Ivanti’s Connect Secure VPN is vulnerable to a critical-severity zero-day vulnerability that has been exploited in attacks as ...
The two issues aren't believed to be chained in the attacks. Ivanti said that CVE-2025-0282 is the exploited zero-day, but ...
Put very simply, only use a fully encrypted platform. That means Signal or WhatsApp or iMessage (if strictly between Apple users) or Google Messages (if strictly between Android users). Do’t message ...
Mandiant says a Chinese cyberespionage group has been exploiting the critical-rated vulnerability since at least mid-December.
Palo Alto Networks has released patches for multiple vulnerabilities in the Expedition migration tool, which was retired on ...
Google Cloud’s Mandiant has linked the exploitation of CVE-2025-0282, a new Ivanti VPN zero-day, to Chinese cyberspies.
The US Cybersecurity and Infrastructure Security Agency (CISA) has stated that there is no evidence suggesting other federal ...
Ivanti's CVE-2025-0282 flaw, exploited by China-linked actors, enables remote code execution. CISA demands urgent patching by ...
CISA lists critical flaws in Mitel MiCollab (CVE-2024-41713, CVE-2024-55550) and Oracle WebLogic (CVE-2020-2883).
GitLab's Joel Krooswyk explains the four changes in federal cybersecurity that will be driven by greater use of artificial ...
SOS is urging residents to now rely more on election offices “as trusted sources” after Meta announced it will no longer ...
CVEs added to CISA's catalog Cybercriminals are actively exploiting two vulnerabilities in Mitel MiCollab, including a ...