CrowdStrike announced a critical vulnerability (CVE-2025-1146) in its Falcon Sensor for Linux and related products, due to a TLS connection error that allows man-in-the-middle attacks. Affecting versions before 7.06, it could compromise data integrity and confidentiality. Users are urged to update to fixed versions, and hotfixes are available for older versions. Regular audits and network monitoring are recommended.
![](https://healsecurity.com/wp-content/uploads/2025/01/fbi-issues-guidance-for-enterprises-as-fake-north-korean-it.jpg)
Threat actors are leaning on trusted services more than ever
Researchers have observed that cyber threats are now using legitimate services as part of their attack strategy. This trend highlights the growing complexity and sophistication