US-based IT security solutions provider Ivanti has disclosed two major vulnerabilities which have been exploited in attacks on customers’ Connect Secure appliances. The flaws allowed attackers to execute remote code, deploy malware and steal sensitive data. Ivanti have released patches for the vulnerabilities and urged customers to update immediately. The company also encouraged users to maintain strong security practices.

The NCSC wants developers to get serious on software security
The NCSC’s new Software Security Code of Practice has been praised by cyber professionals as a significant advancement in enhancing software supply chain security.