Shadowserver

Entity category: organization

Business

Critical SolarWinds Serv-U Flaws Grant Root Server Access

SolarWinds has released critical security patches for its Serv-U file transfer software to fix four vulnerabilities that could allow remote…

Read More »
Cybersecurity

Patched RoundCube Flaws Actively Exploited, CISA Warns

CISA has mandated federal agencies to patch two actively exploited vulnerabilities in Roundcube Webmail within three weeks, highlighting the persistent…

Read More »
Business

6,000+ SmarterMail Servers Vulnerable to Hijacking

A critical authentication bypass vulnerability (CVE-2026-23760) in SmarterMail email servers allows attackers to reset administrator passwords and take full control…

Read More »
Business

Patched FortiGate Firewalls Still Vulnerable to CVE-2025-59718

A critical Fortinet firewall vulnerability (CVE-2025-59718) remains actively exploitable even on systems with official patches, allowing attackers to bypass authentication…

Read More »
Business

Palo Alto Firewall Flaw Lets Hackers Trigger DoS Attacks

A critical vulnerability (CVE-2026-0227) in Palo Alto firewalls could allow unauthenticated attackers to remotely disable them via a denial-of-service attack,…

Read More »
Business

Critical Flaw Exposes 10K+ Fortinet Firewalls to 2FA Bypass

A critical five-year-old Fortinet firewall flaw (CVE-2020-12812) allows attackers to bypass two-factor authentication by altering a username's case, and over…

Read More »
Business

CISA Mandates Federal Patch for Actively Exploited MongoBleed Flaw

A critical vulnerability in MongoDB, tracked as CVE-2025-14847 and dubbed MongoBleed, is being actively exploited to remotely steal sensitive data…

Read More »
Artificial Intelligence

WatchGuard Firewalls Hacked, Fake PoCs Target Security Pros

Critical vulnerabilities in widely used firewalls like WatchGuard are being actively exploited, requiring immediate patching to prevent network breaches. Threat…

Read More »
Business

Critical RCE flaw exposes over 115,000 WatchGuard firewalls

A critical vulnerability (CVE-2025-14733) in WatchGuard Firebox firewalls allows unauthenticated attackers to remotely execute code, primarily affecting devices with IKEv2…

Read More »
Cybersecurity

Urgent: WatchGuard Firewalls Targeted by Critical Attack (CVE-2025-14733)

Over 115,000 WatchGuard Firebox firewalls are actively being targeted via a critical, unauthenticated remote code execution flaw (CVE-2025-14733) in the…

Read More »
Cybersecurity

Thousands of FortiCloud SSO Devices Vulnerable to Remote Hacks

Tens of thousands of internet-facing Fortinet devices remain vulnerable to critical authentication bypass flaws (CVE-2025-59718/9), creating a massive attack surface…

Read More »
BigTech Companies

Cisco Customers Vulnerable to New Chinese Hacking Campaign

A Chinese state-sponsored hacking campaign is exploiting a critical zero-day vulnerability (CVE-2025-20393) in Cisco's Secure Email Gateway and Web Manager…

Read More »
BigTech Companies

SonicWall SMA1000 Zero-Day Exploited in Active Attacks

SonicWall has issued an urgent alert for SMA1000 appliance users to apply a critical update, as active attacks exploit a…

Read More »
Business

CISA Mandates Federal Patch for Actively Exploited Geoserver Flaw

CISA has mandated federal agencies to patch a critical, actively exploited vulnerability (CVE-2025-58360) in GeoServer that allows attackers to steal…

Read More »
Business

Ivanti warns of critical code execution flaw in Endpoint Manager

A critical vulnerability (CVE-2025-10573) in Ivanti's Endpoint Manager allows unauthenticated attackers to execute arbitrary code by tricking an administrator into…

Read More »
Business

CISA: Hackers Actively Exploiting WatchGuard Firewall Flaw

A critical security flaw (CVE-2025-9242) in WatchGuard Firebox firewalls is being actively exploited, prompting CISA to issue an urgent patch…

Read More »
Business

Police Takedown: Rhadamanthys, VenomRAT, and Elysium Malware Operations Disrupted

An international law enforcement effort led by Europol and Eurojust dismantled over 1,000 servers used by major malware families like…

Read More »
BigTech Companies

Microsoft WSUS Patch Disables Windows Server Hotpatching

Microsoft's emergency security update KB5070881, intended to fix a critical remote code execution vulnerability (CVE-2025-59287), inadvertently disrupted hotpatching on some…

Read More »
Business

Hackers Breach Federal Agency via GeoServer Flaw, CISA Warns

A critical vulnerability (CVE-2024-36401) in GeoServer was exploited to breach a U.S. federal agency's network after attackers compromised an unpatched…

Read More »
BigTech Companies

Canada’s House of Commons probes cyberattack data breach

Canada's House of Commons faces a cyberattack compromising sensitive employee data, including names, job titles, and email addresses, raising identity…

Read More »