CISA added two critical zero-day vulnerabilities, CVE-2025-4427 and CVE-2025-4428, affecting Ivanti Endpoint Manager Mobile (EPMM) to its KEV catalog. These vulnerabilities enable authentication bypass and remote code execution via API requests. Organizations should upgrade to patched versions immediately or implement API filtering to mitigate risks. The vulnerabilities underscore ongoing security concerns for Ivanti products.

M&S cyber incident shows no organisation is immune from targeted attacks, and what matters is how you respond – EdTech Innovation Hub
The M&S cyber incident highlights that no organization is safe from targeted attacks. The key takeaway is the importance of an effective response strategy to