ConnectWise Automate Flaws Allow Fake Updates: CVE-2025-11492 and CVE-...
ConnectWise Automate Flaws Allow Fake Updates: CVE-2025-11492 and CVE-2025-11493 When trusted IT management platforms reveal cracks in their armor, every second counts. The latest update for ConnectWi...
CVE-2025-54253: Critical Adobe Experience Manager Vulnerability Active...
CVE-2025-54253: Critical Adobe Experience Manager Vulnerability Actively Exploited A critical vulnerability, CVE-2025-54253, has recently been exploited in Adobe Experience Manager (AEM), drawing urge...
F5 Breach and Urgent BIG-IP Fixes: What You Need to Know
F5 Breach and Urgent BIG-IP Fixes: What You Need to Know On October 15, 2025, F5 disclosed details of a security incident that it first detected in August. According to the company, an intruder access...
Adobe Patches Critical Connect Flaw (CVE-2025-49553) and 35 More Acros...
Adobe Patches Critical Connect Flaw (CVE-2025-49553) and 35 More Across Creative Suite Adobe has released a broad set of security updates addressing 36 vulnerabilities across products including Adobe ...
October 2025 Patch Tuesday: Microsoft Addresses 175 Vulnerabilities, I...
October 2025 Patch Tuesday: Microsoft Addresses 175 Vulnerabilities, Including 3 Exploited Zero-Days [Update] CVE-2025-59287 Added to CISA KEV After Confirmed Exploitation Microsoft has rolled out its...
CVE-2025-61884: Oracle Issues Urgent Security Alert for New E-Business...
CVE-2025-61884: Oracle Issues Urgent Security Alert for New E-Business Suite Vulnerability [Update] CVE-2025-61884 Added to CISA KEV & Ongoing Clop Activity Over the weekend, Oracle dropped an imp...
BreachForums Seized (Yes, Again)
BreachForums Seized (Yes, Again) The U.S. Department of Justice, FBI, and France’s BL2C cybercrime unit, with support from the Paris Prosecutor’s Office, have seized the latest BreachForums domain, ma...
Discord Breach: What We Know So Far?
Discord Breach: What We Know So Far? Discord confirmed a data breach linked to a third-party customer support vendor. Hackers claim to have stolen data from 5.5 million users, including government IDs...
Redis RediShell Vulnerability (CVE-2025-49844): What You Need to Know
Redis RediShell Vulnerability (CVE-2025-49844): What You Need to Know When one of the most widely used databases in the cloud world turns out to have a critical flaw, it’s worth paying attention. Redi...
CVE-2025-61882: Oracle E-Business Suite Exploited – What You Need to K...
CVE-2025-61882: Oracle E-Business Suite Exploited – What You Need to Know Recently, Oracle confirmed a critical zero-day vulnerability in Oracle E-Business Suite (EBS), tracked as CVE-2025-61882. The ...
Fake Microsoft Teams Installers Deliver Oyster Backdoor
Fake Microsoft Teams Installers Deliver Oyster Backdoor Malicious ads and SEO poisoning are still good ways to get into someone’s computer. A recent campaign shows this again by getting people to down...
Red Hat Breach: Crimson Collective Claims Massive Theft of Private Rep...
Red Hat Breach: Crimson Collective Claims Massive Theft of Private Repositories [Update] October 14, 2025: Crimson Collective Advertises Stolen Red Hat Data for Sale [Update] October 7, 2025: Crimson...
CVE-2025-32463: Sudo Privilege Escalation Vulnerability Exploited, CIS...
CVE-2025-32463: Sudo Privilege Escalation Vulnerability Exploited, CISA Warns The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has confirmed that attackers are actively exploiting CVE-...
VMware CVE-2025-41244 Exploited: What You Need to Know About the Lates...
VMware CVE-2025-41244 Exploited: What You Need to Know About the Latest Flaws [Update] VMware Aria Operations & Tools Vulnerability (CVE-2025-41244) Added to CISA KEV Cybersecurity researchers hav...
Cisco ASA, FTD Devices Under Active Attack via Zero-Days CVE-2025-2033...
Cisco ASA, FTD Devices Under Active Attack via Zero-Days CVE-2025-20333 & CVE-2025-20362 A newly disclosed wave of zero-day attacks is targeting Cisco firewall products, raising urgent concerns fo...
CVE-2025-20352: Zero-Day in Cisco IOS & IOS XE SNMP Exploited, Allows ...
CVE-2025-20352: Zero-Day in Cisco IOS & IOS XE SNMP Exploited, Allows DoS and Root RCE [Update] Attackers Exploit CVE-2025-20352 to Deploy Rootkits in Operation Zero Disco [Update] CVE-2025-20352...
CVE-2025-26399: Critical RCE in SolarWinds Web Help Desk Receives a Ho...
CVE-2025-26399: Critical RCE in SolarWinds Web Help Desk Receives a Hotfix Another critical security vulnerability has emerged in SolarWinds’ widely used Web Help Desk software. Marked with a near-max...
CVE-2025-10035: Critical GoAnywhere MFT Vulnerability Could Lead to Co...
CVE-2025-10035: Critical GoAnywhere MFT Vulnerability Could Lead to Command Injection [Update] October 7, 2025: Added details on active exploitation of CVE-2025-10035 by Storm-1175 to deploy Medusa ra...
Heathrow Airport Cyberattack: What Happened, Who's Affected, and What ...
Heathrow Airport Cyberattack: What Happened, Who’s Affected, and What CISOs Should Know [Update] October 22, 2025: Everest Group Claims Responsibility and Shares Alleged Proof of Collins Aerospace Bre...
CVE-2025-10585: New Chrome V8 Zero-Day Exploited in the Wild
CVE-2025-10585: New Chrome V8 Zero-Day Exploited in the Wild Google has released a security update for Chrome users, involving a serious vulnerability that is exploited in the wild. The flaw, identifi...
