Cisco tied an active firewall campaign to a chained set of flaws
Cisco said evidence strongly indicated attackers used CVE-2025-20333 and CVE-2025-20362 in attacks against Secure Firewall ASA and FTD devices. A companio…
The dispatch / historical archive
Original historical analysis alongside the existing sourced news desk. Read what happened, what the evidence establishes, and what a defender can learn.
35 pieces · source dates, never backdated publication
Cisco said evidence strongly indicated attackers used CVE-2025-20333 and CVE-2025-20362 in attacks against Secure Firewall ASA and FTD devices. A companio…
CISA added flaws affecting Adminer, Cisco IOS and IOS XE, Fortra GoAnywhere MFT, Libraesva Email Security Gateway, and Sudo after finding evidence of acti…
F5 described a major incident involving a sophisticated nation-state actor and access to BIG-IP source code and some knowledge-management files. The compa…
The React team disclosed CVE-2025-55182, affecting several React Server DOM packages in versions 19.0, 19.1.0, 19.1.1 and 19.2.0. Patched versions were pu…
The NCSC warned UK organizations about persistent disruptive activity by Russian state-aligned hacktivist groups, building on a December 2025 internationa…
Ivanti issued an update for Endpoint Manager Mobile and said it knew of a very limited number of exploited customer environments. The company separated th…
CERT-EU summarized Cisco advisories for critical and high-severity flaws in Catalyst SD-WAN controllers and SD-WAN Manager. It noted that CVE-2026-20127 h…
CERT-EU reported that Microsoft updated its January advisory for CVE-2026-20963 on 17 March, and CISA added the unauthenticated remote-code-execution flaw…
Microsoft Threat Intelligence said actors were using AI to speed research, improve lures, develop malware, and triage stolen data while humans generally r…
Google Cloud and Mandiant argued that capable models were compressing the vulnerability-discovery and exploitation cycle, while the same techniques could …
CERT-EU relayed Palo Alto Networks’ disclosure of a critical unauthenticated remote-code-execution flaw in PAN-OS and the vendor’s observation of limited …
CERT-EU summarized Ivanti’s 9 June advisory for two critical vulnerabilities in Sentry products that could permit unauthenticated remote code execution.Im…
Google Threat Intelligence Group and Mandiant described multiple large-scale campaigns across 2025 and the first half of 2026, then published defensive gu…
CERT-EU summarized Citrix’s advisory for multiple critical vulnerabilities affecting NetScaler ADC and NetScaler Gateway and recommended prompt updates.Im…
Microsoft documented campaigns that used passkey-themed lures, then registered attacker-controlled authentication methods and moved through cloud workload…
The 2017 filing separated the intrusion window, discovery date and still-provisional impact count.
An ICS-CERT alert connected a global malware event to product notices and defensive coordination.
CISA's December 2020 alert identified affected Orion releases and an active exploitation concern.
The federal directive treated exploitation evidence and server exposure as separate response questions.
A joint CISA–FBI advisory separated affected IT systems from unconfirmed operational-technology intrusion.
The December 2021 joint guidance told operators to find embedded Log4j, not just patch a visible application.
Mandiant's investigation traced a trojanized desktop application back to a prior software compromise.
The 2023 exploitation showed why a fixed server still needs a look back at transferred and stored data.
Microsoft's 2023 account describes unauthorized email access through forged authentication tokens.
The identity provider's November 2023 account distinguished accessed case files from confirmed session hijacks.
Mandiant's 2024 investigation separated cloud-service compromise from compromise of accounts using that service.
The discoverer's March 2024 message is a rare first-hand record of a supply-chain near miss.
The February 2024 revision broadened scope beyond critical infrastructure and elevated supply-chain risk.
CISA's 2023 principles asked suppliers to take ownership of customer security outcomes.
CISA's 2023 guide joined offline backups, integrity tests and an incident-response checklist.
The 2024 joint advisory treated ordinary administrative activity as a detection challenge.
A 2025 first-party research brief described vulnerable open-source workflows and new analysis support.
A 2024 CISA–EPA–FBI release addressed small and large utilities without assuming identical capacity.
The October 2020 release added reconnaissance and resource-development tactics while retiring PRE-ATT&CK.
A March 2024 CMS bulletin documented operational disruption without treating it as a technical root-cause report.
No matches. Clear your search or choose another topic.