Related Threat Clusters
-
Critical BIND 9 DNS Vulnerability Exploited with Public Code Release
A public exploit for CVE-2025-40778, a critical vulnerability in BIND 9, has been released, enabling DNS cache poisoning and traffic redirection. This flaw affects the widely used Domain Name System software, posing…
1 article · Updated November 2, 2025 -
CISA Adds XWiki and VMware Vulnerabilities to KEV Catalog
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added vulnerabilities related to the XWiki Platform and Broadcom's VMware Aria Operations and VMware Tools to its Known Exploited Vulnerabilities…
2 articles · Updated October 31, 2025 -
CISA Confirms Active Exploitation of VMware ESXi CVE-2025-22225
CISA has confirmed the active exploitation of a critical vulnerability in VMware ESXi, tracked as CVE-2025-22225. This zero-day flaw allows attackers to escape security sandboxes and is currently being used in…
7 articles · Updated February 5, 2026 -
CISA Updates KEV Catalog with XWiki and VMware Vulnerabilities
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added vulnerabilities related to the XWiki Platform and Broadcom's VMware Aria Operations and VMware Tools to its Known Exploited Vulnerabilities…
2 articles · Updated October 31, 2025
Recent Intelligence Reports
- CISA: Ransomware intrusions exploiting VMware ESXi bug ongoing — Scworld · February 6, 2026
- CISA: VMware ESXi flaw now exploited in ransomware attacks — Bleepingcomputer · February 4, 2026
- Cybersecurity News Weekly Newsletter – EY Data Leak, Bind 9, Chrome Vulnerability, and ... — Cybersecuritynews · November 2, 2025
- CISA Adds Exploited XWiki, VMware Flaws to KEV Catalog — Feeds.Feedburner · October 31, 2025