Category: Vulnerability

  • WinRAR 0-Day in Phishing Attacks to Deploy RomCom Malware

    WinRAR 0-Day in Phishing Attacks to Deploy RomCom Malware A critical zero-day vulnerability has been identified in WinRAR that cybercriminals are actively exploiting through sophisticated phishing campaigns to distribute RomCom malware.  The flaw, designated as CVE-2025-8088, represents a significant security threat with a CVSS v3.1 score of 8.4, enabling attackers to execute arbitrary code on…

  • 7-Zip Arbitrary File Write Vulnerability Let Attackers Execute Arbitrary Code

    7-Zip Arbitrary File Write Vulnerability Let Attackers Execute Arbitrary Code A newly disclosed security vulnerability in the popular 7-Zip file compression software has raised significant concerns in the cybersecurity community. CVE-2025-55188, discovered and reported by security researcher Landon on August 9, 2025, allows attackers to perform arbitrary file writes during archive extraction, potentially leading to…

  • ChatGPT Connectors ‘0-click’ Vulnerability Let Attackers Exfiltrate Data From Google Drive

    ChatGPT Connectors ‘0-click’ Vulnerability Let Attackers Exfiltrate Data From Google Drive A critical vulnerability in OpenAI’s ChatGPT Connectors feature allows attackers to exfiltrate sensitive data from connected Google Drive accounts without any user interaction beyond the initial file sharing. The attack, dubbed “AgentFlayer,” represents a new class of zero-click exploits targeting AI-powered enterprise tools. The…

  • ECScape: Exploiting ECS Protocol on EC2 to Exfiltrate Cross-Task IAM and Execution Role Credentials

    ECScape: Exploiting ECS Protocol on EC2 to Exfiltrate Cross-Task IAM and Execution Role Credentials A sophisticated technique dubbed “ECScape” that allows malicious containers running on Amazon Elastic Container Service (ECS) to steal AWS credentials from other containers sharing the same EC2 instance. The discovery highlights critical isolation weaknesses in multi-tenant ECS deployments and underscores the…

  • CISA Releases Emergency Advisory Urges Feds to Patch Exchange Server Vulnerability by Monday

    CISA Releases Emergency Advisory Urges Feds to Patch Exchange Server Vulnerability by Monday CISA has issued an emergency advisory directing all Federal Civilian Executive Branch agencies to mitigate a newly disclosed Microsoft Exchange urgently hybrid-joined vulnerability, tracked as CVE-2025-53786, by 9:00 AM EDT on Monday, August 11, 2025. The flaw enables attackers who have already…

  • HTTP/1.1 Fatal Vulnerability Exposes Millions of Websites to Hostile Takeover

    HTTP/1.1 Fatal Vulnerability Exposes Millions of Websites to Hostile Takeover A critical vulnerability in the HTTP/1.1 protocol threatens tens of millions of websites with potential hostile takeovers through sophisticated desynchronization attacks.  This fundamental flaw in the decades-old protocol creates extreme ambiguity about where one request ends and the next begins, enabling attackers to manipulate web…

  • Gemini Exploited via Prompt Injection in Google Calendar Invite to Steal Emails, and Control Smart Devices

    Gemini Exploited via Prompt Injection in Google Calendar Invite to Steal Emails, and Control Smart Devices A sophisticated attack method exploits Google’s Gemini AI assistant through seemingly innocent calendar invitations and emails.  The attack, dubbed “Targeted Promptware Attacks,” demonstrates how indirect prompt injection can compromise users’ digital privacy and even control physical devices in their…

  • Critical Trend Micro Apex One Management RCE Vulnerability Actively Exploited in the wild

    Critical Trend Micro Apex One Management RCE Vulnerability Actively Exploited in the wild Critical command injection remote code execution (RCE) vulnerabilities in Trend Micro Apex One Management Console are currently being actively exploited by threat actors.  The company confirmed observing at least one instance of attempted exploitation in production environments, prompting the immediate release of…

  • CISA Releases Two Advisories Covering Vulnerabilities, and Exploits Surrounding ICS

    CISA Releases Two Advisories Covering Vulnerabilities, and Exploits Surrounding ICS CISA released two urgent Industrial Control Systems (ICS) advisories on August 5, 2025, addressing significant security vulnerabilities in critical manufacturing and energy sector systems.  These advisories detail exploitable flaws that could compromise industrial operations and potentially disrupt essential services across multiple sectors. Key Takeaways1. CISA…

  • Millions of Dell Laptops Vulnerable to Device Takeover and Persistent Malware Attacks

    Millions of Dell Laptops Vulnerable to Device Takeover and Persistent Malware Attacks A wide range of vulnerabilities affects millions of Dell laptops used by government agencies, cybersecurity professionals, and enterprises worldwide. The vulnerabilities, collectively dubbed “ReVault,” target the Broadcom BCM5820X security chip embedded in Dell’s ControlVault3 firmware, creating opportunities for attackers to steal passwords, biometric…

  • Critical Android System Component Vulnerability Allows Remote Code Execution Without User Interaction

    Critical Android System Component Vulnerability Allows Remote Code Execution Without User Interaction Google released its August 2025 Android Security Bulletin on August 4, revealing a critical vulnerability that poses significant risks to Android device users worldwide.  The most severe flaw, designated CVE-2025-48530, affects the core System component and could enable remote code execution without requiring…

  • WAFs protection Bypassed to Execute XSS Payloads Using JS Injection with Parameter Pollution

    WAFs protection Bypassed to Execute XSS Payloads Using JS Injection with Parameter Pollution A sophisticated method to bypass Web Application Firewall (WAF) protections using HTTP Parameter Pollution techniques combined with JavaScript injection.  The research, conducted by Bruno Mendes across 17 different WAF configurations from major vendors including AWS, Google Cloud, Azure, and Cloudflare, revealed alarming…

  • AI-Powered Code Editor Cursor IDE Vulnerability Enables Remote Code Without User Interaction

    AI-Powered Code Editor Cursor IDE Vulnerability Enables Remote Code Without User Interaction A severe vulnerability in the popular AI-powered code editor Cursor IDE, dubbed “CurXecute,” allows attackers to execute arbitrary code on developers’ machines without any user interaction.  The vulnerability, tracked as CVE-2025-54135 with a high severity score of 8.6, affects all Cursor IDE versions prior to…

  • NestJS Framework Vulnerability Let Attackers Execute Arbitrary Code in Developers Machine

    NestJS Framework Vulnerability Let Attackers Execute Arbitrary Code in Developers Machine A critical security vulnerability has been discovered in the NestJS framework’s development tools that enables remote code execution (RCE) attacks against JavaScript developers.  The flaw, identified as CVE-2025-54782, affects the @nestjs/devtools-integration package and allows malicious websites to execute arbitrary code on developers’ local machines…

  • SonicWall Firewall Devices 0-day Vulnerability Actively Exploited by Akira Ransomware

    SonicWall Firewall Devices 0-day Vulnerability Actively Exploited by Akira Ransomware A suspected zero-day vulnerability in SonicWall firewall devices that the Akira ransomware group is actively exploiting. The flaw allows attackers to gain initial access to corporate networks through SonicWall’s SSL VPN feature, leading to subsequent ransomware deployment. In late July 2025, security researchers observed a…

  • Critical CrushFTP 0-Day RCE Vulnerability Technical Details and PoC Released

    Critical CrushFTP 0-Day RCE Vulnerability Technical Details and PoC Released A significant zero-day vulnerability in CrushFTP has been disclosed, allowing unauthenticated attackers to achieve complete remote code execution on vulnerable servers.  The flaw, tracked as CVE-2025-54309 and scoring a critical 9.8 on the CVSS scale, stems from a fundamental breakdown in security checks within CrushFTP’s…

  • OAuth2-Proxy Vulnerability Enables Authentication Bypass by Manipulating Query Parameters

    OAuth2-Proxy Vulnerability Enables Authentication Bypass by Manipulating Query Parameters A critical security vulnerability has been identified in OAuth2-Proxy, a widely-used reverse proxy that provides authentication services for Google, Azure, OpenID Connect, and numerous other identity providers.  The vulnerability, designated as CVE-2025-54576, enables attackers to bypass authentication mechanisms by manipulating query parameters in crafted URLs, potentially…

  • Hackers Exploiting SAP NetWeaver Vulnerability to Deploy Auto-Color Linux Malware

    Hackers Exploiting SAP NetWeaver Vulnerability to Deploy Auto-Color Linux Malware A sophisticated cyberattack targeting a US-based chemicals company has revealed the first observed pairing of SAP NetWeaver exploitation with Auto-Color malware, demonstrating how threat actors are leveraging critical vulnerabilities to deploy advanced persistent threats on Linux systems.  In April 2025, cybersecurity firm Darktrace successfully detected…

  • 200,000 WordPress websites at risk of being hijacked due to vulnerable Post SMTP plugin

    200,000 WordPress websites at risk of being hijacked due to vulnerable Post SMTP plugin Over 200,000 websites running a vulnerable version of a popular WordPress plugin could be at risk of being hijacked by hackers. Read more in my article on the Hot for Security blog. Graham Cluley Go to grahamcluley

  • CISA Warns of PaperCut RCE Vulnerability Exploited in Attacks

    CISA Warns of PaperCut RCE Vulnerability Exploited in Attacks CISA has issued an urgent warning regarding a critical vulnerability in PaperCut NG/MF print management software that threat actors are actively exploiting in ransomware campaigns.  The vulnerability, tracked as CVE-2023-2533, represents a significant security risk to organizations worldwide using the affected software versions. Key Takeaways1. CVE-2023-2533…

  • Critical macOS ‘Sploitlight’ Vulnerability Let Attackers Steal Private Data of Files Bypassing TCC

    Critical macOS ‘Sploitlight’ Vulnerability Let Attackers Steal Private Data of Files Bypassing TCC A critical macOS vulnerability enables attackers to bypass Transparency, Consent, and Control (TCC) protections and steal sensitive user data, including files from protected directories and Apple Intelligence caches.  The vulnerability, dubbed “Sploitlight,” exploits Spotlight plugins to access normally protected information without user consent,…

  • LG Innotek Camera Vulnerabilities Let Attackers Gain Administrative Access

    LG Innotek Camera Vulnerabilities Let Attackers Gain Administrative Access A serious security vulnerability has been discovered in LG Innotek’s LNV5110R camera model that could allow cybercriminals to gain complete administrative control over affected devices.  The U.S. Cybersecurity and Infrastructure Security Agency (CISA) issued an advisory on July 24, 2025, warning of a remotely exploitable flaw…

  • CISA Warns of Microsoft SharePoint Code Injection and Authentication Vulnerability Exploited in Wild

    CISA Warns of Microsoft SharePoint Code Injection and Authentication Vulnerability Exploited in Wild CISA has issued an urgent warning regarding two critical Microsoft SharePoint vulnerabilities that threat actors are actively exploiting in the wild.  The vulnerabilities, designated as CVE-2025-49704 and CVE-2025-49706, pose significant risks to organizations running on-premises SharePoint servers and have been added to…

  • Chrome High-Severity Vulnerabilities Allow Attackers to Execute Arbitrary Code

    Chrome High-Severity Vulnerabilities Allow Attackers to Execute Arbitrary Code Google has released an urgent security update for its Chrome browser, addressing three critical vulnerabilities that could enable attackers to execute arbitrary code on users’ systems. The Stable channel update to version 138.0.7204.168/.169 for Windows and Mac, and 138.0.7204.168 for Linux, is currently rolling out to…

  • Microsoft Releases Mitigations and Threat Hunting Queries for SharePoint Zero-Day

    Microsoft Releases Mitigations and Threat Hunting Queries for SharePoint Zero-Day Thousands of organizations worldwide face active cyberattacks targeting Microsoft SharePoint servers through two critical vulnerabilities, prompting urgent government warnings and emergency patches. Microsoft confirmed over the weekend that threat actors are actively exploiting two zero-day vulnerabilities in on-premises SharePoint servers, designated CVE-2025-53770 and CVE-2025-53771. The…

