Organizations around the world have been targeted by the nascent Warlock ransomware operation in attacks exploiting the Microsoft SharePoint zero-day flaws dubbed "ToolShell", Infosecurity Magazine reports.
Total system breach likely with SAP NetWeaver exploit chain Vulnerable SAP NetWeaver instances could be taken over in attacks involving an exploit chain published by VX-Underground, which combines the maximum severity inadequate authorization check flaw, tracked as CVE-2025-31324, and the critical insecure deserialization bug, tracked as CVE-2025-42999, Security Affairs reports.
The industry is obsessed with vulnerabilities. From vulnerability assessment to vulnerability management to exposure management and even zero days, we love to talk about vulnerabilities. But what about misconfiguration? By definition it's a vulnerability or weakness, but it doesn't have a CVE (common vulnerability enumeration). Should we ignore it?...
Over 870 online instances of the N-able N-central management, automation, and orchestration tool used by managed service providers continue to be impacted by the insecure deserialization flaw, tracked as CVE-2025-8875, and command injection vulnerability, tracked as CVE-2025-8876, which have been exploited in limited attacks, SecurityWeek reports.