Vulnerabilities

High-Severity Vulnerabilities Patched by Ivanti and Zoom

High-Severity Vulnerabilities Patched by Ivanti and Zoom 2025-11-12 at 14:44 By Ionut Arghire Ivanti and Zoom resolved security defects that could lead to arbitrary file writes, elevation of privilege, code execution, and information disclosure. The post High-Severity Vulnerabilities Patched by Ivanti and Zoom appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View […]

High-Severity Vulnerabilities Patched by Ivanti and Zoom Read More »

Chipmaker Patch Tuesday: Over 60 Vulnerabilities Patched by Intel

Chipmaker Patch Tuesday: Over 60 Vulnerabilities Patched by Intel 2025-11-12 at 12:40 By Eduard Kovacs Intel, AMD and Nvidia have published security advisories describing vulnerabilities found recently in their products. The post Chipmaker Patch Tuesday: Over 60 Vulnerabilities Patched by Intel appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Chipmaker Patch Tuesday: Over 60 Vulnerabilities Patched by Intel Read More »

Tenzai Raises $75 Million in Seed Funding to Build AI-Powered Pentesting Platform

Tenzai Raises $75 Million in Seed Funding to Build AI-Powered Pentesting Platform 2025-11-11 at 23:07 By Mike Lennon Tel Aviv, Israel based Tenzai has developed an AI-driven platform for penetration testing, which it says can continuously identify and address vulnerabilities. The post Tenzai Raises $75 Million in Seed Funding to Build AI-Powered Pentesting Platform appeared first

Tenzai Raises $75 Million in Seed Funding to Build AI-Powered Pentesting Platform Read More »

Microsoft Patches Actively Exploited Windows Kernel Zero-Day

Microsoft Patches Actively Exploited Windows Kernel Zero-Day 2025-11-11 at 23:07 By Eduard Kovacs Microsoft’s latest Patch Tuesday updates address more than 60 vulnerabilities in Windows and other products. The post Microsoft Patches Actively Exploited Windows Kernel Zero-Day appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Microsoft Patches Actively Exploited Windows Kernel Zero-Day Read More »

Critical Triofox Vulnerability Exploited in the Wild

Critical Triofox Vulnerability Exploited in the Wild 2025-11-11 at 17:38 By Ionut Arghire A threat actor has exploited the issue to create a new administrator account and then used the account to execute remote access tools. The post Critical Triofox Vulnerability Exploited in the Wild appeared first on SecurityWeek. This article is an excerpt from

Critical Triofox Vulnerability Exploited in the Wild Read More »

SAP Patches Critical Flaws in SQL Anywhere Monitor, Solution Manager

SAP Patches Critical Flaws in SQL Anywhere Monitor, Solution Manager 2025-11-11 at 16:59 By Ionut Arghire Hardcoded credentials in SQL Anywhere Monitor could allow attackers to execute arbitrary code on vulnerable deployments. The post SAP Patches Critical Flaws in SQL Anywhere Monitor, Solution Manager appeared first on SecurityWeek. This article is an excerpt from SecurityWeek

SAP Patches Critical Flaws in SQL Anywhere Monitor, Solution Manager Read More »

QNAP Patches Vulnerabilities Exploited at Pwn2Own Ireland

QNAP Patches Vulnerabilities Exploited at Pwn2Own Ireland 2025-11-10 at 16:49 By Ionut Arghire Multiple vulnerabilities across QNAP’s portfolio could lead to remote code execution, information disclosure, and denial-of-service (DoS) conditions. The post QNAP Patches Vulnerabilities Exploited at Pwn2Own Ireland appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

QNAP Patches Vulnerabilities Exploited at Pwn2Own Ireland Read More »

Runc Vulnerabilities Can Be Exploited to Escape Containers

Runc Vulnerabilities Can Be Exploited to Escape Containers 2025-11-10 at 16:29 By Eduard Kovacs The flaws tracked as CVE-2025-31133, CVE-2025-52565, and CVE-2025-52881 have been patched. The post Runc Vulnerabilities Can Be Exploited to Escape Containers appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Runc Vulnerabilities Can Be Exploited to Escape Containers Read More »

The Cat’s Out of the Bag: A ‘Meow Attack’ Data Corruption Campaign Simulation via MAD-CAT

The Cat’s Out of the Bag: A ‘Meow Attack’ Data Corruption Campaign Simulation via MAD-CAT 2025-11-07 at 19:39 By Karl Biron In 2024, I published Feline Hackers Among Us? (A Deep Dive and Simulation of the Meow Attack), which explored the notorious Meow attack campaign that had plagued unsecured databases since 2020. That article focused

The Cat’s Out of the Bag: A ‘Meow Attack’ Data Corruption Campaign Simulation via MAD-CAT Read More »

