U.S. CISA adds CrushFTP, Google Chromium, and SysAid flaws to its Known Exploited Vulnerabilities catalog

7 months ago

U.S. CISA adds CrushFTP, Google Chromium, and SysAid flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure…

U.S. CISA urges FCEB agencies to fix two Microsoft SharePoint flaws immediately and added them to its Known Exploited Vulnerabilities catalog

7 months ago

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds two Microsoft SharePoint flaws to its Known Exploited Vulnerabilities catalog. The U.S.…

Sophos fixed two critical Sophos Firewall vulnerabilities

7 months ago

Sophos addressed five Sophos Firewall vulnerabilities that could allow remote attackers to execute arbitrary code. Sophos has fixed five vulnerabilities…

French Authorities confirm XSS.is admin arrested in Ukraine

7 months ago

French authorities announced the arrest in Ukraine of an alleged administrator of the long-running cybercrime forum XSS.is. A joint investigation…

Microsoft linked attacks on SharePoint flaws to China-nexus actors

7 months ago

Microsoft linked SharePoint exploits to China-nexus groups Linen Typhoon, Violet Typhoon, and Storm-2603, active since July 7, 2025. Microsoft confirmed…

<gwmw style="display: none; background-color: transparent;"></gwmw>Cisco confirms active exploitation of ISE and ISE-PIC flaws<gwmw style="display: none; background-color: transparent;"></gwmw>

7 months ago

Cisco warns of active exploits targeting Identity Services Engine (ISE) and ISE-PIC flaws, first observed in July 2025. Cisco confirmed…

SharePoint under fire: new ToolShell attacks target enterprises

7 months ago

While SentinelOne did not attribute the attack to a specific threat actor, The Washington Post linked it to China-nexus acors.…

CrushFTP zero-day actively exploited at least since July 18

7 months ago

Hackers exploit CrushFTP zero-day, tracked as CVE-2025-54309, to gain admin access via HTTPS when DMZ proxy is off. Threat actors…

Hardcoded credentials found in HPE Aruba Instant On Wi-Fi devices

7 months ago

Hardcoded credentials in HPE Aruba Instant On Wi-Fi devices, let attackers to bypass authentication and access the web interface. HPE…

MuddyWater deploys new DCHSpy variants amid Iran-Israel conflict

7 months ago

Iran-linked APT MuddyWater is deploying new DCHSpy spyware variants to target Android users amid the ongoing conflict with Israel. Lookout…

This website uses cookies.