home.social

#activeexploitation — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #activeexploitation, aggregated by home.social.

fetched live
  1. CISA has added four vulnerabilities to its KEV catalog with evidence of active exploitation. Affected systems include Microsoft IKE Service Extensions, SharePoint, VMware vCenter, and Apple macOS.

    #CISA #ActiveExploitation #VulnerabilityManagement #PatchManagement

    cyberworldops.eu/en/four-criti

  2. CISA Warns of Active Exploits Targeting Android, Linux Flaws

    A high-severity Android flaw, CVE-2025-48595, is being actively exploited in targeted attacks, allowing hackers to gain increased privileges without needing any user interaction. This critical vulnerability affects Android 14-16 and has prompted CISA to add it to its list of Known Exploited Vulnerabilities.

    osintsights.com/cisa-warns-of-

    #AndroidExploits #EmergingThreats #Cve202548595 #LinuxFlaws #ActiveExploitation

  3. Marimo Flaw Exploited for Credential Theft in Active Attacks

    A critical vulnerability in Marimo is being actively exploited by attackers to steal sensitive credentials, and it requires no prior authentication to run code remotely. This flaw has severe consequences for organizations using Marimo, making it essential to take immediate action.

    osintsights.com/marimo-flaw-ex

    #Marimo #CredentialTheft #RemoteCodeExecution #Preauthentication #ActiveExploitation

  4. Update your #Apple devices ASAP. Two vulnerabilities, CVE-2025-31200 and CVE-2025-31201, have been fixed: support.apple.com/en-us/122282

    "Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on iOS."

    While iOS has been known to be targeted, the fixes are available for all Apple devices and should be installed as soon as possible.

    #activeexploitation #CVE_2025_31200 #CVE_2025_31201

  5. Update your #Apple devices ASAP. Two vulnerabilities, CVE-2025-31200 and CVE-2025-31201, have been fixed: support.apple.com/en-us/122282

    "Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on iOS."

    While iOS has been known to be targeted, the fixes are available for all Apple devices and should be installed as soon as possible.

    #activeexploitation #CVE_2025_31200 #CVE_2025_31201

  6. Update your #Apple devices ASAP. Two vulnerabilities, CVE-2025-31200 and CVE-2025-31201, have been fixed: support.apple.com/en-us/122282

    "Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on iOS."

    While iOS has been known to be targeted, the fixes are available for all Apple devices and should be installed as soon as possible.

    #activeexploitation #CVE_2025_31200 #CVE_2025_31201

  7. Update your #Apple devices ASAP. Two vulnerabilities, CVE-2025-31200 and CVE-2025-31201, have been fixed: support.apple.com/en-us/122282

    "Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on iOS."

    While iOS has been known to be targeted, the fixes are available for all Apple devices and should be installed as soon as possible.

    #activeexploitation #CVE_2025_31200 #CVE_2025_31201

  8. Update your #Apple devices ASAP. Two vulnerabilities, CVE-2025-31200 and CVE-2025-31201, have been fixed: support.apple.com/en-us/122282

    "Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on iOS."

    While iOS has been known to be targeted, the fixes are available for all Apple devices and should be installed as soon as possible.

    #activeexploitation #CVE_2025_31200 #CVE_2025_31201

  9. Security researchers discover vulnerabilities in #Paragon Partition Manager driver used in #activeexploitation

    The actively exploited vulnerability is tracked as CVE-2025-0289, and when exploited, allows an attacker to gain administrative privileges and to execute code. An attacker can potentially download the driver onto a device without Paragon Partition Manager installed.

    Users are advised to patch ASAP, and to enable Vulnerable Driver Blocklist

    #cybersecurity

    bleepingcomputer.com/news/secu

  10. Security researchers discover vulnerabilities in #Paragon Partition Manager driver used in #activeexploitation

    The actively exploited vulnerability is tracked as CVE-2025-0289, and when exploited, allows an attacker to gain administrative privileges and to execute code. An attacker can potentially download the driver onto a device without Paragon Partition Manager installed.

