SonicWall has urged its customers to patch three security vulnerabilities affecting its Secure Mobile Access (SMA) appliances, one of them tagged as exploited in attacks [...]
The nation-state threat actor known as MirrorFace has been observed deploying malware dubbed ROAMINGMOUSE as part of a cyber espionage campaign directed against government agencies and public institutions in Japan and Taiwan.
The activity, detected by Trend Micro in March 2025, involved the use of spear-phishing lures to deliver an updated version of a backdoor called ANEL.
"The ANEL file from
A vulnerability was found in Danfoss AK-SM 8xxA 4.2 and classified as critical. This issue affects some unknown processing. The manipulation leads to improper authentication.
The identification of this vulnerability is CVE-2025-41450. The attack may be initiated remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability has been found in Netis Systems WF2220 1.2.31706 and classified as critical. This vulnerability affects unknown code of the file /cgi-bin-igd/netcore_set.cgi. The manipulation leads to missing authentication.
This vulnerability was named CVE-2025-3759. The attack can be initiated remotely. There is no exploit available.
A vulnerability, which was classified as critical, was found in Netis Systems WF2220 1.2.31706. This affects an unknown part of the file /cgi-bin-igd/netcore_get.cgi. The manipulation leads to missing authentication.
This vulnerability is uniquely identified as CVE-2025-3758. Access to the local network is required for this attack. There is no exploit available.
Currently trending CVE - Hype Score: 52 - A vulnerability in the Out-of-Band Access Point (AP) Image Download feature of Cisco IOS XE Software for Wireless LAN Controllers (WLCs) could allow an unauthenticated, remote attacker to upload arbitrary files to an affected system.
This vulnerability is due to the presence ...
Currently trending CVE - Hype Score: 1 - Craft is a content management system. Versions of Craft CMS on the 4.x branch prior to 4.14.13 and on the 5.x branch prior to 5.6.16 contains a potential remote code execution vulnerability via Twig SSTI. One must have administrator access and `ALLOW_ADMIN_CHANGES` must be ...
Currently trending CVE - Hype Score: 1 - A use-after-free issue was addressed with improved memory management. This issue is fixed in macOS Sequoia 15.4, tvOS 18.4, macOS Ventura 13.7.5, iPadOS 17.7.6, macOS Sonoma 14.7.5, iOS 18.4 and iPadOS 18.4, visionOS 2.4. An attacker on the local network may be able to corrupt ...
Currently trending CVE - Hype Score: 1 - The issue was addressed with improved memory handling. This issue is fixed in AirPlay audio SDK 2.7.1, AirPlay video SDK 3.6.0.126, CarPlay Communication Plug-in R18.1. An attacker on the local network may cause an unexpected app termination.