Latest Security News
Security Updates
Latest security news and articles covering recent vulnerabilities and their impacts.
CVE-2025-50165: Critical Flaw in Windows Graphics Component
2025-11-20 15:47
Zscaler.com
1 CVE
IntroductionIn May 2025, Zscaler ThreatLabz discovered CVE-2025-50165, a critical remote code execution (RCE) vulnerability with a CVSS score of 9.8 that impacts the Windows Graphics Component. The vulnerability lies within windowscodecs.dll, and any applicat…
Security advisory: Uncontrolled Recursion and Use-After-Free vulnerabilities in Qt SVG module impact Qt
2025-10-03 14:14
Www.qt.io
2 CVEs
Two vulnerabilities in Qt SVG module have been discovered. Uncontrolled recursion vulnerability has been assigned the CVE id CVE-2025-10728. Whereas Use-After-Free vulnerability has been assigned the CVE id CVE-2025-10729.
CISA Flags Meteobridge CVE-2025-4008 Flaw as Actively Exploited in the Wild
2025-10-03 08:23
Internet
1 CVE
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday added a high-severity security flaw impacting Smartbedded Meteobridge to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation. The vulnerability,…
Re: [FD]: "Glass Cage" – Zero-Click iMessage → Persistent iOS Compromise + Bricking (CVE-2025-24085 / 24201, CNVD-2025-07885)
2025-10-02 22:20
Seclists.org
2 CVEs
Posted by josephgoyd via Fulldisclosure on Oct 02Updated repo location: https://github.com/JGoyd/Glass-Cage-iOS18-CVE-2025-24085-CVE-2025-24201 Working exploit: https://www.dropbox.com/scl/fi/ech6wdnpnyscbfiu2o8zh/IMG_1118.png?rlkey=jna5uo6aihs6tfbwtsk8fw7e…
Re: [FD]Full Disclosure: CVE-2025-31200 & CVE-2025-31201 – 0-Click iMessage Chain → Secure Enclave Key Theft, Wormable RCE, Crypto Theft
2025-10-02 22:20
Seclists.org
2 CVEs
Posted by josephgoyd via Fulldisclosure on Oct 02Updated repo location: https://github.com/JGoyd/iOS-Attack-Chain-CVE-2025-31200-CVE-2025-31201 Working exploit: https://www.dropbox.com/scl/fi/oerpnhq1ui3xfswsszfh2/Audio-clip.amr?rlkey=7n54m1o84poezyipxvd2f9…
Update Chrome now: Google patches new zero-day threat
2025-10-02 13:03
Fox News
1 CVE
Chrome faces its sixth zero-day attack in 2025 as Google patches critical V8 engine flaw CVE-2025-10585 discovered by Threat Analysis Group.
CISA Adds Five Known Exploited Vulnerabilities to Catalog
2025-10-02 12:00
Cisa.gov
2 CVEs
CISA has added five new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2014-6278 GNU Bash OS Command Injection Vulnerability CVE-2015-7755 Juniper ScreenOS Improper Authent…
Django CVE-2025-59681 and CVE-2025-59682
2025-10-01 15:57
Seclists.org
2 CVEs
Posted by Jacob Walls on Oct 01* Announce link: https://www.djangoproject.com/weblog/2025/oct/01/security-releases/ * Announce content: In accordance with `our security release policy https://docs.djangoproject.com/en/dev/internals/security/>`_, the Django t…
Re: Re: [EXT] Re: [oss-security] CVE-2023-51767: a bogus CVE in OpenSSH
2025-10-01 15:54
Seclists.org
1 CVE
Posted by Emilio Pozuelo Monfort on Oct 01The CVE got assigned by MITRE, so one can dispute it with MITRE directly. Apparently it's already been done, and the CVE appears as disputed [1]. I'm not sure if it will go from there to rejected. Cheers, Emilio […
Re: Re: [EXT] Re: [oss-security] CVE-2023-51767: a bogus CVE in OpenSSH
2025-10-01 07:31
Seclists.org
1 CVE
Posted by Mike O'Connor on Oct 01:> Second, I had expected ECC to "kill Rowhammer dead" only to find that it :> can be possible to cause enough bit flips to get all the way from one :> valid ECC word to another valid ECC word before ECC scrub reaches …
FreeIPA - CVE-2025-7493 - Privilege Escalation from host to domain admin
2025-09-30 15:52
Seclists.org
1 CVE
Posted by Marco Benatto on Sep 30Hello all, please find the announcement of a Privilege Escalation vulnerability in FreeIPA bellow. Upstream release note: https://www.freeipa.org/release-notes/4-12-5.html ==== Security Report ==== * CVE-2025-7493 Contin…
CISA warns of critical Linux Sudo flaw exploited in attacks
2025-09-30 13:42
BleepingComputer
1 CVE
Hackers are actively exploiting a critical vulnerability (CVE-2025-32463) in the sudo package that enables the execution of commands with root-level privileges on Linux operating systems. [...]
