240Articles
9Categories
2025-07-08Date
🚨
CISA Adds Four Critical Vulnerabilities to KEV Catalog Due to Active ExploitationThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added four security flaws to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation in the wild. The list of flaws is as follows - CVE-2014-3931 (CVSS score: 9.8) - A buf…
KEV
πŸ›
CISA Issues Alert Over Actively Exploited Flaw in Zimbra Collaboration Suite
KEV
πŸ›
End of life for Microsoft Office puts malicious macros in the security spotlight
πŸ›
CISA Alerts on Active Exploitation of PHPMailer Command Injection Flaw
πŸ›
macOS SMBClient Flaw Enables Remote Code Execution and Kernel Crashes
πŸ›
SAP Julyβ€―2025 Patch Day: Fixes for 27 Flaws, Including 7 Critical
πŸ›
DNN Vulnerability Exposes NTLM Credentials via Unicode Normalization Bypass
πŸ›
RondoDox Botnet Exploits Flaws in TBK DVRs and Four-Faith Routers to Launch DDoS Attacks
πŸ›
Exploits, Technical Details Released for CitrixBleed2 Vulnerability
πŸ›
How a 12-year-old bug in Sudo is still haunting Linux users
πŸ›
PoC Exploits Released for CitrixBleed2: 127 Bytes Exfiltrated Per Request
πŸ›
CISA Alerts on Active Exploit of Ruby on Rails Path Traversal Flaw
KEV
πŸ›
CVE-2022-33637 Microsoft Defender for Endpoint Tampering Vulnerability
πŸ›
CVE-2022-23278 Microsoft Defender for Endpoint Spoofing Vulnerability
πŸ›
FortiOS Buffer Overflow vulnerability Enables Remote Code Execution by Attackers
πŸ›
CVE-2025-26636 Windows Kernel Information Disclosure Vulnerability
πŸ›
CVE-2025-33054 Remote Desktop Spoofing Vulnerability
πŸ›
CVE-2025-47159 Windows Virtualization-Based Security (VBS) Elevation of Privilege Vulnerability
πŸ›
CVE-2025-21195 Azure Service Fabric Runtime Elevation of Privilege Vulnerability
πŸ›
CVE-2025-47971 Microsoft Virtual Hard Disk Elevation of Privilege Vulnerability
πŸ›
CVE-2025-47972 Windows Input Method Editor (IME) Elevation of Privilege Vulnerability
πŸ›
CVE-2025-47976 Windows Simple Search and Discovery Protocol (SSDP) Service Elevation of Privilege Vulnerability
πŸ›
CVE-2025-47984 Windows GDI Information Disclosure Vulnerability
πŸ›
CVE-2025-47985 Windows Event Tracing Elevation of Privilege Vulnerability
πŸ›
CVE-2025-47986 Universal Print Management Service Elevation of Privilege Vulnerability
πŸ›
CVE-2025-47987 Credential Security Support Provider Protocol (CredSSP) Elevation of Privilege Vulnerability
πŸ›
CVE-2025-48824 Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
πŸ›
CVE-2025-49657 Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
πŸ›
CVE-2025-49658 Windows Transport Driver Interface (TDI) Translation Driver Information Disclosure Vulnerability
πŸ›
CVE-2025-49661 Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
πŸ›
CVE-2025-49670 Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
πŸ›
CVE-2025-49671 Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability
πŸ›
CVE-2025-49672 Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
πŸ›
CVE-2025-49674 Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
πŸ›
CVE-2025-49676 Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
πŸ›
CVE-2025-49677 Microsoft Brokering File System Elevation of Privilege Vulnerability
πŸ›
CVE-2025-49686 Windows TCP/IP Driver Elevation of Privilege Vulnerability
