Security News

U.S. Govt. Funding for MITRE's CVE Ends April 16, Cybersecurity Community on Alert
2025-04-16 05:06

The U.S. government funding for non-profit research giant MITRE to operate and maintain its Common Vulnerabilities and Exposures (CVE) program will expire Wednesday, an unprecedented development...

Uncle Sam kills funding for CVE program. Yes, that CVE program
2025-04-16 00:00

Because vulnerability management has nothing to do with national security, right? Updated US government funding for the world's CVE program – the centralized Common Vulnerabilities and Exposures...

Incomplete Patch in NVIDIA Toolkit Leaves CVE-2024-0132 Open to Container Escapes
2025-04-10 14:13

Cybersecurity researchers have detailed a case of an incomplete patch for a previously addressed security flaw impacting the NVIDIA Container Toolkit that, if successfully exploited, could put...

FortiSwitch vulnerability may give attackers control over vulnerable devices (CVE-2024-48887)
2025-04-10 10:09

Fortinet has released patches for flaws affecting many of its products, among them a critical vulnerability (CVE-2024-48887) in its FortiSwitch appliances that could allow unauthenticated...

WhatsApp vulnerability could be used to infect Windows users with malware (CVE-2025-30401)
2025-04-09 12:51

WhatsApp users are urged to update the Windows client app to plug a serious security vulnerability (CVE-2025-30401) that may allow attackers to trick users into running malicious code. Meta...

RCE flaw in MSP-friendly file sharing platform exploited by attackers (CVE-2025-30406)
2025-04-09 10:37

A critical RCE vulnerability (CVE-2025-30406) affecting the Gladinet CentreStack file-sharing/remote access platform has been added to CISA’s Known Exploited Vulnerabilities catalog on Tuesday....

Microsoft fixes actively exploited Windows CLFS zero-day (CVE-2025-29824)
2025-04-08 19:13

April 2025 Patch Tuesday is here, and Microsoft has delivered fixes for 120+ vulnerabilities, including a zero-day (CVE-2025-29824) that’s under active attack. CVE-2025-29824 CVE-2025-29824 is a...

WinRAR MotW bypass flaw fixed, update ASAP (CVE-2025-31334)
2025-04-07 11:28

WinRAR users, upgrade your software as soon as possible: a vulnerability (CVE-2025-31334) that could allow attackers to bypass Windows’ Mark of the Web (MotW) security warning and execute...

Ivanti VPN customers targeted via unrecognized RCE vulnerability (CVE-2025-22457)
2025-04-03 17:52

A suspected Chinese APT group has exploited CVE-2025-22457 – a buffer overflow bug that was previously thought not to be exploitable – to compromise appliances running Ivanti Connect Secure (ICS)...

Attackers are leveraging Cisco Smart Licensing Utility static admin credentials (CVE-2024-20439)
2025-04-03 13:04

CVE-2024-20439, a static credential vulnerability in the Cisco Smart Licensing Utility, is being exploited by attackers in the wild, CISA has confirmed on Monday by adding the flaw to its Known...