Cybersecurity News

Severe Grafana Flaw Allows Attackers To Gain Elevated Privileges

Grafana released emergency patches for a critical SCIM vulnerability (CVE-2025-41115) that allows attackers to escalate privileges or impersonate admins in…

5 months ago

Authorities Sanction Russia-Based Bulletproof Hosting Provider Linked To Ransomware

The United States, Australia, and the United Kingdom imposed coordinated sanctions on November 19, 2025, targeting Media Land LLC, a…

5 months ago

Severe Vulnerabilities In N-able N-central Enable Unauthorized Legacy API Access and Sensitive File Disclosure

N-able N-central, a popular remote monitoring and management (RMM) platform used by enterprises and managed service providers (MSPs), faces severe…

5 months ago

Critical Twonky Server Vulnerabilities Expose Authentication Bypass Path

Twonky Server version 8.5.2 contains two serious flaws that allow attackers to bypass authentication and steal admin credentials on Linux…

5 months ago

Ollama Parsing Vulnerabilities Could Let Attackers Execute Arbitrary Code Through Crafted Model Files

Ollama versions before 0.7.0 contain parsing flaws that allow attackers to execute arbitrary code by loading a crafted GGUF model…

5 months ago

Security Flaws In Cline AI Coding Agent Enable Prompt Injection, Remote Code Execution, and Data Leakage

AI coding assistants like Cline Bot promise to boost developer productivity. However, recent research reveals serious security gaps that could…

5 months ago

CISA Alerts To Active Exploitation Of Fortinet FortiWeb OS Command Injection Flaw

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical OS command injection vulnerability in Fortinet's FortiWeb web…

5 months ago

Critical SolarWinds Serv-U Flaws Allow Remote Admin-Level Code Execution

SolarWinds has patched three critical vulnerabilities in its Serv-U file transfer software that could let attackers with administrative access run…

5 months ago

Microsoft Introduces Integrated Threat Intelligence Briefing Agent In Defender Portal

Microsoft has launched a significant update at Ignite 2025, integrating the Threat Intelligence Briefing Agent directly into the Microsoft Defender…

5 months ago

CISA Issues Warning About Critical Lynx+ Gateway Vulnerability Exposing Data In Cleartext

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has released a critical advisory warning of multiple severe vulnerabilities in the…

5 months ago