Attackers could achieve escalated SYSTEM privileges on Windows machines through the exploitation of a high-severity ASUS Armoury Crate system management software vulnerability, tracked as CVE-2025-3464, BleepingComputer reports.
Updates have been issued by Tenable to address a trio of high-severity security issues impacting its Nessus vulnerability scanner for Windows, reports Infosecurity Magazine.
Flodrix botnet deployed via Langflow security issue Internet-exposed instances of the widely used Python-based artificial intelligence prototyping framework Langflow impacted by the critical remote code execution flaw, tracked as CVE-2025-3248, have been targeted with ongoing attacks distributing the Flodrix botnet, according to GBHackers News.
Organizations have been urged by Mitel to remediate a critical path traversal vulnerability in the MiCollab communications and collaboration platform, which could be exploited to compromise provisioning data, reports SecurityWeek.
Threat actors could compromise 46,506 Grafana implementations or almost 36% of internet-exposed open-source infrastructure monitoring and visualization platform instances in attacks exploiting the client-side open redirect flaw, tracked as CVE-2025-4123, according to BleepingComputer.
The Hacker News reports that ongoing security issues have prompted ConnectWise to schedule a rotation of digital code signing certificates for ScreenConnect, ConnectWise Remote Monitoring and Management, and ConnectWise Automate executables.
Fast Five
Selected by the SC Media Editorial team every Tuesday.
Sign up now for the top five issues cybersecurity pros need to know this week.