Security Unlocked

Kev

Threat Intelligence

One CISA Catalog Entry, Four Unauthenticated Network-Edge Zero-Days

CISA added four actively exploited, unauthenticated network-edge vulnerabilities from three different vendors to its KEV catalog on the same day, and the clustering says more about where attackers are hunting than any single flaw does.

Threat Intelligence

The Patch-Gap Playbook: A Windows Zero-Day Gets Its Attribution

Volexity's research on UTA0560/BlueMoon turns a Monday footnote into a live espionage campaign, and it shows exactly how much lead time a well-resourced actor gets from the gap between a fix landing in a code repository and that fix reaching a user's machine.