Entries by Joseph Lee

August 2025 Threat Report: Fast-Moving, High-Risk Vulnerabilities

The August 2025 Threat Report underscores how quickly high-risk vulnerabilities can shift from disclosure to active exploitation. Citrix, Fortinet, N-able, and Trend Micro flaws were weaponized within days. Other critical flaws in highly targeted software, such as Microsoft Exchange, emerged. Mainstream enterprise applications, such as Docker Desktop, Git, and Zoom, were also exposed to new […]

CVE-2025-57819: Unauthenticated RCE Threatens FreePBX Systems Globally

! Update January 28th, 2026 According to a recent report from FortiGuard, a newly disclosed vulnerability in FreePBX Endpoint Manager, CVE-2025-64328 (CVSS 8.6), is now being leveraged in real-world attacks. Greenbone includes a remote banner check for CVE-2025-64328, since its disclosure in early November, 2025. The flaw is a post-authentication command injection flaw [CWE-78] in […]

New WinRAR Flaw CVE-2025-8088 Exploited in Social Engineering Attacks

! Update January 28, 2026 Recent reporting from Google Threat Intelligence Group confirms that CVE-2025-8088 continues to be actively exploited well after patch availability. Attacks have been observed across a broad range of threat actors and campaigns and are no longer isolated to a single cluster or region. Threat actors leveraging CVE-2025-8088 include government-backed actors […]

ToolShell: Patch Bypass Prompts Emergency Alerts for Microsoft SharePoint

On Saturday, July 19th, flaws in Microsoft SharePoint Server became the subject of emergency cybersecurity alerts worldwide. Four CVEs are involved and collectively dubbed “ToolShell”; two published in early July already had patches available, but after being bypassed, two new CVEs were issued. The flaws can allow unauthenticated remote code execution (RCE) at the Windows […]

June 2025 Threat Report: A Cyber Combat of Attrition

The 2025 IOCTA report from Europol warns that demand for data on the cybercrime underground is surging. How much data has been stolen exactly? Determining exact numbers is impossible. However, the personal information of 190 million individuals including Social Security Numbers (SSN), was stolen from Change Healthcare in a single breach. That’s more than half […]

CVE-2025-25257: Urgent Pre-Auth RCE in FortiWeb Fabric Connector

A fresh vulnerability, CVE-2025-25257 (CVSS 9.6) in Fortinet’s FortiWeb Fabric Connector presents high risk globally. Although the CVE is still only in RESERVED status as of July 14th, 2025, it has already received a national CERT advisory from Belgium’s CERT.be and the Center for Internet Security (CIS) has also issued an alert. More alerts should […]

LEV: Demystifying the New Vulnerability Metrics in NIST CSWP 41

In 2025, IT security teams are overwhelmed with a deluge of new security risks. The need to prioritize vulnerability remediation is an ongoing theme among IT security and risk analysts. In a haystack of tasks, finding the needles is imperative. Factors compounding this problem include a cybersecurity talent shortage, novel attack techniques, and the increasing […]

May 2025 Threat Report: Hack, Rinse, Repeat

May 2025 was a volcanic month for cybersecurity news, including several large breaches and new critical severity vulnerabilities. The Greenbone blog has already covered some major events, such as new actively exploited vulnerabilities in SAP Netweaver, Commvault Command Center and Ivanti EPMM. In total 4,014 new vulnerabilities were added to MITRE’s CVE (Common Vulnerabilities and […]

Attackers Advance on Two New Ivanti EPMM Flaws

Just last month, CVE-2025-22457 (CVSS 9.8) affecting Ivanti Connect Secure, Policy Secure, and ZTA Gateways was recognized as a vector for ransomware. Now, two new CVEs have been added to the growing list of high-risk Ivanti vulnerabilities; CVE-2025-4427 and CVE-2025-4428 affecting Ivanti EPMM (Endpoint and Patch Management Mobile) are under active exploitation. Greenbone includes active […]