Common Vulnerabilities and Exposures (CVE) stories - Page 3

How AI and software development will continue to shape the developer community in 2025
Tue, 14th Jan 2025
#
llms
#
ai
#
cybersecurity
In 2025, organisations must navigate the complexities of AI integration in software development, balancing innovation with security and skilled developer support.

Mandiant reveals details of major Ivanti VPN vulnerability
Fri, 10th Jan 2025
#
malware
#
firewalls
#
vpns
Mandiant unveils a critical zero-day vulnerability in Ivanti Connect Secure VPN appliances, exploited since December 2024 by a suspected China-linked group.

CVE-2025-0282: Ivanti Connect Secure zero-day exploited in the wild
Thu, 9th Jan 2025
#
firewalls
#
network security
#
advanced persistent threat protection
Ivanti has alerted users that the CVE-2025-0282 zero-day vulnerability in Connect Secure is being actively exploited, with patches now available.

Ivanti issues patch for critical security vulnerability
Thu, 9th Jan 2025
#
advanced persistent threat protection
#
cybersecurity
#
security vulnerabilities
Ivanti has announced critical patches for two vulnerabilities in its Connect Secure and Policy Secure products, one of which is already under active exploitation.

Open source software challenges predicted to continue in 2025
Sun, 5th Jan 2025
#
endpoint protection
#
application security
#
supply chain & logistics
Chris Hughes predicts that open source software adoption will grow in 2025, alongside sophisticated attacks and challenges in governance and security.

CloudSEK report reveals surge in complex cyber threats
Wed, 1st Jan 2025
#
firewalls
#
ransomware
#
mfa
CloudSEK's 2024 Threat Landscape Report reveals a staggering 994TB of data exfiltrated, with ransomware demands averaging over USD $2 million.

2024 cyber threat landscape highlights key attack trends
Tue, 17th Dec 2024
#
malware
#
firewalls
#
ransomware
Rapid7's analysis of the 2024 cyber threat landscape reveals alarming trends in ransomware and vulnerability exploits impacting organisations worldwide.

December Patch Tuesday reveals 70 vulnerabilities
Wed, 11th Dec 2024
#
ransomware
#
iam
#
microsoft
This December, Microsoft addresses 70 vulnerabilities, including 16 critical remote code execution flaws, in its latest Patch Tuesday update.

Nozomi uncovers critical flaws in Advantech networks gear
Thu, 28th Nov 2024
#
firewalls
#
network security
#
iot security
Nozomi Networks has revealed serious vulnerabilities in Advantech's wireless access points, endangering the security of critical infrastructure across sectors.

Ransomware attacks rise by 19% in October according to NCC Group
Mon, 25th Nov 2024
#
ransomware
#
mfa
#
physical security
Ransomware attacks surged 19% in October, totalling 486 incidents globally, as threat actors increasingly targeted critical infrastructure sectors.

Hackuity on cyber security challenges & trends for 2025
Sat, 23rd Nov 2024
#
skills gap
#
job market
#
hackuity
Pierre Samson of Hackuity warns that balancing cyber security compliance costs will pose a major challenge for organisations in 2025.

Critical needrestart vulnerabilities found in Ubuntu Servers
Wed, 20th Nov 2024
#
malware
#
cybersecurity
#
ubuntu
The Qualys Threat Research Unit has identified five critical vulnerabilities in needrestart used by Ubuntu Servers, risking unauthorized root access for users.

Tenable discloses vulnerability in Open Policy Agent OPA
Tue, 19th Nov 2024
#
iam
#
cybersecurity
#
software development
Tenable has disclosed a medium-severity SMB force-authentication vulnerability in all Windows versions of Open Policy Agent before version 0.68.0.

Cybersecurity advisory highlights top vulnerabilities of 2023
Tue, 19th Nov 2024
#
advanced persistent threat protection
#
risk & compliance
#
cybersecurity
Leading cybersecurity agencies have issued an advisory identifying frequently exploited vulnerabilities in 2023, urging enhanced security measures across sectors.

November Patch Tuesday reveals 90 vulnerabilities
Wed, 13th Nov 2024
#
cybersecurity
#
microsoft
#
internet explorer
Microsoft is rolling out patches for 90 vulnerabilities this November, including critical remote code execution flaws and several in-the-wild exploits.

Androxgh0st botnet expands with Mozi IoT capabilities
Wed, 13th Nov 2024
#
datacentre infrastructure
#
iot
#
advanced persistent threat protection
CloudSEK warns that the Androxgh0st botnet has significantly expanded its reach, now targeting critical vulnerabilities in various systems and IoT devices.

Critical vulnerabilities found in Unisoc systems-on-chip
Thu, 31st Oct 2024
#
smartphones
#
risk & compliance
#
cybersecurity
Kaspersky's ICS CERT has revealed critical vulnerabilities in Unisoc SoCs, heightening risks of remote hijacking in devices.

Lazarus APT group targets crypto investors with AI tactics
Wed, 30th Oct 2024
#
blockchain
#
advanced persistent threat protection
#
breach prevention
Kaspersky has uncovered a sophisticated campaign by the Lazarus group targeting cryptocurrency investors, employing social engineering and zero-day exploits.

Tenable reveals vulnerability in Open Policy Agent for Windows
Tue, 29th Oct 2024
#
risk & compliance
#
cybersecurity
#
software development
Tenable has revealed a medium-severity vulnerability in Open Policy Agent for Windows that exposes user credentials, urging updates to version 0.68.0.

Memory safety vulnerabilities continue to plague ICS: Here’s what to do about it
Thu, 24th Oct 2024
#
cybersecurity
#
nsa
#
industrial control systems
Memory safety vulnerabilities are surging in industrial control systems, with over 3,000 reported in 2022, prompting urgent calls for enhanced security measures.