In March 2025, Apache disclosed CVE-2025-24813, a vulnerability impacting Apache Tomcat. This is a widely used platform that allows Apache web servers to run Java-based web applications.
The flaw allows remote code execution, affecting Apache Tomcat versions 9.0.0.M1 to 9.0.98, 10.1.0-M1 to 10.1.34 and 11.0.0-M1 to 11.0.2. The same month, Apache revealed two additional vulnerabilities in Apache Camel, a message routing middleware framework. These vulnerabilities are CVE-2025-27636 and CVE-2025-29891, two flaws that allow remote code execution, affecting Apache Camel versions 4.10.0 to 4.10.1, 4.8.0 to 4.8.4 and 3.10.0 to 3.22.3. These vulnerabilities are significant because millions of developers rely on the platform provided by the Apache Foundation.
Read more…
Source: Palo Alto Unit 42
Sign up for the Cyber Security Review Newsletter
The latest news and insights delivered right to your inbox.
Related:
- Storm-0978 attacks reveal financial and espionage motives
July 11, 2023
Microsoft has identified a phishing campaign conducted by the threat actor tracked as Storm-0978 targeting defense and government entities in Europe and North America. The campaign involved the abuse of CVE-2023-36884, which included a remote code execution vulnerability exploited before disclosure to Microsoft via Word documents, using lures related to the Ukrainian World Congress. Read more… Source: Microsoft
- Attackers Exploit Unpatched Windows Zero-Day Vulnerability
July 11, 2023
A zero-day vulnerability (CVE-2023-36884) affecting Microsoft Windows and Office products is being exploited by attackers in the wild. To date, the exploit has been used in highly targeted attacks against organizations in the government and defense sectors in Europe and North America. The vulnerability was disclosed yesterday (July 11) by Microsoft, which said that an attacker ...
- Florida patients among 11 million affected by HCA Healthcare data breach
July 10, 2023
Data on roughly 11 million HCA Healthcare patients in 20 states including Florida, was stolen and recently posted on an online forum, the hospital chain reported on Sunday. According to the company, an unauthorized party gained access to 27 million rows of data stored at an external location that is used to to automate company email ...
- Ventia takes systems offline to contain cyber attack
July 10, 2023
Ventia has taken an undisclosed number of “key systems” offline to contain a cyber security incident. The listed company, which provides long-term operation, maintenance, and management for critical public and private assets and infrastructure, disclosed the incident on Saturday. Read more… Source: IT News
- The TOITOIN Trojan: Analyzing a New Multi-Stage Attack Targeting LATAM Region
July 7, 2023
This sophisticated campaign targeting LATAM region employs a trojan that follows a multi-staged infection chain, utilizing specially crafted modules throughout each stage. These modules are custom designed to carry out malicious activities, such as injecting harmful code into remote processes, circumventing User Account Control via COM Elevation Moniker, and evading detection by Sandboxes through clever ...
- Telegram has become a window into war
July 7, 2023
Since the invasion of Ukraine in February 2022, Telegram has gained an outsize influence on one of the world’s most watched conflicts. “Telegram is fantastic for many, many reasons and for the fact that we’ve managed to see what is happening at such a crucial point in history,” says Jordan Wildon, digital investigator and founder ...
