Friday, November 21, 2025
Follow on LinkedIn
F5 BIG-IP Authentication Flaw

F5 BIG-IP APM AD (Active Directory) Authentication Flaw Bypassed using a Spoofed AS-REP

Cybersecurity researchers on Wednesday disclosed a new bypass vulnerability (CVE-2021-23008) in the Kerberos Key Distribution Center (KDC) security feature impacting F5 Big-IP application delivery...
Bitdefender SSRF Vulnerability

Bitdefender Vulnerability Let Attackers Trigger SSRF Attacks

A critical security vulnerability has been discovered in Bitdefender's GravityZone Update Server, potentially exposing organizations to server-side request forgery (SSRF) attacks. The flaw, identified as...
8,500+ Exchange Servers Vulnerable To Privilege escalation 0-day Flaw

8,500+ Exchange Servers Vulnerable To Privilege escalation 0-Day Flaw

A critical vulnerability in Microsoft Exchange Server, identified as CVE-2024-21410, has been reported to be actively exploited by threat actors.  This zero-day flaw allows remote...
Google Chrome Zero-day Exploited in the Wild: Patch Now!

Google Chrome Zero-day Exploited in the Wild: Patch Now!

Google has released urgent upgrades to fix the Chrome zero-day high-severity vulnerability that has been widely exploited, which could lead to software crashes or...
GhostContainer Malware Hacking Exchange Servers in the Wild Using N-day Vulnerability

GhostContainer Malware Hacking Exchange Servers in the Wild Using N-day Vulnerability

A highly sophisticated malware campaign targeting Microsoft Exchange servers in government and high-tech organizations across Asia.  The malware, dubbed GhostContainer, exploits known N-day vulnerabilities to...
Google Chrome Use after free Vulnerability leads to Browser Crash

Google Chrome Use-After-Free Vulnerability Leads to Browser Crash

Google Chrome Stable Channel Update for Desktop version 119.0.6.45.159 for Mac and Linux and 119.0.6045.159/.160 for Windows has been released, which will be rolling...
LiteSpeed Cache Plugin XSS Flaw Exposes 4+ Million Sites to Attack

LiteSpeed Cache Plugin XSS Flaw Exposes 4M+ Million Sites to Attack

A critical vulnerability has been discovered in the LiteSpeed Cache plugin, a popular WordPress plugin installed on over 4 million websites. This flaw, identified...
SonicWall Warns of Access Control Vulnerability Exploited in the Wild

SonicWall Warns of Access Control Vulnerability Exploited in the Wild

SonicWall has issued an urgent security advisory regarding a critical vulnerability (CVE-2024-40766) affecting its firewall products. The company warns that this improper access control...
Critical Flaws In Traffic Light Controller Let Attackers Change Signal Lights

Critical Flaws In Traffic Light Controller Let Attackers Change Signal Lights

A critical vulnerability in a traffic light controller has been found, which might allow attackers to change the lights and cause a traffic jam.  A...
Researcher Details Exploitation of Exchange PowerShell via MultiValuedProperty

Researcher Details Exploitation of Exchange PowerShell via MultiValuedProperty

OffensiveCon 2024 devised multiple methods to exploit Microsoft Exchange. One method was using the MultiValuedProperty, through which a researcher was able to exploit Exchange...
CSN

Top 10