183Articles
9Categories
2025-06-10Date
🚨
CISA Adds Erlang SSH and Roundcube Flaws to Known Exploited Vulnerabilities CatalogThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added two critical security flaws impacting Erlang/Open Telecom Platform (OTP) SSH and Roundcube to its Known Exploited Vulnerabilities (KEV) catalog, based on evidence of active exploitation. The vulnerab…
KEV
🚨
CISA Issues Alert on Erlang/OTP SSH Server RCE Vulnerability Under Active ExploitationThe Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent warning regarding a critical vulnerability in Erlang/OTP SSH server implementations that allows attackers to execute arbitrary commands without authentication. The vulnerability, designated as CVE-20…
KEV
🚨
CISA Adds Erlang SSH and Roundcube Flaws to Known Exploited Vulnerabilities Catalogsubmitted by kid to cybersecurity 1 points | 0 comments https://thehackernews.com/2025/06/cisa-adds-erlang-ssh-and-roundcube.html
KEV
🚨
CISA Adds Two Known Exploited Vulnerabilities to CatalogCISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation.  CVE-2025-24016 Wazuh Server Deserialization of Untrusted Data Vulnerability CVE-2025-33053 Web Distributed Authoring and Versioning (WebDA…
KEV
🚨
Mirai botnet weaponizes PoC to exploit Wazuh open-source XDR flawResearchers warn that several botnets built on the Mirai malware codebase are targeting outdated Wazuh XDR and SIEM management servers. For the past several months, the botnets have been exploiting a critical remote code execution vulnerability in Wazuh that was patched in Februa…
KEV
πŸ›
ManageEngine Exchange Reporter Plus Vulnerability Enables Remote Code Execution
πŸ›
Over 84,000 Roundcube Webmail Installations Exposed to Remote Code Vulnerabilities
πŸ›
Exploitation of Critical Wazuh Server RCE Vulnerability Leads to Mirai Variant Deployment
πŸ›
Ivanti Workspace Control Vulnerability Lets Attackers Remotely Exploit To Steal the Credential
πŸ›
CVE-2025-47957 Microsoft Word Remote Code Execution Vulnerability
πŸ›
CVE-2025-29828 Windows Schannel Remote Code Execution Vulnerability
πŸ›
CVE-2025-30399 .NET and Visual Studio Remote Code Execution Vulnerability
πŸ›
CVE-2025-32710 Windows Remote Desktop Services Remote Code Execution Vulnerability
πŸ›
CVE-2025-32712 Win32k Elevation of Privilege Vulnerability
πŸ›
CVE-2025-32713 Windows Common Log File System Driver Elevation of Privilege Vulnerability
πŸ›
CVE-2025-32714 Windows Installer Elevation of Privilege Vulnerability
πŸ›
CVE-2025-32715 Remote Desktop Protocol Client Information Disclosure Vulnerability
πŸ›
CVE-2025-32716 Windows Media Elevation of Privilege Vulnerability
πŸ›
CVE-2025-32718 Windows SMB Client Elevation of Privilege Vulnerability
πŸ›
CVE-2025-32719 Windows Storage Management Provider Information Disclosure Vulnerability
πŸ›
CVE-2025-32720 Windows Storage Management Provider Information Disclosure Vulnerability
πŸ›
CVE-2025-32721 Windows Recovery Driver Elevation of Privilege Vulnerability
πŸ›
CVE-2025-32722 Windows Storage Port Driver Information Disclosure Vulnerability
πŸ›
CVE-2025-32724 Local Security Authority Subsystem Service (LSASS) Denial of Service Vulnerability
πŸ›
CVE-2025-33058 Windows Storage Management Provider Information Disclosure Vulnerability
