New Mirai botnet infect TBK DVR devices via command injection flaw
New Mirai botnet infect TBK DVR devices via command injection flaw

New Mirai botnet infect TBK DVR devices via command injection flaw

2025-06-08 14:17

A new variant of the Mirai malware botnet is exploiting a command injection vulnerability in TBK...

New Supply Chain Malware Operation Hits npm and PyPI Ecosystems, Targeting Millions Globally

New Supply Chain Malware Operation Hits npm and PyPI Ecosystems, Targeting Millions Globally

2025-06-08 13:47

Cybersecurity researchers have flagged a supply chain attack targeting over a dozen packages...

Enterprises are getting stuck in AI pilot hell, say Chatterbox Labs execs

Enterprises are getting stuck in AI pilot hell, say Chatterbox Labs execs

2025-06-08 13:00

Security, not model performance, is what's stalling adoption Interview Before AI becomes...

#AI
Malicious Browser Extensions Infect Over 700 Users Across Latin America Since Early 2025

Malicious Browser Extensions Infect Over 700 Users Across Latin America Since Early 2025

2025-06-08 08:01

Cybersecurity researchers have shed light on a new campaign targeting Brazilian users since the...

Week in review: Google fixes exploited Chrome zero-day, Patch Tuesday forecast

Week in review: Google fixes exploited Chrome zero-day, Patch Tuesday forecast

2025-06-08 08:00

Here’s an overview of some of last week’s most interesting news, articles, interviews and...

Malware found in NPM packages with 1 million weekly downloads

Malware found in NPM packages with 1 million weekly downloads

2025-06-07 19:31

A significant supply chain attack hit NPM after 15 popular Gluestack packages with over 950,000...

Malicious npm packages posing as utilities delete project directories

Malicious npm packages posing as utilities delete project directories

2025-06-07 14:11

Two malicious packages have been discovered in the npm JavaScript package index, which...

Vulnerabilities by Risk level (Last 12 months)

Risk level Last 12 months #
Critical 2980
High 7245
Medium 10715
Low 467

Vulnerabilities by Vendor (Last 12 months)

Vendor Last 12 months #
Linux 2658
Adobe 615
Microsoft 593
Google 473
Apple 464

Latest Vulnerabilities

  • CVE-2025-5839

    8.8

    A vulnerability, which was classified as critical, has been found in Tenda AC9 15.03.02.13. Affected by this issue is the function fromadvsetlanip of the file /goform/AdvSetLanip of the component...

    network
    low complexity
    CWE-120
  • CVE-2025-5840

    7.3

    A vulnerability, which was classified as critical, was found in SourceCodester Client Database Management System 1.0. This affects an unknown part of the file /user_update_customer_order.php. The...

    network
    low complexity
    CWE-434
  • CVE-2025-5838

    6.3

    A vulnerability classified as critical was found in PHPGurukul Employee Record Management System 1.3. Affected by this vulnerability is an unknown functionality of the file...

    network
    low complexity
    CWE-74
  • CVE-2025-5836

    6.3

    A vulnerability was found in Tenda AC9 15.03.02.13. It has been rated as critical. This issue affects the function formSetIptv of the file /goform/SetIPTVCfg of the component POST Request Handler....

    network
    low complexity
    CWE-74
  • CVE-2025-5837

    6.3

    A vulnerability classified as critical has been found in PHPGurukul Employee Record Management System 1.3. Affected is an unknown function of the file /admin/allemployees.php. The manipulation of...

    network
    low complexity
    CWE-74

Latest Critical Vulnerabilities