Featured · 7 min read
CVE-2025-0282 is a critical pre-authentication stack buffer overflow in Ivanti Connect Secure VPN (CVSS 9.0). Exploited by China-nexus nation-state actors since December 2024, deploying SPAWN, DRYHOOK, and PHASEJAM…
Read Full Post →
Exploits
CVE-2024-3400 is a command injection zero-day in Palo Alto Networks PAN-OS GlobalProtect with a perfect CVSS 10.0. Exploited…
🔐
CVE-2025-5156
Red Team
CVE-2021-36934 (HiveNightmare) continues powering Hunters International ransomware campaigns in 2025. Full exploitation chain, MITRE mapping, 4 validated Microsoft…