⤷ Title: CISA Flags Active Exploits in Erlang/OTP SSH and Roundcube Webmail: Critical RCE and XSS Flaws Under Attack
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 10 Jun 2025 02:01:00 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CISA #CVE_2024_42009 #CVE_2025_32433 #cybersecurity #Erlang/OTP #Exploit #KEV Catalog #rce #Roundcube #spear_phishing #Vulnerability #XSS
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 10 Jun 2025 02:01:00 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CISA #CVE_2024_42009 #CVE_2025_32433 #cybersecurity #Erlang/OTP #Exploit #KEV Catalog #rce #Roundcube #spear_phishing #Vulnerability #XSS
Daily CyberSecurity
CISA Flags Active Exploits in Erlang/OTP SSH and Roundcube Webmail: Critical RCE and XSS Flaws Under Attack
CISA adds two critical vulnerabilities to KEV: Erlang/OTP (RCE) and Roundcube (XSS). Actively exploited, these flaws pose severe risks to systems and email accounts.
⤷ Title: Zero-Click to Root: CISA Flags Active Exploits in Apple iOS and TP-Link Routers
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 17 Jun 2025 00:16:47 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CISA #Command Injection #CVE_2023_33538 #CVE_2025_43200 #cybersecurity #iCloud Link #ios #KEV Catalog #rce #Remote Code Execution #spyware #TP_Link #Vulnerability #zero_day
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 17 Jun 2025 00:16:47 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CISA #Command Injection #CVE_2023_33538 #CVE_2025_43200 #cybersecurity #iCloud Link #ios #KEV Catalog #rce #Remote Code Execution #spyware #TP_Link #Vulnerability #zero_day
Daily CyberSecurity
Zero-Click to Root: CISA Flags Active Exploits in Apple iOS and TP-Link Routers
CISA adds two actively exploited zero-days to KEV: an iOS zero-click flaw used by spyware (CVE-2025-43200) and a command injection in TP-Link routers
⤷ Title: PaperCut NG/MF Vulnerability (CVE-2023-2533) Under Active Exploitation, Allows Remote Code Execution
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 30 Jul 2025 02:59:47 +0000
════════════════════════
⌗ Tags: #Vulnerability #CISA #CSRF #cybersecurity #exploitation #KEV #PaperCut MF #PaperCut NG #Print Management #RCE #remote code execution #vulnerability
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 30 Jul 2025 02:59:47 +0000
════════════════════════
⌗ Tags: #Vulnerability #CISA #CSRF #cybersecurity #exploitation #KEV #PaperCut MF #PaperCut NG #Print Management #RCE #remote code execution #vulnerability
Penetration Testing Tools
PaperCut NG/MF Vulnerability (CVE-2023-2533) Under Active Exploitation, Allows Remote Code Execution
CISA issues an urgent alert: PaperCut NG and MF are vulnerable to CVE-2023-2533 (CSRF), allowing remote code execution if an admin clicks a malicious link.
⤷ Title: CISA Adds Citrix and Git Flaws to KEV Catalogue Amid Active Exploitation
════════════════════════
𐀪 Author: Deeba Ahmed
════════════════════════
ⴵ Time: Thu, 28 Aug 2025 19:24:39 +0000
════════════════════════
⌗ Tags: #Security #CISA #Citrix #Cybersecurity #Git #KEV #Vulnerability
════════════════════════
𐀪 Author: Deeba Ahmed
════════════════════════
ⴵ Time: Thu, 28 Aug 2025 19:24:39 +0000
════════════════════════
⌗ Tags: #Security #CISA #Citrix #Cybersecurity #Git #KEV #Vulnerability
Hackread
CISA Adds Citrix and Git Flaws to KEV Catalogue Amid Active Exploitation
Follow us on Bluesky, Twitter (X), Mastodon and Facebook at @Hackread
⤷ Title: High-Severity Vulnerabilities and Espionage Operations Drive The Week
════════════════════════
𐀪 Author: Loginsoft
════════════════════════
ⴵ Time: Fri, 12 Sep 2025 11:20:45 GMT
════════════════════════
⌗ Tags: #loginsoft #kev #cisa #vulnerability #cybersecurity
════════════════════════
𐀪 Author: Loginsoft
════════════════════════
ⴵ Time: Fri, 12 Sep 2025 11:20:45 GMT
════════════════════════
⌗ Tags: #loginsoft #kev #cisa #vulnerability #cybersecurity
Medium
High-Severity Vulnerabilities and Espionage Operations Drive The Week
Executive Summary
⤷ Title: Critical Sudo Flaw (CVSS 9.3) Added to CISA KEV List—Patch Immediately to Prevent Root Access
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 01 Oct 2025 04:20:19 +0000
════════════════════════
⌗ Tags: #Vulnerability #CISA #CVE_2025_32463 #cybersecurity #KEV #Linux #privilege escalation #Root Access #sudo
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Wed, 01 Oct 2025 04:20:19 +0000
════════════════════════
⌗ Tags: #Vulnerability #CISA #CVE_2025_32463 #cybersecurity #KEV #Linux #privilege escalation #Root Access #sudo
Penetration Testing Tools
Critical Sudo Flaw (CVSS 9.3) Added to CISA KEV List—Patch Immediately to Prevent Root Access
CISA has added the critical Sudo LPE flaw (CVE-2025-32463, CVSS 9.3) to its KEV catalog, mandating federal agencies patch the bug that allows local users to gain root access.
