets Hikvision, a leading provider of surveillance and access control systems, faces serious security risks from two newly disclosed stack overflow vulnerabilities. These flaws, tracked as CVE-2025-66176 and CVE-2025-66177, allow attackers on the same local area network (LAN) to trigger device malfunctions by sending specially…

  • Critical Zlib Vulnerability Let Attackers Trigger Buffer Overflow by Invoking untgz

    Critical Zlib Vulnerability Let Attackers Trigger Buffer Overflow by Invoking untgz A severe global buffer overflow vulnerability has been discovered in the zlib untgz utility version 1.3.1.2. Allowing attackers to corrupt memory and potentially execute malicious code through specially crafted command-line input.​ The security flaw resides in the TGZfname() function of the untgz utility, where…

  • Phishing Campaign Uses Maduro Arrest Story to Deliver Backdoor Malware

    Phishing Campaign Uses Maduro Arrest Story to Deliver Backdoor Malware Cybercriminals are leveraging the recent arrest of Venezuelan President Nicolás Maduro to distribute sophisticated backdoor malware. The threat actors exploited news surrounding Maduro’s arrest on January 3, 2025, demonstrating how geopolitical events continue to serve as effective lures for malicious campaigns. The attack likely begins…

  • pcTattletale founder pleads guilty in rare stalkerware prosecution

    pcTattletale founder pleads guilty in rare stalkerware prosecution The founder of a spyware company that encouraged customers to secretly monitor their romantic partners has pleaded guilty to federal charges – marking one of the few successful US prosecutions of a stalkerware operator. Read more in my article on the Hot for Security blog. Graham Cluley…

  • SmarterTools SmarterMail Vulnerability Enables Remote Code Execution Attack – PoC Released

    SmarterTools SmarterMail Vulnerability Enables Remote Code Execution Attack – PoC Released A critical pre-authentication remote code execution vulnerability, identified as CVE-2025-52691, has been discovered in SmarterTools’ SmarterMail solution. The flaw received a maximum CVSS score of 10.0, indicating its severe nature and potential impact on affected systems. SmarterTools describes SmarterMail as “a secure, all-in-one business…

  • Linux Battery Utility Flaw Lets Hackers Bypass Authentication and Tamper System Settings

    Linux Battery Utility Flaw Lets Hackers Bypass Authentication and Tamper System Settings A critical security vulnerability has been discovered in TLP, a widely used Linux laptop battery optimization utility, allowing local attackers to bypass authentication controls and manipulate system power settings without authorization. Security researchers from openSUSE identified a severe authentication bypass flaw in the…

  • Forcepoint DLP Vulnerability Enables Memory Manipulation and Arbitrary Code Execution

    Forcepoint DLP Vulnerability Enables Memory Manipulation and Arbitrary Code Execution A critical security flaw in Forcepoint One DLP Client has been disclosed, allowing attackers to bypass vendor-implemented Python restrictions and execute arbitrary code on enterprise endpoints. The vulnerability, tracked as CVE-2025-14026, undermines the data loss prevention security controls designed to protect sensitive organizational data. The…

  • 10 Best Vulnerability Assessment and Penetration Testing (VAPT) Tools in 2026

    10 Best Vulnerability Assessment and Penetration Testing (VAPT) Tools in 2026 Vulnerability Assessment and Penetration Testing (VAPT) tools form the cornerstone of any cybersecurity toolkit, enabling organizations to identify, analyze, and remediate vulnerabilities across systems, networks, applications, and IT infrastructure. These tools empower proactive security by exposing weaknesses and attack vectors before threat actors can…

  • Eaton Vulnerabilities Let Attackers Execute Arbitrary Code On the Host System

    Eaton Vulnerabilities Let Attackers Execute Arbitrary Code On the Host System A critical security advisory addressing multiple vulnerabilities discovered in the Eaton UPS Companion (EUC) software. These security flaws, if exploited, could allow attackers to execute arbitrary code on the host system, potentially giving them complete control over affected devices. The advisory, identified as ETN-VA-2025-1026, highlights…

  • GHOSTCREW – AI-based Red Team Toolkit for Penetration Testing Invoking Metasploit, Nmap and Other Tools

    GHOSTCREW – AI-based Red Team Toolkit for Penetration Testing Invoking Metasploit, Nmap and Other Tools GHOSTCREW emerges as a game-changing open-source toolkit for red teamers and penetration testers. This AI-powered assistant leverages large language models, integrates the MCP protocol, and supports the optional RAG architecture to orchestrate security tools via natural-language prompts.​ Developed by GH05TCREW,…

  • Infostealers Enable Attackers to Hijack Legitimate Business Infrastructure for Malware Hosting

