Advisories

Authentication Bypass in PAN-OS Management Web Interface (CVE-2025-0108)

On February 12th, Palo Alto Networks released an advisory (CVE-2025-0108) for an authentication bypass vulnerability in Palo Alto Networks PAN-OS software related to the management web interface. The vulnerability could allow for an unauthenticated attacker to run PHP scripts, potentially impacting device integrity.

Feb 19, 2025 - 4 Min Read

Fortinet BreachForums Dump

On January 14th, Beazley Security Labs observed an advertisement posted to the cybercrime community BreachForums, detailing a dump of configuration files and passwords from over 15 thousand Fortinet network appliances.

Jan 17, 2025 - 4 Min Read

Critical Vulnerability in FortiOS and FortiProxy under Active Exploitation (CVE-2024-55591)

On January 14th, Fortinet published an advisory about a critical authentication bypass vulnerability in their FortiOS and FortiProxy software, identified as CVE-2024-55591.

Jan 16, 2025 - 4 Min Read

Critical Vulnerability in Ivanti Connect Secure, Policy Secure, and ZTA Gateway under Active Exploitation (CVE-2025-0282)

On January 8th, software vendor Ivanti published an advisory detailing a critical vulnerability (CVE-2025-0282) in their Connect Secure, Policy Secure, and ZTA Gateway products.

Jan 9, 2025 - 5 Min Read

Critical Vulnerability in Cleo Software (CVE-2024-55956)

On December 10th, software vendor Cleo published an advisory detailing a critical vulnerability in their Harmony, VLTrader, and LexiCom products.

Dec 11, 2024 - 3 Min Read

Critical Vulnerability in Palo Alto PAN-OS (CVE-2024-0012)

On November 18th, Palo Alto Networks published an advisory regarding a critical vulnerability in their PAN-OS software, a core component for their next-generation firewall product line.

Nov 18, 2024 - 3 Min Read

Critical Vulnerability in Cisco ASA (CVE-2024-20329)

On October 24th, 2024, Cisco published an advisory regarding a critical vulnerability in their Adaptive Security Appliance (ASA) Software, a core component of their firewall and VPN appliances. The vulnerability is due to insufficient user input validation and can be abused by a remote authenticated attacker to execute arbitrary commands as the root account.

Oct 30, 2024 - 4 Min Read

FortiJump, Critical Vulnerability in FortiManager API (CVE-2024-47575)

On October 23rd, 2024, Fortinet published an advisory regarding active exploitation of the FortiManager platform, a solution used to centrally manage Fortinet products. The advisory discloses a critical severity vulnerability, nicknamed FortiJump.

Oct 23, 2024 - 4 Min Read

Critical Vulnerability in Palo Alto Expedition (CVE-2024-9464 and CVE-2024-9465)

On October 9th, 2024, cyber security firm Horizon3 published a blog post detailing multiple critical vulnerabilities they discovered in Palo Alto’s Expedition product. Expedition is a utility tool that allows Palo Alto clients to migrate firewall configurations from other vendor products to Palo Alto devices. 

Oct 11, 2024 - 2 Min Read

Critical Vulnerability in CUPS (CVE-2024-47177)

On September 26th, 2024, an independent researcher disclosed a critical vulnerability in CUPS, a printing software package commonly used in Linux systems. CUPS may be enabled by default on some versions of Linux, meaning a server not intended or used as a printer server may still be vulnerable as a result.

Sep 27, 2024 - 2 Min Read