πŸ›
CVE-2025-49687 Windows Input Method Editor (IME) Elevation of Privilege Vulnerability
πŸ›
CVE-2025-49688 Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
πŸ›
CVE-2025-49689 Microsoft Virtual Hard Disk Elevation of Privilege Vulnerability
πŸ›
CVE-2025-49690 Capability Access Management Service (camsvc) Elevation of Privilege Vulnerability
πŸ›
CVE-2025-49691 Windows Miracast Wireless Display Remote Code Execution Vulnerability
πŸ›
CVE-2025-49694 Microsoft Brokering File System Elevation of Privilege Vulnerability
πŸ›
CVE-2025-47991 Windows Input Method Editor (IME) Elevation of Privilege Vulnerability
πŸ›
CVE-2025-47993 Microsoft PC Manager Elevation of Privilege Vulnerability
πŸ›
CVE-2025-47994 Microsoft Office Elevation of Privilege Vulnerability
πŸ›
CVE-2025-36357 AMD: CVE-2025-36357 Transient Scheduler Attack in L1 Data Queue
πŸ›
CVE-2025-36350 AMD: CVE-2024-36350 Transient Scheduler Attack in Store Queue
πŸ›
CVE-2025-48812 Microsoft Excel Information Disclosure Vulnerability
πŸ›
CVE-2025-49711 Microsoft Excel Remote Code Execution Vulnerability
πŸ›
CVE-2025-49716 Windows Netlogon Denial of Service Vulnerability
πŸ›
CVE-2025-49717 Microsoft SQL Server Remote Code Execution Vulnerability
πŸ›
CVE-2025-27613 MITRE: CVE-2025-27613 Gitk Arguments Vulnerability
πŸ›
CVE-2025-27614 MITRE: CVE-2025-27614 Gitk Arbitrary Code Execution Vulnerability
πŸ›
CVE-2025-46334 MITRE: CVE-2025-46334 Git Malicious Shell Vulnerability
πŸ›
CVE-2025-46835 MITRE: CVE-2025-46835 Git File Overwrite Vulnerability
πŸ›
CVE-2025-48384 MITRE: CVE-2025-48384 Git Symlink Vulnerability
πŸ›
CVE-2025-48385 MITRE: CVE-2025-48385 Git Protocol Injection Vulnerability
πŸ›
CVE-2025-48386 MITRE: CVE-2025-48386 Git Credential Helper Vulnerability
πŸ›
CVE-2025-49719 Microsoft SQL Server Information Disclosure Vulnerability
πŸ›
CVE-2025-49721 Windows Fast FAT File System Driver Elevation of Privilege Vulnerability
πŸ›
CVE-2025-49723 Windows StateRepository API Server file Tampering Vulnerability
πŸ›
CVE-2025-49726 Windows Notification Elevation of Privilege Vulnerability
πŸ›
CVE-2025-49731 Microsoft Teams Elevation of Privilege Vulnerability
πŸ›
CVE-2025-49735 Windows KDC Proxy Service (KPSSVC) Remote Code Execution Vulnerability
πŸ›
CVE-2025-47178 Microsoft Configuration Manager Remote Code Execution Vulnerability
πŸ›
CVE-2025-49753 Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
πŸ›
CVE-2025-49756 Office Developer Platform Security Feature Bypass Vulnerability
πŸ›
CVE-2025-49760 Windows Storage Spoofing Vulnerability
πŸ›
CVE-2025-47973 Microsoft Virtual Hard Disk Elevation of Privilege Vulnerability
πŸ›
CVE-2025-47975 Windows Simple Search and Discovery Protocol (SSDP) Service Elevation of Privilege Vulnerability
πŸ›
CVE-2025-47978 Windows Kerberos Denial of Service Vulnerability
πŸ›
CVE-2025-47980 Windows Imaging Component Information Disclosure Vulnerability
πŸ›
CVE-2025-47981 SPNEGO Extended Negotiation (NEGOEX) Security Mechanism Remote Code Execution Vulnerability
πŸ›
CVE-2025-47982 Windows Storage VSP Driver Elevation of Privilege Vulnerability
πŸ›
CVE-2025-47996 Windows MBT Transport Driver Elevation of Privilege Vulnerability
πŸ›
CVE-2025-47998 Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
πŸ›
