Malware & Threats SimpleHelp Vulnerability Exploited Against Utility Billing Software Users CISA warns that vulnerable SimpleHelp RMM instances have been exploited against a utility billing software provider’s customers. Ionut ArghireJune 13, 2025
Email Security Exploited Vulnerability Impacts Over 80,000 Roundcube Servers Exploitation of a critical-severity RCE vulnerability in Roundcube started only days after a patch was released. Ionut ArghireJune 10, 2025
Malware & Threats Mirai Botnets Exploiting Wazuh Security Platform Vulnerability CVE-2025-24016, a critical remote code execution vulnerability affecting Wazuh servers, has been exploited by Mirai botnets. Eduard KovacsJune 9, 2025
Vulnerabilities vBulletin Vulnerability Exploited in the Wild Exploitation of the vBulletin vulnerability tracked as CVE-2025-48827 and CVE-2025-48828 started shortly after disclosure. Eduard KovacsJune 2, 2025
Malware & Threats Companies Warned of Commvault Vulnerability Exploitation CISA warns companies of a widespread campaign targeting a Commvault vulnerability to hack Azure environments. Ionut ArghireMay 23, 2025
Malware & Threats Cityworks Zero-Day Exploited by Chinese Hackers in US Local Government Attacks A Chinese threat actor exploited a zero-day vulnerability in Trimble Cityworks to hack local government entities in the US. Ionut ArghireMay 23, 2025
Malware & Threats Chinese Spies Exploit Ivanti Vulnerabilities Against Critical Sectors A Chinese espionage group has been chaining two recent Ivanti EPMM vulnerabilities in attacks against organizations in multiple critical sectors. Ionut ArghireMay 23, 2025
Vulnerabilities Wiz Warns of Ongoing Exploitation of Recent Ivanti Vulnerabilities Wiz warns that threat actors are chaining two recent Ivanti vulnerabilities to achieve unauthenticated remote code execution. Ionut ArghireMay 21, 2025
Malware & Threats Ransomware Groups, Chinese APTs Exploit Recent SAP NetWeaver Flaws Two ransomware groups and several Chinese APTs have been exploiting two recent SAP NetWeaver vulnerabilities. Ionut ArghireMay 15, 2025
Vulnerabilities Chrome 136 Update Patches Vulnerability With ‘Exploit in the Wild’ Google has rolled out a Chrome 136 update that resolves a high-severity vulnerability for which a public exploit exists. Ionut ArghireMay 15, 2025
Vulnerabilities Fortinet Patches Zero-Day Exploited Against FortiVoice Appliances Fortinet has patched a dozen vulnerabilities, including a critical flaw exploited in the wild against FortiVoice instances. Ionut ArghireMay 14, 2025
Vulnerabilities Ivanti Patches Two EPMM Zero-Days Exploited to Hack Customers Ivanti has released patches for two EPMM vulnerabilities that have been chained in the wild for remote code execution. Ionut ArghireMay 14, 2025
Nation-State Output Messenger Zero-Day Exploited by Turkish Hackers for Iraq Spying A Turkey-affiliated espionage group has exploited a zero-day vulnerability in Output Messenger since April 2024. Ionut ArghireMay 13, 2025
Vulnerabilities SAP Zero-Day Targeted Since January, Many Sectors Impacted Hundreds of SAP NetWeaver instances hacked via a zero-day that allows remote code execution, not only arbitrary file uploads, as initially believed. Ionut ArghireMay 9, 2025
Vulnerabilities Possible Zero-Day Patched in SonicWall SMA Appliances SonicWall patches three SMA 100 vulnerabilities, including a potential zero-day, that could be chained to execute arbitrary code remotely. Ionut ArghireMay 8, 2025
Vulnerabilities Improperly Patched Samsung MagicINFO Vulnerability Exploited by Botnet The patches for an exploited Samsung MagicINFO vulnerability are ineffective and a Mirai botnet has started targeting it. Ionut ArghireMay 8, 2025
Ransomware Second Ransomware Group Caught Exploiting Windows Flaw as Zero-Day At least two ransomware groups exploited the Windows zero-day CVE-2025-29824 before it was patched by Microsoft. Eduard KovacsMay 7, 2025
Vulnerabilities Second OttoKit Vulnerability Exploited to Hack WordPress Sites Threat actors are targeting a critical-severity vulnerability in the OttoKit WordPress plugin to gain administrative privileges. Ionut ArghireMay 7, 2025
Vulnerabilities Second Wave of Attacks Hitting SAP NetWeaver After Zero-Day Compromise Threat actors are revisiting SAP NetWeaver instances to leverage webshells deployed via a recent zero-day vulnerability. Ionut ArghireMay 6, 2025
IoT Security Samsung MagicINFO Vulnerability Exploited Days After PoC Publication Threat actors started exploiting a vulnerability in Samsung MagicINFO only days after a PoC exploit was published. Ionut ArghireMay 6, 2025