Increase in Scans for Palo Alto Global Protect Vulnerability (CVE-2024-3400), (Mon, Sep 29th)
2025-09-29 18:42
Sans.edu
1 CVE
We are all aware of the abysmal state of security appliances, no matter their price tag. Ever so often, we see an increase in attacks against some of these vulnerabilities, trying to mop up systems missed in earlier exploit waves. Currently, on source in part…
Re: [EXT] Re: [oss-security] CVE-2023-51767: a bogus CVE in OpenSSH
2025-09-29 14:40
Seclists.org
1 CVE
Posted by Peter Gutmann on Sep 29Damien Miller writes: Everyone gets that at some point. There was a discussion on another mailing list about it a while back, how do you respond to a CVE for a vulnerability that doesn't exist unless you modify the code or co…
Re: [EXT] Re: [oss-security] CVE-2023-51767: a bogus CVE in OpenSSH
2025-09-29 14:25
Seclists.org
1 CVE
Posted by Theo de Raadt on Sep 29Damien Miller wrote: I don't think the CVE was filed because of the misleading abstract. Rather, it was due to the misleading contents saying that OpenSSH is vulnerable, with a large amount of effort shown, and text explaini…
CISA Adds Five Known Exploited Vulnerabilities to Catalog
2025-09-29 12:00
Cisa.gov
2 CVEs
CISA has added five new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2021-21311 Adminer Server-Side Request Forgery Vulnerability CVE-2025-20352 Cisco IOS and IOS XE Stac…
Akira Ransomware bypasses MFA on SonicWall VPNs
2025-09-29 10:52
Securityaffairs.com
1 CVE
Akira ransomware is targeting SonicWall SSL VPNs, bypassing OTP MFA on accounts, likely using stolen OTP seeds. Since July 2025, Akira ransomware has exploited SonicWall SSL VPNs, likely using credentials obtained from the exploitation of the CVE-2024-40766 v…
WhatsApp 0-Click Vulnerability Exploited Using Malicious DNG File
2025-09-28 16:00
Cybersecuritynews.com
1 CVE
WhatsApp 0-click remote code execution (RCE) vulnerability affecting Apple's iOS, macOS, and iPadOS platforms, detailed with a proof of concept demonstration. The attack chain exploits two distinct vulnerabilities, identified as CVE-2025-55177 and CVE-2025-43…
Re: [EXT] Re: [oss-security] CVE-2023-51767: a bogus CVE in OpenSSH
2025-09-28 15:46
Seclists.org
1 CVE
Posted by Adiletta, Andrew on Sep 28Theo, Even after two years we stand behind our paper and the contributions as outlined. There is nothing more natural for any vulnerability researcher to evaluate the most widely used products. If we had doubts about the …
Re: [EXT] Re: [oss-security] CVE-2023-51767: a bogus CVE in OpenSSH
2025-09-28 14:55
Seclists.org
1 CVE
Posted by Theo de Raadt on Sep 28Damien Miller wrote: Andrew, I think you should answer Damien's comment. I'm a bit more cynical, and think this is very close to open source community engagement malpractice -- where you picked projects specifically to incre…