  • New PoisonSeed Attack Let Attackers Trick Users into Scanning a QR Code with an MFA Authenticator

    New PoisonSeed Attack Let Attackers Trick Users into Scanning a QR Code with an MFA Authenticator A sophisticated new attack technique compromises Fast IDentity Online (FIDO) key authentication by exploiting cross-device sign-in features.  The PoisonSeed attack group has developed a method to downgrade FIDO key protections through adversary-in-the-middle (AitM) phishing campaigns that trick users into…

  • PoC Exploit Released for Critical NVIDIA AI Container Toolkit Vulnerability

    PoC Exploit Released for Critical NVIDIA AI Container Toolkit Vulnerability A critical container escape vulnerability has emerged in the NVIDIA Container Toolkit, threatening the security foundation of AI infrastructure worldwide. Dubbed “NVIDIAScape” and tracked as CVE-2025-23266, this flaw carries a maximum CVSS score of 9.0, representing one of the most severe threats to cloud-based AI…

  • SharePoint 0-Day RCE Vulnerability Actively Exploited in the Wild to Gain Full Server Access

    SharePoint 0-Day RCE Vulnerability Actively Exploited in the Wild to Gain Full Server Access A sophisticated cyberattack campaign targeting Microsoft SharePoint servers has been discovered exploiting a newly weaponized vulnerability chain dubbed “ToolShell,” enabling attackers to gain complete remote control over vulnerable systems without authentication. Eye Security, a Dutch cybersecurity firm, identified the active exploitation…

  • Grafana Vulnerabilities Allow User Redirection to Malicious Sites and Code Execution in Dashboards

    Grafana Vulnerabilities Allow User Redirection to Malicious Sites and Code Execution in Dashboards Two significant Grafana vulnerabilities that could allow attackers to redirect users to malicious websites and execute arbitrary JavaScript code.  The vulnerabilities, identified as CVE-2025-6023 and CVE-2025-6197, affect multiple versions of Grafana, including 12.0.x, 11.6.x, 11.5.x, 11.4.x, and 11.3.x branches.  Both security flaws…

  • CISA Warns of Fortinet FortiWeb SQL Injection Vulnerability Exploited in Attacks

    CISA Warns of Fortinet FortiWeb SQL Injection Vulnerability Exploited in Attacks The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical Fortinet FortiWeb vulnerability to its Known Exploited Vulnerabilities (KEV) catalog, confirming active exploitation of the SQL injection flaw in cyberattacks worldwide. The vulnerability, tracked as CVE-2025-25257, affects Fortinet’s FortiWeb web application firewall…

  • Microsoft Entra ID Vulnerability Let Attackers Escalate Privileges to Global Admin Role

    Microsoft Entra ID Vulnerability Let Attackers Escalate Privileges to Global Admin Role A critical vulnerability in Microsoft Entra ID allows attackers to escalate privileges to the Global Administrator role through the exploitation of first-party applications.  The vulnerability, reported to Microsoft Security Response Center (MSRC) in January 2025, affects organizations using hybrid Active Directory environments with…

  • Smashing Security podcast #426: Choo Choo Choose to ignore the vulnerability

    Smashing Security podcast #426: Choo Choo Choose to ignore the vulnerability In episode 426 of the “Smashing Security” podcast, Graham reveals how you can hijack a train’s brakes from 150 miles away using kit cheaper than a second-hand PlayStation. Meanwhile, Carole investigates how Grok went berserk, which didn’t stop the Department of Defense signing a…

  • Cisco Unified Intelligence Center Vulnerability Allows Remote Attackers to Upload Arbitrary Files

    Cisco Unified Intelligence Center Vulnerability Allows Remote Attackers to Upload Arbitrary Files A critical vulnerability in Cisco’s Unified Intelligence Center (CUIC) web-based management interface has been classified with high severity, allowing authenticated remote attackers with Report Designer privileges to upload arbitrary files to affected systems.  Tracked as CVE-2025-20274 and assigned a CVSS Base Score of…

  • SonicWall SMA Devices 0-Day RCE Vulnerability Exploited to Deploy OVERSTEP Ransomware

    SonicWall SMA Devices 0-Day RCE Vulnerability Exploited to Deploy OVERSTEP Ransomware SonicWall’s end-of-life SMA 100 series appliances are again on the front line after investigators unearthed a covert campaign that couples a suspected zero-day remote-code-execution flaw with a sophisticated backdoor called OVERSTEP. The operation, attributed to the financially motivated group UNC6148, first steals administrator credentials…

  • Node.js Vulnerabilities Exposes Windows App to Path Traversal and HashDoS Attacks

    Node.js Vulnerabilities Exposes Windows App to Path Traversal and HashDoS Attacks The Node.js project has released critical security updates across multiple release lines to address two high-severity vulnerabilities affecting Windows applications and V8 engine implementations.  Security releases are now available for Node.js versions 20.x, 22.x, and 24.x, with patches addressing a path traversal bypass and…

  • Meta’s Llama Firewall Bypassed Using Prompt Injection Vulnerability

    Meta’s Llama Firewall Bypassed Using Prompt Injection Vulnerability Trendyol’s application security team uncovered a series of bypasses that render Meta’s Llama Firewall protections unreliable against sophisticated prompt injection attacks. The findings raise fresh concerns about the readiness of existing LLM security measures and underscore the urgent need for more robust defenses as enterprises increasingly embed…

  • GPUHammer – First Rowhammer Attack Targeting NVIDIA GPUs

    GPUHammer – First Rowhammer Attack Targeting NVIDIA GPUs Cybersecurity researchers at the University of Toronto have achieved a breakthrough in hardware-level attacks by successfully demonstrating GPUHammer, the first Rowhammer attack specifically targeting discrete NVIDIA GPUs. The research, which focuses on the popular NVIDIA A6000 GPU with GDDR6 memory, represents a significant expansion of the decade-old…

