home.social

#kev — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #kev, aggregated by home.social.

  1. VIKI SNIFFER analyzed 72,953 CVEs in the latest OSINT cycle.

    Key findings:

    47,064 CVEs still have no CVSS
    64 MITRE ATT&CK techniques identified
    Strong growth in:
    T1071 — Application Layer Protocol
    T1055 — Process Injection
    T1003.005 — Cached Credentials
    T1020 — Automated Exfiltration

    jaroslawkuchta.substack.com/p/

    #CyberSecurity #ThreatIntelligence #SOC #BlueTeam #MITREATTACK #ExposureManagement #CTEM #ThreatHunting #OSINT #CVE #KEV #InfoSec #IdentitySecurity #LLMSecurity #OpenAPI #MCP #DetectionEngineering

  2. VIKI SNIFFER analyzed 72,953 CVEs in the latest OSINT cycle.

    Key findings:

    47,064 CVEs still have no CVSS
    64 MITRE ATT&CK techniques identified
    Strong growth in:
    T1071 — Application Layer Protocol
    T1055 — Process Injection
    T1003.005 — Cached Credentials
    T1020 — Automated Exfiltration

    jaroslawkuchta.substack.com/p/

    #CyberSecurity #ThreatIntelligence #SOC #BlueTeam #MITREATTACK #ExposureManagement #CTEM #ThreatHunting #OSINT #CVE #KEV #InfoSec #IdentitySecurity #LLMSecurity #OpenAPI #MCP #DetectionEngineering

  3. CISA Opens KEV Nominations to Bolster Vulnerability Intelligence

    CISA is now accepting nominations for its Known Exploited Vulnerabilities catalog, empowering public reporting to strengthen the nation's cybersecurity posture by quickly identifying and mitigating exploited vulnerabilities. By submitting through the new KEV nomination form, you're helping to keep federal,…

    osintsights.com/cisa-opens-kev

    #VulnerabilityDisclosure #KnownExploitedVulnerabilities #Kev #Cisa #VulnerabilityIntelligence

  4. 📰 CISA Adds Seven New Vulnerabilities to 'Must-Patch' KEV Catalog

    📢 CISA has added 7 new vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog. Federal agencies are required to patch under BOD 22-01. All orgs are urged to prioritize these fixes to defend against active threats. #CISA #KEV #PatchNow ...

    🌐 cyber[.]netsecops[.]io

    🔗 cyber.netsecops.io/articles/ci

  5. 📰 CISA Opens KEV Catalog to Public Submissions to Speed Up Threat Response

    CISA is now crowdsourcing threat intelligence! 🌐 The agency has launched a new public submission process for its Known Exploited Vulnerabilities (KEV) catalog, allowing anyone to report actively exploited vulns. 🛡️ #CISA #KEV #Cybersecurity #InfoSec

    🌐 cyber[.]netsecops[.]io

    🔗 cyber.netsecops.io/articles/ci

  6. Апрельский «В тренде VM»: уязвимость в Microsoft SharePoint

    Хабр, привет! На связи Александр Леонов, ведущий эксперт PT Expert Security Center и дежурный по самым опасным уязвимостям месяца. Мы с командой аналитиков Positive Technologies регулярно исследуем информацию об уязвимостях из баз и бюллетеней безопасности вендоров, социальных сетей, блогов, телеграм-каналов, баз эксплойтов, публичных репозиториев кода и выявляем во всем этом многообразии сведений трендовые уязвимости. Это те уязвимости, которые либо уже эксплуатируются вживую, либо будут эксплуатироваться в ближайшее время. С прошлого дайджеста мы добавили еще одну трендовую уязвимость. Подробности о ней читайте под катом. Читать

    habr.com/ru/companies/pt/artic

    #vm #cvss #kev #max_patrol_vm #sharepoint #уязвимости_и_их_эксплуатация #microsoft_office #debugs #cve

  7. Апрельский «В тренде VM»: уязвимость в Microsoft SharePoint

    Хабр, привет! На связи Александр Леонов, ведущий эксперт PT Expert Security Center и дежурный по самым опасным уязвимостям месяца. Мы с командой аналитиков Positive Technologies регулярно исследуем информацию об уязвимостях из баз и бюллетеней безопасности вендоров, социальных сетей, блогов, телеграм-каналов, баз эксплойтов, публичных репозиториев кода и выявляем во всем этом многообразии сведений трендовые уязвимости. Это те уязвимости, которые либо уже эксплуатируются вживую, либо будут эксплуатироваться в ближайшее время. С прошлого дайджеста мы добавили еще одну трендовую уязвимость. Подробности о ней читайте под катом. Читать

    habr.com/ru/companies/pt/artic

    #vm #cvss #kev #max_patrol_vm #sharepoint #уязвимости_и_их_эксплуатация #microsoft_office #debugs #cve