    Infostealers Enable Attackers to Hijack Legitimate Business Infrastructure for Malware Hosting A dangerous cybercrime feedback loop has emerged where stolen credentials from infostealer malware enable attackers to hijack legitimate business websites and turn them into malware distribution platforms. Recent research by the Hudson Rock Threat Intelligence Team reveals this self-sustaining cycle transforms victims into unwitting…

  • Lessons From Mongobleed Vulnerability (CVE-2025-14847) That Actively Exploited In The Wild

    Lessons From Mongobleed Vulnerability (CVE-2025-14847) That Actively Exploited In The Wild The cybersecurity community was alarmed in late December 2025 when MongoDB announced a serious vulnerability called “Mongobleed” (CVE-2025-14847). This high-severity flaw allows unauthenticated attackers to steal sensitive data directly from server memory. With a CVSS score of 8.7 and over 87,000 potentially vulnerable MongoDB…

  • Apache NuttX Vulnerability Let Attackers to Crash Systems

    Apache NuttX Vulnerability Let Attackers to Crash Systems A newly disclosed use-after-free vulnerability in Apache NuttX RTOS could allow attackers to cause system crashes and unintended filesystem operations, prompting urgent security warnings for users running network-exposed services. The flaw, tracked as CVE-2025-48769 and rated moderate in severity, affects a wide range of NuttX versions and…

  • Critical IBM API Connect Vulnerability Let Attackers Bypass Logins

    Critical IBM API Connect Vulnerability Let Attackers Bypass Logins A critical security alert regarding a severe vulnerability in the IBM API Connect platform that could allow remote attackers to bypass authentication mechanisms. Discovered during internal testing, the flaw poses a significant risk to organizations relying on the platform for API management. It grants unauthorized actors…

  • Critical Apache StreamPipes Vulnerability Let Attackers Seize Admin Control

    Critical Apache StreamPipes Vulnerability Let Attackers Seize Admin Control A security patch addressing a critical privilege escalation vulnerability that allows unauthorized users to gain administrative access to the data streaming platform. The flaw, tracked as CVE-2025-47411 and rated important, affects Apache StreamPipes versions 0.69.0 through 0.97.0. The vulnerability stems from a flawed user ID creation…

  • MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

    MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847) An open-source detection tool to help organizations identify potential exploitation of MongoBleed (CVE-2025-14847), a critical memory disclosure vulnerability affecting MongoDB databases.​ The vulnerability allows attackers to extract sensitive information, including credentials, session tokens, and personally identifiable information, directly from server memory without requiring authentication. The flaw exists…

  • MongoBleed (CVE-2025-14847) Now Exploited in the Wild: MongoDB Servers at Critical Risk

    MongoBleed (CVE-2025-14847) Now Exploited in the Wild: MongoDB Servers at Critical Risk A high-severity unauthenticated information-leak vulnerability in MongoDB Server, dubbed MongoBleed after the infamous Heartbleed bug, is now being actively exploited in real-world attacks. MongoDB has disclosed CVE-2025-14847, a critical flaw affecting multiple supported and legacy server versions that allows unauthenticated remote attackers to…

  • 87,000+ MongoDB Instances Vulnerable to MongoBleed Flaw Exposed Online – PoC Exploit Released

    87,000+ MongoDB Instances Vulnerable to MongoBleed Flaw Exposed Online – PoC Exploit Released A high-severity vulnerability in MongoDB Server that allows unauthenticated remote attackers to siphon sensitive data from database memory. Dubbed “MongoBleed” due to its automated similarities to the infamous Heartbleed bug, the flaw tracks as CVE-2025-14847 and carries a CVSS score of 7.5.…

  • TeamViewer DEX Vulnerabilities Let Attackers Trigger DoS Attack and Expose Sensitive Data

    TeamViewer DEX Vulnerabilities Let Attackers Trigger DoS Attack and Expose Sensitive Data Multiple critical vulnerabilities in TeamViewer DEX Client’s Content Distribution Service (NomadBranch.exe), formerly part of 1E Client. Affecting Windows versions before 25.11 and select older branches, the flaws stem from improper input validation (CWE-20), potentially enabling attackers on the local network to execute code,…

  • M-Files Vulnerability Let Attacker Capture Session Tokens of Other Active Users

    M-Files Vulnerability Let Attacker Capture Session Tokens of Other Active Users An information disclosure vulnerability in M-Files Server enables authenticated attackers to capture and reuse session tokens from active users. Potentially gaining unauthorized access to sensitive document management systems. The flaw, tracked as CVE-2025-13008, affects multiple versions across different release branches and carries a high-severity…

  • Net-SNMP Vulnerability Enables Buffer Overflow and the Daemon to Crash

    Net-SNMP Vulnerability Enables Buffer Overflow and the Daemon to Crash A new critical vulnerability affecting the Net-SNMP software suite has been disclosed, posing a significant risk to network infrastructure worldwide. Tracked as CVE-2025-68615, this security flaw allows remote attackers to trigger a buffer overflow, leading to a service crash or potentially a more severe system compromise.…