πŸ›
CVE-2025-33059 Windows Storage Management Provider Information Disclosure Vulnerability
πŸ›
CVE-2025-33060 Windows Storage Management Provider Information Disclosure Vulnerability
πŸ›
CVE-2025-33061 Windows Storage Management Provider Information Disclosure Vulnerability
πŸ›
CVE-2025-33062 Windows Storage Management Provider Information Disclosure Vulnerability
πŸ›
CVE-2025-33063 Windows Storage Management Provider Information Disclosure Vulnerability
πŸ›
CVE-2025-33064 Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
πŸ›
CVE-2025-33065 Windows Storage Management Provider Information Disclosure Vulnerability
πŸ›
CVE-2025-33066 Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
πŸ›
CVE-2025-33067 Windows Task Scheduler Elevation of Privilege Vulnerability
πŸ›
CVE-2025-33075 Windows Installer Elevation of Privilege Vulnerability
πŸ›
CVE-2025-47160 Windows Shortcut Files Security Feature Bypass Vulnerability
πŸ›
CVE-2025-47162 Microsoft Office Remote Code Execution Vulnerability
πŸ›
CVE-2025-47953 Microsoft Office Remote Code Execution Vulnerability
πŸ›
CVE-2025-47955 Windows Remote Access Connection Manager Elevation of Privilege Vulnerability
πŸ›
CVE-2025-47956 Windows Security App Spoofing Vulnerability
πŸ›
CVE-2025-33071 Windows KDC Proxy Service (KPSSVC) Remote Code Execution Vulnerability
πŸ›
CVE-2025-47962 Windows SDK Elevation of Privilege Vulnerability
πŸ›
CVE-2025-47969 Windows Virtualization-Based Security (VBS) Information Disclosure Vulnerability
πŸ›
CVE-2025-24068 Windows Storage Management Provider Information Disclosure Vulnerability
πŸ›
CVE-2025-24069 Windows Storage Management Provider Information Disclosure Vulnerability
πŸ›
CVE-2025-24065 Windows Storage Management Provider Information Disclosure Vulnerability
πŸ›
CVE-2025-32725 DHCP Server Service Denial of Service Vulnerability
πŸ›
CVE-2025-33050 DHCP Server Service Denial of Service Vulnerability
πŸ›
CVE-2025-33052 Windows DWM Core Library Information Disclosure Vulnerability
πŸ›
CVE-2025-33053 Web Distributed Authoring and Versioning (WEBDAV) Remote Code Execution Vulnerability
πŸ›
CVE-2025-33055 Windows Storage Management Provider Information Disclosure Vulnerability
πŸ›
CVE-2025-33056 Windows Local Security Authority (LSA) Denial of Service Vulnerability
πŸ›
CVE-2025-33057 Windows Local Security Authority (LSA) Denial of Service Vulnerability
πŸ›
CVE-2025-33068 Windows Standards-Based Storage Management Service Denial of Service Vulnerability
πŸ›
CVE-2025-33069 Windows App Control for Business Security Feature Bypass Vulnerability
πŸ›
CVE-2025-33070 Windows Netlogon Elevation of Privilege Vulnerability
πŸ›
CVE-2025-33073 Windows SMB Client Elevation of Privilege Vulnerability
πŸ›
CVE-2025-47163 Microsoft SharePoint Server Remote Code Execution Vulnerability
πŸ›
CVE-2025-47164 Microsoft Office Remote Code Execution Vulnerability
πŸ›
CVE-2025-47165 Microsoft Excel Remote Code Execution Vulnerability
πŸ›
CVE-2025-47166 Microsoft SharePoint Server Remote Code Execution Vulnerability
πŸ›
CVE-2025-47167 Microsoft Office Remote Code Execution Vulnerability
πŸ›
CVE-2025-47168 Microsoft Word Remote Code Execution Vulnerability
πŸ›
