#cyberwatch — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #cyberwatch, aggregated by home.social.
-
CVE-2025-14558 is a 9.8-severity vulnerability in FreeBSD's IPv6 auto-configuration that lets attackers execute arbitrary code with a single crafted network packet. FreeBSD released patches on December 16, 2024, but the threat escalated when multiple proof-of-concept exploits hit GitHub about two weeks ago.
Read More: https://www.security.land/freebsd-ipv6-flaw-enables-remote-code-execution-attacks/
#SecurityLand #CyberWatch #FreeBSD #Cybersecurity #VulnerabilityManagement #IPv6 #CVE
-
CVE-2025-14558 is a 9.8-severity vulnerability in FreeBSD's IPv6 auto-configuration that lets attackers execute arbitrary code with a single crafted network packet. FreeBSD released patches on December 16, 2024, but the threat escalated when multiple proof-of-concept exploits hit GitHub about two weeks ago.
Read More: https://www.security.land/freebsd-ipv6-flaw-enables-remote-code-execution-attacks/
#SecurityLand #CyberWatch #FreeBSD #Cybersecurity #VulnerabilityManagement #IPv6 #CVE
-
CVE-2025-14558 is a 9.8-severity vulnerability in FreeBSD's IPv6 auto-configuration that lets attackers execute arbitrary code with a single crafted network packet. FreeBSD released patches on December 16, 2024, but the threat escalated when multiple proof-of-concept exploits hit GitHub about two weeks ago.
Read More: https://www.security.land/freebsd-ipv6-flaw-enables-remote-code-execution-attacks/
#SecurityLand #CyberWatch #FreeBSD #Cybersecurity #VulnerabilityManagement #IPv6 #CVE
-
CVE-2025-14558 is a 9.8-severity vulnerability in FreeBSD's IPv6 auto-configuration that lets attackers execute arbitrary code with a single crafted network packet. FreeBSD released patches on December 16, 2024, but the threat escalated when multiple proof-of-concept exploits hit GitHub about two weeks ago.
Read More: https://www.security.land/freebsd-ipv6-flaw-enables-remote-code-execution-attacks/
#SecurityLand #CyberWatch #FreeBSD #Cybersecurity #VulnerabilityManagement #IPv6 #CVE
-
CVE-2025-14558 is a 9.8-severity vulnerability in FreeBSD's IPv6 auto-configuration that lets attackers execute arbitrary code with a single crafted network packet. FreeBSD released patches on December 16, 2024, but the threat escalated when multiple proof-of-concept exploits hit GitHub about two weeks ago.
Read More: https://www.security.land/freebsd-ipv6-flaw-enables-remote-code-execution-attacks/
#SecurityLand #CyberWatch #FreeBSD #Cybersecurity #VulnerabilityManagement #IPv6 #CVE
-
How many of your dependencies have you actually audited lately?
ReversingLabs uncovered a 4-month campaign where attackers published 14 malicious packages on NuGet, all targeting cryptocurrency developers. These weren't sloppy hacks—they were sophisticated impersonations of legitimate blockchain tools like Nethereum and Coinbase.Net.Api.
#SecurityLand #CyberWatch #Malware #Blockchain #Crypto #Nethereum #Research
Read More: https://www.security.land/crypto-theft-campaign-exploits-nuget-packages-for-months/
-
The Koi Security research team is on a roll this week.
After exposing the GhostPoster campaign that hid malware in Firefox extension logos, they've now uncovered something that should concern every developer using npm: a WhatsApp API package with 56,000 downloads that steals everything passing through it.
#SecurityLand #CyberWatch #NPM #WhatsApp #API #MaliciousPackage #Koi
Read More: https://www.security.land/whatsapp-stealing-malware-lurked-in-npm-package-with-56-000-downloads/
-
Analysis of CVE-2025-14733, a critical WatchGuard Firebox security vulnerability. Learn why unauthenticated RCE persists even after deleting vulnerable VPN configurations.
#SecurityLand #CyberWatch #ZeroDay #Watchguard #SecurityVulnerability #Firewall #CVE
Read More: https://www.security.land/watchguard-cve-2025-14733-critical-vulnerability-analysis/
-
Analysis of CVE-2025-14733, a critical WatchGuard Firebox security vulnerability. Learn why unauthenticated RCE persists even after deleting vulnerable VPN configurations.
#SecurityLand #CyberWatch #ZeroDay #Watchguard #SecurityVulnerability #Firewall #CVE
Read More: https://www.security.land/watchguard-cve-2025-14733-critical-vulnerability-analysis/
-
Ivanti Endpoint Manager faces four security vulnerabilities, including a critical 9.6 CVSS flaw. Updates now available for EPM users.
