Ivanti has released three security advisories in the February Security Update, which addresses vulnerabilities in Ivanti products. In the first advisory, two vulnerabilities were identified in Ivanti Cloud Services Application (CSA).
The Ivanti CSA is an Internet appliance that provides secure communication and functionality over the Internet. It falls under the primary product of Ivanti Endpoint Manager, but security fixes are maintained separately. CVE-2024-47908 is a critical OS command injection vulnerability with a CVSSv3 9.1. Successful exploitation of CVE-2024-47908 could allow a remote authenticated attacker to achieve remote code execution (RCE).
Read more…
Source: NHS Digital
Related:
- Medical records giant Epic pauses product development to fix security bugs that risk patients’ data
October 2, 2026
Epic, the software technology giant that makes the widely used MyChart software for accessing patients’ medical data, has paused most of its product development as the company works to protect its software and systems from cyberattacks. Judy Faulkner, the founder and chief executive of Epic, told Modern Healthcare last month that the pause would likely last ...
- Fortinet sounds the alarm over actively exploited FortiMail zero-day
October 2, 2026
Fortinet is warning customers to lock down FortiMail after attackers started exploiting a critical bug that lets them write files to vulnerable systems without logging in. The flaw, tracked as CVE-2026-104286, carries a CVSS score of 9.8 and affects multiple versions of Fortinet’s email security platform. Fortinet describes the vulnerability as a combination of path traversal and ...
- Update your iPhone, iPad, or Mac: Flaw could run attackers’ code
September 29, 2026
Apple has released updates for iPhones, iPads, and Macs to fix a flaw that could let an attacker run code when a device processes a malicious file. Apple says it may have been used in highly targeted attacks against iPhone users running versions of iOS before iOS 27. The fix is in iOS and iPadOS 26.7.1, ...
- Pentagon breach exposed sensitive data on nearly 3 million people
September 29, 2026
A breach of the Pentagon’s sprawling personnel database exposed sensitive information belonging to a massive swath of military personnel, including Social Security numbers and details about the jobs they held, according to a U.S. defense official. The breach affected 2.76 million living people and another 294,000 who are deceased, the official said. The scope and sensitivity ...
- Fake iPhone Duo preorder scam triggers DarkSword attack
September 29, 2026
Apple announced its first foldable iPhone on September 9, and scammers were ready to ‘deliver’ one before anyone could buy it. Most of what MalwareBytes researchers found around the launch of the iPhone Duo and iPhone 18 Pro was familiar fraud. But one fake preorder page was different. Read more… Source: MalwareBytes Labs Sign up for the Cyber Security Review ...
- Recently disclosed Citrix vulnerabilities exploited in the wild
September 28, 2026
Death and taxes are said to be the only certainties in life. Perhaps it’s time to add attackers targeting newly discovered critical flaws in Citrix’s NetScaler application delivery controller and gateway products to that grim list. On Sunday, the company published a bulletin warning of eight CVEs, the worst of which – CVE-2026-88771 and CVE-2026-88772 – ...
