VulnVibes podcast artwork

PODCAST · technology

VulnVibes

Welcome to VulnVibes, your go-to source for quick, engaging insights into IT security exploits! We break down vulnerabilities, hacks, and defenses into bite-sized videos that anyone can understand. Whether you're a tech enthusiast or a cybersecurity pro, you'll stay ahead of the game with our fast-paced, no-fluff content. Subscribe now to keep your systems secure and your knowledge sharp!

  1. 65

    [VULN] - Xerox Versalink Printers Vulnerable to Pass-Back Attacks - CVE-2024-12510 & CVE-2024-12511

    Researchers at Rapid7 have identified vulnerabilities in Xerox Versalink C7025 multifunction printers that could enable attackers to steal user credentials. Tracked as CVE-2024-12510 and CVE-2024-12511, these flaws facilitate a "pass-back attack," in which the printer is deceived into returning authentication data to the attacker.

  2. 64

    [VULN] - OpenSSH Client & Server Vulnerabilities Allow MiTM and DoS Attacks - CVE-2025-26465 & CVE-2025-26466

    The Qualys Threat Research Unit (TRU) has revealed two newly discovered vulnerabilities in OpenSSH, impacting both clients and servers. Designated as CVE-2025-26465 and CVE-2025-26466, these flaws could allow attackers to carry out machine-in-the-middle (MITM) attacks and denial-of-service (DoS) exploits.

  3. 63

    [WordPress] - WP Safe - 2025.02.18

    Daily Summary of WordPress critical and high vulnerabilities

  4. 62

    [VULN] - SQL Injection Vulnerability in PostgreSQL Allows Remote System Attacks - CVE-2025-1094

    Rapid7 researchers have identified a high-severity SQL injection vulnerability (CVE-2025-1094) in PostgreSQL’s interactive tool, psql. Discovered during an investigation into the exploitation of a separate BeyondTrust vulnerability, this flaw enables attackers to execute arbitrary code on impacted systems.

  5. 61

    [WordPress] - WP Safe - 2025.02.17

    Daily Summary of WordPress critical and high vulnerabilities

  6. 60

    [VULN] - Winzip RCE Vulnerability - CVE-2025-1240

    A critical vulnerability has been identified in WinZip, potentially enabling remote attackers to execute arbitrary code on affected systems. Designated as CVE-2025-1240, this flaw stems from how WinZip processes 7Z files and could be exploited if a user interacts with a malicious file or webpage.

  7. 59

    [VULN] - Severe Vulnerabilities in PAM-PKCS#11 Put Linux Authentication at Risk - CVE-2025-24032

    Multiple critical security flaws have been discovered in the PAM-PKCS#11 login module, a widely used tool for X.509 certificate-based authentication on Linux systems. These vulnerabilities could enable attackers to bypass authentication, gain unauthorized system access, and potentially escalate privileges.

  8. 58

    [VULN] - Remote Code Execution (RCE) Vulnerability Found in Wazuh Server - CVE-2025-24016

    Wazuh, a prominent open-source security solutions provider, has released a critical security advisory about a remote code execution (RCE) vulnerability impacting its platform. Designated as CVE-2025-24016 with a CVSS score of 9.9, this flaw could enable attackers to take full control of affected Wazuh servers.

  9. 57

    [WordPress] - WP Safe - 2025.02.12

    Daily Summary of WordPress critical and high vulnerabilities

  10. 56

    [VULN] - Critical Ivanti CSA Vulnerability Allows Attackers to Execute Arbitrary Code - CVE-2024-47908

    Ivanti has released a security advisory addressing critical vulnerabilities in its Cloud Services Application (CSA). Tracked as CVE-2024-47908 and CVE-2024-11771, these flaws could enable attackers to execute remote code and access sensitive data without authorization.

  11. 55

    [WordPress] - WP Safe - 2025.02.11 - 2

    Daily Summary of WordPress critical and high vulnerabilities

  12. 54

    [WordPress] - WP Safe - 2025.02.11 - 1

    Daily Summary of WordPress critical and high vulnerabilities

  13. 53

    [VULN] - GitHub Enterprise SAML Bypass Vulnerability - CVE-2025-24200

    Security researcher Hakivvi has released a detailed analysis of CVE-2025-23369 (CVSSv4 7.6), a vulnerability that enables attackers to bypass SAML authentication in GitHub Enterprise.

  14. 52

    [VULN] - Apple Releases Emergency Updates to Fix Actively Exploited Zero-Day Vulnerability - CVE-2025-24200

    Apple has released critical security updates for iOS and iPadOS to patch a zero-day vulnerability, CVE-2025-24200, which has been actively exploited in targeted attacks. This flaw enables attackers to bypass USB Restricted Mode on locked devices, potentially exposing sensitive data.

