Category: CyberSecurityNews

Ivanti Cloud Services Application Vulnerability Leads to Privilege Escalation
14
May
2025

Ivanti Cloud Services Application Vulnerability Leads to Privilege Escalation

Ivanti has disclosed a high-severity security vulnerability affecting its Cloud Services Application (CSA) that could allow attackers to escalate privileges…

72 Vulnerabilities Fixed, Including 5 Actively Exploited Zero-Days
14
May
2025

72 Vulnerabilities Fixed, Including 5 Actively Exploited Zero-Days

Microsoft has released its Patch Tuesday updates for May 2025, addressing a total of 78 vulnerabilities across its product ecosystem,…

Windows Common Log File System 0-Day Vulnerability
14
May
2025

Windows Common Log File System 0-Day Vulnerability Actively Exploited in the Wild

Microsoft has confirmed that threat actors are actively exploiting two critical vulnerabilities in the Windows Common Log File System (CLFS)…

Microsoft Scripting Engine 0-Day Vulnerability Enables Remote Code Execution Over Network
14
May
2025

Microsoft Scripting Engine 0-Day Vulnerability Enables Remote Code Execution Over Network

Microsoft has disclosed a critical memory corruption vulnerability in its Scripting Engine (CVE-2025-30397), which allows unauthorized attackers to execute code…

Microsoft Windows 11 Insider Preview Build 26200.5600 Released
14
May
2025

Microsoft Windows 11 Insider Preview Build 26200.5600 Released

Microsoft has rolled out Windows 11 Insider Preview Build 26200.5600 (KB5058493) to the Dev Channel, bringing a host of new…

Windows Ancillary for WinSock 0-Day Vulnerability Let Attackers Escalate Privileges
13
May
2025

Windows Ancillary for WinSock 0-Day Vulnerability Let Attackers Escalate Privileges

Microsoft has patched an actively exploited zero-day vulnerability in the Windows Ancillary Function Driver for WinSock (afd.sys) as part of…

Microsoft Rolls Out Windows 11 Cumulative Updates KB5058411 and KB5058405
13
May
2025

Microsoft Rolls Out Windows 11 Cumulative Updates KB5058411 and KB5058405

Microsoft released two significant cumulative updates for Windows 11, KB5058411 and KB5058405, targeting improved security and system performance across various…

Windows DWM 0-Day Vulnerability Allows Attackers to Escalate Privileges
13
May
2025

Windows DWM 0-Day Vulnerability Allows Attackers to Escalate Privileges

Microsoft has patched a critical zero-day vulnerability in the Windows Desktop Window Manager (DWM) Core Library, tracked as CVE-2025-30400, which…

Researchers Uncovered North Korean Nationals Remote IT Worker Fraud Scheme
13
May
2025

Researchers Uncovered North Korean Nationals Remote IT Worker Fraud Scheme

In a significant cybersecurity investigation, researchers have revealed an elaborate fraud scheme orchestrated by North Korean nationals who used stolen…

SAP May 2025 Patch Tuesday
13
May
2025

SAP May 2025 Patch Tuesday

SAP’s May 2025 Security Patch Day includes an urgent update to the previously released emergency patch for a critical zero-day…

Recurring Supply‑Chain Lapses Expose UEFI Firmware to Pre‑OS Threats
13
May
2025

Recurring Supply‑Chain Lapses Expose UEFI Firmware to Pre‑OS Threats

A disturbing pattern of security failures in the firmware supply chain continues to expose millions of devices to pre-OS threats,…

F5 BIG-IP Command Injection Vulnerability Let Attackers Execute Arbitrary System Commands
13
May
2025

F5 BIG-IP Command Injection Vulnerability Let Attackers Execute Arbitrary System Commands

F5 Networks has disclosed a high-severity command injection vulnerability (CVE-2025-31644) in its BIG-IP products running in Appliance mode.  The vulnerability…