Connect with us

Technology

TeamT5 Warns of Global Risks Posed by Ivanti Vulnerability

Published

on

TAIPEI, April 24, 2025 /PRNewswire/ — Asia Pacific threat intelligence leading brand TeamT5 detected that the China-nexus APT group exploited the critical vulnerability in Ivanti Connect Secure VPN appliances to infiltrate multiple entities around the globe. The victims include nearly 20 different industries across 12 countries. TeamT5 believes that the actor still maintained control over the victim’s network at the time of analysis. We urge enterprises and organizations to take a comprehensive investigation.

Ivanti High-Risk Vulnerability Exposes Systems to Potential Takeover by Attackers

TeamT5’s analysis assessed with high confidence that the actor was exploiting the vulnerabilities of Ivanti Connect Secure VPN appliances to launch attacks around the globe. The actor possibly exploited CVE-2025-0282 or CVE-2025-22457 to conduct initial access.

Both CVE-2025-0282 and CVE-2025-22457 are stack buffer overflow vulnerabilities in Ivanti Connect Secure VPN with a CVSS score of 9.0. Successful exploitation allows the threat actor to achieve remote code execution, leading to intrusion of the internal network and malware implantation.

In the attack, the actor deployed a shared weapon among Chinese threat groups, SPAWNCHIMERA. SPAWNCHIMERA is developed specifically for Ivanti Connect Secure VPN and has all the functionalities of the notorious SPAWN family, including SPAWNANT (installer), SPAWNMOLE (socks5 tunnler), SPAWNSNAIL (SSH backdoor), and SPAWNSLOTH (log wiper).

Moreover, TeamT5’s analysis suggests that other threat actors might also obtain the vulnerability information and start campaigns targeting Ivanti VPN appliances. We have observed massive exploitation attempts against Ivanti VPN appliances since April. Although most exploitation attempts failed, many Ivanti VPN appliances became paralyzed and unstable. 

Widespread Impact Across Countries and Industries Calls for Urgent System Review

TeamT5 points out that the victim countries include Austria, Australia, France, Spain, Japan, South Korea, Netherlands, Singapore, Taiwan, the United Arab Emirates, the United Kingdom, and the United States. The targeted industries include Automotive, Chemical, Conglomerate, Construction, Information Security, Education, Electronics, Financial Institution, Gambling, Government, Intergovernmental Organizations (IGOs), Information Technology, Law Firm, Manufacturing, Materials, Media, Non-Governmental Organizations (NGOs), Research Institute, and Telecommunication.

TeamT5 strongly recommends that affected organizations conduct a thorough incident investigation. Given the versatile TTPs of the actor, such as multi-layers of C2 infrastructure, evasion of monitor mechanism, and the usage of log wiper, without additional technical support, it would be a challenge to detect the actor’s malicious traces inside the network. 

About TeamT5

TeamT5 consists of top cyber threat analysts. Leveraging our geographic and cultural advantages, we have the best understanding of cyber attackers in Asia Pacific. TeamT5 is frequently invited to share insights at top cybersecurity conferences. Our threat intelligence research expertise and solutions are recognized as the 2023-2024 Company of the Year Award in Taiwanese Threat Intelligence by Frost & Sullivan.

Based on our research in malware & Advanced Persistent Threat (APT), we provide cyber threat intelligence reports and anti-ransomware solutions to clients in the USA and Asia Pacific region. Clients include government agencies, financial business, and high tech enterprises.

Website: https://teamt5.org/en/

View original content to download multimedia:https://www.prnewswire.com/apac/news-releases/teamt5-warns-of-global-risks-posed-by-ivanti-vulnerability-302437073.html

SOURCE TeamT5

Continue Reading
Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Technology

DMALL Gains Momentum in Southeast Asia with AI-Driven Retail Platform

Published

on

By

SINGAPORE, May 4, 2026 /PRNewswire/ — As retailers across Southeast Asia face rising operational complexity, shifting consumer expectations and margin pressure, demand is growing for integrated, real-time retail operating systems.

Dmall Inc. (02586.HK) is supporting this shift with a unified retail operating platform that connects core retail functions, improves execution efficiency and enhances visibility across stores, supply chains and customer touchpoints.

As one of China’s largest retail digital solutions providers by revenue and gross merchandise volume, Dmall serves nearly 600 retail clients across 11 countries and regions. Its platform has been shaped by large-scale deployments in complex retail environments, including long-standing work with Wumart Group, Metro, Lawson, 7-Eleven South China and SM Group in Southeast Asia.

Dmall’s recent collaboration with Cold Storage Singapore marks a milestone in supporting retail digital transformation across Southeast Asia. Completed within seven months, the project covered 87 stores across supermarket, hypermarket and express formats, consolidating multiple systems into a single platform across supply chain, merchandising and store operations.

“The transition was completed with minimal disruption to our operations,” said Mr. Lim Boon Chiong, Managing Director of Cold Storage Singapore. “We are seeing early improvements in product availability and replenishment, supported by better visibility across our supply chain and store network.”

