Wednesday , June 24 2026

Recent Posts

Apple Patches Two Critical WebKit Zero-Days Under Active Exploitation

WebKit

Apple has urgently patched two critical zero-day vulnerabilities in the WebKit browser engine affecting iPhone and iPad users. The company revealed these flaws are actively exploited, enabling advanced attacks on high-risk targets. Vulnerabilities CVE-2025-43529 and CVE-2025-14174 let attackers run malicious code if a victim visits a specific web page. WebKit …

Read More »

20 Top Most Exploited Vulns of 2025

exploited

In 2025, many CVEs were exploited, averaging a CVSS severity rating of 8.5, with two hitting the maximum of 10.0, highlighting their critical importance. Most Exploited Vulnerabilities of 2025: CVE-2025-55182: React2Shell CVE-2025-32433: Erlang/OTP SSH Zero-Day Crisis CVE-2025-59287: Microsoft WSUS Deserialization Vulnerability CVE-2025-62221: Windows Cloud Files Driver Zero-Day CVE-2025-62215: Windows Kernel …

Read More »

Alert: CISA orders feds to patch actively exploited Geoserver flaw urgently

Geoserver

CISA has ordered U.S. federal agencies to fix a serious GeoServer vulnerability that is currently being exploited in XML External Entity (XXE) injection attacks. CISA reported a security flaw (CVE-2025-58360) on Thursday, an unauthenticated XML External Entity (XXE) vulnerability in GeoServer 2.26.1 and earlier versions. This open-source server for geospatial …

Read More »