📰 Security news & threat intelligence — updated by our SOC ISO 27001 · SOC 2 aligned · soc@novasecops.com
Nova Security Operations
Threat intelligence

Security news & attacks

Landmark network, server and infrastructure attacks from across the years — and what they teach us. Curated by the Nova Security Operations SOC.

High 🧭 Advisory
Advisory ·

Threat outlook: AI-driven phishing and deepfake fraud accelerate

Security teams report a sharp rise in convincing AI-generated phishing, voice-cloning and deepfake fraud, pushing organisations toward phishing-resistant MFA and stronger identity verification.

Source: Nova SOC threat outlook
High 🧭 Advisory
Advisory ·

Threat outlook: edge and VPN appliances stay the top target

Internet-facing VPNs, firewalls and file-transfer appliances remain the most exploited initial-access point, underscoring the need for rapid patching and exposure monitoring.

Source: Nova SOC threat outlook
Medium 🧭 Advisory
Advisory ·

Threat outlook: ransomware shifts to data-extortion-only

More ransomware crews skip encryption and rely purely on data theft and extortion, raising the importance of egress monitoring, backups and least-privilege access.

Source: Nova SOC threat outlook
High 🐛 Vulnerability
Vulnerability ·

High-severity edge-device and OpenSSH flaws keep teams patching

A steady stream of critical flaws in remote-access and edge devices kept defenders patching through 2025 as attackers raced to weaponise each new disclosure.

Source: Vendor advisories
High 🦠 Ransomware
Ransomware ·

Ransomware intensifies against healthcare and manufacturing

Ransomware groups stepped up attacks on hospitals, manufacturers and logistics firms, with data-extortion tactics causing widespread operational disruption.

Source: Incident responders
High 🐛 Vulnerability
Vulnerability ·

SonicWall secure-access zero-day exploited in the wild

Attackers exploited a flaw in SonicWall secure-access appliances to breach networks, prompting urgent patching guidance.

Source: Vendor advisory
Medium 🗄️ Data Breach
Data Breach ·

Exposed AI-service database leaks chat logs and secrets

A misconfigured, internet-exposed database at an AI service left chat histories and internal secrets publicly accessible until it was secured.

Source: Security researchers
Critical 🐛 Vulnerability
Vulnerability ·

Fortinet firewall auth-bypass exploited to hijack devices (CVE-2024-55591)

A critical authentication-bypass flaw in FortiOS and FortiProxy was exploited to take over internet-facing firewalls and create rogue administrator accounts.

Source: Vendor advisory
Critical 🔗 Supply Chain
Supply Chain ·

Cl0p exploits Cleo managed-file-transfer zero-days

The Cl0p extortion group exploited zero-days in Cleo file-transfer software to steal data from many organisations, echoing earlier mass file-transfer campaigns.

Source: Threat intel vendors
Critical 🐛 Vulnerability
Vulnerability ·

New Ivanti Connect Secure zero-day exploited (CVE-2025-0282)

A fresh zero-day in Ivanti Connect Secure VPN appliances was exploited in the wild, continuing a run of edge-device attacks.

Source: Government advisories
High 🗄️ Data Breach
Data Breach ·

Education platform breach exposes student and staff data

A widely used education software platform disclosed a breach exposing the personal data of students and teachers across many school districts.

Source: Operator disclosure
High 🌊 DDoS
DDoS ·

Record-breaking DDoS attacks absorbed by providers

Network and cloud providers reported mitigating some of the largest volumetric distributed-denial-of-service attacks ever measured, driven by large botnets and protocol abuse.

Source: Cloud providers
Critical 🛰️ Nation-State
Nation-State ·

Salt Typhoon found deep inside telecom networks

State-linked actors were discovered embedded in several major telecom networks, reportedly reaching call-records and lawful-intercept systems.

Source: Government advisories
Critical 🐛 Vulnerability
Vulnerability ·

FortiManager FortiJump zero-day exploited (CVE-2024-47575)

A zero-day in Fortinet FortiManager was abused to reach managed firewalls and steal device configurations and credentials.

Source: Vendor advisory
Medium 🗄️ Data Breach
Data Breach ·

Internet Archive hit by breach and DDoS

A major digital library disclosed a breach exposing tens of millions of user records, alongside disruptive denial-of-service attacks.

Source: Operator disclosure
High 🐛 Vulnerability
Vulnerability ·

CUPS Linux printing flaws enable remote code execution

A chain of flaws in the CUPS printing system could allow remote code execution on many Linux machines and be abused to amplify DDoS attacks.

