Schlagwort: phishing scams 2025


  • 🚨 CRITICAL ALERT: 2 Active Exploits Detected (2026-06-27)

    🚨 CRITICAL ALERT: Active Zero-Day Exploits Immediate Threat Summary: Two critical vulnerabilities with CVSS scores ≥ 8.0 are actively exploited in the wild, allowing attackers to gain root access and execute remote code without authentication. Both CVE-2026-20230 and CVE-2026-12569 are listed in the CISA Known Exploited Vulnerabilities (KEV) catalog as of June 25, 2026, mandating…

  • 🚨 CRITICAL ALERT: 133 Active Exploits Detected (2026-06-24)

    CRITICAL ALERT: Active Zero-Day Exploits 🚨 CRITICAL ALERT: Active Zero-Day Exploits Immediate Threat Summary: A wave of critical vulnerabilities with CVSS scores ranging from 8.0 to 10.0 is currently being exploited in the wild by automated botnets and ransomware operators. CISA has added these to the Known Exploited Vulnerabilities (KEV) catalog, mandating immediate patching for…

  • 🚨 CRITICAL ALERT: 1 Active Exploits Detected (2026-06-17)

    🚨 CRITICAL ALERT: Active Zero-Day Exploits CVE-2026-20127 is a CVSS 10.0 authentication-bypass vulnerability in Cisco Catalyst SD-WAN Controller, Manager, and Validator that allows an unauthenticated remote attacker to bypass peering authentication, gain administrative access, and manipulate SD-WAN fabric configuration through NETCONF. Cisco Talos reports active exploitation, and CISA has listed the issue in KEV, making…

  • 🚨 CRITICAL ALERT: 2 Active Exploits Detected (2026-06-16)

    🚨 CRITICAL ALERT: Active Zero-Day Exploits Two critical vulnerabilities with CVSS scores of 9.8 and 8.5 are in scope, and both are listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, indicating confirmed real-world abuse. Immediate patching and exposure reduction are required to reduce the risk of remote code execution and hostile takeover of affected…

  • 🚨 CRITICAL ALERT: 1 Active Exploits Detected (2026-06-13)

    🚨 CRITICAL ALERT: Active Zero-Day Exploits A critical, network-exploitable vulnerability in Oracle PeopleSoft Enterprise PeopleTools is confirmed at CVSS 9.8 and is listed in the CISA Known Exploited Vulnerabilities catalog, indicating active exploitation risk and urgent remediation requirements. This flaw allows an unauthenticated attacker over HTTP to compromise affected systems and can result in full…

  • 🚨 CRITICAL ALERT: 1 Active Exploits Detected (2026-06-12)

    🚨 CRITICAL ALERT: Active Zero-Day Exploits Ivanti Sentry is affected by a critical CVSS 10.0 pre-authentication OS command injection flaw, CVE-2026-10520, which allows a remote unauthenticated attacker to achieve root-level remote code execution. The issue is listed in CISA’s Known Exploited Vulnerabilities catalog, making immediate remediation a priority for any exposed deployment.[1][3][4] Critical Vulnerabilities (CVSS…

  • 🚨 CRITICAL ALERT: 2 Active Exploits Detected (2026-06-10)

    🚨 CRITICAL ALERT: Active Zero-Day Exploits Two critical vulnerabilities currently in the CISA Known Exploited Vulnerabilities catalog create immediate risk of unauthorized access and remote code execution. CVE-2025-59718 is a CVSS 9.8 Fortinet authentication bypass that allows unauthenticated attackers to evade FortiCloud SSO using a crafted SAML response, and CVE-2026-11645 is a CVSS 8.8 Google…

  • 🚨 CRITICAL ALERT: 2 Active Exploits Detected (2026-06-09)

    🚨 CRITICAL ALERT: Active Zero-Day Exploits Two critical vulnerabilities with CVSS scores above 8.0 and CISA KEV inclusion require immediate action. One affects LiteLLM and can enable arbitrary command execution on the proxy host; the other affects remote access VPN certificate validation and can allow an unauthenticated attacker to bypass authentication and establish a VPN…

  • 🚨 CRITICAL ALERT: 1 Active Exploits Detected (2026-06-04)

    🚨 CRITICAL ALERT: Active Zero-Day Exploits CVE-2026-45247 is a critical unauthenticated remote code execution vulnerability in Mirasvit Full Page Cache Warmer for Magento 2, with a CVSS 9.8 score and CISA KEV listing indicating active exploitation in the wild.[2][3][1] Attackers can send a crafted serialized PHP object through the CacheWarmer cookie to trigger PHP object…

  • 🚨 CRITICAL ALERT: 1 Active Exploits Detected (2026-06-03)

    🚨 CRITICAL ALERT: Active Zero-Day Exploits Google has disclosed active, targeted exploitation of CVE-2025-48595, a critical Android vulnerability with a CVSS score of 8.4 that can lead to code execution through an integer overflow and local privilege escalation without requiring user interaction. This vulnerability is included in CISA’s Known Exploited Vulnerabilities catalog, making it an…