  8. Апрельский «В тренде VM»: уязвимость в Microsoft SharePoint

    Хабр, привет! На связи Александр Леонов, ведущий эксперт PT Expert Security Center и дежурный по самым опасным уязвимостям месяца. Мы с командой аналитиков Positive Technologies регулярно исследуем информацию об уязвимостях из баз и бюллетеней безопасности вендоров, социальных сетей, блогов, телеграм-каналов, баз эксплойтов, публичных репозиториев кода и выявляем во всем этом многообразии сведений трендовые уязвимости. Это те уязвимости, которые либо уже эксплуатируются вживую, либо будут эксплуатироваться в ближайшее время. С прошлого дайджеста мы добавили еще одну трендовую уязвимость. Подробности о ней читайте под катом. Читать

    habr.com/ru/companies/pt/artic

    #vm #cvss #kev #max_patrol_vm #sharepoint #уязвимости_и_их_эксплуатация #microsoft_office #debugs #cve

  9. Апрельский «В тренде VM»: уязвимость в Microsoft SharePoint

    Хабр, привет! На связи Александр Леонов, ведущий эксперт PT Expert Security Center и дежурный по самым опасным уязвимостям месяца. Мы с командой аналитиков Positive Technologies регулярно исследуем информацию об уязвимостях из баз и бюллетеней безопасности вендоров, социальных сетей, блогов, телеграм-каналов, баз эксплойтов, публичных репозиториев кода и выявляем во всем этом многообразии сведений трендовые уязвимости. Это те уязвимости, которые либо уже эксплуатируются вживую, либо будут эксплуатироваться в ближайшее время. С прошлого дайджеста мы добавили еще одну трендовую уязвимость. Подробности о ней читайте под катом. Читать

    habr.com/ru/companies/pt/artic

    #vm #cvss #kev #max_patrol_vm #sharepoint #уязвимости_и_их_эксплуатация #microsoft_office #debugs #cve

  10. Does anyone know if what CISA is putting out post-Jen is worth looking or is just like the rest of the anal flem this administration produces? I mean, for realz inside knowledge?

    thehackernews.com/2026/04/cisa

    #cisa #kev

  11. Does anyone know if what CISA is putting out post-Jen is worth looking or is just like the rest of the anal flem this administration produces? I mean, for realz inside knowledge?

    thehackernews.com/2026/04/cisa

    #cisa #kev

  12. Does anyone know if what CISA is putting out post-Jen is worth looking or is just like the rest of the anal flem this administration produces? I mean, for realz inside knowledge?

    thehackernews.com/2026/04/cisa

    #cisa #kev

  13. Does anyone know if what CISA is putting out post-Jen is worth looking or is just like the rest of the anal flem this administration produces? I mean, for realz inside knowledge?

    thehackernews.com/2026/04/cisa

    #cisa #kev

  14. Does anyone know if what CISA is putting out post-Jen is worth looking or is just like the rest of the anal flem this administration produces? I mean, for realz inside knowledge?

    thehackernews.com/2026/04/cisa

    #cisa #kev

  15. 📰 CISA Mandates Urgent Patching for Eight Actively Exploited Flaws in Cisco, JetBrains, and More

    🚨 CISA adds 8 actively exploited vulnerabilities to its KEV catalog! Flaws in Cisco, PaperCut, & JetBrains products require urgent patching. Federal agencies are mandated to remediate, and all orgs are strongly urged to act now. #KEV #CyberSecurity...

    🔗 cyber.netsecops.io/articles/ci

  16. 📰 CISA Mandates Urgent Patching for Eight Actively Exploited Flaws in Cisco, JetBrains, and More

    🚨 CISA adds 8 actively exploited vulnerabilities to its KEV catalog! Flaws in Cisco, PaperCut, & JetBrains products require urgent patching. Federal agencies are mandated to remediate, and all orgs are strongly urged to act now. #KEV #CyberSecurity...

