Software company Elastic has released security updates for a critical flaw, CVE-2025-25012, in its Kibana data visualization tool. The prototype pollution vulnerability, which allows manipulation of an application’s JavaScript objects, could lead to unauthorized data access or remote code execution. The flaw affects Kibana versions 8.15.0 to 8.17.3 and has been addressed in version 8.17.3. Users are advised to apply patches or disable the Integration Assistant feature for protection.

IXON VPN Vulnerabilities Let Attackers Gain Access to Windows & Linux Systems
A security assessment by Shelltrail revealed three critical vulnerabilities in the IXON VPN client, allowing privilege escalation on Windows and Linux. Identified as CVE-2025-ZZZ-01, CVE-2025-ZZZ-02,