Friday, November 21, 2025
Follow on LinkedIn
Google Chrome Zero-Day Vulnerability Exploited

Google Chrome 0-Day Vulnerability Exploited by APT Hackers in the Wild

A sophisticated attack campaign exploiting a Google Chrome zero-day vulnerability tracked as CVE-2025-2783, marking yet another instance of advanced persistent threat (APT) groups leveraging...
Windows SMB Client Zero-Day Vulnerability Exploited

Windows SMB Client Zero-Day Vulnerability Exploited Using Reflective Kerberos Relay Attack

A critical zero-day vulnerability affecting Windows systems that allows attackers to achieve privilege escalation through a novel Reflective Kerberos Relay Attack.  The vulnerability, designated CVE-2025-33073,...
Salesforce SOQL Injection 0-Day Vulnerability

Critical SOQL Injection 0-Day Vulnerability in Salesforce Affects Millions Worldwide

A critical zero-day vulnerability discovered in Salesforce's default controller has exposed millions of user records across thousands of deployments worldwide.  The security flaw, found in...
Versa Concerto 0-Day Authentication Bypass Vulnerability

Versa Concerto 0-Day Authentication Bypass Vulnerability Allows Remote Code Execution

Significant vulnerabilities were uncovered in Versa Concerto, a widely deployed SD-WAN orchestration platform used by major enterprises and government entities.  The flaws include authentication bypass...
Grafana 0-Day

Grafana 0-Day Vulnerability Let Attackers to Redirect Users to Malicious Websites

A high-severity cross-site scripting (XSS) vulnerability in Grafana could allow attackers to redirect users to malicious websites.  The vulnerability, tracked as CVE-2025-4123 received a CVSS...
Ivanti EPMM 0-day

CISA Adds Ivanti EPMM 0-day to KEV Catalog Following Active Exploitation

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) officially added two critical zero-day vulnerabilities affecting Ivanti Endpoint Manager Mobile (EPMM) to its Known Exploited...
Firefox 0-day Vulnerabilities

Firefox 0-day Vulnerabilities Let Attackers Execute Malicious Code

Mozilla has released an emergency security update to address two critical vulnerabilities in Firefox that could allow attackers to execute malicious code on users'...
SAP Patch Tuesday - Patch for Actively Exploited

SAP May 2025 Patch Tuesday – Patch for Actively Exploited 0-Day & 15 Vulnerabilities

SAP's May 2025 Security Patch Day includes an urgent update to the previously released emergency patch for a critical zero-day vulnerability (CVE-2025-31324) that continues...
CISA Adds SAP 0-day Flaw to KEV List 

CISA Warns SAP 0-day Vulnerability Exploited in the Wild 

CISA has added a critical SAP NetWeaver vulnerability to its Known Exploited Vulnerabilities (KEV) catalog on April 29, 2025.  The zero-day flaw, tracked as CVE-2025-31324,...

RedGolf Hackers Expose Fortinet Exploits & Tools Used to Hack Organizations

RedGolf, a sophisticated threat actor with ties to APT41, provided a rare insight into its operational toolbox after a directory on their attack infrastructure...
CSN

Top 10