CVE-2025-48000 Windows Connected Devices Platform Service Elevation of Privilege Vulnerability
πŸ›
CVE-2025-48001 BitLocker Security Feature Bypass Vulnerability
πŸ›
CVE-2025-48002 Windows Hyper-V Information Disclosure Vulnerability
πŸ›
CVE-2025-48003 BitLocker Security Feature Bypass Vulnerability
πŸ›
CVE-2025-48799 Windows Update Service Elevation of Privilege Vulnerability
πŸ›
CVE-2025-48800 BitLocker Security Feature Bypass Vulnerability
πŸ›
CVE-2025-48802 Windows SMB Server Spoofing Vulnerability
πŸ›
CVE-2025-48803 Windows Virtualization-Based Security (VBS) Elevation of Privilege Vulnerability
πŸ›
CVE-2025-48804 BitLocker Security Feature Bypass Vulnerability
πŸ›
CVE-2025-48805 Microsoft MPEG-2 Video Extension Remote Code Execution Vulnerability
πŸ›
CVE-2025-48806 Microsoft MPEG-2 Video Extension Remote Code Execution Vulnerability
πŸ›
CVE-2025-48808 Windows Kernel Information Disclosure Vulnerability
πŸ›
CVE-2025-48809 Windows Secure Kernel Mode Information Disclosure Vulnerability
πŸ›
CVE-2025-48810 Windows Secure Kernel Mode Information Disclosure Vulnerability
πŸ›
CVE-2025-48811 Windows Virtualization-Based Security (VBS) Enclave Elevation of Privilege Vulnerability
πŸ›
CVE-2025-48814 Remote Desktop Licensing Service Security Feature Bypass Vulnerability
πŸ›
CVE-2025-48815 Windows Simple Search and Discovery Protocol (SSDP) Service Elevation of Privilege Vulnerability
πŸ›
CVE-2025-48816 HID Class Driver Elevation of Privilege Vulnerability
πŸ›
CVE-2025-48817 Remote Desktop Client Remote Code Execution Vulnerability
πŸ›
CVE-2025-48818 BitLocker Security Feature Bypass Vulnerability
πŸ›
CVE-2025-48819 Windows Universal Plug and Play (UPnP) Device Host Elevation of Privilege Vulnerability
πŸ›
CVE-2025-48820 Windows AppX Deployment Service Elevation of Privilege Vulnerability
πŸ›
CVE-2025-48821 Windows Universal Plug and Play (UPnP) Device Host Elevation of Privilege Vulnerability
πŸ›
CVE-2025-48822 Windows Hyper-V Discrete Device Assignment (DDA) Remote Code Execution Vulnerability
πŸ›
CVE-2025-48823 Windows Cryptographic Services Information Disclosure Vulnerability
πŸ›
CVE-2025-49659 Windows Transport Driver Interface (TDI) Translation Driver Elevation of Privilege Vulnerability
πŸ›
CVE-2025-49660 Windows Event Tracing Elevation of Privilege Vulnerability
πŸ›
CVE-2025-49663 Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
πŸ›
CVE-2025-49664 Windows User-Mode Driver Framework Host Information Disclosure Vulnerability
πŸ›
CVE-2025-49665 Workspace Broker Elevation of Privilege Vulnerability
πŸ›
CVE-2025-49666 Windows Server Setup and Boot Event Collection Remote Code Execution Vulnerability
πŸ›
CVE-2025-49667 Windows Win32 Kernel Subsystem Elevation of Privilege Vulnerability
πŸ›
CVE-2025-49668 Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
πŸ›
CVE-2025-49669 Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
πŸ›
CVE-2025-49673 Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
πŸ›
CVE-2025-49675 Kernel Streaming WOW Thunk Service Driver Elevation of Privilege Vulnerability
πŸ›
CVE-2025-49678 NTFS Elevation of Privilege Vulnerability
πŸ›
CVE-2025-49679 Windows Shell Elevation of Privilege Vulnerability
πŸ›
CVE-2025-49680 Windows Performance Recorder (WPR) Denial of Service Vulnerability