  15. 51

    [WordPress] - WP Safe - 2025.02.10

    Daily Summary of WordPress critical and high vulnerabilities

  16. 50

    [VULN] - Critical bugs in Zimbra Collaboration - CVE-2025-25064

    Two newly discovered security vulnerabilities have been identified in Zimbra Collaboration, a popular open-source email and collaboration platform. These flaws, tracked as CVE-2025-25064 and CVE-2025-25065, present a significant risk to businesses using Zimbra for email, calendaring, file sharing, and task management. If exploited, they could enable attackers to gain unauthorized access to sensitive data and internal network resources.

  17. 49

    [VULN] - The Critical Outlook Vulnerability Putting Organizations at Risk - CVE-2024-21413

    A severe security flaw in Microsoft Outlook, identified as CVE-2024-21413, is currently being actively exploited, presenting a major risk to organizations globally. Rated 9.8 out of 10 on the CVSS scale, this vulnerability enables attackers to remotely execute arbitrary code when a user opens a malicious email.

  18. 48

    [VULN] - Cisco ISE Critical vulnerabilities - CVE-2025-20124 & CVE-2025-20125

    Cisco has released a security advisory regarding two critical vulnerabilities in its Identity Services Engine (ISE), a widely used network security policy management platform. These vulnerabilities, identified as CVE-2025-20124 and CVE-2025-20125, could allow authenticated attackers to execute arbitrary commands with root privileges and bypass authorization controls, posing significant risks to affected systems.

  19. 47

    [WordPress] - WP Safe - 2025.02.07

    Daily Summary of WordPress critical and high vulnerabilities

  20. 46

    [WordPress] - WP Safe - 2025.02.06

    Daily Summary of WordPress critical and high vulnerabilities

  21. 45

    [WordPress] - WP Safe - 2025.02.05

    Daily Summary of WordPress critical and high vulnerabilities

  22. 44

    [WordPress] - WP Safe - 2025.02.04

    Daily Summary of WordPress critical and high vulnerabilities

  23. 43

    [WordPress] - WP Safe - 2025.02.03

    Daily Summary of WordPress critical and high vulnerabilities

  24. 42

    [VULN] - Laravel package Voyager RCE vulnerability

    Three security vulnerabilities found in the open-source PHP package Voyager, used for managing Laravel applications, could allow remote code execution attacks.

  25. 41

    [WordPress] - WP Safe - 2025.01.30

    Daily Summary of WordPress critical and high vulnerabilities

  26. 40

    [WordPress] - WP Safe - 2025.01.30

    Daily Summary of WordPress critical and high vulnerabilities

  27. 39

    [HotTopic] - DeepSeek AI - Database Exposure

    Wiz Research discovered a publicly accessible ClickHouse database owned by DeepSeek, granting full control over database operations and access to internal data. This exposure included over a million lines of log streams containing chat history, secret keys, backend details, and other highly sensitive information. The Wiz Research team promptly and responsibly reported the issue to DeepSeek, which swiftly secured the vulnerability.

  28. 38

    [WordPress] - WP Safe - 2025.01.29

    Daily Summary of WordPress critical and high vulnerabilities

  29. 37

    [VULN] - SQL Injection Flaw in VMware Avi Load Balancer - CVE-2025-22217

    Broadcom has issued an alert regarding a high-severity security vulnerability in VMware Avi Load Balancer, identified as CVE-2025-22217, with a CVSS score of 8.6. This unauthenticated blind SQL injection flaw allows malicious actors with network access to execute specially crafted SQL queries, potentially granting them unauthorized access to the database.

  30. 36

    [VULN] - Cacti network monitoring RCE - CVE-2025-22604

    A severe security vulnerability has been revealed in the Cacti open-source network monitoring and fault management framework, potentially enabling an authenticated attacker to execute remote code on vulnerable instances.

  31. 35

    [WordPress] - WP Safe - 2025.01.28

    Daily Summary of WordPress critical and high vulnerabilities

  32. 34

    [VULN] - QNAP patched multiple vulnerabilities

    QNAP has fixed six rsync vulnerabilities that could let attackers gain remote code execution on unpatched Network Attached Storage (NAS) devices.

  33. 33

    [WordPress] - WP Safe - 2025.01.27

    Daily Summary of WordPress critical and high vulnerabilities

  34. 32

    [WordPress] - WP Safe - 2025.01.26

    Daily Summary of WordPress critical and high vulnerabilities

  35. 31

    [WordPress] - WP Safe - 2025.01.25

    Daily Summary of WordPress critical and high vulnerabilities

  36. 30

    [VULN] - Zero-day vulnerability exploited: SonicWall SMA series - CVE-2025-23006

    SonicWall has released an urgent security advisory regarding a critical vulnerability in its SMA1000 Appliance Management Console (AMC) and Central Management Console (CMC). Identified as CVE-2025-23006 with a CVSS score of 9.8, this pre-authentication remote command execution flaw poses a significant risk, enabling attackers to fully compromise vulnerable devices.

