Sophos has released a security advisory addressing five vulnerabilities in Sophos Firewall, two of which are critical and could enable remote attackers to take control of affected devices in specific situations. The company confirms that fixes have been automatically deployed through hotfixes, assuming the auto-installation setting is default. Remediation …
Read More »(CVE-2025-6704, CVE-2025-7624)
Oracle Patched 200 Vulns With July 2025 CPU
Oracle’s July 2025 Critical Patch Update includes 309 new security patches, with 127 addressing remotely exploitable vulnerabilities. SecurityWeek found about 200 unique CVEs in Oracle’s July 2025 CPU, with nine patches for critical flaws. In October, Oracle Communications issued 84 security patches, the highest this month, similar to April. Out …
Read More »Ivanti Zero-Days Exploited to Drop MDifyLoader
Cybersecurity researchers have revealed a new malware named MDifyLoader, linked to cyber attacks using security vulnerabilities in Ivanti Connect Secure (ICS) appliances. A JPCERT/CC report reveals that cybercriminals exploited CVE-2025-0282 and CVE-2025-22457 between December 2024 and July 2025 to deploy MDifyLoader, which facilitates Cobalt Strike attacks in memory. CVE-2025-0282 is …
Read More »CISA added Fortinet FortiWeb vul to KEV catalog
U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a crucial vulnerability in Fortinet FortiWeb in its Known Exploited Vulnerabilities (KEV) catalog, verifying that the SQL injection flaw is being actively exploited in cyberattacks across the globe. The vulnerability, tracked as CVE-2025-25257, affects Fortinet’s FortiWeb web application firewall and carries …
Read More »
CVE-2025-20337
Patch Now! Cisco ISE bug allows pre-auth command execution
A critical vulnerability in Cisco Identity Services Engine (ISE) and Cisco ISE-PIC, identified as CVE-2025-20337, has a CVSS score of 10, indicating its high severity. According to Cisco’s advisory, this vulnerability arises from “insufficient validation of user-supplied input” in a specific API. This means that an unauthenticated, remote attacker can …
Read More »Oracle Patched 309 Vulnerabilities with 145 Remotely Exploitable Flaw
Oracle’s July 2025 Critical Patch Update was released fixing 309 security vulnerabilities across its products. The update impacts 34 key product families. Oracle Communications has the most patches at 112 vulnerabilities, followed by MySQL with 40 and Oracle Fusion Middleware. 145 remote vulnerabilities could be exploited without authentication, allowing attackers …
Read More »4 vulns impact Gigabyte motherboards to UEFI malware bypassing Secure Boot
Four vulnerabilities in Gigabyte firmware were found by Binarly researchers and reported to Carnegie Mellon University’s CERT Coordination Center. The original firmware supplier, American Megatrends Inc. (AMI), fixed issues after being privately informed. However, some OEM firmware builds, like Gigabyte’s, did not implement the fixes initially. In Gigabyte firmware implementations, …
Read More »GitLab patched XSS and Authorization Bypass Flaws
GitLab has released security updates for its Community Edition (CE) and Enterprise Edition (EE) to fix vulnerabilities that could enable cross-site scripting (XSS) attacks and bypass group restrictions. CVE-2025-6948 is a critical cross-site scripting (XSS) vulnerability with a CVSS score of 8.7. It affects all versions prior to 17.11.6, 18.0.4, …
Read More »Urgently patch now: Zoom Patches 6 Flaws
Zoom released a security update addressing six newly discovered vulnerabilities in its Workplace, Rooms, and SDK products for Windows, macOS, Linux, iOS, and Android. These issues could result in denial of service, information leaks, cross-site scripting, and integrity breaches. CVE-2025-46788 (CVSS 7.4): Improper Certificate Validation in Zoom for Linux CVE-2025-49464 …
Read More »Splunk Addresses Third-Party Package Vulns in SOAR Versions
Splunk has issued critical security updates for SOAR versions 6.4.0 and 6.4 to fix several vulnerabilities in third-party packages. The comprehensive security update published on July 7, 2025, fixes several Common Vulnerabilities and Exposures (CVEs) with severity levels from medium to critical. Critical vulnerabilities impact core components like git, Django, …
Read More »
InfoSecBulletin Cybersecurity for mankind