Security News

Ivanti zero-day attacks infected devices with custom malware
2025-01-09 16:11

Hackers exploiting the critical Ivanti Connect Secure zero-day vulnerability disclosed yesterday installed on compromised VPN appliances new malware called 'Dryhook' and 'Phasejam' that is not...

Zero-day exploits plague Ivanti Connect Secure appliances for second year running
2025-01-09 14:45

Factory resets and apply patches is the advice amid fortnight delay for other appliances The cybersecurity industry is urging those in charge of defending their orgs to take mitigation efforts...

Ivanti Connect Secure zero-day exploited since mid-December (CVE-2025-0282)
2025-01-09 12:14

The zero-day attacks leveraging the Ivanti Connect Secure (ICS) vulnerability (CVE-2025-0282) made public on Wednesday were first spotted in mid-December 2024, Mandiant researchers have shared....

Ivanti warns of new Connect Secure flaw used in zero-day attacks
2025-01-08 20:43

Ivanti is warning that a new Connect Secure remote code execution vulnerability tracked as CVE-2025-0282 was exploited in zero-day attacks to install malware on appliances. [...]

Ivanti Connect Secure zero-day exploited by attackers (CVE-2025-0282)
2025-01-08 19:39

Ivanti has fixed two vulnerabilities affecting Ivanti Connect Secure, Policy Secure and ZTA gateways, one of which (CVE-2025-0282) has been exploited as a zero-day by attackers to compromise...

New Mirai botnet targets industrial routers with zero-day exploits
2025-01-07 20:44

A relatively new Mirai-based botnet has been growing in sophistication and is now leveraging zero-day exploits for security flaws in industrial routers and smart home devices. [...]

New Android NoviSpy spyware linked to Qualcomm zero-day bugs
2024-12-16 15:06

The Serbian government exploited Qualcomm zero-days to unlock and infect Android devices with a new spyware named 'NoviSpy,' used to spy on activists, journalists, and protestors. [...]

Cleo patches critical zero-day exploited in data theft attacks
2024-12-12 17:03

Cleo has released security updates for a zero-day flaw in its LexiCom, VLTransfer, and Harmony software, currently exploited in data theft attacks. [...]

Cleo patches zero-day exploited by ransomware gang
2024-12-12 16:19

Cleo has released a security patch to address the critical vulnerability that started getting exploited while still a zero-day to breach internet-facing Cleo Harmony, VLTrader, and LexiCom...

U.S. Charges Chinese Hacker for Exploiting Zero-Day in 81,000 Sophos Firewalls
2024-12-11 06:29

The U.S. government on Tuesday unsealed charges against a Chinese national for allegedly breaking into thousands of Sophos firewall devices globally in 2020. Guan Tianfeng (aka gbigmao and...