Today we published CVE-2025-53548 in response to a vulnerability in our verifyWebhook() helper.
It advises those using this helper to upgrade their npm package. Customers we believe were using affected versions were notified yesterday, in advance of the public disclosure.
We regret the introduction of this vulnerability and are extremely grateful to the Clerk customer who responsibly disclosed the issue. More details are available here:
clerk.com/changelog/2025-07-…
I published blogs detailing two vulnerabilities I recently discovered in Sudo. Update to 1.9.17p1.
CVE-2025-32462 - Sudo Host option Elevation of Privilege Vulnerability stratascale.com/vulnerabilit…
CVE-2025-32463 - Sudo chroot Elevation of Privilege Vulnerability stratascale.com/vulnerabilit…
Just finished reproducing CVE-2025-32433 and putting together a quick PoC exploit — surprisingly easy. Wouldn’t be shocked if public PoCs start dropping soon. If you’re tracking this, now’s the time to take action. #Erlang#SSH
🚨 CVE-2024-48887 Fortinet FortiSwitch GUI vuln (CVSS 9.3)
A remote attacker can change admin passwords without authentication via the set_password endpoint.
Unauthenticated access no verification = full control.
#Vulmon#CyberSecurity#Fortinet
🚨 WhatsApp for Windows Vulnerability: CVE-2025-30401
A crafted attachment could trick users into running malicious code instead of just opening the file — simply by clicking it inside WhatsApp.
#Vulmon#WhatsApp#infosec
Authorization Bypass Vulnerability in Vercel Next.js: CVE-2025-29927
It is possible to bypass authorization checks within a Next.js application, if the authorization check occurs in middleware.
CVSS: 9.1
#Vulmon#React#nextjs#Vercel
🚀 NASA CryptoLib RCE vulnerabilities impact space communication systems!
CryptoLib secures spacecraft-ground station comms using CCSDS SDLS-EP.
#CyberSecurity#SpaceTech#Vulmon
CVE-2025-29909, CVE-2025-29911, CVE-2025-29912, CVE-2025-29913