Security News

Microsoft fixes Power Pages zero-day bug exploited in attacks
2025-02-20 14:34

Microsoft has issued a security bulletin for a high-severity elevation of privilege vulnerability in Power Pages, which hackers exploited as a zero-day in attacks. [...]

A PostgreSQL zero-day was also exploited in US Treasury hack (CVE-2025-1094)
2025-02-17 13:48

The suspected Chinese state-sponsored hackers who breached workstations of several US Treasury employees in December 2024 did so by leveraging not one, but two zero-days, according to Rapid7...

Critical PostgreSQL bug tied to zero-day attack on US Treasury
2025-02-14 14:19

High-complexity bug unearthed by infoseccers, as Rapid7 probes exploit further A high-severity SQL injection bug in the PostgreSQL interactive tool was exploited alongside the zero-day used to...

PostgreSQL flaw exploited as zero-day in BeyondTrust breach
2025-02-14 14:15

​Rapid7's vulnerability research team says attackers exploited a PostgreSQL security flaw as a zero-day to breach the network of privileged access management company BeyondTrust in December. [...]

PostgreSQL Vulnerability Exploited Alongside BeyondTrust Zero-Day in Targeted Attacks
2025-02-14 05:03

Threat actors who were behind the exploitation of a zero-day vulnerability in BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) products in December 2024 likely also exploited a...

Patch Tuesday: Microsoft Patches Two Actively Exploited Zero-Day Flaws
2025-02-12 20:25

February’s report on Microsoft patches includes 56 vulnerabilities, two of which are zero-day flaws that have been exploited.

Microsoft fixes two actively exploited zero-days (CVE-2025-21418, CVE-2025-21391)
2025-02-11 20:15

February 2025 Patch Tuesday is here, and Microsoft has delivered fixes for 56 vulnerabilities, including two zero-days – CVE-2025-21418 and CVE-2025-21391 – under active exploitation....

Microsoft February 2025 Patch Tuesday fixes 4 zero-days, 55 flaws
2025-02-11 18:56

Today is Microsoft's February 2025 Patch Tuesday, which includes security updates for 55 flaws, including four zero-day vulnerabilities, with two actively exploited in attacks. [...]

Fortinet warns of new zero-day exploited to hijack firewalls
2025-02-11 18:56

Fortinet warned today that attackers are exploiting another authentication bypass zero-day bug in FortiOS and FortiProxy to hijack Fortinet firewalls and breach enterprise networks. [...]

Apple Patches Actively Exploited iOS Zero-Day CVE-2025-24200 in Emergency Update
2025-02-11 11:16

Apple on Monday released out-of-band security updates to address a security flaw in iOS and iPadOS that it said has been exploited in the wild. Assigned the CVE identifier CVE-2025-24200, the...