More Ivanti attacks may be on horizon, say experts who are seeing 9x surge in endpoint scans

Ivanti VPN users should stay alert as IP scanning for the vendor’s Connect Secure and Pulse Secure systems surged by 800 percent last week, according to threat intel biz GreyNoise.
The team at the int …
Read more

Published Date:
Apr 25, 2025 (3 hours, 20 minutes ago)

Vulnerabilities has been mentioned in this article.

CVE-2025-0282

Craft CMS RCE exploit chain used in zero-day attacks to steal data

Two vulnerabilities impacting Craft CMS were chained together in zero-day attacks to breach servers and steal data, with exploitation ongoing, according to CERT Orange Cyberdefense.
The vulnerabilitie …
Read more

Published Date:
Apr 25, 2025 (2 hours, 35 minutes ago)

Vulnerabilities has been mentioned in this article.

CVE-2025-32432

CVE-2024-58136

CVE-2025-23209

Critical Commvault Flaw Allows Full System Takeover – Update NOW

Enterprises using Commvault Innovation Release are urged to patch immediately against CVE-2025-34028. This critical flaw allows attackers to run code remotely and gain full control.
A severe security …
Read more

Published Date:
Apr 25, 2025 (1 hour, 46 minutes ago)

Vulnerabilities has been mentioned in this article.

CVE-2025-34028

CVE-2024-27564

CVE ID : CVE-2025-28128

Published : April 25, 2025, 8:15 p.m. | 2 hours, 46 minutes ago

Description : An issue in Mytel Telecom Online Account System v1.0 allows attackers to bypass the OTP verification process via a crafted request.

Severity: 7.0 | HIGH

Visit the link for more details, such as CVSS details, affected products, timeline, and more…

CVE ID : CVE-2025-32979

Published : April 25, 2025, 9:15 p.m. | 1 hour, 46 minutes ago

Description : NETSCOUT nGeniusONE before 6.4.0 b2350 allows Arbitrary File Creation by authenticated users.

Severity: 0.0 | NA

Visit the link for more details, such as CVSS details, affected products, timeline, and more…

CVE ID : CVE-2025-32980

Published : April 25, 2025, 9:15 p.m. | 1 hour, 46 minutes ago

Description : NETSCOUT nGeniusONE before 6.4.0 b2350 has a Weak Sudo Configuration.

Severity: 0.0 | NA

Visit the link for more details, such as CVSS details, affected products, timeline, and more…

CVE ID : CVE-2025-32982

Published : April 25, 2025, 9:15 p.m. | 1 hour, 46 minutes ago

Description : NETSCOUT nGeniusONE before 6.4.0 b2350 has a Broken Authorization Schema for the report module.

Severity: 0.0 | NA

Visit the link for more details, such as CVSS details, affected products, timeline, and more…

CVE ID : CVE-2025-32981

Published : April 25, 2025, 9:15 p.m. | 1 hour, 46 minutes ago

Description : NETSCOUT nGeniusONE before 6.4.0 b2350 allows local users to leverage Insecure Permissions for the nGeniusCLI File.

Severity: 0.0 | NA

Visit the link for more details, such as CVSS details, affected products, timeline, and more…

CVE ID : CVE-2025-32983

Published : April 25, 2025, 9:15 p.m. | 1 hour, 46 minutes ago

Description : NETSCOUT nGeniusONE before 6.4.0 b2350 allows Technical Information Disclosure via a Stack Trace.

Severity: 7.5 | HIGH

Visit the link for more details, such as CVSS details, affected products, timeline, and more…

CVE ID : CVE-2025-32984

Published : April 25, 2025, 9:15 p.m. | 1 hour, 46 minutes ago

Description : NETSCOUT nGeniusONE before 6.4.0 b2350 allows Stored Cross-Site Scripting (XSS) via a certain POST parameter.

Severity: 6.1 | MEDIUM

Visit the link for more details, such as CVSS details, affected products, timeline, and more…

CVE ID : CVE-2025-32985

Published : April 25, 2025, 9:15 p.m. | 1 hour, 46 minutes ago

Description : NETSCOUT nGeniusONE before 6.4.0 b2350 has Hardcoded Credentials that can be obtained from JAR files.

Severity: 0.0 | NA

Visit the link for more details, such as CVSS details, affected products, timeline, and more…