Government CISA Updates Guidance on Patching Cisco Devices Targeted in China-Linked Attacks Federal agencies have reported as ‘patched’ ASA or FTD devices running software versions vulnerable to attacks. Ionut ArghireNovember 13, 2025
Vulnerabilities Critical WatchGuard Firebox Vulnerability Exploited in Attacks Tracked as CVE-2025-9242 (CVSS score of 9.3), the flaw leads to unauthenticated, remote code execution on vulnerable firewalls. Ionut ArghireNovember 13, 2025
Vulnerabilities Cisco ISE, CitrixBleed 2 Vulnerabilities Exploited as Zero-Days: Amazon Amazon has seen a threat actor exploiting CVE-2025-20337 and CVE-2025-5777, two critical Cisco and Citrix vulnerabilities, as zero-days. Ionut ArghireNovember 13, 2025
Vulnerabilities Microsoft Patches Actively Exploited Windows Kernel Zero-Day Microsoft’s latest Patch Tuesday updates address more than 60 vulnerabilities in Windows and other products. Eduard KovacsNovember 11, 2025
Vulnerabilities Critical Triofox Vulnerability Exploited in the Wild A threat actor has exploited the issue to create a new administrator account and then used the account to execute remote access tools. Ionut ArghireNovember 11, 2025
Malware & Threats Landfall Android Spyware Targeted Samsung Phones via Zero-Day Threat actors exploited CVE-2025-21042 to deliver malware via specially crafted images to users in the Middle East. Eduard KovacsNovember 7, 2025
Vulnerabilities Exploited ‘Post SMTP’ Plugin Flaw Exposes WordPress Sites to Takeover The critical vulnerability allows attackers to read arbitrary emails, including password reset messages. Ionut ArghireNovember 5, 2025
Vulnerabilities CISA Warns of CWP Vulnerability Exploited in the Wild A critical vulnerability in Control Web Panel (CWP), tracked as CVE-2025-48703, allows remote, unauthenticated command execution. Eduard KovacsNovember 5, 2025
Vulnerabilities CISA Adds Exploited XWiki, VMware Flaws to KEV Catalog Broadcom has updated its advisory on CVE-2025-41244 to mention the vulnerability’s in-the-wild exploitation. Ionut ArghireOctober 31, 2025
Malware & Threats Chinese APT Exploits Unpatched Windows Flaw in Recent Attacks The Windows shortcut vulnerability has been seen in attacks conducted by Mustang Panda to drop the PlugX malware. Ionut ArghireOctober 31, 2025
Malware & Threats XWiki Vulnerability Exploited in Cryptocurrency Mining Operation Exploits have been available publicly for over half a year, but the bug was previously targeted only for reconnaissance. Ionut ArghireOctober 29, 2025
ICS/OT CISA Warns of Exploited DELMIA Factory Software Vulnerabilities Two DELMIA Apriso flaws can be chained together to gain privileged access to the application and execute arbitrary code remotely. Ionut ArghireOctober 29, 2025
Vulnerabilities Year-Old WordPress Plugin Flaws Exploited to Hack Websites Roughly 9 million exploit attempts were observed this month as mass exploitation of the critical vulnerabilities recommenced. Ionut ArghireOctober 27, 2025
Vulnerabilities Chrome Zero-Day Exploitation Linked to Hacking Team Spyware The threat actor behind Operation ForumTroll used the same toolset typically employed in Dante spyware attacks. Ionut ArghireOctober 27, 2025
Vulnerabilities Critical Windows Server WSUS Vulnerability Exploited in the Wild CVE-2025-59287 allows a remote, unauthenticated attacker to execute arbitrary code and a PoC exploit is available. Eduard KovacsOctober 24, 2025
Vulnerabilities Exploitation of Critical Adobe Commerce Flaw Puts Many eCommerce Sites at Risk Patched in September, the SessionReaper bug could be exploited without authentication to bypass a security feature. Ionut ArghireOctober 23, 2025
Vulnerabilities Lanscope Endpoint Manager Zero-Day Exploited in the Wild The bug has been exploited in the wild as a zero-day and the US cybersecurity agency CISA has added it to its KEV catalog. Ionut ArghireOctober 23, 2025
Vulnerabilities CISA Warns of Exploited Apple, Kentico, Microsoft Vulnerabilities Leading to code execution, authentication bypass, and privilege escalation, the flaws were added to CISA’s KEV list. Ionut ArghireOctober 21, 2025
Vulnerabilities CISA Confirms Exploitation of Latest Oracle EBS Vulnerability The cybersecurity agency has added CVE-2025-61884 to its Known Exploited Vulnerabilities (KEV) catalog. Eduard KovacsOctober 21, 2025
Vulnerabilities Gladinet Patches Exploited CentreStack Vulnerability The unauthenticated local file inclusion bug allows attackers to retrieve the machine key and execute code remotely via a ViewState deserialization issue. Ionut ArghireOctober 17, 2025