Source: Security researchers
High 🐛 Vulnerability
Vulnerability ·

Veeam Backup RCE leveraged by ransomware (CVE-2024-40711)

A critical flaw in Veeam Backup and Replication was used by ransomware groups to gain remote code execution on backup servers.

Source: Vendor advisory
High 🗄️ Data Breach
Data Breach ·

Massive data-broker leak exposes Social Security numbers

A background-check data broker leaked an enormous trove of personal records, including a large number of Social Security numbers.

Source: Public disclosure
Critical ⚠️ Outage
Outage ·

Faulty security update triggers a global IT outage

A defective security-sensor update crashed millions of Windows machines worldwide, grounding flights and disrupting hospitals, banks and broadcasters in one of the largest IT outages ever.

Source: Vendor disclosure
High 🗄️ Data Breach
Data Breach ·

Telecom call and text metadata stolen from cloud platform

A major telecom disclosed that months of call and text metadata for nearly all of its customers had been stolen from a third-party cloud data platform.

Source: Company disclosure
High 🐛 Vulnerability
Vulnerability ·

regreSSHion: critical OpenSSH RCE found (CVE-2024-6387)

A newly discovered remote-code-execution flaw in OpenSSH put a large number of internet-facing Linux servers at risk.

Source: Security researchers
Medium 🛰️ Nation-State
Nation-State ·

Remote-access vendor reports state-linked intrusion

A remote-access software vendor disclosed a state-linked intrusion into its internal corporate IT environment.

Source: Company disclosure
High 🔗 Supply Chain
Supply Chain ·

Polyfill.io CDN hijacked to serve malware

A widely embedded JavaScript service was repurposed after a change of ownership to deliver malicious code to hundreds of thousands of websites.

Source: Security researchers
High 🗄️ Data Breach
Data Breach ·

Cloud data-warehouse accounts plundered via stolen logins

Attackers used stolen credentials on accounts lacking multi-factor authentication to exfiltrate large datasets from many organisations cloud data warehouses.

Source: Incident responders
Medium 🗄️ Data Breach
Data Breach ·

Hardware vendor portal scraped for millions of records

A major hardware vendor disclosed that an online portal had been scraped for tens of millions of customer records.

Source: Company disclosure
Medium 🌐 Network Attack
Network Attack ·

Global brute-force wave targets VPN and SSH gateways

A large-scale credential brute-forcing campaign hammered VPN and SSH services on Cisco, Fortinet and other edge devices worldwide.

Source: Vendor advisories
Critical 🐛 Vulnerability
Vulnerability ·

Palo Alto firewall GlobalProtect zero-day exploited (CVE-2024-3400)

A command-injection zero-day in Palo Alto firewalls was exploited in the wild before a patch was available.

Source: Vendor advisory
Critical 🔗 Supply Chain
Supply Chain ·

XZ Utils backdoor caught before mass impact (CVE-2024-3094)

A maintainer-planted backdoor in the widely used XZ Utils compression library was spotted just days before reaching mainstream Linux distributions, narrowly averting a massive supply-chain compromise.

Source: Open-source community
Critical 🦠 Ransomware
Ransomware ·

Healthcare payments processor crippled by ransomware

A ransomware attack on a major US healthcare payments processor disrupted insurance claims and prescriptions across the country for weeks.

Source: Operator disclosure
Critical 🐛 Vulnerability
Vulnerability ·

ScreenConnect auth-bypass weaponised within days (CVE-2024-1709)

A trivially exploitable authentication-bypass flaw in ConnectWise ScreenConnect remote-access software was rapidly abused to deploy ransomware.

Source: Vendor advisory
High 🛰️ Nation-State
Nation-State ·

Warning: state actors pre-positioned in critical infrastructure

Authorities warned that a state-sponsored group had quietly embedded itself in critical-infrastructure networks, apparently preparing for potential future disruption.

Source: Government advisories
Critical 🐛 Vulnerability
Vulnerability ·

Ivanti VPN zero-days mass-exploited (CVE-2024-21887)

Chained zero-days in Ivanti Connect Secure VPN appliances were mass-exploited to breach corporate networks, prompting emergency directives.

Source: Government advisories
High 🛰️ Nation-State
Nation-State ·

Senior staff email accessed in password-spray attack

State-linked attackers used password-spraying against a forgotten legacy account to read the email of senior staff at a major software vendor.

Source: Company disclosure