#activeexploitation — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #activeexploitation, aggregated by home.social.
-
CISA has added four vulnerabilities to its KEV catalog with evidence of active exploitation. Affected systems include Microsoft IKE Service Extensions, SharePoint, VMware vCenter, and Apple macOS.
#CISA #ActiveExploitation #VulnerabilityManagement #PatchManagement
https://cyberworldops.eu/en/four-critical-vulnerabilities-exploited-against-macos-sharepoint
-
CISA Warns of Active Exploits Targeting Android, Linux Flaws
A high-severity Android flaw, CVE-2025-48595, is being actively exploited in targeted attacks, allowing hackers to gain increased privileges without needing any user interaction. This critical vulnerability affects Android 14-16 and has prompted CISA to add it to its list of Known Exploited Vulnerabilities.
#AndroidExploits #EmergingThreats #Cve202548595 #LinuxFlaws #ActiveExploitation
-
Marimo Flaw Exploited for Credential Theft in Active Attacks
A critical vulnerability in Marimo is being actively exploited by attackers to steal sensitive credentials, and it requires no prior authentication to run code remotely. This flaw has severe consequences for organizations using Marimo, making it essential to take immediate action.
#Marimo #CredentialTheft #RemoteCodeExecution #Preauthentication #ActiveExploitation
-
Update your #Apple devices ASAP. Two vulnerabilities, CVE-2025-31200 and CVE-2025-31201, have been fixed: https://support.apple.com/en-us/122282
"Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on iOS."
While iOS has been known to be targeted, the fixes are available for all Apple devices and should be installed as soon as possible.
-
Update your #Apple devices ASAP. Two vulnerabilities, CVE-2025-31200 and CVE-2025-31201, have been fixed: https://support.apple.com/en-us/122282
"Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on iOS."
While iOS has been known to be targeted, the fixes are available for all Apple devices and should be installed as soon as possible.
-
Update your #Apple devices ASAP. Two vulnerabilities, CVE-2025-31200 and CVE-2025-31201, have been fixed: https://support.apple.com/en-us/122282
"Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on iOS."
While iOS has been known to be targeted, the fixes are available for all Apple devices and should be installed as soon as possible.
-
Update your #Apple devices ASAP. Two vulnerabilities, CVE-2025-31200 and CVE-2025-31201, have been fixed: https://support.apple.com/en-us/122282
"Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on iOS."
While iOS has been known to be targeted, the fixes are available for all Apple devices and should be installed as soon as possible.
-
Update your #Apple devices ASAP. Two vulnerabilities, CVE-2025-31200 and CVE-2025-31201, have been fixed: https://support.apple.com/en-us/122282
"Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on iOS."
While iOS has been known to be targeted, the fixes are available for all Apple devices and should be installed as soon as possible.
-
Security researchers discover vulnerabilities in #Paragon Partition Manager driver used in #activeexploitation
The actively exploited vulnerability is tracked as CVE-2025-0289, and when exploited, allows an attacker to gain administrative privileges and to execute code. An attacker can potentially download the driver onto a device without Paragon Partition Manager installed.
Users are advised to patch ASAP, and to enable Vulnerable Driver Blocklist
-
Security researchers discover vulnerabilities in #Paragon Partition Manager driver used in #activeexploitation
The actively exploited vulnerability is tracked as CVE-2025-0289, and when exploited, allows an attacker to gain administrative privileges and to execute code. An attacker can potentially download the driver onto a device without Paragon Partition Manager installed.
Users are advised to patch ASAP, and to enable Vulnerable Driver Blocklist
-
Security researchers discover vulnerabilities in #Paragon Partition Manager driver used in #activeexploitation
The actively exploited vulnerability is tracked as CVE-2025-0289, and when exploited, allows an attacker to gain administrative privileges and to execute code. An attacker can potentially download the driver onto a device without Paragon Partition Manager installed.
