top of page


Droids Gone Wild: Privilege Escalation Edition
CISA reports that two Android Framework vulnerabilities, CVE-2025-48572 and CVE-2025-48633, are being actively exploited in the wild, enabling local privilege escalation without user interaction on Android 13–16 devices and therefore require prioritized remediation as part of vulnerability management programs.
Dec 814 min read


When Your PLC Becomes Everyone’s PLC: ScadaBR’s Unwanted Guest Login
CISA reports that two long-known OpenPLC ScadaBR web vulnerabilities (stored XSS and authenticated arbitrary file upload) are now being actively exploited and must be urgently remediated by federal and other organizations using the software.
Dec 816 min read
bottom of page