-
CVE-2024-48916 – Ceph JWT Algorithm Validation Bypass Vulnerability
CVE ID : CVE-2024-48916 Published : July 30, 2025, 8:15 p.m. | 11 hours, 51 minutes ago Description : Ceph is a distributed object, block, and file storage platform. In versions 19.2.3 and below, it is possible to send an JWT that has “none” as JWT alg. And by doing so the JWT signature is not checked.…
-
CVE-2025-30105 – Dell XtremIO Log Injection Vulnerability
CVE ID : CVE-2025-30105 Published : July 30, 2025, 6:15 p.m. | 13 hours, 51 minutes ago Description : Dell XtremIO, version(s) 6.4.0-22, contain(s) an Insertion of Sensitive Information into Log File vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information exposure. The attacker may be able to use the…
-
CVE-2025-26332 – Dell XtremIO X2 TechAdvisor Insertion of Sensitive Information into Log File
CVE ID : CVE-2025-26332 Published : July 30, 2025, 6:15 p.m. | 13 hours, 51 minutes ago Description : TechAdvisor versions 2.6 through 3.37-30 for Dell XtremIO X2, contain(s) an Insertion of Sensitive Information into Log File vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information exposure. The attacker may…
-
CVE-2025-45620 – Aver PTC310UV2 Information Disclosure
CVE ID : CVE-2025-45620 Published : July 30, 2025, 5:15 p.m. | 14 hours, 51 minutes ago Description : An issue in Aver PTC310UV2 v.0.1.0000.59 allows a remote attacker to obtain sensitive information via a crafted request Severity: 8.1 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more… Go…
-
CVE-2025-50578 – LinuxServer.io Heimdall HTTP Header Injection and Open Redirect Vulnerability
CVE ID : CVE-2025-50578 Published : July 30, 2025, 4:15 p.m. | 15 hours, 51 minutes ago Description : LinuxServer.io heimdall 2.6.3-ls307 contains a vulnerability in how it handles user-supplied HTTP headers, specifically `X-Forwarded-Host` and `Referer`. An unauthenticated remote attacker can manipulate these headers to perform Host Header Injection and Open Redirect attacks. This allows the loading…
-
AURORA – Leveraging ETW for Advanced Threat Detection
AURORA – Leveraging ETW for Advanced Threat Detection Aurora is a lightweight endpoint agent that applies Sigma rules and IOCs directly to Windows system events reconstructed from Event Tracing for Windows (ETW). Unlike traditional logging tools or Sysmo … Read more Published Date: Jul 31, 2025 (45 minutes ago) Vulnerabilities has been mentioned in this article.…
-
iOS 18.6 to macOS 15.6: Apple Releases Comprehensive Security Updates
iOS 18.6 to macOS 15.6: Apple Releases Comprehensive Security Updates Apple has rolled out a wide-ranging series of Apple security updates and Rapid Security Responses, spanning iOS, iPadOS, macOS, tvOS, watchOS, and visionOS. These carefully coordinated Apple security … Read more Published Date: Jul 31, 2025 (1 hour, 12 minutes ago) Vulnerabilities has been mentioned in this…
-
Secrets are leaking everywhere, and bots are to blame
Secrets are leaking everywhere, and bots are to blame Secrets like API keys, tokens, and credentials are scattered across messaging apps, spreadsheets, CI/CD logs, and even support tickets. According to Entro Security’s NHI & Secrets Risk Report H1 2025, … Read more Published Date: Jul 31, 2025 (3 hours, 21 minutes ago) Vulnerabilities has been mentioned in…
-
iOS 18.6 and macOS Sequoia 15.6 Address Chrome Zero-Day Attack
iOS 18.6 and macOS Sequoia 15.6 Address Chrome Zero-Day Attack Wednesday July 30, 2025 5:09 pm PDT by Juli CloverThe iOS 18.6, iPadOS 18.6, and macOS Sequoia 15.6 updates that Apple released yesterday address a major zero-day attack that targeted Chrome users, ac … Read more Published Date: Jul 31, 2025 (7 hours, 42 minutes ago) Vulnerabilities…
-
Response to CISA Alert: Microsoft Releases Guidance on Exploitation of SharePoint Vulnerabilities
Response to CISA Alert: Microsoft Releases Guidance on Exploitation of SharePoint Vulnerabilities On July 8, 2025, vulnerabilities CVE-2025-49704 (Remote Code Execution) and CVE-2025-49706 (Network Spoofing), affecting on-premises Microsoft SharePoint servers, were officially reported. On the same … Read more Published Date: Jul 30, 2025 (11 hours, 56 minutes ago) Vulnerabilities has been mentioned in this article. CVE-2025-53771…