In 2025, many CVEs were exploited, averaging a CVSS severity rating of 8.5, with two hitting the maximum of 10.0, highlighting their critical importance. Most Exploited Vulnerabilities of 2025: CVE-2025-55182: React2Shell CVE-2025-32433: Erlang/OTP SSH Zero-Day Crisis CVE-2025-59287: Microsoft WSUS Deserialization Vulnerability CVE-2025-62221: Windows Cloud Files Driver Zero-Day CVE-2025-62215: Windows Kernel …
Read More »Alert: CISA orders feds to patch actively exploited Geoserver flaw urgently
CISA has ordered U.S. federal agencies to fix a serious GeoServer vulnerability that is currently being exploited in XML External Entity (XXE) injection attacks. CISA reported a security flaw (CVE-2025-58360) on Thursday, an unauthenticated XML External Entity (XXE) vulnerability in GeoServer 2.26.1 and earlier versions. This open-source server for geospatial …
Read More »India-based CCTV cameras flaw allow attacker stealing video feeds, credentials
A severe security flaw has been revealed in various CCTV camera brands in India. This vulnerability enables attackers to access video feeds and steal login information without needing to authenticate. CISA issued an alert on December 9, 2025, with code ICSA-25-343-03. Identifying threats from D-Link India Limited, Sparsh Securitech, and …
Read More »SAP fixes 3 critical vulns across multiple products
SAP’s December security updates have fixed 14 vulnerabilities in various products, including 3 critical ones. CVE-2025-42880, a code injection flaw with a CVSS score of 9.9, is the most critical issue affecting SAP Solution Manager ST 720. “Due to missing input sanitation, SAP Solution Manager allows an authenticated attacker to …
Read More »FortiOS, FortiWeb, and FortiProxy Vuln Allow Bad Actors Bypass FortiCloud SSO Flaw
Fortinet released security updates for critical vulnerabilities in FortiOS, FortiWeb, FortiProxy, and FortiSwitchManager that could let attackers bypass FortiCloud SSO authentication. Threat actors can exploit the security flaws CVE-2025-59718 and CVE-2025-59719 by taking advantage of weaknesses in cryptographic signature verification in affected products using a malicious SAML message. Fortinet stated …
Read More »Microsoft patched 3 zero days with 56 vulns in December 2025 Patch Tuesday
Microsoft’s last Patch Tuesday updates of 2025 on December fixed 56 vulnerabilities in Windows, Office, Exchange Server, and more. This update addresses 3 serious security issues: two remote code execution problems that have been made public and one vulnerability that allows attackers to gain elevated permissions. Several critical issues are …
Read More »1,20,000 IP cameras hacked; Home video sold for porn site: Suspect arrested
The Korean National Police arrested suspected four people for hacking over 120,000 IP cameras and selling the footage to a foreign adult website. Police are acting against the operators of the illegal content despite not revealing the suspects or websites, through international cooperation. “The National Office of Investigation announced that …
Read More »Google Patches 107 Android Flaws, Including 0 days
On Monday, Google released its monthly security updates for Android, addressing two vulnerabilities that have been exploited in the wild. The patch fixes 107 security issues across various components, including Framework, System, Kernel, and those from Arm, Imagination Technologies, MediaTek, Qualcomm, and Unison. The two high-severity shortcomings that have been …
Read More »Tenda N300 Vulns Let Attacker to Execute Arbitrary Commands
CERT/CC has warned of unpatched command injection vulnerabilities in Tenda’s 4G03 Pro and N300 routers. These flaws allow attackers to execute root commands, and there are no fixes from the vendor, putting users at risk. According to the advisory, “A command injection vulnerability exists across multiple firmware versions that allows …
Read More »WhatsApp API flaw let researchers scrape millions of Bangladeshi accounts
Researchers gathered 3.5 billion WhatsApp phone numbers and personal information by abusing a contact-discovery API without proper rate limiting. This study shows a common tactic used by threat actors to collect user information from unprotected public APIs, even though the researchers haven’t shared the data. Abusing WhatsApp API: The researchers …
Read More »
InfoSecBulletin Cybersecurity for mankind