GLOBAL THREAT
RECON CENTER

Real-time intelligence reports, CVE advisories, and case studies from our global security research team.

CRITICAL Feb 26, 2025
Zero-Day in Popular Cloud VPN Infrastructure Discovered — Active Exploitation Detected in Wild

NullShield Labs identified a critical unauthenticated remote code execution vulnerability in a widely-deployed enterprise VPN appliance. Exploitation allows full network access bypass. Patch available — immediate action required. Over 14,000 exposed endpoints identified via Shodan.

HIGH Feb 25, 2025
New Phishing Campaign Targeting Fintech C-Suite Executives Uncovered

A sophisticated spear-phishing operation targeting CFOs and CEOs at mid-market fintech firms. Campaign uses lookalike domains with valid SSL certificates and MFA bypass techniques.

MEDIUM Feb 24, 2025
Security Alert: Patch Critical RCE in Edge Routers Immediately

Multiple vendors affected by shared networking library vulnerability. NullShield's sensor network detected active scanning targeting CVE-2025-1847. Patch window is narrow.

CRITICAL Feb 22, 2025
APT-41 Infrastructure Identified — New C2 Cluster Targeting Healthcare

NullShield threat hunters identified new command-and-control infrastructure linked to APT-41. Targeting pattern suggests healthcare sector focus with ransomware pre-positioning.

LOW Feb 20, 2025
Supply Chain Advisory: Malicious npm Packages Targeting Developer Environments

17 malicious packages discovered on npm registry impersonating popular utilities. Packages exfiltrate environment variables and SSH keys on install.

ACTIVE ADVISORIES

CVE IDDescriptionSeverityCVSSStatus
CVE-2025-1847Edge router RCE via crafted HTTP headerCRITICAL9.8PATCH NOW
CVE-2024-3891SSL VPN authentication bypassCRITICAL9.1PATCHED
CVE-2025-0234Privilege escalation in Windows kernelHIGH7.8MITIGATE
CVE-2025-0891Apache Log4j-adjacent deserializationHIGH7.5PATCH NOW
CVE-2024-9912OpenSSH timing oracle information leakMEDIUM5.3PATCHED