Security News

SonicWall flags critical bug likely exploited as zero-day, rolls out hotfix
2025-01-23 16:36

Big organizations and governments are main users of these gateways SonicWall is warning customers of a critical vulnerability that was potentially already exploited as a zero-day.…

SonicWall warns of SMA1000 RCE flaw exploited in zero-day attacks
2025-01-23 15:45

SonicWall is warning about a pre-authentication deserialization vulnerability in SonicWall SMA1000 Appliance Management Console (AMC) and Central Management Console (CMC), with reports that it has...

SonicWall SMA appliances exploited in zero-day attacks (CVE-2025-23006)
2025-01-23 08:57

A critical zero-day vulnerability (CVE-2025-23006) affecting SonicWall Secure Mobile Access (SMA) 1000 Series appliances is being exploited by attackers. “We strongly advises users of the SMA1000...

Critical zero-days impact premium WordPress real estate plugins
2025-01-22 22:59

The RealHome theme and the Easy Real Estate plugins for WordPress are vulnerable to two critical severity flaws that allow unauthenticated users to gain administrative privileges. [...]

Hackers exploit 16 zero-days on first day of Pwn2Own Automotive 2025
2025-01-22 14:38

On the first day of Pwn2Own Automotive 2025, security researchers exploited 16 unique zero-days and collected $382,750 in cash awards. [...]

Hackers Exploit Zero-Day in cnPilot Routers to Deploy AIRASHI DDoS Botnet
2025-01-22 13:53

Threat actors are exploiting an unspecified zero-day vulnerability in Cambium Networks cnPilot routers to deploy a variant of the AISURU botnet called AIRASHI to carry out distributed...

Patch procrastination leaves 50,000 Fortinet firewalls vulnerable to zero-day
2025-01-21 18:45

Seven days after disclosure and little action taken, data shows Fortinet customers need to get with the program and apply the latest updates as nearly 50,000 management interfaces are still...

3 Actively Exploited Zero-Day Flaws Patched in Microsoft's Latest Security Update
2025-01-15 05:15

Microsoft kicked off 2025 with a new set of patches for a total of 161 security vulnerabilities across its software portfolio, including three zero-days that have been actively exploited in...

Microsoft fixes actively exploited Windows Hyper-V zero-day flaws
2025-01-14 20:57

Microsoft has marked January 2025 Patch Tuesday with a hefty load of patches: 157 CVE-numbered security issues have been fixed in various products, three of which (in Hyper-V) are being actively...

Microsoft January 2025 Patch Tuesday fixes 8 zero-days, 159 flaws
2025-01-14 19:01

Today is Microsoft's January 2025 Patch Tuesday, which includes security updates for 159 flaws, including eight zero-day vulnerabilities, with three actively exploited in attacks. [...]