Lazarus Group Deploys Sophisticated Infostealer Malware

Lazarus Group Deploys Sophisticated Infostealer Malware North Korea’s Lazarus Group is targeting software developers and IT experts through an advanced infostealer malware campaign. Utilizing malicious Python scripts, fake job interviews, and social engineering, they steal sensitive data and establish persistent access to systems. The malware incorporates multiple layers of encoding and evasion techniques, ultimately delivering […]

Ivanti Addresses Critical Vulnerabilities Affecting Several Products

Ivanti Addresses Critical Vulnerabilities Affecting Several Products Ivanti has disclosed critical vulnerabilities in its Connect Secure, Policy Secure, Secure Access Client and Cloud Services Application products. These flaws could enable remote code execution, unauthorized data access and system compromise. The most severe issues include stack-based buffer overflows and OS command injection vulnerabilities. Ivanti strongly advises […]

DeepSeek iOS App has Severe Security Flaws

DeepSeek iOS App has Severe Security Flaws   The DeepSeek app has gained popularity among iPhone users since its launch, even reaching the top of the App Store charts in the US. A recent analysis by researchers has revealed multiple critical vulnerabilities in the DeepSeek iOS app, posing significant risks to individuals, businesses and government […]

Microsoft Fixes Critical Vulnerability in Azure Ai Face Service

Microsoft Fixes Critical Vulnerability in Azure Ai Face Service Microsoft has addressed two critical security vulnerabilities: one in Azure AI Face Service (CVE-2025-21415, CVSS 9.9) and another in Microsoft Account (CVE-2025-21396, CVSS 7.5), both of which could enable privilege escalation. The Azure AI Face Service flaw resulted from an authentication bypass, while the Microsoft Account […]

Critical Vulnerability Discovered in SonicWall SMA 1000 Series

Critical Vulnerability Discovered in SonicWall SMA 1000 Series Summary SonicWall has issued a critical security advisory for its SMA1000 appliances, revealing a high-severity pre-authentication remote command execution vulnerability (CVE-2025-23006) with a CVSS score of 9.8. This flaw, caused by the deserialization of untrusted data, affects Appliance Management Console (AMC) and Central Management Console (CMC) products […]

Zero-day Vulnerability Actively Exploited In Fortinet FortiGate Firewalls

Zero-day Vulnerability Actively Exploited In Fortinet FortiGate Firewalls A campaign targeting Vulnerability (CVE-2024-55591, CVSS 9.6) in Fortinet FortiGate firewalls with management interfaces was exposed on the internet. Threat actors gained unauthorized access via the CLI console and made configuration changes, including adding super admin accounts and modifying SSL VPN settings. Although the exact vulnerability remains […]

Critical Ivanti Buffer Overflow Vulnerability Exploited in the Wild

Critical Ivanti Buffer Overflow Vulnerability Exploited in the Wild CVE-2025-0282(CVSS 9.0) is a critical stack-based buffer overflow vulnerability affecting Ivanti Connect Secure, Policy Secure, and Neurons for ZTA gateways. The flaw allows unauthenticated remote code execution, and exploitation has been active since December 2024. The vulnerability impacts Ivanti Connect Secure versions before 22.7R2.5, Policy Secure […]