Node.js released security updates on January 13, 2026, fixing vulnerabilities that could cause memory leaks, denial-of-service attacks, and permission bypasses. These updates fix three critical vulnerabilities, among others, urging immediate upgrades for affected systems. High Severity Vulnerabilities: CVE-2025-55131 reveals critical flaws in Buffer.alloc and Uint8Array, resulting from timeout races in …
Read More »Microsoft Patch Tuesday January 2026 addresses 3 zero-days and 114 flaws
Microsoft’s January 2026 updates address 114 vulnerabilities, including critical remote code execution bugs in Office apps and Windows services like LSASS. This Patch Tuesday fixes critical vulnerabilities that allow remote code execution and several privilege escalation problems that could let attackers take over systems. The number of bugs in each …
Read More »CISA orders feds to fix Gogs RCE vuln exploited in zero-day attacks
CISA has instructed government agencies to protect their systems from Gogs vulnerability exploited in zero-day attacks. Designated as CVE-2025-8110, this remote code execution (RCE) vulnerability originates from a path traversal issue within the PutContents API. It empowers authenticated attackers to circumvent the safety measures established for a previously resolved RCE …
Read More »
CIRT Alert
35 unique IP vulnarable via n8n (CVE:2026-21858) instances in Bangladesh
A total of 35 unique IP addresses have been identified exploitable via n8n instances (CVE: 2026-21858). BGD e-GOV CIRT advisory said, these IP address seems to be demonstrating active exploitation activity, indicating real-world targeting and compromise of vulnerable deployments. Affected versons: • n8n self-hosted instances running versions 1.65.0 to below …
Read More »Over 10,000 Fortinet Firewalls Exposed to 5-Year-Old MFA Bypass Vuln
Over 10,000 Fortinet firewalls globally are still vulnerable to CVE-2020-12812, a flaw that allows bypassing multi-factor authentication (MFA) and was revealed over five years ago. Shadowserver added this issue to its daily Vulnerable HTTP Report. CVE-2020-12812 is due to inadequate authentication in FortiOS SSL VPN portals, impacting versions 6.4.0, 6.2.0 …
Read More »Fortinet Warns of 2020 FortiGate Flaw to Bypass 2FA
Fortinet warns that a three-year-old vulnerability allows attackers to bypass 2FA on FortiGate firewalls by merely altering the capitalization of usernames. The vulnerability FG-IR-19-283 (CVE-2020-12812) was reported and fixed in July 2020. Recently, it has been noted that attackers are exploiting this flaw in organizations that haven’t addressed specific configurations. …
Read More »Over 100 Cisco Secure Email Devices Exposed to Zero‑Day Attack
Security researchers found at least 120 Cisco Secure Email Gateway and Cisco Secure Email and Web Manager devices vulnerable to a critical zero-day flaw that is being actively exploited. CVE-2025-20393 is a vulnerability with no patch available, putting organizations at risk. Threat intelligence from Shadowserver Foundation indicates that vulnerable devices …
Read More »Tool Unveil to Detect Cisco Secure Email Gateway 0-Day Vulnerability
A simple Python script to help organizations quickly detect exposure to CVE-2025-20393, a critical zero-day vulnerability in Cisco Secure Email Gateway (SEG) and Secure Malware Analytics (SMA). The “Cisco SMA Exposure Check” tool identifies open ports and services exploited in recent attacks, as noted in Cisco’s advisory. GitHub user StasonJatham …
Read More »ASRock, ASUS, GIGABYTE, MSI Motherboards New UEFI Flaw allow pre-boot attacks
Certain motherboards from ASUS, Gigabyte, MSI, and ASRock are susceptible to DMA attacks that can bypass early-boot memory protections. This security flaw has several identifiers (CVE-2025-11901, CVE-2025‑14302, CVE-2025-14303, and CVE-2025-14304)due to differences in vendor implementations. The vulnerability found by Nick Peterson and Mohamed Al-Sharifi of Riot Games in some UEFI …
Read More »1.7 Million Login Attempts Target Palo Alto and Cisco SSL VPNs in 16 Hours
GreyNoise reported that login attempts on GlobalProtect portals surged to 1.7 million over 16 hours, targeting various VPNs, including Palo Alto Networks GlobalProtect and Cisco SSL VPN. Data revealed that over 10,000 unique IP addresses targeted infrastructure in the United States, Mexico, and Pakistan. The malicious traffic originated almost entirely …
Read More »
InfoSecBulletin Cybersecurity for mankind