Tuesday , August 25 2026
IBM

IMB unveils multiple vulnerabilities in it’s webMethods Integration

Multiple vulnerabilities have been published by IBM in its webMethods Integration Server which cloud allow attackers to execute arbitrary commands on affected systems.

Those published vulnerabilities have been identified in version 10.15 of the software which pose a severe risk for the organizations to integrate and API management.

Chameleon SEO Poisoning
Hackers poison Bing and Google search results to deliver phishing banking pages

Bank customers looking for a login page can now fall into a trap before getting a strange email or text....
Read More
Chameleon SEO Poisoning  Hackers poison Bing and Google search results to deliver phishing banking pages

Mysterious AI model “Ox Alpha” with free 100 trillion tokens a day for coders

A mysterious AI model dubbed "Ox Alpha" has surfaced online and created noise within the developer community after releasing on...
Read More
Mysterious AI model “Ox Alpha” with free 100 trillion tokens a day for coders

After BDJobs, Directorate of Secondary and Higher Education 390k data surfaced online

A group of hackers named “Madarax” claims they have stolen and are offering to sell the personal information of about...
Read More
After BDJobs, Directorate of Secondary and Higher Education 390k data surfaced online

Researchers show new technique to bypass AI safety guardrails in Grok and Gemini

A new hacking technique has been demonstrated to steal data from Elon Musk's Grok AI. It uses a simple trick...
Read More
Researchers show new technique to bypass AI safety guardrails in Grok and Gemini

About thousands of leaked AWS keys Held Full Admin Rights

More than 9,300 AWS access keys that were made public from August 2022 to August 2026 are still active, says...
Read More
About thousands of leaked AWS keys Held Full Admin Rights

US Bank investigates LockBit’s Data Breach Claims

US Bank is looking into LockBit's claims about a breach and stolen data. The ransomware group says they will share...
Read More
US Bank investigates LockBit’s Data Breach Claims

Five new malware families actively targeting Asian Gov.t infra

Central Asian government agencies have been attacked in a cyber spy operation that used a small but different range of...
Read More
Five new malware families actively targeting Asian Gov.t infra

T-Mobile Cuts Cables to Remove Chiness Salt Typhoon Hackers from Network

T-Mobile’s cybersecurity team reportedly physically cut a network cable connecting compromised infrastructure to the outside world. According to Bloomberg, the move...
Read More
T-Mobile Cuts Cables to Remove Chiness Salt Typhoon Hackers from Network

Splunk, Zyxel Patch Multiple Flaws Enabling RCE and Root Command Execution

Splunk has issued security fixes for 17 weaknesses in different apps and add-ons, such as Splunk MCP Server, Splunk AI...
Read More
Splunk, Zyxel Patch Multiple Flaws Enabling RCE and Root Command Execution

“Zombie Card” attack revels expired Visa card may be used for contactless payments

Security experts have shown that expired credit cards can still be used. A study from the University of Massachusetts Amherst,...
Read More
“Zombie Card” attack revels expired Visa card may be used for contactless payments

CVE-2024-45076 has been assigned as high severity scoring CVSS base score of 9.9 which allows an authenticated user to upload and execute arbitrary files on the underlying operating system.

The potential for exploitation is high, given the low complexity required to carry out an attack, and the lack of user interaction needed. The impact on confidentiality, integrity, and availability is rated as high, making it imperative for organizations to address this issue urgently.

CVE-2024-45075 which has a CVSS base score of 8.8 involves privilege escalation which allows An authenticated user could exploit this flaw to create scheduler tasks that escalate their privileges to an administrator level due to missing authentication checks.

CVE-2024-45074 which allows directory traversal attacks to enable an attacker viewing arbitrary files on the system, has a CVSS base score of 6.5 still poses a significant threat by potentially exposing sensitive information.

IBM released Corefix 14 for the Integration Server to install using the Update Manager to mitigate these vulnerabilities. No workarounds or mitigations are available.

These vulnerabilities highlight the ongoing challenges in securing complex integration platforms, which cyber attackers increasingly target due to their critical role in enterprise environments.

Organizations are urged to review their security posture and ensure that all systems are updated to protect against the potential exploitation of these vulnerabilities.

Check Also

Zoom Flaw

AI Finds Nation-State-Level Zoom Flaw in Under 24 Hours, Zero-Click Attack Exposed

A serious security flaw in Zoom might let a hacker take control of someone else’s …