Malicious actors were noted by the Cybersecurity and Infrastructure Security Agency to have been abusing the critical WatchGuard Firebox bug, tracked as CVE-2025-9242, prompting its inclusion in the agency's Known Exploited Vulnerabilities catalog, reports The Hacker News.
Zero-day attacks against Cisco ISE, Citrix NetScaler observed Threat actors have harnessed the critical Citrix Bleed 2 flaw in Citrix NetScaler ADC and Gateway, tracked as CVE-2025-5777, and the maximum severity remote code execution bug in Cisco Identity Services Engine, tracked as CVE-2025-20337, in zero-day intrusions facilitating custom malware distribution, The Hacker News reports.
Updates have been issued by Microsoft to address 63 security issues impacting its products and systems, including an actively exploited high-severity zero-day in Windows Kernel, as part of this month's Patch Tuesday, reports CyberScoop.
Apple's WebKit browser engine was found by Google's artificial intelligence-based cybersecurity agent Big Sleep to have been affected by five security bugs, which could be leveraged to crash browsers or corrupt memory, reports The Hacker News.
BleepingComputer reports that at least 210,000 WordPress sites could be hijacked in intrusions exploiting a critical security flaw in the Post SMTP plugin, tracked as CVE-2025-11833, which have been underway since the beginning of November.
The U.S. Cybersecurity and Infrastructure Security Agency has added two actively exploited vulnerabilities affecting Gladinet and Control Web Panel to its Known Exploited Vulnerabilities catalog.
Fast Five
Selected by the SC Media Editorial team every Tuesday.
Sign up now for the top five issues cybersecurity pros need to know this week.