Dell confirmed three critical vulnerabilities in its Storage Manager (DSM), including CVE-2025-43995, a remotely exploitable authentication bypass flaw. Researchers warn attackers could gain complete …
Category: Vulnerability / Vendor Advisory / Storage Systems
#cve#storage#vulnerability#dell
A critical flaw in Motex LANSCOPE Endpoint Manager (CVE-2025-61932) is under active exploitation according to SOC Prime. The vulnerability enables remote code execution through specially crafted netwo…
Category: Vulnerability / Exploitation Reports / Endpoint Security
#cve#motex#exploit#endpoint#kev
Ubuntu issued USN-7837-1 for GStreamer Good Plugins, addressing CVE-2025-47219 that can cause denial of service or information disclosure via malformed media files. Updates are available for Ubuntu 20…
Category: Threat Alerts / Vulnerabilities & Exploits / Vulnerabilities & Exploits
#ubuntu#gstreamer#dos#cve
Check Point’s weekly bulletin highlights multiple incidents: Toys 'R' Us Canada breach, Askul ransomware disrupting logistics, Verisure data breach via billing partner, LastPass-themed phishing tied t…
Category: Threat Alerts / Threat Intelligence / Threat Intelligence
#weekly#cve#ransomware#apt
Help Net Security's weekly summary highlighted multiple active threats: CVE-2025-59287 (WSUS RCE), CVE-2025-33073 (Windows SMB client), CVE-2025-61932 (Lanscope Endpoint Manager), and CVE-2025-54236 (…
Category: Threat Alerts / Vulnerabilities & Exploits / Vulnerabilities
#cve#microsoft#adobe#oauth#zero-day
CISA has added two major vulnerabilities—CVE-2025-54236 (Adobe Commerce / Magento) and CVE-2025-59287 (Microsoft WSUS)—to its Known Exploited Vulnerabilities catalog. Agencies are required to patch by…
Category: Vulnerabilities / Government / CISA
#cve#cisa#adobe#microsoft#kev
A widespread exploitation campaign targets WordPress websites running outdated GutenKit and Hunk Companion plugins, leveraging CVE-2024-9234, CVE-2024-9707, and CVE-2024-11972 to achieve remote code e…
Category: Threats / Web Security / CMS Exploits
#wordpress#rce#cms#cve#mass-attack
ISC disclosed multiple high-severity vulnerabilities in BIND 9, including CVE-2025-40778 and CVE-2025-40780, which enable DNS cache poisoning, and CVE-2025-8677, which can cause denial-of-service thro…
Category: Threat Alerts / Vulnerabilities & Exploits / Network Infrastructure
#bind9#dns#cve#cache-poisoning#isc
A remote code execution vulnerability dubbed 'SessionReaper' (CVE-2025-54236) in Magento and Adobe Commerce enables attackers to hijack live customer sessions and, in some configurations, achieve full…
Category: Threat Alerts / Vulnerabilities & Exploits / Web Applications
#magento#sessionreaper#ecommerce#cve
Forescout researchers disclosed critical vulnerabilities in TP-Link Omada and Festa VPN routers, including CVE-2025-7850 (command injection via WireGuard settings) and CVE-2025-7851 (residual debug co…
Category: Threat Alerts / Vulnerabilities & Exploits / IoT & Network Devices
#tp-link#iot#routers#cve
Oracle has released its October 2025 Critical Patch Update (CPU), addressing multiple high-severity vulnerabilities across Oracle Database, Fusion Middleware, MySQL, and Java SE. The advisory highligh…
Category: Threat Alerts / Vulnerabilities & Exploits / Vendor Security Advisories
#CVE#patch#Oracle#critical update#RCE
USN‑7833‑2 addresses multiple vulnerabilities in the Linux realtime kernel for Ubuntu 24.04 LTS, including AMD store buffer data inference (CVE‑2024‑36350, CVE‑2024‑36357) and a very large set of subs…
Category: Threat Alerts / Vulnerabilities & Exploits / Vulnerabilities & Exploits
#ubuntu#linux-kernel#usn-7833-2#cve#patch
Microsoft and F5 faced simultaneous critical incidents: Microsoft patched three actively exploited zero-days (CVE-2025-24990, CVE-2025-59230, CVE-2025-47827) while F5 confirmed source code theft in a …
Category: Threat Alerts / Vulnerabilities & Exploits / Zero-Day Exploits
#f5#microsoft#zero-day#supply-chain#cve
A critical XXE vulnerability (CVE-2025-54988) affects Apache Tika’s PDF parser module in versions 1.13 through 3.2.1, enabling attackers to read sensitive files or initiate SSRF-like requests via craf…
Category: Threat Alerts / Vulnerabilities & Exploits / Libraries & Dependencies
#cve#apache-tika#xxe#pdf#ssrf
Two 7-Zip vulnerabilities (CVE-2025-11001, CVE-2025-11002) allow directory traversal via symbolic links in ZIP archives, enabling overwrite of arbitrary files and potential code execution when paired …
Category: Threat Alerts / Vulnerabilities & Exploits / Client Applications
#7zip#cve#rce#zip#symlink
A practitioner’s post details response to CVE-2025-49844 (CVSS 10.0) in Redis, referencing GHSA-4789-qfc9-5f9q. Mitigations included immediate ACL restrictions disabling EVAL/EVALSHA, upgrading from R…
Category: Threat Alerts / Vulnerabilities & Exploits / Databases & Caches
#redis#cve#acl#rce#ha
Microsoft’s Security Update Guide lists CVE-2025-0033 affecting AMD Secure Nested Paging (SNP) during RMP initialization. The entry classifies impact as Critical and ties to Remote Code Execution impa…
Category: Threat Alerts / Vulnerabilities & Exploits / Vulnerabilities & Exploits
#cve#amd#snp#hypervisor#confidential-computing#virtualization