Friday, November 21, 2025
Follow on LinkedIn
New "Daemon Ex Plist" Vulnerability Gives Attackers Root Access on macOS

New “Daemon Ex Plist” Vulnerability Gives Attackers Root Access on macOS

A critical vulnerability in macOS allows attackers to escalate privileges to root access through misconfigured daemon services.  The vulnerability, dubbed "Daemon Ex Plist," exploits weaknesses...
CSA Vulnerability Actively Exploited

Ivanti Warns of CSA Vulnerability Actively Exploited in Attacks

Ivanti has warned about a critical vulnerability in its Cloud Services Appliance (CSA) 4.6, which has been actively exploited in attacks. The vulnerability, identified...
Anthropic’s MCP Server Vulnerability

Anthropic’s MCP Server Vulnerability Allowed Attackers to Escape Sandbox and Execute Code

Two high-severity vulnerabilities in Anthropic's Model Context Protocol (MCP) Filesystem Server enable attackers to escape sandbox restrictions and execute arbitrary code on host systems.  The...
Okta Verify Agent Windows Flaw

Okta Verify Agent Windows Flaw Let Attackers Steal User Passwords

Okta, a leading identity and access management company, has patched a critical vulnerability in its Verify agent for Windows that could allow attackers to...
GitHub Enterprise Server Vulnerability

GitHub Enterprise Server Vulnerability Allow Attackers to Gain Admin Access

The latest update to GitHub Enterprise Server, version 3.13.3, addressed a critical vulnerability (CVE-2024-6800), allowing attackers to forge SAML responses and gain unauthorized access. ...
New Security Vulnerability Let Attackers Microsoft Corporate Email Accounts

New Security Vulnerability Let Attackers Microsoft Corporate Email Accounts

A newly discovered security vulnerability allows attackers to impersonate Microsoft corporate email accounts, significantly increasing the risk of phishing attacks. Security researcher Vsevolod Kokorin,...
Hackers Actively Exploiting WP Automatic Updates Plugin Vulnerability

Hackers Actively Exploiting WP Automatic Updates Plugin Vulnerability

Hackers often target WordPress plugins as they have security loopholes that they can exploit to hack into sites without permission.  Once they have found them,...
HashiCorp Cloud Vault Vulnerability

HashiCorp Cloud Vault Vulnerability Let Attackers Escalate Privileges

HashiCorp, a leading provider of cloud infrastructure automation software, has disclosed a critical security vulnerability in its Vault secret management platform. The flaw, identified as...
Hackers Actively Exploiting CitrixBleed 2 Vulnerability in the Wild

Hackers Actively Exploiting CitrixBleed 2 Vulnerability in the Wild

Researchers have observed widespread exploitation attempts targeting a critical memory disclosure vulnerability in Citrix NetScaler devices, designated as CVE-2025-5777 and dubbed "CitrixBleed 2."  This pre-authentication...
SAP NetWeaver Vulnerability

Critical SAP NetWeaver Vulnerability Let Attackers Bypass Authorization Checks

A critical security vulnerability has been discovered in SAP NetWeaver Application Server for ABAP that allows authenticated attackers to bypass standard authorization checks and...
CSN

Top 10