Thursday , June 4 2026

Recent Posts

Splunk Fixes Six Flaws, Including SSRF and XSS Vulns in Enterprise Platform

Splunk i

Splunk issued security advisories for six vulnerabilities in Splunk Enterprise and Splunk Cloud Platform, with severity levels from medium to high. The issues include improper access control, various cross-site scripting (XSS) types, XML external entity (XXE) injection, denial-of-service (DoS) via LDAP misuse, and a high-severity server-side request forgery (SSRF). CVE-2025-20366 …

Read More »

50K Cisco firewalls vulnerable to actively exploited flaws

admin

50k Cisco ASA and FTD devices on the internet are at risk due to two vulnerabilities being exploited by hackers. Flaws CVE-2025-20333 and CVE-2025-20362 allow remote code execution and access to restricted VPN URLs without authentication. On September 25, Cisco warned that the issues were actively exploited in attacks that …

Read More »

Hackers Exploiting New VMware Zero-Day Since October 2024

October 2024

A newly patched security flaw in Broadcom VMware Tools and VMware Aria Operations has been exploited by a threat actor named UNC5174 since mid-October 2024, according to NVISO Labs. The vulnerability identified as CVE-2025-41244 (CVSS score: 7.8) is a flaw that allows local privilege escalation, impacting the following versions – …

Read More »