204Articles
10Categories
2025-05-13Date
๐Ÿšจ
CISA Warns of Flaw in TeleMessage App Used by Ex-National Security AdvisorAn information exposure flaw in TeleMessage has been added to CISAโ€™s Known Exploited Vulnerabilities catalog. The post CISA Warns of Flaw in TeleMessage App Used by Ex-National Security Advisor appeared first on SecurityWeek .
KEV
๐Ÿšจ
CISA Adds Five Known Exploited Vulnerabilities to CatalogCISA has added five new vulnerabilities to its Known Exploited Vulnerabilities Catalog , based on evidence of active exploitation. CVE-2025-30400 Microsoft Windows DWM Core Library Use-After-Free Vulnerability CVE-2025-32701 Microsoft Windows Common Log File System (CLFS) Driver โ€ฆ
KEV
๐Ÿšจ
RSS feed for CISA KEV vulnerabilities, powered by Vulnerability-Lookupsubmitted by cm0002 to cybersecurity 1 points | 0 comments https://www.vulnerability-lookup.org/user-manual/feed-syndication/#most-recent-entries-from-known-exploited-vulnerabilities
KEV
๐Ÿ›
Attackers Leverage Unpatched Outputโ€ฏMessenger 0โ€‘Day to Deliver Malicious Payloads
๐Ÿ›
CISA Flags Hidden Functionality Flaw in TeleMessage TM SGNL on KEV List
KEV
๐Ÿ›
Asus One-Click Flaw Exposes Users to Remote Code Execution Attacks
๐Ÿ›
F5 BIG-IP Vulnerability Allows Remote Command Execution
๐Ÿ›
PoC Exploit Published for macOS Sandbox Escape Vulnerability (CVE-2025-31258)
๐Ÿ›
PoC Released: CVE-2025-31258 Sandbox Escape in macOS via RemoteViewServices
๐Ÿ›
China-Linked APTs Exploit SAP CVE-2025-31324 to Breach 581 Critical Systems Worldwide
๐Ÿ›
New EU vulnerability database will complement CVE program, not compete with it, says ENISA
๐Ÿ›
CVE-2025-26646 .NET, Visual Studio, and Build Tools for Visual Studio Spoofing Vulnerability
๐Ÿ›
CVE-2025-26684 Microsoft Defender Elevation of Privilege Vulnerability
๐Ÿ›
CVE-2025-29959 Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability
๐Ÿ›
CVE-2025-29960 Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability
๐Ÿ›
CVE-2025-29964 Windows Media Remote Code Execution Vulnerability
๐Ÿ›
CVE-2025-29966 Remote Desktop Client Remote Code Execution Vulnerability
๐Ÿ›
CVE-2025-29967 Remote Desktop Client Remote Code Execution Vulnerability
๐Ÿ›
CVE-2025-29968 Active Directory Certificate Services (AD CS) Denial of Service Vulnerability
๐Ÿ›
CVE-2025-29969 MS-EVEN RPC Remote Code Execution Vulnerability
๐Ÿ›
CVE-2025-29970 Microsoft Brokering File System Elevation of Privilege Vulnerability
๐Ÿ›
CVE-2025-29971 Web Threat Defense (WTD.sys) Denial of Service Vulnerability
๐Ÿ›
CVE-2025-29973 Microsoft Azure File Sync Elevation of Privilege Vulnerability
๐Ÿ›
CVE-2025-29975 Microsoft PC Manager Elevation of Privilege Vulnerability
๐Ÿ›
CVE-2025-29976 Microsoft SharePoint Server Elevation of Privilege Vulnerability
๐Ÿ›
CVE-2025-29977 Microsoft Excel Remote Code Execution Vulnerability
๐Ÿ›
CVE-2025-29978 Microsoft PowerPoint Remote Code Execution Vulnerability
๐Ÿ›
CVE-2025-29979 Microsoft Excel Remote Code Execution Vulnerability
๐Ÿ›
CVE-2025-30375 Microsoft Excel Remote Code Execution Vulnerability
๐Ÿ›
CVE-2025-30376 Microsoft Excel Remote Code Execution Vulnerability
๐Ÿ›
CVE-2025-30377 Microsoft Office Remote Code Execution Vulnerability
๐Ÿ›
CVE-2025-30378 Microsoft SharePoint Server Remote Code Execution Vulnerability
๐Ÿ›
CVE-2025-30379 Microsoft Excel Remote Code Execution Vulnerability
๐Ÿ›
CVE-2025-30381 Microsoft Excel Remote Code Execution Vulnerability
๐Ÿ›
CVE-2025-30382 Microsoft SharePoint Server Remote Code Execution Vulnerability
๐Ÿ›
CVE-2025-30383 Microsoft Excel Remote Code Execution Vulnerability
๐Ÿ›
CVE-2025-30384 Microsoft SharePoint Server Remote Code Execution Vulnerability
๐Ÿ›
CVE-2025-30386 Microsoft Office Remote Code Execution Vulnerability
๐Ÿ›
CVE-2025-30387 Document Intelligence Studio On-Prem Elevation of Privilege Vulnerability
๐Ÿ›
