Security News

Critical Langflow Flaw Added to CISA KEV List Amid Ongoing Exploitation Evidence
2025-05-06 04:24

A recently disclosed critical security flaw impacting the open-source Langflow platform has been added to the Known Exploited Vulnerabilities (KEV) catalog by the U.S. Cybersecurity and...

Commvault CVE-2025-34028 Added to CISA KEV After Active Exploitation Confirmed
2025-05-05 16:01

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a maximum-severity security flaw impacting Commvault Command Center to its Known Exploited Vulnerabilities (KEV) catalog,...

SonicWall Confirms Active Exploitation of Flaws Affecting Multiple Appliance Models
2025-05-01 06:22

SonicWall has revealed that two now-patched security flaws impacting its SMA100 Secure Mobile Access (SMA) appliances have been exploited in the wild. The vulnerabilities in question are listed...

Gladinet’s Triofox and CentreStack Under Active Exploitation via Critical RCE Vulnerability
2025-04-15 04:39

A recently disclosed security flaw in Gladinet CentreStack also impacts its Triofox remote access and collaboration solution, according to Huntress, with seven different organizations compromised...

OttoKit WordPress Plugin Admin Creation Vulnerability Under Active Exploitation
2025-04-11 04:58

A newly disclosed high-severity security flaw impacting OttoKit (formerly SureTriggers) has come under active exploitation within a few hours of public disclosure. The vulnerability, tracked as...

New Mirai botnet behind surge in TVT DVR exploitation
2025-04-08 15:33

A significant spike in exploitation attempts targeting TVT NVMS9000 DVRs has been detected, peaking on April 3, 2025, with over 2,500 unique IPs scanning for vulnerable devices. [...]

CISA Adds CrushFTP Vulnerability to KEV Catalog Following Confirmed Active Exploitation
2025-04-08 08:11

A recently disclosed critical security flaw impacting CrushFTP has been added by the U.S. Cybersecurity and Infrastructure Security Agency (CISA) to its Known Exploited Vulnerabilities (KEV)...

Police shuts down KidFlix child sexual exploitation platform
2025-04-02 14:05

Kidflix, one of the largest platforms used to host, share, and stream child sexual abuse material (CSAM) on the dark web, was shut down on March 11 following a joint action coordinated by German...

CISA Adds NAKIVO Vulnerability to KEV Catalog Amid Active Exploitation
2025-03-20 09:43

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a high-severity security flaw impacting NAKIVO Backup & Replication software to its Known Exploited Vulnerabilities (KEV)...

CISA Warns of Active Exploitation in GitHub Action Supply Chain Compromise
2025-03-19 05:05

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added a vulnerability linked to the supply chain compromise of the GitHub Action, tj-actions/changed-files, to its Known...