CVE-2025-54948 & CVE-2025-54987: Trend Micro Apex One Exploited for RC...
CVE-2025-54948 & CVE-2025-54987: Trend Micro Apex One Exploited for RCE Trend Micro has recently disclosed two critical vulnerabilities, CVE-2025-54948 and CVE-2025-54987, affecting its Apex One o...
Akira Exploits SonicWall SSLVPN in Suspected Zero-Day Attacks
Akira Exploits SonicWall SSLVPN in Suspected Zero-Day Attacks [Update] Surge in Exploitation of CVE-2024-40766 by Akira [Update] SonicWall Links Attacks to CVE-2024-40766, Not a Zero-Day A string of ...
Critical OAuth2-Proxy Vulnerability (CVE-2025-54576) Lets Attackers By...
Critical OAuth2-Proxy Vulnerability (CVE-2025-54576) Lets Attackers Bypass Authentication A security flaw has been found in OAuth2-Proxy, a tool that helps secure web applications using OAuth2 or OIDC...
June 2025: Qantas, 23andMe, Zoomcar, and Coinbase Breaches Lead Impact
June 2025: Qantas, 23andMe, Zoomcar, and Coinbase Breaches Lead Impact June 2025 witnessed a wave of impactful cyber incidents spanning government agencies, critical infrastructure, healthcare, and ma...
Critical SonicWall SMA Vulnerability CVE-2025-40599: What You Need to ...
Critical SonicWall SMA Vulnerability CVE-2025-40599: What You Need to Know SonicWall has disclosed a critical vulnerability in its SMA 100 series remote access devices, tracked as CVE-2025-40599. This...
What Happened to XSS.is? Everything You Need to Know About the Forum T...
What Happened to XSS.is? Everything You Need to Know About the Forum Takedown This week, authorities made a major move against the cybercrime underground. After years of investigation, the suspected a...
ToolShell Campaign: New SharePoint Zero-Day (CVE-2025-53770) Triggers ...
ToolShell Campaign: New SharePoint Zero-Day (CVE-2025-53770) Triggers Widespread Exploitation [Update] October 23, 2025: Broader Exploitation of ToolShell Vulnerability by Chinese Threat Actors [Updat...
CVE‑2025‑37103: Remote Access Risk in Aruba Instant On Access Points D...
CVE‑2025‑37103: Remote Access Risk in Aruba Instant On Access Points Due to Hardcoded Passwords HPE has disclosed a critical vulnerability in Aruba Instant On access points. The flaw involves a hardco...
CVE-2025-54309: New CrushFTP Zero-Day Exploited in the Wild
CVE-2025-54309: New CrushFTP Zero-Day Exploited in the Wild [Update] “Exploit Details and PoC for CVE-2025-54309 Released” A zero-day vulnerability in CrushFTP, tracked as CVE-2025-54309, is under act...
CVE-2025-25257: Attackers Exploit FortiWeb SQL Injection Bug for Remot...
CVE-2025-25257: Attackers Exploit FortiWeb SQL Injection Bug for Remote Code Execution Cybersecurity researchers have sounded the alarm on an actively exploited vulnerability, tracked as CVE-2025-2525...
Cisco ISE Hit by CVSS 10 RCE Vulnerabilities Allowing Full System Take...
Cisco ISE Hit by CVSS 10 RCE Vulnerabilities Allowing Full System Takeover – Patch Now On July 16, Cisco published multiple security advisories disclosing a total of nine vulnerabilities across severa...
Operation Eastwood Targets NoName057(16) in Global Crackdown
Operation Eastwood Targets NoName057(16) in Global Crackdown An international effort, Operation Eastwood, has recently delivered a decisive blow to one of the most active pro-Russian cybercrime groups...
MITRE Launches AADAPT Framework to Secure Digital Assets
MITRE Launches New AADAPT Framework to Secure Digital Assets Threats to the foundations of the digital finance ecosystem are growing at a rapid pace. From cryptocurrency to smart contracts, vulnerabil...
CVE-2025-47812: Wing FTP Server Exposed to Root-Level RCE Attacks
CVE-2025-47812: Wing FTP Server Exposed to Root-Level RCE Attacks Wing FTP Server has been found vulnerable to a severe security flaw that is now under active exploitation. Identified as CVE-2025-4781...
July 2025 Patch Tuesday Overview: 130 Vulnerabilities & One Disclosed ...
July 2025 Patch Tuesday Overview: 130 Vulnerabilities & One Disclosed Zero-Day (CVE-2025-49719) Microsoft’s July 2025 Patch Tuesday brings fixes for 130 security vulnerabilities across its product...
CVE-2025-20309: Cisco Unified CM Flaw Enables Remote Root Access
CVE-2025-20309: Cisco Unified CM Flaw Enables Remote Root Access A newly discovered vulnerability in Cisco’s Unified Communications Manager platforms has drawn significant attention. Tracked as CVE-20...
CVE-2025-49596: Critical Flaw in Anthropic’s MCP Inspector Leads to RC...
CVE-2025-49596: Critical Flaw in Anthropic’s MCP Inspector Leads to RCE A critical vulnerability recently uncovered in Anthropic’s MCP Inspector has raised alarms across the AI developer landscape. An...
CVE-2025-6554: Chrome’s New Zero-Day Under Active Exploitation
CVE-2025-6554: Chrome’s New Zero-Day Under Active Exploitation A high-severity security flaw in Google Chrome is under active exploitation, prompting an urgent response. Identified as CVE-2025-6554, t...
How Are North Korean IT Workers Hacking the Global Remote Job Market?
How Are North Korean IT Workers Hacking the Global Remote Job Market? North Korean threat actors are no longer just building malware or running phishing campaigns. They are quietly infiltrating compan...
CVE-2025-20281 & CVE-2025-20282: Critical Cisco ISE Vulnerabilities Al...
CVE-2025-20281 & CVE-2025-20282: Critical Cisco ISE Vulnerabilities Allow Root-Level RCE [Update] July 29, 2025: “Exploit Released, Actively Used in the Wild” A new security advisory has unveiled ...
