Vulnerabilities CISA Warns of Old jQuery Vulnerability Linked to Chinese APT CISA has added the JQuery flaw CVE-2020-11023, previously linked to APT1, to its Known Exploited Vulnerabilities (KEV) catalog. Eduard KovacsJanuary 24, 2025
Vulnerabilities SonicWall Learns From Microsoft About Potentially Exploited Zero-Day SonicWall has credited Microsoft for reporting CVE-2025-23006, a critical remote command execution vulnerability possibly exploited in the wild. Eduard KovacsJanuary 23, 2025
Data Breaches Data From 15,000 Fortinet Firewalls Leaked by Hackers Hackers have leaked 15,000 Fortinet firewall configurations, which were apparently obtained as a result of exploitation of CVE-2022–40684. Eduard KovacsJanuary 16, 2025
Vulnerabilities Fortinet Confirms New Zero-Day Exploitation Fortinet patches critical vulnerabilities, including a zero-day that has been exploited in the wild since at least November 2024. Eduard KovacsJanuary 15, 2025
Malware & Threats CISA Warns of Second BeyondTrust Vulnerability Exploited in Attacks Attackers have been exploiting a second vulnerability in BeyondTrust’s remote management solutions, CISA warns. Ionut ArghireJanuary 14, 2025
Vulnerabilities Many Ivanti VPNs Still Unpatched as UK Domain Registry Emerges as Victim of Exploitation Many Ivanti VPNs are still exposed to attacks exploiting a recent vulnerability tracked as CVE-2025-0282 and Nominet has been named as a victim. Eduard KovacsJanuary 14, 2025
Cloud Security Critical Aviatrix Controller Vulnerability Exploited Against Cloud Environments Attackers are exploiting a critical vulnerability in Aviatrix Controller to execute arbitrary code in AWS cloud environments. Ionut ArghireJanuary 14, 2025
Vulnerabilities GFI KerioControl Firewall Vulnerability Exploited in the Wild Threat actors are exploiting a recent GFI KerioControl firewall vulnerability that leads to remote code execution. Ionut ArghireJanuary 9, 2025
Malware & Threats Exploitation of New Ivanti VPN Zero-Day Linked to Chinese Cyberspies Google Cloud’s Mandiant has linked the exploitation of CVE-2025-0282, a new Ivanti VPN zero-day, to Chinese cyberspies. Eduard KovacsJanuary 9, 2025
Vulnerabilities CISA Warns of Mitel MiCollab Vulnerabilities Exploited in Attacks CISA says two recently disclosed path traversal vulnerabilities in the Mitel MiCollab collaboration platform have been exploited in attacks. Ionut ArghireJanuary 8, 2025
Vulnerabilities Palo Alto Networks Patches Firewall Zero-Day Exploited for DoS Attacks Palo Alto Networks has patched CVE-2024-3393, a vulnerability that has been exploited for DoS attacks against the company’s firewalls. Eduard KovacsDecember 30, 2024
ICS/OT Four-Faith Industrial Router Vulnerability Exploited in Attacks Threat actors are exploiting a command injection vulnerability in Four-Faith industrial routers to deploy a reverse shell. Ionut ArghireDecember 30, 2024
Vulnerabilities CISA Urges Immediate Patching of Exploited BeyondTrust Vulnerability CISA is urging federal agencies to patch a recent critical vulnerability in BeyondTrust remote access products in one week. Ionut ArghireDecember 20, 2024
Vulnerabilities BeyondTrust Patches Critical Vulnerability Discovered During Security Incident Probe A critical vulnerability in BeyondTrust Privileged Remote Access and Remote Support could lead to arbitrary command execution. Ionut ArghireDecember 18, 2024
Vulnerabilities Exploitation of Recent Critical Apache Struts 2 Flaw Begins Researchers warn of malicious attacks exploiting a recently patched critical vulnerability in Apache Struts 2 leading to remote code execution (RCE). Ionut ArghireDecember 18, 2024
Vulnerabilities CISA Warns of Exploited Adobe ColdFusion, Windows Vulnerabilities CISA has warned organizations that two vulnerabilities affecting Adobe ColdFusion and Windows have been exploited in the wild. Eduard KovacsDecember 17, 2024
Ransomware CVE Assigned to Cleo Vulnerability as Cl0p Ransomware Group Takes Credit for Exploitation The Cl0p ransomware group has taken credit for exploitation of the Cleo product vulnerability tracked as CVE-2024-55956. Eduard KovacsDecember 16, 2024
Malware & Threats Cleo Patches Exploited Flaw as Security Firms Detail Malware Pushed in Attacks Cleo has released patches for the exploited vulnerability and security firms have detailed the malware delivered in attacks. Eduard KovacsDecember 12, 2024
Vulnerabilities Hunk Companion, WP Query Console Vulnerabilities Chained to Hack WordPress Sites Two vulnerabilities in the Hunk Companion and WP Query Console WordPress plugins allow attackers to backdoor websites. Ionut ArghireDecember 12, 2024
Cybercrime Cleo Vulnerability Exploitation Linked to Termite Ransomware Group Exploitation of a vulnerability affecting Cleo file transfer tools has been linked to the new Termite ransomware group. Eduard KovacsDecember 11, 2024