This report presents an analysis of current cyber threats and vulnerabilities, focusing on two critical vulnerabilities in Ivanti software that are being exploited through an exploit chain. The vulnerabilities, CVE-2023-46805 and CVE-2024-21887, allow attackers to bypass authentication and execute arbitrary commands, respectively. It advises companies using Ivanti software to prioritize system patching and enhance VPN security measures. The report also discusses the rise of the Akira ransomware group, which employs various tactics to compromise small to medium-sized businesses. It outlines that Multi-Factor Authentication (MFA) is often not implemented adequately, leading to increased vulnerability during attacks. Additionally, it details social engineering tactics used by groups like Scattered Spider, emphasizing the importance of employee training and strict identity controls in safeguarding against such threats. The report concludes with recommendations for mitigating risks associated with these threats, particularly focusing on VPN technologies and employee awareness training.