Tag: Cybersecurity Threat Advisory

Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: Android framework exploits

Cybersecurity Threat Advisory: Android framework exploits

Google released the December 2025 Android Security Update to address 107 vulnerabilities across the Android OS and vendor components. The most critical aspect of this release is the remediation of two high-severity vulnerabilities. Review this Cybersecurity Threat Advisory to limit...

/ December 6, 2025
Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: Critical React2Shell vulnerability

Cybersecurity Threat Advisory: Critical React2Shell vulnerability

There are two critical unauthenticated remote code execution vulnerabilities in the React Server Components (RSC) “Flight” protocol. Continue reading this Cybersecurity Threat Advisory to learn how to protect you and your clients’ environments. What is the threat? These critical vulnerabilities...

/ December 6, 2025
Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: FortiWeb vulnerabilities in unsupported versions

Cybersecurity Threat Advisory: FortiWeb vulnerabilities in unsupported versions

Security researchers and CISA have warned that Fortinet FortiWeb appliances with unsupported versions are actively being exploited. Fortinet has issued patches for supported versions, but many organizations still run outdated FortiWeb devices, leaving them exposed. Read the Cybersecurity Threat Advisory...

/ December 5, 2025
Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: Oracle Identity Manager vulnerability

Cybersecurity Threat Advisory: Oracle Identity Manager vulnerability

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a critical flaw impacting Oracle Identity Manager to its Known Exploited Vulnerabilities (KEV) catalog. Read this Cybersecurity Threat Advisory to learn about the current risk and apply relevant patches now. What...

/ November 26, 2025
Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: Fluent Bit vulnerabilities

Cybersecurity Threat Advisory: Fluent Bit vulnerabilities

Five vulnerabilities have been identified in Fluent Bit. Upon a successful exploitation, attackers could bypass authentication, perform path traversal, execute remote code, or cause denial of service. Review this Cybersecurity Threat Advisory now to secure you or your clients’ infrastructure....

/ November 26, 2025
Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: Critical Grafana SCIM vulnerability

Cybersecurity Threat Advisory: Critical Grafana SCIM vulnerability

A critical security vulnerability in Grafana Enterprise could allow attackers to escalate privileges and impersonate users. Tracked as CVE-2025-41115, the flaw carries the maximum CVSS score of 10.0. Continue reading this Cybersecurity Threat Advisory to learn how to protect you...

/ November 25, 2025
Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: 7-Zip symbolic link vulnerability

Cybersecurity Threat Advisory: 7-Zip symbolic link vulnerability

Attackers are actively exploiting a high-severity 7-Zip vulnerability, CVE-2025-11001. Attackers use malicious archives to abuse symbolic links, forcing writes outside the intended extraction directory and enabling remote code execution (RCE) when users interact. Review this Cybersecurity Threat Advisory for remediation...

/ November 25, 2025
Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: Fortinet FortiWeb vulnerability exploited

Cybersecurity Threat Advisory: Fortinet FortiWeb vulnerability exploited

A Fortinet FortiWeb path traversal-driven authentication bypass vulnerability is actively exploited in the wild, affecting versions prior to 8.0.2. Researchers have observed automated spraying at scale. Review this Cybersecurity Threat Advisory to learn how to best protect your environment and...

/ November 18, 2025
Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: Severe N-able vulnerabilities

Cybersecurity Threat Advisory: Severe N-able vulnerabilities

Two critical vulnerabilities were disclosed by N-able in the N-central RMM platform, with one having a maximum severity rating. To help safeguard you and your customers’ environments, please review the best practices outlined in this Cybersecurity Threat Advisory. What is...

/ November 18, 2025
Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: Cisco and Citrix zero-day exploits

Cybersecurity Threat Advisory: Cisco and Citrix zero-day exploits

An advanced threat actor is exploiting two previously disclosed zero-day vulnerabilities in Cisco Identity Services Engine (ISE) and Citrix NetScaler ADC to deploy custom malware and maintain persistence on targeted networks. Reports indicate the attacker is chaining appliance exploits to...

/ November 17, 2025