A vulnerability classified as problematic was found in MongoDB mongosh up to 2.3.8. This vulnerability affects unknown code of the component Control Character Handler. The manipulation leads to improper neutralization of escape, meta, or control sequences.
This vulnerability was named CVE-2025-1693. The attack can be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability, which was classified as critical, has been found in MongoDB mongosh up to 2.2.x. Affected by this issue is some unknown functionality of the file C:\node_modules\ of the component File Handler. The manipulation leads to untrusted search path.
This vulnerability is handled as CVE-2025-1756. An attack has to be approached locally. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability, which was classified as problematic, has been found in MongoDB mongosh up to 2.3.8. This issue affects some unknown processing of the component Control Character Handler. The manipulation leads to injection.
The identification of this vulnerability is CVE-2025-1691. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability, which was classified as problematic, was found in MongoDB mongosh up to 2.3.8. Affected is an unknown function of the component Control Character Handler. The manipulation leads to improper neutralization of escape, meta, or control sequences.
This vulnerability is traded as CVE-2025-1692. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability was found in Autodesk Navisworks Freedom, Navisworks Simulate and Navisworks Manage 2025. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the component DWFX File Handler. The manipulation leads to out-of-bounds read.
This vulnerability is known as CVE-2025-1659. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability classified as critical has been found in Autodesk Navisworks Freedom, Navisworks Simulate and Navisworks Manage 2025. This affects an unknown part of the component DWFX File Handler. The manipulation leads to out-of-bounds read.
This vulnerability is uniquely identified as CVE-2025-1658. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability classified as critical was found in Autodesk Navisworks Freedom, Navisworks Simulate and Navisworks Manage 2025. This vulnerability affects unknown code of the component DWFX File Handler. The manipulation leads to buffer overflow.
This vulnerability was named CVE-2025-1660. The attack can be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
Chris Krebs and SentinelOne Targeted as Trump Still Trumpets 2020 Election Lies The White House said President Trump has ordered a probe into former Cybersecurity and Infrastructure Security Agency Director Chris Krebs' government service, revoked any security clearances he holds and suspended security clearances issued to his employer, SentinelOne.
Also: PoisonSeed Phishing Campaign, FTX Clients Face Reimbursement Hurdle This week, Trump administration disbanded a Justice Department crypto unit, the U.S. Securities and Exchange Commission will review crypto guidance, Usual pledged up to $16M in bug bounties, a PoisonSeed phishing campaign, FTX repayment plan troubles and a Coinbase 2FA error.
Also, Oracle Denies Cloud Breach, Blames Hack on Obsolete Servers This week, Port of Seattle notified victims, Oracle blamed hack on obsolete servers, Google and Microsoft released April patches, WK Kellogg breached, six arrested in Spain for AI-investment scam, Scattered Spider's "King Bob" pleaded guilty, SmokeLoader users busted.
California Health Plan With 6 Million Members Blames Software Configuration Error Blue Shield of California is notifying health plan members that their protected health information was potentially shared for nearly three years with Google for advertising purposes because of the way Google Analytics online tracking tools were configured on the insurer's websites.
3 Key Strategies for Security Leaders for Managing On-Premises and Cloud Identities Machine identities now outnumber human identities 45:1, creating new security risks in an increasingly digital world. As organizations expand across hybrid and multi-cloud environments, fragmented identities become harder to manage, requiring proactive strategies to enhance security and governance.
Lowering Machine Identity Risks in AI, ML and Bot Workflows While AI, ML and bot workflows boost efficiency, they also expand the attack surface. Over-permissioned identities, exploitable vulnerabilities and AI misuse pose significant security risks. AI-driven security tools can mitigate these risks by detecting anomalies and automating threat response.