B3NCLOUD.NET
News Intel Stats Tools
CyberNews
B3N.CLOUD
Hauptseiten
Startseite
CyberNews
Quick IT-Tools
Suche
Updates
Security Tools
Breach Check
Phishing Check
IoC Extractor
SSL Check
E-Mail Header Analyzer
CVE-Suche
Cyber IntelligenceNEU
IT-Praxis
Firewall RulesNEU
Security ChecklistsNEU
Incident ResponseNEU
Regex TesterNEU
Cron BuilderNEU
Log AnalyzerNEU
Informationen
Dokumentation
Statistiken
Impressum
Datenschutz
RSS Feed
© 2026 b3ncloud.net

ARTIKEL SUCHE

Threat Feed Query

Durchsuche alle aggregierten Security-Artikel nach Schlagworten, CVE-IDs und Quellen.

2871 Ergebnisse fuer critical Seite 77 von 144

SAP Patches Critical Flaws in SQL Anywhere Monitor, Solution Manager

Hardcoded credentials in SQL Anywhere Monitor could allow attackers to execute arbitrary code on vulnerable deployments. The post SAP Patches Critical Flaws in SQL Anywhere Monitor, Solution Manager appeared first on Sec

securityweek.com • 2025-11-11

Devolutions Server Vulnerability Let Attackers Impersonate Users Using Pre-MFA Cookie

A critical vulnerability in Devolutions Server could allow attackers with low-level access to impersonate other user accounts by exploiting how the application handles authentication cookies before multi-factor authentic

cybersecuritynews.com • 2025-11-11

WatchGuard Firebox Firewall Vulnerability Let Attackers Gain Unauthorized SSH Access

A critical vulnerability in WatchGuard Firebox firewalls could allow attackers to gain complete administrative access to the devices without any authentication. The flaw, tracked as CVE-2025-59396, stems from insecure de

cybersecuritynews.com • 2025-11-11

Threat Actors Attacking Outlook and Google Bypassing Traditional Email Defenses

Email-based threats have reached a critical inflection point in the third quarter of 2025. Threat actors are systematically exploiting weaknesses in traditional email security defenses by targeting the world’s two larges

cybersecuritynews.com • 2025-11-11

SAP Security Update – Patch for Critical Vulnerabilities Allowing Code Execution and Injection Attacks

SAP released its monthly Security Patch Day updates, addressing 18 new security notes and providing two updates to existing ones, focusing on vulnerabilities that could enable remote code execution and various injection

cybersecuritynews.com • 2025-11-11

Hackers Exploiting Triofox 0-Day Vulnerability to Execute Malicious Payload Abusing Anti-Virus Feature

Google Mandiant has disclosed active exploitation of CVE-2025-12480, a critical unauthenticated access vulnerability in Gladinet’s Triofox file-sharing platform. The threat cluster tracked as UNC6485 has been weaponizing

cybersecuritynews.com • 2025-11-11

Critical Triofox bug exploited to run malicious payloads via AV configuration

Hackers exploited Triofox flaw CVE-2025-12480 to bypass auth and install remote access tools via the platform’s antivirus feature. Google’s Mandiant researchers spotted threat actors exploiting a now-patched Triofox flaw

securityaffairs.com • 2025-11-11

CISA Warns of Samsung Mobile Devices 0-Day RCE Vulnerability Exploited in Attacks

CISA has added a critical zero-day vulnerability affecting Samsung mobile devices to its Known Exploited Vulnerabilities catalog. Warning that threat actors are actively exploiting the flaw in real-world attacks. The vul

cybersecuritynews.com • 2025-11-11

Threat Actors Leverage RMM Tools to Deploy Medusa & DragonForce Ransomware

A sophisticated wave of ransomware attacks targeting UK organizations has emerged in 2025, exploiting vulnerabilities in the widely-used SimpleHelp Remote Monitoring and Management platform. Two prominent ransomware grou

cybersecuritynews.com • 2025-11-11

Hackers Exploiting Triofox Flaw to Install Remote Access Tools via Antivirus Feature

Google's Mandiant Threat Defense on Monday said it discovered n-day exploitation of a now-patched security flaw in Gladinet's Triofox file-sharing and remote access platform. The critical vulnerability, tracked as CVE-20

thehackernews.com • 2025-11-10

CISA orders feds to patch Samsung zero-day used in spyware attacks

CISA ordered U.S. federal agencies today to patch a critical Samsung vulnerability that has been exploited in zero-day attacks to deploy LandFall spyware on devices running WhatsApp. [...]

bleepingcomputer.com • 2025-11-10

Popular JavaScript library expr-eval vulnerable to RCE flaw

A critical vulnerability in the popular expr-eval JavaScript library, with over 800,000 weekly downloads on NPM, can be exploited to execute code remotely through maliciously crafted input. [...]

bleepingcomputer.com • 2025-11-10

Two New Web Application Risk Categories Added to OWASP Top 10

OWASP has added two new categories to the revised version of its Top 10 list of the most critical risks to web applications. The post Two New Web Application Risk Categories Added to OWASP Top 10 appeared first on Securi

securityweek.com • 2025-11-10

Critical Vulnerability in Popular NPM Library Exposes AI and NLP Apps to Remote Code Execution

A critical security flaw has been discovered in the widely used npm package expr-eval, potentially exposing AI and natural language processing applications to remote code execution attacks. The vulnerability, tracked as 

cybersecuritynews.com • 2025-11-10

LangGraph Vulnerability Allows Malicious Python Code Execution During Deserialization

A critical remote code execution vulnerability has been discovered in LangGraph’s checkpoint serialization system. The flaw CVE-2025-64439 affects versions of langgraph-checkpoint before 3.0. It allows attackers to execu

cybersecuritynews.com • 2025-11-10

Critical runc Vulnerabilities Put Docker and Kubernetes Container Isolation at Risk

Three critical vulnerabilities in runc, the container runtime powering Docker, Kubernetes, and other containerization platforms. These flaws could allow attackers to escape container isolation and gain root access to hos

cybersecuritynews.com • 2025-11-10

Monsta web-based FTP Remote Code Execution Vulnerability Exploited

A critical remote code execution vulnerability in Monsta FTP, a popular web-based FTP client used by financial institutions and enterprises worldwide. The flaw, now tracked as CVE-2025-34299, affects multiple versions of

cybersecuritynews.com • 2025-11-10

Seven QNAP Zero-Day Vulnerabilities Exploited at Pwn2Own 2025 Now Patched

QNAP has addressed seven critical zero-day vulnerabilities in its network-attached storage (NAS) operating systems, following their successful exploitation by security researchers at Pwn2Own Ireland 2025. These flaws, id

cybersecuritynews.com • 2025-11-08

The Government Shutdown Is a Ticking Cybersecurity Time Bomb

Many critical systems are still being maintained, and the cloud provides some security cover. But experts say that any lapses in protections like patching and monitoring could expose government systems.

wired.com • 2025-11-07

15+ Weaponized npm Packages Attacking Windows Systems to Deliver Vidar Malware

A sophisticated supply-chain attack has emerged targeting Windows systems through compromised npm packages, marking a critical vulnerability in open-source software distribution. Between October 21 and 26, 2025, threat a

cybersecuritynews.com • 2025-11-07
 Zurueck 1 2 3 ... 76 77 78 ... 143 144 Weiter 
B3N.CLOUD
Docs News Tools Suche Impressum Datenschutz
Status
Cookies

Diese Website verwendet ausschließlich technisch notwendige Cookies (Session, Spracheinstellung). Kein Tracking, keine Werbung. Mehr erfahren