Thursday , July 30 2026

Vulnerabilities

1,20,000 IP cameras hacked; Home video sold for porn site: Suspect arrested

120,000 IP cameras

The Korean National Police arrested suspected four people for hacking over 120,000 IP cameras and selling the footage to a foreign adult website. Police are acting against the operators of the illegal content despite not revealing the suspects or websites, through international cooperation. “The National Office of Investigation announced that …

Read More »

Google Patches 107 Android Flaws, Including 0 days

Android

On Monday, Google released its monthly security updates for Android, addressing two vulnerabilities that have been exploited in the wild. The patch fixes 107 security issues across various components, including Framework, System, Kernel, and those from Arm, Imagination Technologies, MediaTek, Qualcomm, and Unison. The two high-severity shortcomings that have been …

Read More »

Tenda N300 Vulns Let Attacker to Execute Arbitrary Commands

Tenda

CERT/CC has warned of unpatched command injection vulnerabilities in Tenda’s 4G03 Pro and N300 routers. These flaws allow attackers to execute root commands, and there are no fixes from the vendor, putting users at risk. According to the advisory, “A command injection vulnerability exists across multiple firmware versions that allows …

Read More »

WhatsApp API flaw let researchers scrape millions of Bangladeshi accounts

API

Researchers gathered 3.5 billion WhatsApp phone numbers and personal information by abusing a contact-discovery API without proper rate limiting. This study shows a common tactic used by threat actors to collect user information from unprotected public APIs, even though the researchers haven’t shared the data. Abusing WhatsApp API: The researchers …

Read More »

CISA warns of active exploitation of Oracle Identity Manager RCE flaw

Oracle Identity Manager

CISA warns government agencies to patch Oracle Identity Manager (CVE-2025-61757) due to potential zero-day exploitation. CVE-2025-61757 is a pre-authentication remote code execution vulnerability in Oracle Identity Manager, found by Searchlight Cyber analysts Adam Kues and Shubham Shahflaw. The flaw stems from an authentication bypass in Oracle Identity Manager’s REST APIs, …

Read More »

CERT-In Alerts: Asus Router Flaw Endangers Millions in India

CERT-In

CERT-In warns that many homes, small offices, and service providers in India are at risk from a critical authentication flaw, CVE-2025-59367, found in popular Asus DSL-series WiFi routers. The national cybersecurity agency has issued a security alert regarding this vulnerability. The CERT-In Vulnerability Note CIVN-2025-0322 warns that remote attackers can …

Read More »

CISA urges gov.t agencies to patch new FortiWeb flaw within 7 days

gov.t

CISA has instructed U.S. gov.t agencies to secure their systems within a week due to a vulnerability in Fortinet’s FortiWeb web application firewall that has been exploited in zero-day attacks. CVE-2025-58034 is an OS command injection flaw that lets authenticated attackers execute code with minimal effort and no user interaction. …

Read More »

CVE-2025-64446
Fortinet Confirms Active Exploitation of FortiWeb Vulnerability

EMS

Fortinet warned on Friday about a vulnerability in FortiWeb that lets remote, unauthenticated attackers gain admin access to web application firewalls. The bug, labeled CVE-2025-64446 with a CVSS score of 9.1, is a path traversal vulnerability, allowing attackers to run admin commands through specially crafted HTTP or HTTPS requests. Fortinet noted, …

Read More »

Palo Alto PAN-OS Firewall Vuln Allow Attackers Reboot Firewall

PAN-OS firewall

Palo Alto Networks unveils a critical vulnerability in its PAN-OS firewall software that lets unauthenticated attackers remotely restart firewalls by sending specific packets. CVE-2025-4619 is a critical vulnerability that threatens organizations using Palo Alto firewalls for network security. The flaw, identified as CWE-754 (Improper Check for Unusual or Exceptional Conditions), …

Read More »

Microsoft November 2025 Patch Tuesday fixes 63 flaws 1 zero-day

2025 Patch Tuesday

Microsoft has issued its November 2025 Patch Tuesday, fixing 63 vulnerabilities, including a high-priority zero-day flaw that’s currently exploited. This crucial update provides five critical and 64 important fixes, vital for organizations to strengthen their defenses. The updates span key products like SQL Server, Windows Hyper-V, Visual Studio, Windows Kernel, …

Read More »