Topic: cisa alert
-
Multiple Threat Groups Exploit Active WinRAR Vulnerability
A critical path traversal vulnerability (CVE-2025-6218) in WinRAR for Windows is being actively exploited, allowing attackers to execute arbitrary code by tricking users into opening malicious files. Multiple sophisticated threat groups, including Bitter APT and Gamaredon, are weaponizing the fla...
Read More » -
Palo Alto firewall zero-day exploited for weeks
A critical zero-day vulnerability (CVE-2026-0300) in Palo Alto Networks PAN-OS firewalls is being exploited by suspected state-sponsored threat actors, allowing unauthenticated remote code execution with root privileges through a buffer overflow in the User-ID Authentication Portal. First unsucce...
Read More » -
Patch Now: CISA Warns of Active Oracle Identity Manager Attack
A critical vulnerability (CVE-2025-61757) in Oracle Identity Manager is being actively exploited, allowing unauthenticated attackers to execute arbitrary code via HTTP. CISA has urgently added this flaw to its Known Exploited Vulnerabilities catalog, advising immediate patching or isolation of af...
Read More » -
Ransomware Gangs Now Exploiting Critical Linux Flaw
A critical Linux kernel vulnerability (CVE-2024-1086) is now being actively exploited by ransomware gangs, allowing attackers to gain complete control over affected systems. The flaw enables local privilege escalation to root access, permitting attackers to disable security, deploy malware, and s...
Read More » -
Skuld Infostealer Exploits WSUS Flaw (CVE-2025-59287)
A critical remote code execution vulnerability (CVE-2025-59287) in Windows Server Update Services (WSUS) is being actively exploited, allowing attackers to install information-stealing malware on unpatched systems. The flaw stems from unsafe deserialization of untrusted data, enabling unauthentic...
Read More »