Aggregator
CVE-2025-30445 | Apple visionOS type confusion
CVE-2025-31197 | Apple tvOS denial of service
CVE-2025-31197 | Apple iOS/iPadOS denial of service
CVE-2025-31197 | Apple macOS denial of service
CVE-2025-31197 | Apple visionOS denial of service
CISA Releases Three Industrial Control Systems Advisories
CISA released three Industrial Control Systems (ICS) advisories on April 29, 2025. These advisories provide timely information about current security issues, vulnerabilities, and exploits surrounding ICS.
- ICSA-25-119-01 Rockwell Automation ThinManager
- ICSA-25-119-02 Delta Electronics ISPSoft
- ICSA-25-105-05 Lantronix XPort (Update A)
CISA encourages users and administrators to review newly released ICS advisories for technical details and mitigations.
CISA Adds One Known Exploited Vulnerability to Catalog
CISA has added one new vulnerability to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation.
- CVE-2025-31324 SAP NetWeaver Unrestricted File Upload Vulnerability
These types of vulnerabilities are frequent attack vectors for malicious cyber actors and pose significant risks to the federal enterprise.
Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities established the Known Exploited Vulnerabilities Catalog as a living list of known Common Vulnerabilities and Exposures (CVEs) that carry significant risk to the federal enterprise. BOD 22-01 requires Federal Civilian Executive Branch (FCEB) agencies to remediate identified vulnerabilities by the due date to protect FCEB networks against active threats. See the BOD 22-01 Fact Sheet for more information.
Although BOD 22-01 only applies to FCEB agencies, CISA strongly urges all organizations to reduce their exposure to cyberattacks by prioritizing timely remediation of Catalog vulnerabilities as part of their vulnerability management practice. CISA will continue to add vulnerabilities to the catalog that meet the specified criteria.
CVE-2022-3034 | Mozilla Thunderbird up to 91.13.0 HTML Email information disclosure (Bug 1745751 / Nessus ID 208589)
CVE-2022-3352 | vim up to 9.0.0598 use after free (FEDORA-2022-40161673a3 / Nessus ID 211239)
CVE-2022-1097 | Mozilla Firefox up to 98 NSSToken Object use after free (Bug 1745667 / Nessus ID 208650)
CVE-2022-28281 | Mozilla Firefox up to 98 WebAuthN Extension out-of-bounds write (Bug 1755621 / Nessus ID 208650)
CVE-2022-28282 | Mozilla Firefox up to 98 rel use after free (Bug 1751609 / Nessus ID 208650)
Половина смартфонов в мире беззащитна. А ваш в их числе?
This month in security with Tony Anscombe – April 2025 edition
Вместо защиты — выкуп: 86% компаний капитулировали перед атаками
ResolverRAT Targets Healthcare and Pharmaceutical Sectors Through Sophisticated Phishing Attacks
A previously undocumented remote access trojan (RAT) named ResolverRAT has surfaced, specifically targeting healthcare and pharmaceutical organizations worldwide. First observed as recently as March 10, 2025, this malware distinguishes itself from related threats like Rhadamanthys and Lumma through its sophisticated in-memory execution and multi-layered evasion techniques. Morphisec, a leading cybersecurity firm, has detailed the malware’s […]
The post ResolverRAT Targets Healthcare and Pharmaceutical Sectors Through Sophisticated Phishing Attacks appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.