Category: CyberSecurityNews

Kerio Control Firewall Vulnerability Allows 1-Click Remote Code Execution
09
Jan
2025

Kerio Control Firewall Vulnerability Allows 1-Click Remote Code Execution

A critical vulnerability in Kerio Control, a popular firewall and Unified Threat Management (UTM) product, has been discovered that could…

PoC Exploit Released For Apache Struts Remote Code Execution Vulnerability
09
Jan
2025

PoC Exploit Released For Apache Struts Remote Code Execution Vulnerability

A proof-of-concept (PoC) exploit for the critical Apache Struts vulnerability, CVE-2024-53677, has been publicly released, raising alarm across the cybersecurity…

PoC Exploit Code Released For macOS TCC Bypass Vulnerability
09
Jan
2025

PoC Exploit Code Released For macOS TCC Bypass Vulnerability

A proof-of-concept (PoC) exploit code for a critical vulnerability in macOS, identified as CVE-2024-54527 has been disclosed. This vulnerability allows…

Palo Alto Networks Expedition Tool Vulnerability Exposes Firewall Credentials
09
Jan
2025

Palo Alto Networks Expedition Tool Vulnerability Exposes Firewall Credentials

Multiple vulnerabilities in Palo Alto Networks’ Expedition migration tool have been discovered, potentially exposing sensitive firewall credentials, including usernames, cleartext…

Ivanti VPN 0-Day
09
Jan
2025

Active Exploitation of Ivanti VPN 0-Day Vulnerability (CVE-2025-0282)

Ivanti publicly disclosed two critical vulnerabilities CVE-2025-0282 and CVE-2025-0283 affecting its Connect Secure (ICS) VPN appliances. The announcement comes amidst…

Wireshark 4.4.3 Released
09
Jan
2025

Wireshark 4.4.3 Released – What’s New!

The Wireshark Foundation has announced the release of Wireshark 4.4.3, the latest version of the world’s most popular network protocol…

Ivanti VPN Zero-Day Vulnerability Actively Exploited in the Wild
09
Jan
2025

Ivanti VPN Zero-Day Vulnerability Actively Exploited in the Wild

Ivanti has disclosed actively exploiting a critical zero-day vulnerability, CVE-2025-0282, in its Connect Secure VPN appliances. This vulnerability allows unauthenticated…

Dell Update Package Framework Vulnerability Let Attackers Escalate Privileges
08
Jan
2025

Dell Update Package Framework Vulnerability Let Attackers Escalate Privileges

A critical security vulnerability has been identified in Dell’s Update Package (DUP) Framework, potentially exposing systems to privilege escalation and…

CISA Warns of Three Vulnerabilities Actively Exploited in Attacks
08
Jan
2025

CISA Warns of Three Vulnerabilities Actively Exploited in Attacks

The Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent alert regarding three critical vulnerabilities that are currently being…

CVE Partnership with Thales Group as a Designated Root for Vulnerability Management
08
Jan
2025

CVE Partnership with Thales as a Designated Root for Vulnerability Management

The CVE® Program has announced a significant expansion of its collaboration with Thales Group to strengthen the management and assignment…

Kaaviya Ragupathy
08
Jan
2025

Microsoft Pushes Identity Management Feature For Azure Via Entra

Microsoft has announced the Public Preview of Managed Identities as Federated Identity Credentials (FICs) for Microsoft Entra. The innovation aims…

Tushar Subhra Dutta
08
Jan
2025

IBM Concert Software Vulnerabilities Let Attackers Trigger DoS Condition

IBM Concert Software has been found vulnerable to multiple security flaws that could allow attackers to trigger denial-of-service (DoS) conditions,…