  • CISA Adds Digiever Authorization Vulnerability to KEV List Following Active Exploitation

    CISA Adds Digiever Authorization Vulnerability to KEV List Following Active Exploitation A critical vulnerability affecting Digiever DS-2105 Pro network video recorders was added to the Known Exploited Vulnerabilities (KEV) catalog on December 22, 2025, following evidence of active exploitation in the wild. CVE-2023-52163 is a missing authorization vulnerability in Digiever DS-2105 Pro devices. That enables…

  • Cybersecurity Weekly Recap – PornHub Breach, Cisco 0-Day, Amazon Detains DPRK IT Worker, and more

    Cybersecurity Weekly Recap – PornHub Breach, Cisco 0-Day, Amazon Detains DPRK IT Worker, and more In a week that revealed the flaws in digital trust, cybersecurity headlines were filled with high-profile breaches, zero-day exploits, and bold nation-state espionage. Attackers claimed to have swiped usernames, emails, and encrypted passwords from over 1.2 million accounts, underscoring the…

  • Hackers Weaponize SVG Files and Office Documents to Target Windows Users

    Hackers Weaponize SVG Files and Office Documents to Target Windows Users Cybersecurity researchers have uncovered a sophisticated email campaign deploying a commodity loader to distribute Remote Access Trojans and information stealers. The operation primarily targets manufacturing and government organizations across Italy, Finland, and Saudi Arabia, using highly evasive techniques. Infection chain Multi-Vector Attack Strategy The…

  • WatchGuard 0-day Vulnerability Exploited in the Wild to Hijack Firewalls

    WatchGuard 0-day Vulnerability Exploited in the Wild to Hijack Firewalls An urgent security update has been released to fix a critical zero-day vulnerability in WatchGuard Firebox firewalls. With warnings that hackers are already actively exploiting the flaw in the wild to take control of affected devices. The vulnerability, tracked as CVE-2025-14733, carries a critical severity score…

  • Cisco AsyncOS 0-Day Vulnerability Exploited in the Wild to run System-level Commands

    Cisco AsyncOS 0-Day Vulnerability Exploited in the Wild to run System-level Commands An active campaign exploiting a zero-day vulnerability in Cisco AsyncOS Software, targeting Secure Email Gateway (formerly Email Security Appliance, ESA) and Secure Email and Web Manager (formerly Content Security Management Appliance, SMA). The attack, spotted since late November 2025 and publicly disclosed on…

  • Smashing Security podcast #448: The Kindle that got pwned

    Smashing Security podcast #448: The Kindle that got pwned Think your Kindle is harmless? Think again! In this episode, we unpack a Black Hat Europe talk revealing how a boobytrapped audiobook could exploit the Amazon eBook reader – potentially letting an attacker break into your account and seize control of your credit card. Plus a…

  • Critical FortiGate Devices SSO Vulnerabilities Actively Exploited in the Wild

    Critical FortiGate Devices SSO Vulnerabilities Actively Exploited in the Wild An active intrusion is targeting critical authentication bypass vulnerabilities in Fortinet’s FortiGate appliances and related products. Threat actors are exploiting CVE-2025-59718 and CVE-2025-59719 to perform unauthenticated single sign-on (SSO) logins via malicious SAML messages, granting attackers administrative access. Fortinet disclosed the flaws in a PSIRT…

  • Windows Remote Access Connection Manager Vulnerability Enables Arbitrary Code Execution

    Windows Remote Access Connection Manager Vulnerability Enables Arbitrary Code Execution A critical security issue involving the Windows Remote Access Connection Manager (RasMan) that allows local attackers to execute arbitrary code with System privileges. While investigating CVE-2025-59230, the vulnerability that Microsoft addressed in the October 2025 security updates. 0patch security analysts discovered a complex exploit chain that…

  • CISA Adds Sierra Router Vulnerability to KEV Catalogue Following Active Exploitation

    CISA Adds Sierra Router Vulnerability to KEV Catalogue Following Active Exploitation A critical vulnerability affecting Sierra Wireless routers has been added to its Known Exploited Vulnerabilities (KEV) catalog. This decision comes after evidence emerged that the flaw is being actively exploited in the wild. Posing significant risks to organizations that still utilize these legacy devices.…

  • CISA Warns of Windows Cloud Files Mini Filter 0-Day Vulnerability Exploited in Attacks