#SecurityLand #CyberWatch #SecurityVulnerability #Ivanti #EPM #CVSS #CVE #XSS
Read More: https://www.security.land/critical-flaws-ivanti-epm-endpoint-management/
-
Cybersecurity and Infrastructure Security Agency (CISA) issued Emergency Directive 25-03 after threat actors exploited Cisco ASA zero-days, including RCE and privilege escalation flaws. The agency praised quick reporting and mandates urgent patching — once again showing U.S. cyber defense leadership in transparency and rapid response.
#SecurityLand #CyberWatch #CISA #Cisco #ZeroDay #RCE #PrivilegeEscalation #SecurityVulnerability
Read More: https://www.security.land/cisa-orders-agencies-to-mitigate-cisco-asa-zero-day-exploitation/
-
A critical RCE vulnerability in Control Web Panel (CVE-2025-48703) allows remote command execution. Patch to version 0.9.8.1205 immediately.
#SecurityLand #CyberWatch #SecurityVulnerability #RCE #CVE #CWP #ControlWebPanel
Read More: https://www.security.land/critical-rce-vulnerability-found-in-control-web-panel/
-
🚨 CRITICAL: 7 severe security flaws found in popular FlowiseAI framework! Includes remote code execution, file manipulation & account takeover vulnerabilities. 5 rated "Critical" severity. Patches available - update immediately!
#SecurityLand #CyberWatch #AIFramework #CyberSecurity #Flowise #RCE
-
The vulnerability affects Apache NiFi versions 1.13.0 through 2.2.0. According to security researchers, the issue stems from the platform's logging functionality.
#securityland #cyberwatch #vulnerability #apache #nifi #mongodb
https://www.security.land/security-vulnerability-in-apache-nifi-exposes-mongodb-credentials/
-
Critical vulnerability allows attackers to bypass authentication on Fortinet devices. Is your network infrastructure at risk? Discover which versions are vulnerable and how to protect your systems immediately.
#SecurityLand #CyberWatch #CyberSecurity #Fortinet #Vulnerability #FortiOS
-
🚨Critical security vulnerability (CVSS 10.0) discovered in Pterodactyl Panel! Attackers can execute code without authentication. Game server admins must update to v1.11.11 immediately to prevent compromise.
#SecurityLand #CyberWatch #Cybersecurity #GameServers #Pterodactyl #SecurityVulnerability #CVSS
-
🚨Critical security vulnerability (CVSS 10.0) discovered in Pterodactyl Panel! Attackers can execute code without authentication. Game server admins must update to v1.11.11 immediately to prevent compromise.
#SecurityLand #CyberWatch #Cybersecurity #GameServers #Pterodactyl #SecurityVulnerability #CVSS
-
A devastating security flaw has been discovered in OpenAI’s ChatGPT that could silently steal your Gmail data without you ever knowing. Security firm Radware has uncovered what they’re calling “ShadowLeak”.
#SecurityLand #CyberWatch #OpenAI #ChatGPT #Radware #Vulnerability #ShadowLeak
-
A devastating security flaw has been discovered in OpenAI’s ChatGPT that could silently steal your Gmail data without you ever knowing. Security firm Radware has uncovered what they’re calling “ShadowLeak”.
#SecurityLand #CyberWatch #OpenAI #ChatGPT #Radware #Vulnerability #ShadowLeak
-
Cisco has disclosed 13 IOS and IOS XE vulnerabilities, including CVE-2025-20352, which is already being exploited. Immediate updates are strongly advised.
#SecurityLand #CyberWatch #Cisco #SecurityVulnerability #CVE #PatchNow
Read More: https://www.security.land/cisco-releases-security-advisories-for-ios-and-ios-xe-vulnerabilities/
-
🚨 Sophisticated "Shai-Hulud" worm compromises 187+ NPM packages in devastating supply chain attack. The self-replicating malware steals dev credentials and publicly exposes them on GitHub. CrowdStrike among victims. JavaScript ecosystem under siege.
#SecurityLand #CyberWatch #CyberSecurity #NPM #SupplyChain #ShaiHulud #Github #Javascript
-
🚨 Sophisticated "Shai-Hulud" worm compromises 187+ NPM packages in devastating supply chain attack. The self-replicating malware steals dev credentials and publicly exposes them on GitHub. CrowdStrike among victims. JavaScript ecosystem under siege.
#SecurityLand #CyberWatch #CyberSecurity #NPM #SupplyChain #ShaiHulud #Github #Javascript
-
pgAdmin CVE-2025-9636 vulnerability enables OAuth session hijacking, threatening PostgreSQL database security. Database administrators must prioritize pgAdmin 9.8 upgrade immediately. Essential reading for cybersecurity professionals.
#SecurityLand #CyberWatch #Cybersecurity #PostgreSQL #DatabaseSecurity #CVE #OAuth #pgAdmin
-
pgAdmin CVE-2025-9636 vulnerability enables OAuth session hijacking, threatening PostgreSQL database security. Database administrators must prioritize pgAdmin 9.8 upgrade immediately. Essential reading for cybersecurity professionals.