    Users are advised to patch ASAP, and to enable Vulnerable Driver Blocklist

    #cybersecurity

    bleepingcomputer.com/news/secu

  11. Security researchers discover vulnerabilities in #Paragon Partition Manager driver used in #activeexploitation

    The actively exploited vulnerability is tracked as CVE-2025-0289, and when exploited, allows an attacker to gain administrative privileges and to execute code. An attacker can potentially download the driver onto a device without Paragon Partition Manager installed.

    Users are advised to patch ASAP, and to enable Vulnerable Driver Blocklist

    #cybersecurity

    bleepingcomputer.com/news/secu

  12. Security researchers reveal #activeexploitation against #SimpleHelp RMM vulnerabilities

    The vulnerabilities are tracked as CVE-2024-57726, CVE-2024-57727, and CVE-2024-57728, and when exploited, allows an attacker to gain admin privileges

    Administrators are advised to patch ASAP

    #cybersecurity #vulnerabilitymanagement

    bleepingcomputer.com/news/secu

  13. Security researchers reveal #activeexploitation against #SimpleHelp RMM vulnerabilities

    The vulnerabilities are tracked as CVE-2024-57726, CVE-2024-57727, and CVE-2024-57728, and when exploited, allows an attacker to gain admin privileges

    Administrators are advised to patch ASAP

    #cybersecurity #vulnerabilitymanagement

    bleepingcomputer.com/news/secu

  14. Security researchers reveal #activeexploitation against #SimpleHelp RMM vulnerabilities

    The vulnerabilities are tracked as CVE-2024-57726, CVE-2024-57727, and CVE-2024-57728, and when exploited, allows an attacker to gain admin privileges

    Administrators are advised to patch ASAP

    #cybersecurity #vulnerabilitymanagement

    bleepingcomputer.com/news/secu

  15. pls appreciate i wore an aqua colored sweater to talk about aquabot

    🚨Active exploitation attempt🚨
    Akamai Security Intelligence and Response Team (SIRT) has identified a new variant of the Mirai-based Aquabot, dubbed Aquabotv3 keeping in line with the naming conventions of the first two.

    it is using CVE-2024-41710, a command injection vulnerability that affects Mitel SIP models. There was a POC made public in august 2024 but this is the first time it's been seen actively seeking exploitation ITW.

    not only that! This malware exhibits a behavior we have never before seen with a Mirai variant: a function (report_kill) to report back to the C2 when a kill signal was caught on the infected device.

    We (we = the SIRT) have not seen any response from the C2 as of the date this was originally posted (Jan. 28, 2024).

    Incredible work Larry Cashdollar and Kyle Lefton 🎉

    Full technical analysis including IOCs:
    akamai.com/blog/security-resea

    #mirai #malware #activeexploitation #security #research #botnet

  16. pls appreciate i wore an aqua colored sweater to talk about aquabot

    🚨Active exploitation attempt🚨
    Akamai Security Intelligence and Response Team (SIRT) has identified a new variant of the Mirai-based Aquabot, dubbed Aquabotv3 keeping in line with the naming conventions of the first two.

    it is using CVE-2024-41710, a command injection vulnerability that affects Mitel SIP models. There was a POC made public in august 2024 but this is the first time it's been seen actively seeking exploitation ITW.

    not only that! This malware exhibits a behavior we have never before seen with a Mirai variant: a function (report_kill) to report back to the C2 when a kill signal was caught on the infected device.

    We (we = the SIRT) have not seen any response from the C2 as of the date this was originally posted (Jan. 28, 2024).

