Vulnerabilities Organizations Warned of Exploited Adobe AEM Forms Vulnerability A public PoC existed when Adobe patched the Experience Manager Forms (AEM Forms) bug in early August. Ionut ArghireOctober 16, 2025
Malware & Threats Cisco Routers Hacked for Rootkit Deployment Threat actors are exploiting CVE-2025-20352, a recent Cisco zero-day, to deploy a rootkit on older networking devices. Ionut ArghireOctober 16, 2025
Vulnerabilities Exploitation of Oracle EBS Zero-Day Started 2 Months Before Patching Hundreds of internet-exposed Oracle E-Business Suite instances may still be vulnerable to attacks. Eduard KovacsOctober 8, 2025
Vulnerabilities Fortra GoAnywhere MFT Zero-Day Exploited in Ransomware Attacks The Medusa ransomware operators exploited the GoAnywhere MFT vulnerability one week before patches were released. Ionut ArghireOctober 7, 2025
Data Breaches Oracle E-Business Suite Zero-Day Exploited in Cl0p Attacks Oracle has informed customers that it has patched a critical remote code execution vulnerability tracked as CVE-2025-61882. Eduard KovacsOctober 6, 2025
Vulnerabilities Organizations Warned of Exploited Meteobridge Vulnerability Patched in mid-May, the security defect allows remote unauthenticated attackers to execute arbitrary commands with root privileges. Ionut ArghireOctober 3, 2025
Vulnerabilities Broadcom Fails to Disclose Zero-Day Exploitation of VMware Vulnerability Impacting VMware Aria Operations and VMware Tools, the flaw can be exploited to elevate privileges on the VM. Ionut ArghireOctober 1, 2025
Vulnerabilities Organizations Warned of Exploited Sudo Vulnerability The vulnerability could allow local, low-privileged attackers to execute commands with root privileges, leading to full system compromise. Ionut ArghireSeptember 30, 2025
Vulnerabilities Recent Fortra GoAnywhere MFT Vulnerability Exploited as Zero-Day Eight days before patches, a threat actor exploited CVE-2025-10035 as a zero-day to create a backdoor admin account. Ionut ArghireSeptember 26, 2025
Vulnerabilities Cisco Firewall Zero-Days Exploited in China-Linked ArcaneDoor Attacks Leading to remote code execution and privilege escalation, the flaws were exploited on Cisco ASA 5500-X series devices that lack secure boot. Ionut ArghireSeptember 26, 2025
Network Security Cisco Patches Zero-Day Flaw Affecting Routers and Switches The security defect allows remote attackers with administrative privileges to execute arbitrary code as the root user. Ionut ArghireSeptember 25, 2025
Vulnerabilities GeoServer Flaw Exploited in US Federal Agency Hack The hackers remained undetected for three weeks, deploying China Chopper, remote access scripts, and reconnaissance tools. Ionut ArghireSeptember 24, 2025
Email Security Libraesva Email Security Gateway Vulnerability Exploited by Nation-State Hackers Tracked as CVE-2025-59689, the command injection bug could be triggered via malicious emails containing crafted compressed attachments. Ionut ArghireSeptember 24, 2025
Vulnerabilities SolarWinds Makes Third Attempt at Patching Exploited Vulnerability CVE-2025-26399 is a patch bypass of CVE-2024-28988, which is a patch bypass of the exploited CVE-2024-28986. Ionut ArghireSeptember 23, 2025
Malware & Threats CISA Analyzes Malware From Ivanti EPMM Intrusions Hackers chained two Ivanti EPMM vulnerabilities to collect system information, dump credentials, and execute malware. Ionut ArghireSeptember 19, 2025
Vulnerabilities Chrome 140 Update Patches Sixth Zero-Day of 2025 An exploited type confusion in the V8 JavaScript engine tracked as CVE-2025-10585 was found by Google Threat Analysis Group this week. Ionut ArghireSeptember 18, 2025
Mobile & Wireless Samsung Patches Zero-Day Exploited Against Android Users Reported by Meta and WhatsApp, the vulnerability leads to remote code execution and was likely exploited by a spyware vendor. Ionut ArghireSeptember 15, 2025
ICS/OT DELMIA Factory Software Vulnerability Exploited in Attacks A deserialization of untrusted data in the MOM software allows attackers to achieve remote code execution. Ionut ArghireSeptember 12, 2025
Ransomware Akira Ransomware Attacks Fuel Uptick in Exploitation of SonicWall Flaw The Akira ransomware group is likely exploiting a combination of three attack vectors to gain unauthorized access to vulnerable appliances. Ionut ArghireSeptember 11, 2025
Vulnerabilities Recent SAP S/4HANA Vulnerability Exploited in Attacks A critical SAP S/4HANA code injection flaw tracked as CVE-2025-42957 and allowing full system takeover has been exploited in the wild. Eduard KovacsSeptember 5, 2025