Vulnerabilities and CVEs CVE-2025-32433: critical Erlang/OTP SSH server RCE
CVE-2025-32433 is a CVSS 10.0 unauthenticated RCE in Erlang/OTP SSH. Affected versions, public PoC, detection and vendor fixes.
Daily news, analysis and practical guides explaining what happened, who is affected and what to do next. We also turn this knowledge into practical training for organisations.
Vulnerabilities and CVEs CVE-2025-32433 is a CVSS 10.0 unauthenticated RCE in Erlang/OTP SSH. Affected versions, public PoC, detection and vendor fixes.
Vulnerabilities and CVEs CVE-2025-29824 is another 0-day in the Windows CLFS driver, used by ransomware to seize SYSTEM. Why this class of flaw returns and how to limit the risk.
Vulnerabilities and CVEs CVE-2025-3248 (CVSS 9.8) enables unauthenticated code execution in Langflow before 1.3.0. Public PoC, KEV status, detection and fixes.
Vulnerabilities and CVEs CVE-2025-1974 (CVSS 9.8) enables ingress-nginx RCE and possible Kubernetes takeover. Affected versions, public PoC, detection and fixes.
Threats and Incidents In February 2025, $1.5bn in crypto vanished from Bybit. We break down the Lazarus attack and what failed despite a cold wallet.
Once a month, a concise summary of the vulnerabilities and threats that matter. No spam, unsubscribe anytime.