07/11

CISA tags Citrix Bleed 2 as exploited, gives agencies a day to patch

https://www.bleepingcomputer.com/news/security/cisa-tags-citrix-bleed-2-as-exploited-gives-agencies-a-day-to-patch/
CISA tags Citrix Bleed 2 as exploited, gives agencies a day to patch

Pre-Auth SQL Injection to RCE - Fortinet FortiWeb Fabric Connector (CVE-2025-25257)

https://labs.watchtowr.com/pre-auth-sql-injection-to-rce-fortinet-fortiweb-fabric-connector-cve-2025-25257/
Pre-Auth SQL Injection to RCE - Fortinet FortiWeb Fabric Connector (CVE-2025-25257)

PerfektBlue Bluetooth Vulnerabilities Expose Millions of Vehicles to Remote Code Execution

https://thehackernews.com/2025/07/perfektblue-bluetooth-vulnerabilities.html
PerfektBlue Bluetooth Vulnerabilities Expose Millions of Vehicles to Remote Code Execution

摩诃草(APT-Q-36)仿冒高校域名实施窃密行动

https://mp.weixin.qq.com/s/xn313WWNi7rln-WfwFgE5w
摩诃草(APT-Q-36)仿冒高校域名实施窃密行动

Fortinet Releases Patch for Critical SQL Injection Flaw in FortiWeb (CVE-2025-25257)

https://thehackernews.com/2025/07/fortinet-releases-patch-for-critical.html
Fortinet Releases Patch for Critical SQL Injection Flaw in FortiWeb (CVE-2025-25257)

eSIM Hack Allows for Cloning, Spying  - SecurityWeek

https://www.securityweek.com/esim-hack-allows-for-cloning-spying/
eSIM Hack Allows for Cloning, Spying  - SecurityWeek

Three Buddy Problem

https://episodes.fm/1414525622
Three Buddy Problem

NVIDIA shares guidance to defend GDDR6 GPUs against Rowhammer attacks

https://www.bleepingcomputer.com/news/security/nvidia-issues-guidance-to-defend-gddr6-gpus-against-rowhammer/
NVIDIA shares guidance to defend GDDR6 GPUs against Rowhammer attacks

Iranian-Backed Pay2Key Ransomware Resurfaces with 80% Profit Share for Cybercriminals

https://thehackernews.com/2025/07/iranian-backed-pay2key-ransomware.html
Iranian-Backed Pay2Key Ransomware Resurfaces with 80% Profit Share for Cybercriminals

Declawing PUMAKIT — Elastic Security Labs

https://elastic.co/security-labs/declawing-pumakit
Declawing PUMAKIT — Elastic Security Labs

Exploits for pre-auth Fortinet FortiWeb RCE flaw released, patch now

https://www.bleepingcomputer.com/news/security/exploits-for-pre-auth-fortinet-fortiweb-rce-flaw-released-patch-now/
Exploits for pre-auth Fortinet FortiWeb RCE flaw released, patch now

The zero-day that could've compromised every Cursor and Windsurf user

https://www.bleepingcomputer.com/news/security/the-zero-day-that-couldve-compromised-every-cursor-and-windsurf-user/
The zero-day that could've compromised every Cursor and Windsurf user

Rowhammer Attack Demonstrated Against Nvidia GPU - SecurityWeek

https://www.securityweek.com/rowhammer-attack-demonstrated-against-nvidia-gpu/
Rowhammer Attack Demonstrated Against Nvidia GPU - SecurityWeek