Tag: Cyber Security News

Ivanti 0-day RCE Vulnerability Exploitation Details Disclosed

A detailed technical analysis has been published regarding CVE-2025-22457, an unauthenticated remote code execution (RCE) vulnerability impacting several Ivanti products. The vulnerability was recently exploited in the wild by a suspected China-nexus threat actor, affecting Ivanti Connect Secure, Pulse Connect…

Microsoft Issues Urgent Patch to Resolve Office Update Crashes

Microsoft has issued an emergency patch addressing widespread crashes in Office 2016 applications following a problematic update.  The fix, identified as KB5002623 and released on April 10, 2025, resolves critical issues that caused Microsoft Word, Excel, and Outlook to stop…

iOS 18.4 Update Introduces Critical Bug in Dynamic Symbol Resolution

Apple’s latest iOS 18.4 update has introduced a significant bug affecting dynamic symbol resolution on devices supporting Pointer Authentication Code (PAC). This issue, first observed by Fabien Perigaud, a noted reverse-engineering expert, has implications for applications relying on dynamic library…

TP-Link IoT Smart Hub Vulnerability Exposes Wi-Fi Credentials

A critical vulnerability in the TP-Link Tapo H200 V1 IoT Smart Hub that could expose users’ Wi-Fi credentials to attackers.  The flaw, assigned CVE-2025-3442, stems from the device’s firmware storing sensitive information in plain text, making it accessible to attackers…

Russian APT Hackers Using Device Code Phishing Technique to Bypass MFA

A sophisticated cyber campaign orchestrated by the Russian state-backed group Storm-2372 has emerged, exploiting device code phishing tactics to circumvent Multi-Factor Authentication (MFA) security measures. This targeted approach represents a significant escalation in threat actors’ capabilities to defeat advanced security…