Tuesday , March 4 2025

Recent Posts

CVE-2025-20029
PoC Exploit Released for F5 BIG-IP Command Injection Vuln

F5 BIG-IP

Security researchers have released a proof-of-concept exploit for CVE-2025-20029, a serious command injection vulnerability in F5’s BIG-IP application delivery controllers. The flaw has a CVSS v3.1 score of 8.8 and allows authenticated attackers to execute arbitrary system commands due to improper handling of special elements in the iControl REST API …

Read More »

By 1 April 2025
Australia Bans Kaspersky on its govt systems and devices

Kaspersky

On February 21, the Australian Department of Home Affairs issued a directive prohibiting the installation of Kaspersky Lab products and services on all Australian government systems and devices. The directive under the protective security policy framework (PSPF) mandates federal entities to eliminate “all instances” of Kaspersky’s products. Home Affairs secretary …

Read More »

CISA Flags Craft CMS Code Injection Flaw Amid Active Attacks

(CMS)

CISA has added a serious security flaw in the Craft content management system (CMS) to its Known Exploited Vulnerabilities catalog due to evidence of active exploitation. The vulnerability CVE-2025-23209 (CVSS score: 8.1) affects Craft CMS versions 4 and 5. It was fixed by the maintainers in late December 2024 with …

Read More »