LogoVulnerable U
Read
Watch
Jobs
Membership
Login
Subscribe

Archive

Apache

+1

Apache Patches Two Serious Flaws in Solr Search Platform

Jan 28, 2025

•

3 min read

Apache Patches Two Serious Flaws in Solr Search Platform

The bugs can allow arbitrary path-write access and uploading of an arbitrary configset

Newsroom
Newsroom

News

Apple Warns iPhone Users of Exploited iOS Bug

Jan 27, 2025

•

2 min read

Apple Warns iPhone Users of Exploited iOS Bug

The flaw (CVE-2025-24085) is fixed in iOS 18.3, iPadOS 18.3, macOS Sequoia 15.3, watchOS 11.3, tvOS 18.3 and visionOS 2.3.

Newsroom
Newsroom

Newsletter

🎓️ Vulnerable U | #100

Jan 24, 2025

•

13 min read

🎓️ Vulnerable U | #100

CISA's Advisory board disbanded, Zero click Outlook 0day, Fortinet saga continues, PowerSchool breach has data back to 1985, Sam Curry hacked a Subaru, and more!

Matt Johansen
Matt Johansen

News

SonicWall Warns of Potentially Exploited Critical Flaw

Jan 23, 2025

•

2 min read

SonicWall Warns of Potentially Exploited Critical Flaw

The critical flaw (CVE-2025-23006) has been identified in the SMA1000 Appliance Management Console and Central Management Console

Newsroom
Newsroom

Microsoft

+1

Zero-Click OLE RCE (CVE-2025-21298) - Microsoft Outlook Impacted

Jan 23, 2025

•

5 min read

Zero-Click OLE RCE (CVE-2025-21298) - Microsoft Outlook Impacted

Simply previewing a malicious RTF file in Microsoft Outlook can trigger the exploit—no additional clicks needed.

Newsroom
Newsroom
FBI and CISA Detail How Attackers Are Exploiting Ivanti CSA Flaws

Jan 22, 2025

•

3 min read

FBI and CISA Detail How Attackers Are Exploiting Ivanti CSA Flaws

The four vulnerabilities that Ivanti disclosed in the fall include two bugs that can be used to gain remote code execution, a path traversal bug, and a SQL injection vulnerability.

Newsroom
Newsroom

News

Mirai IoT Botnet Behind Record-Breaking DDoS Attack

Jan 22, 2025

•

3 min read

Mirai IoT Botnet Behind Record-Breaking DDoS Attack

Cloudflare, which mitigated the attack, said it targeted an Internet service provider (ISP) in Eastern Asia in 2024 and lasted 80 seconds

Newsroom
Newsroom

News

Attackers Target Aviatrix CVE-2024-50603 Flaw

Jan 21, 2025

•

3 min read

Attackers Target Aviatrix CVE-2024-50603 Flaw

Newsroom
Newsroom

News

+1

U.S. Issues Sanctions Linked to Telecom, Treasury Breaches

Jan 17, 2025

•

4 min read

U.S. Issues Sanctions Linked to Telecom, Treasury Breaches

The U.S. announced sanctions against a company and individual tied to major espionage attacks on the Treasury Department and U.S. telecom entities.

Newsroom
Newsroom

Newsletter

🎓️ Vulnerable U | #099

Jan 17, 2025

•

14 min read

🎓️ Vulnerable U | #099

Biden's cybersecurity executive order, Anatomy of a voice phishing hack, PlugX malware campaign and subsequent FBI kill switch on it, Fortinet's bad week, FTC sues GoDaddy for not doing security basics, and much more!

Matt Johansen
Matt Johansen

News

Russian Spear-Phishing Attacks Targeted WhatsApp Accounts

Jan 16, 2025

•

3 min read

Russian Spear-Phishing Attacks Targeted WhatsApp Accounts

The Star Blizzard threat group expanded its typical spear-phishing attack vector to target WhatsApp accounts.

Newsroom
Newsroom

Linux

+1

Six Bugs Fixed in Rsync

Jan 16, 2025

•

2 min read

Six Bugs Fixed in Rsync

The most serious flaw can lead to remote code execution

Newsroom
Newsroom
Load more
Vulnerable U

Vulnerable U

Infosec's favorite weekly newsletter for news, tools, and tips with 38,000+ CISOs, founders, change-makers, and straight up hackers.


Home

Posts

Authors

Account

Upgrade

Sponsors

Sponsors