Zimbra Collaboration Server GraphQL Vulnerability Exposes Sensitive User Data
30
Apr
2025

Zimbra Collaboration Server GraphQL Vulnerability Exposes Sensitive User Data

A critical Cross-Site Request Forgery (CSRF) vulnerability in Zimbra Collaboration Server (ZCS) versions 9.0 through 10.1, tracked as CVE-2025-32354, allows…

Researchers Exploit OAuth Misconfigurations to Gain Unrestricted Access to Sensitive Data
30
Apr
2025

Researchers Exploit OAuth Misconfigurations to Gain Unrestricted Access to Sensitive Data

A security researcher has uncovered a serious vulnerability resulting from incorrectly configured OAuth2 credentials in a startling discovery from a…

PowerDNS DNSdist Vulnerability Let Attackers Cause Denial of Service Condition
30
Apr
2025

PowerDNS DNSdist Vulnerability Let Attackers Cause Denial of Service Condition

A high-severity vulnerability (CVE-2025-30194) in PowerDNS DNSdist, a widely used DNS load balancer and security tool, enables remote attackers to…

Wormable AirPlay Zero-Click RCE Flaw Allows Remote Device Hijack via Wi-Fi
30
Apr
2025

Wormable AirPlay Zero-Click RCE Flaw Allows Remote Device Hijack via Wi-Fi

A major set of vulnerabilities-collectively named “AirBorne”-in Apple’s AirPlay protocol and SDK have been unveiled, enabling an array of severe…

Arkose Labs launches Edge and Scraping Protection to secure enterprise digital borders
30
Apr
2025

Arkose Labs launches Edge and Scraping Protection to secure enterprise digital borders

Arkose Labs has announced the expansion of its security portfolio with two new offerings: Arkose Edge and Arkose Scraping Protection….

Meta Launches LlamaFirewall Framework to Stop AI Jailbreaks, Injections, and Insecure Code
30
Apr
2025

Meta Launches LlamaFirewall Framework to Stop AI Jailbreaks, Injections, and Insecure Code

Apr 30, 2025Ravie LakshmananSecure Coding / Vulnerability Meta on Tuesday announced LlamaFirewall, an open-source framework designed to secure artificial intelligence…

Artificial intelligence roles the ‘only safe jobs in banking’
30
Apr
2025

Artificial intelligence roles the ‘only safe jobs in banking’

Artificial intelligence (AI)-related roles could be the only “safe jobs” in the banking sector as financial organisations “relentlessly” press on…

This month in security with Tony Anscombe – April 2025 edition
30
Apr
2025

This month in security with Tony Anscombe – April 2025 edition

From the near-demise of MITRE’s CVE program to a report showing that AI outperforms elite red teamers in spearphishing, April…

WhatsApp Introduces AI Tools With Promise of Full Message Secrecy
30
Apr
2025

WhatsApp Introduces AI Tools With Promise of Full Message Secrecy

WhatsApp, the world’s largest messaging platform, has announced a major leap in privacy-preserving artificial intelligence (AI) with the introduction of…

Docker Registry Vulnerability Lets macOS Users Access Any Registry Without Authorization
30
Apr
2025

Docker Registry Vulnerability Lets macOS Users Access Any Registry Without Authorization

A recently discovered vulnerability in Docker Desktop for macOS is raising concerns in the developer and security communities. The flaw, which stems…

Saviynt ISPM provides insights into an organization’s identity and access posture
30
Apr
2025

Saviynt ISPM provides insights into an organization’s identity and access posture

Saviynt launched AI-powered Identity Security Posture Management (ISPM) as part of its converged Identity Cloud platform. Saviynt’s ISPM provides actionable…

Avast Antivirus Vulnerability Let Attackers Escalate Privileges
30
Apr
2025

Avast Antivirus Vulnerability Let Attackers Escalate Privileges

Security researchers have disclosed a critical vulnerability in Avast Free Antivirus that could allow attackers to gain elevated system privileges…