F5 Networks has revealed a new HTTP/2 vulnerability impacting several BIG-IP products, which could enable remote attackers to conduct denial-of-service attacks on corporate networks. The security flaw named CVE-2025-54500, known as the “HTTP/2 MadeYouReset Attack,” was announced on August 13, 2025, with updates on August 15. The vulnerability exploits malformed …
Read More »
(CVE-2025-49457)
Zoom Patches Critical Flaw Allowing Privilege Escalation Risk
Zoom has released security updates for its Windows clients to fix two major vulnerabilities, CVE-2025-49456 and CVE-2025-49457, which could allow attackers to exploit race conditions and untrusted search paths. The first flaw, CVE-2025-49456 (CVSS 6.2), is a race condition in the installer for certain Zoom Clients for Windows. According to …
Read More »Adobe Patched 60+ Vulnerabilities Across 13 Products
Adobe’s August 2025 Patch Tuesday updates fix over 60 vulnerabilities in 3D design, content creation, publishing, and other products. The software giant has released 13 new advisories, including five for vulnerabilities in Substance 3D products: Viewer, Modeler, Painter, Sampler, and Stager. Adobe fixed critical code execution vulnerabilities and several medium-severity …
Read More »WinRAR Zero-Day and 7-Zip Vulnerability actively exploited
ESET researchers found a zero-day vulnerability in WinRAR for Windows, tracked as CVE-2025-8088, which has been used to run malicious code on victims’ computers. With a CVSS v3.1 score of 8.4, this flaw lets attackers manipulate extraction processes and place harmful files in the wrong system areas. Vulnerable versions of …
Read More »28,000+ Microsoft Exchange Servers Exposed Online for CVE-2025-53786
More than 28,000 unpatched Microsoft Exchange servers are publicly accessible and vulnerable to the critical security flaw CVE-2025-53786, as reported by The Shadowserver Foundation on August 7, 2025. CISA’s Emergency Directive 25-02 on August 7 requires federal agencies to fix a critical vulnerability in Microsoft Exchange hybrid setups by 9:00 …
Read More »Multiple 0-days to Bypass BitLocker and Extract Data
Researchers revealed critical zero-day vulnerabilities that bypass Windows BitLocker encryption, enabling attackers with physical access to quickly extract data from encrypted devices. Research by Alon Leviev and Netanel Ben Simon from Microsoft’s STORM team reveals critical flaws in the Windows Recovery Environment (WinRE) that threaten BitLocker’s security. Four Critical Attack …
Read More »DataCenter Exposes 38GB of PII Including Emails and Phone Numbers
Cybersecurity researcher Jeremiah Fowler discovered an unencrypted database with 38 GB of CSV and PDF files and reported it to Website Planet. The exposed data included hundreds of thousands of names, addresses, phone numbers, emails, and other sensitive information. The publicly exposed database was not password-protected or encrypted. It contained …
Read More »
CVE-2025-54948
Trend Micro alerts of Apex One zero-day exploited in attacks
Trend Micro warned customers to quickly secure their systems due to a remote code execution vulnerability in its Apex One endpoint security platform that is currently being exploited. Apex One is an endpoint security platform designed to automatically detect and respond to threats, including malicious tools, malware, and vulnerabilities. The …
Read More »Dell Laptop PCs 100+ models affected through “ReVault” attack
More than 100 Dell laptop models in the Latitude and Precision series are vulnerable due to five common security issues affecting their firmware and Microsoft Windows APIs, according to a Cisco Talos report. Talos researchers named the vulnerabilities ReVault. They allow an attacker to keep access to a victim’s device …
Read More »HashiCorp patched A Vault Flaw Allowing Code Execution
HashiCorp has recently fixed a critical vulnerability—CVE-2025-6000—in its secrets management tool, Vault. With a CVSS score of 9.1, this flaw could let privileged Vault operators run arbitrary code on the host system if misconfigured. “A privileged Vault operator within the root namespace with write permission to sys/audit may obtain code …
Read More »
InfoSecBulletin Cybersecurity for mankind