Aggregator
CVE-2025-27820 | Apache HttpComponents up to 5.4.2 PSL Validation privilege escalation
INC
Critical Commvault RCE vulnerability fixed, PoC available (CVE-2025-34028)
If your organization is using Commvault Command Center for your data protection, backup creation, configuration and restoration needs, you should check whether your on-premise installation has been upgraded to patch a critical vulnerability (CVE-2025-34028) that could allow unauthenticated remote code execution. About CVE-2025-34028 CVE-2025-34028 is a path traversal vulnerability affecting Commvault Command Center (Innovation Release) versions from 11.38.0 to 11.38.19, on Windows and Linux. It was unearthed by watchTowr researcher Sonny Macdonald, who discovered an … More →
The post Critical Commvault RCE vulnerability fixed, PoC available (CVE-2025-34028) appeared first on Help Net Security.
CVE-2023-36909 | Microsoft Windows up to Server 2022 Message Queuing denial of service
CVE-2023-35376 | Microsoft Windows up to Server 2022 Message Queuing denial of service
CVE-2023-35377 | Microsoft Windows up to Server 2022 Message Queuing denial of service
CVE-2023-38254 | Microsoft Windows up to Server 2022 Message Queuing denial of service
CVE-2023-36533 | Zoom SDK up to 5.14.6 resource consumption
CISA Releases Seven Industrial Control Systems Advisories
CISA released seven Industrial Control Systems (ICS) advisories on April 24, 2025. These advisories provide timely information about current security issues, vulnerabilities, and exploits surrounding ICS.
- ICSA-25-114-01 Schneider Electric Modicon Controllers
- ICSA-25-114-02 ALBEDO Telecom Net.Time - PTP/NTP Clock
- ICSA-25-114-03 Vestel AC Charger
- ICSA-25-114-04 Nice Linear eMerge E3
- ICSA-25-114-05 Johnson Controls Software House iSTAR Configuration Utility (ICU) Tool
- ICSA-25-114-06 Planet Technology Network Products
- ICSA-24-338-05 Fuji Electric Monitouch V-SFT (Update A)
CISA encourages users and administrators to review newly released ICS advisories for technical details and mitigations.
NIST Updates Critical Wildfire Evacuation and Sheltering Guidance
Linux 'io_uring' security blindspot allows stealthy rootkit attacks
CVE-2004-0613 | osTicket 1.2 Attachment privileges management (EDB-24225 / Nessus ID 13645)
DirectDefense launches Security Essentials to protect growing SMBs
DirectDefense has launched DirectDefense Security Essentials, a fully managed, subscription-based security program purpose-built for small to mid-sized businesses (SMBs). With Security Essentials, DirectDefense is addressing the critical security needs of the underserved SMB market by combining virtual CISO (vCISO) services, identity threat protection, and vulnerability management at a price point designed for growing businesses. Many SMBs face high exposure to cyber threats but lack the budget, staff, and technology to respond effectively. SMBs also struggle … More →
The post DirectDefense launches Security Essentials to protect growing SMBs appeared first on Help Net Security.