Vulnerability

CISA Alerts On Actively Exploited Buffer Overflow Flaw In D-Link Routers

Attackers exploit this vulnerability through the router's web interface components, specifically "cgibin" and "hnap_main," by submitting input that exceeds allocated…

4 months ago

Over 500 Apache Tika Toolkit Instances Exposed To Critical XXE Vulnerability

Security researchers have uncovered a severe flaw in Apache Tika, a popular open-source toolkit for content analysis and extraction. CVE-2025-66516…

4 months ago

Hackers Abuse AWS IAM Eventual Consistency To Maintain Persistent Access

Attackers can keep access to AWS accounts even after admins delete compromised keys. New research from OffensAI shows how AWS…

4 months ago

CISA Includes React2Shell Vulnerability In KEV Catalog Due To Ongoing Exploitation

CISA has added CVE-2025-55182, dubbed React2Shell, to its Known Exploited Vulnerabilities (KEV) catalog due to confirmed active exploitation. This critical…

4 months ago

Next.js Unveils Scanner To Detect and Patch Apps Vulnerable To react2shell

Vercel has released a new command-line tool, fix-react2shell-next, to help developers quickly detect and patch CVE-2025-66478, a critical remote code…

4 months ago

Severe Cal.com Vulnerability Lets Attackers Bypass Authentication with Fake TOTP Codes

Cal.com, a popular open-source scheduling platform, faces a critical authentication flaw that allows attackers to bypass password checks by using…

4 months ago

2.15M Internet-Exposed Next.js Web Services Under Active Attack Patch Immediately

React Server Components (RSC) in React 19.x suffer from insecure deserialization in the "Flight" protocol, allowing attackers to send crafted…

4 months ago

Critical Flaw In Apache Tika Core Enables Exploitation Through Malicious PDF Files

A critical XML External Entity (XXE) vulnerability in Apache Tika, tracked as CVE-2025-66516, exposes users to attacks through specially crafted…

4 months ago

NCSC Launches Proactive Notification Service To Alert System Owners Of Vulnerabilities

The UK's National Cyber Security Centre (NCSC) has rolled out its Proactive Notification Service, partnering with internet monitoring firm Netcraft…

4 months ago

Security Vulnerability In NVIDIA Triton Could Let Attackers Trigger DoS Using Crafted Payloads

NVIDIA has issued a security bulletin warning about two high-severity vulnerabilities in its Triton Inference Server software. These flaws allow…

4 months ago