Ivanti patches actively exploited zero-day.
Recent reports indicate that a zero-day vulnerability is actively being exploited in GFI KerioControl firewalls, posing significant risks for developers and IT professionals managing network security. This vulnerability allows attackers…
China’s UNC5337 Exploits a Critical Ivanti RCE Bug, Again
As we move into another year, the persistence of certain vulnerabilities reminds developers of the ongoing security challenges presented by third-party dependencies, particularly with Ivanti products. The recent exploitation of…
Critical Mitel, Oracle flaws find active exploitation, CISA urges patching
The Cybersecurity and Infrastructure Security Agency (CISA) has reported critical vulnerabilities in Mitel and Oracle products that are currently under active exploitation. Both sets of flaws have now been added…
Ivanti Warns of New Zero-Day Attacks Hitting Connect Secure Product
With the rise of cyber threats, developers must maintain vigilance in their security practices. Ivanti has recently reported that its Connect Secure product line is vulnerable to a new zero-day…
A Signature Verification Bypass in Nuclei (CVE-2024-43405)
A Signature Verification Bypass in Nuclei (CVE-2024-43405) In a recent discovery by Wiz’s engineering team, a significant vulnerability has been identified in Nuclei, a popular tool used for identifying security…
High-Severity Vulnerability Discovered In Nuclei: What You Need To Know
High-Severity Vulnerability Discovered in Nuclei: What Developers Should Know A recent finding by Wiz has uncovered a high-severity vulnerability within Nuclei, a widely used tool for security scanning and vulnerability…
SysBumps – New Kernel Break Attack Bypassing macOS Systems Security
Recent findings from security researchers reveal SysBumps, a sophisticated attack vector targeting macOS systems equipped with Apple Silicon processors. This method exploits speculative execution vulnerabilities associated with system calls, effectively…
Sophos Firewall Vulnerabilities Could Allow Remote Attacks
Developers and IT security professionals utilizing Sophos firewall solutions should prioritize updating their devices following the recent announcement regarding critical security vulnerabilities. According to the vendor, these flaws can be…
ASUS Routers Vulnerabilities Allows Arbitrary Code Execution
ASUS has issued a critical security advisory, drawing attention to multiple vulnerabilities present in several of its router models, which could allow for arbitrary code execution. For developers, especially those…
Exploit Code Published for Potentially Dangerous Windows LDAP Vulnerability
Exploit Code Published for Potentially Dangerous Windows LDAP Vulnerability The recent release of proof-of-concept (PoC) code for CVE-2024-49113 highlights a growing concern for developers working with Windows environments. This vulnerability…









