Zoom released a security update addressing six newly discovered vulnerabilities in its Workplace, Rooms, and SDK products for Windows, macOS, Linux, iOS, and Android. These issues could result in denial of service, information leaks, cross-site scripting, and integrity breaches. CVE-2025-46788 (CVSS 7.4): Improper Certificate Validation in Zoom for Linux CVE-2025-49464 …
Read More »Splunk Addresses Third-Party Package Vulns in SOAR Versions
Splunk has issued critical security updates for SOAR versions 6.4.0 and 6.4 to fix several vulnerabilities in third-party packages. The comprehensive security update published on July 7, 2025, fixes several Common Vulnerabilities and Exposures (CVEs) with severity levels from medium to critical. Critical vulnerabilities impact core components like git, Django, …
Read More »
CVE-2025-25257
Fortinet Addresses Major SQL Injection Flaw in FortiWeb
Fortinet has issued a critical patch for a critical vulnerability in its FortiWeb product, a web application firewall commonly used in enterprises. Identified as CVE-2025-25257, this high-severity issue is an unauthenticated SQL injection flaw that lets remote attackers run unauthorized SQL commands through specially crafted HTTP or HTTPS requests. “An …
Read More »Microsoft July 2025 Patch Tuesday: One zero-day, 137 flaws
Microsoft’s Patch Tuesday in July 2025 is critical, featuring updates for 137 vulnerabilities, including a zero-day in Microsoft SQL Server. The extensive nature of these updates brings relief to defenders and anxiety to users needing to secure their operations. This analysis emphasizes key points, the associated risks, and the implications …
Read More »CISA Adds Four Critical Active Exploiting Vulns to KEV
CISA added four security flaws to its Known Exploited Vulnerabilities (KEV) catalog on Monday due to evidence of active exploitation. The list of flaws is as follows: CVE-2014-3931 (CVSS score: 9.8) A buffer overflow vulnerability in Multi-Router Looking Glass (MRLG) that could allow remote attackers to cause an arbitrary memory …
Read More »IBM X-Force Reveals Azure Arc Flaws
IBM X-Force has analyzed Microsoft Azure Arc, revealing how this hybrid-cloud management tool can pose risks for code execution, privilege escalation, and stealthy persistence. This study began when IBM’s red team found a hardcoded Azure Service Principal secret in a PowerShell script, prompting a closer look at Azure Arc’s operations …
Read More »Critical RCE Flaws in Cisco ISE and ISE-PIC Allow to Gain Root Access
Cisco has issued updates to fix two critical security vulnerabilities in Identity Services Engine (ISE) and ISE Passive Identity Connector (ISE-PIC) that could allow unauthorized users to run commands as the root user. The vulnerabilities CVE-2025-20281 and CVE-2025-20282 both have a CVSS score of 10.0. CVE-2025-20281: An unauthenticated remote code execution …
Read More »Citrix Released Emergency Patches for Actively Exploited CVE-2025-6543
Citrix has issued security updates for a critical vulnerability in NetScaler ADC that has been actively exploited. The vulnerability CVE-2025-6543 has a CVSS score of 9.2, indicating high severity. It’s a memory overflow issue that may cause control flow errors and denial-of-service. To exploit it, the appliance must be set …
Read More »Hacker Target 70+ Microsoft Exchange Servers to Steal Credentials with Keyloggers
Unidentified hackers are targeting exposed Microsoft Exchange servers to inject harmful code into login pages and steal credentials. Positive Technologies published an analysis last week revealing two types of JavaScript keylogger code on the Outlook login page. Those that save collected data to a local file accessible over the internet …
Read More »
ALERT (CVE: 2023-28771)
Zyxel Firewalls Under Attack via CVE-2023-28771 by 244 IPs
GreyNoise found attempts to exploit CVE-2023-28771, a vulnerability in Zyxel’s IKE affecting UDP port 500. The attack centers around CVE-2023-28771, a high-severity remote code execution vulnerability (CVSS 9.8) affecting Zyxel Internet Key Exchange (IKE) packet decoders over UDP port 500. Exploitation attempts against CVE-2023-28771 were minimal throughout recent weeks. On …
Read More »
InfoSecBulletin Cybersecurity for mankind