    CISA Warns of Windows Cloud Files Mini Filter 0-Day Vulnerability Exploited in Attacks A critical alert regarding an active zero-day vulnerability affecting the Microsoft Windows Cloud Files Mini Filter Driver. The vulnerability poses a significant risk to organizations running affected Windows systems and requires immediate remediation efforts. CISA reports that the vulnerability, tracked as CVE-2025-62221,…

  • Google Warns Multiple Hacker Groups Are Exploiting React2Shell to Spread Malware

    Google Warns Multiple Hacker Groups Are Exploiting React2Shell to Spread Malware Google Threat Intelligence Group (GTIG) has issued a warning regarding the widespread exploitation of a critical security flaw in React Server Components. Known as React2Shell (CVE-2025-55182), this vulnerability allows attackers to take control of servers remotely without needing a password. Since the vulnerability was disclosed…

  • CISA Warns of Google Chromium 0-Day Vulnerability Exploited in Attacks

    CISA Warns of Google Chromium 0-Day Vulnerability Exploited in Attacks The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical zero-day vulnerability in Google Chromium’s ANGLE graphics engine to its Known Exploited Vulnerabilities (KEV) catalog. Tracked as CVE-2025-14174, the flaw allows remote attackers to trigger out-of-bounds memory access via a malicious HTML page,…

  • Apple 0-Day Vulnerabilities Exploited in Sophisticated Attacks Targeting iPhone Users

    Apple 0-Day Vulnerabilities Exploited in Sophisticated Attacks Targeting iPhone Users Apple patches two WebKit zero-day flaws actively exploited in sophisticated attacks targeting specific iPhone users running iOS versions prior to 26.​ The iOS 26.2 and iPadOS 26.2 updates, released December 12, 2025, address CVE-2025-43529 and CVE-2025-14174 in WebKit. CVE-2025-43529 involves a use-after-free vulnerability enabling arbitrary…

  • Apache Struts 2 DoS Vulnerability Let Attackers Crash Server

    Apache Struts 2 DoS Vulnerability Let Attackers Crash Server A critical denial-of-service vulnerability has been discovered in Apache Struts 2, affecting multiple versions of the popular web application framework. The vulnerability, identified as CVE-2025-64775, exploits a file leak in multipart request processing that can cause disk exhaustion and server crashes. Organizations running affected versions should…

  • CISA Warns of OSGeo GeoServer 0-Day Vulnerability Exploited in Attacks

    CISA Warns of OSGeo GeoServer 0-Day Vulnerability Exploited in Attacks An urgent warning about a critical security flaw in OSGeo GeoServer, a widely used open-source geographic data-sharing server. CISA has added the vulnerability to its Known Exploited Vulnerabilities (KEV) catalog, indicating that threat actors are actively leveraging this zero-day flaw in attacks targeting both public…

  • New Vulnerabilities in React Server Components Allow DoS Attacks and Source Code Leaks

    New Vulnerabilities in React Server Components Allow DoS Attacks and Source Code Leaks Less than a week after addressing a critical Remote Code Execution (RCE) vulnerability, the React team has disclosed three additional security flaws affecting React Server Components (RSC). Security researchers discovered these new issues while attempting to bypass the mitigations for the previous…

  • React2Shell flaw (CVE-2025-55182) exploited for remote code execution

    React2Shell flaw (CVE-2025-55182) exploited for remote code execution The availability of exploit code will likely lead to more widespread opportunistic attacks Mindi McDowell Go to sophos

  • Windows Defender Firewall Service Vulnerability Let Attackers Disclose Sensitive Data

    Windows Defender Firewall Service Vulnerability Let Attackers Disclose Sensitive Data A critical information disclosure vulnerability in Windows Defender Firewall Service, which could allow authorized attackers to access sensitive heap memory on affected systems. The vulnerability, tracked as CVE-2025-62468, was assigned an Important severity rating and released on December 9, 2025. The flaw stems from an…

  • Google Warns of Chrome 0-Day Vulnerability Actively Exploited in the wild

    Google Warns of Chrome 0-Day Vulnerability Actively Exploited in the wild Google has released an urgent security update for the Chrome browser to address a high-severity zero-day vulnerability that is currently being exploited in the wild. This emergency patch is part of the latest Stable channel update, bringing the version to 143.0.7499.109/.110 for Windows and…

  • Smashing Security podcast #447: Grok the stalker, the Louvre heist, and Microsoft 365 mayhem

    Smashing Security podcast #447: Grok the stalker, the Louvre heist, and Microsoft 365 mayhem On this week’s show we learn that AI really can be a stalker’s best friend, as we explore a strange tale that starts with a manatee-shaped mailbox on a millionaire’s lawn and ends with Grok happily doxxing real people, mapping out…

