A recently disclosed security flaw impacting Apache Tomcat is actively exploited in the wild following the release of a public proof-of-concept just thirty hours after public disclosure. CVE-2025-24813 is the (for a short while) attackers new best friend since authentication is not required to pull off an attack Tomcat is an infrastructure component: its embedded in something else you own and run. As such, it might not be on your radar. After all, you bought and paid for Biggus Software I...| Agilicus
Asymmetric warfare: Big governments attack little governments. Attackers need to be right once, defenders need to be right 24x7x365. Municipalities continue to be a target.| Agilicus
Last weeks hyper-critical NGFW vulnerability is this weeks embedded operational technology challenge due to nested risk and supply chain.| Agilicus
Recently Palo Alto announced a 10.0 CVE in the Global Protect feature of their PAN-OS firewall. "Unauthenticated attacker [can] execute arbitrary code with root privileges on the firewall". Well, that is not good. But, how "not good" is it? It's terrifyingly bad ungood in fact.| Agilicus