MS Family August 2025 Secondary Security Update Advisory

MS Family August 2025 Secondary Security Update Advisory

Overview   Microsoft(https://www.microsoft.com) has released a security update that fixes vulnerabilities in products it has supplied. Users of affected products are advised to update to the latest version.   Affected Products     Apps family Microsoft PC Manager   Azure Family Microsoft Purview Data Governance   ESU Family Windows Server

NVIDIA Product Security Update Advisory

NVIDIA Product Security Update Advisory

Overview   We have released a security update to fix vulnerabilities in NVIDIA products. Users of affected products are advised to update to the latest version.    Affected Products   CVE-2025-23333, CVE-2025-23334   Triton Inference Server Versions: 25.07 and earlier   CVE-2025-23335   Triton Inference Server Version: less than 25.05

N-able Product Security Update Advisory (CVE-2025-8875)

N-able Product Security Update Advisory (CVE-2025-8875)

Overview   We have released a security update to address a vulnerability in our N-able products. Users of affected products are advised to update to the latest version.    Affected Products   CVE-2025-8875   N-central Version: 2025.3.1 and earlier     Resolved Vulnerabilities   Local code execution vulnerability due to

WordPress Plugin Security Update Advisory (CVE-2025-7384)

WordPress Plugin Security Update Advisory (CVE-2025-7384)

Overview   We have released a security update to address a vulnerability in our WordPress plugin. Users of affected products are advised to update to the latest version.    Affected Products   CVE-2025-7384   Contact-form-entries Version: 1.4.3 and earlier     Resolved Vulnerabilities   PHP object injection vulnerability in contact-form-entries

Commvault Security Update Advisory (CVE-2025-57790)

Commvault Security Update Advisory (CVE-2025-57790)

Overview   We have released a security update that addresses a vulnerability in Commvault. Users of affected products are advised to update to the latest version.     Affected Products   CVE-2025-57790   Commvault Versions: 11.32.0 and later and 11.32.101 and earlierCommvault Version: 11.36.0 or later and 11.36.59 or earlier

Keras Security Update Advisory (CVE-2025-1550)

Keras Security Update Advisory (CVE-2025-1550)

Overview   We have released a security update to address a vulnerability in Keras. Users of affected products are advised to update to the latest version.    Affected Products   CVE-2025-1550   Keras Versions: 3.0.0 and above and below 3.9.0     Resolved Vulnerabilities   Arbitrary file overwrite vulnerability due

Dell Product Security Update Advisory (CVE-2025-24919)

Dell Product Security Update Advisory (CVE-2025-24919)

Overview   We have released security updates to fix vulnerabilities in Dell products. Users of affected products are advised to update to the latest version.    Affected Products   CVE-2025-24919   Dell ControlVault3 Plus Driver and Firmware Versions: 6.2.24.0 and earlierDell ControlVault3 Plus Driver and Firmware Version: 5.15.7.0 and earlier

Mobile Security & Malware Issue 3st Week of August, 2025

Mobile Security & Malware Issue 3st Week of August, 2025

ASEC Blog publishes “Mobile Security & Malware Issue 3st Week of August, 2025”

Underground Ransomware Targeting Korean Companies

Underground Ransomware Targeting Korean Companies

The Underground ransomware gang is launching continuous ransomware attacks against companies in various countries and industries, including South Korea. This post describes the analysis and characteristics of the Underground ransomware.   1. Overview 1.1 Team Underground The ransomware strain operated by the group known as Underground was first identified in

July 2025 Major APT Group Trends

July 2025 Major APT Group Trends

Purpose and Scope This report covers nation-led threat groups, presumed to conduct cyber espionage or sabotage supported by certain governments. These groups are referred to as advanced persistent threat (APT) groups for the sake of convenience. Therefore, this report does not contain information on cybercriminal groups aiming to gain financial