MITRE shares 2025’s top 25 most dangerous software weaknesses December 12, 2025 MITRE has shared this year’s top 25 list of the most dangerous software weaknesses behind over 39,000 security vulnerabilities disclosed
CISA orders feds to patch actively exploited Geoserver flaw December 12, 2025 CISA has ordered U.S. federal agencies to patch a critical GeoServer vulnerability now actively exploited in XML External Entity (XXE)
New Windows RasMan zero-day flaw gets free, unofficial patches December 12, 2025 Free unofficial patches are available for a new Windows zero-day vulnerability that allows attackers to crash the Remote Access Connection
Notepad++ fixes flaw that let attackers push malicious update files December 12, 2025 Notepad++ version 8.8.9 was released to fix a security weakness in its WinGUp update tool after researchers and users reported
Hackers exploit Gladinet CentreStack cryptographic flaw in RCE attacks December 12, 2025 Hackers are exploiting a new, undocumented vulnerability in the implementation of the cryptographic algorithm present in Gladinet’s CentreStack and Triofox products
Brave browser starts testing agentic AI mode for automated tasks December 12, 2025 Brave has introduced a new AI browsing feature that leverages Leo, its privacy-respecting AI assistant, to perform automated tasks for