FreePBX Unauthenticated SQL Injection Leads to RCE
There's a bug in FreePBX that lets someone walk in without a login, drop a cron job, and get a shell on your server. No username. No password. Just a web r...
Expert analysis, threat intelligence, and practical guidance from Red Secure Tech's security specialists — covering penetration testing, vulnerability assessment, incident response, and secure development for UK businesses.
There's a bug in FreePBX that lets someone walk in without a login, drop a cron job, and get a shell on your server. No username. No password. Just a web request. It's CVE-2025-57819. Jared Brits fou...
Read Full ArticleThere's a bug in FreePBX that lets someone walk in without a login, drop a cron job, and get a shell on your server. No username. No password. Just a web r...
Metabase has a problem. A user with an account and permission to run native queries can execute operating system commands on the server. That's not a typo....
If you run PodcastGenerator on your website, you need to pay attention. Here's the deal. Someone with admin access can type JavaScript into a Live Item. T...
Remember that "major malicious attack" on RubyGems back in May? The one where hundreds of junk packages flooded the registry and forced maintainers to susp...
Anthropic just dropped a 154-page report that should make anyone in security sit up straight. Between December 2025 and August 2026, cybercriminals and sta...
You receive a phone call. The voice on the other end sounds exactly like your grandson. He is scared. He says he is in trouble and needs money fast. You pa...
Your endpoint detection and response tool is running. It is watching for malicious behavior. It is blocking known attacks. You feel protected. Then an att...
Qilin is not just another ransomware group. It is the most operationally active ransomware operation on the planet. And it has figured out how to use artif...
Our blog insights are backed by hands-on service delivery. Whether you need a penetration test, vulnerability assessment, emergency website recovery, or secure web development — our UK cybersecurity specialists are ready to help.
Emergency malware removal, backdoor elimination, blacklist delisting, and full post-incident hardening for compromised websites.
Authorised simulated attacks exposing real vulnerabilities in your web applications, networks, and infrastructure before attackers do.
Systematic identification and prioritisation of security weaknesses across your digital estate — with actionable remediation guidance.
OWASP-aligned web application development with security engineered in from architecture through to penetration-tested deployment.
Advanced adversary simulation testing your organisation's detection and response capabilities against real-world threat actor behaviour.
Actionable intelligence on threat actors, attack vectors, and emerging risks targeting your sector — enabling proactive defensive decisions.
© 2016 – 2026 Red Secure Tech Ltd. Registered in England and Wales — Company No: 15581067