631.
632.
Maximum severity GoAnywhere MFT flaw exploited as zero day
(bleepingcomputer.com)
633.
634.
635.
CISA orders agencies to patch Cisco flaws exploited in zero-day attacks
(bleepingcomputer.com)
636.
New Supermicro BMC flaws can create persistent backdoors
(bleepingcomputer.com)
637.
Unpatched flaw in OnePlus phones lets rogue apps text messages
(bleepingcomputer.com)
638.
From MCP to shell: MCP auth flaws enable RCE in Claude Code, Gemini CLI and more
(news.ycombinator.com)
639.
Microsoft Entra ID flaw allowed hijacking any company's tenant
(bleepingcomputer.com)
640.
Fortra warns of max severity flaw in GoAnywhere MFT’s License Servlet
(bleepingcomputer.com)
643.
644.
645.
As hackers exploit one high-severity SAP flaw, company warns of 3 more
(arstechnica.com)
646.
Microsoft September 2025 Patch Tuesday fixes 81 flaws, two zero-days
(bleepingcomputer.com)
647.
Adobe patches critical SessionReaper flaw in Magento eCommerce platform
(bleepingcomputer.com)
648.
SAP fixes maximum severity NetWeaver command execution flaw
(bleepingcomputer.com)
650.
Max severity Argo CD API flaw leaks repository credentials
(bleepingcomputer.com)
651.
Hackers exploited Sitecore zero-day flaw to deploy backdoors
(bleepingcomputer.com)
652.
New TP-Link zero-day surfaces as CISA warns other flaws are exploited
(bleepingcomputer.com)
653.
654.
Hackers use new HexStrike-AI tool to rapidly exploit n-day flaws
(bleepingcomputer.com)
655.
Google fixes actively exploited Android flaws in September update
(bleepingcomputer.com)
656.
657.
Hardware Flaw in Apple A16 Chip: Debug Logic Active on Production Devices
(news.ycombinator.com)
658.
659.
Over 28,000 Citrix devices vulnerable to new exploited RCE flaw
(bleepingcomputer.com)
660.
Citrix fixes critical NetScaler RCE flaw exploited in zero-day attacks
(bleepingcomputer.com)