CVE-2025-27468 Windows Kernel-Mode Driver Elevation of Privilege Vulnerability
๐Ÿ›
CVE-2025-30393 Microsoft Excel Remote Code Execution Vulnerability
๐Ÿ›
CVE-2025-29826 Microsoft Dataverse Elevation of Privilege Vulnerability
๐Ÿ›
CVE-2025-30394 Windows Remote Desktop Gateway (RD Gateway) Denial of Service Vulnerability
๐Ÿ›
CVE-2025-30400 Microsoft DWM Core Library Elevation of Privilege Vulnerability
๐Ÿ›
CVE-2025-32701 Windows Common Log File System Driver Elevation of Privilege Vulnerability
๐Ÿ›
CVE-2025-32703 Visual Studio Information Disclosure Vulnerability
๐Ÿ›
CVE-2025-32706 Windows Common Log File System Driver Elevation of Privilege Vulnerability
๐Ÿ›
CVE-2025-21264 Visual Studio Code Security Feature Bypass Vulnerability
๐Ÿ›
CVE-2025-32709 Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
๐Ÿ›
CVE-2025-26677 Windows Remote Desktop Gateway (RD Gateway) Denial of Service Vulnerability
๐Ÿ›
CVE-2025-27488 Microsoft Windows Hardware Lab Kit (HLK) Elevation of Privilege Vulnerability
๐Ÿ›
CVE-2025-26685 Microsoft Defender for Identity Spoofing Vulnerability
๐Ÿ›
CVE-2025-29829 Windows Trusted Runtime Interface Driver Information Disclosure Vulnerability
๐Ÿ›
CVE-2025-29830 Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability
๐Ÿ›
CVE-2025-29831 Windows Remote Desktop Services Remote Code Execution Vulnerability
๐Ÿ›
CVE-2025-29832 Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability
๐Ÿ›
CVE-2025-29833 Microsoft Virtual Machine Bus (VMBus) Remote Code Execution Vulnerability
๐Ÿ›
CVE-2025-29835 Windows Remote Access Connection Manager Information Disclosure Vulnerability
๐Ÿ›
CVE-2025-29836 Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability
๐Ÿ›
CVE-2025-29837 Windows Installer Information Disclosure Vulnerability
๐Ÿ›
CVE-2025-29838 Windows ExecutionContext Driver Elevation of Privilege Vulnerability
๐Ÿ›
CVE-2025-29839 Windows Multiple UNC Provider Driver Information Disclosure Vulnerability
๐Ÿ›
CVE-2025-29840 Windows Media Remote Code Execution Vulnerability
๐Ÿ›
CVE-2025-29841 Universal Print Management Service Elevation of Privilege Vulnerability
๐Ÿ›
CVE-2025-29842 UrlMon Security Feature Bypass Vulnerability
๐Ÿ›
CVE-2025-29954 Windows Lightweight Directory Access Protocol (LDAP) Denial of Service Vulnerability
๐Ÿ›
CVE-2025-29955 Windows Hyper-V Denial of Service Vulnerability
๐Ÿ›
CVE-2025-29956 Windows SMB Information Disclosure Vulnerability
๐Ÿ›
CVE-2025-29957 Windows Deployment Services Denial of Service Vulnerability
๐Ÿ›
CVE-2025-29958 Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability
๐Ÿ›
CVE-2025-29961 Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability
๐Ÿ›
CVE-2025-29962 Windows Media Remote Code Execution Vulnerability
๐Ÿ›
CVE-2025-29963 Windows Media Remote Code Execution Vulnerability
๐Ÿ›
CVE-2025-29974 Windows Kernel Information Disclosure Vulnerability
๐Ÿ›
CVE-2025-30385 Windows Common Log File System Driver Elevation of Privilege Vulnerability
๐Ÿ›
CVE-2025-30388 Windows Graphics Component Remote Code Execution Vulnerability
๐Ÿ›
CVE-2025-30397 Scripting Engine Memory Corruption Vulnerability
๐Ÿ›
CVE-2025-32702 Visual Studio Remote Code Execution Vulnerability
๐Ÿ›
CVE-2025-32704 Microsoft Excel Remote Code Execution Vulnerability
๐Ÿ›
CVE-2025-32705 Microsoft Outlook Remote Code Execution Vulnerability
๐Ÿ›
CVE-2025-32707 NTFS Elevation of Privilege Vulnerability
๐Ÿ›
CVE-2025-24063 Kernel Streaming Service Driver Elevation of Privilege Vulnerability
๐Ÿ›
CVE-2017-0045 Windows DVD Maker XML External Entity Information Disclosure Vulnerability
๐Ÿ›
Researchers bypass Intelโ€™s Spectre fixes โ€” six years of CPUs at risk
โš ๏ธ
So schรผtzen Zugriffskontrollen vor Ransomware
โš ๏ธ
Top-Tipps fรผr die erfolgreiche Nutzung von Bedrohungsdaten
โš ๏ธ
Deepfake attacks are inevitable. CISOs canโ€™t prepare soon enough.