Users are advised to patch ASAP, and to enable Vulnerable Driver Blocklist
-
Security researchers reveal #activeexploitation against #SimpleHelp RMM vulnerabilities
The vulnerabilities are tracked as CVE-2024-57726, CVE-2024-57727, and CVE-2024-57728, and when exploited, allows an attacker to gain admin privileges
Administrators are advised to patch ASAP
-
Security researchers reveal #activeexploitation against #SimpleHelp RMM vulnerabilities
The vulnerabilities are tracked as CVE-2024-57726, CVE-2024-57727, and CVE-2024-57728, and when exploited, allows an attacker to gain admin privileges
Administrators are advised to patch ASAP
-
Security researchers reveal #activeexploitation against #SimpleHelp RMM vulnerabilities
The vulnerabilities are tracked as CVE-2024-57726, CVE-2024-57727, and CVE-2024-57728, and when exploited, allows an attacker to gain admin privileges
Administrators are advised to patch ASAP
-
pls appreciate i wore an aqua colored sweater to talk about aquabot
🚨Active exploitation attempt🚨
Akamai Security Intelligence and Response Team (SIRT) has identified a new variant of the Mirai-based Aquabot, dubbed Aquabotv3 keeping in line with the naming conventions of the first two.it is using CVE-2024-41710, a command injection vulnerability that affects Mitel SIP models. There was a POC made public in august 2024 but this is the first time it's been seen actively seeking exploitation ITW.
not only that! This malware exhibits a behavior we have never before seen with a Mirai variant: a function (report_kill) to report back to the C2 when a kill signal was caught on the infected device.
We (we = the SIRT) have not seen any response from the C2 as of the date this was originally posted (Jan. 28, 2024).
Incredible work Larry Cashdollar and Kyle Lefton 🎉
Full technical analysis including IOCs:
https://www.akamai.com/blog/security-research/2025-january-new-aquabot-mirai-variant-exploiting-mitel-phones#mirai #malware #activeexploitation #security #research #botnet
-
pls appreciate i wore an aqua colored sweater to talk about aquabot
🚨Active exploitation attempt🚨
Akamai Security Intelligence and Response Team (SIRT) has identified a new variant of the Mirai-based Aquabot, dubbed Aquabotv3 keeping in line with the naming conventions of the first two.it is using CVE-2024-41710, a command injection vulnerability that affects Mitel SIP models. There was a POC made public in august 2024 but this is the first time it's been seen actively seeking exploitation ITW.
not only that! This malware exhibits a behavior we have never before seen with a Mirai variant: a function (report_kill) to report back to the C2 when a kill signal was caught on the infected device.
We (we = the SIRT) have not seen any response from the C2 as of the date this was originally posted (Jan. 28, 2024).
Incredible work Larry Cashdollar and Kyle Lefton 🎉
Full technical analysis including IOCs:
https://www.akamai.com/blog/security-research/2025-january-new-aquabot-mirai-variant-exploiting-mitel-phones#mirai #malware #activeexploitation #security #research #botnet
-
pls appreciate i wore an aqua colored sweater to talk about aquabot
🚨Active exploitation attempt🚨
Akamai Security Intelligence and Response Team (SIRT) has identified a new variant of the Mirai-based Aquabot, dubbed Aquabotv3 keeping in line with the naming conventions of the first two.it is using CVE-2024-41710, a command injection vulnerability that affects Mitel SIP models. There was a POC made public in august 2024 but this is the first time it's been seen actively seeking exploitation ITW.
not only that! This malware exhibits a behavior we have never before seen with a Mirai variant: a function (report_kill) to report back to the C2 when a kill signal was caught on the infected device.
We (we = the SIRT) have not seen any response from the C2 as of the date this was originally posted (Jan. 28, 2024).
