CVE-2025-6226 IDOR in CreatePost API allows for timeboxed message disclosure

Mattermost versions 10.5.x <= 10.5.6, 10.8.x <= 10.8.1, 10.7.x <= 10.7.3, 9.11.x <= 9.11.16 fail to verify authorization when retrieving cached posts by PendingPostID which ...

Continue Reading
CERT-UA Discovers LAMEHUG Malware Linked to APT28, Using LLM for Phishing Campaign

The Computer Emergency Response Team of Ukraine (CERT-UA) has disclosed details of a phishing campaign that's designed to deliver a malware codenamed LAMEHUG. "An obvious feature of LAME ...

Continue Reading
CVE-2025-6227

Mattermost versions 10.5.x <= 10.5.7, 9.11.x <= 9.11.16 fail to negotiate a new token when accepting the invite which allows a user that intercepts both invite and password to send synch ...

Continue Reading
CVE-2025-7444

creation_timestamp| type| source ---|---|--- 2025-07-18 10:30:52+00:00| seen|...Read More ...

Continue Reading
K000152630: Node.js vulnerability CVE-2025-27210

Security Advisory Description The cve record for the cve id does not exist. (CVE-2025-27210) Impact There is no impact; F5 products are not affected by this...Read More ...

Continue Reading
CVE-2025-50126

creation_timestamp| type| source ---|---|--- 2025-07-18 11:28:34+00:00| seen|...Read More ...

Continue Reading
CVE-2025-6227 Invite token is used as part of the secure communication

Mattermost versions 10.5.x <= 10.5.7, 9.11.x <= 9.11.16 fail to negotiate a new token when accepting the invite which allows a user that intercepts both invite and password to send synch ...

Continue Reading
CVE-2025-6227 Invite token is used as part of the secure communication

Mattermost versions 10.5.x <= 10.5.7, 9.11.x <= 9.11.16 fail to negotiate a new token when accepting the invite which allows a user that intercepts both invite and password to send synch ...

Continue Reading

Back to Main

Subscribe for the latest news: