CSIRT.SK
@CSIRT_SK
Followers
2K
Following
197
Media
159
Statuses
7K
CSIRT.SK performs tasks associated with responding to computer security incidents within public administration information systems in the Slovak Republic.
Slovak Republic
Joined November 2015
‼️Hackers Weaponize SVG Files and Office Documents | Source: https://t.co/5ekM1fpgIV A sophisticated email campaign deploying a commodity loader to distribute Remote Access Trojans and information stealers. The operation primarily targets manufacturing and government
0
51
204
🚨Alert🚨:CVE-2025-68613(CVSS 10.0): A Critical Remote Code Execution (RCE) Vulnerability in n8n. 📊905.9K Services are found on the https://t.co/ysWb28BTvF yearly. 🔗Hunter Link: https://t.co/htPYV2VaDy 👇Query HUNTER : https://t.co/q9rtuGfZuz="N8n"
7
82
297
ASRock, ASUS, GIGABYTE, MSI Boards vulnerable to pre-boot memory Attacks https://t.co/c0KmkE5Z9p
#securityaffairs #hacking #UFI
securityaffairs.com
A new UEFI flaw exposes some ASRock, ASUS, GIGABYTE, and MSI motherboards to early-boot DMA attacks, bypassing IOMMU protections.
0
2
2
🚨 Upozorňujeme na kritickou zranitelnost ve WatchGuard Firebox, CVE-2025-14733. Jedná se o chybu typu out-of-bounds write v procesu iked systému Fireware OS, která umožňuje vzdálenému neautentizovanému útočníkovi spustit libovolný kód. Zranitelnost vzniká při nesprávném
0
5
4
UEFI Vulnerability in Major Motherboards Enables Early-Boot Attacks
securityweek.com
ASRock, Asus, Gigabyte, and MSI motherboards are vulnerable to early-boot DMA attacks.
0
6
6
New password spraying attacks target Cisco, PAN VPN gateways - @billtoulas
https://t.co/EPo39tTb5f
https://t.co/EPo39tTb5f
bleepingcomputer.com
An automated campaign is targeting multiple VPN platforms, with credential-based attacks being observed on Palo Alto Networks GlobalProtect and Cisco SSL VPN.
0
35
67
Hewlett Packard Enterprise (HPE) has patched a maximum-severity OneView vulnerability (CVE-2025-37164) that enables attackers to execute arbitrary code remotely. https://t.co/F4z3J17wIM
bleepingcomputer.com
Hewlett Packard Enterprise (HPE) has patched a maximum-severity vulnerability in its HPE OneView software that enables attackers to execute arbitrary code remotely.
0
34
52
🚨🚨CVE-2025-68460 & CVE-2025-68461: Roundcube Alert: High-Severity SVG XSS and CSS Sanitizer Flaws Threaten Webmail Privacy ZoomEye Dork👉app="RoundCube Webmail" 642.9k+ exposed instances. ZoomEye Link: https://t.co/s6g9BCPzEE Refer: 1. https://t.co/ynzLaPxuZA 2.
0
13
70
🚨🚨Zero-Day Alert: CVE-2025-20393 (CVSS 10) Attack targets Cisco Secure Email Gateway & Web Manager with exposed ports, allowing root-level command execution. Search by vul.cve Filter👉vul.cve="CVE-2025-20393" ZoomEye Dork👉app="Cisco Secure Email Platform" 2.4k+ exposed
0
12
44
🚨Alert🚨:CVE-2025-40602(Zero-Day) : Hackers Chain SonicWall SMA1000 Flaws for Unauthenticated Root RCE 📊23.9K+ Services are found on the https://t.co/ysWb28BTvF yearly. 🔗Hunter Link: https://t.co/jGrnMs1bXv 👇Query HUNTER : https://t.co/q9rtuGfZuz="SonicWall SMA1000"
1
6
41
⚠️⚠️ CVE-2025-63387: Unauthenticated Access to System Features in Dify /console/api/system-features API endpoint, authentication middleware 🔗FOFA Link: https://t.co/Sc4sSu3ZMJ 🎯85k+ Results are found on the https://t.co/pb16tGYaKe nearly year. FOFA Query: app="Dify" 🔖Refer:
1
17
84
🚨 Upozorňujeme na kritickou Zero-day zranitelnost v Cisco AsyncOS, CVE-2025-20393. Jedná se o chybu s maximální závažností (CVSS 10.0), která vzniká kvůli nesprávné validaci vstupu. Útočník může prostřednictvím této zranitelnosti spustit libovolné příkazy s oprávněním root na
0
3
3
Warning: Patches were released for #CVE-2025-46295. Critical vulnerability identified in #Apache Commons Text library of #Claris #FileMaker Server. Successful exploitation could lead to full #remote compromise of FileMaker Server instances. https://t.co/dFw9LgBJGm
#Patch #Patch
0
1
0
🛑 WARNING: CVE-2025-20393 is rated 10.0, with no patch available. Cisco confirmed active exploitation of an AsyncOS zero-day by a China-linked APT. The flaw allows root-level command execution on affected email security appliances and enables attackers to establish
24
316
1K
🐞 Microsoft Security Updates break MSMQ, causing enterprise apps and (IIS) sites to fail Source: https://t.co/EfrAznZkqt Microsoft has confirmed that its December 2025 Windows security update (KB5071546, OS Build 19045.6691) is causing Message Queuing (MSMQ) failures, leading
2
48
155
🛑 SonicWall patched an actively exploited flaw in SMA 100 series appliances. CVE-2025-40602 lets attackers escalate privileges via the management console and was chained with a prior bug for root access. Patches are now out for affected versions. 🔗 Read →
1
27
79
🚨Alert🚨:CVE-2025-20393(Zero-Day, CVSS 10) : UAT-9686 actively targets Cisco Secure Email Gateway and Secure Email and Web Manager 📊8.6K+ Services are found on the https://t.co/ysWb28BTvF yearly. 🔗Hunter Link: https://t.co/WvJCoe2Q54 👇Query HUNTER :
1
15
65