Tag: zero-day
-
Apple plugs zero-day holes used in targeted iPhone attacks (CVE-2025-31200, CVE-2025-31201)
Apple has released emergency security updates for iOS/iPadOS, macOS, tvOS and visionOS that fix two zero-day vulnerabilities (CVE-2025-31200, CVE-2025-31201) that have been … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2025/04/17/apple-plugs-zero-days-holes-used-in-targeted-iphone-attacks-cve-2025-31200-cve-2025-31201/
-
Apple plugs zero-days holes used in targeted iPhone attacks (CVE-2025-31200, CVE-2025-31201)
Apple has released emergency security updates for iOS/iPadOS, macOS, tvOS and visionOS that fix two zero-day vulnerabilities (CVE-2025-31200, CVE-2025-31201) that have been … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2025/04/17/apple-plugs-zero-days-holes-used-in-targeted-iphone-attacks-cve-2025-31200-cve-2025-31201/
-
CVE-2025-31200: Apple Patches Two Actively Exploited Zero-Days
Apple has rolled out critical security updates across its ecosystem, including iOS, iPadOS, macOS Sequoia, tvOS, and visionOS, to address two newly discovered zero-day vulnerabilities that are currently being exploited in real-world attacks. Two Actively Exploited Zero-Day Flaws Patched The… First seen on sensorstechforum.com Jump to article: sensorstechforum.com/cve-2025-31200-zero-days-apple/
-
Multiple orgs subjected to attacks involving Gladinet zero-day
First seen on scworld.com Jump to article: www.scworld.com/brief/multiple-orgs-subjected-to-attacks-involving-gladinet-zero-day
-
Zero-Day in CentreStack Raises Concerns for MSPs and Enterprises
First seen on scworld.com Jump to article: www.scworld.com/brief/zero-day-in-centrestack-raises-concerns-for-msps-and-enterprises
-
Apple says zero-day bugs exploited against ‘specific targeted individuals’ using iOS
One of the bugs was discovered by Google’s security researchers who investigate government-backed cyberattacks. First seen on techcrunch.com Jump to article: techcrunch.com/2025/04/16/apple-says-zero-day-bugs-exploited-against-specific-targeted-individuals-using-ios/
-
Apple fixes two zero-days exploited in targeted iPhone attacks
Apple released emergency security updates to patch two zero-day vulnerabilities that were used in an “extremely sophisticated attack” against specific targets’ iPhones. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/apple-fixes-two-zero-days-exploited-in-targeted-iphone-attacks/
-
Hertz Data Breach Exposes Customer Information in Cleo Zero-Day Attack
Hertz has confirmed a data breach exposing customer data after a zero-day attack targeting file transfer software from Cleo Communications First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/hertz-data-breach-exposes-customer/
-
Ein Appell an die Sicherheits-Community Umgang mit der CrushFTP-Sicherheitslücke
Ob Zero-Day-Exploits oder Fehlkonfigurationen Sicherheitslücken sind längst eine alltägliche Herausforderung. Entscheidend ist nicht nur, dass sie entdeckt werden, sondern wie mit den Erkenntnissen umgegangen wird. Zwischen koordinierter Offenlegung und der Gefahr von Angriffswellen auf ungeschützte Systeme ist eine Debatte entbrannt, die längst nicht mehr nur Fachkreise betrifft. Der jüngste Fall einer Schwachstelle in der… First…
-
Hertz Falls Victim to Cleo Zero-Day Attacks
Customer data such as birth dates, credit card numbers and driver’s license information were stolen when threat actors exploited zero-day vulnerabilities in Cleo-managed file transfer products. First seen on darkreading.com Jump to article: www.darkreading.com/vulnerabilities-threats/hertz-falls-victim-cleo-zero-day-attacks
-
Attackers exploit zero-day flaw in Gladinet CentreStack file-sharing platform
Critical vulnerability affects both CentreStack and Gladinet’s on-premises file-sharing server, Triofox. First seen on cybersecuritydive.com Jump to article: www.cybersecuritydive.com/news/attackers-exploit-zero-day-gladinet-centrestack-file-sharing/745407/