Incredible work Larry Cashdollar and Kyle Lefton 🎉
Full technical analysis including IOCs:
https://www.akamai.com/blog/security-research/2025-january-new-aquabot-mirai-variant-exploiting-mitel-phones#mirai #malware #activeexploitation #security #research #botnet
-
pls appreciate i wore an aqua colored sweater to talk about aquabot
🚨Active exploitation attempt🚨
Akamai Security Intelligence and Response Team (SIRT) has identified a new variant of the Mirai-based Aquabot, dubbed Aquabotv3 keeping in line with the naming conventions of the first two.it is using CVE-2024-41710, a command injection vulnerability that affects Mitel SIP models. There was a POC made public in august 2024 but this is the first time it's been seen actively seeking exploitation ITW.
not only that! This malware exhibits a behavior we have never before seen with a Mirai variant: a function (report_kill) to report back to the C2 when a kill signal was caught on the infected device.
We (we = the SIRT) have not seen any response from the C2 as of the date this was originally posted (Jan. 28, 2024).
Incredible work Larry Cashdollar and Kyle Lefton 🎉
Full technical analysis including IOCs:
https://www.akamai.com/blog/security-research/2025-january-new-aquabot-mirai-variant-exploiting-mitel-phones#mirai #malware #activeexploitation #security #research #botnet
-
pls appreciate i wore an aqua colored sweater to talk about aquabot
🚨Active exploitation attempt🚨
Akamai Security Intelligence and Response Team (SIRT) has identified a new variant of the Mirai-based Aquabot, dubbed Aquabotv3 keeping in line with the naming conventions of the first two.it is using CVE-2024-41710, a command injection vulnerability that affects Mitel SIP models. There was a POC made public in august 2024 but this is the first time it's been seen actively seeking exploitation ITW.
not only that! This malware exhibits a behavior we have never before seen with a Mirai variant: a function (report_kill) to report back to the C2 when a kill signal was caught on the infected device.
We (we = the SIRT) have not seen any response from the C2 as of the date this was originally posted (Jan. 28, 2024).
Incredible work Larry Cashdollar and Kyle Lefton 🎉
Full technical analysis including IOCs:
https://www.akamai.com/blog/security-research/2025-january-new-aquabot-mirai-variant-exploiting-mitel-phones#mirai #malware #activeexploitation #security #research #botnet
-
#Ivanti has revealed #activeexploitation against a vulnerability in its appliances
The vulnerability is tracked as CVE-2025-0282, and when exploited, allows an attacker to remotely execute code
Administrators are advised to patch ASAP
-
#Ivanti has revealed #activeexploitation against a vulnerability in its appliances
The vulnerability is tracked as CVE-2025-0282, and when exploited, allows an attacker to remotely execute code
Administrators are advised to patch ASAP
-
#Ivanti has revealed #activeexploitation against a vulnerability in its appliances
The vulnerability is tracked as CVE-2025-0282, and when exploited, allows an attacker to remotely execute code
Administrators are advised to patch ASAP
-
#Ivanti has revealed #activeexploitation against a vulnerability in its appliances
The vulnerability is tracked as CVE-2025-0282, and when exploited, allows an attacker to remotely execute code
Administrators are advised to patch ASAP
-
Security researchers reveal #activeexploitation of a vulnerability in #FourFaith routers
The vulnerability is tracked as CVE-2024-12856, and when exploited, allows an attacker to inject commands
Administrators are advised to reach out to their Four-Faith contacts for mitigation steps
-
Security researchers reveal #activeexploitation of a vulnerability in #FourFaith routers
The vulnerability is tracked as CVE-2024-12856, and when exploited, allows an attacker to inject commands
Administrators are advised to reach out to their Four-Faith contacts for mitigation steps
-
#PaloAlto reveals #activeexploitation against vulnerability in its firewall
The vulnerability is tracked as CVE-2024-3393, and when exploited, causes the firewall to reboot
Administrators are advised to patch ASAP, or to apply mitigations if not able to patch
-
#PaloAlto reveals #activeexploitation against vulnerability in its firewall
The vulnerability is tracked as CVE-2024-3393, and when exploited, causes the firewall to reboot
Administrators are advised to patch ASAP, or to apply mitigations if not able to patch
-
#PaloAlto reveals #activeexploitation against vulnerability in its firewall
The vulnerability is tracked as CVE-2024-3393, and when exploited, causes the firewall to reboot
Administrators are advised to patch ASAP, or to apply mitigations if not able to patch
-
Security researchers reveal #activeexploitation against a critical #ApacheStruts 2 vulnerability
The vulnerability is tracked as CVE-2024-53677, and when exploited, can allow an attacker to remotely execute code
Administrators are advised to patch ASAP
-
Security researchers reveal #activeexploitation against critical vulnerability in Array Networks SSL VPN products
The vulnerability is tracked as CVE-2023-28461, and when exploited, allows an attacker to remotely execute code
Administrators are advised to patch ASAP
-
UPDATE: Security researchers reveal over 2000 Palo Alto firewalls have been compromised using these vulnerabilities
-
UPDATE: Broadcom is warning that they have observed #activeexploitation for this vulnerability
-
Security researchers reveal #activeexploitation against a SharePoint vulnerability
The vulnerability is tracked as CVE-2024-38094, and when exploited, allows an attacker to remotely execute code. The vulnerability was patched during July Patch Tuesday.
