Tag: update
-
PowerDNS Vulnerability Allows Attackers to Trigger DoS Attacks Through Malicious TCP Connections
PowerDNS has released a critical security update to address a vulnerability in its DNSdist load balancer that could allow remote attackers to trigger denial of service attacks without authentication. The issue, tracked as CVE-2025-30193, was patched in version 1.9.10 released on May 20, 2025. Security researchers warn that organizations using DNSdist should apply this update…
-
M&S Braces for £300 Million Cyber-Attack Costs
An M&S trading update estimates the ongoing cyber-incident will cost £300m, largely from lost sales due to the suspension of online orders First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/ms-300million-cyber-costs/
-
A critical flaw in OpenPGP.js lets attackers spoof message signatures
A critical flaw in OpenPGP.js, tracked as CVE-2025-47934, lets attackers spoof message signatures; updates have been released to address the flaw. A critical vulnerability, tracked as CVE-2025-47934, in OpenPGP.js allowed spoofing of message signature verification. OpenPGP.js is an open-source JavaScript library that implements the OpenPGP standard for email and data encryption. It allows developers to…
-
Critical VMware ESXi vCenter Flaw Allows Remote Execution of Arbitrary Commands
VMware by Broadcom has released critical security updates to address multiple severe vulnerabilities affecting its virtualization products, with evidence suggesting active exploitation in the wild. The vulnerabilities, tracked as CVE-2025-22224, CVE-2025-22225, and CVE-2025-22226, affect VMware ESXi, Workstation, Fusion, Cloud Foundation, and Telco Cloud Platform products. With CVSS scores ranging from 7.1 to 9.3, these flaws…
-
Schwachstelle in Chrome wird derzeit aktiv ausgenutzt
Eine Anfang Mai bekannt gewordene Sicherheitslücke in Google Chrome wird derzeit aktiv ausgenutzt, wie die US-Sicherheitsbehörde CISA warnt. Nutzer sollten schnellstmöglich ein Update durchführen. First seen on 8com.de Jump to article: www.8com.de/cyber-security-blog/schwachstelle-in-chrome-wird-derzeit-aktiv-ausgenutzt
-
Judge Lets Delta Lawsuit Over CrowdStrike Outage Proceed
Georgia Court Allows Claims of Fraud, Trespass Over Falcon Software Update. Delta can proceed with its lawsuit against CrowdStrike over a July 2024 update that allegedly bypassed Microsoft safeguards and crashed thousands of systems. The judge found that Delta sufficiently alleged fraud, computer trespass and gross negligence, allowing key claims to move forward. First seen…
-
Freshly discovered bug in OpenPGP.js undermines whole point of encrypted comms
Tags: updateUpdate before that proof-of-concept comes to bite First seen on theregister.com Jump to article: www.theregister.com/2025/05/20/openpgp_js_flaw/
-
You’ve already been targeted: Why patch management is mission-critical
Tags: updateFirst seen on csoonline.com Jump to article: https://www.csoonline.com/article/3990385/youve-already-been-targeted-why-patch-management-is-mission-critical.html
-
Selbstzerstörung per Update: Diese Cyber-Waffe macht Botnetze unschädlich
First seen on t3n.de Jump to article: t3n.de/news/selbstzerstoerung-per-update-1686660/
-
Microsoft Issues Urgent Patch to Resolve BitLocker Recovery Problem
Microsoft has released an emergency update to address a critical issue affecting Windows 10 devices with specific Intel processors. The update (KB5061768) fixes a problem introduced in the May 13, 2025 security update that was causing unexpected system failures and forcing users to enter BitLocker recovery keys. This fix comes as Microsoft continues its regular…
-
Tor Browser 14.5.2 Released: Bug Fixes and Enhanced Features
Tor Project has launched Tor Browser 14.5.2, a significant update addressing security vulnerabilities, refining cross-platform functionality, and enhancing build system reliability. This release integrates critical Firefox security patches, resolves longstanding privacy-related bugs, and implements infrastructural improvements to streamline future development. Tor Browser 14.5.2 prioritizes security by rebasing its underlying engine on Firefox 128.10.1esr, Mozilla’s Extended…
-
Windows 10: Notfallfix für Bitlocker-Panne erfordert manuellen Eingriff
Einige Windows-10-Systeme fragen nach der Installation des Mai-Updates wiederholt den Bitlocker-Key ab. Ein Fix ist nun verfügbar, muss aber manuell eingespielt werden. First seen on golem.de Jump to article: www.golem.de/news/windows-10-notfallfix-fuer-bitlocker-panne-erfordert-manuellen-eingriff-2505-196357.html
-
Windows 11 24H2: KB5058411 wirft Update-Fehler 0x800f081f
Kurze Frage in die Runde der Blog-Leser, ob die Installation des Mai 2025-Updates KB5058411 für Windows 11 24H2 durchgelaufen ist. Mir liegt eine Anfrage vor, ob mir etwas zum Fehler KB5058411 aus der Leserschaft vorliegt. Es ist ein eher generischer … First seen on borncity.com Jump to article: www.borncity.com/blog/2025/05/20/windows-11-24h2-kb5058411-wirft-update-fehler-0x800f081f/
-
Mozilla fixed zero-days recently demonstrated at Pwn2Own Berlin 2025
Mozilla addressed two critical Firefox vulnerabilities that could be potentially exploited to access sensitive data or achieve code execution. Mozilla released security updates to fix two critical vulnerabilities in the Firefox browser that could be potentially exploited to access sensitive data or achieve code execution. >>This week at the security hacking competition pwn2own, security researchers…
-
Windows 10 emergency updates fix BitLocker recovery issues
