Multiple critical cybersecurity vulnerabilities and hardware issues have emerged affecting major technology companies and products. Xiaomi has issued urgent warnings for users to update several popular smartphone models due to a severe battery flaw and a camera malfunction caused by the HyperOS 2.0 update, which renders the camera unusable. Qualcomm has released patches addressing over 30 vulnerabilities in its chips, including three zero-day exploits that have been actively targeted by hackers. These Qualcomm flaws have been added to the U.S. Cybersecurity and Infrastructure Security Agency's (CISA) Known Exploited Vulnerabilities catalog. Google has deployed an emergency update for its Chrome browser to fix a high-severity zero-day vulnerability (CVE-2025-5419) in the V8 JavaScript engine, which is being exploited in the wild to corrupt memory via crafted HTML pages. Users worldwide are urged to update immediately. Additionally, a decade-old critical vulnerability (CVE-2025-49113) in Roundcube Webmail allows authenticated users to execute malicious code and has been exploited by nation-state actors like APT28. Hewlett Packard Enterprise (HPE) has issued a patch for a StoreOnce bug (CVE-2025-37093) that permits authentication bypass and remote code execution as root. Cisco has warned of critical authentication bypass flaws in its Identity Services Engine (ISE) impacting cloud deployments on AWS, Microsoft Azure, and Oracle Cloud Infrastructure, allowing unauthenticated attackers to access configurations and data. Google continues to address bugs in Android 16 QPR1 beta releases, including new features and fixes for Pixel devices. These developments highlight the ongoing challenges in securing widely used software and hardware platforms against sophisticated cyber threats.
گوگل کروم کو استعمال کرنے والے سنگین خطرے سے بچنے کیلئے اسے فوری اپ ڈیٹ کرلیں https://t.co/zbUUu8r5xS
Critical flaw in Cisco ISE impacts cloud deployments on AWS, Microsoft Azure, and Oracle Cloud Infrastructure: https://t.co/6wPP0r4h9v by Security Affairs #infosec #cybersecurity #technology #news
Roundcube ≤ 1.6.10 Post-Auth RCE via PHP Object Deserialization https://t.co/5chFASbIQh