Security News

'Ongoing' Ivanti hijack bug exploitation reaches clouds
2025-05-21 01:27

Nothing like insecure code in security suites The "ongoing exploitation" of two Ivanti bugs has now extended beyond on-premises environments and hit customers' cloud instances, according to...

AWS Default IAM Roles Found to Enable Lateral Movement and Cross-Service Exploitation
2025-05-20 12:42

Cybersecurity researchers have discovered risky default identity and access management (IAM) roles impacting Amazon Web Services that could open the door for attackers to escalate privileges,...

Ransomware gangs increasingly use Skitnet post-exploitation malware
2025-05-16 14:00

Ransomware gang members increasingly use a new malware called Skitnet ("Bossnet") to perform stealthy post-exploitation activities on breached networks. [...]

Critical Langflow Flaw Added to CISA KEV List Amid Ongoing Exploitation Evidence
2025-05-06 04:24

A recently disclosed critical security flaw impacting the open-source Langflow platform has been added to the Known Exploited Vulnerabilities (KEV) catalog by the U.S. Cybersecurity and...

Commvault CVE-2025-34028 Added to CISA KEV After Active Exploitation Confirmed
2025-05-05 16:01

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a maximum-severity security flaw impacting Commvault Command Center to its Known Exploited Vulnerabilities (KEV) catalog,...

SonicWall Confirms Active Exploitation of Flaws Affecting Multiple Appliance Models
2025-05-01 06:22

SonicWall has revealed that two now-patched security flaws impacting its SMA100 Secure Mobile Access (SMA) appliances have been exploited in the wild. The vulnerabilities in question are listed...

Gladinet’s Triofox and CentreStack Under Active Exploitation via Critical RCE Vulnerability
2025-04-15 04:39

A recently disclosed security flaw in Gladinet CentreStack also impacts its Triofox remote access and collaboration solution, according to Huntress, with seven different organizations compromised...

OttoKit WordPress Plugin Admin Creation Vulnerability Under Active Exploitation
2025-04-11 04:58

A newly disclosed high-severity security flaw impacting OttoKit (formerly SureTriggers) has come under active exploitation within a few hours of public disclosure. The vulnerability, tracked as...

New Mirai botnet behind surge in TVT DVR exploitation
2025-04-08 15:33

A significant spike in exploitation attempts targeting TVT NVMS9000 DVRs has been detected, peaking on April 3, 2025, with over 2,500 unique IPs scanning for vulnerable devices. [...]

CISA Adds CrushFTP Vulnerability to KEV Catalog Following Confirmed Active Exploitation
2025-04-08 08:11

A recently disclosed critical security flaw impacting CrushFTP has been added by the U.S. Cybersecurity and Infrastructure Security Agency (CISA) to its Known Exploited Vulnerabilities (KEV)...