Security News

Fortinet Patches CVE-2025-32756 Zero-Day RCE Flaw Exploited in FortiVoice Systems
2025-05-14 04:21

Fortinet has patched a critical security flaw that it said has been exploited as a zero-day in attacks targeting FortiVoice enterprise phone systems. The vulnerability, tracked as CVE-2025-32756,...

ASUS Patches DriverHub RCE Flaws Exploitable via HTTP and Crafted .ini Files
2025-05-12 14:03

ASUS has released updates to address two security flaws impacting ASUS DriverHub that, if successfully exploited, could enable an attacker to leverage the software in order to achieve remote code...

Chinese Hackers Exploit SAP RCE Flaw CVE-2025-31324, Deploy Golang-Based SuperShell
2025-05-09 04:29

A China-linked unnamed threat actor dubbed Chaya_004 has been observed exploiting a recently disclosed security flaw in SAP NetWeaver. Forescout Vedere Labs, in a report published today, said it...

PoC exploit for SysAid pre-auth RCE released, upgrade quickly!
2025-05-07 12:20

WatchTowr researchers have released a proof-of-concept (PoC) exploit that chains two vulnerabilities in SysAid On-Prem – the self-hosted version of the platform behind SysAid’s popular IT service...

SysAid Patches 4 Critical Flaws Enabling Pre-Auth RCE in On-Premise Version
2025-05-07 11:31

Cybersecurity researchers have disclosed multiple security flaw in the on-premise version of SysAid IT support software that could be exploited to achieve pre-authenticated remote code execution...

Samsung MagicINFO 9 Server RCE flaw now exploited in attacks
2025-05-06 17:10

Hackers are exploiting an unauthenticated remote code execution (RCE) vulnerability in the Samsung MagicINFO 9 Server to hijack devices and deploy malware. [...]

Critical Langflow RCE flaw exploited to hack AI app servers
2025-05-06 16:05

The U.S. Cybersecurity & Infrastructure Security Agency (CISA) has tagged a Langflow remote code execution vulnerability as actively exploited, urging organizations to apply security updates and...

RCE flaw in tool for building AI agents exploited by attackers (CVE-2025-3248)
2025-05-06 13:08

A missing authentication vulnerability (CVE-2025-3248) in Langflow, a web application for building AI-driven agents, is being exploited by attackers in the wild, CISA has confirmed by adding it to...

Wormable AirPlay Flaws Enable Zero-Click RCE on Apple Devices via Public Wi-Fi
2025-05-05 17:06

Cybersecurity researchers have disclosed a series of now-patched security vulnerabilities in Apple's AirPlay protocol that, if successfully exploited, could enable an attacker to take over...

Apple 'AirBorne' flaws can lead to zero-click AirPlay RCE attacks
2025-04-29 17:32

​A set of security vulnerabilities in Apple's AirPlay Protocol and AirPlay Software Development Kit (SDK) exposed unpatched third-party and Apple devices to various attacks, including remote code...