Vendors
-
QNAP: Windows NetBak PC Agent affected by critical ASP.NET Core flaw
QNAP warned that its NetBak PC Agent for Windows is impacted by CVE-2025-55315, a critical ASP.NET Core vulnerability in the Kestrel web server that can enable credential hijacking or request-smuggling attacks, and urged users to reinstall the agent or install the latest ASP.NET Core runtime.
-
Kaspersky links Chrome zero-day campaign to Italian spyware firm Memento Labs
Kaspersky detailed Operation ForumTroll, a campaign that used a Chrome sandbox escape (CVE-2025-2783) to deliver modular spyware LeetAgent and a second implant called Dante, which researchers attribute with high confidence to Memento Labs, a firm formed from assets of the former Hacking Team.
-
Mass attacks exploit outdated GutenKit and Hunk Companion WordPress plugins
A mass exploitation campaign is targeting WordPress sites running outdated GutenKit and Hunk Companion plugins, leveraging three critical vulnerabilities that can lead to remote code execution; Wordfence said it blocked 8.7 million attack attempts over two days and urged administrators to update plugins and check for indicators of compromise.
-
Microsoft issues out-of-band fix for WSUS vulnerability CVE-2025-59287
Microsoft released an out-of-band cumulative update to address CVE-2025-59287, a critical WSUS deserialization vulnerability being exploited in the wild; admins should apply the patch or disable WSUS/block ports 8530 and 8531 until systems can be rebooted after updating.
-
Toys “R” Us Canada notifies customers after customer records leaked
Toys “R” Us Canada told customers a threat actor posted stolen customer records on the unindexed internet on July 30, 2025. Third-party investigators confirmed the data’s authenticity, which may include names, addresses, emails and phone numbers; passwords and payment data were not exposed. The company said it has upgraded security and is notifying regulators, and…
-
Former L3Harris cyber executive charged with selling trade secrets to Russia
Federal prosecutors say Peter Williams, a former Trenchant general manager, misappropriated eight trade secrets and sold them to an undisclosed buyer in Russia, allegedly earning about $1.3 million; prosecutors seek forfeiture of multiple assets and an arraignment is set for Oct. 29.
-
CISA Adds Critical Lanscope Endpoint Manager Flaw to KEV Catalog
CISA added CVE-2025-61932, a critical arbitrary-code vulnerability in Motex Lanscope Endpoint Manager, to its Known Exploited Vulnerabilities catalog and said it is being actively exploited; Motex has released patched versions and agencies are advised to remediate by Nov. 12, 2025.
-
BIND flaws could enable DNS cache poisoning; patches issued
BIND developers warned of two vulnerabilities, CVE-2025-40778 and CVE-2025-40780, that can enable DNS cache poisoning by allowing forged responses to be accepted; patches were released and operators are urged to apply them.










