Vulnerabilities

SonicWall Flags Old Vulnerability as Actively Exploited

SonicWall Flags Old Vulnerability as Actively Exploited 2025-04-17 at 14:05 By Eduard Kovacs A SonicWall SMA 100 series vulnerability patched in 2021, which went unnoticed at the time of patching, is being exploited in the wild. The post SonicWall Flags Old Vulnerability as Actively Exploited appeared first on SecurityWeek. This article is an excerpt from […]

SonicWall Flags Old Vulnerability as Actively Exploited Read More »

Apple Quashes Two Zero-Days With iOS, MacOS Patches

Apple Quashes Two Zero-Days With iOS, MacOS Patches 2025-04-16 at 23:38 By Ryan Naraine The vulnerabilities are described as code execution and mitigation bypass issues that affect Apple’s iOS, iPadOS and macOS platforms. The post Apple Quashes Two Zero-Days With iOS, MacOS Patches appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View

Apple Quashes Two Zero-Days With iOS, MacOS Patches Read More »

MITRE CVE Program Gets Last-Hour Funding Reprieve

MITRE CVE Program Gets Last-Hour Funding Reprieve 2025-04-16 at 19:36 By Ryan Naraine The US government’s cybersecurity agency CISA has “executed the option period on the contract” to keep the vulnerability catalog operational. The post MITRE CVE Program Gets Last-Hour Funding Reprieve appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original

MITRE CVE Program Gets Last-Hour Funding Reprieve Read More »

Critical Vulnerability Found in Apache Roller Blog Server

Critical Vulnerability Found in Apache Roller Blog Server 2025-04-16 at 14:44 By Ionut Arghire A critical vulnerability in Apache Roller could be used to maintain persistent access by reusing older sessions even after password changes. The post Critical Vulnerability Found in Apache Roller Blog Server appeared first on SecurityWeek. This article is an excerpt from

Critical Vulnerability Found in Apache Roller Blog Server Read More »

Chrome 135, Firefox 137 Updates Patch Severe Vulnerabilities

Chrome 135, Firefox 137 Updates Patch Severe Vulnerabilities 2025-04-16 at 14:01 By Ionut Arghire Chrome 135 and Firefox 137 updates have been rolled out with patches for critical- and high-severity vulnerabilities. The post Chrome 135, Firefox 137 Updates Patch Severe Vulnerabilities appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Chrome 135, Firefox 137 Updates Patch Severe Vulnerabilities Read More »

Oracle Patches 180 Vulnerabilities With April 2025 CPU

Oracle Patches 180 Vulnerabilities With April 2025 CPU 2025-04-16 at 14:01 By Ionut Arghire Oracle’s April 2025 Critical Patch Update contains 378 security patches that resolve approximately 180 unique CVEs. The post Oracle Patches 180 Vulnerabilities With April 2025 CPU appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Oracle Patches 180 Vulnerabilities With April 2025 CPU Read More »

MITRE Warns CVE Program Faces Disruption Amid US Funding Uncertainty

MITRE Warns CVE Program Faces Disruption Amid US Funding Uncertainty 2025-04-15 at 23:46 By Ryan Naraine MITRE warns of a deterioration of national vulnerability databases and advisories, slowed vendor reaction and limited response operations. The post MITRE Warns CVE Program Faces Disruption Amid US Funding Uncertainty appeared first on SecurityWeek. This article is an excerpt

MITRE Warns CVE Program Faces Disruption Amid US Funding Uncertainty Read More »

Trend Micro Flags Incomplete Nvidia Patch That Leaves AI Containers Exposed

Trend Micro Flags Incomplete Nvidia Patch That Leaves AI Containers Exposed 2025-04-14 at 19:48 By Ryan Naraine Trend Micro researchers flagging problems with Nvidia’s patch for a critical, code execution vulnerability in the Nvidia Container Toolkit. The post Trend Micro Flags Incomplete Nvidia Patch That Leaves AI Containers Exposed appeared first on SecurityWeek. This article

Trend Micro Flags Incomplete Nvidia Patch That Leaves AI Containers Exposed Read More »

Threat Actor Allegedly Selling Fortinet Firewall Zero-Day Exploit

Threat Actor Allegedly Selling Fortinet Firewall Zero-Day Exploit 2025-04-14 at 16:49 By Ionut Arghire A threat actor claims to offer a zero-day exploit for an unauthenticated remote code execution vulnerability in Fortinet firewalls. The post Threat Actor Allegedly Selling Fortinet Firewall Zero-Day Exploit appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View

Threat Actor Allegedly Selling Fortinet Firewall Zero-Day Exploit Read More »

Rapid7 Reveals RCE Path in Ivanti VPN Appliance After Silent Patch Debacle

Rapid7 Reveals RCE Path in Ivanti VPN Appliance After Silent Patch Debacle 2025-04-11 at 21:05 By Ryan Naraine The CVE-2025-22457 has already been exploited by a China-nexus hacking gang notorious for breaking into edge network devices. The post Rapid7 Reveals RCE Path in Ivanti VPN Appliance After Silent Patch Debacle appeared first on SecurityWeek. This

Rapid7 Reveals RCE Path in Ivanti VPN Appliance After Silent Patch Debacle Read More »

