SIEM as a Service
Wordpress Plugin Vulnerability Code Execution

WordPress Plugin Vulnerability Exposes 10,000 Sites to Code Execution Attacks

A critical security flaw in the GiveWP Donation Plugin tracked as CVE-2025-0912, has exposed over 100,000 WordPress websites to unauthenticated remote code execution (RCE) attacks.  The vulnerability, scoring a maximum CVSS 9.8 (Critical) severity rating,...
Cisco Webex BroadWorks Vulnerability

Cisco Webex for BroadWorks Vulnerability Let Remote Attackers Access Data & Credentials

A newly disclosed vulnerability in Cisco Webex for BroadWorks Release 45.2 enables remote attackers to intercept sensitive credentials and user data when Session Initiation Protocol (SIP) communications lack encryption. This vulnerability, rated as low severity...

CISA Warns of Actively Exploited VMware Vulnerabilities, Urges Immediate Patching

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) issued an urgent alert on March 4, 2025, adding three critical VMware vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog following confirmed in-the-wild exploitation. The vulnerabilities...
Vim Editor Vulnerability Exploited

Vim Editor Vulnerability Exploited Via TAR Files to Trigger Code Execution

The Vim text editor vulnerability CVE-2025-27423 is a high-severity issue that allows for arbitrary code execution via malicious TAR archives. Affecting Vim versions prior to 9.1.1164, this flaw in the bundled tar.vim plugin exposes users...
HPE Remote Support Tool

HPE Remote Support Tool Vulnerability Let Attackers Execute Arbitrary code – PoC Released

A newly disclosed vulnerability in Hewlett Packard Enterprise's (HPE) Insight Remote Support tool enables unauthenticated attackers to execute arbitrary code on vulnerable systems, with proof-of-concept (PoC) exploit code now publicly available.  Tracked as CVE-2024-53676, this...
Zoho ADSelfService Plus Vulnerability

Zoho ADSelfService Plus Vulnerability Let Attackers Gain Unauthorized Access

Zoho has patched a high-severity vulnerability (CVE-2025-1723) in its ADSelfService Plus software, a widely used self-service password management and single sign-on solution.  The flaw, discovered in builds 6510 and earlier, could enable attackers to bypass...

NVIDIA Warns of Multiple Vulnerabilities that Let Attackers Execute Malicious Code

NVIDIA has issued urgent security advisories addressing multiple vulnerabilities in its Hopper HGX 8-GPU High-Performance Computing (HMC) platforms, including a high-severity flaw (CVE-2024-0114, CVSS 8.1) that permits unauthorized code execution, privilege escalation, and systemic...

Chrome 134 Released, Fixes 14 Vulnerabilities That Could Crash the Browser

Google has rolled out Chrome 134 to the stable channel, delivering critical security updates that resolve 14 vulnerabilities, including high-severity flaws that could enable browser crashes, data leaks, or arbitrary code execution.  The update (versions...
Android RAT

New Android RAT Dubbed “AndroRAT” Attacking to Steal Pattern, PIN & Passcodes

A newly identified variant of the Android Remote Access Tool (RAT), AndroRAT, has emerged as a critical cybersecurity threat, leveraging sophisticated techniques to steal device unlock patterns, PINs, and passcodes.  The malware, first documented in...

VMware ESXi Vulnerabilities Exploited in Wild to Execute Malicious Code

VMware has issued a critical security advisory (VMSA-2025-0004) warning of active exploitation of three vulnerabilities in its ESXi, Workstation, and Fusion products. These flaws, CVE-2025-22224, CVE-2025-22225, and CVE-2025-22226, allow attackers to execute malicious code,...
SIEM as a Service

Recent Posts