-
Hertz data breach: Customers in US, EU, UK, Australia and Canada affected
American car rental company Hertz has suffered a data breach linked to last year’s exploitation of Cleo zero-day vulnerabilities by a ransomware gang. The breach … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2025/04/15/hertz-data-breach-customers-in-us-eu-uk-australia-and-canada-affected/
-
Schattenseiten unkoordinierter Veröffentlichung von Schwachstellen
Ob Zero-Day-Exploits oder Fehlkonfigurationen Sicherheitslücken sind längst eine alltägliche Herausforderung. Entscheidend ist nicht nur, dass sie entdeckt werden, sondern wie mit den Erkenntnissen umgegangen wird. Zwischen koordinierter Offenlegung und der Gefahr von Angriffswellen auf ungeschützte Systeme ist eine Debatte entbrannt, die längst nicht mehr nur Fachkreise betrifft. Der jüngste Fall einer Schwachstelle in der […]…
-
CentreStack 0-Day Exploit Enables Remote Code Execution on Web Servers
A critical 0-day vulnerability has been disclosed in CentreStack, a popular enterprise cloud storage and collaboration platform, which could allow attackers to execute arbitrary code remotely on affected web servers. The vulnerability, tracked as CVE-2025-30406, leverages a flaw in the application’s handling of cryptographic keys responsible for securing sensitive ViewState data. Flaw in MachineKey Management…
-
Hertz disclosed a data breach following 2024 Cleo zero-day attack
Hertz Corporation disclosed a data breach after customer data was stolen via Cleo zero-day exploits in late 2024, affecting Hertz, Thrifty, and Dollar brands. Car rental giant Hertz Corporation disclosed a data breach that impacted its Hertz, Thrifty, and Dollar brands. Threat actors gained access to customer data via Cleo zero-day exploits in late 2024.…
-
Wie ein IT Security Assessment den Mittelstand schützen kann
Kleinere und mittlere Unternehmen geraten zunehmend ins Visier von Cyberangriffen mit täglich bis zu 500.000 neuen Schadvarianten und 18 Zero-Day-Angriffen. Ein Cybersecurity Assessment deckt Schwachstellen auf und zeigt, wie Sie sich schützen können. Doch was muss ein gutes Assessment wirklich leisten? First seen on itsicherheit-online.com Jump to article: www.itsicherheit-online.com/news/cybersecurity/wie-ein-it-security-assessment-den-mittelstand-schuetzen-kann/
-
Hertz confirms customer info, drivers’ licenses stolen in data breach
Car rental giant Hertz Corporation warns it suffered a data breach after customer data for its Hertz, Thrifty, and Dollar brands was stolen in the Cleo zero-day data theft attacks. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/hertz-confirms-customer-info-drivers-licenses-stolen-in-data-breach/
-
Hertz confirms customer info and drivers’ licenses stolen in data breach
Car rental giant Hertz Corporation warns it suffered a data breach after customer data for its Hertz, Thrifty, and Dollar brands was stolen in the Cleo zero-day data theft attacks. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/hertz-confirms-customer-info-and-drivers-licenses-stolen-in-data-breach/
-
Fortinet Zero-Day Bug May Lead to Arbitrary Code Execution
A threat actor posted about the zero-day exploit on the same day that Fortinet published a warning about known vulnerabilities under active exploitation. First seen on darkreading.com Jump to article: www.darkreading.com/vulnerabilities-threats/fortinet-zero-day-arbitrary-code-execution
-
Threat Actor Allegedly Selling Fortinet Firewall Zero-Day Exploit
A threat actor claims to offer a zero-day exploit for an unauthenticated remote code execution vulnerability in Fortinet firewalls. The post Threat Actor Allegedly Selling Fortinet Firewall Zero-Day Exploit appeared first on SecurityWeek. First seen on securityweek.com Jump to article: www.securityweek.com/threat-actor-allegedly-selling-fortinet-firewall-zero-day-exploit/