    Incredible work Larry Cashdollar and Kyle Lefton 🎉

    Full technical analysis including IOCs:
    akamai.com/blog/security-resea

    #mirai #malware #activeexploitation #security #research #botnet

  17. pls appreciate i wore an aqua colored sweater to talk about aquabot

    🚨Active exploitation attempt🚨
    Akamai Security Intelligence and Response Team (SIRT) has identified a new variant of the Mirai-based Aquabot, dubbed Aquabotv3 keeping in line with the naming conventions of the first two.

    it is using CVE-2024-41710, a command injection vulnerability that affects Mitel SIP models. There was a POC made public in august 2024 but this is the first time it's been seen actively seeking exploitation ITW.

    not only that! This malware exhibits a behavior we have never before seen with a Mirai variant: a function (report_kill) to report back to the C2 when a kill signal was caught on the infected device.

    We (we = the SIRT) have not seen any response from the C2 as of the date this was originally posted (Jan. 28, 2024).

    Incredible work Larry Cashdollar and Kyle Lefton 🎉

    Full technical analysis including IOCs:
    akamai.com/blog/security-resea

    #mirai #malware #activeexploitation #security #research #botnet

  18. pls appreciate i wore an aqua colored sweater to talk about aquabot

    🚨Active exploitation attempt🚨
    Akamai Security Intelligence and Response Team (SIRT) has identified a new variant of the Mirai-based Aquabot, dubbed Aquabotv3 keeping in line with the naming conventions of the first two.

    it is using CVE-2024-41710, a command injection vulnerability that affects Mitel SIP models. There was a POC made public in august 2024 but this is the first time it's been seen actively seeking exploitation ITW.

    not only that! This malware exhibits a behavior we have never before seen with a Mirai variant: a function (report_kill) to report back to the C2 when a kill signal was caught on the infected device.

    We (we = the SIRT) have not seen any response from the C2 as of the date this was originally posted (Jan. 28, 2024).

    Incredible work Larry Cashdollar and Kyle Lefton 🎉

    Full technical analysis including IOCs:
    akamai.com/blog/security-resea

    #mirai #malware #activeexploitation #security #research #botnet

  19. pls appreciate i wore an aqua colored sweater to talk about aquabot

    🚨Active exploitation attempt🚨
    Akamai Security Intelligence and Response Team (SIRT) has identified a new variant of the Mirai-based Aquabot, dubbed Aquabotv3 keeping in line with the naming conventions of the first two.

    it is using CVE-2024-41710, a command injection vulnerability that affects Mitel SIP models. There was a POC made public in august 2024 but this is the first time it's been seen actively seeking exploitation ITW.

    not only that! This malware exhibits a behavior we have never before seen with a Mirai variant: a function (report_kill) to report back to the C2 when a kill signal was caught on the infected device.

    We (we = the SIRT) have not seen any response from the C2 as of the date this was originally posted (Jan. 28, 2024).

    Incredible work Larry Cashdollar and Kyle Lefton 🎉

    Full technical analysis including IOCs:
    akamai.com/blog/security-resea

    #mirai #malware #activeexploitation #security #research #botnet

  20. #Ivanti has revealed #activeexploitation against a vulnerability in its appliances

    The vulnerability is tracked as CVE-2025-0282, and when exploited, allows an attacker to remotely execute code

    Administrators are advised to patch ASAP

    #cybersecurity

    bleepingcomputer.com/news/secu

  21. #Ivanti has revealed #activeexploitation against a vulnerability in its appliances

    The vulnerability is tracked as CVE-2025-0282, and when exploited, allows an attacker to remotely execute code

    Administrators are advised to patch ASAP

    #cybersecurity

    bleepingcomputer.com/news/secu

  22. #Ivanti has revealed #activeexploitation against a vulnerability in its appliances

    The vulnerability is tracked as CVE-2025-0282, and when exploited, allows an attacker to remotely execute code

    Administrators are advised to patch ASAP

    #cybersecurity

    bleepingcomputer.com/news/secu

  23. #Ivanti has revealed #activeexploitation against a vulnerability in its appliances

    The vulnerability is tracked as CVE-2025-0282, and when exploited, allows an attacker to remotely execute code