⤷ Title: CISA Emergency Alert: Critical Adobe AEM Flaw (CVE-2025-54253, CVSS 10.0) Under Active Exploitation
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 16 Oct 2025 03:47:02 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Adobe AEM #CISA #Critical Vulnerability #KEV Catalog #misconfiguration #rce #Remote Code Execution #zero_day
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 16 Oct 2025 03:47:02 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Adobe AEM #CISA #Critical Vulnerability #KEV Catalog #misconfiguration #rce #Remote Code Execution #zero_day
Daily CyberSecurity
CISA Emergency Alert: Critical Adobe AEM Flaw (CVE-2025-54253, CVSS 10.0) Under Active Exploitation
CISA added a Critical (CVSS 10.0) RCE flaw (CVE-2025-54253) in Adobe Experience Manager Forms to its KEV Catalog due to active exploitation. Patch is mandatory by Nov 5.
⤷ Title: CISA Warns of Active Exploitation in XWiki and VMware Vulnerabilities
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 31 Oct 2025 02:12:09 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Broadcom #CISA #CVE_2025_24893 #CVE_2025_41244 #KEV Catalog #privilege escalation #Remote Code Execution #VMware Aria Operations #VMware Tools #VulnCheck #XWiki
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Fri, 31 Oct 2025 02:12:09 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Broadcom #CISA #CVE_2025_24893 #CVE_2025_41244 #KEV Catalog #privilege escalation #Remote Code Execution #VMware Aria Operations #VMware Tools #VulnCheck #XWiki
Daily CyberSecurity
CISA Warns of Active Exploitation in XWiki and VMware Vulnerabilities
CISA adds XWiki (CVE-2025-24893) and VMware (CVE-2025-41244) to its KEV Catalog after confirming active exploitation in the wild.
⤷ Title: CISA Flags Actively Exploited OpenPLC Flaw (CVE-2021-26829)
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Sat, 29 Nov 2025 01:40:24 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CISA #CVE_2021_26829 #cybersecurity news #ICS security #KEV Catalog #OpenPLC #SCADA Security #ScadaBR #Stored XSS
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Sat, 29 Nov 2025 01:40:24 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CISA #CVE_2021_26829 #cybersecurity news #ICS security #KEV Catalog #OpenPLC #SCADA Security #ScadaBR #Stored XSS
Daily CyberSecurity
CISA Flags Actively Exploited OpenPLC Flaw (CVE-2021-26829)
The Cybersecurity and Infrastructure Security Agency (CISA) has issued a new mandate for federal agencies to secure their industrial control systems following evidence of active exploitation in th…
⤷ Title: CISA KEV Alert: HPE’s Maximum CVSS Score Flaw and a Zombie PowerPoint Bug
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 08 Jan 2026 03:55:40 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CISA #CVE_2009_0556 #CVE_2025_37164 #HPE OneView #Infrastructure Security #KEV Catalog #Microsoft PowerPoint #vulnerability management #zero_day
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 08 Jan 2026 03:55:40 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CISA #CVE_2009_0556 #CVE_2025_37164 #HPE OneView #Infrastructure Security #KEV Catalog #Microsoft PowerPoint #vulnerability management #zero_day
Daily CyberSecurity
CISA KEV Alert: HPE’s Maximum CVSS Score Flaw and a Zombie PowerPoint Bug
The Cybersecurity and Infrastructure Security Agency (CISA) has updated its Known Exploited Vulnerabilities (KEV) Catalog with two new entries that span nearly two decades of computing history. Th…