CVE-2025-47169 Microsoft Word Remote Code Execution Vulnerability
πŸ›
CVE-2025-47170 Microsoft Word Remote Code Execution Vulnerability
πŸ›
CVE-2025-47171 Microsoft Outlook Remote Code Execution Vulnerability
πŸ›
CVE-2025-47172 Microsoft SharePoint Server Remote Code Execution Vulnerability
πŸ›
CVE-2025-47173 Microsoft Office Remote Code Execution Vulnerability
πŸ›
CVE-2025-47174 Microsoft Excel Remote Code Execution Vulnerability
πŸ›
CVE-2025-47175 Microsoft PowerPoint Remote Code Execution Vulnerability
πŸ›
CVE-2025-47176 Microsoft Outlook Remote Code Execution Vulnerability
πŸ›
CVE-2025-3052 Cert CC: CVE-2025-3052 InsydeH2O Secure Boot Bypass
πŸ›
CVE-2025-47959 Visual Studio Remote Code Execution Vulnerability
πŸ›
CVE-2025-47968 Microsoft AutoUpdate (MAU) Elevation of Privilege Vulnerability
πŸ›
CVE-2025-47977 Nuance Digital Engagement Platform Spoofing Vulnerability
πŸ›
Microsoft Windows WebDAV 0-Day RCE Vulnerability Actively Exploited in The Wild
KEV
πŸ›
New Secure Boot flaw lets attackers install bootkit malware, patch now
πŸ›
Stealth Falcon's Exploit of Microsoft Zero Day Vulnerability; Middle Eastern Cyber Espionage.
πŸ›
Stealth Falcon's Exploit of Microsoft Zero Day Vulnerability; Middle Eastern Cyber Espionage.
πŸ›
CVE-2025-32717 Microsoft Word Remote Code Execution Vulnerability
⚠️
PoC Exploit Released for Fortinet 0-Day Vulnerability that Allows Remote Code Execution
⚠️
Google Vulnerability Allowed Hackers to Access User Phone Numbers
⚠️
Vulnerability in DanaBot Malware C2 Server Leaks Threat Actor Usernames and Crypto Keys
⚠️
Sensata Technologies Faces Disruption Due to Ransomware Attack
⚠️
Bringing CISA's Secure by Design Principles to OT Systems - Matthew Rogers - ASW #334
⚠️
Exploited Vulnerability Impacts Over 80,000 Roundcube Servers
⚠️
SAP Security Patch Day: 14 Vulnerabilities Resolved Across Various Products
⚠️
Malicious Actors Exploit SoraAI’s Popularity & GitHub to Distribute Malware
⚠️
Multicloud security automation is essential β€” but no silver bullet
⚠️
Russia-linked PathWiper malware hits Ukrainian infrastructure
⚠️
Researcher Found Flaw to Discover Phone Numbers Linked to Any Google Account
⚠️
Indian Authorities Bust Cybercriminals Posing as Microsoft Tech Support
⚠️
Critical Vulnerability Patched in SAP NetWeaver
⚠️
New npm threats can erase production systems with a single request
⚠️
Five Zero-Days, 15 Misconfigurations Found in Salesforce Industry Cloud
⚠️
Google Vulnerability Allowed Hackers to Access User Phone Numbers
⚠️
Two Botnets, One Flaw: Mirai Spreads Through Wazuh Vulnerability | Akamai
⚠️
Critical Vulnerability in Lovable’s Security Policies Allows Malicious Code Injection
⚠️
New SharePoint Phishing Campaigns Employing Deceptive Lick Techniques
⚠️
ISPConfig Vulnerability Allows Privilege Escalation to Superadmin and PHP Code Injection Exploit
⚠️
Hackers Stole 300,000 Crash Reports From Texas Department of Transportation
⚠️
Hackers Persist in Using ConnectWise ScreenConnect Tool to Distribute Malware
⚠️
Severe SAP NetWeaver Vulnerability Allows Attackers to Bypass Authorization Checks
⚠️
Seraphic Security Unveils BrowserTotalβ„’ – Free AI-Powered Browser Security Assessment for Enterprises
⚠️
Curl Is EVERYWHERE! 20 Billion Installs?!