    Administrators are advised to patch ASAP

    #cybersecurity

    bleepingcomputer.com/news/secu

  24. Security researchers reveal #activeexploitation of a vulnerability in #FourFaith routers

    The vulnerability is tracked as CVE-2024-12856, and when exploited, allows an attacker to inject commands

    Administrators are advised to reach out to their Four-Faith contacts for mitigation steps

    #cybersecurity

    bleepingcomputer.com/news/secu

  25. Security researchers reveal #activeexploitation of a vulnerability in #FourFaith routers

    The vulnerability is tracked as CVE-2024-12856, and when exploited, allows an attacker to inject commands

    Administrators are advised to reach out to their Four-Faith contacts for mitigation steps

    #cybersecurity

    bleepingcomputer.com/news/secu

  26. #PaloAlto reveals #activeexploitation against vulnerability in its firewall

    The vulnerability is tracked as CVE-2024-3393, and when exploited, causes the firewall to reboot

    Administrators are advised to patch ASAP, or to apply mitigations if not able to patch

    #cybersecurity

    bleepingcomputer.com/news/secu

  27. #PaloAlto reveals #activeexploitation against vulnerability in its firewall

    The vulnerability is tracked as CVE-2024-3393, and when exploited, causes the firewall to reboot

    Administrators are advised to patch ASAP, or to apply mitigations if not able to patch

    #cybersecurity

    bleepingcomputer.com/news/secu

  28. #PaloAlto reveals #activeexploitation against vulnerability in its firewall

    The vulnerability is tracked as CVE-2024-3393, and when exploited, causes the firewall to reboot

    Administrators are advised to patch ASAP, or to apply mitigations if not able to patch

    #cybersecurity

    bleepingcomputer.com/news/secu

  29. Security researchers reveal #activeexploitation against a critical #ApacheStruts 2 vulnerability

    The vulnerability is tracked as CVE-2024-53677, and when exploited, can allow an attacker to remotely execute code

    Administrators are advised to patch ASAP

    #cybersecurity

    bleepingcomputer.com/news/secu

  30. Security researchers reveal #activeexploitation against critical vulnerability in Array Networks SSL VPN products

    The vulnerability is tracked as CVE-2023-28461, and when exploited, allows an attacker to remotely execute code

    Administrators are advised to patch ASAP

    #cybersecurity #vulnerabilitymanagement

    bleepingcomputer.com/news/secu

  31. Security researchers reveal #activeexploitation against a SharePoint vulnerability

    The vulnerability is tracked as CVE-2024-38094, and when exploited, allows an attacker to remotely execute code. The vulnerability was patched during July Patch Tuesday.

    Administrators are advised to patch ASAP

    #cybersecurity #vulnerabilitymanagement

    thehackernews.com/2024/10/cisa

  32. #Mozilla has released software updates to address a critical vulnerability in #Firefox

    The vulnerability is tracked as CVE-2024-9680, and when exploited, allows an attacker to run arbitrary code. Mozilla says they have reports the vulnerability is being exploited in the wild.

    Users are advised to patch ASAP

    #cybersecurity #vulnerabilitymanagement #activeexploitation

    bleepingcomputer.com/news/secu

  33. Security researchers reveal #activeexploitation against Progress #WhatsUpGold vulnerability

    The vulnerability is tracked as CVE-2024-4885, and when exploited, allows an attacker to execute any code. Security researchers have observed exploitation of this vulnerability since Aug 1, 2024.

    Administrators are advised to patch ASAP

    #cybersecurity

    bleepingcomputer.com/news/secu

  34. Security researchers reveal they have observed #activeexploitation against vulnerability in #SolarWinds #ServU

    The vulnerability is tracked as CVE-2024-28995, and when exploited, allows an attacker to read sensitive files on the system. Researchers have released proof-of-concept exploits, and widespread exploitation came soon after.

    Administrators are advised to patch ASAP

    #cybersecurity

    bleepingcomputer.com/news/secu

  35. Security researchers reveal they have observed #activeexploitation against vulnerability in #SolarWinds #ServU

    The vulnerability is tracked as CVE-2024-28995, and when exploited, allows an attacker to read sensitive files on the system. Researchers have released proof-of-concept exploits, and widespread exploitation came soon after.