  • Windows PowerShell 0-Day Vulnerability Let Attackers Execute Malicious Code

    Windows PowerShell 0-Day Vulnerability Let Attackers Execute Malicious Code Security update addressing a dangerous Windows PowerShell vulnerability that allows attackers to execute malicious code on affected systems. The vulnerability, tracked as CVE-2025-54100, was publicly disclosed on December 9, 2025, and represents a significant security risk for organizations worldwide. The flaw stems from improper neutralization of…

  • Gemini Zero-Click Vulnerability Let Attackers Access Gmail, Calendar, and Docs

    Gemini Zero-Click Vulnerability Let Attackers Access Gmail, Calendar, and Docs A critical zero-click vulnerability dubbed “GeminiJack” in Google Gemini Enterprise and previously Vertex AI Search that let attackers steal sensitive corporate data from Gmail, Calendar, and Docs with minimal effort. According to Noma Labs, it was considered an architectural flaw rather than merely a bug.…

  • Windows Cloud Files Mini Filter Driver 0-Day Vulnerability Exploited in the Wild

    Windows Cloud Files Mini Filter Driver 0-Day Vulnerability Exploited in the Wild Microsoft has released urgent security updates to address a zero-day vulnerability in the Windows Cloud Files Mini Filter Driver (cldflt.sys) that is currently being exploited in the wild. Assigned the identifier CVE-2025-62221, this elevation of privilege flaw affects a wide range of Windows…

  • 500+ Apache Tika Toolkit Instances Vulnerable to Critical XXE Attack Exposed Online

    500+ Apache Tika Toolkit Instances Vulnerable to Critical XXE Attack Exposed Online Over 565 internet-exposed Apache Tika Server instances are vulnerable to a critical XML External Entity (XXE) injection flaw. That could enable attackers to steal sensitive data, launch denial-of-service attacks, or conduct server-side request forgery operations. The vulnerability, tracked as CVE-2025-66516, affects tika-core versions…

  • Researchers Hack Google’s Gemini CLI Through Prompt Injections in GitHub Actions

    Researchers Hack Google’s Gemini CLI Through Prompt Injections in GitHub Actions A critical vulnerability class dubbed “PromptPwnd,” affects AI agents integrated into GitHub Actions and GitLab CI/CD pipelines. This flaw allows attackers to inject malicious prompts via untrusted user inputs like issue titles or pull request bodies, tricking AI models into executing privileged commands that…

  • Cloudflare Outage Hits Internet with 500 Internal Server Error

    Cloudflare Outage Hits Internet with 500 Internal Server Error Cloudflare has confirmed that it is currently experiencing a significant outage that is affecting the Cloudflare Dashboard and several Cloudflare API services. The issue began earlier today and has caused widespread disruptions for users who rely on Cloudflare’s management tools and automation features. According to Cloudflare,…

  • Cacti Command Injection Vulnerability Let Attackers Execute Malicious Code Remotely

    Cacti Command Injection Vulnerability Let Attackers Execute Malicious Code Remotely A critical command injection vulnerability in the open-source network monitoring tool Cacti allows authenticated attackers to execute arbitrary code remotely, potentially compromising the entire monitoring infrastructure. The flaw, tracked as CVE-2025-66399, affects all versions up to 1.2.28 and stems from inadequate input validation in the…

  • Vim for Windows Vulnerability Let Attackers Execute Arbitrary Code

    Vim for Windows Vulnerability Let Attackers Execute Arbitrary Code A critical security vulnerability has been discovered in Vim for Windows that could allow attackers to execute malicious code on users’ computers. The vulnerability, identified as CVE-2025-66476, affects Vim versions before 9.1.1947 and has been rated high severity, with a CVSS score of 7.8. The flaw…

  • Akamai Patches HTTP Request Smuggling Vulnerability in Edge Servers

    Akamai Patches HTTP Request Smuggling Vulnerability in Edge Servers A critical HTTP request smuggling vulnerability in Akamai’s edge server infrastructure has been successfully fixed. The vulnerability, identified as CVE-2025-66373, stemmed from improper processing of HTTP requests containing invalid chunk-encoded bodies, potentially exposing thousands of customers to sophisticated attacks. Understanding HTTP Chunked Transfer Encoding HTTP chunked…

  • Chrome 143 Released With Fix for 13 Vulnerabilities that Enable Arbitrary Code Execution

    Chrome 143 Released With Fix for 13 Vulnerabilities that Enable Arbitrary Code Execution Google has officially promoted Chrome 143 to the Stable channel, rolling out version 143.0.7499.40 for Linux and 143.0.7499.40/41 for Windows and Mac. This significant update addresses 13 security vulnerabilities, including several high-severity flaws that could allow attackers to execute arbitrary code or…

  • OpenVPN Vulnerabilities Let Hackers Triggers Dos Attack and Bypass Security Checks

