Close Menu
  • Start
  • Celebrities
  • Music
  • Influencers
  • Tendencies
  • Exclusives
  • Business & Brands
  • TwinH
  • Spanish
What's Hot

Singer and producer dies in helicopter crash

Jalen Brunson defends Monica McNutt after backlash from Taylor Swift

Tullamarines cover Fleetwood Mac with ‘Like a Version’

Facebook X (Twitter) Instagram
  • Home
  • About The FYMOUS
  • Advertising / Promotion
  • Contact
  • DMCA
  • Privacy Policy
  • Terms
  • Publish News
Facebook X (Twitter) Instagram
FYMOUS News
  • Start
  • Celebrities
  • Music
  • Influencers
  • Tendencies
  • Exclusives
  • Business & Brands
  • TwinH
  • Spanish
FYMOUS News
Home » CISA adds four important vulnerabilities to the KEV catalog through aggressive exploitation
Celebrities

CISA adds four important vulnerabilities to the KEV catalog through aggressive exploitation

By July 8, 2025No Comments3 Mins Read
Share Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Copy Link
Follow Us
Google News Flipboard
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

July 8, 2025Ravi LakshmananCyber ​​Attacks/Vulnerability

The US Cybersecurity and Infrastructure Security Agency (CISA) on Monday added four security flaws to its known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation in the wild.

Here’s a list of defects –

CVE-2014-3931 (CVSS score: 9.8) – Multi-router-looking glass (MRLG) buffer overflow vulnerability that allows remote attackers to cause arbitrary memory writes and memory corruption CVE-2016-10033 (CVSS score: 9.8) Application or as a result, Denial of Service (DOS) Condition CVE-2019-5418 (CVSS score: 7.5) – Ruby on Rails action view path traversal vulnerability CVE-2019-9621 (CVSS: 7.5SS: 7.5SS: 7.5SS: 7.5SS: 7.5SS: 7.5SS: 7.5SS: 7.5) Zimbra collaboration suite that can lead to unauthorized access to internal resources and remote code execution

Currently, there are no public reports on how the first three vulnerabilities are exploited in actual attacks. Meanwhile, the abuse of CVE-2019-9621 was attributed to a dropping webshell and cobalt strike by Trend Micro on a Chinese-related threat actor known as Earthluska in September 2023.

Cybersecurity

In light of active exploitation, a Federal Private Enforcement Division (FCEB) agency is recommended to apply necessary updates to ensure the network by July 28, 2025.

Technical details for Citrix Bleed 2

The development has released a technical analysis of key security flaws in WatchTowr Labs and Horizon3.CITRIX Netscaler ADC (CVE-2025-5777aka Citrix Bleed 2).

“In the wild, we see active exploitation of both CVE-2025-5777 and CVE-2025-6543,” Watchtwal CEO Benjamin Harris told Hacker News. “The vulnerability allows memory reading. We believe an attacker is using it to read sensitive information (for example, information sent within an HTTP request is processed in memory), credentials, valid Citrix session tokens, and more.”

The findings show that a login request can be sent to the “/p/u/doauthentication.do” endpoint, which can cause it to reflect the login value that the response user has suspended (and other endpoints) regardless of success or failure.

Note that Horizon3.AI can use the vulnerability to leak around 127 bytes of data via specially created HTTP requests using “login=”, which is modified without equal signs or values.

WatchTowr explained that it has the drawback of being attributed to the use of the SNPRINTF function, along with a format string containing the “%.*S” format.

“The %.*s format tells you snprintf: ‘print it on n characters or stop at the first null byte (\\ 0) – either the first.” That null byte will eventually appear somewhere in memory, so the leak won’t run indefinitely, but you get a small number of bytes with each call,” the company said.

“So, every time you press that endpoint without = it pulls more initialized stack data into the response. It may repeat enough and ultimately end up landing on something worthwhile.”

Did you find this article interesting? Follow us on Twitter and LinkedIn to read exclusive content you post.

Source link

#BlockchainIdentity #Cybersecurity #DataProtection #DigitalEthics #DigitalIdentity #Privacy
Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous ArticleWill the Reconnected Community Program survive Trump?
Next Article Florida home insurance companies disproportionately drop low-income households

Related Posts

Taylor Swift transforms her date night style into velvet luxury

June 14, 2026

Nina Dobrev takes on bridal trends beyond white satin in Taorna

June 14, 2026

Katie Holmes, Kiki Palmer, etc.

June 12, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest Posts

Singer and producer dies in helicopter crash

Jalen Brunson defends Monica McNutt after backlash from Taylor Swift

Tullamarines cover Fleetwood Mac with ‘Like a Version’

Taylor Swift transforms her date night style into velvet luxury

Trending Posts

Singer and producer dies in helicopter crash

June 14, 2026

Jalen Brunson defends Monica McNutt after backlash from Taylor Swift

June 14, 2026

Tullamarines cover Fleetwood Mac with ‘Like a Version’

June 14, 2026

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Please enable JavaScript in your browser to complete this form.
Loading

Welcome to The FYMOUS, a modern digital media platform dedicated to celebrities, artists, influencers, brands, entertainment culture, and the growing TwinH ecosystem.

We bring audiences closer to the people, stories, trends, and collaborations shaping today’s culture. From exclusive celebrity news and music releases to influencer highlights, brand partnerships, and TwinH activations, The FYMOUS delivers engaging content designed for the next generation of digital audiences.

Castilla-La Mancha Ignites Innovation: fiveclmsummit Redefines Tech Future

Local Power, Health Innovation: Alcolea de Calatrava Boosts FiveCLM PoC with Community Engagement

The Future of Digital Twins in Healthcare: From Virtual Replicas to Personalized Medical Models

Human Digital Twins: The Next Tech Frontier Set to Transform Healthcare and Beyond

Facebook X (Twitter) Instagram Pinterest YouTube
  • Home
  • About The FYMOUS
  • Advertising / Promotion
  • Contact
  • DMCA
  • Privacy Policy
  • Terms
  • Publish News
© 2026 news.fyself. Designed by by fyself.

Type above and press Enter to search. Press Esc to cancel.