U.S. computer software and services provider PTC has alerted that potential exploitation of a critical flaw in its product lifecycle management solutions FlexPLM and Windchill via trusted data deserialization could result in remote code execution, reports BleepingComputer.
Intrusions exploiting the high-severity stored cross-site scripting flaw in Zimbra Collaboration, tracked as CVE-2025-66376, have been launched against Ukraine by a Russian advanced persistent threat operation suspected to be APT28, also known as Fancy Bear, Sofacy Group, BlueDelta, and STRONTIUM, according to Security Affairs.
The Cybersecurity and Infrastructure Security Agency has updated its Known Exploited Vulnerabilities list to include high-severity flaws impacting Microsoft SharePoint and the Synacor Zimbra Collaboration Suite, Security Affairs reports.
Fast Five
Selected by the SC Media Editorial team every Tuesday.
Sign up now for the top five issues cybersecurity pros need to know this week.