CISA warns of a vulnerability (CVE-2025-21590) in Juniper Networks’ Junos OS, allowing local attackers to execute arbitrary code due to improper kernel isolation. Exploited by the China-linked group UNC3886 via outdated routers, it poses significant risks. Juniper advises upgrading to patched versions and implementing security measures. Organizations should address this by April 3, 2025, to mitigate threats.

The NCSC wants developers to get serious on software security
The NCSC’s new Software Security Code of Practice has been praised by cyber professionals as a significant advancement in enhancing software supply chain security.