Critical Vite Flaw Exposes Development Servers: CVE-2025-31125 Allows Remote File Access Without Authentication
CVE-2025-31125 is a security vulnerability that affects Vite, a widely used frontend development and build tool for…
continue reading..
Critical authentication bypass vulnerability in Versa Networks Versa Concerto allows an unauthenticated remote access
CVE-2025-34026 is a critical authentication bypass vulnerability in Versa Networks Versa Concerto, the SD-WAN orchestration and management…
continue reading..
Critical Zimbra Vulnerability Exposes Mail Servers to Remote File Disclosure Attacks
CVE-2025-68645 is a high-severity Local File Inclusion (LFI) vulnerability affecting Zimbra Collaboration Suite (ZCS) in the Classic…
continue reading..
Attackers Chain Excessive Windows LOLBins to Stealthily Deploy Dual RAT Payloads
In late January 2026, researchers uncovered an unusual malware infection attempt that didn’t stand out for advanced…
continue reading..
OWASP ZAP Introduces New PTK Add-On, Bringing Browser-Based Security Testing Into One Unified Workflow
The Zed Attack Proxy (ZAP), a popular open-source security testing tool, now includes native support for the…
continue reading..
Curl Ends Bug Bounty Program After Surge of AI-Generated Vulnerability Reports
The curl project, a cornerstone of modern internet infrastructure, has announced that it will end its bug…
continue reading..
Critical SmarterMail Vulnerability Under Active Attack, Admin Accounts Compromised
A critical security vulnerability has been discovered in SmarterTools’ SmarterMail email server software, and it is currently…
continue reading..
Okta Warns of Vishing-Driven Attacks Targeting SSO Accounts
Okta has publicly warned organizations about a growing wave of attacks that combine voice phishing (vishing) with…
continue reading..
When Search Becomes the Attack Vector: APT37’s Abuse of Google Ads for Silent Espionage
Incident Overview APT37 (also known as Reaper) is a threat group linked to North Korea that has…
continue reading..