  37. 29

    [WordPress] - WP Safe - 2025.01.24

    Daily Summary of WordPress critical and high vulnerabilities

  38. 28

    [VULN] - Microsoft Configuration Manager Exploit - CVE-2024-43468

    Security researcher Mehdi Elyassa from Synacktiv published the technical details and a proof-of-concept (PoC) exploit code for a critical vulnerability in Microsoft Configuration Manager (MCM), tracked as CVE-2024-43468, with a CVSS score of 9.8. This flaw allows unauthenticated attackers to exploit SQL injection vulnerabilities, enabling the execution of arbitrary commands on servers and their underlying databases.

  39. 27

    [VULN] - Kibana Exposing Sensitive Information - CVE-2024-43707

    Kibana, the popular open-source data visualization and exploration tool, has released a security update addressing two vulnerabilities, including one high severity flaw. The update, version 8.15.0, is available now and all users are strongly encouraged to upgrade their installations immediately.

  40. 26

    [WordPress] - WP Safe - 2025.01.22

    Daily Summary of WordPress critical and high vulnerabilities

  41. 25

    [WordPress] - WP Safe - 2025.01.21

    Daily Summary of WordPress critical and high vulnerabilities

  42. 24

    [VULN] - Outlook Remote Code Execution - CVE-2025-21298

    Microsoft has addressed a critical vulnerability (CVE-2025-21298) in its latest 2025 Patch Tuesday update. This flaw, rated with a CVSS score of 9.8, allows attackers to achieve remote code execution (RCE) on Windows devices through a specially crafted email

  43. 23

    [WordPress] - WP Safe - 2025.01.21

    Daily Summary of WordPress critical and high vulnerabilities

  44. 22

    [VULN] - Oracle Patch-Batch - CVE-2025-21535

    Oracle Releases January 2025 Patch to Address 318 Flaws Across Major Products

  45. 21

    [VULN] - Critical Sentry Account Takeover - CVE-2025-22146

    A recently patched vulnerability Sentry could have allowed attackers to take over accounts

  46. 20

    [VULN] - Mongoose Search Injection Flaw - CVE-2025-2306

    Search injection attack has been discovered on the popular MongoDB object modeling tool.

  47. 19

    [WordPress] - WP Safe - 2025.01.20

    Daily Summary of WordPress critical and high vulnerabilities

  48. 18

    [Hot Topic] - TikTok has been banned in the USA

    Short update of latest information about TikTok ban in the USA

  49. 17

    [WordPress] - WP Safe - 2025.01.17

    Daily Summary of WordPress critical and high vulnerabilities

  50. 16

    [WordPress] - WP Safe - 2025.01.16

    Daily Summary of WordPress critical and high vulnerabilities

Type above to search every episode's transcript for a word or phrase. Matches are scoped to this podcast.

Searching…

We're indexing this podcast's transcripts for the first time — this can take a minute or two. We'll show results as soon as they're ready.

No matches for "" in this podcast's transcripts.

Showing of matches

No topics indexed yet for this podcast.

Loading reviews...

ABOUT THIS SHOW

Welcome to VulnVibes, your go-to source for quick, engaging insights into IT security exploits! We break down vulnerabilities, hacks, and defenses into bite-sized videos that anyone can understand. Whether you're a tech enthusiast or a cybersecurity pro, you'll stay ahead of the game with our fast-paced, no-fluff content. Subscribe now to keep your systems secure and your knowledge sharp!

HOSTED BY

VulnVibes

CATEGORIES

Frequently Asked Questions

How many episodes does VulnVibes have?

VulnVibes currently has 50 episodes available on PodParley. New episodes are automatically indexed when they're published to the podcast feed.

What is VulnVibes about?

Welcome to VulnVibes, your go-to source for quick, engaging insights into IT security exploits! We break down vulnerabilities, hacks, and defenses into bite-sized videos that anyone can understand. Whether you're a tech enthusiast or a cybersecurity pro, you'll stay ahead of the game with our...

How often does VulnVibes release new episodes?

VulnVibes has 50 episodes. Check the episode list to see recent publication dates and frequency.

Where can I listen to VulnVibes?

You can listen to VulnVibes on PodParley by clicking any episode. We provide an embedded audio player for direct listening, and you can also subscribe via your preferred podcast app using the RSS feed.

Who hosts VulnVibes?

VulnVibes is created and hosted by VulnVibes.
URL copied to clipboard!