  • Hackers Actively Exploiting CitrixBleed 2 Vulnerability in the Wild

    Hackers Actively Exploiting CitrixBleed 2 Vulnerability in the Wild Researchers have observed widespread exploitation attempts targeting a critical memory disclosure vulnerability in Citrix NetScaler devices, designated as CVE-2025-5777 and dubbed “CitrixBleed 2.”  This pre-authentication flaw enables attackers to craft malicious requests that leak uninitialized memory from affected NetScaler ADC and Gateway devices, potentially exposing sensitive…

  • Laravel APP_KEY Vulnerability Allows Remote Code Execution – Hundreds of Apps Affected

    Laravel APP_KEY Vulnerability Allows Remote Code Execution – Hundreds of Apps Affected A critical vulnerability in Laravel applications exposes APP_KEY configuration values, enabling attackers to achieve remote code execution (RCE).  Collaborative research between GitGuardian and Synacktiv revealed that approximately 260,000 APP_KEYs have been exposed on GitHub since 2018, with over 600 applications confirmed vulnerable to…

  • Best SOC 2 Type 2 Certified Complaint Solutions – 2025

    Best SOC 2 Type 2 Certified Complaint Solutions – 2025 In today’s digital-first business landscape, SOC 2 Type 2 compliance is no longer optional for organizations handling sensitive customer data. As cyber threats escalate and regulatory scrutiny intensifies, demonstrating robust security controls and continuous monitoring is essential for trust, growth, and competitive advantage. This comprehensive…

  • Smashing Security podcast #425: Call of Duty: From pew-pew to pwned

    Smashing Security podcast #425: Call of Duty: From pew-pew to pwned In episode 425 of “Smashing Security”, Graham reveals how “Call of Duty: WWII” has been weaponised – allowing hackers to hijack your entire PC during online matches, thanks to ancient code and Microsoft’s Game Pass. Meanwhile, Carole digs into a con targeting the recently…

  • Microsoft SQL Server 0-Day Vulnerability Exposes Sensitive Data Over Network

    Microsoft SQL Server 0-Day Vulnerability Exposes Sensitive Data Over Network A critical information disclosure vulnerability in Microsoft SQL Server, designated as CVE-2025-49719, allows unauthorized attackers to access sensitive data over network connections.  This vulnerability stems from improper input validation within SQL Server’s processing mechanisms, enabling attackers to disclose uninitialized memory contents without requiring authentication or…

  • Microsoft Remote Desktop Client Vulnerability Let Attackers Execute Remote Code

    Microsoft Remote Desktop Client Vulnerability Let Attackers Execute Remote Code A critical security vulnerability in Microsoft Remote Desktop Client could allow attackers to execute arbitrary code on victim systems.  The vulnerability, designated as CVE-2025-48817, affects multiple versions of Windows and poses significant security risks for organizations that rely on Remote Desktop Protocol (RDP) connections. Key…

  • ScriptCase Vulnerabilities Let Attackers Execute Remote Code and Gain Server Access

    ScriptCase Vulnerabilities Let Attackers Execute Remote Code and Gain Server Access Two critical vulnerabilities in ScriptCase’s Production Environment module can be chained together to achieve pre-authenticated remote command execution on affected servers.  The vulnerabilities, tracked as CVE-2025-47227 and CVE-2025-47228, affect version 1.0.003-build-2 of the Production Environment module included in ScriptCase version 9.12.006 (23), with previous…

  • “CitrixBleed 2” Vulnerability PoC Released – Warns of Potential Widespread Exploitation

    “CitrixBleed 2” Vulnerability PoC Released – Warns of Potential Widespread Exploitation Critical flaw in Citrix NetScaler devices echoes infamous 2023 security breach that crippled major organizations worldwide. The new critical vulnerability in Citrix NetScaler devices has security experts warning of potential widespread exploitation, drawing alarming parallels to the devastating “CitrixBleed” attacks that plagued organizations in…

  • Writable File in Lenovo’s Windows Directory Enables a Stealthy AppLocker Bypass

    Writable File in Lenovo’s Windows Directory Enables a Stealthy AppLocker Bypass A significant security vulnerability has been discovered in Lenovo’s preloaded Windows operating systems, where a writable file in the Windows directory enables attackers to bypass Microsoft’s AppLocker security framework.  The issue affects all variants of Lenovo machines running default Windows installations and poses serious…

  • Next.js Cache Poisoning Vulnerability Let Attackers Trigger DoS Condition

    Next.js Cache Poisoning Vulnerability Let Attackers Trigger DoS Condition Key Takeaways1. Next.js versions 15.1.0-15.1.8 have a cache poisoning bug causing DoS attacks through blank page delivery.2. Needs affected Next.js version + ISR with cache revalidation + SSR with CDN caching 204 responses.3. Race condition allows HTTP 204 responses to be cached for static pages, serving…

  • Critical HIKVISION applyCT Vulnerability Exposes Devices to Code Execution Attacks

    Critical HIKVISION applyCT Vulnerability Exposes Devices to Code Execution Attacks A critical security vulnerability has been discovered in HIKVISION’s applyCT component, part of the HikCentral Integrated Security Management Platform, that allows attackers to execute arbitrary code remotely without authentication.  Assigned CVE-2025-34067 with a maximum CVSS score of 10.0, this vulnerability stems from the platform’s use…

  • Catwatchful stalkerware app spills secrets of 62,000 users – including its own admin

    Catwatchful stalkerware app spills secrets of 62,000 users – including its own admin Another scummy stalkerware app has spilled its guts, revealing the details of its 62,000 users – and data from thousands of victims’ infected devices. Graham Cluley Go to grahamcluley

  • New Sophisticated Attack ypasses Content Security Policy Using HTML-Injection Technique

    New Sophisticated Attack ypasses Content Security Policy Using HTML-Injection Technique A sophisticated technique to bypass Content Security Policy (CSP) protections using a combination of HTML injection and browser cache manipulation.  The method exploits the interaction between nonce-based CSP implementations and browser caching mechanisms, specifically targeting the back/forward cache (bfcache) and disk cache systems.  Key Takeaways1.…

