SIEM as a Service
Ivanti 0-day RCE Vulnerability

Ivanti 0-day RCE Vulnerability Exploitation Details Disclosed

A detailed technical analysis has been published regarding CVE-2025-22457, an unauthenticated remote code execution (RCE) vulnerability impacting several Ivanti products. The vulnerability was recently exploited in the wild by a suspected China-nexus threat actor, affecting...

Windows CLFS Zero-Day Vulnerability Actively Exploited by Ransomware Group

A critical zero-day vulnerability in the Windows Common Log File System (CLFS) has been uncovered and is being actively exploited by a ransomware group. The vulnerability Tracked as CVE-2025-29824, this elevation of privilege flaw has...
Android 0-Day Vulnerability

Google Patched Android 0-Day Vulnerability Exploited in the Wild

Google has released its April 2025 Android Security Bulletin, addressing numerous critical vulnerabilities including two zero-day flaws actively exploited in targeted attacks.  This marks the third consecutive month that Google has issued emergency patches for...
Apple Three 0-Day Vulnerabilities

Apple Warns of Three 0-Day Vulnerabilities Actively Exploited in Attacks

Apple has issued an urgent security advisory concerning three critical zero-day vulnerabilities CVE-2025-24200, CVE-2025-24201, and CVE-2025-24085 that have been actively exploited in sophisticated attacks.  These vulnerabilities affect a wide range of Apple devices, including iPhones,...
Mozilla Releases Patch

Mozilla Releases Urgent Patch for Windows Users Following Exploited Chrome 0-Day

Mozilla has released an emergency security update for its Firefox browser on Windows systems to address a critical vulnerability that could allow attackers to escape browser sandboxes and potentially gain control of affected systems.  The...
Windows Zero-day Vulnerability

New Windows 0-Day Vulnerability Let Remote Attackers Steal NTLM Credentials – Unofficial Patch

A critical vulnerability affecting all Windows operating systems from Windows 7 and Server 2008 R2 through the latest Windows 11 v24H2 and Server 2025.  This zero-day flaw enables attackers to capture users' NTLM authentication credentials...
Google Chrome Zero-day Vulnerability

Google Chrome Zero-day Vulnerability Exploited by Hackers in the Wild

Google has released an urgent security update for its Chrome browser after cybersecurity researchers at Kaspersky discovered a zero-day vulnerability being actively exploited by sophisticated threat actors.  The vulnerability, identified as CVE-2025-2783, allowed attackers to...
Paragon Spyware Exploited WhatsApp Zero-day

Paragon Spyware Exploited WhatsApp Zero-day Vulnerability to Attack High-value Targets

Researchers have uncovered extensive evidence linking Israeli firm Paragon Solutions to a sophisticated spyware operation that exploited a zero-day vulnerability in WhatsApp to target journalists and civil society members. Following the investigation, WhatsApp notified approximately...
8-Year Old Windows Shortcut Zero-Day

8-Year Old Windows Shortcut Zero-Day Exploited by 11 State-Sponsored Hacker Groups

A critical Windows vulnerability that has been exploited since 2017 by state-sponsored threat actors has been uncovered recently by researchers. The vulnerability, tracked as ZDI-CAN-25373, allows attackers to execute hidden malicious commands on victims' machines...
Apple WebKit Zero-Day Vulnerability

Apple WebKit Zero-Day Vulnerability Actively Exploit in High Profile Cyber Attacks

Apple has released emergency security updates addressing a critical zero-day vulnerability in its WebKit browser engine, identified as CVE-2025-24201, which has been actively exploited in targeted attacks. The flaw, described as an out-of-bounds write...
SIEM as a Service

Recent Posts

Jenkins Docker Images Vulnerability

Jenkins Docker Images Vulnerability Let Attackers Insert Themselves in Network Path

A critical security flaw in widely used Jenkins Docker images has been discovered, potentially compromising build pipelines across thousands of organizations.  The vulnerability, disclosed in...