Latest Security News
Security Updates
Latest security news and articles covering recent vulnerabilities and their impacts.
CVE-2025-3248 – Unauthenticated Remote Code Execution in Langflow via Insecure Python exec Usage
2025-06-18 14:01
Offsec.com
1 CVE
CVE-2025-3248 is a critical RCE vulnerability in Langflow that allows unauthenticated attackers to execute arbitrary Python code via unsanitized input to exec(). Learn how it works and how to protect your system. The post CVE-2025-3248 – Unauthenticated Remot…
Watch out, Veeam fixed a new critical bug in Backup & Replication product
2025-06-18 13:33
Securityaffairs.com
1 CVE
Veeam addressed a new critical flaw in Backup & Replication product that could potentially result in remote code execution. Veeam has rolled out security patches to address a critical security vulnerability, tracked CVE-2025-23121 (CVSS score of 9.9) in its B…
News Flodrix botnet targets vulnerable Langflow servers
2025-06-18 10:43
Securityaffairs.com
1 CVE
Attackers exploit CVE-2025-3248 in Langflow servers to deliver Flodrix botnet via downloader scripts, Trend Research reports. Trend Research uncovered an ongoing campaign exploiting the vulnerability CVE-2025-3248 to deliver the Flodrix botnet. Attackers expl…
Alarming ASUS Armoury Crate Vulnerability Can Give Hackers Admin Access
2025-06-18 10:31
Hot Hardware
1 CVE
Security researchers have revealed that the ASUS Armoury Crate software has a serious vulnerability (tracked as CVE-2025-3464) that could allow hackers to gain admin access to computers. The ASUS Armoury Crate software was designed to help users control and …
Veeam Patches CVE-2025-23121: Critical RCE Bug Rated 9.9 CVSS in Backup & Replication
2025-06-18 05:49
Internet
1 CVE
Veeam has rolled out patches to contain a critical security flaw impacting its Backup & Replication software that could result in remote code execution under certain conditions. The security defect, tracked as CVE-2025-23121, carries a CVSS score of 9.9 out o…
: "Glass Cage" – Zero-Click iMessage → Persistent iOS Compromise + Bricking (CVE-2025-24085 / 24201, CNVD-2025-07885)
2025-06-18 03:07
Seclists.org
2 CVEs
Posted by josephgoyd via Fulldisclosure on Jun 17"Glass Cage" – Sophisticated Zero-Click iMessage Exploit ChainEnabling Persistent iOS Compromise and Device Bricking CVE-2025-24085, CVE-2025-24201(CNVD-2025-07885) Author: Joseph Goydish II Date: 06/10/2025 …
Google Chrome Zero-Day CVE-2025-2783 Exploited by TaxOff to Deploy Trinper Backdoor
2025-06-17 19:16
Internet
1 CVE
A now-patched security flaw in Google Chrome was exploited as a zero-day by a threat actor known as TaxOff to deploy a backdoor codenamed Trinper. The attack, observed in mid-March 2025 by Positive Technologies, involved the use of a sandbox escape vulnerabil…
CISA Adds One Known Exploited Vulnerability to Catalog
2025-06-17 12:00
Cisa.gov
1 CVE
CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. CVE-2023-0386 Linux Kernel Improper Ownership Management Vulnerability These types of vulnerabili…
Attackers target Zyxel RCE vulnerability CVE-2023-28771
2025-06-17 10:34
Securityaffairs.com
1 CVE
GreyNoise researchers have observed exploit attempts targeting the remote code execution vulnerability CVE-2023-28771 in Zyxel devices. On June 16, GreyNoise researchers detected exploit attempts targeting CVE-2023-28771 (CVSS score 9.8), a remote code execut…
TP-Link Router Flaw CVE-2023-33538 Under Active Exploit, CISA Issues Immediate Alert
2025-06-17 08:12
Internet
1 CVE
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a high-severity security flaw in TP-Link wireless routers to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation. The vulnerability in ques…
CISA Adds Two Known Exploited Vulnerabilities to Catalog
2025-06-16 12:00
Cisa.gov
2 CVEs
CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. CVE-2025-43200 Apple Multiple Products Unspecified Vulnerability CVE-2023-33538 TP-Link Multiple Route…
Apple Products Security Restriction Bypass Vulnerability
2025-06-16 01:00
Hkcert.org
1 CVE
A vulnerability was identified in Apple Products. A remote attacker could exploit this vulnerability to trigger security restriction bypass on the targeted system. Note: For CVE-2025-43200, a logic issue existed when processing a maliciously crafted phot…
Week in review: Microsoft fixes exploited zero-day, Mirai botnets target unpatched Wazuh servers
2025-06-15 08:00
Help Net Security
1 CVE
Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Microsoft fixes zero-day exploited for cyber espionage (CVE-2025-33053) For June 2025 Patch Tuesday, Microsoft has fixed 66 new CVEs, including a zero-day exploi…
sslh: Remote Denial-of-Service Vulnerabilities (CVE-2025-46807, CVE-2025-46806)
2025-06-13 14:32
Seclists.org
2 CVEs
Posted by Matthias Gerstner on Jun 13Hello list, this is a review report about remote Denial-of-Service vulnerabilities in sslh. We also offer a rendered HTML version of this report on our blog [1]. Please find the full details below. 1) Introduction ======…
iOS zero-click attacks used to deliver Graphite spyware (CVE-2025-43200)
2025-06-13 12:06
Help Net Security
1 CVE
A zero-click attack leveraging a freshly disclosed Messages vulnerability (CVE-2025-43200) has infected the iPhones of two European journalists with Paragon’s Graphite mercenary spyware, Citizen Lab researchers have revealed on Thursday. The attacks happened …
Apple confirmed that Messages app flaw was actively exploited in the wild
2025-06-13 10:15
Securityaffairs.com
1 CVE
Apple confirmed that a security flaw in its Messages app was actively exploited in the wild to target journalists with Paragon’s Graphite spyware. Apple confirmed that a now-patched vulnerability, tracked as CVE-2025-43200, in its Messages app was actively ex…
Security advisory: Recently discovered Use After Free issue in QHttp2ProtocolHandler impacts Qt
2025-06-13 09:00
Www.qt.io
1 CVE
There is a "Use After Free" vulnerability in Qt's QHttp2ProtocolHandler in the QtNetwork module. This has been assigned the CVE id CVE-2025-5991.
Apple Zero-Click Flaw in Messages Exploited to Spy on Journalists Using Paragon Spyware
2025-06-13 07:03
Internet
1 CVE
Apple has disclosed that a now-patched security flaw present in its Messages app was actively exploited in the wild to target civil society members in sophisticated cyber attacks. The vulnerability, tracked as CVE-2025-43200, was addressed on February 10, 202…
PostgreSQL JDBC 42.7.7 Security update for CVE-2025-49146
2025-06-13 00:00
Postgresql.org
1 CVE
The PostgreSQL JDBC team have released version 42.7.7. to address CVE-2025-49146 When the PostgreSQL JDBC driver is configured with channel binding set to required (default value is prefer), the driver would incorrectly allow connections to proceed with authe…
CVE-2025-6031 - Insecure device pairing in end-of-life Amazon Cloud Cam
2025-06-12 17:29
Amazon.com
1 CVE
Scope: Amazon Content Type: Informational Publication Date: 2025/06/12 10:30 AM PDT Description Amazon Cloud Cam is a home security camera that was deprecated on December 2, 2022, is end of life, and is no longer actively supported. When a user powers on t…