Apple on Monday backported fixes for a recently patched security flaw that has been actively exploited in the wild.
The vulnerability in question is CVE-2025-43300 (CVSS score: 8.8), an out-of-bounds write issue in the ImageIO component that could result in memory corruption when processing a malicious image file.
"Apple is aware of a report that this issue may have been exploited in an
The web browser has quietly become one of the most critical components of enterprise infrastructure—and one of the most dangerous. Join BleepingComputer, SC Media, and Push Security on September 29 at 12:00 PM ET for a live webinar on how attackers are targeting the browser to hijack sessions, steal data, and bypass security. [...]
AI agents are rapidly becoming a core part of the enterprise, being embedded across enterprise workflows, operating with autonomy, and making decisions about which systems to access and how to use them. But as agents grow in power and autonomy, so do the risks and threats.
Recent studies show 80% of companies have already experienced unintended AI agent actions, from unauthorized system
A vulnerability identified as critical has been detected in Creative Software Community Portal up to 1.1. This affects an unknown part of the file articleview.php. This manipulation of the argument mid causes sql injection.
The identification of this vulnerability is CVE-2006-2255. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
A vulnerability was found in CPG-Nuke Dragonfly CMS 9.0.6.1. It has been declared as problematic. This impacts an unknown function of the file install.php. Such manipulation of the argument installlang leads to path traversal.
This vulnerability is traded as CVE-2006-0644. The attack may be launched remotely. Furthermore, there is an exploit available.
A vulnerability was found in cPanel 10. It has been declared as problematic. Affected by this issue is some unknown functionality of the file dohtaccess.html of the component dohtaccess.html. Executing manipulation of the argument File can lead to HTML injection.
This vulnerability is tracked as CVE-2006-4293. The attack can be launched remotely. Moreover, an exploit is present.
A vulnerability was found in cPanel WebHost Manager 3.1.0. It has been classified as problematic. The impacted element is an unknown function. This manipulation of the argument ndomain causes basic cross site scripting.
This vulnerability is registered as CVE-2006-6198. Remote exploitation of the attack is possible. Furthermore, an exploit is available.
A vulnerability has been found in cPanel 11 and classified as problematic. Affected is an unknown function. Performing manipulation of the argument Account results in basic cross site scripting.
This vulnerability was named CVE-2006-6523. The attack may be initiated remotely. In addition, an exploit is available.
A vulnerability labeled as critical has been found in PHPOffice PhpSpreadsheet up to 1.29.x/2.1.11/2.3.x/3.9.x/4.x. This affects the function setPath of the component HTML Document Handler. Such manipulation leads to server-side request forgery.
This vulnerability is documented as CVE-2025-54370. The attack can be executed remotely. There is not any exploit available.
The affected component should be upgraded.
A vulnerability labeled as critical has been found in Samsung Smart Phone. Affected by this issue is some unknown functionality of the component Exynos Baseband. Such manipulation leads to improper authorization.
This vulnerability is listed as CVE-2023-21455. The attack must be carried out from within the local network. There is no available exploit.
The affected component should be upgraded.