top of page

Notícias

Vulnerabilidades

6 de dezembro de 2025

Your smart home is at risk - 6 ways to protect your devices from attack

The fewer entry points you leave open, the more secure your smart home will be.

6 de dezembro de 2025

React2Shell flaw exploited to breach 30 orgs, 77k IP addresses vulnerable

Over 77,000 Internet-exposed IP addresses are vulnerable to the critical React2Shell remote code execution flaw (CVE-2025-55182), with researchers now confirming that attackers have already compromised over 30 organizations across multiple sectors. [...]

5 de dezembro de 2025

Barracuda Application Protection safeguards against critical React and Next.js vulnerabilities

Two critical remote code execution (RCE) vulnerabilities—CVE-2025-55182 and CVE-2025-66478—impact applications built on React and Next.js, enabling attackers to execute arbitrary code without authentication. Barracuda Application Protection, including Barracuda WAF and WAF-as-a-Service, offers automatic safeguards against these threats through real-time signature updates and layered defenses.

4 de dezembro de 2025

Max-severity vulnerability in React, Node.js patched, update ASAP (CVE-2025-55182)

A critical vulnerability (CVE-2025-55182) in React Server Components (RSC) may allow unauthenticated attackers to achieve remote code exection on the application server, the React development team warned on Wednesday. The maximum-severity vulnerability was privately reported by Lachlan Davidson and has been fixed. At this moment, there are no public reports of it being exploited by attackers and no confirmed public PoC exploits (for now). Nevertheless, affected users have been advised to upgrade to a non-vulnerable … More → The post Max-severity vulnerability in React, Node.js patched, update ASAP (CVE-2025-55182) appeared first on Help Net Security.

4 de dezembro de 2025

NCSC's 'Proactive Notifications' warns orgs of flaws in exposed devices

The UK's National Cyber Security Center (NCSC) announced the testing phase of a new service called Proactive Notifications, designed to inform organizations in the country of vulnerabilities present in their environment. [...]

4 de dezembro de 2025

Your Android phone may be in critical danger - update it ASAP

Google just gave you 107 reasons to update your Android phone, including high-severity vulnerabilities and several that are the worst of the worst.

4 de dezembro de 2025

WebXR Flaw Hits 4 Billion Chromium Users, Update Your Browser Now

Cybersecurity startup AISLE discovered a Medium severity flaw in the WebXR component of Chrome, Edge, and other Chromium browsers. Over 4 billion devices were at risk. Update now.

3 de dezembro de 2025

University of Phoenix discloses data breach after Oracle hack

The University of Phoenix (UoPX) has joined a growing list of U.S. universities breached in a Clop data theft campaign targeting vulnerable Oracle E-Business Suite instances in August 2025. [...]

3 de dezembro de 2025

Developers scramble as critical React flaw threatens major apps

The open-source code library is one of the most extensively used application frameworks. Wiz found vulnerable versions in around 39% of cloud environments. The post Developers scramble as critical React flaw threatens major apps appeared first on CyberScoop.

3 de dezembro de 2025

Patch Management Procedure: Building a Secure and Efficient Update Process

Reading Time: 6 minutes Cyber threats are growing more advanced every year, and unpatched systems remain one of the biggest reasons organizations suffer data breaches. In fact, many attacks rely on known vulnerabilities that could have been prevented with proper updates. That's why having a strong patch management procedure is essential for IT managers, cybersecurity teams, and business leaders.... The post Patch Management Procedure: Building a Secure and Efficient Update Process appeared first on Comodo News and Internet Security Information.

bottom of page