    OpenVPN Vulnerabilities Let Hackers Triggers Dos Attack and Bypass Security Checks OpenVPN has released critical security updates for its 2.6 stable and 2.7 development branches, addressing three vulnerabilities that could lead to local denial-of-service (DoS), security bypasses, and buffer over-reads. The patches, included in the newly released version 2.6.17 and 2.7_rc3, fix issues ranging from…

  • Tor Adopts Galois Onion Encryption to Strengthen Defense Against Online Attacks

    Tor Adopts Galois Onion Encryption to Strengthen Defense Against Online Attacks The Tor Project has announced a significant cryptographic overhaul, retiring its legacy relay encryption algorithm after decades of service and replacing it with Counter Galois Onion (CGO). This research-backed encryption design defends against a broader class of sophisticated online attackers. Tor’s relay encryption serves…

  • ASUS MyASUS Flaw Lets Hackers Escalate to SYSTEM-Level Access

    ASUS MyASUS Flaw Lets Hackers Escalate to SYSTEM-Level Access ASUS has disclosed a high security vulnerability in its MyASUS application that could allow local attackers to escalate their privileges to SYSTEM-level access on affected Windows devices. The flaw, tracked as CVE-2025-59373, carries a high-severity CVSS 4.0 score of 8.5, indicating a significant risk to millions…

  • The AI Fix #78: The big AI bubble, and robot Grandma in the cloud

    The AI Fix #78: The big AI bubble, and robot Grandma in the cloud In episode 78 of The AI Fix, alien robot spiders invade Antarctica (or Facebook says they do), Mark prepares humanity for AI-powered fighter jets with loyalty issues, and Graham tries to work out why his AI-generated country music career hasn’t yet…

  • Microsoft’s Update Health Tools Configuration Vulnerability Let Attackers Execute Arbitrary Code Remotely

    Microsoft’s Update Health Tools Configuration Vulnerability Let Attackers Execute Arbitrary Code Remotely A critical remote code execution (RCE) vulnerability in Microsoft’s Update Health Tools (KB4023057). A widely deployed Windows component designed to expedite security updates through Intune. The flaw stems from the tool connecting to dropped Azure Blob storage accounts that attackers could register and control.​ How…

  • Wireshark Vulnerabilities Let Attackers Crash by Injecting a Malformed Packet

    Wireshark Vulnerabilities Let Attackers Crash by Injecting a Malformed Packet The Wireshark Foundation has rolled out a crucial security update for its widely used network protocol analyzer, addressing multiple vulnerabilities that could lead to denial-of-service conditions. The latest release, version 4.6.1, specifically targets flaws discovered in the Bundle Protocol version 7 (BPv7) and Kafka dissectors.…

  • SonicOS SSLVPN Vulnerability Let Attackers Crash the Firewall Remotely

    SonicOS SSLVPN Vulnerability Let Attackers Crash the Firewall Remotely SonicWall has disclosed a critical stack-based buffer overflow vulnerability in its SonicOS SSLVPN service. That allows remote unauthenticated attackers to crash firewalls through denial-of-service attacks. The vulnerability was internally discovered and reported by SonicWall’s security team. The flaw, tracked as CVE-2025-40601, carries a CVSS score of 7.5…

  • CISA Warns of Critical Lynx+ Gateway Vulnerability Exposes Data in Cleartext

    CISA Warns of Critical Lynx+ Gateway Vulnerability Exposes Data in Cleartext The Cybersecurity and Infrastructure Security Agency (CISA) has issued a critical warning about a severe vulnerability in Lynx+ Gateway devices that could expose sensitive information in clear text during transmission. The flaw allows attackers to catch network traffic and obtain plaintext credentials and other…

  • Critical pgAdmin4 Vulnerability Lets Attackers Execute Remote Code on Servers

    Critical pgAdmin4 Vulnerability Lets Attackers Execute Remote Code on Servers A severe remote code execution (RCE) flaw has been uncovered in pgAdmin4, the popular open-source interface for PostgreSQL databases. Dubbed CVE-2025-12762, the vulnerability affects versions up to 9.9 and could allow attackers to run arbitrary commands on the hosting server, potentially compromising entire database infrastructures.…

  • OpenAI Sora 2 Vulnerability Exposes System Prompts via Audio Transcripts

    OpenAI Sora 2 Vulnerability Exposes System Prompts via Audio Transcripts A vulnerability in OpenAI’s advanced video generation model, Sora 2, that enables the extraction of its hidden system prompt through audio transcripts, raising concerns about the security of multimodal AI systems. This vulnerability, detailed in a blog post by AI security firm Mindgard, demonstrates how…

  • ChatGPT Hacked Using Custom GPTs Exploiting SSRF Vulnerability to Expose Secrets