The platform has also contributed to more consistent store execution and a more reliable customer experience. The first phase provides a foundation for the next stage of development, including AI-driven capabilities to further support product availability, freshness management and operational efficiency.

Dmall and Cold Storage Singapore plan to extend their cooperation to the fuel and convenience store format in June 2026, reflecting a deepening partnership and a shared commitment to creating greater operational value across retail formats.

“Southeast Asia is one of the world’s most dynamic retail markets, but also one of the most operationally complex,” said Mr. Zhongwei Ren, Partner and Chief Strategy Officer of Dmall. “By combining operational integration with AI-driven capabilities, Dmall aims to help retailers build more adaptive, scalable and efficient operations.”

About Dmall 

Founded in 2015, Dmall (02586.HK) is committed to advancing retail through technology. As one of Asia’s leading providers of digital retail solutions, Dmall delivers integrated, AI-driven innovations that help retailers improve efficiency, optimize decisions and create greater value.

View original content to download multimedia:https://www.prnewswire.com/apac/news-releases/dmall-gains-momentum-in-southeast-asia-with-ai-driven-retail-platform-302761046.html

SOURCE Dmall Inc.

Continue Reading

Technology

Germany’s PDF/UA Mandate Raises the Bar for HTML to PDF C# Workflows

Published

on

By

Enterprise .NET teams generating PDFs at scale face new compliance pressure. Most aren’t ready.

CHICAGO, May 4, 2026 /PRNewswire/ — The German government’s Deutschland Stack has standardized on PDF/UA as the required format for final-form digital documents. For .NET teams building HTML to PDF C# workflows, the mandate forces a question many have deferred: does the library you depend on actually produce compliant output, or just output that looks right?

Iron Software’s IronPDF, a commercial .NET library used in regulated industries across logistics, healthcare, and finance, generates PDF/UA-1 compliant documents directly from HTML in C#. That’s the same conformance level the Deutschland Stack now requires.

“Accessibility compliance has shifted from important to mandatory,” said Cameron Rimington, CEO of Iron Software. “Government rules like this set a floor that enterprise teams are expected to meet, not aspire to. The question is whether their tooling can clear that bar without bolt-on remediation.”

From recommendation to requirement

PDF/UA (ISO 14289) defines what makes a PDF universally accessible: correct tag structure, logical reading order, and metadata that lets assistive technologies parse the document reliably. The standard has existed since 2012, but adoption has been patchy.

Germany’s decision to embed PDF/UA into its national digital stack moves it from best practice to enforceable baseline. Combined with the European Accessibility Act, which extends similar requirements to digital products serving EU markets, the compliance window for document-heavy .NET applications is closing fast.

Most HTML to PDF C# workflows aren’t compliant yet

Despite the regulatory pressure, PDF/UA compliance is still the exception across enterprise .NET. Many teams generating PDFs at volume, particularly those running HTML to PDF C# pipelines, are using libraries that produce visually correct files but miss the structural and metadata requirements accessibility standards actually demand.

As mandates harden, that gap is harder to defer.

“Germany just standardized on PDF/UA. In our experience, most development teams aren’t compliant yet, and they know it,” said Rimington. “That gap is why they’re coming to us.”

What this means for .NET developers

Teams generating PDFs in .NET, for government portals, financial statements, healthcare records, or legal filings, are increasingly being asked to prove their output meets accessibility standards, not just that it renders.

IronPDF gives developers a direct path from HTML to PDF in C# with two methods that cover the common cases:

RenderHtmlAsPdfUa generates PDF/UA-1 compliant documents directly from HTMLSaveAsPdfUa converts existing PDFs to PDF/UA-1

When source HTML is semantic and well-structured, compliant output can be produced in a single call with no remediation step required. For less structured input, additional tagging may be needed to reach full compliance.

The library also supports PDF/A (conformance levels 1 through 3, both b and a) and PDF versions 1.2 through 1.7, covering archival and compliance requirements common in public sector and enterprise deployments.

In production: serving Germany’s regulated industries

The compliance pressure IronPDF is built for is already shaping decisions on the ground. ThreeB IT, a software engineering firm based in Ibbenbüren, has standardized on IronPDF for document generation across logistics and healthcare platforms, including systems serving Kuehne + Nagel and nationwide COVID-19 testing infrastructure.

Operating under strict GDPR and healthcare data rules made the library choice a compliance decision as much as a technical one.

“Because Iron Software doesn’t store any data, GDPR compliance is simple. That’s critical for every project we build,” said Thimo Buchheister, CEO of ThreeB IT.

Deployment speed mattered just as much.

“IronPDF made it possible to build a nationwide COVID testing system in two weeks. The key part was ready within hours,” said Buchheister.

The firm now treats Iron Software libraries as a default in its stack.

“We’ll integrate at least one Iron Software product in every future project. It’s become part of our standard stack,” Buchheister added.