-
Krypto-Miner, Zero-Day-Malware und Linux-basierte Bedrohungen legen laut WatchguardSecurity-Report weiter zu
Gerade hat Watchguard Technologies den Internet-Security-Report für das vierte Quartal 2024 veröffentlicht. Die Zunahme von netzwerkbasierter Malware um 94 Prozent im Vergleich zum Vorquartal ist dabei gewiss eine der eindrucksvollsten Beobachtungen. Dies geht einher mit einem generellen Anstieg des Malware-Volumens, wozu nicht zuletzt sechs Prozent mehr Erkennungen durch die Gateway-Antivirus (GAV)-Funktionalität und die um 74…
-
âš¡ Weekly Recap: Windows 0-Day, VPN Exploits, Weaponized AI, Hijacked Antivirus and More
Attackers aren’t waiting for patches anymore, they are breaking in before defenses are ready. Trusted security tools are being hijacked to deliver malware. Even after a breach is detected and patched, some attackers stay hidden.This week’s events show a hard truth: it’s not enough to react after an attack. You have to assume that any…
-
FortiGate 0-Day Exploit Allegedly Up for Sale on Dark Web
A chilling new development in the cybersecurity landscape has emerged, as a threat actor has reportedly advertised an alleged zero-day exploit targeting Fortinet’s FortiGate firewalls on a prominent dark web forum. This exploit purportedly enables unauthenticated remote code execution (RCE) and full configuration access to FortiOS, unlocking the potential for attackers to seize control of…
-
Schwachstellen eliminieren: Ein IT Security Assessment gegen Cyberattacken
Kleinere und mittlere Organisationen sind vermehrt Opfer von Cyberangriffen. Da ihre IT häufig mehr Lücken hat als die großer Unternehmen, bietet der Mittelstand damit auch mehr Angriffsfläche. Bei bis zu 500.000 neuen Schadvarianten sowie 18 Zero-Day-Hacks täglich mit oft fatalen Folgen. Ein Cybersecurity Assessment identifiziert potenzielle Einfallstore für Cyberkriminelle und zeigt notwendige Sicherheitsmaßnahmen auf. Der……
-
Ivanti 0-Day RCE Flaw Exploitation Details Revealed
Tags: cyber, cybersecurity, exploit, flaw, ivanti, rce, remote-code-execution, vulnerability, zero-dayA critical unauthenticated Remote Code Execution (RCE) vulnerability, CVE-2025-22457, has been disclosed by Ivanti, sparking concerns across the cybersecurity industry. The flaw, which affects several Ivanti products, allows attackers to execute arbitrary code remotely, potentially compromising sensitive enterprise environments. Researchers, including the Rapid7 vulnerability team, have provided a detailed breakdown of how the flaw was exploited and what…
-
Zero-Day in CentreStack File Sharing Platform Under Attack
Gladinet’s platform is widely used among managed service providers, and a critical deserialization flaw could put MSP customers in jeopardy. First seen on darkreading.com Jump to article: www.darkreading.com/vulnerabilities-threats/zero-day-centrestack-platform-under-attack
-
Zero-Day Vulnerability in CentreStack Exploited to Breach Enterprise File Servers
First seen on scworld.com Jump to article: www.scworld.com/brief/zero-day-vulnerability-in-centrestack-exploited-to-breach-enterprise-file-servers
-
Gladinet CentreStack zero-day exploitation sought to compromise file storage servers
First seen on scworld.com Jump to article: www.scworld.com/brief/gladinet-centrestack-zero-day-exploitation-sought-to-compromise-file-storage-servers
-
Patch Tuesday: Microsoft Fixes 134 Vulnerabilities, Including 1 Zero-Day
One CVE was used against “a small number of targets.” Windows 10 users needed to wait a little bit for their patches. First seen on techrepublic.com Jump to article: www.techrepublic.com/article/news-microsoft-patch-tuesday-april-2025/