    🔗 cyber.netsecops.io/articles/ci

  17. New KEV added 🚨
    CVE-2026-34197 (Apache ActiveMQ)
    • Active exploitation confirmed
    • High-risk entry point
    KEV = patch now, not later

    Source: cisa.gov/news-events/alerts/20

    💬 How fast is your patch cycle?
    Follow @technadu

    #InfoSec #CyberSecurity #KEV

  18. New KEV added 🚨
    CVE-2026-34197 (Apache ActiveMQ)
    • Active exploitation confirmed
    • High-risk entry point
    KEV = patch now, not later

    Source: cisa.gov/news-events/alerts/20

    💬 How fast is your patch cycle?
    Follow @technadu

    #InfoSec #CyberSecurity #KEV

  19. New KEV added 🚨
    CVE-2026-34197 (Apache ActiveMQ)
    • Active exploitation confirmed
    • High-risk entry point
    KEV = patch now, not later

    Source: cisa.gov/news-events/alerts/20

    💬 How fast is your patch cycle?
    Follow @technadu

    #InfoSec #CyberSecurity #KEV

  20. New KEV added 🚨
    CVE-2026-34197 (Apache ActiveMQ)
    • Active exploitation confirmed
    • High-risk entry point
    KEV = patch now, not later

    Source: cisa.gov/news-events/alerts/20

    💬 How fast is your patch cycle?
    Follow @technadu

    #InfoSec #CyberSecurity #KEV

  21. CISA adds CVE-2026-1340 (Ivanti EPMM) to KEV ⚠️

    Active exploitation confirmed
    Known vulns = real attack surface
    Are KEVs in your patch priority?

    Source: cisa.gov/news-events/alerts/20

    💬 Engage
    🔔 Follow TechNadu

    #InfoSec #KEV #CISA #VulnMgmt

  22. CISA adds CVE-2026-1340 (Ivanti EPMM) to KEV ⚠️

    Active exploitation confirmed
    Known vulns = real attack surface
    Are KEVs in your patch priority?

    Source: cisa.gov/news-events/alerts/20

    💬 Engage
    🔔 Follow TechNadu

    #InfoSec #KEV #CISA #VulnMgmt

  23. CISA adds CVE-2026-1340 (Ivanti EPMM) to KEV ⚠️

    Active exploitation confirmed
    Known vulns = real attack surface
    Are KEVs in your patch priority?

    Source: cisa.gov/news-events/alerts/20

    💬 Engage
    🔔 Follow TechNadu

    #InfoSec #KEV #CISA #VulnMgmt

  24. CISA adds CVE-2026-1340 (Ivanti EPMM) to KEV ⚠️

    Active exploitation confirmed
    Known vulns = real attack surface
    Are KEVs in your patch priority?

    Source: cisa.gov/news-events/alerts/20

    💬 Engage
    🔔 Follow TechNadu

    #InfoSec #KEV #CISA #VulnMgmt

  25. CISA KEV heute updated (08.04., 17:27 UTC) – frische Einträge droppen. ZDI Upcoming: 7 neue CANs (Oracle x2, OriginLab, Linux, BlueZ etc., CVSS 7+). Keine Published seit Proteus-0-Days. Details KEV: github.com/cisagov/kev-data/co Patched? #infosec #ZeroDay #KEV

  26. 📰 CISA KEV Alert: Actively Exploited Flaws in Langflow AI Framework and Trivy Scanner

    📢 CISA KEV UPDATE: Two flaws now under active exploitation! A critical RCE in Langflow AI framework (CVE-2026-33017) and a supply-chain attack via Trivy scanner (CVE-2026-33634). Patch now! ⚠️ #KEV #CyberSecurity #RCE

    🔗 cyber.netsecops.io/articles/ci

  27. 📰 CISA KEV Alert: Actively Exploited Flaws in Langflow AI Framework and Trivy Scanner

    📢 CISA KEV UPDATE: Two flaws now under active exploitation! A critical RCE in Langflow AI framework (CVE-2026-33017) and a supply-chain attack via Trivy scanner (CVE-2026-33634). Patch now! ⚠️ #KEV #CyberSecurity #RCE

    🔗 cyber.netsecops.io/articles/ci

  28. CISA adds CVE-2026-33634 (Trivy) to KEV - active exploitation confirmed.

    If it’s in KEV, it’s already a threat.

    Source: cisa.gov/news-events/alerts/20

    💬 Is KEV your top patch priority?
    🔔 Follow TechNadu

    #InfoSec #KEV #CyberSecurity

  29. CISA adds CVE-2026-33634 (Trivy) to KEV - active exploitation confirmed.

    If it’s in KEV, it’s already a threat.

    Source: cisa.gov/news-events/alerts/20

    💬 Is KEV your top patch priority?
    🔔 Follow TechNadu

    #InfoSec #KEV #CyberSecurity

  30. CISA adds CVE-2026-33634 (Trivy) to KEV - active exploitation confirmed.

    If it’s in KEV, it’s already a threat.

    Source: cisa.gov/news-events/alerts/20

    💬 Is KEV your top patch priority?
    🔔 Follow TechNadu

    #InfoSec #KEV #CyberSecurity

  31. CISA adds CVE-2026-33634 (Trivy) to KEV - active exploitation confirmed.

    If it’s in KEV, it’s already a threat.

