JSTGTECH
← All posts

Tagged “cve”

3 posts

CVE-2025-0282: the Ivanti VPN zero-day, and its sequel

A stack-based buffer overflow in Ivanti Connect Secure let Chinese state hackers run a malware ecosystem on VPN gateways for weeks before anyone noticed.

securityvpnnetworkingcve

Java deserialization after Log4Shell: CVE-2023-46604

Apache ActiveMQ's unauthenticated RCE shows Java deserialization bugs never went away after Log4Shell — only the exploitation playbook got faster.

securityjavacveappsec

MOVEit and the MFT zero-day exploitation playbook

CVE-2023-34362 turned one SQL injection in MOVEit Transfer into 2,700+ breached organizations — and the same pattern keeps repeating against MFT software.

securitycveransomwareappsec