.NET SOAPwn flaw opens door to file writes and remote code execution via malformed WSDL

December 10, 2025Ravi LakshmananEnterprise security/web services New research reveals exploit primitives in the .NET Framework that could be leveraged against enterprise-grade applications to enable remote code execution. WatchTowr Labs, which codenamed the “invalid cast vulnerability” SOAPwn, said the issue affects Barracuda Service Center RMM, Ivanti Endpoint Manager (EPM), and Umbraco 8. However, given the popularity […]
Three weaknesses in PCIe encryption expose PCIe 5.0+ systems to data processing flaws

December 10, 2025Ravi LakshmananHardware security/vulnerabilities Three security vulnerabilities have been disclosed in the Peripheral Component Interconnect Express (PCIe) Integrity and Data Encryption (IDE) protocol specification that could expose local attackers to significant risk. According to the PCI Special Interest Group (PCI-SIG), this flaw affects PCIe Base Spec Revision 5.0 and later, a protocol mechanism introduced […]
How attackers exploit cloud misconfigurations across AWS, AI models, and Kubernetes

December 10, 2025hacker newsCloud security/threat detection Cloud security is changing. Attackers can no longer just break down doors. They are finding unlocked windows in your configuration, identity, and code. Standard security tools often miss these threats because they appear to be normal activity. To stop them, we need to see exactly how these attacks occur […]
WinRAR vulnerability CVE-2025-6218 is under active attack by multiple threat groups

December 10, 2025Ravi LakshmananVulnerabilities/Malware The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added a security flaw affecting the WinRAR file archiver and compression utility to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation. The vulnerability, tracked as CVE-2025-6218 (CVSS score: 7.8), is a path traversal bug that allows code execution. […]
Microsoft issues security fixes for 56 flaws, including active exploits and two zero-days

Microsoft ended 2025 by releasing patches for 56 security flaws in various products across the Windows platform. This includes one vulnerability that is being exploited in the wild. Of the 56 deficiencies, 3 were rated critical and 53 were rated critical. Two other flaws are listed as publicly known at the time of release. These […]
Fortinet, Ivanti, and SAP issue emergency patches for authentication and code execution flaws

December 10, 2025Ravi LakshmananVulnerabilities / Endpoint Security Fortinet, Ivanti, and SAP have moved to address critical security flaws in their products that, if successfully exploited, could lead to authentication bypass and code execution. The Fortinet vulnerability affects FortiOS, FortiWeb, FortiProxy, and FortiSwitchManager and is related to a case of improper validation of cryptographic signatures. These […]
North Korea-linked attackers exploit React2Shell to deploy new EtherRAT malware

North Korean-linked attackers may have become the latest to exploit a recently revealed critical security React2Shell flaw in React Server Components (RSC) to deliver a previously undocumented remote access Trojan called EtherRAT. “EtherRAT leverages Ethereum smart contracts for command-and-control (C2) resolution, deploys five independent Linux persistence mechanisms, and downloads its own Node.js runtime from nodejs.org,” […]
Four threat clusters use CastleLoader as GrayBravo expands its malware services infrastructure

December 9, 2025Ravi LakshmananCybersecurity/Malware Four different clusters of threat activity have been observed utilizing a malware loader known as CastleLoader, reinforcing previous assessments that this tool is being made available to other threat actors under a malware-as-a-service (MaaS) model. The threat actor behind CastleLoader has been assigned the name GrayBravo by Recorded Future’s Insikt Group, […]
Storm-0249 Using ClickFix, Fileless PowerShell, and DLL Sideloading to Escalate Ransomware Attacks

December 9, 2025Ravi LakshmananRansomware/Endpoint Security The threat actor known as Storm-0249 may be moving from its role as an initial access broker to a combination of more sophisticated tactics such as domain spoofing, DLL sideloading, and fileless PowerShell execution to facilitate ransomware attacks. “These techniques allow them to evade defenses, penetrate networks, maintain persistence, and […]
How to streamline zero trust using the shared signals framework

Zero Trust can help organizations reduce their attack surface and respond quickly to threats, but many companies still struggle to implement Zero Trust because security tools don’t reliably share signals. According to Accenture, 88% of organizations admit that they faced significant challenges when implementing such an approach. If the products cannot communicate, real-time access decisions […]