๐จ [CRITICAL INFRASTRUCTURE ALERT]: CVE-2025-8088
โข CVE ID: CVE-2025-8088
โข CVSS Score: 8.8 (High)
โข Affected: Gamaredon WinRAR Deliver
What it is:
Visibility beats Perfection
https://www.facebook.com/securitycyber
https://www.linkedin.com/in/charlie-collins-cc-757345381
https://securitycyber.uk/contact
Student-Founded SOC-Focused Ethically Operated. Cyber Defence Built Honestly. Automated cybersecurity intelligence feed. https://securitycyber.uk
๐จ [CRITICAL INFRASTRUCTURE ALERT]: CVE-2025-8088
โข CVE ID: CVE-2025-8088
โข CVSS Score: 8.8 (High)
โข Affected: Gamaredon WinRAR Deliver
What it is:
๐จ [CRITICAL INFRASTRUCTURE ALERT]: CVE-2026-3300
โข CVE ID: CVE-2026-3300
โข CVSS Score: 9.8 (Critical)
โข Affected: Everest Forms Pro
What it is:
๐จ CVE-2026-45247 ๐จ
Description
Mirasvit Full Page Cache Warmer for Magento 2 before version 1.11.12 contains a PHP object injection vulnerability that allows unauthenticated attackers to achieve remote code execution by supplying a crafted serialized PHP object in the CacheWarmer cookie. Attackers can exploit the unrestricted call to PHP's native unserialize() function combined with gadget chains available in Magento and its dependencies to execute arbitrary code on the server.
๐จ CRITICAL ALERT
WhatsApp, Slack Notifications Could Hijack Google Gemini on Android
โข WhatsApp, Slack Notifications Could Hijack Google Gemini on Android
โข A single poisoned notification from WhatsApp, Slack, SMS, Signal, Instagram, or Messenger could have hijacked Google Gemini's voice assistant on Android and made it open a victim's connected ...
Resources: https://securitycyber.uk | https://www.hackthebox.com
CISA Adds Exploited Magento RCE Flaw CVE-2026-45247 to KEV Catalog
**Critical Alert:** A severe vulnerability (CVE-2026-45247) has been identified and requires immediate attention from security teams worldwide.
## The Details
Resources: https://securitycyber.uk | https://www.hackthebox.com