CISA has added a critical authentication bypass vulnerability (CVE-2025-31161) in CrushFTP (versions 10.0.0-10.8.3 and 11.0.0-11.3.0) to its KEV Catalog. With a CVSS score of 9.8, this flaw allows remote, unauthenticated access, posing high risks. CrushFTP issued patches on March 21, 2025. Organizations are urged to urgently update their installations to mitigate risks.

Hackers Actively Exploiting Critical Exchange & SharePoint Server Vulnerabilities
Microsoft has warned that cybercriminals are increasingly exploiting critical vulnerabilities in on-premises Exchange and SharePoint Servers. New techniques like NTLM relay and credential leakage enable