    ChatGPT Hacked Using Custom GPTs Exploiting SSRF Vulnerability to Expose Secrets A Server-Side Request Forgery (SSRF) vulnerability in OpenAI’s ChatGPT. The flaw, lurking in the Custom GPT “Actions” feature, allowed attackers to trick the system into accessing internal cloud metadata, potentially exposing sensitive Azure credentials. The bug, discovered by Open Security during casual experimentation, highlights…

  • SecureVibes – AI Tool Scans for Vulnerabilities in 11 Languages with Claude AI Agents

    SecureVibes – AI Tool Scans for Vulnerabilities in 11 Languages with Claude AI Agents In the fast-paced world of “vibecoding,” where developers use AI to build applications rapidly, a new open-source tool is stepping up to tackle security risks. SecureVibes, created by developer Anshuman Bhartiya, leverages Anthropic’s Claude AI through a multi-agent system to detect…

  • Windows Remote Desktop Services Vulnerability Let Attackers Escalate Privileges

    Windows Remote Desktop Services Vulnerability Let Attackers Escalate Privileges Microsoft has disclosed a significant vulnerability in Windows Remote Desktop Services (RDS) that could allow authorized attackers to escalate their privileges on affected systems. Tracked as CVE-2025-60703, the flaw stems from an untrusted pointer dereference, a classic memory safety issue that has plagued software for years, and…

  • Zoom Vulnerabilities Let Attackers Bypass Access Controls to Access Session Data

    Zoom Vulnerabilities Let Attackers Bypass Access Controls to Access Session Data Zoom has issued multiple security bulletins detailing patches for several vulnerabilities affecting its Workplace applications. The disclosures, published today, highlight two high-severity issues alongside medium-rated flaws, underscoring the ongoing challenges in securing video conferencing tools used by millions in hybrid work environments. These updates…

  • SAP Security Update – Patch for Critical Vulnerabilities Allowing Code Execution and Injection Attacks

    SAP Security Update – Patch for Critical Vulnerabilities Allowing Code Execution and Injection Attacks SAP released its monthly Security Patch Day updates, addressing 18 new security notes and providing two updates to existing ones, focusing on vulnerabilities that could enable remote code execution and various injection attacks across its product ecosystem. These patches are crucial…

  • CISA Warns of Samsung Mobile Devices 0-Day RCE Vulnerability Exploited in Attacks

    CISA Warns of Samsung Mobile Devices 0-Day RCE Vulnerability Exploited in Attacks CISA has added a critical zero-day vulnerability affecting Samsung mobile devices to its Known Exploited Vulnerabilities catalog. Warning that threat actors are actively exploiting the flaw in real-world attacks. The vulnerability, tracked as CVE-2025-21042, is an out-of-bounds write vulnerability in the libimagecodec.quram.so library on…

  • Critical runc Vulnerabilities Put Docker and Kubernetes Container Isolation at Risk

    Critical runc Vulnerabilities Put Docker and Kubernetes Container Isolation at Risk Three critical vulnerabilities in runc, the container runtime powering Docker, Kubernetes, and other containerization platforms. These flaws could allow attackers to escape container isolation and gain root access to host systems. However, no active exploits have been detected yet. The vulnerabilities leverage race mount…

  • Monsta web-based FTP Remote Code Execution Vulnerability Exploited

    Monsta web-based FTP Remote Code Execution Vulnerability Exploited A critical remote code execution vulnerability in Monsta FTP, a popular web-based FTP client used by financial institutions and enterprises worldwide. The flaw, now tracked as CVE-2025-34299, affects multiple versions of the software and has been exploited in the wild. Monsta FTP is a browser-based file transfer client…

  • Seven QNAP Zero-Day Vulnerabilities Exploited at Pwn2Own 2025 Now Patched

    Seven QNAP Zero-Day Vulnerabilities Exploited at Pwn2Own 2025 Now Patched QNAP has addressed seven critical zero-day vulnerabilities in its network-attached storage (NAS) operating systems, following their successful exploitation by security researchers at Pwn2Own Ireland 2025. These flaws, identified as CVE-2025-62847, CVE-2025-62848, CVE-2025-62849, and associated ZDI canonical entries ZDI-CAN-28353, ZDI-CAN-28435, ZDI-CAN-28436, enable remote code execution (RCE)…

  • Hackers Hijack Samsung Galaxy Phones via 0-Day Exploit Using a Single WhatsApp Image

    Hackers Hijack Samsung Galaxy Phones via 0-Day Exploit Using a Single WhatsApp Image A sophisticated spyware operation targeting Samsung Galaxy devices, dubbed LANDFALL, which exploited a zero-day vulnerability to infiltrate phones through seemingly innocuous images shared on WhatsApp. This campaign, active since mid-2024, allowed attackers to deploy commercial-grade Android malware capable of full device surveillance…