KEV
โš ๏ธ
Tรผrkiye Hackers Exploited Output Messenger Zero-Day to Drop Golang Backdoors on Kurdish Servers
โš ๏ธ
Merckโ€™s CISO Volker BuรŸ on securing global operations
โš ๏ธ
Moldovan Police Arrest Suspect in โ‚ฌ4.5M Ransomware Attack on Dutch Research Agency
โš ๏ธ
CIO des Jahres 2025 โ€“ jetzt mitmachen und bis Ende Mai bewerben
โš ๏ธ
Secure Code Reviews, LLM Coding Assistants, and Trusting Code - Rey Bango, Karim Toubb... - ASW #330
โš ๏ธ
Output Messenger Zero-Day Exploited by Turkish Hackers for Iraq Spying
โš ๏ธ
Court Rules Against NSO Group
โš ๏ธ
CISAโ€™s alert pivot reflects a new era of decentralized cyber threat communication
KEV
โš ๏ธ
Hackers Abuse PyInstaller to Deploy Stealthy macOS Infostealer
โš ๏ธ
European Vulnerability Database Launches Amid US CVE Chaos
โš ๏ธ
Radware Says Recently Disclosed WAF Bypasses Were Patched in 2023
โš ๏ธ
SAP Patches Another Critical NetWeaver Vulnerability
โš ๏ธ
Zoom Workplace Apps Flaws Allow Hackers to Gain Elevated Access
โš ๏ธ
Four Hackers Caught Exploiting Old Routers as Proxy Servers
โš ๏ธ
How phishing emails are sent from no-reply@accounts.google.com | Kaspersky official blog
โš ๏ธ
M&S says customer data stolen in cyberattack, forces password resets
โš ๏ธ
Output Messenger Zero-Day Exploited by Turkish Hackers for Iraq Spying
โš ๏ธ
F5 BIG-IP Vulnerability Allows Remote Command Execution
โš ๏ธ
Malicious PyPI Package Posing as Solana Tool Stole Source Code in 761 Downloads
โš ๏ธ
Ivanti warns of critical Neurons for ITSM auth bypass flaw
โš ๏ธ
Britainโ€™s intelligence services see โ€œdirect connection between Russian cyber attacks and physical threats to our security"
โš ๏ธ
Britainโ€™s intelligence services see โ€œdirect connection between Russian cyber attacks and physical threats to our security"
โš ๏ธ
Hackers Weaponize KeePass Password Manager to Spread Malware and Steal Passwords
โš ๏ธ
Ransomware Attacks Surge by 123% Amid Evolving Tactics and Strategies
โš ๏ธ
Fortinet fixes critical zero-day exploited in FortiVoice attacks
โš ๏ธ
Fortinet FortiVoice Zero-day Vulnerability Actively Exploited in The Wild
KEV
โš ๏ธ
He Used a Fortinet Boxโ€ฆ And Got More Than He Bargained For!
