A critical security vulnerability affecting the Craft content management system (CMS) has been included in the U.S. Cybersecurity and Infrastructure Security Agency's (CISA) Known Exploited Vulnerabilities (KEV) catalog, following evidence of active exploitation. This flaw, identified as CVE-2025-23209, has been assigned a CVSS score of 8.1 and affects versions 4 and 5 of Craft CMS. The issue, a code injection vulnerability, enables remote code execution due to compromised user security keys in vulnerable versions. The developers addressed the flaw in updates released in late December 2024 (versions 4.13.8 and 5.5.8). The vulnerable versions of Craft CMS are those between 5.0.0-RC1 and 5.5.5, as well as versions between 4.0.0-RC1 and 4.13.8. According to Craft CMS's advisory, all unpatched versions of the software with a compromised security key are affected. Although the exact method by which the user security keys were compromised remains unclear, Craft CMS has advised users to either update to patched versions or rotate their security keys to reduce the risk. To mitigate the risk, CISA recommends that Federal Civilian Executive Branch (FCEB) agencies apply the necessary updates by March 13, 2025. In addition to this, Craft CMS had issued a warning in December 2024 about another vulnerability (CVE-2024-56145), which also allowed remote code execution but was not added to CISA's KEV catalog at the time. This highlights the ongoing security challenges facing Craft CMS users.
A threat actor identified as UAC-0184 has been linked to targeted cyber espionage campaigns against Ukrainian military and government organizations. The campaign leverages phishing...
Cybersecurity researchers have identified a widespread malware campaign abusing fake Google Chrome update prompts to infect users with malicious payloads. The attack leverages comp...
Microsoft has introduced a significant security enhancement in its Edge browser after security researchers disclosed that the browser was automatically loading all saved passwords ...