Administrators are advised to patch ASAP
#cybersecurity #vulnerabilitymanagement
https://thehackernews.com/2024/10/cisa-warns-of-active-exploitation-of.html
-
#Mozilla has released software updates to address a critical vulnerability in #Firefox
The vulnerability is tracked as CVE-2024-9680, and when exploited, allows an attacker to run arbitrary code. Mozilla says they have reports the vulnerability is being exploited in the wild.
Users are advised to patch ASAP
-
Security researchers reveal #activeexploitation against Progress #WhatsUpGold vulnerability
The vulnerability is tracked as CVE-2024-4885, and when exploited, allows an attacker to execute any code. Security researchers have observed exploitation of this vulnerability since Aug 1, 2024.
Administrators are advised to patch ASAP
-
Security researchers reveal they have observed #activeexploitation against vulnerability in #SolarWinds #ServU
The vulnerability is tracked as CVE-2024-28995, and when exploited, allows an attacker to read sensitive files on the system. Researchers have released proof-of-concept exploits, and widespread exploitation came soon after.
Administrators are advised to patch ASAP
-
Security researchers reveal they have observed #activeexploitation against vulnerability in #SolarWinds #ServU
The vulnerability is tracked as CVE-2024-28995, and when exploited, allows an attacker to read sensitive files on the system. Researchers have released proof-of-concept exploits, and widespread exploitation came soon after.
Administrators are advised to patch ASAP
-
@campuscodi Kudos to @h4sh for assigning the CVE to the actively exploited CrushFTP zero-day: https://infosec.exchange/@h4sh/112316550866303546
According to his analysis and patch diffing, the CVSSv3 score for CVE-2024-4040 is 7.7 HIGH: Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
Did some patch diffing on the new #crushFTP bug, and it does look like the bug has 2 components and at least one of them need some form of authentication to exploit (need creation of something).
After the first stage, the reading of the file outside of VFS sandbox might not need authentication. I am not sure.#CrushFTP #zeroday #vulnerability #CVE_2024_4040 #eitw #activeexploitation
-
@campuscodi Kudos to @h4sh for assigning the CVE to the actively exploited CrushFTP zero-day: https://infosec.exchange/@h4sh/112316550866303546
According to his analysis and patch diffing, the CVSSv3 score for CVE-2024-4040 is 7.7 HIGH: Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
Did some patch diffing on the new #crushFTP bug, and it does look like the bug has 2 components and at least one of them need some form of authentication to exploit (need creation of something).
After the first stage, the reading of the file outside of VFS sandbox might not need authentication. I am not sure.#CrushFTP #zeroday #vulnerability #CVE_2024_4040 #eitw #activeexploitation
-
@campuscodi Kudos to @h4sh for assigning the CVE to the actively exploited CrushFTP zero-day: https://infosec.exchange/@h4sh/112316550866303546
According to his analysis and patch diffing, the CVSSv3 score for CVE-2024-4040 is 7.7 HIGH: Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
Did some patch diffing on the new #crushFTP bug, and it does look like the bug has 2 components and at least one of them need some form of authentication to exploit (need creation of something).