πŸ›
CVE-2025-49681 Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability
πŸ›
CVE-2025-49682 Windows Media Elevation of Privilege Vulnerability
πŸ›
CVE-2025-49683 Microsoft Virtual Hard Disk Remote Code Execution Vulnerability
πŸ›
CVE-2025-49684 Windows Storage Port Driver Information Disclosure Vulnerability
πŸ›
CVE-2025-49685 Windows Search Service Elevation of Privilege Vulnerability
πŸ›
CVE-2025-49693 Microsoft Brokering File System Elevation of Privilege Vulnerability
πŸ›
CVE-2025-49695 Microsoft Office Remote Code Execution Vulnerability
πŸ›
CVE-2025-49696 Microsoft Office Remote Code Execution Vulnerability
πŸ›
CVE-2025-49697 Microsoft Office Remote Code Execution Vulnerability
πŸ›
CVE-2025-49698 Microsoft Word Remote Code Execution Vulnerability
πŸ›
CVE-2025-49699 Microsoft Office Remote Code Execution Vulnerability
πŸ›
CVE-2025-49700 Microsoft Word Remote Code Execution Vulnerability
πŸ›
CVE-2025-49701 Microsoft SharePoint Remote Code Execution Vulnerability
πŸ›
CVE-2025-49702 Microsoft Office Remote Code Execution Vulnerability
πŸ›
CVE-2025-49703 Microsoft Word Remote Code Execution Vulnerability
πŸ›
CVE-2025-49704 Microsoft SharePoint Remote Code Execution Vulnerability
πŸ›
CVE-2025-49705 Microsoft PowerPoint Remote Code Execution Vulnerability
πŸ›
CVE-2025-49706 Microsoft SharePoint Server Spoofing Vulnerability
πŸ›
CVE-2025-49714 Visual Studio Code Python Extension Remote Code Execution Vulnerability
πŸ›
CVE-2025-49718 Microsoft SQL Server Information Disclosure Vulnerability
πŸ›
CVE-2025-49722 Windows Print Spooler Denial of Service Vulnerability
πŸ›
CVE-2025-49724 Windows Connected Devices Platform Service Remote Code Execution Vulnerability
πŸ›
CVE-2025-49725 Windows Notification Elevation of Privilege Vulnerability
πŸ›
CVE-2025-49727 Win32k Elevation of Privilege Vulnerability
πŸ›
CVE-2025-49729 Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
πŸ›
CVE-2025-49730 Microsoft Windows QoS Scheduler Driver Elevation of Privilege Vulnerability
πŸ›
CVE-2025-49732 Windows Graphics Component Elevation of Privilege Vulnerability
πŸ›
CVE-2025-49733 Win32k Elevation of Privilege Vulnerability
πŸ›
CVE-2025-47999 Windows Hyper-V Denial of Service Vulnerability
πŸ›
CVE-2025-49737 Microsoft Teams Elevation of Privilege Vulnerability
πŸ›
CVE-2025-49738 Microsoft PC Manager Elevation of Privilege Vulnerability
πŸ›
CVE-2025-49739 Visual Studio Elevation of Privilege Vulnerability
πŸ›
CVE-2025-49740 Windows SmartScreen Security Feature Bypass Vulnerability
πŸ›
CVE-2025-49742 Windows Graphics Component Remote Code Execution Vulnerability
πŸ›
CVE-2025-49744 Windows Graphics Component Elevation of Privilege Vulnerability
πŸ›
CVE-2025-47988 Azure Monitor Agent Remote Code Execution Vulnerability
πŸ›
July Patch Tuesday: 14 critical Microsoft vulnerabilities, one SAP hole rated at 10 in severity
⚠️
Discovery of compromised Shellter security tool raises disclosure debate
⚠️
How talent-strapped CISOs can tap former federal government cyber pros
⚠️
Chinese wegen US-Spionageverdacht in Mailand festgenommen
⚠️
Weekly Update 459
⚠️
Checking in on the State of Appsec in 2025 - Sandy Carielli, Janet Worthington - ASW #338
⚠️
Call of Duty Gamers Hacked via RCE Exploit Allowing Player-to-Player Attacks
