home.social

#cyberwatch — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #cyberwatch, aggregated by home.social.

  1. CVE-2025-14558 is a 9.8-severity vulnerability in FreeBSD's IPv6 auto-configuration that lets attackers execute arbitrary code with a single crafted network packet. FreeBSD released patches on December 16, 2024, but the threat escalated when multiple proof-of-concept exploits hit GitHub about two weeks ago.

    Read More: security.land/freebsd-ipv6-fla

    #SecurityLand #CyberWatch #FreeBSD #Cybersecurity #VulnerabilityManagement #IPv6 #CVE

  2. CVE-2025-14558 is a 9.8-severity vulnerability in FreeBSD's IPv6 auto-configuration that lets attackers execute arbitrary code with a single crafted network packet. FreeBSD released patches on December 16, 2024, but the threat escalated when multiple proof-of-concept exploits hit GitHub about two weeks ago.

    Read More: security.land/freebsd-ipv6-fla

    #SecurityLand #CyberWatch #FreeBSD #Cybersecurity #VulnerabilityManagement #IPv6 #CVE

  3. CVE-2025-14558 is a 9.8-severity vulnerability in FreeBSD's IPv6 auto-configuration that lets attackers execute arbitrary code with a single crafted network packet. FreeBSD released patches on December 16, 2024, but the threat escalated when multiple proof-of-concept exploits hit GitHub about two weeks ago.

    Read More: security.land/freebsd-ipv6-fla

    #SecurityLand #CyberWatch #FreeBSD #Cybersecurity #VulnerabilityManagement #IPv6 #CVE

  4. CVE-2025-14558 is a 9.8-severity vulnerability in FreeBSD's IPv6 auto-configuration that lets attackers execute arbitrary code with a single crafted network packet. FreeBSD released patches on December 16, 2024, but the threat escalated when multiple proof-of-concept exploits hit GitHub about two weeks ago.

    Read More: security.land/freebsd-ipv6-fla

    #SecurityLand #CyberWatch #FreeBSD #Cybersecurity #VulnerabilityManagement #IPv6 #CVE

  5. CVE-2025-14558 is a 9.8-severity vulnerability in FreeBSD's IPv6 auto-configuration that lets attackers execute arbitrary code with a single crafted network packet. FreeBSD released patches on December 16, 2024, but the threat escalated when multiple proof-of-concept exploits hit GitHub about two weeks ago.

    Read More: security.land/freebsd-ipv6-fla

    #SecurityLand #CyberWatch #FreeBSD #Cybersecurity #VulnerabilityManagement #IPv6 #CVE

  6. How many of your dependencies have you actually audited lately?

    ReversingLabs uncovered a 4-month campaign where attackers published 14 malicious packages on NuGet, all targeting cryptocurrency developers. These weren't sloppy hacks—they were sophisticated impersonations of legitimate blockchain tools like Nethereum and Coinbase.Net.Api.

    #SecurityLand #CyberWatch #Malware #Blockchain #Crypto #Nethereum #Research

    Read More: security.land/crypto-theft-cam

  7. The Koi Security research team is on a roll this week.

    After exposing the GhostPoster campaign that hid malware in Firefox extension logos, they've now uncovered something that should concern every developer using npm: a WhatsApp API package with 56,000 downloads that steals everything passing through it.

    #SecurityLand #CyberWatch #NPM #WhatsApp #API #MaliciousPackage #Koi

    Read More: security.land/whatsapp-stealin

  8. Analysis of CVE-2025-14733, a critical WatchGuard Firebox security vulnerability. Learn why unauthenticated RCE persists even after deleting vulnerable VPN configurations.

    #SecurityLand #CyberWatch #ZeroDay #Watchguard #SecurityVulnerability #Firewall #CVE

    Read More: security.land/watchguard-cve-2

  9. Analysis of CVE-2025-14733, a critical WatchGuard Firebox security vulnerability. Learn why unauthenticated RCE persists even after deleting vulnerable VPN configurations.