After the first stage, the reading of the file outside of VFS sandbox might not need authentication. I am not sure.#CrushFTP #zeroday #vulnerability #CVE_2024_4040 #eitw #activeexploitation
-
@campuscodi Kudos to @h4sh for assigning the CVE to the actively exploited CrushFTP zero-day: https://infosec.exchange/@h4sh/112316550866303546
According to his analysis and patch diffing, the CVSSv3 score for CVE-2024-4040 is 7.7 HIGH: Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
Did some patch diffing on the new #crushFTP bug, and it does look like the bug has 2 components and at least one of them need some form of authentication to exploit (need creation of something).
After the first stage, the reading of the file outside of VFS sandbox might not need authentication. I am not sure.#CrushFTP #zeroday #vulnerability #CVE_2024_4040 #eitw #activeexploitation
-
Shoutout to @h4sh for getting a CVE ID assigned to this actively exploited zero-day CrushFTP vulnerability: CVE-2024-4040 (reported by Simon Garrelou, of Airbus CERT). https://www.cve.org/CVERecord?id=CVE-2024-4040
VFS Sandbox Escape in CrushFTP in all versions before 10.7.1 and 11.1.0 on all platforms allows remote attackers with low privileges to read files from the filesystem outside of VFS Sandbox.
#zeroday #eitw #activeexploitation #CrushFTP #vulnerability #CVE_2024_4040
-
Shoutout to @h4sh for getting a CVE ID assigned to this actively exploited zero-day CrushFTP vulnerability: CVE-2024-4040 (reported by Simon Garrelou, of Airbus CERT). https://www.cve.org/CVERecord?id=CVE-2024-4040
VFS Sandbox Escape in CrushFTP in all versions before 10.7.1 and 11.1.0 on all platforms allows remote attackers with low privileges to read files from the filesystem outside of VFS Sandbox.
#zeroday #eitw #activeexploitation #CrushFTP #vulnerability #CVE_2024_4040
-
Shoutout to @h4sh for getting a CVE ID assigned to this actively exploited zero-day CrushFTP vulnerability: CVE-2024-4040 (reported by Simon Garrelou, of Airbus CERT). https://www.cve.org/CVERecord?id=CVE-2024-4040
VFS Sandbox Escape in CrushFTP in all versions before 10.7.1 and 11.1.0 on all platforms allows remote attackers with low privileges to read files from the filesystem outside of VFS Sandbox.
#zeroday #eitw #activeexploitation #CrushFTP #vulnerability #CVE_2024_4040
-
Shoutout to @h4sh for getting a CVE ID assigned to this actively exploited zero-day CrushFTP vulnerability: CVE-2024-4040 (reported by Simon Garrelou, of Airbus CERT). https://www.cve.org/CVERecord?id=CVE-2024-4040
VFS Sandbox Escape in CrushFTP in all versions before 10.7.1 and 11.1.0 on all platforms allows remote attackers with low privileges to read files from the filesystem outside of VFS Sandbox.
