Sophos CTU researchers reported active exploitation of a remote code execution flaw (CVE-2025-59287) in Microsoft WSUS. Attackers used a Base64-encoded PowerShell command to exfiltrate Active Director…
Category: Vulnerabilities / Exploitation / Microsoft
#windows#cve-2025-59287#rce#sophos#vulnerability
A critical vulnerability in the WP Freeio plugin, used for job board sites, is being actively exploited. The flaw allows unauthenticated attackers to execute arbitrary code or escalate privileges. Sec…
Category: Advisories / WordPress / Plugins
#wordpress#plugin#wp-freeio#vulnerability#exploit
Two newly disclosed vulnerabilities, CVE-2025-55752 and CVE-2025-55754, affect Apache Tomcat servers. These flaws could allow unauthorized directory traversal and sensitive log exposure under specific…
Category: Vulnerabilities / Server / Apache
#apache#tomcat#cve-2025-55752#cve-2025-55754#vulnerability
Researchers from Georgia Tech, Purdue, and Synkhronix unveiled TEE.Fail, a physical side-channel attack on DDR5-based trusted execution environments (Intel SGX/TDX and AMD SEV-SNP). The exploit enable…
Category: Vulnerabilities / Hardware / Hardware Security
#hardware#intel#amd#vulnerability#side-channel
LayerX researchers identified a vulnerability in OpenAI’s ChatGPT Atlas Browser that could allow local file access and data exfiltration through embedded web scripts. The issue could expose sensitive …
Category: Vulnerability / AI Security / Browser Exploitation
#chatgpt#openai#layerx#vulnerability#browser
Dell confirmed three critical vulnerabilities in its Storage Manager (DSM), including CVE-2025-43995, a remotely exploitable authentication bypass flaw. Researchers warn attackers could gain complete …
Category: Vulnerability / Vendor Advisory / Storage Systems
#cve#storage#vulnerability#dell
Ubuntu published USN-7842-1 addressing a vulnerability in radare2. While the notice landing page is cookie-gated, the advisory indicates fixes available via standard updates for supported releases.
Category: Threat Alerts / Vulnerabilities & Exploits / Vulnerabilities & Exploits
#ubuntu#radare2#vulnerability#usn
A critical flaw, CVE-2025-40778, affects over 706,000 exposed BIND 9 resolver instances. The vulnerability enables off-path attackers to inject forged DNS records due to improper bailiwick checks. Wit…
Category: Vulnerabilities / DNS Security / DNS Security
#dns#vulnerability#bind9#cve-2025-40778#cache-poisoning
SecurityWeek reports that the planned $1M WhatsApp exploit demonstration at Pwn2Own 2025 was withdrawn, with researchers disclosing only low-risk bugs to Meta. The event highlighted Meta’s improved se…
Category: Mobile / Vulnerability Disclosure / Vulnerability News
#whatsapp#meta#pwn2own#vulnerability
Security researchers disclosed a serious remote code execution vulnerability in the Rust library tokio-tar, affecting major projects such as uv, testcontainers, and wasmCloud. The vulnerability stems …
Category: Threat Alerts / Vulnerabilities & Exploits / Open Source Supply Chain
#Rust#RCE#vulnerability#supply chain