home.social

#cve2025 — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #cve2025, aggregated by home.social.

fetched live
  1. 🚨 CVE-2025-14388: CRITICAL vuln in PhastPress (≤3.7) lets unauth attackers read files like wp-config.php using double-encoded null bytes. Patch unavailable—disable plugin, block %2500 in URLs, monitor logs! radar.offseq.com/threat/cve-20 #OffSeq #WordPress #Vulnerability #CVE2025

  2. 🚨 CVE-2025-68398: CRITICAL vuln in Weblate (<5.15.1). Privileged users can overwrite Git configs, risking full system compromise. Patch to 5.15.1+ & audit Git settings now! radar.offseq.com/threat/cve-20 #OffSeq #Weblate #Infosec #CVE2025

  3. Cal.com has patched a critical authentication bypass (CVE-2025-66489) that allowed attackers to submit any non-empty TOTP field and skip password checks. Versions ≤5.9.7 were impacted.

    Update to 5.9.8 to ensure both password and TOTP verification are enforced.
    How should MFA implementations be validated to prevent logic gaps like this?

    Source: gbhackers.com/critical-cal-com

    Share your insights and follow us for more security reporting.

    #infosec #appsec #CVE2025 #authentication #MFA #ThreatIntel #SecureCoding #SoftwareSecurity #VulnerabilityManagement #SecurityUpdate

  4. Threat actors are actively exploiting CVE-2025-59287 in WSUS to deploy ShadowPad.

    ASEC notes the attackers used PowerCat for shell access, then fetched and installed ShadowPad with certutil/curl, executing it through DLL side-loading.

    How are you securing WSUS or other update infrastructure in your environment?
    💬 Share your insights
    ⭐ Follow TechNadu for timely threat intel

    #infosec #WSUS #ShadowPad #CVE2025 #malware #threatintel #sysadmin #DFIR #TechNadu

  5. ⚠️ New Critical Linux CVE ⚠️

    Unless you’re using Talos Linux.

    In which case, you're fully secure. Carry on, and let your minimal, immutable OS keep you safe from CVE-2025-32463 and CVE-2025-32462.

    #CVE2025 #Linux #Kubernetes #CyberSecurity

  6. 🔒 CRITICAL: CVE-2025-49794 in libxml2 hits RHEL 10. Remote, unauthenticated use-after-free via crafted XML can crash apps or cause undefined behavior. Monitor for patches, filter XML inputs, and restrict access! radar.offseq.com/threat/cve-20 #OffSeq #Linux #RHEL #CVE2025 #Infosec

  7. 🚨 Chinese hackers exploiting a Cityworks zero-day (CVE-2025-0994) to hit US local agencies, including municipal systems and public services, warns #CiscoTalos.

    Read: hackread.com/chinese-hackers-e

    #CyberSecurity #Infosec #CVE2025 #Cityworks #ZeroDay #RCE #China

  8. 🚨 #CISA warns CVE-2025-3248 in Langflow is being actively exploited. Critical RCE flaw allows full server takeover. Patch to v1.3.0 ASAP.

    #Infosec #CVE2025 #Langflow #CyberSecurity

    Read: hackread.com/langflow-vulnerab