The vulnerability allows unauthenticated attackers to access sensitive credentials from log archives. It's a broken access control flaw, which enables attackers to obtain plaintext credentials.
One flaw, CVE-2025-48595, is particularly alarming. This vulnerability has a CVSS score of 8.4.
Google's June 2026 Android update patches 124 vulnerabilities, including an actively exploited zero-day in the Android Framework tracked as CVE-2025-48595.
A critical remote code execution vulnerability in VMware vCenter Server is being actively exploited in the wild. CVE-2025-1234 carries a CVSS score of 9.8 and affects all recent versions. Immediate patching is recommended.
It was announced on the same day that Trustwave SpiderLabs revealed a new approach to get around Outlook security and send malicious links to victims. was reported by [threatpost](<https://threatpo...