    Administrators are advised to patch ASAP

    #cybersecurity

    bleepingcomputer.com/news/secu

  36. @campuscodi Kudos to @h4sh for assigning the CVE to the actively exploited CrushFTP zero-day: infosec.exchange/@h4sh/1123165

    According to his analysis and patch diffing, the CVSSv3 score for CVE-2024-4040 is 7.7 HIGH: Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N

    Did some patch diffing on the new #crushFTP bug, and it does look like the bug has 2 components and at least one of them need some form of authentication to exploit (need creation of something).
    After the first stage, the reading of the file outside of VFS sandbox might not need authentication. I am not sure.

    #CrushFTP #zeroday #vulnerability #CVE_2024_4040 #eitw #activeexploitation

  37. @campuscodi Kudos to @h4sh for assigning the CVE to the actively exploited CrushFTP zero-day: infosec.exchange/@h4sh/1123165

    According to his analysis and patch diffing, the CVSSv3 score for CVE-2024-4040 is 7.7 HIGH: Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N

    Did some patch diffing on the new #crushFTP bug, and it does look like the bug has 2 components and at least one of them need some form of authentication to exploit (need creation of something).
    After the first stage, the reading of the file outside of VFS sandbox might not need authentication. I am not sure.

    #CrushFTP #zeroday #vulnerability #CVE_2024_4040 #eitw #activeexploitation

  38. @campuscodi Kudos to @h4sh for assigning the CVE to the actively exploited CrushFTP zero-day: infosec.exchange/@h4sh/1123165

    According to his analysis and patch diffing, the CVSSv3 score for CVE-2024-4040 is 7.7 HIGH: Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N

    Did some patch diffing on the new #crushFTP bug, and it does look like the bug has 2 components and at least one of them need some form of authentication to exploit (need creation of something).
    After the first stage, the reading of the file outside of VFS sandbox might not need authentication. I am not sure.

    #CrushFTP #zeroday #vulnerability #CVE_2024_4040 #eitw #activeexploitation

  39. @campuscodi Kudos to @h4sh for assigning the CVE to the actively exploited CrushFTP zero-day: infosec.exchange/@h4sh/1123165

    According to his analysis and patch diffing, the CVSSv3 score for CVE-2024-4040 is 7.7 HIGH: Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N

    Did some patch diffing on the new #crushFTP bug, and it does look like the bug has 2 components and at least one of them need some form of authentication to exploit (need creation of something).
    After the first stage, the reading of the file outside of VFS sandbox might not need authentication. I am not sure.

    #CrushFTP #zeroday #vulnerability #CVE_2024_4040 #eitw #activeexploitation

  40. Shoutout to @h4sh for getting a CVE ID assigned to this actively exploited zero-day CrushFTP vulnerability: CVE-2024-4040 (reported by Simon Garrelou, of Airbus CERT). cve.org/CVERecord?id=CVE-2024-

    VFS Sandbox Escape in CrushFTP in all versions before 10.7.1 and 11.1.0 on all platforms allows remote attackers with low privileges to read files from the filesystem outside of VFS Sandbox.

    #zeroday #eitw #activeexploitation #CrushFTP #vulnerability #CVE_2024_4040

  41. Shoutout to @h4sh for getting a CVE ID assigned to this actively exploited zero-day CrushFTP vulnerability: CVE-2024-4040 (reported by Simon Garrelou, of Airbus CERT). cve.org/CVERecord?id=CVE-2024-

    VFS Sandbox Escape in CrushFTP in all versions before 10.7.1 and 11.1.0 on all platforms allows remote attackers with low privileges to read files from the filesystem outside of VFS Sandbox.

