Middle Eastern government bodies and ISPs have been targeted with Eagerbee malware, potentially linked to the CoughingDown threat operation. Originally deployed against South Asian organizations via the Microsoft Exchange ProxyLogon bug, Eagerbee steals operating system information and network addresses, and creates a TCP/SSL channel for malicious injections. Experts advise immediate patching of vulnerable Exchange servers.
Ivanti Connect Secure zero-day exploited since mid-December (CVE-2025-0282)
Mandiant researchers have found that zero-day attacks on the Ivanti Connect Secure (ICS) vulnerability were first spotted in mid-December 2024. The attacks seem to originate