View original content:https://www.prnewswire.com/news-releases/germanys-pdfua-mandate-raises-the-bar-for-html-to-pdf-c-workflows-302761055.html

SOURCE Iron Software

Continue Reading

Technology

Cregis Showcases at Money20/20 Asia 2026, Exploring a New Paradigm for Financial Infrastructure Powered by Stablecoins and On-Chain Payments

Published

on

By

HONG KONG, DUBAI, UAE and SINGAPORE, May 4, 2026 /PRNewswire/ — From April 21 to 23, 2026, at Money20/20 Asia 2026—one of the most influential fintech events in the Asia-Pacific region—Cregis participated as an exhibitor at Booth 6001. The conference brought together industry leaders to discuss key themes such as payment innovation, cross-border settlement, digital assets, and regulatory developments. During the event, Cregis presented its comprehensive digital asset infrastructure solutions tailored for enterprises and financial institutions, while engaging in in-depth conversations with participants from banks, payment providers, fintech companies, and Web3 organizations.

Advancing Payment Infrastructure

Throughout the event, the Cregis team highlighted its end-to-end capabilities in on-chain payments and digital asset management, with a focus on enterprise payment and treasury needs. As stablecoins and blockchain technologies increasingly move into real-world applications, enterprise priorities are shifting from simply supporting crypto assets to enabling efficient, secure, and controllable fund flows.

Cregis offers a unified infrastructure that supports multi-chain and multi-asset management, adaptable to a wide range of use cases including cross-border trade settlement, merchant payments, and corporate treasury operations. By ensuring both security and compliance, the platform enables more efficient global fund movement and greater transparency in settlement processes.

Richard, Co-Founder of Cregis, commented during the event: “Today, the key challenge for enterprises is no longer whether to enter the digital asset space, but how to build a fund management system that balances efficiency, security, and compliance. Through our infrastructure, we aim to help businesses operate more effectively in an increasingly complex global payments landscape.”

A New Cross-Border Payment Paradigm Driven by Stablecoins

Stablecoins and on-chain payments emerged as central topics at this year’s conference. As more financial institutions and payment providers explore the use of digital assets in cross-border settlement, stablecoins are becoming a critical bridge between traditional finance and the crypto economy.

During the event, Cregis engaged with various industry partners to discuss practical applications of stablecoins in cross-border trade, enterprise settlement, and treasury management. Compared to traditional cross-border payment rails, stablecoin-based settlement offers clear advantages in efficiency, cost, and transparency. At the same time, it raises higher requirements for underlying infrastructure, particularly in areas such as secure custody, fund monitoring, and regulatory compliance.

Engaging Industry Leaders: Exploring the Future Evolution of Finance in Asia

Beyond its presence on the exhibition floor, Cregis co-hosted a side event titled The Reserved Table: Redefining Asia’s Future of Settlements alongside WIDTH, StraitsX, and PlatON. The event brought together key players across payments, stablecoins, and cross-border settlement to explore the future trajectory of financial infrastructure in Asia.

At the event, Tannie, Head of Southeast Asia at Cregis, joined a panel discussion themed “A New Standard of Value: Stablecoins, Settlement & the New Money Stack”, where he shared insights from frontline enterprise use cases.

Tannie noted that the market still tends to view stablecoins primarily as a “product”, such as a yield-generating tool or trading instrument. However, in real-world business scenarios, stablecoins are increasingly evolving into foundational infrastructure. For exchanges, payment providers, and cross-border enterprises, the focus is no longer on yield, but on critical operational questions: how to enable real-time global settlement, how to manage liquidity across regions, and how to reduce reliance on traditional banking systems.

Looking ahead, Tannie emphasized that the deeper significance of stablecoins lies in their ability to fundamentally reshape how enterprises manage capital. Within an infrastructure-driven stablecoin framework, businesses can achieve:

Policy-based approval and signing mechanisms for fund movementsReal-time on-chain reconciliation and automated settlementA unified liquidity view across multiple chains and wallets24/7 uninterrupted treasury operations

This shift signals that stablecoins are not merely replacing traditional payment rails—they are driving enterprises to transition from conventional financial workflows toward a more programmable, automated “next-generation operating system for capital.”

From Payment Capabilities to Global Financial Connectivity

As stablecoins, on-chain payments, and enterprise-grade asset management systems continue to mature, a more efficient, transparent, and globally connected financial network is taking shape.

Richard noted: “In the coming years, as the convergence between traditional finance and Web3 accelerates, demand for robust digital asset infrastructure will continue to grow. Cregis aims to be a key enabler in this transition, providing enterprises with secure, scalable, and reliable foundational capabilities.”

Looking ahead, Cregis will continue to enhance its product offerings across custody, payments, and asset management. By focusing on real-world business needs, the company is committed to building a more comprehensive digital asset infrastructure, empowering global enterprises to improve efficiency, manage risks, and achieve sustainable growth in the next generation of financial systems.

View original content to download multimedia:https://www.prnewswire.com/apac/news-releases/cregis-showcases-at-money2020-asia-2026-exploring-a-new-paradigm-for-financial-infrastructure-powered-by-stablecoins-and-on-chain-payments-302761060.html

SOURCE Cregis

Continue Reading

Trending