Siemens Fixes 66 SQL Injection Flaws in TeleControl Server Basic

Siemens Fixes 66 SQL Injection Flaws in TeleControl Server Basic Siemens has released a critical security advisory addressing 66 high-severity SQL injection vulnerabilities impacting its TeleControl Server Basic platform. According to the Siemens advisory, attacker … Read more Published Date: Apr 18, 2025 (3 hours, 11 minutes ago) Vulnerabilities has been mentioned in this article. CVE-2025-32870 CVE-2025-29905 […]

Sophisticated Phishing Campaign Uses Multi-Layered Tactics to Deliver Malware

Sophisticated Phishing Campaign Uses Multi-Layered Tactics to Deliver Malware A recent report from Unit 42, the threat intelligence division of Palo Alto Networks, reveals a sophisticated and evasive phishing campaign discovered in December 2024. This campaign, notable for its … Read more Published Date: Apr 18, 2025 (3 hours, 15 minutes ago) Vulnerabilities has been mentioned in […]

Interlock Ransomware Uses Evolving Tactics to Evade Detection

Interlock Ransomware Uses Evolving Tactics to Evade Detection Screenshot of Interlock’s DLS | Image: Sekoia A new report by Sekoia Threat Detection & Research (TDR) details the activities of Interlock, a ransomware intrusion set first observed in September 2024, … Read more Published Date: Apr 18, 2025 (3 hours, 32 minutes ago) Vulnerabilities has been mentioned in […]

CVE-2025-3246 – GitHub Enterprise Server Cross-Site Scripting Vulnerability

The following table lists the changes that have been made to the CVE-2025-3246 vulnerability over time. Vulnerability history details can be useful for understanding the evolution of a vulnerability, and for identifying the most recent changes that may impact the vulnerability’s severity, exploitability, or other characteristics. New CVE Received by [email protected] Apr. 17, 2025 Action […]

CVE-2025-3509 – GitHub Enterprise Server Remote Code Execution Vulnerability in Pre-Receive Hook Functionality

A Remote Code Execution (RCE) vulnerability was identified in GitHub Enterprise Server that allowed attackers to execute arbitrary code by exploiting the pre-receive hook functionality, potentially leading to privilege escalation and system compromise. The vulnerability involves using dynamically allocated ports that become temporarily available, such as during a hot patch upgrade. This means the vulnerability […]

CVE-2025-3124 – GitHub Enterprise Server Private Repository Information Disclosure

A missing authorization vulnerability was identified in GitHub Enterprise Server that allowed a user to see the names of private repositories that they wouldn’t otherwise have access to in the Security Overview in GitHub Advanced Security. The Security Overview was required to be filtered only using the `archived:` filter and all other access controls were […]