Aggregator
CISA Releases Ten Industrial Control Systems Advisories
CISA released ten Industrial Control Systems (ICS) advisories on September 30, 2025. These advisories provide timely information about current security issues, vulnerabilities, and exploits surrounding ICS.
- ICSA-25-273-01 MegaSys Enterprises Telenium Online Web Application
- ICSA-25-273-02 Festo SBRD-Q/SBOC-Q/SBOI-Q
- ICSA-25-273-03 Festo CPX-CEC-C1 and CPX-CMXX
- ICSA-25-273-04 Festo Controller CECC-S,-LK,-D Family Firmware
- ICSA-25-273-05 OpenPLC_V3
- ICSA-25-273-06 National Instruments Circuit Design Suite
- ICSA-25-273-07 LG Innotek Camera Multiple Models
- ICSA-25-063-02 Keysight Ixia Vision Product Family (Update A)
- ICSA-22-298-02 HEIDENHAIN Controller TNC (Update A)
- ICSA-25-226-26 Rockwell Automation FLEX 5000 I/O (Update A)
CISA encourages users and administrators to review newly released ICS advisories for technical details and mitigations.
CAISI Evaluation of DeepSeek AI Models Finds Shortcomings and Risks
Sharpening the Focus on Product Requirements and Cybersecurity Risks: Updating Foundational Activities for IoT Product Manufacturers
Conversations and the Media Climate Accord at IBC2025
Гуманоиды, выходите из симуляции. NVIDIA открывает нейросетям двери в реальный мир
安卓开发与逆向第一阶段完结,全部App代码兼容安卓16,蓝色锁头icon可爱又迷人,第二阶段开更!免费送知识星球一年!
Stop Alert Chaos: Context Is the Key to Effective Incident Response
Defensie start met bouw radarinstallatie Herwijnen
CISA Issues Alert on Actively Exploited Libraesva ESG Command Injection Vulnerability
The Cybersecurity and Infrastructure Security Agency (CISA) has issued a critical security alert highlighting the active exploitation of a serious vulnerability in the Libraesva Email Security Gateway (ESG). Cataloged as CVE-2025-59689, this command injection vulnerability has emerged as a significant threat for organizations relying on Libraesva’s email security defenses. Libraesva’s Email Security Gateway is widely […]
The post CISA Issues Alert on Actively Exploited Libraesva ESG Command Injection Vulnerability appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
Western Digital My Cloud NAS devices vulnerable to unauthenticated RCE (CVE-2025-30247)
Western Digital has fixed a critical remote code execution vulnerability (CVE-2025-30247) in the firmware powering its My Cloud network-attached storage (NAS) devices, and has urged users to upgrade as soon as possible. About CVE-2025-30247 Western Digital’s My Cloud devices are designed for home and small business users, to store documents and other content and access it via mobile apps or web browser. In small office settings, it’s also often used as a server for backups … More →
The post Western Digital My Cloud NAS devices vulnerable to unauthenticated RCE (CVE-2025-30247) appeared first on Help Net Security.
Linus Torvalds 从 Linux 6.18 中完全移除了 Bcachefs
От «user» до «root» за секунду: критический баг в sudo угрожает миллионам устройств
【安全圈】伪造 Postmark MCP 服务器 npm 包窃取数千封邮件,仅凭一行恶意代码
【安全圈】荷兰两名17岁少年因涉嫌为亲俄黑客从事间谍活动被捕
【安全圈】日本最大啤酒制造商因网络攻击暂停生产
【安全圈】CISA警告:Linux/Unix系统关键 Sudo 漏洞已被在野利用
Urgent: China-Linked Hackers Exploit New VMware Zero-Day Since October 2024
CISA Issues Alert on Active Exploitation of Linux and Unix Sudo Flaw
The Cybersecurity and Infrastructure Security Agency (CISA) has released an urgent alert for system administrators and IT teams worldwide. Researchers have confirmed that attackers are actively exploiting a serious vulnerability in the sudo utility used on many Linux and Unix systems. This flaw, tracked as CVE-2025-32463, could allow attackers to gain full administrative control of affected machines. Sudo […]
The post CISA Issues Alert on Active Exploitation of Linux and Unix Sudo Flaw appeared first on GBHackers Security | #1 Globally Trusted Cyber Security News Platform.
Ivanti upgrades Connect Secure with hardened system and gateway improvements
Ivanti released Ivanti Connect Secure (ICS) version 25.X. The update includes a modernized enterprise-grade OS, platform hardening, and gateway enhancements designed to reduce vulnerabilities, shrink attack surfaces, and improve resilience. Enterprise security is central to Connect Secure 25.X. Many legacy software components have been rearchitected with security in mind. These enhancements include a secure web server and Web Application Firewall (WAF), Secure Boot protection, disk encryption, key management, and secure factory reset, to name a … More →
The post Ivanti upgrades Connect Secure with hardened system and gateway improvements appeared first on Help Net Security.