Our news

  • CISA and US and International Partners Publish Guidance on Priority Considerations in Product Selection for OT Owners and Operators

    Today, CISA—along with U.S. and international partners—released joint guidance Secure by Demand: Priority Considerations for Operational Technology Owners and Operators when Selecting Digital Products. As part of CISA’s Secure by Demand series, this guidance focuses on helping customers identify manufacturers dedicated to continuous improvement and achieving a better cost balance, as well as how Operational Technology…

    READ MORE

  • CISA Releases the Cybersecurity Performance Goals Adoption Report

    Today, CISA released the Cybersecurity Performance Goals Adoption Report to highlight how adoption of Cybersecurity Performance Goals (CPGs) benefits our nation’s critical infrastructure sectors. Originally released in October 2022, CISA’s CPGs are voluntary practices that critical infrastructure owners can take to protect themselves against cyber threats.  This report is based on analysis of 7,791 critical…

    READ MORE

  • Ivanti Releases Security Updates for Connect Secure, Policy Secure, and ZTA Gateways

    Ivanti released security updates to address vulnerabilities (CVE-2025-0282, CVE-2025-0283) in Ivanti Connect Secure, Policy Secure, and ZTA Gateways. A cyber threat actor could exploit CVE-2025-0282 to take control of an affected system. CISA has added CVE-2025-0282 to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. CISA urges organizations to hunt for any malicious…

    READ MORE

  • CISA Adds One Vulnerability to the KEV Catalog

    CISA has added one new vulnerability to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation. CVE-2025-0282 Ivanti Connect Secure Vulnerability These types of vulnerabilities are frequent attack vectors for malicious cyber actors and pose significant risks to the federal enterprise. CISA urges organizations to apply mitigations as set forth in the CISA instructions linked…

    READ MORE

  • Vulnerability Summary for the Week of December 30, 2024

    High Vulnerabilities PrimaryVendor — Product Description Published CVSS Score Source Info 10CentMail–10CentMail  Improper Neutralization of Input During Web Page Generation (‘Cross-site Scripting’) vulnerability in 10CentMail allows Reflected XSS.This issue affects 10CentMail: from n/a through 2.1.50. 2025-01-02 7.1 CVE-2024-56030 2100 Technology Electronic–Official Document Management System  The Electronic Official Document Management System from 2100 Technology has an…

    READ MORE

  • Vulnerability Summary for the Week of December 23, 2024

    High Vulnerabilities PrimaryVendor — Product Description Published CVSS Score Source Info 1000 Projects–Attendance Tracking Management System  A vulnerability was found in 1000 Projects Attendance Tracking Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /admin/course_action.php. The manipulation of the argument course_code leads to sql injection. The…

    READ MORE

  • Vulnerability Summary for the Week of December 16, 2024

    High Vulnerabilities PrimaryVendor — Product Description Published CVSS Score Source Info 1000 Projects–Attendance Tracking Management System  A vulnerability has been found in 1000 Projects Attendance Tracking Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /student/check_student_login.php. The manipulation of the argument student_emailid leads to sql injection.…

    READ MORE

  • Let’s Talk About Spyware and Pegasus Sextortion Scams

    Before we dive into the sextortion scam that has been the spotlight of discussion since September, let’s cover what spyware and its related symptoms are. Spyware is a malicious software that infiltrates user devices without consent and secretly collects information. There are various types of spyware including Adware, Keyloggers, Trojan Horse Viruses, Rootkits and more.…

    READ MORE

  • Fortinet Releases Security Updates for FortiManager

    Fortinet released a security update to address a vulnerability in FortiManager. A remote cyber threat actor could exploit this vulnerability to take control of an affected system. Users and administrators are encouraged to review the following Fortinet Security Bulletin and apply the necessary updates: FG-IR-24-425

    READ MORE

  • CISA Releases Best Practice Guidance for Mobile Communications

    Today, CISA released Mobile Communications Best Practice Guidance. The guidance was crafted in response to identified cyber espionage activity by People’s Republic of China (PRC) government-affiliated threat actors targeting commercial telecommunications infrastructure, specifically addressing “highly targeted” individuals who are in senior government or senior political positions and likely to possess information of interest to these…

    READ MORE