  • Cisco Unified CM Vulnerability Allows Remote Attacker to Login As Root User

    Cisco Unified CM Vulnerability Allows Remote Attacker to Login As Root User A severe vulnerability in Cisco Unified Communications Manager (Unified CM) systems could allow remote attackers to gain root-level access to affected devices.  The vulnerability, designated CVE-2025-20309 with a maximum CVSS score of 10.0, affects Engineering Special releases and stems from hardcoded SSH credentials…

  • CISA Warns of Chrome 0-Day Vulnerability Exploited in Attacks

    CISA Warns of Chrome 0-Day Vulnerability Exploited in Attacks CISA has issued an urgent warning about a critical zero-day vulnerability in Google Chrome that attackers are actively exploiting in the wild.  The vulnerability, designated CVE-2025-6554, affects the Chromium V8 JavaScript engine and has been added to CISA’s Known Exploited Vulnerabilities (KEV) catalog, marking it as…

  • FileFix Attack Exploits Windows Browser Features to Bypass Mark-of-the-Web Protection

    FileFix Attack Exploits Windows Browser Features to Bypass Mark-of-the-Web Protection A sophisticated new variation of cyberattacks emerged in July 2025, exploiting a critical vulnerability in how Chrome and Microsoft Edge handle webpage saving functionality. The attack, dubbed “FileFix 2.0,” bypasses Windows’ Mark of the Web (MOTW) security feature by leveraging legitimate browser saving mechanisms combined…

  • The AI Fix #57: AI is the best hacker in the USA, and self-learning AI

    The AI Fix #57: AI is the best hacker in the USA, and self-learning AI In episode 57 of The AI Fix, our hosts discover an AI “dream recorder”, Mark Zuckerberg tantalises OpenAI staff with $100 million signing bonuses, Graham finds out why robot butlers sit in chairs, Wikipedia holds the line against AI slop,…

  • CISA Warns of Citrix NetScaler ADC and Gateway Vulnerability Actively Exploited in Attacks

    CISA Warns of Citrix NetScaler ADC and Gateway Vulnerability Actively Exploited in Attacks CISA has issued an urgent warning regarding a critical buffer overflow vulnerability in Citrix NetScaler ADC and Gateway products, designated as CVE-2025-6543.  Added to CISA’s Known Exploited Vulnerabilities (KEV) catalog on June 30, 2025, threat actors are actively exploiting this high-severity flaw…

  • CISA Warns of FortiOS Hard-Coded Credentials Vulnerability Exploited in Attacks

    CISA Warns of FortiOS Hard-Coded Credentials Vulnerability Exploited in Attacks CISA has issued a critical warning regarding a Fortinet FortiOS vulnerability that poses significant risks to network security infrastructure.  On June 25, 2025, CISA added CVE-2019-6693 to its Known Exploited Vulnerabilities (KEV) catalog, indicating that this hard-coded credentials flaw is being actively exploited in real-world…

  • Firefox 140 Released With Fix for Code Execution Vulnerability – Update Now

    Firefox 140 Released With Fix for Code Execution Vulnerability – Update Now Mozilla has released Firefox 140, addressing multiple critical security vulnerabilities, including a high-impact use-after-free vulnerability that could lead to code execution.  The update patches twelve distinct security flaws ranging from memory safety issues to platform-specific vulnerabilities affecting both desktop and mobile versions of…

  • Realtek Vulnerability Let Attackers Trigger DoS Attack via Bluetooth Secure Connections Pairing Process

    Realtek Vulnerability Let Attackers Trigger DoS Attack via Bluetooth Secure Connections Pairing Process A significant security vulnerability has been identified in Realtek’s RTL8762E SDK v1.4.0 that allows attackers to exploit the Bluetooth Low Energy (BLE) Secure Connections pairing process to launch denial-of-service attacks.  The vulnerability, discovered in the RTL8762EKF-EVB development platform, stems from improper validation…

  • WinRAR Directory Vulnerability Allows Arbitrary Code Execution Using a Malicious File

    WinRAR Directory Vulnerability Allows Arbitrary Code Execution Using a Malicious File Summary 1. A high-severity flaw (CVE-2025-6218) in WinRAR allows attackers to execute arbitrary code by exploiting how the software handles file paths within archives. 2. The vulnerability enables attackers to use specially crafted archive files with directory traversal sequences, leading to remote code execution.…

  • WhatsApp Banned on U.S. House Staffers Devices Due to Potential Security Risks

    WhatsApp Banned on U.S. House Staffers Devices Due to Potential Security Risks Summary 1. The U.S. House Chief Administrative Officer banned WhatsApp from all government-issued devices used by congressional staffers, including mobile, desktop, and web browser versions. 2. The ban was implemented due to concerns about lack of transparency in data protection, absence of stored…

  • Amazon EKS Vulnerabilities Expose Sensitive AWS Credentials and Escalate Privileges

    Amazon EKS Vulnerabilities Expose Sensitive AWS Credentials and Escalate Privileges Summary 1.  Overprivileged containers can steal AWS credentials by targeting the 169.254.170.23:80 endpoint through packet sniffing and API spoofing attacks. 2. Attackers use tcpdump to intercept plaintext traffic or manipulate network settings to deploy fake HTTP servers that capture authorization tokens. 3.  Amazon considers this…

  • Threat Actor Allegedly Selling FortiGate API Exploit Tool Targeting FortiOS

    Threat Actor Allegedly Selling FortiGate API Exploit Tool Targeting FortiOS A threat actor has reportedly put up for sale a sophisticated FortiGate API exploit tool on a dark web marketplace, igniting significant concern within the cybersecurity community. The tool, which is being marketed for a price of $12,000 and comes with escrow services to facilitate…

  • Critical OpenVPN Driver Vulnerability Allows Attackers to Crash Windows Systems

