Attackers Abuse Google Cloud Services to Steal Microsoft 365 Credentials
Cybersecurity researchers have uncovered an ongoing phishing campaign where threat actors are actively misusing Google Cloud infrastructure…
continue reading..
CVE-2025-13744: Stored XSS in Search & Filter Views Enables Session Hijack and Admin Compromise
CVE-2025-13744 Vulnerability Type: Cross-Site Scripting (XSS)Category: Web Application – Stored XSSCVSS Score: 8.4Severity: HighAttack Vector: NetworkAttack Complexity:…
continue reading..
CVE-2025-47388: Qualcomm DSP Memory Corruption Exposes Android Devices to Kernel Crash and Privilege Escalation
Executive Summary What This Vulnerability Is CVE-2025-47388 is a memory corruption flaw in Qualcomm’s DSP service, a…
continue reading..
CVE-2025-15471: Critical Unauthenticated OS Command Injection in TRENDnet TEW-713RE Router
Executive summary There’s an OS command-injection flaw in the TEW-713RE web management stack. An attacker who can…
continue reading..
CVE-2025-30996: Critical WordPress Theme Flaw Enables Instant Web-Shell Takeover
Severity: CriticalCVSS: ~9.8Impact: Full site takeoverExploitability: High (authenticated attacker)Attack Outcome: Remote code execution via web shell What’s…
continue reading..
CVE-2025-14942: Silent SSH Handshake Flaw Exposes Credentials in wolfSSH
Product: wolfSSH (by wolfSSL)Vulnerability Type: Credential Disclosure / Authentication Logic FlawSeverity: CRITICALCVSS v3.x Score: 9.4 (Critical)Attack Vector:…
continue reading..
CVE-2025-60534: When Trust Replaces Authentication in Blue Access Cobalt
CVE ID: CVE-2025-60534Product: Blue Access – CobaltVulnerability Type: Authentication BypassSeverity: CriticalCVSS (estimated): 9.8Attack Vector: Remote, unauthenticatedPrivileges Required:…
continue reading..
CVE-2025-60262: Unauthenticated Root Takeover via FTP on H3C Wireless Controllers
Vulnerability Type: Authentication Bypass / Privilege EscalationAffected Component: FTP service (vsftpd) on H3C Wireless ControllersSeverity: CriticalCVSS v3.1…
continue reading..
Phishing from the Inside: Microsoft Warns of Email Routing Risks
Microsoft’s Threat Intelligence team has alerted organizations that threat actors are increasingly exploiting misconfigured email routing and…
continue reading..
