Latest Security News
Security Updates
Latest security news and articles covering recent vulnerabilities and their impacts.
CVE-2025-4427, CVE-2025-4428: Ivanti Endpoint Manager Mobile (EPMM) Remote Code Execution
2025-05-13 21:40
Tenable.com
2 CVEs
Remote code execution vulnerability in a popular mobile device management solution from Ivanti has been exploited in the wild in limited attacksBackgroundOn May 13, Ivanti released a security advisory to address a high severity remote code execution (RCE) a…
Microsoft’s May 2025 Patch Tuesday Addresses 71 CVEs (CVE-2025-32701, CVE-2025-32706, CVE-2025-30400)
2025-05-13 19:11
Tenable.com
3 CVEs
5Critical66Important0Moderate0LowMicrosoft addresses 71 CVEs including seven zero-days, five of which were exploited in the wild.Microsoft patched 71 CVEs in its May 2025 Patch Tuesday release, with five rated crit…
Zero-day exploited to compromise Fortinet FortiVoice systems (CVE-2025-32756)
2025-05-13 18:38
Help Net Security
1 CVE
Fortinet has patched a critical vulnerability (CVE-2025-32756) that has been exploited in the wild to compromise FortiVoice phone / conferencing systems, the company’s product security incident response team has revealed on Tuesday. About CVE-2025-32756 CVE-2…
Snort Subscriber Rules Update 2025-05-13
2025-05-13 17:36
Seclists.org
1 CVE
Posted by Research via Snort-sigs on May 13Talos Snort Subscriber Rules Update Synopsis: Talos is aware of vulnerabilities affecting products from Microsoft Corporation. Details: Microsoft Vulnerability CVE-2025-24063: A coding deficiency exists in Microsof…
Ivanti EPMM vulnerabilities exploited in the wild (CVE-2025-4427, CVE-2025-4428)
2025-05-13 17:26
Help Net Security
2 CVEs
Attackers have exploited vulnerabilities in open-source libraries to compromise on-prem Ivanti Endpoint Manager Mobile (EPMM) instances of a “very limited” number of customers, Ivanti has confirmed on Tuesday, and urged customers to install a patch as soon as…
Ivanti EPMM Flaws Exploited in the Wild: Chained RCE and Auth Bypass Threaten Mobile Device Management
2025-05-13 16:37
SecurityOnline.info
2 CVEs
Ivanti has released a security updates addressing two vulnerabilities in Endpoint Manager Mobile (EPMM)—CVE-2025-4427 and CVE-2025-4428—that, when chained The post Ivanti EPMM Flaws Exploited in the Wild: Chained RCE and Auth Bypass Threaten Mobile Device Management appeared first on Daily CyberSecurity.
Fortinet CVE-2025-32756 Exploited in the Wild: Critical RCE Flaw Hits FortiVoice and More
2025-05-13 15:45
SecurityOnline.info
1 CVE
Fortinet has disclosed a critical stack-based buffer overflow vulnerability, tracked as CVE-2025-32756, affecting a wide range of its The post Fortinet CVE-2025-32756 Exploited in the Wild: Critical RCE Flaw Hits FortiVoice and More appeared first on Daily CyberSecurity.
China-Linked APTs Exploit SAP CVE-2025-31324 to Breach 581 Critical Systems Worldwide
2025-05-13 15:13
Internet
1 CVE
A recently disclosed critical security flaw impacting SAP NetWeaver is being exploited by multiple China-nexus nation-state actors to target critical infrastructure networks. "Actors leveraged CVE-2025-31324, an unauthenticated file upload vulnerability that …
CISA Adds Five Known Exploited Vulnerabilities to Catalog
2025-05-13 12:00
Cisa.gov
2 CVEs
CISA has added five new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. CVE-2025-30400 Microsoft Windows DWM Core Library Use-After-Free Vulnerability CVE-2025-32701 Microsoft Windows…
PoC Released: CVE-2025-31258 Sandbox Escape in macOS via RemoteViewServices
2025-05-13 02:37
SecurityOnline.info
1 CVE
Apple has released a patch for a newly disclosed vulnerability in macOS, tracked as CVE-2025-31258, that could allow The post PoC Released: CVE-2025-31258 Sandbox Escape in macOS via RemoteViewServices appeared first on Daily CyberSecurity.
