Security News

Microsoft fixes actively exploited Windows Hyper-V zero-day flaws
2025-01-14 20:57

Microsoft has marked January 2025 Patch Tuesday with a hefty load of patches: 157 CVE-numbered security issues have been fixed in various products, three of which (in Hyper-V) are being actively...

Microsoft January 2025 Patch Tuesday fixes 8 zero-days, 159 flaws
2025-01-14 19:01

Today is Microsoft's January 2025 Patch Tuesday, which includes security updates for 159 flaws, including eight zero-day vulnerabilities, with three actively exploited in attacks. [...]

Fortinet fixes FortiOS zero-day exploited by attackers for months (CVE-2024-55591)
2025-01-14 17:15

Fortinet has patched an authentication bypass vulnerability (CVE-2024-55591) affecting its FortiOS firewalls and FortiProxy web gateways that has been exploited as a zero-day by attackers to...

Fortinet warns of auth bypass zero-day exploited to hijack firewalls
2025-01-14 15:24

​Attackers are exploiting a new authentication bypass zero-day vulnerability in FortiOS and FortiProxy to hijack Fortinet firewalls and breach enterprise networks. [...]

Fortinet Warns of New Zero-Day Used in Attacks on Firewalls with Exposed Interfaces
2025-01-14 09:13

Threat hunters are calling attention to a new campaign that has targeted Fortinet FortiGate firewall devices with management interfaces exposed on the public internet. "The campaign involved...

Miscreants 'mass exploited' Fortinet firewalls, 'highly probable' zero-day used
2025-01-14 01:43

Ransomware 'not off the table,' Arctic Wolf threat hunter tells El Reg Miscreants running a "mass exploitation campaign" against Fortinet firewalls, which peaked in December, may be using an...

UK domain registry Nominet breached via Ivanti zero-day
2025-01-13 20:03

The number of internet-facing Ivanti Connect Secure instances vulnerable to attack via CVE-2025-0282 has fallen from 2,048 to 800 in the last four days, the Shadowserver Foundation shared today....

UK domain registry Nominet confirms breach via Ivanti zero-day
2025-01-13 16:50

Nominet, the official .UK domain registry and one of the largest country code registries, has confirmed that its network was breached two weeks ago using an Ivanti VPN zero-day vulnerability. [...]

Nominet probes network intrusion linked to Ivanti zero-day exploit
2025-01-13 10:29

Unauthorized activity detected, but no backdoors found UK domain registrar Nominet is investigating a potential intrusion into its network related to the latest Ivanti zero-day exploits.…

Week in review: Exploited Ivanti Connect Secure zero-day, Patch Tuesday forecast
2025-01-12 09:00

Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Ivanti Connect Secure zero-day exploited by attackers (CVE-2025-0282) Ivanti has fixed two...