    #zeroday #eitw #activeexploitation #CrushFTP #vulnerability #CVE_2024_4040

  42. Shoutout to @h4sh for getting a CVE ID assigned to this actively exploited zero-day CrushFTP vulnerability: CVE-2024-4040 (reported by Simon Garrelou, of Airbus CERT). cve.org/CVERecord?id=CVE-2024-

    VFS Sandbox Escape in CrushFTP in all versions before 10.7.1 and 11.1.0 on all platforms allows remote attackers with low privileges to read files from the filesystem outside of VFS Sandbox.

    #zeroday #eitw #activeexploitation #CrushFTP #vulnerability #CVE_2024_4040

  43. Shoutout to @h4sh for getting a CVE ID assigned to this actively exploited zero-day CrushFTP vulnerability: CVE-2024-4040 (reported by Simon Garrelou, of Airbus CERT). cve.org/CVERecord?id=CVE-2024-

    VFS Sandbox Escape in CrushFTP in all versions before 10.7.1 and 11.1.0 on all platforms allows remote attackers with low privileges to read files from the filesystem outside of VFS Sandbox.

    #zeroday #eitw #activeexploitation #CrushFTP #vulnerability #CVE_2024_4040

  44. Microsoft reported that APT28 (Fancy Bear, Forest Blizzard) used a custom tool to elevate privileges and steal credentials in compromised networks. This GooseEgg tool leveraged CVE-2022-38028 (7.8 high, disclosed 11 October 2022 by Microsoft; Windows Print Spooler Elevation of Privilege Vulnerability) as a zero-day since at least June 2020 (possibly as early as April 2019) which was 2 years 4 months. APT28 is publicly attributed to Russian General Staff Main Intelligence Directorate (GRU). IOC provided. 🔗 microsoft.com/en-us/security/b

    cc: @serghei @campuscodi @briankrebs @jwarminsky

    #APT28 #cyberespionage #Russia #FancyBear #ForestBlizzard #CVE_2022_38028 #eitw #activeexploitation #GooseEgg

  45. Microsoft reported that APT28 (Fancy Bear, Forest Blizzard) used a custom tool to elevate privileges and steal credentials in compromised networks. This GooseEgg tool leveraged CVE-2022-38028 (7.8 high, disclosed 11 October 2022 by Microsoft; Windows Print Spooler Elevation of Privilege Vulnerability) as a zero-day since at least June 2020 (possibly as early as April 2019) which was 2 years 4 months. APT28 is publicly attributed to Russian General Staff Main Intelligence Directorate (GRU). IOC provided. 🔗 microsoft.com/en-us/security/b

    cc: @serghei @campuscodi @briankrebs @jwarminsky

    #APT28 #cyberespionage #Russia #FancyBear #ForestBlizzard #CVE_2022_38028 #eitw #activeexploitation #GooseEgg

  46. Microsoft reported that APT28 (Fancy Bear, Forest Blizzard) used a custom tool to elevate privileges and steal credentials in compromised networks. This GooseEgg tool leveraged CVE-2022-38028 (7.8 high, disclosed 11 October 2022 by Microsoft; Windows Print Spooler Elevation of Privilege Vulnerability) as a zero-day since at least June 2020 (possibly as early as April 2019) which was 2 years 4 months. APT28 is publicly attributed to Russian General Staff Main Intelligence Directorate (GRU). IOC provided. 🔗 microsoft.com/en-us/security/b

    cc: @serghei @campuscodi @briankrebs @jwarminsky

    #APT28 #cyberespionage #Russia #FancyBear #ForestBlizzard #CVE_2022_38028 #eitw #activeexploitation #GooseEgg

  47. Microsoft reported that APT28 (Fancy Bear, Forest Blizzard) used a custom tool to elevate privileges and steal credentials in compromised networks. This GooseEgg tool leveraged CVE-2022-38028 (7.8 high, disclosed 11 October 2022 by Microsoft; Windows Print Spooler Elevation of Privilege Vulnerability) as a zero-day since at least June 2020 (possibly as early as April 2019) which was 2 years 4 months. APT28 is publicly attributed to Russian General Staff Main Intelligence Directorate (GRU). IOC provided. 🔗 microsoft.com/en-us/security/b

    cc: @serghei @campuscodi @briankrebs @jwarminsky

    #APT28 #cyberespionage #Russia #FancyBear #ForestBlizzard #CVE_2022_38028 #eitw #activeexploitation #GooseEgg

  48. CrushFTP has released software updates to address a zero-day vulnerability that is being actively exploited.

    The vulnerability does not yet have a CVE ID. When exploited, can allow an attacker to download sensitive files from the system.

