Monthly NDV – December/2025

The December NDV highlights the most critical and high-severity vulnerabilities, including actively exploited flaws in widely used technologies.

Critical vulnerability enables remote code execution in n8n via Git node manipulation

A critical flaw (CVE-2025-65964, CVSS 9.4) in n8n allows remote code execution by abusing Git Node configuration, letting attackers run malicious scripts on the host server.

Critical Fortinet vulnerabilities allow authentication bypass

Fortinet has patched two critical flaws (CVSS 9.8) that enable full authentication bypass via SAML response forgery in FortiOS.

Microsoft fixes actively exploited zero-day and 56 additional vulnerabilities in December Patch Tuesday

Microsoft’s December Patch Tuesday delivers fixes for 57 vulnerabilities, including an actively exploited zero-day (CVE-2025-62221) enabling SYSTEM-level privilege escalation.

SAP fixes critical vulnerabilities in the December 2025 Patch Day

SAP released patches for 14 flaws, including critical vulnerabilities enabling code execution and full system compromise in Solution Manager, Commerce Cloud, and jConnect, requiring urgent updates.

Intelligence Brief – WhatsApp Malware in Brazil: Water Saci, Maverick & Coyote

Cybercriminals are using WhatsApp to deliver multi-stage malware designed to steal data and gain remote access.

Monthly NDV OT-ICS – November/2025

An issue in Azure Front Door led to worldwide disruptions across Microsoft services, impacting applications relying on the platform.

Monthly NDV – November/2025

See November’s most critical vulnerabilities and the urgent actions needed to reduce risk.

New Sha1-Hulud Wave Hits Over 25,000 Repositories via NPM Supply Chain

The new malware variant compromises thousands of npm repositories, stealing credentials and wiping directories if exfiltration fails.

Privacy Overview
SEK

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.

Strictly Necessary Cookies

Strictly Necessary Cookie should be enabled at all times so that we can save your preferences for cookie settings.

Analytics

This website uses Google Analytics to collect anonymous information such as the number of visitors to the site, and the most popular pages.

Keeping this cookie enabled helps us to improve our website.

Marketing

This website uses the following additional cookies:

(List the cookies that you are using on the website here.)