Saturday , August 1 2026

Vulnerabilities

3 critical vulnerabilities affect Hikvision product: Patch Now

Hikvision

The Hikvision Security Response Center issued advisory revealing three critical vulnerabilities in HikCentral products. CVE identifiers CVE-2025-39245, CVE-2025-39246, and CVE-2025-39247 represent vulnerabilities with moderate to high severity, potentially allowing attackers to execute unauthorized commands, gain elevated privileges, or obtain administrative access. Summary:  (1) There is a CSV Injection Vulnerability in …

Read More »

(CVE-2025-20241)
Cisco Warns of High-Severity Flaw in Nexus Switches

cisco

Cisco Systems released a security advisory about a critical denial-of-service vulnerability in the Nexus 3000 and 9000 Series Switches using NX-OS software. The flaw, identified as CVE-2025-20241 and rated 7.4 on the CVSS scale, can let an unauthenticated nearby attacker interrupt essential network services. Cisco explains that “a vulnerability in …

Read More »

CVE-2025-9074
Docker Fixes Critical Desktop flaw With CVSS Score 9.3

Docker

Docker has issued fixes for a critical security vulnerability in the Docker Desktop app for Windows and macOS that could enable an attacker to escape a container. The vulnerability CVE-2025-9074 has a CVSS score of 9.3 and is fixed in version 4.44.3. “A malicious container running on Docker Desktop could access …

Read More »

South Asian APT to Compromise Phones of Military-linked Individuals In Bangladesh

A sophisticated South Asian APT group is conducting a widespread espionage campaign against military personnel and defense organizations in Sri Lanka, Bangladesh, Pakistan, and Turkey. Threat actors are using a multi-stage attack strategy that combines phishing with new Android malware to target the mobile devices of military-related individuals. The campaign …

Read More »

Azure’s Default API Connection Vuln Enables Full Cross-Tenant Compromise

API Connection

A critical vulnerability in Microsoft Azure’s API Connection allowed attackers to breach resources in various Azure tenants globally. Gulbrandsrud discovered the flaw that earned him a $40,000 bounty and a chance to present at Black Hat. This flaw exploited Azure’s shared API Management setup, allowing unauthorized access to Key Vaults, …

Read More »

CVE-2018-0171
FBI alerts of Russian hackers exploiting old Cisco flaw

FBI

The Federal Bureau of Investigation (FBI) is warning the public, private sector, and international community of the threat posed to computer networks and critical infrastructure by cyber actors attributed to the Russian Federal Security Service’s (FSB) Center 16. The FBI detected Russian FSB cyber actors exploiting Simple Network Management Protocol …

Read More »

CVE-2025-43300
Apple Issues Urgent Patch for Zero-Day Vuln Exploited in the Wild

Apple

Apple has issued urgent security updates to fix a zero-day vulnerability that is being actively exploited, warning that attackers may have used it in targeted campaigns. CVE-2025-43300 is a flaw in Apple’s Image I/O framework that allows out-of-bounds writing, affecting how applications manage common image file formats. According to Apple’s …

Read More »

Copilot Breaks Your Audit Log, but Microsoft Won’t Tell the customer

Copilot

A significant security vulnerability has been discovered in Microsoft’s Copilot for M365 that allowed users, including potential malicious insiders, to access and interact with sensitive files without leaving any record in the official audit logs. After patching the flaw, Microsoft has reportedly decided against issuing a formal CVE or notifying …

Read More »

0-Day Clickjacking Vuls Found in Password Managers like 1Password, LastPass

password managers

A cybersecurity researcher revealed zero-day clickjacking vulnerabilities in eleven major password managers, risking credential theft for millions of users with just one malicious click. The new attack technique, dubbed “DOM-based Extension Clickjacking,” represents a significant evolution from traditional web-based clickjacking attacks. This technique targets user interface elements created by password …

Read More »

(CVE-2025-54948)
CISA Adds Actively Exploited Trend Micro Apex One Vulnerability

Trend Micro Apex One

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has included the critical Trend Micro Apex One vulnerability, CVE-2025-54948, in its Known Exploited Vulnerabilities (KEV) Catalog due to active exploitation. Trend Micro Apex One is a popular endpoint security platform that detects and responds to malware and other security threats. However, …

Read More »