CISA added two critical zero-day vulnerabilities, CVE-2025-4427 and CVE-2025-4428, affecting Ivanti Endpoint Manager Mobile (EPMM) to its KEV catalog. These vulnerabilities enable authentication bypass and remote code execution via API requests. Organizations should upgrade to patched versions immediately or implement API filtering to mitigate risks. The vulnerabilities underscore ongoing security concerns for Ivanti products.

Malicious VS Code Extensions Attacking Windows Solidity Developers to Steal Login Credentials
A campaign targeting Solidity developers has surfaced, distributing trojanized extensions through Visual Studio Code that exfiltrate sensitive information, including cryptocurrency wallet credentials. Three malicious extensions