⚠️
The trust crisis in the cloud…and why blockchain deserves a seat at the table
⚠️
SAP Patches Critical Flaws That Could Allow Remote Code Execution, Full System Takeover
⚠️
ClickFix-Attacken bedrohen Unternehmenssicherheit
⚠️
Overcoming Technical Barriers in Desktop and Application Virtualization
⚠️
MediaTek Julyβ€―2025 Security Update Addresses Multiple Chipset Vulnerabilities
⚠️
VLAI: A RoBERTa-Based Model for Automated Vulnerability Severity Classification
⚠️
VenusTech and Salt Typhoon Breach Sheds Light on China's Covert Cyber Mercenary Networks
⚠️
Ivanti Products Connect Secure and Policy Secure Hit by Denial-of-Service Vulnerabilities
⚠️
CISA Releases One Industrial Control Systems Advisory
⚠️
Microsoft July 2025 Patch Tuesday fixes one zero-day, 137 flaws
⚠️
NetSupport RAT Spreads Through Compromised WordPress Sites Using ClickFix Technique
⚠️
Microsoft Patch Tuesday July 2025: 130 Vulnerabilities Patched, Including 1 Zero-Day and 41 RCE Flaws
⚠️
Hackers Use Leaked Shellter Tool License to Spread Lumma Stealer and SectopRAT Malware
⚠️
New LogoKit Phishing Campaign Exploits Cloudflare Turnstile and Amazon S3 for Higher Success Rates
⚠️
Activision took down Call of Duty game after PC players hacked, says source
⚠️
Git security vulnerabilities announced
⚠️
Git security vulnerabilities announced
⚠️
Critical Patches Issued for Microsoft Products, July 8, 2025
⚠️
Hackers Manipulate Search Results to Target IT Pros with Trojanized PuTTY and WinSCP
⚠️
Advancing Protection in Chrome on Android
⚠️
Microsoft Patch Tuesday, July 2025, (Tue, Jul 8th)
⚠️
New Android TapTrap attack fools users with invisible UI trick
⚠️
BERT Ransomware Can Force Shutdown of ESXi Virtual Machines to Hinder Recovery
⚠️
Malicious Open Source Packages Surge 188% Annually - Infosecurity Magazine
⚠️
A Vulnerability in FortiWeb Could Allow for SQL Injection
⚠️
M&S confirms social engineering led to massive ransomware attack
⚠️
Microsoft Patches 130 Vulnerabilities for July 2025 Patch Tuesday
⚠️
11 Google-Verified Chrome Extensions Infected Over 1.7 Million Users
πŸ“’
[Control systems] Schneider Electric security advisory (AV25-403)
πŸ“’
SAP security advisory – July 2025 monthly rollup (AV25-402)
πŸ“’
[Control systems] Siemens security advisory (AV25-404)
πŸ“’
Ivanti security advisory (AV25-405)
πŸ“’
Fortinet security advisory (AV25-406)
πŸ“’
Microsoft security advisory – July 2025 monthly rollup (AV25-407)
πŸ“’
Adobe security advisory (AV25-408)
πŸ”₯
NordDragonScan Targets Windows Users to Steal Login Credentials
πŸ”₯
Atomic macOS Info-Stealer Updated with New Backdoor for Persistent Access
πŸ”₯
5 Ways Identity-based Attacks Are Breaching Retail
πŸ”₯
Qantas Hit with Extortion Demand After Data Breach
πŸ”₯
Qantas is being extorted in recent data-theft cyberattack
πŸ”₯
Surmodics & Kentfield Hospital Fall Victim to Cyberattacks
πŸ”₯
Marks & Spencer chair refuses to say if retailer paid hackers after ransomware attack
πŸ”₯
DPRK macOS 'NimDoor' Malware Targets Web3, Crypto Platforms
πŸ”₯
4 Critical Steps in Advance of 47-Day SSL/TLS Certificates
πŸ”₯
Ransomware negotiator investigated over criminal gang kickbacks | Malwarebytes
πŸ”₯
Bladed Feline: Iran's Cyber Cat Is Real and Dangerous
πŸ”₯
$200K Gone in a Zoom Call!