#zeroday #eitw #activeexploitation #CrushFTP #vulnerability #CVE_2024_4040
-
Microsoft reported that APT28 (Fancy Bear, Forest Blizzard) used a custom tool to elevate privileges and steal credentials in compromised networks. This GooseEgg tool leveraged CVE-2022-38028 (7.8 high, disclosed 11 October 2022 by Microsoft; Windows Print Spooler Elevation of Privilege Vulnerability) as a zero-day since at least June 2020 (possibly as early as April 2019) which was 2 years 4 months. APT28 is publicly attributed to Russian General Staff Main Intelligence Directorate (GRU). IOC provided. 🔗 https://www.microsoft.com/en-us/security/blog/2024/04/22/analyzing-forest-blizzards-custom-post-compromise-tool-for-exploiting-cve-2022-38028-to-obtain-credentials/
cc: @serghei @campuscodi @briankrebs @jwarminsky
#APT28 #cyberespionage #Russia #FancyBear #ForestBlizzard #CVE_2022_38028 #eitw #activeexploitation #GooseEgg
-
Microsoft reported that APT28 (Fancy Bear, Forest Blizzard) used a custom tool to elevate privileges and steal credentials in compromised networks. This GooseEgg tool leveraged CVE-2022-38028 (7.8 high, disclosed 11 October 2022 by Microsoft; Windows Print Spooler Elevation of Privilege Vulnerability) as a zero-day since at least June 2020 (possibly as early as April 2019) which was 2 years 4 months. APT28 is publicly attributed to Russian General Staff Main Intelligence Directorate (GRU). IOC provided. 🔗 https://www.microsoft.com/en-us/security/blog/2024/04/22/analyzing-forest-blizzards-custom-post-compromise-tool-for-exploiting-cve-2022-38028-to-obtain-credentials/
cc: @serghei @campuscodi @briankrebs @jwarminsky
#APT28 #cyberespionage #Russia #FancyBear #ForestBlizzard #CVE_2022_38028 #eitw #activeexploitation #GooseEgg
-
Microsoft reported that APT28 (Fancy Bear, Forest Blizzard) used a custom tool to elevate privileges and steal credentials in compromised networks. This GooseEgg tool leveraged CVE-2022-38028 (7.8 high, disclosed 11 October 2022 by Microsoft; Windows Print Spooler Elevation of Privilege Vulnerability) as a zero-day since at least June 2020 (possibly as early as April 2019) which was 2 years 4 months. APT28 is publicly attributed to Russian General Staff Main Intelligence Directorate (GRU). IOC provided. 🔗 https://www.microsoft.com/en-us/security/blog/2024/04/22/analyzing-forest-blizzards-custom-post-compromise-tool-for-exploiting-cve-2022-38028-to-obtain-credentials/
cc: @serghei @campuscodi @briankrebs @jwarminsky
#APT28 #cyberespionage #Russia #FancyBear #ForestBlizzard #CVE_2022_38028 #eitw #activeexploitation #GooseEgg
-
Microsoft reported that APT28 (Fancy Bear, Forest Blizzard) used a custom tool to elevate privileges and steal credentials in compromised networks. This GooseEgg tool leveraged CVE-2022-38028 (7.8 high, disclosed 11 October 2022 by Microsoft; Windows Print Spooler Elevation of Privilege Vulnerability) as a zero-day since at least June 2020 (possibly as early as April 2019) which was 2 years 4 months. APT28 is publicly attributed to Russian General Staff Main Intelligence Directorate (GRU). IOC provided. 🔗 https://www.microsoft.com/en-us/security/blog/2024/04/22/analyzing-forest-blizzards-custom-post-compromise-tool-for-exploiting-cve-2022-38028-to-obtain-credentials/
cc: @serghei @campuscodi @briankrebs @jwarminsky
#APT28 #cyberespionage #Russia #FancyBear #ForestBlizzard #CVE_2022_38028 #eitw #activeexploitation #GooseEgg
-
CrushFTP has released software updates to address a zero-day vulnerability that is being actively exploited.
The vulnerability does not yet have a CVE ID. When exploited, can allow an attacker to download sensitive files from the system.
Administrators are advised to patch ASAP.
-
CrushFTP has released software updates to address a zero-day vulnerability that is being actively exploited.
The vulnerability does not yet have a CVE ID. When exploited, can allow an attacker to download sensitive files from the system.
Administrators are advised to patch ASAP.
-
CrushFTP has released software updates to address a zero-day vulnerability that is being actively exploited.
The vulnerability does not yet have a CVE ID. When exploited, can allow an attacker to download sensitive files from the system.
Administrators are advised to patch ASAP.
