[CRITICAL] – JFrog Artifactory Flaws Actively Exploited to Gain Administrative Control
Wiz reports active exploitation of three Artifactory vulnerabilities, including chains that yield administrative control.
Cybersecurity, AI, etc.
Cybersecurity (breaches, incidents, vulnerabilities, ransomware, supply chain attacks)
Wiz reports active exploitation of three Artifactory vulnerabilities, including chains that yield administrative control.
Trezor says attackers breached its email provider and sent phishing messages from its legitimate domain.
Veradigm says stolen vendor credentials were used to download patient personal data, including some Social Security numbers.
Check Point released fixes for two CVSS 9.8 VPN certificate flaws that may permit unauthenticated remote code execution.
Android's September updates address 180 vulnerabilities, including critical System-component issues that may allow remote code execution.
Wiz found 9.6% of sampled public LiteLLM instances accepted default or no authentication, enabling severe AI-gateway compromise paths.
Attackers are exploiting Fortinet CVE-2025-25249 to deploy PivotC2; update affected FortiOS and FortiSwitchManager releases.
CISA added an actively exploited NetScaler authentication bypass to KEV; exposed gateway and AAA deployments need urgent updates.
Cisco reports active exploitation of two Secure FMC flaws, including a CVSS 10 authentication bypass enabling root access.
Google issued Chrome updates for an exploited V8 out-of-bounds write; update desktop Chrome to the patched Stable release.