SecurityOnline

F5 Warns of TLS Session Resumption Vulnerability in NGINX

“This vulnerability can lead to the exposure of resources or functionality to unintended actors, possibly providing attackers with limited access to sensitive information,” F5 warns in its advisory.

Security Flaws in Apache Cassandra Lead to Unauthorized Access, Privilege Escalation, and JMX Credential Theft

Organizations relying on Cassandra are urged to take immediate action to mitigate these risks. Upgrading to the latest patched versions is paramount. The recommended fixes are in versions 3.0.31, 3.11.18, 4.0.16, 4.1.8, and 5.0.3.

Symantec PAM Patches Critical Security Flaw – CVE-2025-24503 (CVSSv4 9.3)

Symantec has released version 4.2.1 of its Privileged Access Manager (PAM) to address multiple security vulnerabilities, including those that could allow for remote code execution and session hijacking.

TAG-124 Traffic Distribution System Powers Multiple Malware Campaigns

The TDS network comprises compromised WordPress websites, actor-controlled payload servers, and a sophisticated management system, allowing cybercriminals to dynamically route traffic to malicious content while evading detection.

Threat Actors Exploit CVE-2019-18935 to Gain Remote Access and Elevate Privileges

The eSentire Threat Response Unit (TRU) warned of threat actors exploiting a six-year-old vulnerability, CVE-2019-18935, in Progress Telerik UI for ASP.NET AJAX. It allows attackers to upload and execute malicious files on vulnerable servers.

Google Fixes High-Severity Chrome Vulnerabilities (CVE-2025-0444 & CVE-2025-0445)

This release is particularly noteworthy for addressing two high-severity use-after-free vulnerabilities, one in Skia and the other in V8, Chrome’s rendering engine and JavaScript engine, respectively.

Critical Veeam Backup Vulnerability Enables Remote Code Execution

The vulnerability affects a wide range of Veeam products, including Veeam Backup for Salesforce, Nutanix AHV, AWS, Microsoft Azure, Google Cloud, Oracle Linux Virtualization Manager, and Red Hat Virtualization.

Update: PoC Exploit Released for Linux Kernel Enabling Privilege Escalation and Container Escape

The vulnerability affects various Linux kernel versions, including v6.8 to v6.9, v5.15.147, v6.1.78, and v6.6.17. System administrators are advised to upgrade to patched versions immediately.

Update: PoC Privilege Escalation Exploit Revealed for Active Directory Domain Services

The exploit takes advantage of Windows Performance Counters, a mechanism that allows applications and services to register monitoring routines via PerfMon.exe or Windows Management Instrumentation (WMI).

Fully Undetectable macOS Backdoor Called "Tiny FUD" Discovered

This stealthy macOS malware leverages process name manipulation, DYLD injection, and C2-based command execution to operate undetected, making it a significant threat to Apple users.

Defend Against Threats with Cyber Fusion

Cyware is the leading provider of cyber fusion solutions that power threat intelligence sharing , end-to-end automation and 360-degree threat response.

Trending Tags