Thursday , June 4 2026

Recent Posts

Cisco and SonicWall warn zero-day exploited in attacks

zero-day

Cisco warned customers maximum-severity Cisco AsyncOS zero-day actively exploited in attacks targeting Secure Email Gateway (SEG) and Secure Email and Web Manager (SEWM) appliances. This yet-to-be-patched zero-day (CVE-2025-20393) affects only Cisco SEG and Cisco SEWM appliances with non-standard configurations, when the Spam Quarantine feature is enabled and exposed on the …

Read More »

Hacker exploited Critical React2Shell flaw to deploy ransomware within a minute

React2Shell

A financially motivated ransomware gang exploited React2Shell vulnerability (CVE-2025-55182) to quickly access corporate networks and deploy malware less than a minute later. React2Shell (CVE-2025-55182) is a maximum severity vulnerability in React Server Components (RSC) which was publicly disclosed on 3 December 2025. The vulnerability impacts the Flight Protocol, a core …

Read More »

CISA added Actively Exploited Apple WebKit 0-Day Flow

zero-day

CISA has listed a critical zero-day vulnerability affecting various Apple products in its Known Exploited Vulnerabilities catalog, indicating it is being actively exploited. CVE-2025-43529 is a severe use-after-free vulnerability in WebKit, Apple’s rendering engine, affecting millions of users on iOS, iPadOS, macOS, and other Apple platforms. A use-after-free vulnerability (CWE-416) …

Read More »