Wireshark 4.6.1: critical security update addresses major vulnerabilities
A recent update from the Wireshark Foundation addresses critical vulnerabilities impacting the widely used network protocol analyzer, potentially exposing users to denial-of-service conditions. The vulnerability lies within the...
Chrome: a rapid-response Zero-Day exploits type confusion vulnerabilities
Google’s Chrome browser has found itself squarely in the crosshairs. A critical, previously unknown vulnerability – a zero-day – is actively being leveraged in the wild, triggering a...
NVIDIA NeMo Framework: a critical cascade of vulnerabilities
The NVIDIA NeMo Framework, a cornerstone of conversational AI development, has recently revealed a significant and frankly concerning weakness. The disclosure, detailed in a critical security update, centers...
China-Linked APTs exploit critical SAP NetWeaver vulnerability to breach over 580 systems globally
In a significant escalation of cyber-espionage activities, multiple China-affiliated advanced persistent threat (APT) groups have been found actively exploiting a recently disclosed critical vulnerability in SAP NetWeaver, identified...
MITRE Signals Critical Risk to CVE Program as Federal Funding Expires
The cybersecurity world faces a significant challenge as the Common Vulnerabilities and Exposures (CVE) program, a cornerstone of global vulnerability management, risks disruption due to expiring federal funding....
Malicious NPM packages targeting PayPal users: a recap analysis
FortiGuard Labs recently uncovered a series of malicious NPM packages designed to steal sensitive information from compromised systems. These packages, created between March 5 and March 14, were...
Surge in Palo Alto Networks scanner activity
GreyNoise has detected a significant surge in login scanning activity aimed at Palo Alto Networks PAN-OS GlobalProtect portals. In the last month, nearly 24,000 unique IP addresses have...
Critical Remote Code Execution vulnerability discovered in GiveWP WordPress Plugin (CVE-2025-0912)
A critical security vulnerability, identified as CVE-2025-0912, has been discovered in the GiveWP WordPress donation plugin. This flaw potentially exposes over 100,000 WordPress websites to remote code execution...