#SecurityLand #CyberWatch #Cybersecurity #PostgreSQL #DatabaseSecurity #CVE #OAuth #pgAdmin
-
🚨Docker Desktop vulnerability CVE-2025-9074 (CVSS 9.3) allows containers to bypass isolation & access Docker APIs. Affects ALL installations regardless of ECI settings. Update to v4.44.3 immediately.
#SecurityLand #CyberWatch #Docker #Cybersecurity #ContainerSecurity #Docker
Read More: https://www.security.land/critical-docker-desktop-vulnerability-exposes-container-api-access-risk/
-
The Tokiwa Group recently experienced a ransomware attack leading to a potential data breach affecting over 420,000 customer, employee, and business partner records. The company is actively addressing the incident and has begun notifying impacted individuals and partners.
#SecurityLand #CyberWatch #Cybersecurity #DataBreach #Ransomware #TokiwaGroup #Japan
-
🚨 ALERT: CrushFTP zero-day vulnerability (CVE-2025-54309) is actively compromising government and healthcare networks worldwide. Attackers reverse-engineered vendor code to exploit old bugs - a dangerous new attack methodology that challenges traditional patch management. CVSS 9.0 severity demands immediate action.
#SecurityLand #CyberWatch #CyberSecurity #ZeroDay #InfoSec #CrushFTP #Healthcare #Government #FTP #SecurityVulnerability
-
🚨 BREAKING: Eye Security discovers ToolShell attacks hitting Microsoft SharePoint servers worldwide. Attackers bypass authentication entirely, gaining complete system control in 72 hours from disclosure to mass exploitation. Critical CVE-2025-53770/53771 vulnerabilities actively exploited.
#SecurityLand #CyberWatch #Exploit #Microsoft #Cybersecurity #SharePoint #Vulnerability
-
XenServer VM Tools vulnerabilities let attackers gain kernel privileges on Windows VMs. If you run virtualized Windows environments, patch NOW!
#SecurityLand #CyberWatch #XenServer #CVE #VirtualizationSecurity #Windows #Vulnerability
-
Critical security flaws discovered in VMware core products including vCenter Server and ESXi. Vulnerabilities could allow command execution and service disruption. Updates available now to protect your infrastructure.
#SecurityLand #CyberWatch #Broadcom #VMware #Vulnerability #PatchNow #SecurityVulnerability #Technology
-
Critical security flaws discovered in VMware core products including vCenter Server and ESXi. Vulnerabilities could allow command execution and service disruption. Updates available now to protect your infrastructure.
#SecurityLand #CyberWatch #Broadcom #VMware #Vulnerability #PatchNow #SecurityVulnerability #Technology
-
CERT Orange Polska successfully defended against a massive 1.3 Tbps DDoS attack targeting a major Polish company. Learn how their preparation and expertise prevented what could have been devastating digital damage.
#SecurityLand #CyberWatch #Poland #DDoS #Cyberattack #Cybersecurity #CERT #DDoSAttack
-
CISA has issued an urgent advisory about six actively exploited vulnerabilities affecting Ivanti EPMM, Zimbra, Output Messenger, and other enterprise systems. Learn which systems are at risk and what actions your organization should take immediately to protect critical infrastructure.
#SecurityLand #CyberWatch #CISA #Vulnerability #Ivanti #EPMM #Zimbra #OutputMessenger #EnterpriseSecurity #SecurityExploit #CriticalInfrastructure #Government
Read More: https://www.security.land/us-government-warns-about-six-actively-exploited-vulnerabilities/
-
CISA has issued an urgent advisory about six actively exploited vulnerabilities affecting Ivanti EPMM, Zimbra, Output Messenger, and other enterprise systems. Learn which systems are at risk and what actions your organization should take immediately to protect critical infrastructure.
#SecurityLand #CyberWatch #CISA #Vulnerability #Ivanti #EPMM #Zimbra #OutputMessenger #EnterpriseSecurity #SecurityExploit #CriticalInfrastructure #Government
Read More: https://www.security.land/us-government-warns-about-six-actively-exploited-vulnerabilities/
-
🚨 A critical vulnerability (CVE-2025-47275) in the Auth0 SDK exposes Symfony, Laravel, and WordPress users to brute-force session attacks. Okta has released patches—learn how to protect your application now.
#SecurityLand #CyberWatch #Auth0 #Okta #PHP #Laravel #WordPress #Symfony #Vulnerability #Patch
-
🚨 A critical vulnerability (CVE-2025-47275) in the Auth0 SDK exposes Symfony, Laravel, and WordPress users to brute-force session attacks. Okta has released patches—learn how to protect your application now.