    Source: cisa.gov/news-events/alerts/20

    💬 Is KEV your top patch priority?
    🔔 Follow TechNadu

    #InfoSec #KEV #CyberSecurity

  32. So are we going to get #ICE goons to help out with #CISA too?

    I’m sure they’d be just as great at the #KEV

  33. So are we going to get #ICE goons to help out with #CISA too?

    I’m sure they’d be just as great at the #KEV

  34. So are we going to get #ICE goons to help out with #CISA too?

    I’m sure they’d be just as great at the #KEV

  35. So are we going to get #ICE goons to help out with #CISA too?

    I’m sure they’d be just as great at the #KEV

  36. So are we going to get #ICE goons to help out with #CISA too?

    I’m sure they’d be just as great at the #KEV

  37. 📰 CISA KEV Catalog Updated: Federal Agencies Must Patch Exploited Flaws in Apple, Laravel, Craft CMS

    📢 CISA KEV UPDATE: Actively exploited flaws in Apple visionOS (CVE-2026-28217), Laravel (CVE-2024-4671), & Craft CMS (CVE-2026-25487) added to catalog. Federal agencies must patch by April 12. All orgs urged to patch NOW! ⚠️ #KEV #CISA

    🔗 cyber.netsecops.io/articles/ci

  38. gcve-eu-kev updated — a CISA KEV and ENISA CNW/EUVD to GCVE BCP-07 converter.

    It now also includes a generic RSS/Atom exporter for any GCVE KEV BCP-07 feed.

    @gcve

    #cybersecurity #gcve #kev #cve #vulnerability #vulnerabilitymanagement

    🔗 github.com/gcve-eu/gcve-eu-kev
    🔗 gcve.eu/bcp/gcve-bcp-07/

  39. gcve-eu-kev updated — a CISA KEV and ENISA CNW/EUVD to GCVE BCP-07 converter.

    It now also includes a generic RSS/Atom exporter for any GCVE KEV BCP-07 feed.

    @gcve

    #cybersecurity #gcve #kev #cve #vulnerability #vulnerabilitymanagement

    🔗 github.com/gcve-eu/gcve-eu-kev
    🔗 gcve.eu/bcp/gcve-bcp-07/

  40. gcve-eu-kev updated — a CISA KEV and ENISA CNW/EUVD to GCVE BCP-07 converter.

    It now also includes a generic RSS/Atom exporter for any GCVE KEV BCP-07 feed.

    @gcve

    #cybersecurity #gcve #kev #cve #vulnerability #vulnerabilitymanagement

    🔗 github.com/gcve-eu/gcve-eu-kev
    🔗 gcve.eu/bcp/gcve-bcp-07/

  41. gcve-eu-kev updated — a CISA KEV and ENISA CNW/EUVD to GCVE BCP-07 converter.

    It now also includes a generic RSS/Atom exporter for any GCVE KEV BCP-07 feed.

    @gcve

    #cybersecurity #gcve #kev #cve #vulnerability #vulnerabilitymanagement

    🔗 github.com/gcve-eu/gcve-eu-kev
    🔗 gcve.eu/bcp/gcve-bcp-07/

  42. gcve-eu-kev updated — a CISA KEV and ENISA CNW/EUVD to GCVE BCP-07 converter.

    It now also includes a generic RSS/Atom exporter for any GCVE KEV BCP-07 feed.

    @gcve

    #cybersecurity #gcve #kev #cve #vulnerability #vulnerabilitymanagement

    🔗 github.com/gcve-eu/gcve-eu-kev
    🔗 gcve.eu/bcp/gcve-bcp-07/

  43. CISA flips the switch: Ivanti EPM (CVE-2026-1603) is under active exploit. A low-complexity XSS allows total authentication bypass with zero user interaction. If your EPM is internet-facing, the "Master Key" is compromised. Get the Strategic Arsenal now. #CyberSecurity #Ivanti #KEV

    thecybermind.co/2026/03/11/dec

  44. CISA flips the switch: Ivanti EPM (CVE-2026-1603) is under active exploit. A low-complexity XSS allows total authentication bypass with zero user interaction. If your EPM is internet-facing, the "Master Key" is compromised. Get the Strategic Arsenal now. #CyberSecurity #Ivanti #KEV

    thecybermind.co/2026/03/11/dec

  45. CISA added 3 exploited vulnerabilities to the KEV catalog:
    • Omnissa Workspace ONE – SSRF
    • SolarWinds Web Help Desk – Deserialization flaw
    • Ivanti Endpoint Manager – Auth bypass
    KEV flaws remain top attack vectors.

    Source: cisa.gov/news-events/alerts/20

    Follow TechNadu for infosec updates.

    #Infosec #KEV #CyberSecurity