#cve2025 — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #cve2025, aggregated by home.social.
-
All I Want for Xmas Is Your Secrets: LangGrinch Hits LangChain (CVE-2025-68664)
https://cyata.ai/blog/langgrinch-langchain-core-cve-2025-68664/
#HackerNews #LangGrinch #LangChain #CVE2025 #cybersecurity #secrets
-
🚨 CVE-2025-14388: CRITICAL vuln in PhastPress (≤3.7) lets unauth attackers read files like wp-config.php using double-encoded null bytes. Patch unavailable—disable plugin, block %2500 in URLs, monitor logs! https://radar.offseq.com/threat/cve-2025-14388-cwe-158-improper-neutralization-of--469918d2 #OffSeq #WordPress #Vulnerability #CVE2025
-
🚨 CVE-2025-68398: CRITICAL vuln in Weblate (<5.15.1). Privileged users can overwrite Git configs, risking full system compromise. Patch to 5.15.1+ & audit Git settings now! https://radar.offseq.com/threat/cve-2025-68398-cwe-20-improper-input-validation-in-186802ce #OffSeq #Weblate #Infosec #CVE2025
-
Cal.com has patched a critical authentication bypass (CVE-2025-66489) that allowed attackers to submit any non-empty TOTP field and skip password checks. Versions ≤5.9.7 were impacted.
Update to 5.9.8 to ensure both password and TOTP verification are enforced.
How should MFA implementations be validated to prevent logic gaps like this?Share your insights and follow us for more security reporting.
#infosec #appsec #CVE2025 #authentication #MFA #ThreatIntel #SecureCoding #SoftwareSecurity #VulnerabilityManagement #SecurityUpdate
-
Threat actors are actively exploiting CVE-2025-59287 in WSUS to deploy ShadowPad.
ASEC notes the attackers used PowerCat for shell access, then fetched and installed ShadowPad with certutil/curl, executing it through DLL side-loading.
How are you securing WSUS or other update infrastructure in your environment?
💬 Share your insights
⭐ Follow TechNadu for timely threat intel#infosec #WSUS #ShadowPad #CVE2025 #malware #threatintel #sysadmin #DFIR #TechNadu
-
Cryptographic Issues in Cloudflare's Circl FourQ Implementation (CVE-2025-8556)
https://www.botanica.software/blog/cryptographic-issues-in-cloudflares-circl-fourq-implementation
#HackerNews #Cryptography #Cloudflare #FourQ #CVE2025 #Cybersecurity
-
GitHub Copilot: Remote Code Execution via Prompt Injection (CVE-2025-53773)
https://embracethered.com/blog/posts/2025/github-copilot-remote-code-execution-via-prompt-injection/
#HackerNews #GitHubCopilot #RemoteCodeExecution #PromptInjection #CVE2025 #CyberSecurity
-
RediShell: Critical remote code execution vulnerability in Redis
https://www.wiz.io/blog/wiz-research-redis-rce-cve-2025-49844
#HackerNews #RediShell #Redis #Vulnerability #RCE #CyberSecurity #CVE2025
-
Is This Bad? This Feels Bad. (Fortra GoAnywhere CVE-2025-10035)
https://labs.watchtowr.com/is-this-bad-this-feels-bad-goanywhere-cve-2025-10035/
#HackerNews #IsThisBad #ThisFeelsBad #Fortra #GoAnywhere #CVE2025 #10035 #Cybersecurity
-
⚠️ New Critical Linux CVE ⚠️
Unless you’re using Talos Linux.
In which case, you're fully secure. Carry on, and let your minimal, immutable OS keep you safe from CVE-2025-32463 and CVE-2025-32462.
-
🔒 CRITICAL: CVE-2025-49794 in libxml2 hits RHEL 10. Remote, unauthenticated use-after-free via crafted XML can crash apps or cause undefined behavior. Monitor for patches, filter XML inputs, and restrict access! https://radar.offseq.com/threat/cve-2025-49794-expired-pointer-dereference-in-red--18de3c2a #OffSeq #Linux #RHEL #CVE2025 #Infosec
-
Spoofing OpenPGP.js signature verification
https://codeanlabs.com/blog/research/cve-2025-47934-spoofing-openpgp-js-signatures/
#HackerNews #Spoofing #OpenPGP.js #signature #verification #OpenPGPjs #CVE2025 #cybersecurity #research
-
🚨 Chinese hackers exploiting a Cityworks zero-day (CVE-2025-0994) to hit US local agencies, including municipal systems and public services, warns #CiscoTalos.
Read: https://hackread.com/chinese-hackers-exploit-cityworks-0day-us-local-agencies/
#CyberSecurity #Infosec #CVE2025 #Cityworks #ZeroDay #RCE #China
-
I used o3 to find a remote zeroday in the Linux SMB implementation
#HackerNews #o3 #zeroday #Linux #SMB #cybersecurity #vulnerability #CVE2025-37899 #hacking
-
Can You Really Trust That Permission Pop-Up on macOS? (CVE-2025-31250)
https://wts.dev/posts/tcc-who/
#HackerNews #TrustIssues #PermissionPopup #macOS #CVE2025 #CyberSecurity
-
🚨 #CISA warns CVE-2025-3248 in Langflow is being actively exploited. Critical RCE flaw allows full server takeover. Patch to v1.3.0 ASAP.
#Infosec #CVE2025 #Langflow #CyberSecurity
Read: https://hackread.com/langflow-vulnerability-cve-2025-3248-actively-exploited-cisa/
-
Linux Kernel Exploitation: CVE-2025-21756
https://hoefler.dev/articles/vsock.html
#HackerNews #LinuxKernel #Exploitation #CVE2025 #CVE21756 #CyberSecurity #OpenSource
-
Critical vulnerability found in Erlang/OTP SSH server
https://nvd.nist.gov/vuln/detail/CVE-2025-32433
#HackerNews #CriticalVulnerability #ErlangOTP #SSHServer #CyberSecurity #CVE2025 #CVE
-
Meta Alerts Users About Actively Exploited Freetype Vulnerability
#CyberSecurity #FreeType #CVE2025 #OpenSourceSecurity #SoftwareVulnerabilities #SecurityAlert #Meta #PatchNow