CISA KEV Catalog update Part II – March 2025

CISA KEV Catalog update Part II – March 2025

On March 4, 2025, the Cybersecurity and Infrastructure Security Agency (CISA) expanded its Known Exploited Vulnerabilities (KEV) catalog, including four additional vulnerabilities. These vulnerabilities—affecting key systems such as the Linux…
Silver Fox APT Campaign

Silver Fox APT Campaign

Silver Fox APT is a sophisticated cyberespionage group believed to be based in China. Recently, they have been targeting healthcare organizations by exploiting vulnerabilities in Philips DICOM viewers. This campaign…
CISA KEV Catalog Update Part I – March 2025

CISA KEV Catalog Update Part I – March 2025

On March 3, 2025, the Cybersecurity and Infrastructure Security Agency (CISA) updated its Known Exploited Vulnerabilities (KEV) catalog by adding several new vulnerabilities, including those affecting Hitachi Vantara and other…
CVE-2025-20111 impacts Cisco Nexus

CVE-2025-20111 impacts Cisco Nexus

CVE-2025-20111 is a high-severity vulnerability identified in the health monitoring diagnostics of Cisco Nexus 3000 Series Switches and Cisco Nexus 9000 Series Switches operating in standalone NX-OS mode. This vulnerability…
Yokai Backdoor Campaign targets Thailand

Yokai Backdoor Campaign targets Thailand

Yokai Backdoor is a sophisticated malware campaign that has recently targeted Thai government officials using advanced techniques such as DLL side-loading. This backdoor is notable for its ability to execute…
CVE-2025-23363 impacts Siemens TeamCenter

CVE-2025-23363 impacts Siemens TeamCenter

CVE-2025-23363 is a high-severity vulnerability identified in Siemens Teamcenter, a product lifecycle management (PLM) software suite used by businesses to manage the entire lifecycle of a product. This vulnerability allows…
CVE-2025-20059 impacts Ping Identity

CVE-2025-20059 impacts Ping Identity

CVE-2025-20059 represents a critical security vulnerability known as a Relative Path Traversal flaw, which impacts the Ping Identity PingAM Java Policy Agent. This vulnerability allows for parameter injection, enabling attackers…