Vulnerabilities Critical Erlang/OTP SSH Flaw Exposes Many Devices to Remote Hacking Servers exposed to complete takeover due to CVE-2025-32433, an unauthenticated remote code execution flaw in Erlang/OTP SSH. Eduard KovacsApril 17, 2025
Vulnerabilities SonicWall Flags Old Vulnerability as Actively Exploited A SonicWall SMA 100 series vulnerability patched in 2021, which went unnoticed at the time of patching, is being exploited in the wild. Eduard KovacsApril 17, 2025
Malware & Threats Apple Quashes Two Zero-Days With iOS, MacOS Patches The vulnerabilities are described as code execution and mitigation bypass issues that affect Apple’s iOS, iPadOS and macOS platforms. Ryan NaraineApril 16, 2025
Government MITRE CVE Program Gets Last-Hour Funding Reprieve The US government's cybersecurity agency CISA has “executed the option period on the contract” to keep the vulnerability catalog operational. Ryan NaraineApril 16, 2025
Vulnerabilities Critical Vulnerability Found in Apache Roller Blog Server A critical vulnerability in Apache Roller could be used to maintain persistent access by reusing older sessions even after password changes. Ionut ArghireApril 16, 2025
Vulnerabilities Chrome 135, Firefox 137 Updates Patch Severe Vulnerabilities Chrome 135 and Firefox 137 updates have been rolled out with patches for critical- and high-severity vulnerabilities. Ionut ArghireApril 16, 2025