Adobe’s August 2025 Patch Tuesday updates fix over 60 vulnerabilities in 3D design, content creation, publishing, and other products. The software giant has released 13 new advisories, including five for vulnerabilities in Substance 3D products: Viewer, Modeler, Painter, Sampler, and Stager. Adobe fixed critical code execution vulnerabilities and several medium-severity …
Read More »WinRAR Zero-Day and 7-Zip Vulnerability actively exploited
ESET researchers found a zero-day vulnerability in WinRAR for Windows, tracked as CVE-2025-8088, which has been used to run malicious code on victims’ computers. With a CVSS v3.1 score of 8.4, this flaw lets attackers manipulate extraction processes and place harmful files in the wrong system areas. Vulnerable versions of …
Read More »28,000+ Microsoft Exchange Servers Exposed Online for CVE-2025-53786
More than 28,000 unpatched Microsoft Exchange servers are publicly accessible and vulnerable to the critical security flaw CVE-2025-53786, as reported by The Shadowserver Foundation on August 7, 2025. CISA’s Emergency Directive 25-02 on August 7 requires federal agencies to fix a critical vulnerability in Microsoft Exchange hybrid setups by 9:00 …
Read More »Multiple 0-days to Bypass BitLocker and Extract Data
Researchers revealed critical zero-day vulnerabilities that bypass Windows BitLocker encryption, enabling attackers with physical access to quickly extract data from encrypted devices. Research by Alon Leviev and Netanel Ben Simon from Microsoft’s STORM team reveals critical flaws in the Windows Recovery Environment (WinRE) that threaten BitLocker’s security. Four Critical Attack …
Read More »DataCenter Exposes 38GB of PII Including Emails and Phone Numbers
Cybersecurity researcher Jeremiah Fowler discovered an unencrypted database with 38 GB of CSV and PDF files and reported it to Website Planet. The exposed data included hundreds of thousands of names, addresses, phone numbers, emails, and other sensitive information. The publicly exposed database was not password-protected or encrypted. It contained …
Read More »
CVE-2025-54948
Trend Micro alerts of Apex One zero-day exploited in attacks
Trend Micro warned customers to quickly secure their systems due to a remote code execution vulnerability in its Apex One endpoint security platform that is currently being exploited. Apex One is an endpoint security platform designed to automatically detect and respond to threats, including malicious tools, malware, and vulnerabilities. The …
Read More »Dell Laptop PCs 100+ models affected through “ReVault” attack
More than 100 Dell laptop models in the Latitude and Precision series are vulnerable due to five common security issues affecting their firmware and Microsoft Windows APIs, according to a Cisco Talos report. Talos researchers named the vulnerabilities ReVault. They allow an attacker to keep access to a victim’s device …
Read More »HashiCorp patched A Vault Flaw Allowing Code Execution
HashiCorp has recently fixed a critical vulnerability—CVE-2025-6000—in its secrets management tool, Vault. With a CVSS score of 9.1, this flaw could let privileged Vault operators run arbitrary code on the host system if misconfigured. “A privileged Vault operator within the root namespace with write permission to sys/audit may obtain code …
Read More »17K+ SharePoint Servers Exposed to Internet : 840 Servers Vuln to 0-Day Attacks
Over 17k Microsoft SharePoint servers are exposed to internet attacks, with 840 vulnerable to the critical zero-day vulnerability CVE-2025-53770, according to Shadowserver Foundation. The “ToolShell” vulnerability has a critical CVSS score of 9.8 and lets unauthorized users run arbitrary code on on-premises SharePoint servers. Microsoft has attributed the attacks to …
Read More »
CVE-2025-31700 & CVE-2025-31701
Buffer Overflow Flaws in Dahua IP Cameras Expose Devices to RCE
Dahua Technology released a security advisory about two serious vulnerabilities in its IP cameras, after a report from the Bitdefender IoT Research Team. The vulnerabilities, CVE-2025-31700 and CVE-2025-31701, each have a CVSS score of 8.1 and are due to buffer overflow issues that can let remote attackers crash devices or …
Read More »
InfoSecBulletin Cybersecurity for mankind