โš ๏ธ
Ivanti Released Security Updates to Fix for the Mutiple RCE Vulnerabilities โ€“ Patch Now
โš ๏ธ
Microsoft May 2025 Patch Tuesday fixes 5 exploited zero-days, 72 flaws
KEV
โš ๏ธ
Zero-Day Attacks Highlight Another Busy Microsoft Patch Tuesday
โš ๏ธ
Ivanti fixes EPMM zero-days chained in code execution attacks
โš ๏ธ
Microsoft May 2025 Patch Tuesday fixes 5 exploited zero-days, 72 flaws
โš ๏ธ
Microsoft Patch Tuesday May 2025 Released With the Fixes for 72 Flaws With 5 Actively Exploited 0-Day
KEV
โš ๏ธ
Microsoft to Lay Off About 3% of Its Workforce
โš ๏ธ
AI Picked a Sideโ€ฆ And Shocked Everyone ๐Ÿ‘€
โš ๏ธ
Adobe Patches Big Batch of Critical-Severity Software Flaws
โš ๏ธ
Microsoft Patch Tuesday: May 2025, (Tue, May 13th)
โš ๏ธ
The Clock Is Ticking: Why Phishing Remains The Fastest-Moving Cyber Threat in 2025
โš ๏ธ
SAP patches second zero-day flaw exploited in recent attacks
โš ๏ธ
Critical Patches Issued for Microsoft Products, May 13, 2025
โš ๏ธ
News Alert: INE Security outlines top 5 training priorities emerging from RSAC 2025
โš ๏ธ
Is That Guy in the Lobbyโ€ฆ Hacking Your System?
โš ๏ธ
4 critical leadership priorities for CISOs in the AI era
โš ๏ธ
12 AI terms you (and your flirty chatbot) should know by now
โš ๏ธ
Whatโ€™s New in Android Security and Privacy in 2025
KEV
โš ๏ธ
Advanced Protection: Googleโ€™s Strongest Security for Mobile Devices
โš ๏ธ
Multiple Vulnerabilities in Fortinet Products Could Allow for Arbitrary Code Execution
๐Ÿ“‹
Apple Releases Security Patches to Fix Critical Data Exposure Flaws
๐Ÿ“‹
Microsoft will update Office apps on Windows 10 until 2028
๐Ÿ“ข
CISA mutes own website, shifts routine cyber alerts to Muskโ€™s X, RSS, email โ€ข The Register
๐Ÿ“ข
IAM 2025: Diese 10 Trends entscheiden รผber Ihre Sicherheitsstrategie
๐Ÿ“ข
Apple security advisory (AV25-264)
๐Ÿ“ข
SAP security advisory โ€“ May 2025 monthly rollup (AV25-265)
๐Ÿ“ข
Five Years Later: Evolving IoT Cybersecurity Guidelines
๐Ÿ“ข
CISA Statement on Cyber-Related Alerts and Notifications
๐Ÿ”ฅ
Suspected DoppelPaymer Ransomware Group Member Arrested
๐Ÿ”ฅ
INE Security Alert: Top 5 Takeaways from RSAC 2025
๐Ÿ”ฅ
Marks & Spencer Says Data Stolen in Ransomware Attack
๐Ÿ”ฅ
Marks & Spencer confirms customersโ€™ personal data was stolen in hack
๐Ÿ”ฅ
Cybercriminals Hide Undetectable Ransomware Inside JPG Images
๐Ÿ”ฅ
You think ransomware is bad? Wait until it infects CPUs
๐Ÿ”ฅ
A Subtle Form of Siege: DDoS Smokescreens as a Cover for Quiet Data Breaches
๐Ÿ”ฅ
Airline carrying out deportation flights confirms cyberattack to SEC
๐Ÿ”ฅ
Marks & Spencer Confirms Customer Data Breach in Recent Cyber Attack
๐Ÿ”ฅ
Two yearsโ€™ jail for down-on-his-luck man who sold ransomware online
๐Ÿ”ฅ
Government email alert system GovDelivery used to send scam messages
๐Ÿ”ฅ
Twilio denies breach following leak of alleged Steam 2FA codes
๐Ÿ”ฅ
Looks Like a Resume. Itโ€™s Actually a Backdoorโ€ฆ
๐Ÿ”ฅ
The Cyber Ransom Debate: Pay Up or Shut Down?