Data Exposure Vulnerability Found in Deep Learning Tool Keras

Data Exposure Vulnerability Found in Deep Learning Tool Keras 2025-11-07 at 15:41 By Ionut Arghire The vulnerability is tracked as CVE-2025-12058 and it can be exploited for arbitrary file loading and conducting SSRF attacks. The post Data Exposure Vulnerability Found in Deep Learning Tool Keras appeared first on SecurityWeek. This article is an excerpt from

Data Exposure Vulnerability Found in Deep Learning Tool Keras Read More »

Chrome 142 Update Patches High-Severity Flaws

Chrome 142 Update Patches High-Severity Flaws 2025-11-07 at 12:35 By Ionut Arghire An out-of-bounds write flaw in WebGPU tracked as CVE-2025-12725 could be exploited for remote code execution. The post Chrome 142 Update Patches High-Severity Flaws appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Chrome 142 Update Patches High-Severity Flaws Read More »

Cisco Patches Critical Vulnerabilities in Contact Center Appliance

Cisco Patches Critical Vulnerabilities in Contact Center Appliance 2025-11-06 at 14:50 By Ionut Arghire The flaws allow attackers to execute arbitrary code remotely and elevate their privileges to root on an affected system. The post Cisco Patches Critical Vulnerabilities in Contact Center Appliance appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View

Cisco Patches Critical Vulnerabilities in Contact Center Appliance Read More »

CISA Warns of CWP Vulnerability Exploited in the Wild

CISA Warns of CWP Vulnerability Exploited in the Wild 2025-11-05 at 10:08 By Eduard Kovacs A critical vulnerability in Control Web Panel (CWP), tracked as CVE-2025-48703, allows remote, unauthenticated command execution. The post CISA Warns of CWP Vulnerability Exploited in the Wild appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original

CISA Warns of CWP Vulnerability Exploited in the Wild Read More »

SpiderLabs Ransomware Tracker Update October 2025: Qlin Doubles Down on Attacks

SpiderLabs Ransomware Tracker Update October 2025: Qlin Doubles Down on Attacks 2025-11-04 at 17:18 By The worldwide ransomware landscape saw a dramatic shift in attacks in October 2025, jumping 41% month over month, with the most prolific attacker, Qlin, more than doubling the number of attacks it launched, according to Trustwave, A LevelBlue Company, research.

SpiderLabs Ransomware Tracker Update October 2025: Qlin Doubles Down on Attacks Read More »

Scattered LAPSUS$ Hunters: Anatomy of a Federated Cybercriminal Brand

Scattered LAPSUS$ Hunters: Anatomy of a Federated Cybercriminal Brand 2025-11-04 at 16:27 By Trustwave SpiderLabs’ Cyber Threat Intelligence team is tracking the recent emergence of what appears to be the consolidation of three well-known threat groups into a “federated alliance” that offers, among its activities, Extortion-as-a-Service (EaaS). This article is an excerpt from SpiderLabs Blog

Scattered LAPSUS$ Hunters: Anatomy of a Federated Cybercriminal Brand Read More »

Apple Patches 19 WebKit Vulnerabilities 

Apple Patches 19 WebKit Vulnerabilities  2025-11-04 at 13:25 By Ionut Arghire Apple has released iOS 26.1 and macOS Tahoe 26.1 with patches for over 100 vulnerabilities, including critical flaws. The post Apple Patches 19 WebKit Vulnerabilities  appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Apple Patches 19 WebKit Vulnerabilities  Read More »

How Software Development Teams Can Securely and Ethically Deploy AI Tools

How Software Development Teams Can Securely and Ethically Deploy AI Tools 2025-11-03 at 18:13 By Matias Madou To deploy AI tools securely and ethically, teams must balance innovation with accountability—establishing strong governance, upskilling developers, and enforcing rigorous code reviews. The post How Software Development Teams Can Securely and Ethically Deploy AI Tools appeared first on

How Software Development Teams Can Securely and Ethically Deploy AI Tools Read More »

Google Pays $100,000 in Rewards for Two Chrome Vulnerabilities

Google Pays $100,000 in Rewards for Two Chrome Vulnerabilities 2025-11-03 at 12:27 By Ionut Arghire The two bugs are high-severity type confusion and inappropriate implementation issues in the browser’s V8 JavaScript engine. The post Google Pays $100,000 in Rewards for Two Chrome Vulnerabilities appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View

Google Pays $100,000 in Rewards for Two Chrome Vulnerabilities Read More »

CISA Adds Exploited XWiki, VMware Flaws to KEV Catalog

CISA Adds Exploited XWiki, VMware Flaws to KEV Catalog 2025-10-31 at 13:59 By Ionut Arghire Broadcom has updated its advisory on CVE-2025-41244 to mention the vulnerability’s in-the-wild exploitation. The post CISA Adds Exploited XWiki, VMware Flaws to KEV Catalog appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

CISA Adds Exploited XWiki, VMware Flaws to KEV Catalog Read More »

Scroll to Top