Microsoft has released out-of-band updates to fix a known issue causing Windows 10 systems to boot into BitLocker recovery after installing the May 2025 security updates. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/microsoft/windows-10-emergency-updates-fix-bitlocker-recovery-issues/
-
RCE Vulnerability Found in RomethemeKit For Elementor Plugin
RomethemeKit for Elementor has released a patch addressing an RCE vulnerability exposing 30,000 sites First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/rce-vulnerability-in-romethemekit/
-
Mozilla fixes Firefox zero-days exploited at hacking contest
Mozilla released emergency security updates to address two Firefox zero-day vulnerabilities demonstrated in the recent Pwn2Own Berlin 2025 hacking competition. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/mozilla-fixes-firefox-zero-days-exploited-at-hacking-contest/
-
Java Development Updates: Key Features, Vulnerabilities News
OpenJDK updates for JDK 25, including new JEPs, release schedules, and advancements in AI tools for Java development. First seen on securityboulevard.com Jump to article: securityboulevard.com/2025/05/java-development-updates-key-features-vulnerabilities-news/
-
Firefox Patches 2 Zero-Days Exploited at Pwn2Own Berlin with $100K in Rewards
Mozilla has released security updates to address two critical security flaws in its Firefox browser that could be potentially exploited to access sensitive data or achieve code execution.The vulnerabilities, both of which were exploited as a zero-day at Pwn2Own Berlin, are listed below -CVE-2025-4918 – An out-of-bounds access vulnerability when resolving Promise objects that could…
-
News brief: Patch critical SAP, Samsung and chat app flaws now
Check out the latest security news from the Informa TechTarget team. First seen on techtarget.com Jump to article: www.techtarget.com/searchsecurity/news/366623968/News-brief-Patch-critical-SAP-Samsung-and-chat-app-flaws-now
-
CISA to Stop Publishing Cybersecurity Alerts and Advisories on Webpages
Cybersecurity and Infrastructure Security Agency (CISA) has announced significant changes to how it communicates cybersecurity updates and guidance to stakeholders. In a recent announcement, CISA revealed plans to shift away from listing advisories on its webpage to focus on more direct communication channels. However, following community feedback, the agency has temporarily paused these changes while…
-
Mark Zuckerberg’s Vision: AI Companions and the Loneliness Epidemic
In this episode, we explore Mark Zuckerberg’s bold claim that AI friends will replace human friendships, and discuss the potential implications of a world where technology mediates our connections. We also update listeners on the recent developments in the 23andMe bankruptcy case and what it means for former customers. Joining the conversation is co-host Scott……
-
SAP Patchday Mai 2025 – Update für kritische NetWeaver-Schwachstelle
First seen on security-insider.de Jump to article: www.security-insider.de/sap-sicherheitsupdates-mai-2025-patchday-a-f29f32ffb3db6ba91d3f3e9042755b5a/
-
Week in review: Microsoft patches 5 actively exploited 0-days, recently fixed Chrome vulnerability exploited
Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Patch Tuesday: Microsoft fixes 5 actively exploited zero-days On May 2025 … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2025/05/18/week-in-review-microsoft-patches-5-actively-exploited-0-days-recently-fixed-chrome-vulnerability-exploited/
-
Mai 2025-Patchday: Tenable Einschätzung zu Schwachstellen
Zum 13. Mai 2025 hat Microsoft ja zahlreiche Sicherheits-Updates für Windows, Office und weitere Produkte veröffentlich. Ich hatte zeitnah einen kurzen Überblick über die adressierten Schwachstellen gegeben. Sicherheitsanbieter Tenable hat mir im Nachgang noch deren Einschätzung zu den Sicherheitslücken übermittelt, … First seen on borncity.com Jump to article: www.borncity.com/blog/2025/05/17/mai-2025-patchday-einschaetzung-zu-schwachstellen/
-
DoD SPRS Scores: How Often Should You Update Them?
The overall defense industrial base is growing increasingly aware of the needs of modern information and cyber security. From recent major supply chain attacks to the constant threat of nation-state actors trying to compromise systems, it’s important to be committed to the best security you can implement, no matter where you are in the supply……
-
OutBand-Updates für Windows 11 24H2 LTSC und Windows Server 2008/R2 (Mai 2025)
Noch ein kleiner Nachtrag für Administratoren von Windows Server 2008/R2. Es gab zum 13. Mai 2025 Out-of-Band-Updates für diese Betriebssystemversionen, um Sicherheitslücken zu schließen. Und für Windows 11 24H2 Enterprise LTSC hat Microsoft wohl auch ein Sonderupdate zum Schließen von … First seen on borncity.com Jump to article: www.borncity.com/blog/2025/05/17/out-of-band-updates-fuer-windows-11-24h2-ltsc-und-windows-server-2008-r2-mai-2025/
-
Why vulnerability scanning and patching alone no longer work
First seen on scworld.com Jump to article: www.scworld.com/perspective/why-vulnerability-scanning-and-patching-alone-no-longer-work
-
Microsoft confirms May Windows 10 updates trigger BitLocker recovery
Microsoft has confirmed that some Windows 10 and Windows 10 Enterprise LTSC 2021 systems will boot into BitLocker recovery after installing the May 2025 security updates. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/microsoft/microsoft-confirms-may-windows-10-updates-trigger-bitlocker-recovery/