    Critical OpenVPN Driver Vulnerability Allows Attackers to Crash Windows Systems Summary 1. A critical OpenVPN Windows driver flaw (CVE-2025-50054) allowed local attackers to crash systems. 2. The vulnerability enabled denial-of-service attacks but did not expose user data. 3. OpenVPN 2.7_alpha2 fixes the issue and improves Windows support. 4. Users should update promptly and restrict driver…

  • Record Breaking 7.3 Tbps DDoS Attack Blasting 37.4 Terabytes in Just 45 Seconds

    Record Breaking 7.3 Tbps DDoS Attack Blasting 37.4 Terabytes in Just 45 Seconds The largest distributed denial-of-service (DDoS) attack ever documented was successfully stopped by Cloudflare in mid-May 2025, with attackers unleashing a devastating 7.3 terabits per second (Tbps) attack that delivered 37.4 terabytes of malicious traffic in just 45 seconds.  Summary 1. Cloudflare blocked…

  • Apache SeaTunnel Vulnerability Allows Unauthorized Users to Perform Deserialization Attack

    Apache SeaTunnel Vulnerability Allows Unauthorized Users to Perform Deserialization Attack Apache SeaTunnel, the widely used distributed data integration platform, has disclosed a significant security vulnerability that enables unauthorized users to execute arbitrary file read operations and deserialization attacks through its RESTful API interface.  The vulnerability, tracked as CVE-2025-32896 and reported on April 12, 2025, affects…

  • Hackers Exploit Atlassian’s Model Context Protocol by Submitting a Malicious Support Ticket

    Hackers Exploit Atlassian’s Model Context Protocol by Submitting a Malicious Support Ticket A sophisticated attack vector targeting Atlassian’s Model Context Protocol (MCP) that allows external threat actors to gain privileged access to internal systems through malicious support tickets.  The attack, dubbed “Living off AI,” exploits the trust boundary between external users submitting support requests and…

  • Cisco AnyConnect VPN Server Vulnerability Let Attackers Trigger DoS Attack

    Cisco AnyConnect VPN Server Vulnerability Let Attackers Trigger DoS Attack A critical security vulnerability affecting Cisco Meraki MX and Z Series devices could allow unauthenticated attackers to launch denial of service (DoS) attacks against AnyConnect VPN services.  The vulnerability, tracked as CVE-2025-20271 with a CVSS score of 8.6, was published on June 18, 2025, and…

  • Apache Traffic Server Vulnerability Let Attackers Trigger DoS Attack via Memory Exhaustion

    Apache Traffic Server Vulnerability Let Attackers Trigger DoS Attack via Memory Exhaustion A critical security vulnerability has been discovered in Apache Traffic Server that allows remote attackers to trigger denial-of-service (DoS) attacks through memory exhaustion.  The vulnerability, tracked as CVE-2025-49763, affects the Edge Side Includes (ESI) plugin and poses significant risks to organizations running affected…

  • Open Next for Cloudflare SSRF Vulnerability Let Attackers Load Remote Resources from Arbitrary Hosts

    Open Next for Cloudflare SSRF Vulnerability Let Attackers Load Remote Resources from Arbitrary Hosts A high-severity Server-Side Request Forgery (SSRF) vulnerability has been identified in the @opennextjs/cloudflare package, enabling attackers to exploit the /_next/image endpoint to load remote resources from arbitrary hosts.  The vulnerability, assigned CVE-2025-6087 with a CVSS score of 7.8, affects all versions…

  • Chrome Vulnerabilities Let Attackers Execute Arbitrary Code – Update Now!

    Chrome Vulnerabilities Let Attackers Execute Arbitrary Code – Update Now! Google has released an urgent security update for Chrome browsers across all desktop platforms, addressing critical vulnerabilities that could allow attackers to execute arbitrary code on users’ systems.  The update, rolled out on Tuesday, June 17, 2025, patches three significant security flaws including two high-severity…

  • CISA Warns of Linux Kernel Improper Ownership Management Vulnerability Exploited in Attacks

    CISA Warns of Linux Kernel Improper Ownership Management Vulnerability Exploited in Attacks CISA has added a critical Linux kernel vulnerability to its Known Exploited Vulnerabilities (KEV) catalog, warning that CVE-2023-0386 is being actively exploited in real-world attacks.  This improper ownership management flaw in the Linux kernel’s OverlayFS subsystem allows local attackers to escalate privileges through…

  • Critical Linux Privilege Escalation Vulnerabilities Let Attackers Gain Full Root Access

    Critical Linux Privilege Escalation Vulnerabilities Let Attackers Gain Full Root Access Two critical, interconnected flaws, CVE-2025-6018 and CVE-2025-6019, enable unprivileged attackers to achieve root access on major Linux distributions. Affecting millions worldwide, these vulnerabilities pose a severe security emergency that demands immediate patching. The first vulnerability exploits PAM configuration weaknesses in SUSE systems, while the…

  • Graphite Spyware Exploits Apple iOS Zero-Click Vulnerability to Attack Journalists

    Graphite Spyware Exploits Apple iOS Zero-Click Vulnerability to Attack Journalists The advanced Graphite mercenary spyware, developed by Paragon, targets journalists through a sophisticated zero-click vulnerability in Apple’s iOS. At least three European journalists have been confirmed as targets, with two cases forensically verified. The spyware exploited a zero-day vulnerability in iOS that allowed attackers to compromise…

  • Smashing Security podcast #421: Toothpick flirts, Google leaks, and ICE ICE scammers

    Smashing Security podcast #421: Toothpick flirts, Google leaks, and ICE ICE scammers What do a sleazy nightclub carpet, Google’s gaping privacy hole, and an international student conned by fake ICE agents have in common? This week’s episode of the “Smashing Security” podcast obviously. Graham explains how a Singaporean bug-hunter cracked Google’s defences and could brute-force…

  • CISA Warns of Erlang/OTP SSH Server RCE Vulnerability Exploited in Attacks

    CISA Warns of Erlang/OTP SSH Server RCE Vulnerability Exploited in Attacks CISA has issued an urgent warning regarding a critical vulnerability in Erlang/OTP SSH servers that is being actively exploited in the wild.  The vulnerability, tracked as CVE-2025-32433, enables attackers to achieve unauthenticated remote code execution on affected systems, prompting its immediate addition to CISA’s…

