Curated news, CVE analysis, and threat reports from the world's top cybersecurity sources.
CISA released an advisory about ransomware actors leveraging unpatched SimpleHelp RMM vulnerabilities to compromise a utility billing software provider. The campaign has targeted organizations since January 2025 using SimpleHelp versions 5.5.7 and earlier.
CISA published malware analysis report MAR-25993211-r1.v2 analyzing RESURGE malware targeting Ivanti Connect Secure appliances. The malware enables persistent backdoor access and data exfiltration through compromised VPN gateways.
CISA updated its Malware Analysis Report for RESURGE malware associated with Ivanti Connect Secure, providing deeper technical insight. The analysis shows that RESURGE can remain dormant until a remote actor connects, posing an ongoing threat.
Notification This report is provided "as is" for informational purposes only.
This CISA malware analysis report covers Volt Typhoon, a Chinese state-sponsored threat actor targeting critical infrastructure. The group uses living-off-the-land techniques combined with custom malware for stealthy operations.
This CISA malware analysis report covers Volt Typhoon, a Chinese state-sponsored threat actor targeting critical infrastructure. The group uses living-off-the-land techniques combined with custom malware for stealthy operations.