Cyber Security

Articles on SystemTek’s website that relate to cyber security.

NewsSecurity Vulnerabilities

Ubiquiti Networks UniFi Console Missing Authentication for Critical Function Authentication Bypass Vulnerability (CVE-2025-23116)

– This vulnerability allows network-adjacent attackers to bypass authentication on affected Ubiquiti Networks UniFi Console devices.

Read More
NewsSecurity Vulnerabilities

Ubiquiti Networks AI Bullet Insufficient Firmware Update Validation Remote Code Execution Vulnerability (CVE-2025-23117)

– This vulnerability allows network-adjacent attackers to execute arbitrary code on affected Ubiquiti Networks AI Bullet Cameras.

Read More
NewsMicrosoftSoftware

External Apps Can Exploit OneDrive Security Flaw

– Websites that support OneDrive file uploads—such as ChatGPT, Slack, Trello, ClickUp, Zoom, and others—can gain access to a user’s entire OneDrive account, not just the files selected for upload. This access may persist for extended periods.

Read More
NewsSecurity Vulnerabilities

Hewlett Packard Enterprise Directory Traversal Remote Code Execution Vulnerability (CVE-2025-37099)

– This vulnerability allows remote attackers to execute arbitrary code on affected installations of Hewlett Packard Enterprise Insight Remote Support. Authentication is not required to exploit this vulnerability.

Read More
NewsTelecoms

Student-led research deploys AI to spot stealthy Android malware

– Researchers at Florida Polytechnic University have developed an artificial intelligence technique that can detect elusive malware known as remote access trojans (RATs) on Android devices. The breakthrough could help protect millions of users from cybercriminals who use RATs to steal personal information and control devices without detection.

Read More
NewsSecurity Vulnerabilities

Cisco Identity Services Engine on Cloud Platforms Static Credential Vulnerability (CVE-2025-20286)

– A critical vulnerability in Amazon Web Services (AWS), Microsoft Azure, and Oracle Cloud Infrastructure (OCI) cloud deployments of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to access sensitive data, execute limited administrative operations, modify system configurations, or disrupt services within the impacted systems.

Read More
NewsSecurity Vulnerabilities

Sante DICOM Viewer Pro DCM File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability (CVE-2025-5481)

CVE number = CVE-2025-5481 This vulnerability allows remote attackers to execute arbitrary code on affected installations of Sante DICOM Viewer

Read More
NewsGoogleSoftware

Google Chrome to Revoke Trust in Two Certificate Authorities Citing Compliance and Conduct Concerns

– Google has announced that it will stop trusting digital certificates issued by Chunghwa Telecom and Netlock, citing “patterns of concerning behaviour observed over the past year.”

Read More
NewsSecurity Vulnerabilities

Cisco Meraki MX and Z Series Teleworker Gateway AnyConnect VPN Denial of Service Vulnerabilities

– Multiple vulnerabilities in the Cisco AnyConnect VPN server of Cisco Meraki MX and Cisco Meraki Z Series Teleworker Gateway devices could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition to the AnyConnect VPN service on an affected device.

Read More
NewsSecurity Vulnerabilities

Cisco Meraki MX and Z Series Teleworker Gateway AnyConnect VPN Session Takeover and Denial of Service Vulnerability (CVE-2024-20509)

– A vulnerability in the Cisco AnyConnect VPN server of Cisco Meraki MX and Cisco Meraki Z Series Teleworker Gateway devices could allow an unauthenticated, remote attacker to hijack an AnyConnect VPN session or cause a denial of service condition for individual users of the AnyConnect VPN service on affected device.

Read More