Overview
Description
Statistics
- 5 Posts
- 5 Interactions
Fediverse
Threat actors are actively exploiting CVE-2025-59287 in WSUS to deploy ShadowPad.
ASEC notes the attackers used PowerCat for shell access, then fetched and installed ShadowPad with certutil/curl, executing it through DLL side-loading.
How are you securing WSUS or other update infrastructure in your environment?
💬 Share your insights
⭐ Follow TechNadu for timely threat intel
#infosec #WSUS #ShadowPad #CVE2025 #malware #threatintel #sysadmin #DFIR #TechNadu
🚨 Hackers are using a fixed Windows bug (CVE-2025-59287) to spread ShadowPad malware through WSUS servers.
They used normal Windows tools like curl and certutil to install it — a method seen before in Chinese hacking groups.
Systems patched too late may have already been compromised.
Full story ↓ https://thehackernews.com/2025/11/shadowpad-malware-actively-exploits.html
Bluesky
Overview
- Grafana
- Grafana Enterprise
Description
Statistics
- 5 Posts
- 3 Interactions
Fediverse
Grafana : une faille dans SCIM permet d’élever ses privilèges et de devenir admin ! https://www.it-connect.fr/grafana-scim-cve-2025-41115/ #ActuCybersécurité #Cybersécurité #Vulnérabilité
Bluesky
Overview
Description
Statistics
- 2 Posts
- 29 Interactions
Fediverse
On Thursday, this blog was released about CVE-2025-61757 in Oracle Fusion Middleware - Oracle Identity Manager really
https://slcyber.io/research-center/breaking-oracles-identity-manager-pre-auth-rce/
Within 24 hours, it was added to CISA KEV as actively exploited 🤔
Overview
- scripteo
- Ads Pro Plugin - Multi-Purpose WordPress Advertising Manager
Description
Statistics
- 2 Posts
- 1 Interaction
Fediverse
⚠️ CVE-2025-7402: HIGH severity SQL Injection in Ads Pro Plugin (≤4.95) for WordPress. Unauthenticated attackers can leak DB data via 'site_id'—patch unavailable. Deploy WAF & monitor activity! https://radar.offseq.com/threat/cve-2025-7402-cwe-89-improper-neutralization-of-sp-c1c197c1 #OffSeq #WordPress #SQLi #Vuln
Overview
Description
Statistics
- 2 Posts
Fediverse
🚨 CVE-2025-48507 (HIGH): AMD Kria™ SOM flaw lets non-secure processors access secure memory & crypto ops via improper validation in TF-A. Patch ASAP, restrict access, and monitor for exploitation. https://radar.offseq.com/threat/cve-2025-48507-cwe-1284-improper-validation-of-spe-d9783ee6 #OffSeq #Vulnerability #Firmware #InfoSec
Overview
Description
Statistics
- 1 Post
- 6 Interactions
Fediverse
7-Zip RCE flaw (CVE-2025-11001) actively exploited in attacks in the wild https://securityaffairs.com/184850/security/7-zip-rce-flaw-cve-2025-11001-actively-exploited-in-attacks-in-the-wild.html
Overview
- pgadmin.org
- pgAdmin 4
Description
Statistics
- 1 Post
- 1 Interaction
Fediverse
Pwning Fries on HTB 🍟💥
🔍 Gitea cred leaks
🚪 pgAdmin RCE (CVE-2025-2945)
🕸️ Ligolo-ng pivots
🛠️ NFS SUID abuse
From docker escapes to domain dominance. Check out the full Hard Weekly writeup! 👇
http://kzs.me/m9n5cr
#HackTheBox #Infosec #CTF #CyberSecurity #htb #1337sheets
Overview
Description
Statistics
- 1 Post
- 1 Interaction
Overview
- Microsoft
- Azure Bastion Developer
Description
Statistics
- 1 Post
Bluesky
Overview
- vllm-project
- vllm
Description
Statistics
- 1 Post