Topic: vulnerability reporting
-
Chinese Hackers Exploiting VMware Zero-Day Since 2025
A critical privilege escalation vulnerability (CVE-2025-41244) in Broadcom's VMware software has been actively exploited since October 2024, allowing attackers to gain root-level control over affected virtual machines. The exploitation has been attributed to UNC5174, a Chinese state-sponsored thr...
Read More » -
Tata Motors Patches Security Flaws That Exposed Customer Data
A security researcher discovered and reported critical vulnerabilities in Tata Motors' E-Dukaan portal, including exposed AWS private keys that could access sensitive customer and corporate data. The breach risked exposing extensive information such as customer invoices with personal details, MyS...
Read More » -
Urgent Apple Update Fixes Critical Security Exploits
Apple has released urgent security patches for two actively exploited zero-day vulnerabilities (CVE-2025-14174 and CVE-2025-43529) in its WebKit browser engine, which is used across iPhones, iPads, and Macs. The flaws, discovered through a collaboration between Apple and Google, could allow memor...
Read More »