Security News

Attackers exploited old flaws to breach SonicWall SMA appliances (CVE-2024-38475, CVE-2023-44221)
2025-05-02 13:16

Attackers have been using two previously known vulnerabilities (CVE-2024-38475, CVE-2023-44221) to compromise SonicWall secure mobile access devices, the vendor has confirmed by updating the...

How to Automate CVE and Vulnerability Advisory Response with Tines
2025-05-02 10:30

Run by the team at workflow orchestration and AI platform Tines, the Tines library features pre-built workflows shared by security practitioners from across the community - all free to import and...

Commvault Confirms Hackers Exploited CVE-2025-3928 as Zero-Day in Azure Breach
2025-05-01 08:11

Enterprise data backup platform Commvault has revealed that an unknown nation-state threat actor breached its Microsoft Azure environment by exploiting CVE-2025-3928 but emphasized there is no...

⚡ Weekly Recap: Critical SAP Exploit, AI-Powered Phishing, Major Breaches, New CVEs & More
2025-04-28 12:18

What happens when cybercriminals no longer need deep skills to breach your defenses? Today’s attackers are armed with powerful tools that do the heavy lifting — from AI-powered phishing kits to...

Critical SAP NetWeaver flaw exploited by suspected initial access broker (CVE-2025-31324)
2025-04-28 09:47

CVE-2025-31324, a critical vulnerability in the SAP NetWeaver platform, is being actively exploited by attackers to upload malicious webshells to enable unauthorized file uploads and code...

Amid CVE funding fumble, 'we were mushrooms, kept in the dark,' says board member
2025-04-25 22:19

What next for US-bankrolled vulnerability tracker? It's edging closer to a more independent, global future Kent Landfield, a founding member of the Common Vulnerabilities and Exposures (CVE)...

Rack Ruby vulnerability could reveal secrets to attackers (CVE-2025-27610)
2025-04-25 09:26

Researchers have uncovered three serious vulnerabilities in Rack, a server interface used by most Ruby web app frameworks (Ruby on Rails, Sinatra, Hanami, Roda, and others). Two of the flaws –...

DslogdRAT Malware Deployed via Ivanti ICS Zero-Day CVE-2025-0282 in Japan Attacks
2025-04-25 08:43

Cybersecurity researchers are warning about a new malware called DslogdRAT that's installed following the exploitation of a now-patched security flaw in Ivanti Connect Secure (ICS). The malware,...

159 CVEs Exploited in Q1 2025 — 28.3% Within 24 Hours of Disclosure
2025-04-24 12:58

As many as 159 CVE identifiers have been flagged as exploited in the wild in the first quarter of 2025, up from 151 in Q4 2024. "We continue to see vulnerabilities being exploited at a fast pace...

Critical Commvault RCE vulnerability fixed, PoC available (CVE-2025-34028)
2025-04-24 12:05

If your organization is using Commvault Command Center for your data protection, backup creation, configuration and restoration needs, you should check whether your on-premise installation has...