Updates have been issued by CoreDNS to fix a high-severity flaw in its DNS-over-QUIC implementation, tracked as CVE-2025-47950, which could be exploited to disrupt DNS servers via stream amplification intrusions, GBHackers News reports.
Major European food delivery platform GonnaOrder had real-time order information from thousands of its customers inadvertently exposed by a Kafka Broker instance that has been unsecured since August 2022, reports Cybernews.
SecurityWeek reports that Adobe has fixed hundreds of flaws impacting several of its offerings, including code execution vulnerabilities in Acrobat Reader and Adobe Commerce, as part of this month's Patch Tuesday.
Updates have been released by Ivanti to fix a trio of high-severity hardcoded key flaws impacting its Workspace Control platform, which could be leveraged to compromise vulnerable systems' database credentials and facilitate further lateral movement, Cyber Security News reports.