As per sources, X41 D-Sec GmbH is a well-known cybersecurity company recently completed a white-box penetration test on the Mullvad VPN app and found several security issues. These included a critical vulnerability and two high severity vulnerabilities. Despite these findings, the report praised Mullvad VPN for its strong overall security and the company’s commitment to regular security audits. The vulnerabilities were identified during an audit of the Mullvad VPN app, revealing significant risks like issues with signal handlers and the potential for sideloading during installation. A major flaw, CVE-2024-55884 (MLLVD-CR-24-01), had a CVSS score of 9.0 and was caused by insufficient stack sizes for signal handlers. This could lead to memory corruption if exploited in the right situation, though it would require advanced skills. The problem occurred due to a collision between the alternate stack and the heap of other processes running concurrently, creating a chance for exploitation. Mullvad VPN has acted quickly to fix the vulnerabilities and is undergoing a follow-up audit to verify that the issues are properly addressed. X41 D-Sec GmbH recommends that Mullvad continue to conduct regular security reviews and work to mitigate these vulnerabilities further, strengthening the overall system security. This proactive approach will improve the app's defense against future threats.
Microsoft has released its September 2025 Patch Tuesday security updates, addressing 81 vulnerabilities, including two publicly disclosed zero-day flaws (CVE-2025-55234 and CVE-202...
Rockwell Automation has issued a critical advisory for a vulnerability tracked as CVE-2025-7350, affecting its Stratix industrial Ethernet switches. The flaw, rated 9.6 CVSS 3.1 sc...
In June 2025, Chess.com suffered a data breach when attackers exploited a third-party file transfer tool used by the platform. The intrusion took place between June 5 and June 18, ...