Latest Posts
Major Supply Chain Attack Impacting React NativeZero-day in Windows Server 2025’s Active Directory enables full Domain TakeoverURGENT COMMVAULT ALERT CVE-2025-3928 Enables M365 Tenant CompromiseFive windows 0-days: The Lazarus Group Says Thanks for Not PatchingCPU Based Ransomware. Oof. How CPU Vulnerabilities Open the Door to Microcode Ransomware
  • Follow
  • Follow
  • Follow
  • Follow
  • Home
  • BULLETINS
  • ABOUT US
  • Free Security Resources
    • Training Workshops
  • CONTACT US
    • Subscribe to Free Newsletter!
    • Tell Your Story!
Fortinet FortiOS Authentication Bypass: A Super-Admin’s Worst Nightmare

Fortinet FortiOS Authentication Bypass: A Super-Admin’s Worst Nightmare

by Jonathan R. Brennan, CISSP | Mar 20, 2025 | Bulletins

A critical vulnerability—CVE-2025-24472—has surfaced in Fortinet’s FortiOS and FortiProxy systems, drawing immediate concern from cybersecurity agencies. The flaw, which boasts a CVSS score of 8.1, allows remote attackers to gain super-admin privileges via crafted...
GIT Gone Bad: Massive GitHub Supply Chain Attack Exposes Credentials

GIT Gone Bad: Massive GitHub Supply Chain Attack Exposes Credentials

by Jonathan R. Brennan, CISSP | Mar 19, 2025 | Uncategorized

AKRIA RANSOMWARE CRACKED – for now.

AKRIA RANSOMWARE CRACKED – for now.

by Jonathan R. Brennan, CISSP | Mar 18, 2025 | Bulletins

Subhead: Security researchers crack a flaw in Akira’s Linux variant, but businesses can’t afford to relax just yet. Breaking Down the Akira Ransomware Threat Akira ransomware has been hitting targets hard since March 2023. As a Ransomware-as-a-Service (RaaS)...
EXPLOITED in 30 HOURS.  Critical RCE flaw in Apache Tomcat leads to RCE

EXPLOITED in 30 HOURS. Critical RCE flaw in Apache Tomcat leads to RCE

by Jonathan R. Brennan, CISSP | Mar 17, 2025 | Bulletins

EXPLOITED in 30 HOURS. Critical RCE flaw in Apache Tomcat leads to RCE A new vulnerability in Apache Tomcat is being actively exploited—here’s what you need to know. The Short Version: If you’re running Apache Tomcat, you need to take action. A newly disclosed path...
Cisco IOS XR Vulnerability (CVE-2025-20115): A BGP Crash Course You Didn’t Want

Cisco IOS XR Vulnerability (CVE-2025-20115): A BGP Crash Course You Didn’t Want

by Jonathan R. Brennan, CISSP | Mar 16, 2025 | Bulletins

Cisco IOS XR Vulnerability (CVE-2025-20115): A BGP Crash Course You Didn’t Want A Single Packet Can Wreck Your Network—Here’s How to Stop It.   Cisco just dropped an advisory on CVE-2025-20115, a high-severity memory corruption vulnerability in Cisco IOS XR software....
« Older Entries
Next Entries »

Follow Us

  • Facebook
  • Twitter
  • Instagram
  • LinkedIn
  • YouTube

Search

Recent Posts

  • Major Supply Chain Attack Impacting React Native
  • Zero-day in Windows Server 2025’s Active Directory enables full Domain Takeover
  • URGENT COMMVAULT ALERT CVE-2025-3928 Enables M365 Tenant Compromise
  • Five windows 0-days: The Lazarus Group Says Thanks for Not Patching
  • CPU Based Ransomware. Oof. How CPU Vulnerabilities Open the Door to Microcode Ransomware

Categories

  • Bulletins
  • NEWS
  • Resources
  • Training
  • Uncategorized
  • User Stories

SecurityBlotter.com
Panic More. Patch Less.



Copyright 2025All rights reserved. Duplication or republication of any contents is prohibited without written permission from SecurityBlotter.

Recent News

  • Supply Chain CompromiseMajor Supply Chain Attack Impacting React Native
  • Zero-day in Windows Server 2025’s Active Directory…
  • URGENT COMMVAULT ALERT CVE-2025-3928 Enables M365…

Designed by Elegant Themes | Powered by WordPress