A critical security vulnerability (CVE-2025-34028) in Commvault Command Center version 11.38 allows unauthenticated attackers to execute arbitrary code remotely, with a high CVSS score of 9.0. Affected systems should update to version 11.38.20 or 11.38.25, released on April 10, 2025, to mitigate risks. Immediate isolation from external access is recommended if updates cannot be applied.

Threat Actors Using Weaponized SVG Files to Redirect Users to Malicious Websites
In 2025, phishing campaigns have adopted SVG files, which embed malicious JavaScript to redirect users to credential-harvesting sites. These versatile files evade traditional security measures,