July 25, 2025 at 11:10PM

👾 Math.random() is predictable. CVE-2025-7783: Critical Vulnerability in JavaScript Library Exposes Millions of Apps to Code Execution Attacks. Critical Vulnerability in JavaScript Library Exposes Millions of Apps to Code Execution Attacks https://github.com/form-data/form-data/security/advisories/GHSA-fjxv-7rqg-78g4

July 24, 2025 at 01:07AM

■■■■■ CVE-2025-53771: SharePoint vulnerability with 9.8 severity rating under exploit across the globe. Ongoing attacks are allowing hackers to steal credentials, giving privileged access. https://arstechnica.com/security/2025/07/sharepoint-vulnerability-with-9-8-severity-rating-is-under-exploit-across-the-globe/

July 22, 2025 at 05:57PM

■■□□□ Microsoft’s Secure Boot UEFI bootloader signing key expires in September, posing problems for Linux users. https://www.tomshardware.com/tech-industry/cyber-security/microsoft-signing-key-required-for-secure-boot-uefi-bootloader-expires-in-september-which-could-be-problematic-for-linux-users

July 22, 2025 at 05:57PM

■■■■■ Four new Android spyware samples linked to Iran’s intel agency. Persians added snooping capabilities to DCHSpy after Israeli bombs fell. https://www.theregister.com/2025/07/21/muddywaters_android_iran/