πŸ”₯
Impostor Uses AI to Impersonate Rubio and Contact Foreign and US Officials
πŸ•΅οΈ
ISC Stormcast For Tuesday, July 8th, 2025 https://isc.sans.edu/podcastdetail/9516, (Tue, Jul 8th)
πŸ•΅οΈ
Critical Vulnerabilities in KIA Infotainment Let Attackers Inject Code with PNG Files
πŸ•΅οΈ
Researchers Share CitrixBleed 2 Detection Analysis After Initial Hold - Infosecurity Magazine
πŸ•΅οΈ
Chrome Store Features Extension Poisoned With Sophisticated Spyware
πŸ•΅οΈ
Hackers abuse leaked Shellter red team tool to deploy infostealers
πŸ•΅οΈ
CyberheistNews Vol 15 #27 Is Your Human Risk Management Program Really Making a Difference? Measure It Now
πŸ•΅οΈ
Malware Attacks on Android Devices Surge in Q2, Driven by Banking Trojans and Spyware
πŸ•΅οΈ
The Wild Wild West of Agentic AI – An Attack Surface CISOs Can’t Afford to Ignore
πŸ•΅οΈ
Modernizing Cybersecurity for State and Local Government
πŸ•΅οΈ
Employee gets $920 for credentials used in $140 million bank heist
πŸ•΅οΈ
Legit Shellter Pen-Testing Tool Used in Malware Attacks
πŸ•΅οΈ
Researchers Reveal Scatter Spider’s Tools, Tactics, and Key Indicators
πŸ•΅οΈ
Android malware Anatsa infiltrates Google Play to target US banks
πŸ•΅οΈ
Over 500 Scattered Spider Phishing Domains Poised to Target Multiple I - Infosecurity Magazine
πŸ•΅οΈ
Enhancing Microsoft 365 security by eliminating high-privilege access
πŸ•΅οΈ
XMRig Malware Disables Windows Updates and Scheduled Tasks to Maintain Persistence
πŸ•΅οΈ
China-Linked VELETRIX Loader Used in Attacks on Telecommunications Infrastructure
πŸ•΅οΈ
New Report Finds Billions of Leaked Credentials and ULP Files on Dark Web Are Outdated
πŸ•΅οΈ
Adobe Patches Critical Code Execution Bugs
πŸ•΅οΈ
Browser hijacking campaign infects 2.3M Chrome, Edge users
πŸ•΅οΈ
Spying on your kids, Bank Robberies, Qantas, LOTL, sudo, Hunters, Aaran Leyland... - SWN #492
🌐
Researchers Uncover Batavia Windows Spyware Stealing Documents from Russian Firms
🌐
Malicious Pull Request Targets 6,000+ Developers via Vulnerable Ethcode VS Code Extension
🌐
Android malware Anatsa infiltrates Google Play to target US banks
🌐
Anatsa Android Banking Trojan Hits 90,000 Users with Fake PDF App on Google Play
πŸŽ™οΈ
The AI Fix #58: An AI runs a shop into the ground, and AI’s obsession with the number 27
πŸ“‘
Shrinking your digital footprint: a checklist by Kaspersky | Kaspersky official blog
πŸ“‘
BaitTrap: Over 17,000 Fake News Websites Caught Fueling Investment Fraud Globally
πŸ“‘
Malicious Chrome extensions with 1.7M installs found on Web Store
πŸ“‘
Windows 10 KB5062554 cumulative update released with 13 changes, fixes
πŸ“‘
Windows 11 KB5062553 & KB5062552 cumulative updates released
πŸ“‘
Samsung announces major security enhancements coming to One UI 8
πŸ“‘
US government confirms arrest of Chinese national accused of stealing COVID research and mass-hacking email servers