Ivanti EPMM Zero-Day RCE Exploited, Federal Agencies Urged to Patch
Patch Ivanti Endpoint Manager Mobile to version 12.6.1.1 or later to fix CVE‑2026‑6973.
Get 5 things to act on each day — instead of 1,500 articles to read. Free, Builder, or Pro.
Patch Ivanti Endpoint Manager Mobile to version 12.6.1.1 or later to fix CVE‑2026‑6973.
Patch WordPress themes, plugins, and remove unused components; restrict PowerShell execution and enable application allow‑listing to stop ClickFix attacks.
Patch the kernel to the latest LTS (6.18) and deploy the bpf‑lsm mitigation immediately.
Patch: Delete any NOVupdate.exe, NOVupdate.exe.dat, and avk.dll from Startup, block license.claude‑pro.com, and run a full AV scan to remove the Beagle backdoor.
Patch Microsoft Teams to block malicious links, enable MFA, and monitor Teams traffic for phishing.
Patch your Python environments by uninstalling the three malicious packages and monitor for ZiChatBot activity.
Patch vm2 to the latest release (v3.0.9) immediately
Patch ADT's exposed endpoints and enforce MFA on admin accounts.
Block the malicious Google Ads result for the 'managewp' query and verify that your ManageWP login redirects to the official domain, preventing credential theft.
Patch all installations of DAEMON Tools Lite 12.5.1 by uninstalling, scanning, and installing 12.6.0.2445 from the official site.
Patch or secure Android Debug Bridge on all devices to prevent enlistment in the xlabs_v1 Mirai‑derived botnet.
Patch vm2 to 3.10.5 or later immediately to prevent arbitrary host code execution.
Patch Slider Revolution to 7.0.11 immediately to mitigate CVE-2026-6692 and prevent authenticated RCE.
Configure your DNS resolver to treat .de as an insecure zone using an override rule to bypass DNSSEC validation during the outage.
Upgrade CNC to 7.2 or later and NSO to 6.5 or later to patch CVE‑2026‑20188 and eliminate the DoS risk.
Patch WP Engine firewall rules to whitelist current AI crawler UAs (ClaudeBot, GPTBot, Amazonbot) and remove outdated blocklist entries.
Check your firewall configuration and restrict or disable the User‑ID Authentication Portal until a patch is released.
Patch or remove the Pheno plugin immediately and monitor for CloudZ RAT activity.
Enable IOMMU in BIOS and apply NVIDIA firmware patches to mitigate rowhammer vulnerabilities.
Patch the theori‑io plugin immediately by applying the latest release or the provided patch to enforce authentication on notification settings.
Patch PAN‑OS to the latest version that fixes CVE‑2026‑0300 immediately.
Patch: Verify installer signatures and update to the latest DAEMON Tools version to mitigate the supply chain attack.
Patch: Immediately audit all development machines for LD_PRELOAD usage, remove unauthorized PAM modules, and apply security patches to kernel and userland libraries.
Remove the trojanized DAEMON Tools installers and run a full malware scan to eliminate the embedded backdoor.
Patch Breeze Cache to 2.4.5 immediately to eliminate the arbitrary file upload flaw.
Patch: restrict any public API endpoints that allow destructive actions, enforce RBAC, add audit logging, and run security scans.
Disable end‑to‑end encryption for Instagram DMs by May 8, 2026; update any integrations that rely on encrypted messages.
Patch Apache HTTP Server to the latest security release (2.5.70) immediately and verify HTTP/2 handling.
Patch your TETRA parameter rotation policy to enforce quarterly changes and audit verification layers.
Patch kernel to 6.19.12 or later to mitigate CVE-2026-31431.
We use cookies so the comment feature on this site works. Read more