[MY_SUBSCRIPTIONS]

Get cybersecurity news alerts delivered to your inbox

📡 [FLUX RSS]

Subscribe to the news feed

7 derniers jours

> FILTERS

> Last 7 Days

> TODAY'S SUMMARY (14 articles)

|

// AI-powered summary generated at 16:00

> CVE-2025-55228 Windows Graphics Component Remote Code Execution Vulnerability
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Win32K - GRFX allows an authorized attacker to execute code locally.
> CVE-2025-55236 Graphics Kernel Remote Code Execution Vulnerability
Time-of-check time-of-use (toctou) race condition in Graphics Kernel allows an authorized attacker to execute code locally.
> Collaborator Everywhere v2
Collaborator Everywhere is a well-known extension for Burp Suite Professional to probe and detect out-of-band pingbacks.  We developed an upgrade to the existing extension with several new exiting features. Payloads can now be edited, interactions are displayed in a separate tab and stored with the...
> CVE-2025-55245 Xbox Gaming Services Elevation of Privilege Vulnerability
Improper link resolution before file access ('link following') in Xbox allows an authorized attacker to elevate privileges locally.
> CVE-2025-55243 Microsoft OfficePlus Spoofing Vulnerability
Exposure of sensitive information to an unauthorized actor in Microsoft Office Plus allows an unauthorized attacker to perform spoofing over a network.
> OS command injection in CLI
An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] in FortiDDoS-F CLI may allow a privileged attacker to execute unauthorized code or commands via crafted CLI requests. Revised on 2025-09-09 00:00:00
> CVE-2025-55317 Microsoft AutoUpdate (MAU) Elevation of Privilege Vulnerability
Improper link resolution before file access ('link following') in Microsoft AutoUpdate (MAU) allows an authorized attacker to elevate privileges locally.
> CVE-2025-49692 Azure Connected Machine Agent Elevation of Privilege Vulnerability
Improper access control in Azure Windows Virtual Machine Agent allows an authorized attacker to elevate privileges locally.
> Path traversal in policy scripting
A Relative Path Traversal vulnerability [CWE-23] in FortiWeb may allow an authenticated attacker to perform an arbitrary file read on the underlying system via crafted requests. Revised on 2025-09-09 00:00:00
> CVE-2025-53796 Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability
Buffer over-read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.
> CVE-2025-53800 Windows Graphics Component Elevation of Privilege Vulnerability
No cwe for this issue in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally.
> preparing for the worst
One of these mantras I keep repeating is how we in the curl project keep improving, keep polishing and keep tightening every bolt there is. No one can do everything right from day one, but given time and will we can over time get a lot of things lined up in neat and tidy lines. … Continue reading pr...
> CVE-2025-53801 Microsoft DWM Core Library Elevation of Privilege Vulnerability
Untrusted pointer dereference in Windows DWM allows an authorized attacker to elevate privileges locally.
> CVE-2025-53802 Windows Bluetooth Service Elevation of Privilege Vulnerability
Use after free in Windows Bluetooth Service allows an authorized attacker to elevate privileges locally.
> ZDI-25-892: Microsoft .NET IsTypeAuthorized Deserialization of Untrusted Data Denial-of-Service Vulnerability
This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of Microsoft .NET. Interaction with the .NET framework is required to exploit this vulnerability but attack vectors may vary depending on the implementation. The ZDI has assigned a CVSS ratin...
> CVE-2025-53803 Windows Kernel Memory Information Disclosure Vulnerability
Generation of error message containing sensitive information in Windows Kernel allows an authorized attacker to disclose information locally.
> CVE-2025-53804 Windows Kernel-Mode Driver Information Disclosure Vulnerability
Exposure of sensitive information to an unauthorized actor in Windows Kernel allows an authorized attacker to disclose information locally.
> Knowledge Base Digest - August 2025
Articles Evil Twin access points not correctly detected by Airspace Monitoring How to use device folders in WatchGuard Cloud Wireless Fireboxes or WatchGuard access points managed by WatchGuard Cloud classified as Rogue AP in Wi-Fi Cloud WIPS Configuration verification failed error message when you...
> CVE-2025-53805 HTTP.sys Denial of Service Vulnerability
Out-of-bounds read in Windows Internet Information Services allows an unauthorized attacker to deny service over a network.
> CVE-2025-53806 Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability
Buffer over-read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.