In March 2025, Apache disclosed CVE-2025-24813, a vulnerability impacting Apache Tomcat. This is a widely used platform that allows Apache web servers to run Java-based web applications.
The flaw allows remote code execution, affecting Apache Tomcat versions 9.0.0.M1 to 9.0.98, 10.1.0-M1 to 10.1.34 and 11.0.0-M1 to 11.0.2. The same month, Apache revealed two additional vulnerabilities in Apache Camel, a message routing middleware framework. These vulnerabilities are CVE-2025-27636 and CVE-2025-29891, two flaws that allow remote code execution, affecting Apache Camel versions 4.10.0 to 4.10.1, 4.8.0 to 4.8.4 and 3.10.0 to 3.22.3. These vulnerabilities are significant because millions of developers rely on the platform provided by the Apache Foundation.
Read more…
Source: Palo Alto Unit 42
Sign up for the Cyber Security Review Newsletter
The latest news and insights delivered right to your inbox.
Related:
- Hackers took down U.S. airport web sites, Department of Homeland Security confirms
October 10, 2022
Unknown hackers attacked and temporarily shut down the public-facing websites of at least several major U.S. airports on Monday, a Department of Homeland Security official confirmed to USA TODAY. The official from DHS’ Cybersecurity and Infrastructure Security Agency or CISA, declined to comment on who might have been behind what appeared to be a coordinated series ...
- Intel Alder Lake BIOS code leak may contain vital secrets
October 10, 2022
Source code for the BIOS used with Intel’s 12th-gen Core processors has been leaked online, possibly including details of undocumented model-specific registers (MSRs) and even the private signing key for Intel’s Boot Guard security technology. The source code was apparently shared via 4chan and GitHub, in a file containing tools and code for generating and optimizing ...
- Criminal multitool LilithBot arrives on malware-as-a-service scene
October 10, 2022
A Russia based threat group that set up a malware distribution shop earlier this year is behind a Swiss Army knife-like botnet that comes with a range of other malicious capabilities, from stealing information to mining cryptocurrency. That’s according to researchers at Zscaler’s ThreatLabz threat intelligence unit. It said the Eternity group – also known as ...
- Iranian state-run live TV hacked by protesters
October 9, 2022
Iran’s state-run broadcaster was apparently hacked on air Saturday, with a news bulletin interrupted by a protest against the country’s leader. A mask appeared on the screen, followed by an image of Supreme Leader Ali Khamenei with flames around him. The group called itself “Adalat Ali”, or Ali’s Justice. Read more… Source: BBC News
- Pro-Iranian hackers attack Israeli gas company website
October 9, 2022
Iraqi hacker group “al-Tahara” attacked the websites for two natural gas companies. The first, Energean, is an international company which has done extensive business with Israel, having acquired the Karish and Tanin natural gas fields from Delek Drilling and Avner Oil in 2016. The second, Israel Natural Gas Lines, is a corporation owned by the Israeli ...
- ADATA denies RansomHouse cyberattack, says leaked data from 2021 breach
October 8, 2022
Taiwanese chip maker ADATA denies claims of a RansomHouse cyberattack after the threat actors began posting stolen files on their data leak site. The RansomHouse gang added ADATA files to their data leak site on Tuesday, claiming they stole 1TB worth of documents in a 2022 cyberattack.The threat actors also leaked samples of allegedly stolen files, ...
