Category: GBHackers

Multiple Cisco Tools at Risk from Erlang/OTP SSH Remote Code Execution Flaw
24
Apr
2025

Multiple Cisco Tools at Risk from Erlang/OTP SSH Remote Code Execution Flaw

Cisco has issued a high-severity advisory (cisco-sa-erlang-otp-ssh-xyZZy) warning of a critical remote code execution (RCE) vulnerability in products using Erlang/OTP’s…

Commvault RCE Vulnerability Exploited—PoC Released
24
Apr
2025

Commvault RCE Vulnerability Exploited—PoC Released

Enterprises and managed service providers globally are now facing urgent security concerns following the disclosure of a major pre-authenticated remote…

Zyxel RCE Flaw Lets Attackers Run Commands Without Authentication
24
Apr
2025

Zyxel RCE Flaw Lets Attackers Run Commands Without Authentication

Security researcher Alessandro Sgreccia (aka “rainpwn”) has revealed a set of critical vulnerabilities in Zyxel’s USG FLEX-H firewall series that…

Hackers Use 1000+ IP Addresses to Target Ivanti VPN Vulnerabilities
24
Apr
2025

Hackers Use 1000+ IP Addresses to Target Ivanti VPN Vulnerabilities

A sweeping wave of suspicious online activity is putting organizations on alert as hackers ramp up their efforts to probe…

Critical Langflow Flaw Enables Malicious Code Injection – Technical Breakdown Released
24
Apr
2025

Critical Langflow Flaw Enables Malicious Code Injection – Technical Breakdown Released

A critical remote code execution (RCE) vulnerability, identified as CVE-2025-3248 with a CVSS score of 9.8, has been uncovered in…

Redis DoS Flaw Allows Attackers to Crash Servers or Drain Memory
24
Apr
2025

Redis DoS Flaw Allows Attackers to Crash Servers or Drain Memory

A high-severity denial-of-service (DoS) vulnerability in Redis, tracked as CVE-2025-21605, allows unauthenticated attackers to crash servers or exhaust system memory by…

Threat Actors Growing More Sophisticated, Exploiting Zero-Day Vulnerabilities
24
Apr
2025

Threat Actors Growing More Sophisticated, Exploiting Zero-Day Vulnerabilities

Google’s Mandiant team has released its M-Trends 2025 report, highlighting the increasing sophistication of threat actors, particularly China-nexus groups. These…

GitLab Releases Critical Patch for XSS, DoS, and Account Takeover Bugs
24
Apr
2025

GitLab Releases Critical Patch for XSS, DoS, and Account Takeover Bugs

Why Application Security is Non-Negotiable The resilience of your digital infrastructure directly impacts your ability to scale. And yet, application…

SonicWall SSLVPN Flaw Allows Hackers to Crash Firewalls Remotely
24
Apr
2025

SonicWall SSLVPN Flaw Allows Hackers to Crash Firewalls Remotely

SonicWall has issued an urgent advisory (SNWLID-2025-0009) warning of a high-severity vulnerability in its SSLVPN Virtual Office interface that enables…

Microsoft Offers $30,000 Bounties for AI Security Flaws
24
Apr
2025

Microsoft Offers $30,000 Bounties for AI Security Flaws

Microsoft has launched a new bounty program that offers up to $30,000 to security researchers who discover vulnerabilities in its…

Blue Shield Exposed Health Data of 4.7 Million via Google Ads
24
Apr
2025

Blue Shield Exposed Health Data of 4.7 Million via Google Ads

Blue Shield of California has disclosed a significant data privacy incident affecting up to 4.7 million members, after discovering that…

Strengthening Your Weakest Security Link
24
Apr
2025

Strengthening Your Weakest Security Link

Despite billions spent annually on cybersecurity technology, organizations continue to experience breaches with alarming frequency. The most sophisticated security systems…