SIEM as a Service
Linux USB-Audio Driver Out-of-Bounds Vulnerability

CISA Warns of Linux USB-Audio Driver Out-of-Bounds Vulnerability Exploited in the Wild

The Cybersecurity and Infrastructure Security Agency (CISA) has added two significant Linux kernel vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog yesterday, confirming both flaws are being actively weaponized in targeted attacks. Federal agencies have...
VMware Patches Multiple 47 Vulnerabilities

VMware Patches Multiple 47 Vulnerabilities VMware Tanzu Greenplum Backup & Components

VMware has released critical security updates to address 47 vulnerabilities across multiple VMware Tanzu Greenplum products, including 29 issues in VMware Tanzu Greenplum Backup and Restore and 18 bugs in various components of VMware...
Windows Kerberos Vulnerability

Windows Kerberos Vulnerability Let Attackers Bypass Security Features & Access Credentials

Microsoft has released a patch for a critical Windows Kerberos vulnerability (CVE-2025-29809) that allows attackers to bypass security features and potentially access sensitive authentication credentials.  The flaw, addressed in the April 2025 Patch Tuesday updates,...
Microsoft Windows CLFS Vulnerability

CISA Warns of Microsoft Windows CLFS Vulnerability Exploited in Wild

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical Microsoft Windows vulnerability to its Known Exploited Vulnerabilities (KEV) catalog.  The flaw in the Windows Common Log File System (CLFS) driver, tracked as...
Apache mod_auth_openidc Vulnerability

Apache mod_auth_openidc Vulnerability Exposes Protected Content to Unauthenticated Users

A significant security vulnerability in Apache's mod_auth_openidc module has been discovered that could allow unauthorized access to protected web resources.  The flaw, tracked as CVE-2025-31492 and rated 8.2 on the CVSSv4 scale, affects widely deployed...
Ivanti Connect Secure Devices

5000+ Exposed Ivanti Connect Secure Devices Vulnerable to RCE Attacks

Over 5,113 Ivanti Connect Secure VPN appliances remain unpatched and vulnerable to the active exploitation of CVE-2025-22457, a critical stack-based buffer overflow vulnerability that enables remote code execution (RCE).  The Shadowserver Foundation's recent scans revealed...
CISA Warns of CrushFTP Authentication Bypass Vulnerability

CISA Warns of CrushFTP Authentication Bypass Vulnerability Exploited in Attacks

The Cybersecurity and Infrastructure Security Agency (CISA) has added a critical authentication bypass vulnerability in CrushFTP file transfer software to its Known Exploited Vulnerabilities (KEV) Catalog.  Designated as CVE-2025-31161, this vulnerability is actively being exploited...
AWS Systems Manager Plugin Vulnerability

AWS Systems Manager Plugin Vulnerability Let Attackers Execute Arbitrary Code

A critical vulnerability in the AWS Systems Manager (SSM) Agent that could allow attackers to execute arbitrary code with elevated privileges.  The vulnerability, stemming from improper input validation within the ValidatePluginId function, affects a core...
Fortinet Warns of FortiSwitch Vulnerability

Fortinet Warns of FortiSwitch Vulnerability Let Attackers Modify Admin Passwords

Fortinet has issued a critical advisory regarding a newly discovered vulnerability in its FortiSwitch product line. The vulnerability, identified as an unverified password change vulnerability (CWE-620), could allow remote, unauthenticated attackers to modify administrative...
NIST Announced That All CVEs Published

NIST Will Mark All CVEs Published Before 01/01/2018 as ‘Deferred’

The National Institute of Standards and Technology (NIST) announced on April 2, 2025, that all Common Vulnerabilities and Exposures (CVEs) with a published date prior to January 1, 2018, will be marked as "Deferred"...
SIEM as a Service

Recent Posts

Incident Response Unified Logging Standards

Incident Response Teams Call For Unified Logging Standards In Breach Scenarios

In today's rapidly evolving cybersecurity landscape, incident response teams are increasingly advocating for unified logging standards to effectively combat security breaches. The absence of...