Researchers have disclosed two severe vulnerabilities in the Sudo command-line utility impacting most Linux and Unix-like systems, enabling local attackers to escalate their privileges to root. Administrators are urged to apply patches immediately, as these flaws potentially impact a vast number of servers and endpoints globally by allowing attackers to gain full control over compromised systems.
Source: The Hacker News
Google Fined $314M for Misusing Idle Android Users’ Data
A California court has ordered Google to pay over $314 million for misusing data from Android users' devices while they were idle. The verdict, which ends a class-action lawsuit from 2019, found Google passively collected cell phone data without user consent, raising new questions about privacy practices for mobile platforms and the need for robust transparency.
Source: The Hacker News
Catwatchful Spyware Flaw Exposes Data of Over 62,000 Users, Including its Own Admins
A critical flaw in the Catwatchful Android spyware app has leaked the user database, including email addresses and plaintext passwords of more than 62,000 customers and even administrators. This incident not only puts thousands of victims at risk, but also highlights the persistent security issues and privacy violations tied to stalkerware and surveillance apps.
Source: Security Affairs
Emergency Patches Released for Cisco Unified CM Critical Root Credential Flaw (CVSS 10)
Cisco has issued an urgent fix for a critical vulnerability in its Unified Communications Manager (Unified CM), assigned the maximum severity score of CVSS 10. The flaw, rooted in hardcoded root credentials, could allow remote attackers to seize full control over enterprise communications systems, underscoring the importance of immediate patching and credential management.
Source: HackRead
CVE-2025-5777 "CitrixBleed 2" – Critical NetScaler ADC Vulnerability Exploited
A new critical vulnerability dubbed "CitrixBleed 2" (CVE-2025-5777) has been discovered in NetScaler ADC, with reports of exploitation in the wild. This memory overflow issue raises major concerns for organizations relying on Citrix for secure application delivery, with experts warning to prioritize detection and patching strategies to thwart attacks taking advantage of the flaw.
Source: CISO2CISO / Socprime.com
The Week in Vulnerabilities: Critical Zero-Days Affect Chrome, Cisco, WinRAR, and Industrial Control Systems
Cyble researchers highlight several high-risk, actively exploited vulnerabilities this week, including a Chrome V8 zero-day, critical RCE flaws in Cisco ISE, a WinRAR directory traversal bug, and severe issues in UPS monitoring software. Dark web activity also signals threats against Apple iOS devices via alleged iMessage zero-click exploits, stressing the need for relentless vulnerability management and patching across both IT and OT environments.
Source: Cyble
Taiwan Flags Major Chinese Apps Over Excessive Data Collection and Security Risks
Taiwan’s National Security Bureau has warned the public about severe security risks posed by Chinese-developed apps including TikTok, Weibo, RedNote, WeChat, and Baidu Cloud, citing excessive data collection and transfer to China-based servers. Regulatory scrutiny in Asia-Pacific is intensifying as concerns grow over nation-state surveillance leveraging consumer applications and critical information infrastructure.
Source: The Hacker News
You May Also Be Interested In...