Latest Security News
Security Updates
Latest security news and articles covering recent vulnerabilities and their impacts.
Microsoft fixes critical wormable Windows flaw (CVE-2025-47981)
2025-07-09 11:30
Help Net Security
3 CVEs
For July 2025 Patch Tuesday, Microsoft has released patches for 130 vulnerabilities, among them one that’s publicly disclosed (CVE-2025-49719) and a wormable RCE bug on Windows and Windows Server (CVE-2025-47981). CVE-2025-49719 and CVE-2025-49717, in Microso…
Helm local code execution via a malicious chart – CVE-2025-53547
2025-07-09 05:49
Github.com
1 CVE
A Helm contributor discovered that a specially crafted `Chart.yaml` file along with a specially linked `Chart.lock` file can lead to local code execution when dependencies are updated. ### Impac...
CVE-2025-48384: Breaking Git with a carriage return and cloning RCE
2025-07-08 17:48
Dgl.cx
1 CVE
Article URL: https://dgl.cx/2025/07/git-clone-submodule-cve-2025-48384 Comments URL: https://news.ycombinator.com/item?id=44502330 Points: 3 # Comments: 0
Multiple vulnerabilities fixed in Git
2025-07-08 17:11
Seclists.org
1 CVE
Posted by Taylor Blau on Jul 08The Git project released new versions of Git today, July 8, 2025, addressing multiple security vulnerabilities. Those vulnerabilities are: CVE-2025-27613, CVE-2025-27614, CVE-2025-46334, CVE-2025-46835, CVE-2025-48384, CVE-2025-…
Check for CitrixBleed 2 exploitation even if you patched quickly! (CVE-2025-5777)
2025-07-08 15:31
Help Net Security
1 CVE
With PoC exploits for CVE-2025-5777 (aka CitrixBleed 2) now public and reports of active exploitation of the flaw since mid-June, you should check whether your Citrix NetScaler ADC and/or Gateway instances have been probed and compromised by attackers. Citrix…
Xen Security Advisory 471 v1 (CVE-2024-36350,CVE-2024-36357) - x86: Transitive Scheduler Attacks
2025-07-08 14:11
Seclists.org
1 CVE
Posted by Xen . org security team on Jul 08 Xen Security Advisory CVE-2024-36350,CVE-2024-36357 / XSA-471 x86: Transitive Scheduler Attacks ISSUE DESCRIPTION ================= Researchers from Microsoft and ETH Zurich have discovered several new speculati…
CISA Adds Four Critical Vulnerabilities to KEV Catalog Due to Active Exploitation
2025-07-08 05:08
Internet
1 CVE
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added four security flaws to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation in the wild. The list of flaws is as follows - CVE-2014-3931 (CV…
Zimbra Multiple Vulnerabilities
2025-07-08 01:00
Hkcert.org
1 CVE
Multiple vulnerabilities were identified in Zimbra. A remote attacker could exploit some of these vulnerabilities to trigger denial of service condition, remote code execution and cross-site scripting on the targeted system. Note: CVE-2019-9621 is being …
Public exploits released for CitrixBleed 2 NetScaler flaw, patch now
2025-07-07 22:57
BleepingComputer
1 CVE
Researchers have released proof-of-concept (PoC) exploits for a critical Citrix NetScaler vulnerability, tracked as CVE-2025-5777 and dubbed CitrixBleed2, warning that the flaw is easily exploitable and can successfully steal user session tokens. [...]
CitrixBleed 2 exploits are on the loose as security researchers yell and wave their hands
2025-07-07 20:38
Biztoc.com
1 CVE
NetScaler vendor issued a patch but otherwise, stony silence Multiple exploits are circulating for CVE-2025-5777, a critical bug in Citrix NetScaler ADC and NetScaler Gateway dubbed CitrixBleed 2, and security analysts are warning a "significant portion" of u…
CitrixBleed 2 exploits are on the loose as security researchers yell and wave their hands
2025-07-07 20:31
Theregister.com
1 CVE
NetScaler vendor issued a patch but otherwise, stony silence Multiple exploits are circulating for CVE-2025-5777, a critical bug in Citrix NetScaler ADC and NetScaler Gateway dubbed CitrixBleed 2, and security analysts are warning a "significant portion" of u…
This Week in Security: Anthropic, Coinbase, and Oops Hunting
2025-07-07 14:00
Hackaday
1 CVE
Anthropic has had an eventful couple weeks, and we have two separate write-ups to cover. The first is a vulnerability in the Antropic MCP Inspector, CVE-2025-49596. We’ve talked a bit …read more
CISA Adds Four Known Exploited Vulnerabilities to Catalog
2025-07-07 12:00
Cisa.gov
2 CVEs
CISA has added four new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2014-3931 Multi-Router Looking Glass (MRLG) Buffer Overflow Vulnerability CVE-2016-10033 PHPMailer Co…
Week in review: Sudo local privilege escalation flaws fixed, Google patches actively exploited Chrome
2025-07-06 08:00
Help Net Security
2 CVEs
Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Sudo local privilege escalation vulnerabilities fixed (CVE-2025-32462, CVE-2025-32463) If you haven’t recently updated the Sudo utility on your Linux box(es), yo…
DSA-5958-1 jpeg-xl - security update
2025-07-04 00:00
Debian.org
1 CVE
Multiple vulnerabilities are discovered in jpeg-xl, the JPEG XL ("JXL") image coding library, including out of bounds read/write and stack based buffer overflow, which may cause excessive memory usage and denial of service attacks. CVE-2023-0645 Specifical…
CVE-2025-53367: An exploitable out-of-bounds write in DjVuLibre
2025-07-03 20:52
Github.blog
1 CVE
DjVuLibre has a vulnerability that could enable an attacker to gain code execution on a Linux Desktop system when the user tries to open a crafted document. The post CVE-2025-53367: An exploitable out-of-bounds write in DjVuLibre appeared first on The GitHub …
CVE-2025-53367: An exploitable OOB write in DjVuLibre
2025-07-03 20:02
Seclists.org
1 CVE
Posted by Kevin Backhouse on Jul 03DjVuLibre version 3.5.29 was released today. It fixes CVE-2025-53367 (GHSL-2025-055), an out-of-bounds write in the MMRDecoder::scanruns method. The vulnerability could be exploited to gain code execution on a Linux Desktop …
CVE-2025-29306 – Unauthenticated Remote Code Execution in FoxCMS v1.2.5 via Unserialize Injection
2025-07-03 14:57
Offsec.com
1 CVE
Discover details about CVE-2025-29306, a critical RCE vulnerability in FoxCMS 1.2.5. Learn how unsafe use of PHP's unserialize() function enables remote attackers to execute arbitrary system commands. The post CVE-2025-29306 – Unauthenticated Remote Code Exec…
RondoDox Unveiled: Breaking Down a New Botnet Threat
2025-07-03 13:00
Fortinet.com
2 CVEs
FortiGuard Labs analyzes RondoDox, a stealthy new botnet targeting TBK DVRs and Four-Faith routers via CVE-2024-3721 and CVE-2024-12856. Learn how it evades detection, establishes persistence, and mimics gaming and VPN traffic to launch DDoS attacks.
Update your browser: Security fix for Chrome zero-day CVE-2025-6554
2025-07-03 11:13
Opera.com
1 CVE
Chromium's latest release addressed new vulnerabilities. Security updates have been released for Opera - get the latest versions now.