    #SecurityLand #CyberWatch #ZeroDay #Watchguard #SecurityVulnerability #Firewall #CVE

    Read More: security.land/watchguard-cve-2

  10. Cybersecurity and Infrastructure Security Agency (CISA) issued Emergency Directive 25-03 after threat actors exploited Cisco ASA zero-days, including RCE and privilege escalation flaws. The agency praised quick reporting and mandates urgent patching — once again showing U.S. cyber defense leadership in transparency and rapid response.

    #SecurityLand #CyberWatch #CISA #Cisco #ZeroDay #RCE #PrivilegeEscalation #SecurityVulnerability

    Read More: security.land/cisa-orders-agen

  11. 🚨 CRITICAL: 7 severe security flaws found in popular FlowiseAI framework! Includes remote code execution, file manipulation & account takeover vulnerabilities. 5 rated "Critical" severity. Patches available - update immediately!

    #SecurityLand #CyberWatch #AIFramework #CyberSecurity #Flowise #RCE

    Read More: security.land/critical-securit

  12. The vulnerability affects Apache NiFi versions 1.13.0 through 2.2.0. According to security researchers, the issue stems from the platform's logging functionality.

    #securityland #cyberwatch #vulnerability #apache #nifi #mongodb

    security.land/security-vulnera

  13. Critical vulnerability allows attackers to bypass authentication on Fortinet devices. Is your network infrastructure at risk? Discover which versions are vulnerable and how to protect your systems immediately.

    #SecurityLand #CyberWatch #CyberSecurity #Fortinet #Vulnerability #FortiOS

    Read More: security.land/critical-fortine

  14. 🚨Critical security vulnerability (CVSS 10.0) discovered in Pterodactyl Panel! Attackers can execute code without authentication. Game server admins must update to v1.11.11 immediately to prevent compromise.

    #SecurityLand #CyberWatch #Cybersecurity #GameServers #Pterodactyl #SecurityVulnerability #CVSS

    security.land/critical-securit

  15. 🚨Critical security vulnerability (CVSS 10.0) discovered in Pterodactyl Panel! Attackers can execute code without authentication. Game server admins must update to v1.11.11 immediately to prevent compromise.

    #SecurityLand #CyberWatch #Cybersecurity #GameServers #Pterodactyl #SecurityVulnerability #CVSS

    security.land/critical-securit

  16. A devastating security flaw has been discovered in OpenAI’s ChatGPT that could silently steal your Gmail data without you ever knowing. Security firm Radware has uncovered what they’re calling “ShadowLeak”.

    #SecurityLand #CyberWatch #OpenAI #ChatGPT #Radware #Vulnerability #ShadowLeak

    Read More: security.land/zero-click-chatg

  17. A devastating security flaw has been discovered in OpenAI’s ChatGPT that could silently steal your Gmail data without you ever knowing. Security firm Radware has uncovered what they’re calling “ShadowLeak”.

    #SecurityLand #CyberWatch #OpenAI #ChatGPT #Radware #Vulnerability #ShadowLeak

    Read More: security.land/zero-click-chatg

  18. 🚨 Sophisticated "Shai-Hulud" worm compromises 187+ NPM packages in devastating supply chain attack. The self-replicating malware steals dev credentials and publicly exposes them on GitHub. CrowdStrike among victims. JavaScript ecosystem under siege.

    #SecurityLand #CyberWatch #CyberSecurity #NPM #SupplyChain #ShaiHulud #Github #Javascript

    Read More: security.land/npm-under-attack

  19. 🚨 Sophisticated "Shai-Hulud" worm compromises 187+ NPM packages in devastating supply chain attack. The self-replicating malware steals dev credentials and publicly exposes them on GitHub. CrowdStrike among victims. JavaScript ecosystem under siege.

    #SecurityLand #CyberWatch #CyberSecurity #NPM #SupplyChain #ShaiHulud #Github #Javascript

    Read More: security.land/npm-under-attack

  20. pgAdmin CVE-2025-9636 vulnerability enables OAuth session hijacking, threatening PostgreSQL database security. Database administrators must prioritize pgAdmin 9.8 upgrade immediately. Essential reading for cybersecurity professionals.