-
Palo Alto Networks released additional details about CVE-2024-3400: the fact that it is a combination of two bugs in PAN-OS; how an attacker was exploiting it; how disabling telemetry initially worked; and how they fixed it. The timeline from discovery to remediation encompasses the whole blog post. Overall a comprehensive after-action review from a company that notified the public almost immediately of an exploited zero-day. 🔗https://www.paloaltonetworks.com/blog/2024/04/more-on-the-pan-os-cve/
#CVE_2024_3400 #PaloAltoNetworks #zeroday #activeexploitation #eitw #kev #KnownExploitedVulnerabilitiesCatalog #vulnerability #ProofofConcept #PANOS #IOC
-
Palo Alto Networks released additional details about CVE-2024-3400: the fact that it is a combination of two bugs in PAN-OS; how an attacker was exploiting it; how disabling telemetry initially worked; and how they fixed it. The timeline from discovery to remediation encompasses the whole blog post. Overall a comprehensive after-action review from a company that notified the public almost immediately of an exploited zero-day. 🔗https://www.paloaltonetworks.com/blog/2024/04/more-on-the-pan-os-cve/
#CVE_2024_3400 #PaloAltoNetworks #zeroday #activeexploitation #eitw #kev #KnownExploitedVulnerabilitiesCatalog #vulnerability #ProofofConcept #PANOS #IOC
-
Palo Alto Networks released additional details about CVE-2024-3400: the fact that it is a combination of two bugs in PAN-OS; how an attacker was exploiting it; how disabling telemetry initially worked; and how they fixed it. The timeline from discovery to remediation encompasses the whole blog post. Overall a comprehensive after-action review from a company that notified the public almost immediately of an exploited zero-day. 🔗https://www.paloaltonetworks.com/blog/2024/04/more-on-the-pan-os-cve/
#CVE_2024_3400 #PaloAltoNetworks #zeroday #activeexploitation #eitw #kev #KnownExploitedVulnerabilitiesCatalog #vulnerability #ProofofConcept #PANOS #IOC
-
Palo Alto Networks released additional details about CVE-2024-3400: the fact that it is a combination of two bugs in PAN-OS; how an attacker was exploiting it; how disabling telemetry initially worked; and how they fixed it. The timeline from discovery to remediation encompasses the whole blog post. Overall a comprehensive after-action review from a company that notified the public almost immediately of an exploited zero-day. 🔗https://www.paloaltonetworks.com/blog/2024/04/more-on-the-pan-os-cve/
#CVE_2024_3400 #PaloAltoNetworks #zeroday #activeexploitation #eitw #kev #KnownExploitedVulnerabilitiesCatalog #vulnerability #ProofofConcept #PANOS #IOC
-
It's not a Friday without an actively exploited zero-day vulnerability (with no CVE ID) in a file transfer product. cc: @todb
- Bleeping Computer: CrushFTP warns users to patch exploited zero-day “immediately”
- CrushFTP: CrushFTP: Update
- Exploitation report: CrowdStrike on Reddit: SITUATIONAL AWARENESS // 2024-04-19 // CrushFTP Virtual Filesystem Escape Vulnerability in the Wild
-
It's not a Friday without an actively exploited zero-day vulnerability (with no CVE ID) in a file transfer product. cc: @todb
- Bleeping Computer: CrushFTP warns users to patch exploited zero-day “immediately”
- CrushFTP: CrushFTP: Update
- Exploitation report: CrowdStrike on Reddit: SITUATIONAL AWARENESS // 2024-04-19 // CrushFTP Virtual Filesystem Escape Vulnerability in the Wild
-
It's not a Friday without an actively exploited zero-day vulnerability (with no CVE ID) in a file transfer product. cc: @todb
- Bleeping Computer: CrushFTP warns users to patch exploited zero-day “immediately”
- CrushFTP: CrushFTP: Update
- Exploitation report: CrowdStrike on Reddit: SITUATIONAL AWARENESS // 2024-04-19 // CrushFTP Virtual Filesystem Escape Vulnerability in the Wild
-
It's not a Friday without an actively exploited zero-day vulnerability (with no CVE ID) in a file transfer product. cc: @todb
- Bleeping Computer: CrushFTP warns users to patch exploited zero-day “immediately”
- CrushFTP: CrushFTP: Update
- Exploitation report: CrowdStrike on Reddit: SITUATIONAL AWARENESS // 2024-04-19 // CrushFTP Virtual Filesystem Escape Vulnerability in the Wild