Saturday, October 25, 2025
Follow on LinkedIn
Home Vulnerability News

Vulnerability News

WSUS RCE Vulnerability Exploited

CISA Warns of Hackers Actively Exploiting Windows Server Update Services RCE Vulnerability in the...

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has warned organizations worldwide about active exploitation of a critical remote code execution (RCE) vulnerability in...

ChatGPT Atlas Stores OAuth Tokens Unencrypted Leads to Unauthorized Access to User Accounts

A significant vulnerability in OpenAI's newly released ChatGPT Atlas browser reveals that it stores unencrypted OAuth tokens in a SQLite database with overly permissive...
73 Unique 0-day Vulnerabilities Pwn2Own

Hackers Exploited 73 0-Day Vulnerabilities and Earned $1,024,750

The hacking community celebrated the end of Pwn2Own Ireland 2025. Researchers demonstrated their skills by identifying 73 unique zero-day vulnerabilities across different devices. The event,...

Microsoft Releases Emergency Patch For Windows Server Update Service RCE Vulnerability

Microsoft has rolled out an out-of-band emergency patch for a remote code execution (RCE) vulnerability affecting the Windows Server Update Services (WSUS). Identified as CVE-2025-59287,...

HP OneAgent Update Brokes Trust And Disconnect Devices From Entra ID

The HP OneAgent software update has disconnected Windows devices from Microsoft Entra ID. As a result, users can no longer access their corporate identities. Version...
Samsung Galaxy S25 0-Day Vulnerability

Hackers Exploited Samsung Galaxy S25 0-Day Vulnerability to Enable Camera and Track Location

At Pwn2Own Ireland 2025, cybersecurity researchers Ben R. and Georgi G. from Interrupt Labs showcased an impressive achievement by successfully exploiting a zero-day vulnerability...
Comet Browser Screenshot Feature Vulnerability

Perplexity’s Comet Browser Screenshot Feature Vulnerability Let Attackers Inject Malicious Prompts

A new vulnerability in Perplexity's Comet AI browser allows attackers to inject malicious prompts through seemingly innocuous screenshots. Disclosed on October 21, 2025, this flaw...

Hackers Exploiting Adobe Magento RCE Vulnerability Exploited in the Wild – 3 in 5...

Hackers have begun actively targeting a critical remote code execution flaw in Adobe's Magento e-commerce platform, putting thousands of online stores at immediate risk...

CISA Warns of Motex LANSCOPE Endpoint Manager Vulnerability Actively Exploited in the Wild

CISA has issued a critical alert regarding a severe vulnerability in Motex LANSCOPE Endpoint Manager, a popular tool for managing IT assets across networks. Dubbed...

Jira Software Vulnerability Let Attacker Modify Any Filesystem Path Writable By JVM process

Atlassian has disclosed a high-severity path traversal vulnerability in Jira Software Data Center and Server that enables authenticated attackers to arbitrarily write files to...
CSN

Top 10