Over 17k Microsoft SharePoint servers are exposed to internet attacks, with 840 vulnerable to the critical zero-day vulnerability CVE-2025-53770, according to Shadowserver Foundation. The “ToolShell” vulnerability has a critical CVSS score of 9.8 and lets unauthorized users run arbitrary code on on-premises SharePoint servers. Microsoft has attributed the attacks to …
Read More »
CVE-2025-31700 & CVE-2025-31701
Buffer Overflow Flaws in Dahua IP Cameras Expose Devices to RCE
Dahua Technology released a security advisory about two serious vulnerabilities in its IP cameras, after a report from the Bitdefender IoT Research Team. The vulnerabilities, CVE-2025-31700 and CVE-2025-31701, each have a CVSS score of 8.1 and are due to buffer overflow issues that can let remote attackers crash devices or …
Read More »
(CVE-2025-6704, CVE-2025-7624)
Urgent Sophos Firewall Update: Two Critical RCE Flaws Patched
Sophos has released a security advisory addressing five vulnerabilities in Sophos Firewall, two of which are critical and could enable remote attackers to take control of affected devices in specific situations. The company confirms that fixes have been automatically deployed through hotfixes, assuming the auto-installation setting is default. Remediation …
Read More »Oracle Patched 200 Vulns With July 2025 CPU
Oracle’s July 2025 Critical Patch Update includes 309 new security patches, with 127 addressing remotely exploitable vulnerabilities. SecurityWeek found about 200 unique CVEs in Oracle’s July 2025 CPU, with nine patches for critical flaws. In October, Oracle Communications issued 84 security patches, the highest this month, similar to April. Out …
Read More »Ivanti Zero-Days Exploited to Drop MDifyLoader
Cybersecurity researchers have revealed a new malware named MDifyLoader, linked to cyber attacks using security vulnerabilities in Ivanti Connect Secure (ICS) appliances. A JPCERT/CC report reveals that cybercriminals exploited CVE-2025-0282 and CVE-2025-22457 between December 2024 and July 2025 to deploy MDifyLoader, which facilitates Cobalt Strike attacks in memory. CVE-2025-0282 is …
Read More »CISA added Fortinet FortiWeb vul to KEV catalog
U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a crucial vulnerability in Fortinet FortiWeb in its Known Exploited Vulnerabilities (KEV) catalog, verifying that the SQL injection flaw is being actively exploited in cyberattacks across the globe. The vulnerability, tracked as CVE-2025-25257, affects Fortinet’s FortiWeb web application firewall and carries …
Read More »
CVE-2025-20337
Patch Now! Cisco ISE bug allows pre-auth command execution
A critical vulnerability in Cisco Identity Services Engine (ISE) and Cisco ISE-PIC, identified as CVE-2025-20337, has a CVSS score of 10, indicating its high severity. According to Cisco’s advisory, this vulnerability arises from “insufficient validation of user-supplied input” in a specific API. This means that an unauthenticated, remote attacker can …
Read More »Oracle Patched 309 Vulnerabilities with 145 Remotely Exploitable Flaw
Oracle’s July 2025 Critical Patch Update was released fixing 309 security vulnerabilities across its products. The update impacts 34 key product families. Oracle Communications has the most patches at 112 vulnerabilities, followed by MySQL with 40 and Oracle Fusion Middleware. 145 remote vulnerabilities could be exploited without authentication, allowing attackers …
Read More »4 vulns impact Gigabyte motherboards to UEFI malware bypassing Secure Boot
Four vulnerabilities in Gigabyte firmware were found by Binarly researchers and reported to Carnegie Mellon University’s CERT Coordination Center. The original firmware supplier, American Megatrends Inc. (AMI), fixed issues after being privately informed. However, some OEM firmware builds, like Gigabyte’s, did not implement the fixes initially. In Gigabyte firmware implementations, …
Read More »GitLab patched XSS and Authorization Bypass Flaws
GitLab has released security updates for its Community Edition (CE) and Enterprise Edition (EE) to fix vulnerabilities that could enable cross-site scripting (XSS) attacks and bypass group restrictions. CVE-2025-6948 is a critical cross-site scripting (XSS) vulnerability with a CVSS score of 8.7. It affects all versions prior to 17.11.6, 18.0.4, …
Read More »
InfoSecBulletin Cybersecurity for mankind