#SecurityLand #CyberWatch #Auth0 #Okta #PHP #Laravel #WordPress #Symfony #Vulnerability #Patch
-
Japan's Ministry of Defense confirms losing roughly 1700 documents from the 90s containing personal info. An apology has been issued.
#SecurityLand #CyberWatch #Japan #DataLoss #Privacy #Japan #MinistryOfDefense #DataSecurity
Read More: https://www.security.land/japan-ministry-of-defense-reports-loss-of-personal-data-documents/
-
The hunters become the hunted: LockBit ransomware group suffers data breach as unknown hackers expose 100K+ lines of operational data including Bitcoin addresses and admin credentials.
#SecurityLand #CyberWatch #LockBit #Ransomware #CyberSecurity #LockBitHack #LockBitDatabase
Read More: https://www.security.land/lockbit-ransomware-group-suffers-major-breach-admin-database-exposed/
-
🚨 Radware Cloud WAF flaws let attackers bypass filters. Learn about CVE-2024-56523 & 56524 and secure your systems now.
#SecurityLand #CyberWatch #SecurityVulnerability #CVE #Radware #Cloud #WAF
Read More: https://www.security.land/critical-security-flaws-in-radware-cloud-waf-risk-filter-bypass-patch-now/
-
🚨 Cisco issues emergency alert: A critical vulnerability (CVSS 10.0) in IOS XE Wireless Controller risks root access. Learn mitigation steps now.
#SecurityLand #CyberWatch #SecurityVulnerability #CVE #IOSXE #Cisco #WirelessController
-
🚨 A severe SQL injection vulnerability (CVE-2025-46337) has been discovered in the ADOdb PostgreSQL driver. Developers using PHP + PostgreSQL must update to version 5.22.9 immediately to stay secure.
#SecurityLand #CyberWatch #SecurityVulnerability #CVE #ADOdb #PostgreSQL #PHP #SQLInjection
Read More: https://www.security.land/critical-sql-injection-vulnerability-found-in-adodb-postgresql-driver/
-
🚨 A severe SQL injection vulnerability (CVE-2025-46337) has been discovered in the ADOdb PostgreSQL driver. Developers using PHP + PostgreSQL must update to version 5.22.9 immediately to stay secure.
#SecurityLand #CyberWatch #SecurityVulnerability #CVE #ADOdb #PostgreSQL #PHP #SQLInjection
Read More: https://www.security.land/critical-sql-injection-vulnerability-found-in-adodb-postgresql-driver/
-
A critical SAP vulnerability scoring 10/10 is actively being exploited to deploy ransomware across enterprise systems. Security experts from ReliaQuest warn this zero-day flaw in NetWeaver could compromise corporate and government data worldwide. Learn how to protect your organization now.
#SecurityLand #CyberWatch #ZeroDay #Vulnerability #SAP #NetWeaver #EnterpriseSecurity
-
Deep dive into the critical buffer overflow vulnerability (CVE-2025-42599, CVSS 9.8) in Active! mail that led to the IIJ Secure MX Service data breach. Understand the risks of this high-severity flaw.
#SecurityLand #CyberWatch #Vulnerability #IIJ #ActiveMail #DataBreach
-
Chinese threat actor UNC5221 has significantly upgraded their BRICKSTORM malware with triple-layer encryption that renders most security monitoring ineffective, according to NVISO Security. Now targeting both Linux and Windows environments, this sophisticated threat uses traffic tunneling instead of direct command execution to avoid detection. European strategic industries are primary targets.
#SecurityLand #CyberWatch #CyberSecurity #ThreatIntelligence #APT #Brickstorm
-
Ukrainian cyber police, alongside international agencies, have busted a global fraud ring that stole 154.6 Bitcoins from victims across Europe and the US. 💻💰
#securityland #cyberwatch #cryptocurrency #scam #police #LEA #ukraine
-
Hey #Memphis folks, does anyone know how to search the #MPD #CyberWatch crime mapping system for homicides?
The search interface has categories for damn near everything -- I can even look up "Sports Tampering" incidents -- but neither "homicide" nor "murder" (nor attempt of either) are in the list of search options... 🧐
-
Cisco has disclosed 13 IOS and IOS XE vulnerabilities, including CVE-2025-20352, which is already being exploited. Immediate updates are strongly advised.
#SecurityLand #CyberWatch #Cisco #SecurityVulnerability #CVE #PatchNow
Read More: https://www.security.land/cisco-releases-security-advisories-for-ios-and-ios-xe-vulnerabilities/
-
A devastating security flaw has been discovered in OpenAI’s ChatGPT that could silently steal your Gmail data without you ever knowing. Security firm Radware has uncovered what they’re calling “ShadowLeak”.
#SecurityLand #CyberWatch #OpenAI #ChatGPT #Radware #Vulnerability #ShadowLeak