⚠️
CISA Releases Four Industrial Control Systems Advisories
⚠️
Microsoft June 2025 Patch Tuesday fixes exploited zero-day, 66 flaws
KEV
⚠️
SAP NetWeaver Vulnerability Allows Attackers to Escalate Privileges
⚠️
Critical Vulnerability Patched in SAP NetWeaver - SecurityWeek
⚠️
Microsoft Patch Tuesday Covers WebDAV Flaw Marked as β€˜Already Exploited’
⚠️
Code Execution Flaws Haunt Adobe Acrobat Reader, Adobe Commerce
⚠️
Researchers Uncover 20+ Configuration Risks, Including Five CVEs, in Salesforce Industry Cloud
⚠️
Microsoft Patch Tuesday June 2025 – 66 Vulnerabilities Patched Including 2 Zero-Day
KEV
⚠️
Microsoft Patch Tuesday June 2025, (Tue, Jun 10th)
⚠️
DanaBot malware operators exposed via C2 bug added in 2022
⚠️
Critical Patches Issued for Microsoft Products, June 10, 2025
⚠️
Multiple Vulnerabilities in Mozilla Firefox Could Allow for Arbitrary Code Execution
⚠️
Multiple Vulnerabilities in Adobe Products Could Allow for Arbitrary Code Execution
πŸ“‹
Ivanti Workspace Control hardcoded key flaws expose SQL credentials
πŸ“‹
Adobe Releases Patch Fixing 254 Vulnerabilities, Closing High-Severity Security Gaps
πŸ“’
[Control systems] Siemens security advisory (AV25-327)
πŸ“’
[Control systems] Schneider Electric security advisory (AV25-328)
πŸ“’
Ivanti security advisory (AV25-329)
πŸ“’
SAP security advisory – June 2025 monthly rollup (AV25-330)
πŸ“’
HPE security advisory (AV25-331)
πŸ“’
Mozilla security advisory (AV25-332)
πŸ“’
Microsoft security advisory – June 2025 monthly rollup (AV25-333)
πŸ“’
Red Hat security advisory (AV25-334)
πŸ“’
Google Chrome security advisory (AV25-336)
πŸ“’
Adobe security advisory (AV25-335)
πŸ”₯
Sensata Technologies says personal data stolen by ransomware gang
πŸ”₯
Whole Foods Distributor United Natural Foods Hit by Cyberattack
πŸ”₯
WiredBucks - 918,529 breached accounts
πŸ”₯
Rare Werewolf APT Uses Legitimate Software in Attacks on Hundreds of Russian Enterprises
πŸ”₯
Sensitive Information Stolen in Sensata Ransomware Attack
πŸ”₯
Sensata Technologies says personal data stolen by ransomware gang
πŸ”₯
SentinelOne shares new details on China-linked breach attempt
πŸ”₯
Sophos Emergency Incident Response is now available
πŸ”₯
Ongoing cyberattack at US grocery distributor giant UNFI affecting customer orders
πŸ”₯
AI is a data-breach time bomb, reveals new report
πŸ”₯
Texas Dept. of Transportation breached, 300k crash records stolen
πŸ”₯
Texas Dept. of Transportation breached, 300k crash records stolen
πŸ”₯
Whole Foods tells staff cyberattack at its primary distributor UNFI will affect product availability
πŸ•΅οΈ
ISC Stormcast For Tuesday, June 10th, 2025 https://isc.sans.edu/podcastdetail/9486, (Tue, Jun 10th)
πŸ•΅οΈ
Chinese spy crew appears to be preparing for conflict by backdooring more than 70 critical organizations worldwide
πŸ•΅οΈ
Chinese spy crew appears to be preparing for conflict by backdooring more than 70 critical organizations worldwide
