IBM has issued fixes for three security vulnerabilities in its IBM Security Verify Access and IBM Verify Identity Access products. These issues could permit privilege escalation, command execution, and script injection. Customers are urged to install these patches right away to avoid exploitation in production environments. CVE-2025-36355 lets authenticated users …
Read More »Hacker Claims Breach of Huawei Source Code and Internal Tools
A threat actor claims to have breached Huawei Technologies Co., Ltd. (Huawei), a multinational technology company based in Shenzhen, China, that specializes in telecommunications equipment. The incident, which the actor states occurred in October 2025, allegedly resulted in the exfiltration of internal company data. According to the actor, the compromised …
Read More »Oracle released patch for E business suite (CVE-2025-61882) after Cl0p attack
Oracle has issued an emergency update to fix a serious security issue in its E-Business Suite, which has been targeted in recent Cl0p data theft attacks. The critical vulnerability, CVE-2025-61882 (CVSS score: 9.8), could let an unauthenticated attacker with HTTP access compromise the Oracle Concurrent Processing component. “This vulnerability is …
Read More »Hackers exploited Zimbra flaw as zero-day using iCalendar files
Researchers monitoring for larger .ICS calendar attachments found that a flaw in Zimbra Collaboration Suite (ZCS) was used in zero-day attacks at the beginning of the year. ICS files, or iCalendar files, store plain text calendar information, like meetings and events, and allow exchange between different calendar apps. Threat actors …
Read More »Alert: Self-Propagating Malware Spreading Via WhatsApp
Trendâ„¢ Research is investigating a malware campaign that uses WhatsApp to infect users. This attack is focused on spreading quickly and taking advantage of social trust, rather than theft or ransomware. It’s called SORVEPOTEL and is currently most active in Brazil. The campaign is dubbed SORVEPOTEL by Trend Micro that …
Read More »Splunk Fixes Six Flaws, Including SSRF and XSS Vulns in Enterprise Platform
Splunk issued security advisories for six vulnerabilities in Splunk Enterprise and Splunk Cloud Platform, with severity levels from medium to high. The issues include improper access control, various cross-site scripting (XSS) types, XML external entity (XXE) injection, denial-of-service (DoS) via LDAP misuse, and a high-severity server-side request forgery (SSRF). CVE-2025-20366 …
Read More »50K Cisco firewalls vulnerable to actively exploited flaws
50k Cisco ASA and FTD devices on the internet are at risk due to two vulnerabilities being exploited by hackers. Flaws CVE-2025-20333 and CVE-2025-20362 allow remote code execution and access to restricted VPN URLs without authentication. On September 25, Cisco warned that the issues were actively exploited in attacks that …
Read More »Hackers Exploiting New VMware Zero-Day Since October 2024
A newly patched security flaw in Broadcom VMware Tools and VMware Aria Operations has been exploited by a threat actor named UNC5174 since mid-October 2024, according to NVISO Labs. The vulnerability identified as CVE-2025-41244 (CVSS score: 7.8) is a flaw that allows local privilege escalation, impacting the following versions – …
Read More »
CVE-2025-55177 and CVE-2025-43300
WhatsApp 0-Click Vuln Exploited Using Malicious DNG File
Security researchers found a zero-click vulnerability in WhatsApp that lets remote code execution (RCE) on iOS, macOS, and iPadOS. The attack chain uses two vulnerabilities, CVE-2025-55177 and CVE-2025-43300, to compromise a device without user interaction. Researchers from DarkNavyOrg demonstrated a “zero-click” exploit that targets WhatsApp. This attack involves sending a …
Read More »Cisco warns customer of ASA firewall zero-days exploited in attacks
Cisco warned customers to patch two zero-day vulnerabilities that are actively being exploited in attacks and impact the company’s firewall software. The first one (CVE-2025-20333) allows authenticated, remote attackers to execute arbitrary code on devices running vulnerable Adaptive Security Appliance (ASA) and Firewall Threat Defense (FTD) software, while the second …
Read More »
InfoSecBulletin Cybersecurity for mankind