Also: Netskope's High-Stakes IPO, How AI Sovereignty Threatens Our Shared Reality In this week's update, four ISMG editors discussed explosive whistleblower claims about alleged mishandling of Americans' sensitive U.S. Social Security data, Netskope's push for an initial public offering and the global fight over the geopolitical sovereignty of artificial intelligence platforms.
Absolute Dental Says Breach Involved Third-Party Managed Services Firm A Nevada dental practice is notifying more than 1.2 million individuals of a hacking incident that compromised sensitive health and personal information. The incident involved "inadvertent execution of a malicious version of a legitimate software tool," said Absolute Dental.
Defense Department Suspends, Reviews Microsoft 'Digital Escorts' Program The Pentagon is reviewing Microsoft's decade-long use of "digital escorts" - U.S.-based staff who review code from Chinese engineers - into military cloud systems, a workaround now deemed a "breach of trust" that may have exposed sensitive but unclassified government data.
A vulnerability marked as critical has been reported in Cisco Data Center Network Manager. The affected element is an unknown function of the component REST API Endpoint. Performing manipulation results in protection mechanism failure.
This vulnerability is identified as CVE-2025-20347. The attack can be initiated remotely. There is not any exploit available.
It is suggested to upgrade the affected component.
A vulnerability described as problematic has been identified in Cisco Nexus Dashboard. The impacted element is an unknown function of the component REST API Endpoint. Executing manipulation can lead to insertion of sensitive information into sent data.
This vulnerability is tracked as CVE-2025-20348. The attack can be launched remotely. No exploit exists.
Upgrading the affected component is recommended.
A vulnerability has been found in basecamp google_sign_in up to 1.2.x and classified as problematic. Affected by this issue is some unknown functionality. Performing manipulation results in open redirect.
This vulnerability is reported as CVE-2025-57821. The attack is possible to be carried out remotely. No exploit exists.
The affected component should be upgraded.
A vulnerability was found in coollabsio Coolify up to 4.0.0-beta.420.5. It has been classified as critical. This vulnerability affects unknown code. The manipulation leads to code injection.
This vulnerability is traded as CVE-2025-34159. It is possible to initiate the attack remotely. There is no exploit available.
Upgrading the affected component is recommended.
A vulnerability was found in coollabsio Coolify up to 4.0.0-beta.420.6. It has been declared as critical. This issue affects some unknown processing. The manipulation results in os command injection.
This vulnerability is known as CVE-2025-34161. It is possible to launch the attack remotely. No exploit is available.
It is recommended to upgrade the affected component.
A vulnerability was found in coollabsio Coolify up to 4.0.0-beta.420.6. It has been rated as problematic. Impacted is an unknown function of the component Project Creation Workflow. This manipulation causes cross site scripting.
This vulnerability is handled as CVE-2025-34157. The attack can be initiated remotely. There is not any exploit available.
Upgrading the affected component is advised.
A vulnerability categorized as problematic has been discovered in Gitblit up to 1.7.1. The affected element is an unknown function of the component Wicket Interface. Such manipulation leads to cross site scripting.
This vulnerability is uniquely identified as CVE-2025-50977. The attack can be launched remotely. No exploit exists.
A vulnerability identified as critical has been detected in RaspAP raspap-webgui up to 3.3.2. The impacted element is an unknown function of the file includes/hostapd.php. Performing manipulation of the argument interface results in command injection.
This vulnerability was named CVE-2025-50428. The attack may be initiated remotely. There is no available exploit.
To fix this issue, it is recommended to deploy a patch.
A vulnerability labeled as critical has been found in NodeBB 4.3.0. This affects an unknown function of the file /api/v3/search/categories of the component API Endpoint. Executing manipulation of the argument Search can lead to sql injection.
The identification of this vulnerability is CVE-2025-50979. The attack may be launched remotely. There is no exploit available.
A vulnerability marked as critical has been reported in simple-admin-core up to 1.6.7. This impacts an unknown function of the file /sys-api/role/update. The manipulation leads to sql injection.
This vulnerability is referenced as CVE-2025-51667. Remote exploitation of the attack is possible. No exploit is available.
A vulnerability classified as problematic has been found in Cisco Unified Computing System and Unified Computing System E-Series Software. This affects an unknown function of the component Virtual Keyboard Video Monitor. The manipulation leads to open redirect.
This vulnerability is listed as CVE-2025-20317. The attack may be initiated remotely. There is no available exploit.
It is recommended to upgrade the affected component.
A vulnerability, which was classified as problematic, was found in Cisco Unified Computing System and Unified Computing System E-Series Software. Affected by this vulnerability is an unknown functionality of the component Virtual Keyboard Video Monitor. Such manipulation leads to basic cross site scripting.
This vulnerability is documented as CVE-2025-20342. The attack can be executed remotely. There is not any exploit available.
You should upgrade the affected component.