News
-
CISA Adds Gogs Path Traversal CVE-2025-8110 to Known Exploited Vulnerabilities Catalog
CISA added CVE-2025-8110, a high severity Gogs path traversal that can enable code execution, to its Known Exploited Vulnerabilities catalog on January 12 2026. About 1,600 exposed instances exist with several hundred compromised.
-
Apex Legends players report character hijacks during live matches
Players reported Apex Legends characters being controlled remotely during live matches, causing disconnects and name changes. The developer acknowledged and then resolved the incident after about six hours while saying there was no evidence of remote code execution.
-
BreachForums database of 323,986 user accounts leaked in January
A database of 323,986 BreachForums accounts was published January 9. The dump is dated August and includes hashed passwords, private messages, a password protected PGP key and a 4,400 word manifesto titled Doomsday.
-
Endesa discloses customer data breach affecting contract and payment details
Endesa and operator Energía XXI disclosed that hackers accessed a commercial platform and obtained customer contract information, including identity and payment details. The firm serves about 22 million clients and is notifying affected customers.
-
OpenCode vulnerability allowed unauthenticated code execution on users machines
An independent disclosure found OpenCode started an unauthenticated local HTTP server that allowed connected clients to execute arbitrary code. Update to v1.1.10 or newer and check server settings to reduce exposure.
-
GoBruteforcer botnet targets crypto and blockchain databases with credential brute force
A technical analysis found GoBruteforcer campaigns since mid 2025 that turn exposed Linux servers into botnet nodes to brute force FTP and database credentials and to probe blockchain accounts for funds.
-
Critical RCE and two DoS flaws patched in Apex Central on-premise
Trend Micro issued updates for Apex Central on-premise after a Tenable technical analysis detailed CVE-2025-69258, a critical RCE with CVSS 9.8, and two DoS flaws that can be triggered via MsgReceiver.exe on TCP port 20001.
-
CISA retires 10 Emergency Directives issued 2019 to 2024
CISA is retiring 10 Emergency Directives issued from 2019 through 2024 after required actions were implemented or enforcement moved to Binding Operational Directive 22-01. The closed directives include SolarWinds and Exchange mitigation orders.
-
FBI warns Kimsuky used malicious QR codes in 2025 quishing campaigns
An FBI flash alert warned that North Korea linked group Kimsuky used malicious QR codes in 2025 spear phishing to target think tanks, academia, and government entities. The attacks aimed to steal session tokens and bypass multi factor authentication.










