Unpatched Gog exploits zero-day in over 700 instances in active attack

December 11, 2025Ravi LakshmananVulnerability / Cloud Security New research from Wiz reveals that Gogs is actively exploiting unpatched high-severity security vulnerabilities, with over 700 compromised instances accessible over the internet. This flaw, tracked as CVE-2025-8110 (CVSS score: 8.7), is a case of file overwriting in the file update API of a Go-based self-hosted Git service. […]

Chrome targeted by active field exploit related to undisclosed high-severity flaw

December 11, 2025Ravi LakshmananZero-day/vulnerabilities Google shipped a security update for its Chrome browser on Wednesday that addressed three security flaws, including one it announced was being exploited in the wild. This vulnerability is rated as High Severity and is tracked under Chromium issue tracking ID 466192044. Unlike other disclosures, Google has chosen to keep information […]

Active attack exploits Gladinet’s hard-coded keys to gain unauthorized access and code execution

December 11, 2025Ravi LakshmananVulnerabilities/Encryption Huntress warns that a new vulnerability in Gladinet’s CentreStack and Triofox products due to the use of hard-coded encryption keys is being actively exploited, affecting nine organizations so far. “An attacker could exploit this as a way to access the web.config file, potentially opening the door to deserialization and remote code […]

React2Shell exploit delivers crypto miners and new malware across multiple sectors

React2Shell continues to see heavy exploitation, with threat actors leveraging the highest severity security flaws in React Server Components (RSC) to deliver cryptocurrency miners and a range of previously undocumented malware families, according to new research from Huntress. This includes a Linux backdoor called PeerBlight, a reverse proxy tunnel called CowTunnel, and a Go-based post-exploitation […]

.NET SOAPwn flaw opens door to file writes and remote code execution via malformed WSDL

December 10, 2025Ravi LakshmananEnterprise security/web services New research reveals exploit primitives in the .NET Framework that could be leveraged against enterprise-grade applications to enable remote code execution. WatchTowr Labs, which codenamed the “invalid cast vulnerability” SOAPwn, said the issue affects Barracuda Service Center RMM, Ivanti Endpoint Manager (EPM), and Umbraco 8. However, given the popularity […]

Three weaknesses in PCIe encryption expose PCIe 5.0+ systems to data processing flaws

December 10, 2025Ravi LakshmananHardware security/vulnerabilities Three security vulnerabilities have been disclosed in the Peripheral Component Interconnect Express (PCIe) Integrity and Data Encryption (IDE) protocol specification that could expose local attackers to significant risk. According to the PCI Special Interest Group (PCI-SIG), this flaw affects PCIe Base Spec Revision 5.0 and later, a protocol mechanism introduced […]

WinRAR vulnerability CVE-2025-6218 is under active attack by multiple threat groups

December 10, 2025Ravi LakshmananVulnerabilities/Malware The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added a security flaw affecting the WinRAR file archiver and compression utility to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation. The vulnerability, tracked as CVE-2025-6218 (CVSS score: 7.8), is a path traversal bug that allows code execution. […]

How attackers exploit cloud misconfigurations across AWS, AI models, and Kubernetes

December 10, 2025hacker newsCloud security/threat detection Cloud security is changing. Attackers can no longer just break down doors. They are finding unlocked windows in your configuration, identity, and code. Standard security tools often miss these threats because they appear to be normal activity. To stop them, we need to see exactly how these attacks occur […]

Fortinet, Ivanti, and SAP issue emergency patches for authentication and code execution flaws

December 10, 2025Ravi LakshmananVulnerabilities / Endpoint Security Fortinet, Ivanti, and SAP have moved to address critical security flaws in their products that, if successfully exploited, could lead to authentication bypass and code execution. The Fortinet vulnerability affects FortiOS, FortiWeb, FortiProxy, and FortiSwitchManager and is related to a case of improper validation of cryptographic signatures. These […]