    Administrators are advised to patch ASAP.

    #cybersecurity #CrushFTP #zeroday #activeexploitation

    bleepingcomputer.com/news/secu

  49. CrushFTP has released software updates to address a zero-day vulnerability that is being actively exploited.

    The vulnerability does not yet have a CVE ID. When exploited, can allow an attacker to download sensitive files from the system.

    Administrators are advised to patch ASAP.

    #cybersecurity #CrushFTP #zeroday #activeexploitation

    bleepingcomputer.com/news/secu

  50. CrushFTP has released software updates to address a zero-day vulnerability that is being actively exploited.

    The vulnerability does not yet have a CVE ID. When exploited, can allow an attacker to download sensitive files from the system.

    Administrators are advised to patch ASAP.

    #cybersecurity #CrushFTP #zeroday #activeexploitation

    bleepingcomputer.com/news/secu

  51. Palo Alto Networks released additional details about CVE-2024-3400: the fact that it is a combination of two bugs in PAN-OS; how an attacker was exploiting it; how disabling telemetry initially worked; and how they fixed it. The timeline from discovery to remediation encompasses the whole blog post. Overall a comprehensive after-action review from a company that notified the public almost immediately of an exploited zero-day. 🔗paloaltonetworks.com/blog/2024

    #CVE_2024_3400 #PaloAltoNetworks #zeroday #activeexploitation #eitw #kev #KnownExploitedVulnerabilitiesCatalog #vulnerability #ProofofConcept #PANOS #IOC

  52. Palo Alto Networks released additional details about CVE-2024-3400: the fact that it is a combination of two bugs in PAN-OS; how an attacker was exploiting it; how disabling telemetry initially worked; and how they fixed it. The timeline from discovery to remediation encompasses the whole blog post. Overall a comprehensive after-action review from a company that notified the public almost immediately of an exploited zero-day. 🔗paloaltonetworks.com/blog/2024

    #CVE_2024_3400 #PaloAltoNetworks #zeroday #activeexploitation #eitw #kev #KnownExploitedVulnerabilitiesCatalog #vulnerability #ProofofConcept #PANOS #IOC

  53. Palo Alto Networks released additional details about CVE-2024-3400: the fact that it is a combination of two bugs in PAN-OS; how an attacker was exploiting it; how disabling telemetry initially worked; and how they fixed it. The timeline from discovery to remediation encompasses the whole blog post. Overall a comprehensive after-action review from a company that notified the public almost immediately of an exploited zero-day. 🔗paloaltonetworks.com/blog/2024

    #CVE_2024_3400 #PaloAltoNetworks #zeroday #activeexploitation #eitw #kev #KnownExploitedVulnerabilitiesCatalog #vulnerability #ProofofConcept #PANOS #IOC

  54. Palo Alto Networks released additional details about CVE-2024-3400: the fact that it is a combination of two bugs in PAN-OS; how an attacker was exploiting it; how disabling telemetry initially worked; and how they fixed it. The timeline from discovery to remediation encompasses the whole blog post. Overall a comprehensive after-action review from a company that notified the public almost immediately of an exploited zero-day. 🔗paloaltonetworks.com/blog/2024

    #CVE_2024_3400 #PaloAltoNetworks #zeroday #activeexploitation #eitw #kev #KnownExploitedVulnerabilitiesCatalog #vulnerability #ProofofConcept #PANOS #IOC