Security News

Unpatched PHP Voyager Flaws Leave Servers Open to One-Click RCE Exploits
2025-01-30 07:21

Three security flaws have been disclosed in the open-source PHP package Voyager that could be exploited by an attacker to achieve one-click remote code execution on affected instances. "When an...

New Aquabot Botnet Exploits CVE-2024-41710 in Mitel Phones for DDoS Attacks
2025-01-30 06:41

A Mirai botnet variant dubbed Aquabot has been observed actively attempting to exploit a medium-severity security flaw impacting Mitel phones in order to ensnare them into a network capable of...

Hackers exploit critical unpatched flaw in Zyxel CPE devices
2025-01-29 14:42

Hackers are exploiting a critical command injection vulnerability in Zyxel CPE Series devices that is currently tracked as CVE-2024-40891 and remains unpatched since last July. [...]

New SLAP & FLOP Attacks Expose Apple M-Series Chips to Speculative Execution Exploits
2025-01-29 10:49

A team of security researchers from Georgia Institute of Technology and Ruhr University Bochum has demonstrated two new side-channel attacks targeting Apple silicon that could be exploited to leak...

Clone2Leak attacks exploit Git flaws to steal credentials
2025-01-27 16:36

A set of three distinct but related attacks, dubbed 'Clone2Leak,' can leak credentials by exploiting how Git and its credential helpers handle authentication requests. [...]

Palo Alto Firewalls Found Vulnerable to Secure Boot Bypass and Firmware Exploits
2025-01-23 15:13

An exhaustive evaluation of three firewall models from Palo Alto Networks has uncovered a host of known security flaws impacting the devices' firmware as well as misconfigured security features....

Cisco warns of denial of service flaw with PoC exploit code
2025-01-22 18:47

Cisco has released security updates to patch a ClamAV denial-of-service (DoS) vulnerability, which has proof-of-concept (PoC) exploit code. [...]

Hackers exploit 16 zero-days on first day of Pwn2Own Automotive 2025
2025-01-22 14:38

On the first day of Pwn2Own Automotive 2025, security researchers exploited 16 unique zero-days and collected $382,750 in cash awards. [...]

Hackers Exploit Zero-Day in cnPilot Routers to Deploy AIRASHI DDoS Botnet
2025-01-22 13:53

Threat actors are exploiting an unspecified zero-day vulnerability in Cambium Networks cnPilot routers to deploy a variant of the AISURU botnet called AIRASHI to carry out distributed...

Mirai Variant Murdoc_Botnet Exploits AVTECH IP Cameras and Huawei Routers
2025-01-21 14:00

Cybersecurity researchers have warned of a new large-scale campaign that exploits security flaws in AVTECH IP cameras and Huawei HG532 routers to rope the devices into a Mirai botnet variant...