SIEM as a Service
VMware Vulnerabilities Exploited Ransomware

VMware Vulnerabilities Exploited Actively to Bypass Security Controls & Deploy Ransomware

A surge of ransomware attacks leveraging critical VMware virtualization vulnerabilities has triggered global alerts. Threat actors exploit flaws in ESXi, Workstation, and Fusion products to paralyze enterprise infrastructures. The vulnerabilities CVE-2025-22224 (CVSS 9.3), CVE-2025-22225 (CVSS...

ChatGPT Crawler Vulnerability Let Attackers Trigger DDoS Attack On Any Websites

OpenAI's ChatGPT API has been found to have a significant crawler vulnerability that enables attackers to launch Distributed Denial of Service (DDoS) attacks on arbitrary websites.  This vulnerability is a significant concern for both web...
ThinkPHP & ownCloud

Hackers Exploiting ThinkPHP & ownCloud Vulnerabilities at Large Scale

A recent surge in exploitation activity has been observed targeting two critical vulnerabilities, CVE-2022-47945 in ThinkPHP and CVE-2023-49103 in ownCloud. These attacks highlight the persistent threat posed by unpatched systems and the challenges organizations face...
Cisco AnyConnect VPN Server Vulnerability

Cisco AnyConnect VPN Server Vulnerability Let Attacker Trigger DoS Condition

Cisco disclosed a critical security vulnerability affecting Cisco Meraki MX and Z Series devices, which presents significant risks to enterprise networks.  The vulnerability tracked as CVE-2025-20212 and associated with allows authenticated remote attackers to trigger...
OWASP Top 10 2025 Smart Contract

OWASP Top 10 2025 – Most Critical Weaknesses Exploited/Discovered

The Open Web Application Security Project (OWASP) has released its much-anticipated Smart Contract Top 10 for 2025, a comprehensive awareness document aimed at equipping Web3 developers and security teams with the knowledge to combat...
Zero-Day Vulnerability in PDF Files

Zero-Day Vulnerability in PDF Files Leaking NTLM Data in Adobe & Foxit Reader

Cybersecurity researchers at EXPMON have uncovered an intriguing "zero-day behavior" in PDF samples that could potentially be exploited by attackers to leak sensitive NTLM authentication data. The discovery highlights vulnerabilities in how Adobe Reader...
Apache Tomcat RCE Vulnerability Exploited

Critical Apache Tomcat RCE Vulnerability Exploited in Just 30hrs of Public Exploit

Security researchers have confirmed that a critical remote code execution (RCE) vulnerability in Apache Tomcat, tracked as CVE-2025-24813, is being actively exploited in the wild. The vulnerability, which enables attackers to take control of servers...

FortiOS & FortiProx 0-Day Allows Attackers Hijacks Firewall & Gain Super Admin Access

Fortinet has issued an urgent warning about actively exploiting an already patched authentication bypass zero-day vulnerability (CVE-2025-24472) affecting its FortiOS and FortiProxy products. This critical flaw allows remote attackers to gain super-admin privileges by sending...
Critical LDAP Client Vulnerability Let Attackers Gain Vulnerable System Access Remotely

Critical LDAP Client Vulnerability Let Attackers Gain Vulnerable System Access Remotely

A newly disclosed critical vulnerability, identified as CVE-2024-49124, has been classified as a Remote Code Execution (RCE) flaw with a severity rating of Critical by Microsoft. This vulnerability explicitly impacts systems utilizing the Lightweight...
VMware Avi Load Balancer Vulnerability

VMware Avi Load Balancer Vulnerability Let Attackers Gain Database Access

Broadcom disclosed a critical vulnerability affecting its Avi Load Balancer product. The vulnerability, identified as CVE-2025-22217, is an unauthenticated blind SQL injection vulnerability that could allow attackers with network access to execute specially crafted...
SIEM as a Service

Recent Posts