  • ManageEngine Exchange Reporter Plus Vulnerability Allows Remote Code Execution

    ManageEngine Exchange Reporter Plus Vulnerability Allows Remote Code Execution A severe security vulnerability has been identified in ManageEngine Exchange Reporter Plus that could allow attackers to execute arbitrary commands on target servers.  Designated as CVE-2025-3835, this critical remote code execution vulnerability affects all Exchange Reporter Plus installations with build 5721 and below.  ManageEngine has responded…

  • 84,000+ Roundcube Webmail Installation Vulnerable to Remote Code Execution Attacks

    84,000+ Roundcube Webmail Installation Vulnerable to Remote Code Execution Attacks A critical security vulnerability affecting Roundcube webmail installations has exposed over 84,000 systems worldwide to remote code execution attacks. The vulnerability, tracked as CVE-2025-49113, allows authenticated users to execute arbitrary code remotely, presenting a significant security risk to organizations relying on this popular open-source webmail…

  • SAP June 2025 Patch Day – 14 Vulnerabilities Patched Across Multiple Products

    SAP June 2025 Patch Day – 14 Vulnerabilities Patched Across Multiple Products SAP released its monthly Security Patch Day update addressing 14 critical vulnerabilities across multiple enterprise products.  The comprehensive security update includes patches addressing critical authorization bypass issues and cross-site scripting vulnerabilities, with CVSS scores ranging from 3.0 to 9.6.  Organizations using SAP enterprise…

  • PoC Exploit Released for Fortinet 0-Day Vulnerability that Allows Remote Code Execution

    PoC Exploit Released for Fortinet 0-Day Vulnerability that Allows Remote Code Execution A new proof-of-concept (PoC) exploit for a critical zero-day vulnerability affecting multiple Fortinet products raises urgent concerns about the security of enterprise network infrastructure. The vulnerability, tracked as CVE-2025-32756, carries a maximum CVSS score of 9.8 and enables unauthenticated remote code execution through…

  • Splunk Enterprise XSS Vulnerability Let Attackers Execute Unauthorized JavaScript Code

    Splunk Enterprise XSS Vulnerability Let Attackers Execute Unauthorized JavaScript Code A significant security vulnerability in the Splunk Enterprise platform could allow low-privileged attackers to execute unauthorized JavaScript code through a reflected Cross-Site Scripting (XSS) flaw.  The vulnerability, tracked as CVE-2025-20297, affects multiple versions of Splunk Enterprise and Splunk Cloud Platform, prompting the company to issue…

  • Google Chrome 0-Day Vulnerability Exploited in the Wild to Execute Arbitrary Code

    Google Chrome 0-Day Vulnerability Exploited in the Wild to Execute Arbitrary Code Google has released an emergency security update for Chrome after confirming that a critical zero-day vulnerability is being actively exploited by attackers in the wild. The vulnerability, tracked as CVE-2025-5419, allows threat actors to execute arbitrary code on victims’ systems through out-of-bounds read…

  • Denodo Scheduler Vulnerability Let Attackers Execute Remote Code

    Denodo Scheduler Vulnerability Let Attackers Execute Remote Code A significant security vulnerability has been discovered in Denodo Scheduler, a data management software component, that allows attackers to execute remote code on affected systems.  The flaw, identified as CVE-2025-26147, exploits a path traversal vulnerability in the Kerberos authentication configuration feature, potentially compromising the security of enterprise…

  • Threat Actors Actively Exploiting Critical vBulletin Vulnerability in the Wild

    Threat Actors Actively Exploiting Critical vBulletin Vulnerability in the Wild A critical, unauthenticated remote code execution vulnerability in vBulletin forum software is now being actively exploited. The vulnerability, which impacts vBulletin versions 5.0.0 through 6.0.3, has been assigned CVE-2025-48827 and CVE-2025-48828 and is now being actively targeted by threat actors, marking it as a Known…

  • Critical Roundcube Vulnerability Let Attackers Execute Remote Code

    Critical Roundcube Vulnerability Let Attackers Execute Remote Code A critical vulnerability in the widely used Roundcube Webmail software allows authenticated attackers to execute arbitrary code remotely.  The vulnerability, discovered through PHP object deserialization flaws, affects all installations running versions 1.6. x and 1.5. One of the popular open-source webmail clients.  Security researcher firs0v reported the…

  • Microsoft OneDrive File Picker Vulnerability Exposes Users’ Entire Cloud Storage to Websites

    Microsoft OneDrive File Picker Vulnerability Exposes Users’ Entire Cloud Storage to Websites A critical security flaw in Microsoft’s OneDrive File Picker has exposed millions of users to unauthorized data access, allowing third-party web applications to gain complete access to users’ entire OneDrive storage rather than just selected files.  Security researchers from Oasis Security reported on…

  • Smashing Security podcast #419: Star Wars, the CIA, and a WhatsApp malware mirage

    Smashing Security podcast #419: Star Wars, the CIA, and a WhatsApp malware mirage Why is a cute Star Wars fan website now redirecting to the CIA? How come Cambodia has become the world’s hotspot for scam call centres? And can a WhatsApp image really drain your bank account with a single download, or is it…

  • Multiple pfSense Firewall Vulnerabilities Let Attackers Inject Malicious Codes

    Multiple pfSense Firewall Vulnerabilities Let Attackers Inject Malicious Codes Three critical vulnerabilities in pfSense firewall software that could allow authenticated attackers to inject malicious code, manipulate cloud backups, and potentially achieve remote code execution.  The vulnerabilities affect both pfSense Community Edition (CE) prior to version 2.8.0 beta and corresponding pfSense Plus builds. These flaws, CVE-2024-57273,…

  • glibc Vulnerability Exposes Millions of Linux Systems to Code Execution Attacks

    glibc Vulnerability Exposes Millions of Linux Systems to Code Execution Attacks A critical vulnerability in the GNU C Library (glibc), potentially exposing millions of Linux systems to local privilege escalation attacks.  Tracked as CVE-2025-4802 and publicly disclosed on May 16, 2025, this vulnerability could allow attackers to execute arbitrary code by manipulating the LD_LIBRARY_PATH environment…

