Featured · 7 min read
CVE-2025-0282 is a critical pre-authentication stack buffer overflow in Ivanti Connect Secure VPN (CVSS 9.0). Exploited by China-nexus nation-state actors since December 2024, deploying SPAWN, DRYHOOK, and PHASEJAM…
Read Full Post →
Cyber Awareness
CVE-2025-21298 is a critical Windows OLE vulnerability with CVSS 9.8. Attackers send a malicious RTF email and viewing…
Cyber Awareness
CVE-2024-4577 is a CVSS 9.8 argument injection in PHP CGI on Windows that bypasses the 12-year-old CVE-2012-1823 patch…
Exploits
CVE-2024-3400 is a command injection zero-day in Palo Alto Networks PAN-OS GlobalProtect with a perfect CVSS 10.0. Exploited…
Cyber Awareness
A signal handler race condition in OpenSSH allows unauthenticated remote code execution as root on millions of Linux…