• Skip to primary navigation
  • Skip to main content
  • Skip to primary sidebar
Mobile menu toggle
  • Blog on X
  • Blog on Youtube
  • RSS feed X

Decipher Logo Home

  • Articles
  • Video
  • AI
  • General
  • Government
  • Intrusions
  • Law Enforcement
  • Open Source Software Security
  • Podcast
  • Supply Chain
  • Vulnerabilities
  • All Topics
  • Home
  • Articles
  • Video
  • Blog on X
  • Blog on Youtube
  • RSS feed X

All topics


Vulnerabilities


11 Posts

React2Shell, Typhoon Attacks, and Why Our Infrastructure is So Vulnerable

Dennis and Lindsey react (!) to the React2Shell vulnerability disclosure and the quick exploitation of it by Chinese threat actors, then discuss the continues intrusions into critical infrastructure by the Salt Typhoon actors and this week’s congressional hearing on telecom network security. Finally, we talk about some upcoming hacker movie episodes, including Die Hard and maybe Home Alone!

By Dennis Fisher

December 5, 2025 | 1 min read

Podcast

Critical Flaw CVE-2025-55182 Affects React Server Components

All developers using React Server Components are urged to upgrade immediately, and some apps that don’t include React Server Function endpoints could be vulnerable, as well.

By Dennis Fisher

December 3, 2025 | 2 min read

ReactVulnerability

Fortinet CVE-2025-64446 Under Active Attack

That vulnerability (CVE-2025-64446) affects several versions of FortiWeb and CISA  has added it to its Known Exploited Vulnerabilities catalog.

By Dennis Fisher

November 19, 2025 | 2 min read

Fortinet

Lighthouse Phishing Kit Takedown, Zero Day Mysteries, and Measuring Cyber Attack Costs

This week was a bit of a throwback to olden times, with the disclosure by Amazon threat intelligence of  zero days in Cisco and Citrix products that were exploited by an unnamed APT, and Google using legal action to disrupt the Lighthouse phishing service operation. We dig into those two stories, plus we discuss the […]

By Dennis Fisher

November 14, 2025 | 1 min read

Podcast

APT Targets Cisco and Citrix Zero Days

The chain of discovery began with Amazon's security honeypot service, MadPot, which detected exploitation attempts for the Citrix Bleed Two vulnerability (CVE-2025-5777) before its public disclosure

By Dennis Fisher

November 12, 2025 | 2 min read

APTCisco

Microsoft Warns of Exploited Windows Kernel Zero-Day 

The important-severity flaw (CVE-2025-62215) has been exploited, said Microsoft.

By Lindsey O'Donnell-Welch

November 11, 2025 | 2 min read

MicrosoftPatch TuesdayWindows
  • Page 1
  • Page 2
  • »

sidebar

  • Blog on X
  • Blog on Youtube
  • RSS feed X
Home
  • Term & Conditions
  • ©2025 Decipher
  • Articles
  • Video

Powered by
...
►
Necessary cookies enable essential site features like secure log-ins and consent preference adjustments. They do not store personal data.
None
►
Functional cookies support features like content sharing on social media, collecting feedback, and enabling third-party tools.
None
►
Analytical cookies track visitor interactions, providing insights on metrics like visitor count, bounce rate, and traffic sources.
None
►
Advertisement cookies deliver personalized ads based on your previous visits and analyze the effectiveness of ad campaigns.
None
►
Unclassified cookies are cookies that we are in the process of classifying, together with the providers of individual cookies.
None
Powered by