๐Ÿ•ต๏ธ
ISC Stormcast For Tuesday, May 13th, 2025 https://isc.sans.edu/podcastdetail/9448, (Tue, May 13th)
๐Ÿ•ต๏ธ
Earth Ammit Disrupts Drone Supply Chains Through Coordinated Multi-Wave Attacks in Taiwan
๐Ÿ•ต๏ธ
Authorโ€™s Q&A: Itโ€™s high time for CISOs to start leading strategically โ€” or risk being scapegoated
๐Ÿ•ต๏ธ
Cobalt Strike 4.11.1 Released With SSL Checkbox Fix
๐Ÿ•ต๏ธ
Researchers Uncover Remote IT Job Fraud Scheme Involving North Korean Nationals
๐Ÿ•ต๏ธ
Orca Snaps Up Opus in Cloud Security Automation Push
๐Ÿ•ต๏ธ
Repeated Firmware Key-Management Failures Undermine Intel Boot Guard and UEFI Secure Boot
๐Ÿ•ต๏ธ
PupkinStealer Targets Windows Users to Steal Browser Login Credentials
๐Ÿ•ต๏ธ
North Korean Konni APT Targets Ukraine with Malware to track Russian Invasion Progress
๐Ÿ•ต๏ธ
Phishing Scams on the Rise with Sophisticated PhaaS Toolkits and Realistic Fake Pages
๐Ÿ•ต๏ธ
Hackers Weaponizing PDF Invoices to Attack Windows, Linux & macOS Systems
๐Ÿ•ต๏ธ
Phishing Campaign Uses Blob URLs to Bypass Email Security and Avoid Detection
๐Ÿ•ต๏ธ
4 Hackers Arrested After Millions Made in Global Botnet Business
๐Ÿ•ต๏ธ
Apple Patches Major Security Flaws in iOS, macOS Platforms
๐Ÿ•ต๏ธ
Fake image-to-video AI sites deliver novel โ€˜Noodlophileโ€™ infostealer
๐Ÿ•ต๏ธ
Spain investigates cyber weaknesses at small power plants after blackout, FT reports
๐Ÿ•ต๏ธ
Scattered Spider Launches Supply Chain Attacks on UK Retail Organizations
๐Ÿ•ต๏ธ
Advancing Cybersecurity in Australia
๐Ÿ•ต๏ธ
CyberheistNews Vol 15 #19 [Heads Up] Talos Report Shows Phishing Attacks Surged in Q1 2025
๐Ÿ•ต๏ธ
Sharing Intelligence Beyond CTI Teams, Across Wider Functions and Departments
๐Ÿ•ต๏ธ
North Korean Konni APT Targets Ukraine with Malware to track Russian Invasion Progress
๐Ÿ•ต๏ธ
Scattered Spider Launches Supply Chain Attacks on UK Retail Organizations
๐Ÿ•ต๏ธ
One Paste = One Stolen Wallet (Cybersecurity Alert)
๐Ÿ•ต๏ธ
Swan Vector APT Targets Organizations with Malicious LNK and DLL Implants
๐Ÿ•ต๏ธ
Researchers Introduce Mythic Framework Agent to Enhance Pentesting Tool Performance
๐Ÿ•ต๏ธ
UK Considers New Enterprise IoT Security Law
๐Ÿ•ต๏ธ
New Intel CPU flaws leak sensitive data from privileged memory
๐Ÿ•ต๏ธ
Government email alert system GovDelivery used to send scam messages
๐Ÿ•ต๏ธ
How to Protect Your Business from Scattered Spider's Latest Attack Methods
๐Ÿ•ต๏ธ
North Korea ramps up cyberspying in Ukraine to assess war risk
๐Ÿ•ต๏ธ
Deepfake, South Korea, Moonlander, ChineseAI, FBI, AI damages professional reputation - SWN #476
๐Ÿ•ต๏ธ
Intel data-leaking Spectre defenses scared off once again
๐ŸŒ
Deepfake Defense in the Age of AI
๐ŸŒ
Android 16 expands 'Advanced Protection' with device-level security
๐ŸŽ™๏ธ
The AI Fix #50: AI brings dead man back for killerโ€™s trial, and the judge loves it
๐Ÿ“ก
Introducing the Sophos MSP Elevate program
๐Ÿ“ก
Increase Red Team Operations 10X with Adversarial Exposure Validation
๐Ÿ“ก
Cybersecurity Isnโ€™t Insurance โ€” Itโ€™s Survival!
๐Ÿ“ก
New Intel CPU flaws leak sensitive data from privileged memory
๐Ÿ“ก
How CISOs Quietly Influence Billions in Revenue!
๐Ÿ“ก
Google announces new security features for Android for protection against scam and theft
๐Ÿ“ก
Windows 10 KB5058379 update fixes SgrmBroker errors in Event Viewer
๐Ÿ“ก
Windows 11 KB5058411 and KB5058405 cumulative updates released
๐Ÿ“ก
Cybersecurity Is Teamwork... and Tech Headaches
๐Ÿ“ก
Google introduces Advanced Protection mode for its most at-risk Android users
๐Ÿ“ก
Nineteen Sophos Women Recognized by CRNโ€™s Women of the Channel
๐Ÿ“ก
Trend Micro Puts a Spotlight on AI at Pwn2Own Berlin
๐Ÿ“ก
xAIโ€™s promised safety report is MIA