Microsoft Fixes Critical WSUS RCE Flaw CVE-2025-59287 Under Active Attack

Microsoft Fixes Critical WSUS RCE Flaw CVE-2025-59287 Under Active Attack

Microsoft has released urgent updates to address the critical WSUS RCE vulnerability CVE-2025-59287, which is currently under active exploitation. The flaw allows unauthorized attackers to execute code over a network, necessitating immediate patching for affected Windows Server versions.
Oct 25, 2025 CVE: CVE-2025-59287
ChatGPT Atlas Faces Clipboard Injection Vulnerability

ChatGPT Atlas Faces Clipboard Injection Vulnerability

OpenAI's new AI web browser, ChatGPT Atlas, has been found to be vulnerable to clipboard injection attacks. This vulnerability could allow malicious actors to manipulate the user's clipboard, potentially leading to security breaches.
Oct 24, 2025
Critical Vulnerability Found in Motex Lanscope Endpoint Manager

Critical Vulnerability Found in Motex Lanscope Endpoint Manager

CISA has issued an urgent alert regarding a critical flaw in Motex Lanscope Endpoint Manager, tracked as CVE-2025-61932. This vulnerability, rated 9.8 on the CVSS scale, allows attackers to bypass authentication mechanisms, leading to potential unauthorized access and data compromise.
Oct 24, 2025 CVE: CVE-2025-61932
Microsoft Issues Emergency Patch for Critical WSUS Vulnerability

Microsoft Issues Emergency Patch for Critical WSUS Vulnerability

Microsoft has released an emergency security patch for a critical vulnerability in Windows Server Update Services (WSUS) that is being actively exploited. The vulnerability, tracked as CVE-2025-59287, allows remote code execution and carries a severity score of 9.8 out of 10.
Oct 24, 2025 CVE: CVE-2025-59287
Critical Vulnerability CVE-2025-59287 in Windows Server Update Services

Critical Vulnerability CVE-2025-59287 in Windows Server Update Services

Microsoft has released an out-of-band security update for a critical vulnerability in Windows Server Update Services (WSUS), tracked as CVE-2025-59287. This flaw allows remote code execution by unauthenticated threat actors, and a new patch is necessary to fully mitigate the issue as the initial patch was incomplete.
Oct 24, 2025 CVE: CVE-2025-59287
Forescout Warns of Critical Vulnerabilities in TP-Link Routers

Forescout Warns of Critical Vulnerabilities in TP-Link Routers

Forescout Technologies has identified two critical vulnerabilities in TP-Link Omada and Festa VPN routers that could expose industrial systems to significant risks. The vulnerabilities, CVE-2025-7850 and CVE-2025-7851, allow for OS command injection and unauthorized root access, respectively.
Oct 24, 2025 CVE: CVE-2025-7850, CVE-2025-7851
High-Severity Path Traversal Vulnerability in Jira Software

High-Severity Path Traversal Vulnerability in Jira Software

Atlassian has disclosed a critical path traversal vulnerability in Jira Software Data Center and Server, allowing authenticated attackers to write files to any path accessible by the JVM. The flaw, tracked as CVE-2025-22167, affects versions from 9.12.0 through 11.0.1 and poses significant risks if unpatched.
Oct 23, 2025 CVE: CVE-2025-22167
Critical CVE-2025-54236 Flaw Exploited in Adobe Commerce and Magento

Critical CVE-2025-54236 Flaw Exploited in Adobe Commerce and Magento

Over 250 attacks have been reported in just 24 hours targeting Adobe Commerce and Magento due to a critical flaw tracked as CVE-2025-54236. This vulnerability allows for customer account takeovers via the REST API, with only 38% of stores currently patched.
Oct 23, 2025 CVE: CVE-2025-54236
Cybersecurity Experts Warn of Vulnerabilities in OpenAI's ChatGPT Atlas

Cybersecurity Experts Warn of Vulnerabilities in OpenAI's ChatGPT Atlas

Cybersecurity experts have raised concerns about OpenAI's new browser, ChatGPT Atlas, which may be susceptible to attacks that could compromise user data. The browser's features, including 'browser memories' and 'agent mode,' could potentially be exploited through prompt injection attacks, leading to unauthorized access to sensitive information.
Oct 23, 2025
Bitter APT Exploiting Old WinRAR Vulnerability in New Backdoor Attacks

Bitter APT Exploiting Old WinRAR Vulnerability in New Backdoor Attacks

The Bitter APT group is leveraging an old vulnerability in WinRAR to deploy new backdoor attacks. This highlights the ongoing threat posed by advanced persistent threats (APTs) that exploit outdated software vulnerabilities.
Oct 22, 2025 Actor: Bitter APT Sector: Various Region: Global
Hackers Exploit Azure Apps to Create Malicious Apps Impersonating Microsoft

Hackers Exploit Azure Apps to Create Malicious Apps Impersonating Microsoft

A recent investigation revealed a critical loophole in Azure applications that allowed hackers to create malicious apps using reserved Microsoft names. This vulnerability enabled attackers to gain unauthorized access and escalate privileges within Microsoft 365 environments, posing significant risks to organizations.
Oct 22, 2025 Actor: Unknown Sector: Information Technology Region: Global