News & Alerts
Stay updated with news, alerts and advisories.
| Title | Category | Date | Description | Tag | CVE | Id |
|---|---|---|---|---|---|---|
| FortiBleed - Analysis of Reported Credential Compromise of FortiGate Devices | Advisory | 22/06/2026 3:01 am | Fortinet is aware of reports of malicious cyber actors targeting Fortinet devices in a credential-harvesting campaign referred to as FortiBleed. Based on our initial analysis, we believe the activity ... | Critical | CVE-2025-59718 & CVE-2025-59719 | 56 |
| ClickFix distributing Vidar Stealer via WordPress | Alert | 13/05/2026 1:41 am | The Fiji CERT with the Australian Signals Directorate’s Australian Cyber Security Centre (ASD's ACSC) has observed ClickFix associated activity leveraging WordPress hosted infrastructure to distribute... | Critical | N/A | 55 |
| Active exploitation of cPanel/WHM critical vulnerability | Alert | 12/05/2026 1:36 am | This alert is relevant to all Fijian organisations that utilise cPanel/ WebHost Manager (WHM). This alert is intended for a technical audience. Fiji CERT is aware of active exploitation in the regi... | Critical | CVE-2026-41940 | 54 |
| Defending Against China-Nexus Covert Networks of Compromised Devices | Alert | 28/04/2026 8:41 pm | All Critical Infrastructure operators, Government agencies, and private sector organisations to strengthen monitoring and defensive measures against covert networks of compromised devices linked to ad... | Critical | N/A | 53 |
| Cisco Firepower and Secure Firewall | Alert | 24/04/2026 3:54 am | This malware can persist as an active threat on Cisco devices running ASA or Firepower Threat Defense (FTD) software, maintaining post-patching persistence and enabling threat actors to re-access comp... | High | CVE-2025-2333 CVE-2025-20362 | 52 |
| Adobe Patches Actively Exploited Acrobat Reader Flaw | Alert | 14/04/2026 8:01 pm | The vulnerability, identified as CVE-2026-34621, has a CVSS severity score of 8.6 out of 10. If successfully exploited, it could enable an attacker to execute malicious code on impacted systems. | Critical | CVE-2026-34621 | 51 |
| Cisco Catalyst SD-WAN Vulnerabilities | Alert | 16/03/2026 8:25 pm | A flaw in Cisco Catalyst SD-WAN Manager’s API authentication could let a remote attacker gain **netadmin-level access** by sending crafted requests, potentially allowing full control of the system. | Critical | CVE-2026-20129 CVE-2026-20133 CVE-2026-20122 | 50 |
| Google Android Out-of-Bounds Write Local Privilege Escalation Vulnerability | Alert | 16/03/2026 1:01 am | There is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed f... | High | CVE-2026-0124 | 49 |
| Apple iOS and iPadOS Use-After-Free Vulnerability | Advisory | 16/03/2026 12:48 am | A use-after-free issue was addressed with improved memory management. This issue is fixed in iOS 17 and iPadOS 17, iOS 15.8.7 and iPadOS 15.8.7. An app may be able to execute arbitrary code with kerne... | High | CVE-2023-41974 | 48 |
| Google Chromium V8 Memory Buffer Restriction Vulnerability | Alert | 16/03/2026 12:00 am | Inappropriate implementation in V8 in Google Chrome prior to 146.0.7680.75 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Hi... | High | CVE-2026-3910 | 47 |
| SQL Server Elevation of Privilege Vulnerability | Alert | 15/03/2026 11:14 pm | An authorized user can exploit improper access control in SQL Server to gain elevated privileges over the network. | High | CVE-2026-21262 | 46 |
| RESURGE Malware Investigation Exposes a Quiet but Actively Operating Threat | Alert | 15/03/2026 10:42 pm | CISA’s updated report on **RESURGE** details a stealthy malware that uses SSH, network evasion, and forged TLS to persist on systems like Ivanti Connect Secure, providing defenders with enhanced detec... | High | CVE-2025-0282 | 45 |