Security News

Miscreants 'mass exploited' Fortinet firewalls, 'highly probable' zero-day used
2025-01-14 01:43

Ransomware 'not off the table,' Arctic Wolf threat hunter tells El Reg Miscreants running a "mass exploitation campaign" against Fortinet firewalls, which peaked in December, may be using an...

UK domain registry Nominet breached via Ivanti zero-day
2025-01-13 20:03

The number of internet-facing Ivanti Connect Secure instances vulnerable to attack via CVE-2025-0282 has fallen from 2,048 to 800 in the last four days, the Shadowserver Foundation shared today....

UK domain registry Nominet confirms breach via Ivanti zero-day
2025-01-13 16:50

Nominet, the official .UK domain registry and one of the largest country code registries, has confirmed that its network was breached two weeks ago using an Ivanti VPN zero-day vulnerability. [...]

Nominet probes network intrusion linked to Ivanti zero-day exploit
2025-01-13 10:29

Unauthorized activity detected, but no backdoors found UK domain registrar Nominet is investigating a potential intrusion into its network related to the latest Ivanti zero-day exploits.…

Week in review: Exploited Ivanti Connect Secure zero-day, Patch Tuesday forecast
2025-01-12 09:00

Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Ivanti Connect Secure zero-day exploited by attackers (CVE-2025-0282) Ivanti has fixed two...

Zero-Day Vulnerability in Ivanti VPN
2025-01-09 17:16

It’s being actively exploited.

Ivanti zero-day attacks infected devices with custom malware
2025-01-09 16:11

Hackers exploiting the critical Ivanti Connect Secure zero-day vulnerability disclosed yesterday installed on compromised VPN appliances new malware called 'Dryhook' and 'Phasejam' that is not...

Zero-day exploits plague Ivanti Connect Secure appliances for second year running
2025-01-09 14:45

Factory resets and apply patches is the advice amid fortnight delay for other appliances The cybersecurity industry is urging those in charge of defending their orgs to take mitigation efforts...

Ivanti Connect Secure zero-day exploited since mid-December (CVE-2025-0282)
2025-01-09 12:14

The zero-day attacks leveraging the Ivanti Connect Secure (ICS) vulnerability (CVE-2025-0282) made public on Wednesday were first spotted in mid-December 2024, Mandiant researchers have shared....

Ivanti warns of new Connect Secure flaw used in zero-day attacks
2025-01-08 20:43

Ivanti is warning that a new Connect Secure remote code execution vulnerability tracked as CVE-2025-0282 was exploited in zero-day attacks to install malware on appliances. [...]