Re: CVE-2025-22247 - Insecure file handling vulnerability in open-vm-tools
2025-05-13 02:02
Seclists.org
1 CVE
Posted by Solar Designer on May 12Hi, Thank you very much VMware PSIRT for fixing and disclosing this issue. I'm sorry I'm not familiar with open-vm-tools, but I thought we could clarify the below for everyone in here: The commit message says: Skimming th…
CVE-2025-1087: Critical Template Injection in Insomnia API Client Enables Remote Code Execution
2025-05-13 00:42
SecurityOnline.info
1 CVE
A critical vulnerability in Kong’s popular open-source API client, Insomnia, could allow attackers to execute arbitrary code on The post CVE-2025-1087: Critical Template Injection in Insomnia API Client Enables Remote Code Execution appeared first on Daily CyberSecurity.
Can You Really Trust That Permission Pop-Up on macOS? (CVE-2025-31250)
2025-05-12 18:26
Wts.dev
1 CVE
A security research blog.
Researchers found one-click RCE in ASUS’s pre-installed software DriverHub
2025-05-12 17:57
Securityaffairs.com
2 CVEs
Expert found two flaws in DriverHub, pre-installed on Asus motherboards, which allow remote code execution via crafted HTTP requests. Security researcher ‘MrBruh’ discovered two vulnerabilities, tracked as CVE-2025-3462 (CVSS score of 8.4) and CVE-2025-3463 (…
Xen Security Advisory 469 v2 (CVE-2024-28956) - x86: Indirect Target Selection
2025-05-12 17:18
Seclists.org
1 CVE
Posted by Xen . org security team on May 12 Xen Security Advisory CVE-2024-28956 / XSA-469 version 2 x86: Indirect Target Selection UPDATES IN VERSION 2 ==================== State the CVE. ISSUE DESCRIPTION ================= Researchers at VU Amsterdam…
Türkiye-Linked Hackers Exploit Output Messenger Zero-Day (CVE-2025-27920) in Espionage Campaign
2025-05-12 16:34
SecurityOnline.info
1 CVE
Microsoft Threat Intelligence has linked a regional cyber-espionage campaign exploiting a zero-day vulnerability in Output Messenger to the The post Türkiye-Linked Hackers Exploit Output Messenger Zero-Day (CVE-2025-27920) in Espionage Campaign appeared first on Daily CyberSecurity.
CVE-2025-22247 - Insecure file handling vulnerability in open-vm-tools
2025-05-12 16:32
Seclists.org
1 CVE
Posted by VMware PSIRT on May 12Description ============================================================== CVE-2025-22247: open-vm-tools contains an insecure file handling vulnerability. VMware has evaluated the severity of this issue to be in the Moderate …
Marbled Dust leverages zero-day in Output Messenger for regional espionage | Microsoft Security Blog
2025-05-12 16:11
Microsoft.com
1 CVE
Since April 2024, the threat actor that Microsoft Threat Intelligence tracks as Marbled Dust has been observed exploiting user accounts that have not applied fixes to a zero-day vulnerability (CVE-2025-27920) in the messaging app Output Messenger, a multiplat…
Compromised SAP NetWeaver instances are ushering in opportunistic threat actors
2025-05-12 12:58
Help Net Security
1 CVE
A second wave of attacks against the hundreds of SAP NetWeaver platforms compromised via CVE-2025-31324 is underway. “[The] attacks [are] staged by follow-on, opportunistic threat actors who are leveraging previously established webshells (from the first zero…
VMware Tools Update Addresses Insecure File Handling Vulnerability
2025-05-12 10:57
SecurityOnline.info
1 CVE
Broadcom has released a security advisory addressing a moderate-severity vulnerability in VMware Tools, identified as CVE-2025-22247, which could The post VMware Tools Update Addresses Insecure File Handling Vulnerability appeared first on Daily CyberSecurity.