vulnerability

New MobileGestalt Exploit for iOS 26.0.1 Enables Unauthorized Writes to Protected Data

A sandbox escape vulnerability affecting iPhones and iPads running iOS 16.2 beta 1 or earlier versions. The proof-of-concept (POC) exploits…

4 days ago

Hackers Exploiting XWiki Vulnerability in the Wild to Hire the Servers for Botnet

A sharp increase in attacks targeting a critical vulnerability in XWiki servers. Multiple threat actors are actively exploiting CVE-2025-24893 to deploy botnets…

4 days ago

Critical pgAdmin4 Vulnerability Lets Attackers Execute Remote Code on Servers

A severe remote code execution (RCE) flaw has been uncovered in pgAdmin4, the popular open-source interface for PostgreSQL databases. Dubbed…

6 days ago

Critical Fortinet FortiWeb Vulnerability Exploited in the Wild to Create Admin Accounts

A critical vulnerability in Fortinet's FortiWeb Web Application Firewall (WAF) is being actively exploited by threat actors, potentially as a…

1 week ago

Microsoft Defender for O365 New Feature Allows Security Teams to Trigger Automated Investigations

Microsoft has rolled out enhanced remediation capabilities in Defender for Office 365 (O365), enabling security teams to initiate automated investigations…

1 week ago

Palo Alto PAN-OS Firewall Vulnerability Let Attackers Reboot Firewall by Sending Malicious Packet

Palo Alto Networks has disclosed a critical denial-of-service vulnerability in its PAN-OS firewall software that allows unauthenticated attackers to remotely…

1 week ago

OpenAI Sora 2 Vulnerability Exposes System Prompts via Audio Transcripts

A vulnerability in OpenAI's advanced video generation model, Sora 2, that enables the extraction of its hidden system prompt through…

1 week ago

Lite XL Text editor Vulnerability Let Attackers Execute Arbitrary Code

A vulnerability has been discovered in Lite XL, a lightweight text editor, that could allow attackers to execute arbitrary code…

1 week ago

Citrix NetScaler ADC and Gateway Vulnerability Enables Cross-Site Scripting Attacks

Cloud Software Group has disclosed a cross-site scripting (XSS) vulnerability affecting NetScaler ADC and NetScaler Gateway products. Tracked as CVE-2025-12101,…

1 week ago

Multiple Apache OpenOffice Vulnerabilities Leads to Memory Corruption and Unauthorized Content Loading

Apache OpenOffice has released version 4.1.16, addressing seven critical security vulnerabilities that enable unauthorized remote document loading and memory corruption…

1 week ago