January 2025
CISA and FBI Release Advisory on How Threat Actors Chained Vulnerabilities in Ivanti Cloud Service Applications
CISA, in partnership with the Federal Bureau of Investigation (FBI), released Threat Actors Chained Vulnerabilities in Ivanti Cloud Service Applications. This advisory was crafted in response to active exploitation of vulnerabilities—CVE-2024-8963, an administrative bypass vulnerability; CVE-2024-9379, a SQL injection vulnerability; and CVE-2024-8190 and CVE-2024-9380, remote code execution vulnerabilities—in Ivanti Cloud Service Appliances (CSA) in September 2024.
CISA, and the use of trusted third-party incident response data, found that threat actors chained the listed vulnerabilities to gain initial access, conduct remote code execution (RCE), obtain credentials, and implant webshells on victim networks.
CISA and FBI strongly encourage network administrators and defenders to upgrade to the latest supported version of Ivanti CSA and to hunt for malicious activity on their networks using the detection methods and indicators of compromise (IOCs) provided in the advisory. All members of the cybersecurity community are also encouraged to visit CISA’s Known Exploited Vulnerabilities Catalog to help better manage vulnerabilities and keep pace with threat activity. For more information and guidance on protection against the most common and impactful threats, tactics, techniques, and procedures, visit CISA’s Cross-Sector Cybersecurity Performance Goals.
2025 NFL mock draft roundup: Mel Kiper Jr. makes first Patriots prediction
ESPN’s Mel Kiper Jr. has finally unveiled his first 2025 NFL Mock Draft, and his pick for the Patriots at No. 4 is interesting.
5 Ugly Abraham Lincoln Facts No One Likes to Talk About
Microsoft relaxes data center grip on OpenAI amid $500 billion joint venture
MLB free agency: Blue Jays reportedly signing Anthony Santander; Dodgers adding Roki Sasaki, Tanner Scott
Stay up to date with the latest from the baseball hot stove.
OF Anthony Santander signs 5-year, $92.5 million deal with Blue Jays: Report
Santander put up career numbers as a pending free agent in 2024, slugging 44 home runs with Baltimore.
With signing of Anthony Santander, the Blue Jays did what they needed to do
After missing out on other top free agents, Toronto gets an injection of power in the lineup with the switch-hitting slugger.
MLB free agency 2024-25: Top 50 players available this winter, starting with Juan Soto and Roki Sasaki
This offseason’s free-agent class is headlined by a generational hitter and full of fascinating players at a variety of positions.
Jeff Torborg, 1990 AL Manager of the Year and 10-year MLB catcher, dies at 83
As a player, Torborg caught a Sandy Koufax perfect game and Nolan Ryan no-hitter. He managed five MLB clubs over 11 seasons.