  • NVIDIA NVApp for Windows Vulnerability Let Attackers Execute Malicious Code

    NVIDIA NVApp for Windows Vulnerability Let Attackers Execute Malicious Code NVIDIA has patched a critical vulnerability in its App for Windows that could allow local attackers to execute arbitrary code and escalate privileges on affected systems. Tracked as CVE-2025-23358, the flaw exists in the installer component. It poses a significant security risk to Windows users…

  • Chrome Emergency Update to Patch Multiple Vulnerabilities that Enable Remote Code Execution

    Chrome Emergency Update to Patch Multiple Vulnerabilities that Enable Remote Code Execution Google has rolled out an urgent security patch for its Chrome browser, addressing five vulnerabilities that could enable attackers to execute malicious code remotely. The update, version 142.0.7444.134/.135 for Windows, 142.0.7444.135 for macOS, and 142.0.7444.134 for Linux, targets critical flaws in core components…

  • Windows Cloud Files Mini Filter Driver Vulnerability Exploited to Escalate Privileges

    Windows Cloud Files Mini Filter Driver Vulnerability Exploited to Escalate Privileges A privilege escalation flaw in Windows Cloud Files Mini Filter Driver has been discovered, allowing local attackers to bypass file write protections and inject malicious code into system processes. Security researchers have uncovered CVE-2025-55680, a high-severity privilege-escalation vulnerability in the Windows Cloud Files Mini…

  • AMD Zen 5 Processors RDSEED Vulnerability Breaks Integrity With Randomness

    AMD Zen 5 Processors RDSEED Vulnerability Breaks Integrity With Randomness AMD has disclosed a critical vulnerability affecting its Zen 5 processor lineup that compromises the reliability of random number generation, a fundamental security feature in modern computing. The flaw, tracked as CVE-2025-62626, impacts the RDSEED instruction used by systems to generate cryptographically secure random numbers…

  • Apple Patches Multiple Critical Vulnerabilities in iOS 26.1 and iPadOS 26.1

    Apple Patches Multiple Critical Vulnerabilities in iOS 26.1 and iPadOS 26.1 Apple released iOS 26.1 and iPadOS 26.1, addressing multiple vulnerabilities that could lead to privacy breaches, app crashes, and potential data leaks for iPhone and iPad users. The update targets devices starting from the iPhone 11 series and various iPad models, including the iPad…

  • Hackers Actively Scanning for TCP Port 8530/8531 Linked to WSUS Vulnerability CVE-2025-59287

    Hackers Actively Scanning for TCP Port 8530/8531 Linked to WSUS Vulnerability CVE-2025-59287 Cybersecurity researchers and firewall monitoring services have detected a dramatic surge in reconnaissance activity targeting Windows Server Update Services (WSUS) infrastructure. Network sensors collected from security organizations, including data from Shadowserver, show a significant increase in scans directed at TCP ports 8530 and…

  • Windows Graphics Vulnerabilities Allow Remote Attackers to Execute Arbitrary Code

    Windows Graphics Vulnerabilities Allow Remote Attackers to Execute Arbitrary Code Multiple vulnerabilities in Microsoft’s Graphics Device Interface (GDI), a core component of the Windows operating system responsible for rendering graphics. These flaws, discovered by Check Point through an intensive fuzzing campaign targeting Enhanced Metafile (EMF) formats, could enable remote attackers to execute arbitrary code or…

  • OpenAI’s New Aardvark GPT-5 Agent that Detects and Fixes Vulnerabilities Automatically

    OpenAI’s New Aardvark GPT-5 Agent that Detects and Fixes Vulnerabilities Automatically OpenAI has unveiled Aardvark, an autonomous AI agent powered by its cutting-edge GPT-5 model, designed to detect software vulnerabilities and automatically propose fixes. This tool aims to entrust developers and security teams by scaling human-like analysis across vast codebases, addressing the escalating challenge of…

  • CISA Warns of Linux Kernel Use-After-Free Vulnerability Exploited in Attacks to Deploy Ransomware

    CISA Warns of Linux Kernel Use-After-Free Vulnerability Exploited in Attacks to Deploy Ransomware The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent alert about a critical use-after-free vulnerability in the Linux kernel, tracked as CVE-2024-1086. This vulnerability, hidden within the netfilter: nf_tables component, allows local attackers to escalate their privileges and potentially…

  • Hackers Exploiting Windows Server Update Services Flaw to Steal Sensitive Data from Organizations

    Hackers Exploiting Windows Server Update Services Flaw to Steal Sensitive Data from Organizations Windows Server Update Services (WSUS) vulnerability is actively exploited in the wild. Criminals are using this vulnerability to steal sensitive data from organizations in various industries. The vulnerability, tracked as CVE-2025-59287, was patched by Microsoft on October 14, 2025, but attackers quickly…