Friday, November 21, 2025
Follow on LinkedIn

Hackers Exploiting Microsoft WSUS Vulnerability In The Wild – 2800 Instances Exposed Online

Hackers are actively exploiting a critical flaw in Microsoft's Windows Server Update Services (WSUS), with security researchers reporting widespread attempts in the wild. The vulnerability,...

HP OneAgent Update Brokes Trust And Disconnect Devices From Entra ID

The HP OneAgent software update has disconnected Windows devices from Microsoft Entra ID. As a result, users can no longer access their corporate identities. Version...

Hackers Exploiting Adobe Magento RCE Vulnerability Exploited in the Wild – 3 in 5...

Hackers have begun actively targeting a critical remote code execution flaw in Adobe's Magento e-commerce platform, putting thousands of online stores at immediate risk...

CISA Warns of Motex LANSCOPE Endpoint Manager Vulnerability Actively Exploited in the Wild

CISA has issued a critical alert regarding a severe vulnerability in Motex LANSCOPE Endpoint Manager, a popular tool for managing IT assets across networks. Dubbed...
TARmageddon Vulnerability

TARmageddon Vulnerability In Rust Library Let Attackers Replace Config Files And Execute Remote Codes

A severe vulnerability in the async-tar Rust library and its popular forks, including the widely used tokio-tar. Dubbed TARmageddon and tracked as CVE-2025-62518, the...

Chinese Hackers Exploiting ToolShell Vulnerability To Compromise Networks Of Government Agencies

China-based threat actors have exploited the critical ToolShell vulnerability in Microsoft SharePoint servers to infiltrate networks across multiple continents, targeting government agencies and critical...

Critical Vulnerability In Oracle E-Business Suite’s Marketing Product Allows Full Access To Attackers

Oracle has disclosed two critical vulnerabilities in its E-Business Suite's Marketing product that could hand full control to remote attackers. Dubbed CVE-2025-53072 and CVE-2025-62481, these...

Apache Syncope Groovy RCE Vulnerability Let Attackers Inject Malicious Code

Apache Syncope, an open-source identity management system, has been found vulnerable to remote code execution (RCE) through its Groovy scripting feature, as detailed in...
Zyxel Devices Exposed

ZYXEL Authorization Bypass Vulnerability Let Attackers View and Download System Configuration

A critical vulnerability in Zyxel’s ATP and USG series firewalls allows attackers to bypass authorization controls and access sensitive system configurations. Dubbed CVE-2025-9133, this flaw...
Dolby Digital Plus 0-Click Vulnerability

Dolby Digital Plus 0-Click Vulnerability Enables RCE Attack via Malicious Audio on Android

A critical zero-click vulnerability in Dolby Digital Plus (DDP) audio decoding software has been disclosed, allowing attackers to execute malicious code remotely via seemingly...
CSN

Top 10