Vulnerabilities Critical Next.js Vulnerability in Hacker Crosshairs Threat actors have started probing servers impacted by a critical-severity vulnerability in the web application development framework Next.js. Ionut ArghireMarch 26, 2025
Network Security Vulnerability Exploitation Possibly Behind Widespread DrayTek Router Reboots DrayTek routers around the world are rebooting and the vendor’s statement suggests that it may involve the exploitation of a vulnerability. Eduard KovacsMarch 25, 2025
Vulnerabilities CISA Warns of Exploited Nakivo Vulnerability CISA has added an absolute path traversal bug in Nakivo Backup and Replication to its Known Exploited Vulnerabilities list. Ionut ArghireMarch 20, 2025
Vulnerabilities Hackers Target Cisco Smart Licensing Utility Vulnerabilities SANS is seeing attempts to exploit two critical Cisco Smart Licensing Utility vulnerabilities tracked as CVE-2024-20439 and CVE-2024-20440. Eduard KovacsMarch 20, 2025
Mobile & Wireless Paragon Spyware Attacks Exploited WhatsApp Zero-Day Attacks involving Paragon’s Graphite spyware involved a WhatsApp zero-day that could be exploited without any user interaction. Eduard KovacsMarch 20, 2025
Artificial Intelligence ChatGPT Tool Vulnerability Exploited Against US Government Organizations A year-old vulnerability in a third-party ChatGPT tool is being exploited against financial entities and US government organizations. Ionut ArghireMarch 18, 2025
Malware & Threats Unpatched Edimax Camera Flaw Exploited Since at Least May 2024 A recently disclosed Edimax zero-day vulnerability has been exploited in the wild by Mirai botnets for nearly a year. Eduard KovacsMarch 13, 2025
Malware & Threats Grafana Flaws Likely Targeted in Broad SSRF Exploitation Campaign Threat actors are likely targeting Grafana path traversal bugs for reconnaissance in a SSRF exploitation campaign targeting popular platforms. Ionut ArghireMarch 13, 2025
Vulnerabilities Newly Patched Windows Zero-Day Exploited for Two Years Microsoft on Tuesday patched a zero-day vulnerability in the Windows Win32 kernel that has been exploited since March 2023. Ionut ArghireMarch 12, 2025
IoT Security Edimax Says No Patches Coming for Zero-Day Exploited by Botnets Edimax is aware that CVE-2025-1316 has been exploited in the wild, but the impacted devices were discontinued over a decade ago. Eduard KovacsMarch 11, 2025
Vulnerabilities CISA Warns of Ivanti EPM Vulnerability Exploitation CISA has added three critical-severity flaws in Ivanti EPM to its Known Exploited Vulnerabilities catalog. Ionut ArghireMarch 11, 2025
Malware & Threats Critical PHP Vulnerability Under Mass Exploitation GreyNoise warns of mass exploitation of a critical vulnerability in PHP leading to remote code execution on vulnerable servers. Ionut ArghireMarch 10, 2025
IoT Security Edimax Camera Zero-Day Disclosed by CISA Exploited by Botnets Multiple Mirai-based botnets are exploiting CVE-2025-1316, an Edimax IP camera vulnerability that allows remote command execution. Eduard KovacsMarch 7, 2025
Vulnerabilities Exploited VMware ESXi Flaws Put Many at Risk of Ransomware, Other Attacks Scans show that tens of thousands of VMware ESXi instances are affected by CVE-2025-22224 and other vulnerabilities disclosed recently as zero-days. Eduard KovacsMarch 6, 2025
Vulnerabilities Broadcom Patches 3 VMware Zero-Days Exploited in the Wild Broadcom patched VMware zero-days CVE-2025-22224, CVE-2025-22225 and CVE-2025-22226 after Microsoft warned it of exploitation. Eduard KovacsMarch 4, 2025
Mobile & Wireless Google Patches Pair of Exploited Vulnerabilities in Android Android’s March 2025 security update addresses over 40 vulnerabilities, including two actively exploited in the wild. Ionut ArghireMarch 4, 2025
Vulnerabilities Exploitation Long Known for Most of CISA’s Latest KEV Additions Exploitation has been known for months or years for most of the latest vulnerabilities added by CISA to its KEV catalog. Eduard KovacsMarch 4, 2025
Vulnerabilities Sites of Major Orgs Abused in Spam Campaign Exploiting Virtual Tour Software Flaw XSS vulnerability allowed a threat actor to redirect users to arbitrary domains. Eduard KovacsFebruary 27, 2025
Vulnerabilities CISA Warns of Attacks Exploiting Oracle Agile PLM Vulnerability CISA has added CVE-2024-20953, an Oracle Agile PLM vulnerability patched in January 2024, to its KEV catalog. Eduard KovacsFebruary 25, 2025
Vulnerabilities CISA Warns of Attacks Exploiting Craft CMS Vulnerability CISA has added a Craft CMS flaw tracked as CVE-2025-23209 to its Known Exploited Vulnerabilities (KEV) catalog. Eduard KovacsFebruary 21, 2025