  • VMware ESXi, Firefox, Red Hat Linux & SharePoint 0-Day Vulnerabilities Exploited – Pwn2Own Day 2

    VMware ESXi, Firefox, Red Hat Linux & SharePoint 0-Day Vulnerabilities Exploited – Pwn2Own Day 2 Security researchers uncovered critical zero-day vulnerabilities across major enterprise platforms during the second day of Pwn2Own Berlin 2025, earning a staggering $435,000 in bounties. The competition, hosted at the OffensiveCon conference, witnessed successful exploits against VMware ESXi, Microsoft SharePoint, Mozilla…

  • Prescription for disaster: Sensitive patient data leaked in Ascension breach

    Prescription for disaster: Sensitive patient data leaked in Ascension breach Ascension, one of the largest private healthcare companies in the United States, has confirmed that the personal data of some 437,329 patients has been exposed following an attack by cybercriminals. Read more in my article on the Fortra blog. Graham Cluley Go to grahamcluley

  • Microsoft Warns of AD CS Vulnerability Let Attackers Deny Service Over a Network

    Microsoft Warns of AD CS Vulnerability Let Attackers Deny Service Over a Network Microsoft has issued a security advisory regarding a new vulnerability in Active Directory Certificate Services (AD CS) that could allow attackers to perform denial-of-service attacks over a network.  The vulnerability, identified as CVE-2025-29968, affects multiple versions of Windows Server and has been…

  • Microsoft Defender Vulnerability Allows Attackers to Elevate Privileges

    Microsoft Defender Vulnerability Allows Attackers to Elevate Privileges A newly disclosed security flaw in Microsoft Defender for Endpoint could allow attackers with local access to elevate their privileges to SYSTEM level, potentially gaining complete control over affected systems.  The vulnerability, tracked as CVE-2025-26684, was patched as part of Microsoft’s May 2025 Patch Tuesday security updates…

  • 82,000+ WordPress Sites Exposed to Remote Code Execution Attacks

    82,000+ WordPress Sites Exposed to Remote Code Execution Attacks Critical vulnerabilities were identified in TheGem, a premium WordPress theme with more than 82,000 installations worldwide.  Researchers identified two separate but interconnected vulnerabilities in TheGem theme versions 5.10.3 and earlier.  When combined, these vulnerabilities create a dangerous attack vector that could lead to remote code execution…

  • Cobalt Strike 4.11.1 Released With Fix For ‘Enable SSL’ Checkbox

    Cobalt Strike 4.11.1 Released With Fix For ‘Enable SSL’ Checkbox Fortra has released Cobalt Strike 4.11.1, an out-of-band update addressing critical issues discovered in their recent 4.11 release.  This update, released on May 12, 2025, focuses primarily on resolving module stomping complications while also addressing issues with SSL certificate functionality and adding deprecation warnings for…

  • PoC Exploit Released for macOS CVE-2025-31258 Vulnerability Bypassing Sandbox Security

    PoC Exploit Released for macOS CVE-2025-31258 Vulnerability Bypassing Sandbox Security A proof-of-concept (PoC) exploit has been released for a recently patched vulnerability in Apple’s macOS operating system, tracked as CVE-2025-31258.  The flaw could allow malicious applications to break out of the macOS sandbox protection mechanism, potentially giving attackers access to sensitive system resources and user…

  • F5 BIG-IP Command Injection Vulnerability Let Attackers Execute Arbitrary System Commands

    F5 BIG-IP Command Injection Vulnerability Let Attackers Execute Arbitrary System Commands F5 Networks has disclosed a high-severity command injection vulnerability (CVE-2025-31644) in its BIG-IP products running in Appliance mode.  The vulnerability exists in an undisclosed iControl REST endpoint and BIG-IP TMOS Shell (tmsh) command, allowing attackers to bypass Appliance mode security restrictions.  Classified as CWE-78…

  • PoC Exploit Released For Linux Kernel’s nftables Subsystem Vulnerability

    PoC Exploit Released For Linux Kernel’s nftables Subsystem Vulnerability A critical Proof-of-Concept (PoC) exploit has been released for a significant vulnerability in the Linux kernel’s nftables subsystem, tracked as CVE-2024-26809.  This flaw, rooted in the kernel’s netfilter infrastructure, exposes affected systems to local privilege escalation through a sophisticated double-free attack.  Security researchers, including the user…

  • Critical Vulnerabilities in Mitel SIP Phones Let Attackers Inject Malicious Commands

    Critical Vulnerabilities in Mitel SIP Phones Let Attackers Inject Malicious Commands Security researchers have discovered two significant vulnerabilities affecting Mitel’s suite of SIP phones that could allow attackers to execute arbitrary commands and upload malicious files. The more severe vulnerability, identified as CVE-2025-47188, received a critical CVSS score of 9.8 and affects the company’s 6800…

  • “PupkinStealer” A New .NET-Based Malware Steals Browser Credentials & Exfiltrate via Telegram

    “PupkinStealer” A New .NET-Based Malware Steals Browser Credentials & Exfiltrate via Telegram A newly identified information-stealing malware, dubbed PupkinStealer, Developed in C# using the .NET framework, this lightweight yet effective malware targets sensitive user data, including browser credentials, desktop files, messaging app sessions, and screenshots. According to a CYFIRMA detailed analysis shared with Cyber Security…

  • Chinese Hackers Exploit SAP RCE Vulnerability to Upload Supershell Backdoors

    Chinese Hackers Exploit SAP RCE Vulnerability to Upload Supershell Backdoors A critical remote code execution vulnerability in SAP NetWeaver Visual Composer (CVE-2025-31324) is being actively exploited by a Chinese threat actor to compromise enterprise systems worldwide. The vulnerability allows attackers to achieve remote code execution by uploading malicious web shells through the vulnerable /developmentserver/metadatauploader endpoint.…