CVE Feed
- CVE-2025-10776 – LionCoders SalePro POS Insecure Cleartext Transmission Vulnerability September 22, 2025
- CVE-2025-10774 – Ruijie 6000-E10 Remote OS Command Injection Vulnerability September 22, 2025
- CVE-2025-10773 – B-Link BL-AC2100 Web Management Interface Remote Stack Buffer Overflow September 22, 2025
- CVE-2025-10775 – Wavlink WL-NU516U1 Os Command Injection Vulnerability September 22, 2025
- CVE-2025-10772 – Huggingface LeRobot ZeroMQ Socket Handler Authentication Bypass September 22, 2025
- CVE-2025-10771 – "Jeecgboot JimuReport DB2 JDBC Handler Remote Deserialization Vulnerability" September 22, 2025
- CVE-2025-10767 – CosmodiumCS OnlyRAT Os Command Injection Vulnerability September 22, 2025
- CVE-2025-10770 – "Jeecgboot JimuReport MySQL JDBC Handler Deserialization Vulnerability" September 22, 2025
- CVE-2025-53692 – Sitecore Sitecore Experience Manager/Xperience Platform XSS September 21, 2025
- CVE-2025-6544 – H2O-3 Deserialization Remote Code Execution September 21, 2025
- CVE-2025-10769 – H2oai H2o-3 Remote Deserialization Vulnerability in H2 JDBC Driver September 21, 2025
- CVE-2025-10768 – IBMDB2 JDBC Driver Remote Deserialization Vulnerability September 21, 2025
- CVE-2025-10766 – SeriaWei ZKEACMS Remote Path Traversal Vulnerability September 21, 2025
- CVE-2025-10765 – SeriaWei ZKEACMS Server-Side Request Forgery Vulnerability September 21, 2025
- CVE-2025-10762 – Kuaifan DooTask SQL Injection September 21, 2025
- CVE-2025-10763 – Academico-sis Profile Picture Handler Unrestricted File Upload Vulnerability September 21, 2025
- CVE-2025-10764 – SeriaWei ZKEACMS Server-Side Request Forgery (SSRF) Vulnerability September 21, 2025
- CVE-2025-10761 – Harness Login Endpoint Authentication Bypass September 21, 2025
- CVE-2025-10760 – Harness SSRF September 21, 2025
Microsoft Security
- Microsoft Defender delivered 242% return on investment over three years​​ September 18, 2025​The latest 2025 commissioned Forrester Consulting Total Economic Impactâ„¢ (TEI) study reveals a 242% ROI over three years for organizations that chose Microsoft Defender. It helps security leaders consolidate tools, reduce overhead, and empower their SecOps teams with operational efficiencies powered by AI and automation. In total, the study found Defender delivered $17.8 million in […]Scott Woodgate
- Microsoft Purview innovations for your Fabric data: Unify data security and governance for the AI era September 16, 2025The Microsoft Fabric and Purview teams are thrilled to participate in the European Microsoft Fabric Community Conference. The post Microsoft Purview innovations for your Fabric data: Unify data security and governance for the AI era appeared first on Microsoft Security Blog.Rudra Mitra
- Azure mandatory multifactor authentication: Phase 2 starting in October 2025 September 5, 2025Microsoft Azure is announcing the start of Phase 2 multi-factor authentication enforcement at the Azure Resource Manager layer, starting October 1, 2025. The post Azure mandatory multifactor authentication: Phase 2 starting in October 2025 appeared first on Microsoft Security Blog.Joy Shah and Neha Kulkarni
- Storm-0501’s evolving techniques lead to cloud-based ransomware August 27, 2025Financially motivated threat actor Storm-0501 has continuously evolved their campaigns to achieve sharpened focus on cloud-based tactics, techniques, and procedures (TTPs). While the threat actor has been known for targeting hybrid cloud environments, their primary objective has shifted from deploying on-premises endpoint ransomware to using cloud-based ransomware tactics. The post Storm-0501’s evolving techniques lead to […]Microsoft Threat Intelligence
- Microsoft ranked number one in modern endpoint security market share third year in a row August 27, 2025For a third year a row, Microsoft has been named the number one leader for endpoint security market share, as featured in a new IDC report. The post Microsoft ranked number one in modern endpoint security market share third year in a row appeared first on Microsoft Security Blog.Rob Lefferts