Tag: zero-day vulnerability

Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: Critical VMware vCenter Server vulnerability

Cybersecurity Threat Advisory: Critical VMware vCenter Server vulnerability

CISA has added a critical VMware vCenter Server vulnerability to its Known Exploited Vulnerabilities catalog, confirming active exploitation in the wild. The flaw is tracked as CVE‑2024‑37079 with a CVSS score of 9.8. It was originally patched in June 2024...

/ January 27, 2026
Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: Gogs zero-day vulnerability

Cybersecurity Threat Advisory: Gogs zero-day vulnerability

A high-severity, unpatched vulnerability in the Gogs self-hosted Git service is being tracked as CVE-2025-8110. With a CVSS score of 8.7, it is under active exploitation, with more than 700 compromised instances exposed on the internet. Review this Cybersecurity Threat...

/ December 15, 2025
Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: VMware zero-day vulnerability exploited

Cybersecurity Threat Advisory: VMware zero-day vulnerability exploited

Threat actors have actively exploited a zero-day vulnerability in Broadcom VMware Tools and VMware Aria Operations (CVE-2025-41244) in the wild. The China-linked group UNC5174 (aka Uteus/Uetus) has exploited the flaw for privilege escalation in VMware-targeted attacks. Continue reading this edition...

/ October 1, 2025 / 1 Comment
Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: WinRAR zero-day exploited

Cybersecurity Threat Advisory: WinRAR zero-day exploited

A critical path traversal zero-day vulnerability — tracked as CVE‑2025‑8088 — has been identified in WinRAR and related components (Windows RAR, UnRAR.dll, and the portable UnRAR source code), and is currently being actively exploited. Review the details in this Cybersecurity...

/ August 12, 2025
Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: CrushFTP zero-day vulnerability

Cybersecurity Threat Advisory: CrushFTP zero-day vulnerability

CrushFTP has disclosed a new critical vulnerability, CVE-2025-54309, which is currently being exploited in the wild. One indicator of compromise is a “last_logins” value set for internal default accounts. Review the details in this Cybersecurity Threat Advisory to help minimize...

/ July 23, 2025
Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: Microsoft SQL server zero-day vulnerability

Cybersecurity Threat Advisory: Microsoft SQL server zero-day vulnerability

A critical information disclosure vulnerability has been identified in Microsoft SQL Server, designated as CVE-2025-49719 with a CVSS score of 7.5. This vulnerability allows unauthorized attackers to access sensitive data over a network, posing a serious risk to organizations that...

/ July 18, 2025
Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: Microsoft zero-day vulnerability

Cybersecurity Threat Advisory: Microsoft zero-day vulnerability

Microsoft disclosed a vulnerability, CVE-2025-26633, affecting the Microsoft Management Console (MMC). A known threat actor called EncryptHub is exploiting it. Read this Cybersecurity Threat Advisory to learn how to mitigate your risks from this zero-day vulnerability. What is the threat?...

/ March 28, 2025
Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: Apple critical zero-day vulnerability

Cybersecurity Threat Advisory: Apple critical zero-day vulnerability

Apple has issued emergency security updates to address a critical zero-day vulnerability, CVE-2025-24200, which has been exploited in targeted and “extremely sophisticated” attacks. This vulnerability affects iPhone and iPad users, posing significant risks to user security. Review the details of...

/ February 13, 2025
Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: Fortinet zero-day vulnerability

Cybersecurity Threat Advisory: Fortinet zero-day vulnerability

A critical zero-day vulnerability has been found affecting Fortinet FortiOS and FortiProxy devices. This vulnerability enables attackers to bypass authentication and gain privileges. Keep reading this Cybersecurity Threat Advisory for information to keep your environment safe. What is the threat?...

/ January 15, 2025
Cybersecurity Threat Advisory
Cybersecurity Threat Advisory: Ivanti zero-day vulnerabilities

Cybersecurity Threat Advisory: Ivanti zero-day vulnerabilities

Two vulnerabilities have been identified in Ivanti Connect Secure and Ivanti Policy Secure Gateways, CVE-2023-46805 and CVE-2024-21887 respectively, which when exploited together allow for unauthenticated remote code execution. These CVEs affect all supported versions of the products. Continue reading this...

/ January 16, 2024