CISA has added a critical authentication bypass vulnerability (CVE-2025-31161) in CrushFTP (versions 10.0.0-10.8.3 and 11.0.0-11.3.0) to its KEV Catalog. With a CVSS score of 9.8, this flaw allows remote, unauthenticated access, posing high risks. CrushFTP issued patches on March 21, 2025. Organizations are urged to urgently update their installations to mitigate risks.

43% Top 100 Enterprise-Used Mobile Apps Opens Door for Hackers to Access Sensitive Data
A security audit found that 43% of the top 100 mobile apps used in enterprises have critical vulnerabilities, risking sensitive corporate data. Key issues include