Securing the Energy Sector: The Backbone of the UK’s AI Ambitions

Securing the Energy Sector: The Backbone of the UK’s AI Ambitions 2025-04-11 at 16:08 By Ed Williams AI and Energy Security: The UK’s Crucial Cybersecurity Challenge – Learn why safeguarding the energy sector is critical for the UK’s AI ambitions and technological leadership. Rising Cyber Threats: Ransomware and Legacy Systems in the Energy Sector –

Securing the Energy Sector: The Backbone of the UK’s AI Ambitions Read More »

Vulnerability in OttoKit WordPress Plugin Exploited in the Wild

Vulnerability in OttoKit WordPress Plugin Exploited in the Wild 2025-04-11 at 15:17 By Ionut Arghire A vulnerability in the OttoKit WordPress plugin with over 100,000 active installations has been exploited in the wild. The post Vulnerability in OttoKit WordPress Plugin Exploited in the Wild appeared first on SecurityWeek. This article is an excerpt from SecurityWeek

Vulnerability in OttoKit WordPress Plugin Exploited in the Wild Read More »

SonicWall Patches High-Severity Vulnerability in NetExtender

SonicWall Patches High-Severity Vulnerability in NetExtender 2025-04-11 at 14:18 By Ionut Arghire SonicWall has released fixes for three vulnerabilities in NetExtender for Windows, including a high-severity bug. The post SonicWall Patches High-Severity Vulnerability in NetExtender appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

SonicWall Patches High-Severity Vulnerability in NetExtender Read More »

Pixel-Perfect Trap: The Surge of SVG-Borne Phishing Attacks

Pixel-Perfect Trap: The Surge of SVG-Borne Phishing Attacks 2025-04-10 at 23:16 By Bernard Bautista and Kevin Adriano Ever thought an image file could be part of a cyber threat? The Trustwave SpiderLabs Email Security team has identified a major spike in SVG image-based attacks, where harmless-looking graphics are being used to hide dangerous links. This

Pixel-Perfect Trap: The Surge of SVG-Borne Phishing Attacks Read More »

Juniper Networks Patches Dozens of Junos Vulnerabilities

Juniper Networks Patches Dozens of Junos Vulnerabilities 2025-04-10 at 16:46 By Ionut Arghire Juniper Networks has patched two dozen vulnerabilities in Junos OS and Junos OS Evolved, and dozens of flaws in Junos Space third-party dependencies. The post Juniper Networks Patches Dozens of Junos Vulnerabilities appeared first on SecurityWeek. This article is an excerpt from

Juniper Networks Patches Dozens of Junos Vulnerabilities Read More »

United Nations Urges Global Action as Cyberattacks Threaten Healthcare Systems

United Nations Urges Global Action as Cyberattacks Threaten Healthcare Systems 2025-04-10 at 16:17 By Global Call to Action: The United Nations urges international cooperation to protect healthcare infrastructure from rising cyber threats. Critical Insights from Trustwave SpiderLabs: Discover key findings from real-world Red Team exercises revealing vulnerabilities in healthcare security. Healthcare Under Siege: Learn how ransomware attacks target

United Nations Urges Global Action as Cyberattacks Threaten Healthcare Systems Read More »

CISA Urges Urgent Patching for Exploited CentreStack, Windows Zero-Days

CISA Urges Urgent Patching for Exploited CentreStack, Windows Zero-Days 2025-04-09 at 14:24 By Ionut Arghire CISA has added fresh CentreStack and Windows CLFS vulnerabilities to the Known Exploited Vulnerabilities catalog. The post CISA Urges Urgent Patching for Exploited CentreStack, Windows Zero-Days appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

CISA Urges Urgent Patching for Exploited CentreStack, Windows Zero-Days Read More »

Vulnerabilities Patched by Ivanti, VMware, Zoom 

Vulnerabilities Patched by Ivanti, VMware, Zoom  2025-04-09 at 14:02 By Ionut Arghire Ivanti, VMware, and Zoom released fixes for dozens of vulnerabilities in their products on April 2025 Patch Tuesday. The post Vulnerabilities Patched by Ivanti, VMware, Zoom  appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Vulnerabilities Patched by Ivanti, VMware, Zoom  Read More »

Fortinet Patches Critical FortiSwitch Vulnerability

Fortinet Patches Critical FortiSwitch Vulnerability 2025-04-09 at 13:43 By Ionut Arghire Fortinet fixes a critical-severity bug in FortiSwitch that could allow an attacker to modify administrative passwords. The post Fortinet Patches Critical FortiSwitch Vulnerability appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Fortinet Patches Critical FortiSwitch Vulnerability Read More »

Microsoft Patches 125 Windows Vulns, Including Exploited CLFS Zero-Day

Microsoft Patches 125 Windows Vulns, Including Exploited CLFS Zero-Day 2025-04-08 at 22:03 By Ryan Naraine Patch Tuesday: Microsoft ships urgent cover for another WIndows CLFS vulnerability already exploited in the wild. The post Microsoft Patches 125 Windows Vulns, Including Exploited CLFS Zero-Day appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original

Microsoft Patches 125 Windows Vulns, Including Exploited CLFS Zero-Day Read More »

Scroll to Top