Security News

Microsoft fixes two actively exploited zero-days (CVE-2025-21418, CVE-2025-21391)
2025-02-11 20:15

February 2025 Patch Tuesday is here, and Microsoft has delivered fixes for 56 vulnerabilities, including two zero-days – CVE-2025-21418 and CVE-2025-21391 – under active exploitation....

Microsoft February 2025 Patch Tuesday fixes 4 zero-days, 55 flaws
2025-02-11 18:56

Today is Microsoft's February 2025 Patch Tuesday, which includes security updates for 55 flaws, including four zero-day vulnerabilities, with two actively exploited in attacks. [...]

Fortinet warns of new zero-day exploited to hijack firewalls
2025-02-11 18:56

Fortinet warned today that attackers are exploiting another authentication bypass zero-day bug in FortiOS and FortiProxy to hijack Fortinet firewalls and breach enterprise networks. [...]

Apple Patches Actively Exploited iOS Zero-Day CVE-2025-24200 in Emergency Update
2025-02-11 11:16

Apple on Monday released out-of-band security updates to address a security flaw in iOS and iPadOS that it said has been exploited in the wild. Assigned the CVE identifier CVE-2025-24200, the...

Apple fixes zero-day flaw exploited in “extremely sophisticated” attack (CVE-2025-24200)
2025-02-11 10:40

Users of iPhones and iPads that run iOS/iPadOS 18 and iPadOS 17 are urged to implement the latest updates to plug a security feature bypass vulnerability (CVE-2025-24200) exploited in the wild in...

Apple fixes zero-day exploited in 'extremely sophisticated' attacks
2025-02-10 19:08

Apple has released emergency security updates to patch a zero-day vulnerability that the company says was exploited in targeted and "extremely sophisticated" attacks. [...]

XE Hacker Group Exploits VeraCore Zero-Day to Deploy Persistent Web Shells
2025-02-10 05:14

Threat actors have been observed exploiting multiple security flaws in various software products, including Progress Telerik UI for ASP.NET AJAX and Advantive VeraCore, to drop reverse shells and...

Cybercrime gang exploited VeraCore zero-day vulnerabilities for years (CVE-2025-25181, CVE-2024-57968)
2025-02-05 16:42

XE Group, a cybercriminal outfit that has been active for over a decade, has been quietly exploiting zero-day vulnerabilities (CVE-2025-25181, CVE-2024-57968) in VeraCore software, a popular...

7-Zip MotW bypass exploited in zero-day attacks against Ukraine
2025-02-04 14:43

A 7-Zip vulnerability allowing attackers to bypass the Mark of the Web (MotW) Windows security feature was exploited by Russian hackers as a zero-day since September 2024. [...]

Russian cybercrooks exploiting 7-Zip zero-day vulnerability (CVE-2025-0411)
2025-02-04 13:02

CVE-2025-0411, a Mark-of-the-Web bypass vulnerability in the open-source archiver tool 7-Zip that was fixed in November 2024, has been exploited in zero-day attacks to deliver malware to Ukrainian...