Overview
Description
Statistics
- 5 Posts
- 1 Interaction
Bluesky
Overview
Description
Statistics
- 3 Posts
- 20 Interactions
Fediverse
Over 10K Fortinet firewalls remain exposed to a five-year-old 2FA bypass (CVE-2020-12812), letting attackers skip authentication with simple username changes. 🛡️
Admins are urged to patch or adjust settings as active exploitation continues. ⚠️
#TechNews #CyberSecurity #DataBreach #Infosec #Vulnerability #ZeroDay #NetworkSecurity #ThreatIntel #Ransomware #Privacy #Security #Firewall #CISA #Fortinet #ExposedSystems #Network #Infrastructure #CVE #2FA #MFA #Hacking
Bluesky
Overview
- SmarterTools
- SmarterMail
Description
Statistics
- 3 Posts
- 1 Interaction
Fediverse
🚨 New plugin: SmarterMailPlugin (CVE-2025-52691).
SmarterMail versions prior to Build 9413 affected by critical remote code execution vulnerability via arbitrary file upload.
Results: https://leakix.net/search?q=%2Bplugin%3ASmarterMailPlugin&scope=leak
Overview
Description
Statistics
- 2 Posts
- 1 Interaction
Fediverse
CVE-2025-68613: n8n RCE Vulnerability
Exploit/PoC: https://github.com/wioui/n8n-CVE-2025-68613-exploit
n8n has a critical security flaw that lets authenticated users execute arbitrary code through its workflow expression system. When users configure workflows, the expressions they provide can sometimes be evaluated without proper isolation from the underlying runtime environment.
Credit: NexxelSecurity
Overview
- IBM
- API Connect
Description
Statistics
- 2 Posts
- 1 Interaction
Bluesky
Overview
Description
Statistics
- 3 Posts
- 1 Interaction
Fediverse
🚨 Plugin update: ZimbraPlugin (CVE-2025-68645).
Zimbra Collaboration Suite 10.0 and 10.1 affected by unauthenticated LFI vulnerability.
Results: https://leakix.net/search?q=%2Btags%3Acve-2025-68645&scope=leak
Bluesky
Overview
Description
Statistics
- 2 Posts
Fediverse
RondoDox botnet exploits React2Shell flaw to breach Next.js servers
https://www.bleepingcomputer.com/news/security/rondodox-botnet-exploits-react2shell-flaw-to-breach-nextjs-servers/
The RondoDox botnet has been observed exploiting the critical React2Shell flaw
(CVE-2025-55182) to infect vulnerable Next.js servers with malware and
cryptominers.
First documented by Fortinet in July 2025, RondoDox is a large-scale botnet
that targets multiple n-day flaws in global attacks. In November, VulnCheck
spotted new RondoDox variants that featured exploits for CVE-2025-24893, a
critical remote code execution (RCE) vulnerability in the XWiki Platform.
A new report from cybersecurity company CloudSEK notes that RondoDox started
scanning for vulnerable Next.js servers on December 8 and began deploying
botnet clients three days later.
Overview
Description
Statistics
- 1 Post
- 1 Interaction
Overview
- Moodle Project
- moodle
Description
Statistics
- 1 Post
Fediverse
🚨CVE-2025-26529: Moodle XSS to RCE Exploit
Description information displayed in the site administration live log required additional sanitizing to prevent a stored XSS risk.
Credit: QXN0cm8
YouTube: https://www.youtube.com/@A5troRo0t
Overview
- Plex
- Media Server
Description
Statistics
- 1 Post
Fediverse
🟠 CVE-2025-69414 - High (8.5)
Plex Media Server (PMS) through 1.42.2.10156 allows retrieval of a permanent access token via a /myplex/account call with a transient access token.
🔗 https://www.thehackerwire.com/vulnerability/CVE-2025-69414/
#CVE #vulnerability #infosec #cybersecurity #security #Tenda