    #SecurityLand #CyberWatch #Cybersecurity #PostgreSQL #DatabaseSecurity #CVE #OAuth #pgAdmin

    Read More: security.land/critical-pgadmin

  21. pgAdmin CVE-2025-9636 vulnerability enables OAuth session hijacking, threatening PostgreSQL database security. Database administrators must prioritize pgAdmin 9.8 upgrade immediately. Essential reading for cybersecurity professionals.

    #SecurityLand #CyberWatch #Cybersecurity #PostgreSQL #DatabaseSecurity #CVE #OAuth #pgAdmin

    Read More: security.land/critical-pgadmin

  22. 🚨Docker Desktop vulnerability CVE-2025-9074 (CVSS 9.3) allows containers to bypass isolation & access Docker APIs. Affects ALL installations regardless of ECI settings. Update to v4.44.3 immediately.

    #SecurityLand #CyberWatch #Docker #Cybersecurity #ContainerSecurity #Docker

    Read More: security.land/critical-docker-

  23. The Tokiwa Group recently experienced a ransomware attack leading to a potential data breach affecting over 420,000 customer, employee, and business partner records. The company is actively addressing the incident and has begun notifying impacted individuals and partners.

    #SecurityLand #CyberWatch #Cybersecurity #DataBreach #Ransomware #TokiwaGroup #Japan

    Read More: security.land/tokiwa-group-dat

  24. 🚨 ALERT: CrushFTP zero-day vulnerability (CVE-2025-54309) is actively compromising government and healthcare networks worldwide. Attackers reverse-engineered vendor code to exploit old bugs - a dangerous new attack methodology that challenges traditional patch management. CVSS 9.0 severity demands immediate action.

    #SecurityLand #CyberWatch #CyberSecurity #ZeroDay #InfoSec #CrushFTP #Healthcare #Government #FTP #SecurityVulnerability

    Read More: security.land/critical-crushft

  25. 🚨 BREAKING: Eye Security discovers ToolShell attacks hitting Microsoft SharePoint servers worldwide. Attackers bypass authentication entirely, gaining complete system control in 72 hours from disclosure to mass exploitation. Critical CVE-2025-53770/53771 vulnerabilities actively exploited.

    #SecurityLand #CyberWatch #Exploit #Microsoft #Cybersecurity #SharePoint #Vulnerability

    Read More: security.land/sharepoint-under

  26. Critical security flaws discovered in VMware core products including vCenter Server and ESXi. Vulnerabilities could allow command execution and service disruption. Updates available now to protect your infrastructure.

    #SecurityLand #CyberWatch #Broadcom #VMware #Vulnerability #PatchNow #SecurityVulnerability #Technology

    Read More: security.land/multiple-securit

  27. Critical security flaws discovered in VMware core products including vCenter Server and ESXi. Vulnerabilities could allow command execution and service disruption. Updates available now to protect your infrastructure.

    #SecurityLand #CyberWatch #Broadcom #VMware #Vulnerability #PatchNow #SecurityVulnerability #Technology

    Read More: security.land/multiple-securit

  28. CERT Orange Polska successfully defended against a massive 1.3 Tbps DDoS attack targeting a major Polish company. Learn how their preparation and expertise prevented what could have been devastating digital damage.

    #SecurityLand #CyberWatch #Poland #DDoS #Cyberattack #Cybersecurity #CERT #DDoSAttack

    Read More: security.land/record-breaking-

  29. CISA has issued an urgent advisory about six actively exploited vulnerabilities affecting Ivanti EPMM, Zimbra, Output Messenger, and other enterprise systems. Learn which systems are at risk and what actions your organization should take immediately to protect critical infrastructure.

    #SecurityLand #CyberWatch #CISA #Vulnerability #Ivanti #EPMM #Zimbra #OutputMessenger #EnterpriseSecurity #SecurityExploit #CriticalInfrastructure #Government

    Read More: security.land/us-government-wa

  30. CISA has issued an urgent advisory about six actively exploited vulnerabilities affecting Ivanti EPMM, Zimbra, Output Messenger, and other enterprise systems. Learn which systems are at risk and what actions your organization should take immediately to protect critical infrastructure.

