Protecting Privacy Build Trust

Protecting Privacy Build Trust
  • Contact Us

Privacy Trust

on May 22, 2025 at 10:00 am — UAT-6382 exploits Cityworks zero-day vulnerability to deliver malware 

Cisco Talos has observed exploitation of CVE-2025-0994, a remote-code-execution vulnerability in Cityworks, a popular asset management system.   The Cybersecurity and Infrastructure Security Agency (CISA) and Trimble have both released advisories pertaining to this vulnerability, with Trimble’s advisory specifically listing indicators of compromise (IOCs) related to the intrusion exploiting the CVE.   IOCs pertaining to intrusions discovered

on May 22, 2025 at 10:00 am — UAT-6382 exploits Cityworks zero-day vulnerability to deliver malware  Read More »

on May 15, 2025 at 7:00 am — CVE-2025-32709 Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability 

In the Security Updates table, added all supported editions of Windows Server 2008 and Windows Server 2008 R2 as they are affected by this vulnerability. Customers running these versions of Windows Server please note that to be protected from this vulnerability you need to install the out-of-band updates as follows: * Windows Server 2008 R2:

on May 15, 2025 at 7:00 am — CVE-2025-32709 Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability  Read More »

on May 15, 2025 at 5:20 pm — Chromium: CVE-2025-4609 Incorrect handle provided in unspecified circumstances in Mojo 

This CVE was assigned by Chrome.  Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information. 

on May 15, 2025 at 5:20 pm — Chromium: CVE-2025-4609 Incorrect handle provided in unspecified circumstances in Mojo  Read More »

on May 15, 2025 at 5:20 pm — Chromium: CVE-2025-4664 Insufficient policy enforcement in Loader 

This CVE was assigned by Chrome.  Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2025) for more information. Google is aware of reports that an exploit for CVE-2025-4664 exists in the wild. 

on May 15, 2025 at 5:20 pm — Chromium: CVE-2025-4664 Insufficient policy enforcement in Loader  Read More »