Curated news, CVE analysis, and threat reports from the world's top cybersecurity sources.
Advisory at a Glance Executive Summary CISA began incident response efforts at a U.S. federal civilian executive branch (FCEB) agency following the detection of potential malicious activity identified through security alerts generated by the agency’s endpoint detection and response (EDR) tool.
CISA published lessons learned from a recent incident response engagement to help organizations improve their cybersecurity posture. The report details common gaps in detection and response capabilities observed during real incidents.
Advisory at a Glance Executive Summary CISA began incident response efforts at a U.S. federal civilian executive branch (FCEB) agency following the detection of potential malicious activity identified through security alerts generated by the agency’s endpoint detection and response (EDR) tool. CISA identified three lessons learned from the engagement that illuminate how to effectively mitigate risk, prepare for, and respond to incidents: vulnerabilities were not promptly remediated, the agency did not test or exercise their incident response plan (IRP), and EDR alerts were not continuously reviewed.
CISA obtained two sets of malware from an organization compromised by threat actors exploiting vulnerabilities in Ivanti Endpoint Manager Mobile. The malware contains loaders for malicious listeners that enable arbitrary code execution on the compromised server.
Malware Analysis at a Glance Executive Summary The Cybersecurity and Infrastructure Security Agency (CISA) obtained two sets of malware from an organization compromised by cyber threat actors exploiting CVE-2025-4427 and CVE-2025-4428 in Ivanti Endpoint Manager Mobile (Ivanti EPMM).
CISA obtained malware from organizations compromised via Ivanti EPMM vulnerabilities CVE-2025-4427 and CVE-2025-4428, revealing loaders for malicious listeners enabling arbitrary code execution.