CVE-2025-9491: Windows Shortcut Vulnerability Exploited by Armored Likho
CVE-2025-9491 is a now-patched Windows shortcut vulnerability (ZDI-CAN-25373) that allows remote code execution. Addressed by Microsoft in November 2025 Patch Tuesday, it…
Critical and exploited CVEs, vulnerability intelligence and remediation guidance.
CVE-2025-9491 is a now-patched Windows shortcut vulnerability (ZDI-CAN-25373) that allows remote code execution. Addressed by Microsoft in November 2025 Patch Tuesday, it…
Url redirection to untrusted site ('open redirect') in M365 Copilot allows an unauthorized attacker to elevate privileges over a network.
Ransomware Groups Turn to Citrix Bleed 2, BYOVD, and Supply Chain Credentials Ravie LakshmananJul 02, 2026Malware / Cyber Attack Threat actors associated…
ThreatsDay: AI Compute Hijacking, Apple Email Flaw, BlueHammer Ransomware + 14 Stories Ravie LakshmananJul 02, 2026Hacking News / Cybersecurity News This week’s…
A malicious actor with access to the network and under certain network configurations could exploit an Improper Access Control vulnerability found in…
A malicious actor with access to the network and low privileges could exploit a Server-Side Request Forgery (SSRF) in UniFi Protect Application…
An old vulnerability in Nacos configuration server allowing authentication bypass by faking a web header. Used by WP-SHELLSTORM in an earlier campaign…
A path traversal vulnerability in FortiWeb exploited via fake PoC repos in the ChocoPoC campaign. Allows attackers to read arbitrary files on…
A vulnerability in MongoDB, exploited via fake PoC repos in the ChocoPoC campaign.
CVE-2024-49113 was identified as a relevant cybersecurity entity in recently ingested reporting. This profile is generated so related cyber news, CVEs, malware,…