πŸ•΅οΈ
Vulnerabilities Exposed Phone Number of Any Google User
πŸ•΅οΈ
Malware Deployment Campaigns: β€˜Librarian Ghouls’ APT Group Targets Organizations
πŸ•΅οΈ
Hidden Backdoors in npm Packages Let Attackers Wipe Entire Systems
πŸ•΅οΈ
CYFIRMA INDUSTRY REPORT – ENERGY & UTILITIES - CYFIRMA
πŸ•΅οΈ
Nearly 300,000 crash records stolen from Texas transportation department | The Record from Recorded Future News
πŸ•΅οΈ
Resecurity | APT 41: Threat Intelligence Report and Malware Analysis
πŸ•΅οΈ
New Zealand Government Mandates DMARC Under New Secure Email Framework - Security Boulevard
πŸ•΅οΈ
PayU Plugin Flaw Allows Account Takeover on 5000 WordPress Sites - Infosecurity Magazine
πŸ•΅οΈ
Swimlane Raises $45 Million for Security Automation Platform
πŸ•΅οΈ
CyberheistNews Vol 15 #23 [Heads Up] Your Kid's School Cybersecurity Gets Worse at an Alarming Rate
πŸ•΅οΈ
The AI Fix #54: Will AI collapse under its own garbage, and AI charity β€œHunger Games”
πŸ•΅οΈ
KnowBe4 Wins Big with 2025 TrustRadius Top Rated Awards
πŸ•΅οΈ
FIN6 hackers pose as job seekers to backdoor recruiters’ devices
πŸ•΅οΈ
North Korean APT Hackers Target Users on Social Media to Spread Malware
πŸ•΅οΈ
Beware of Instagram Growth Tools Stealing Login Credentials and Sending Them to Attackers
πŸ•΅οΈ
FIN6 Uses AWS-Hosted Fake Resumes on LinkedIn to Deliver More_eggs Malware
πŸ•΅οΈ
Massive Heroku outage impacts web platforms worldwide
πŸ•΅οΈ
Rare Werewolf APT Uses Legitimate Software in Attacks on Hundreds of Russian Enterprises
πŸ•΅οΈ
Rust-based Myth Stealer Malware Spread via Fake Gaming Sites Targets Chrome, Firefox Users
πŸ•΅οΈ
ESET Details on How to Manage Your Digital Footprint
πŸ•΅οΈ
New Report Highlights the Internet as the Primary Threat to Industrial Automation Systems
πŸ•΅οΈ
FIN6 hackers pose as job seekers to backdoor recruiters’ devices
πŸ•΅οΈ
New Secure Boot flaw lets attackers install bootkit malware, patch now
πŸ•΅οΈ
Vixen Panda, NPM, Roundcube, IoT, 4Chan, Josh Marpet, and more... - SWN #484
🌐
Rust-based Myth Stealer Malware Spread via Fake Gaming Sites Targets Chrome, Firefox Users
🌐
FIN6 hackers pose as job seekers to backdoor recruiters’ devices
πŸ“‘
Five plead guilty to laundering $36 million stolen in investment scams
πŸ“‘
The Hidden Threat in Your Stack: Why Non-Human Identity Management is the Next Cybersecurity Frontier
πŸ“‘
OpenAI working to fix ChatGPT outage affecting users worldwide
πŸ“‘
Massive Heroku outage impacts web platforms worldwide
πŸ“‘
Why This Ethical Hacker Still Finds Web Hacking Addictive
πŸ“‘
Getting started with Wirego
πŸ“‘
Microsoft Outlook to block more risky attachments used in attacks
πŸ“‘
Windows 11Β KB5060842Β and KB5060999Β cumulative updates released
πŸ“‘
Windows 10 KB5060533 cumulative update released with 7 changes, fixes
πŸ“‘
ConnectWise rotating code signing certificates over security concerns
πŸ“‘
Ofcom investigates 4chan for not protecting users from illegal content