    #SecurityLand #CyberWatch #CISA #Vulnerability #Ivanti #EPMM #Zimbra #OutputMessenger #EnterpriseSecurity #SecurityExploit #CriticalInfrastructure #Government

    Read More: security.land/us-government-wa

  31. 🚨 A critical vulnerability (CVE-2025-47275) in the Auth0 SDK exposes Symfony, Laravel, and WordPress users to brute-force session attacks. Okta has released patches—learn how to protect your application now.

    #SecurityLand #CyberWatch #Auth0 #Okta #PHP #Laravel #WordPress #Symfony #Vulnerability #Patch

    Read More: security.land/critical-vulnera

  32. 🚨 A critical vulnerability (CVE-2025-47275) in the Auth0 SDK exposes Symfony, Laravel, and WordPress users to brute-force session attacks. Okta has released patches—learn how to protect your application now.

    #SecurityLand #CyberWatch #Auth0 #Okta #PHP #Laravel #WordPress #Symfony #Vulnerability #Patch

    Read More: security.land/critical-vulnera

  33. The hunters become the hunted: LockBit ransomware group suffers data breach as unknown hackers expose 100K+ lines of operational data including Bitcoin addresses and admin credentials.

    #SecurityLand #CyberWatch #LockBit #Ransomware #CyberSecurity #LockBitHack #LockBitDatabase

    Read More: security.land/lockbit-ransomwa

  34. 🚨 A severe SQL injection vulnerability (CVE-2025-46337) has been discovered in the ADOdb PostgreSQL driver. Developers using PHP + PostgreSQL must update to version 5.22.9 immediately to stay secure.

    #SecurityLand #CyberWatch #SecurityVulnerability #CVE #ADOdb #PostgreSQL #PHP #SQLInjection

    Read More: security.land/critical-sql-inj

  35. 🚨 A severe SQL injection vulnerability (CVE-2025-46337) has been discovered in the ADOdb PostgreSQL driver. Developers using PHP + PostgreSQL must update to version 5.22.9 immediately to stay secure.

    #SecurityLand #CyberWatch #SecurityVulnerability #CVE #ADOdb #PostgreSQL #PHP #SQLInjection

    Read More: security.land/critical-sql-inj

  36. A critical SAP vulnerability scoring 10/10 is actively being exploited to deploy ransomware across enterprise systems. Security experts from ReliaQuest warn this zero-day flaw in NetWeaver could compromise corporate and government data worldwide. Learn how to protect your organization now.

    #SecurityLand #CyberWatch #ZeroDay #Vulnerability #SAP #NetWeaver #EnterpriseSecurity

    security.land/critical-sap-zer

  37. Deep dive into the critical buffer overflow vulnerability (CVE-2025-42599, CVSS 9.8) in Active! mail that led to the IIJ Secure MX Service data breach. Understand the risks of this high-severity flaw.

    #SecurityLand #CyberWatch #Vulnerability #IIJ #ActiveMail #DataBreach

    security.land/critical-buffer-

  38. Chinese threat actor UNC5221 has significantly upgraded their BRICKSTORM malware with triple-layer encryption that renders most security monitoring ineffective, according to NVISO Security. Now targeting both Linux and Windows environments, this sophisticated threat uses traffic tunneling instead of direct command execution to avoid detection. European strategic industries are primary targets.

    #SecurityLand #CyberWatch #CyberSecurity #ThreatIntelligence #APT #Brickstorm

    security.land/brickstorm-malwa

  39. Hey #Memphis folks, does anyone know how to search the #MPD #CyberWatch crime mapping system for homicides?

    The search interface has categories for damn near everything -- I can even look up "Sports Tampering" incidents -- but neither "homicide" nor "murder" (nor attempt of either) are in the list of search options... 🧐

  40. A devastating security flaw has been discovered in OpenAI’s ChatGPT that could silently steal your Gmail data without you ever knowing. Security firm Radware has uncovered what they’re calling “ShadowLeak”.

    #SecurityLand #CyberWatch #OpenAI #ChatGPT #Radware #Vulnerability #ShadowLeak

    Read More: security.land/zero-click-chatg