In October 2025, the Cl0p extortion group launched another mass data-theft campaign, this time exploiting a zero-day in Oracle E-Business Suite tracked as CVE-2025-61882. The pattern […]
In late July 2025, active exploitation of on-premises Microsoft SharePoint Server put a large number of organizations into incident-response mode almost overnight. The exploit chain, widely […]
January 2025 opened with another edge-device zero-day. Ivanti disclosed CVE-2025-0282, a critical stack-based buffer overflow in Connect Secure, Policy Secure, and related gateways, that was already […]
In December 2024, attackers began exploiting vulnerabilities in Cleo’s managed file transfer products, and the Clop extortion group claimed responsibility for the resulting data theft. It […]