Security News

Juniper patches critical auth bypass in Session Smart routers
2025-02-18 17:07

​Juniper Networks has patched a critical vulnerability that allows attackers to bypass authentication and take over Session Smart Router (SSR) devices. [...]

Juniper Session Smart Routers Vulnerability Could Let Attackers Bypass Authentication
2025-02-18 12:18

Juniper Networks has released security updates to address a critical security flaw impacting Session Smart Router, Session Smart Conductor, and WAN Assurance Router products that could be...

Week in review: Microsoft fixes two actively exploited 0-days, PAN-OS auth bypass hole plugged
2025-02-16 09:00

Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Microsoft fixes two actively exploited zero-days (CVE-2025-21418, CVE-2025-21391) February 2025...

Hackers exploit authentication bypass in Palo Alto Networks PAN-OS
2025-02-14 21:20

Hackers are launching attacks against Palo Alto Networks PAN-OS firewalls by exploiting a recently fixed vulnerability (CVE-2025-0108) that allows bypassing authentication. [...]

Hackers Use CAPTCHA Trick on Webflow CDN PDFs to Bypass Security Scanners
2025-02-13 15:13

A widespread phishing campaign has been observed leveraging bogus PDF documents hosted on the Webflow content delivery network (CDN) with an aim to steal credit card information and commit...

PAN-OS authentication bypass hole plugged, PoC is public (CVE-2025-0108)
2025-02-13 11:03

Palo Alto Networks has fixed a high-severity authentication bypass vulnerability (CVE-2025-0108) in the management web interface of its next-gen firewalls, a proof-of-concept exploit (PoC) for...

Palo Alto Networks Patches Authentication Bypass Exploit in PAN-OS Software
2025-02-13 09:39

Palo Alto Networks has addressed a high-severity security flaw in its PAN-OS software that could result in an authentication bypass. The vulnerability, tracked as CVE-2025-0108, carries a CVSS...

Fortinet discloses second firewall auth bypass patched in January
2025-02-11 18:56

Fortinet has disclosed a second authentication bypass vulnerability that was fixed as part of a January 2025 update for FortiOS and FortiProxy devices. [...]

7-Zip MotW bypass exploited in zero-day attacks against Ukraine
2025-02-04 14:43

A 7-Zip vulnerability allowing attackers to bypass the Mark of the Web (MotW) Windows security feature was exploited by Russian hackers as a zero-day since September 2024. [...]

Russian Cybercrime Groups Exploiting 7-Zip Flaw to Bypass Windows MotW Protections
2025-02-04 12:28

A recently patched security vulnerability in the 7-Zip archiver tool was exploited in the wild to deliver the SmokeLoader malware. The flaw, CVE-2025-0411 (CVSS score: 7.0), allows remote...