Vulnerabilities CISA Warns of Exploited Adobe ColdFusion, Windows Vulnerabilities CISA has warned organizations that two vulnerabilities affecting Adobe ColdFusion and Windows have been exploited in the wild. Eduard KovacsDecember 17, 2024
Vulnerabilities Chinese Hackers Exploiting Critical Vulnerability in Array Networks Gateways CISA warns about attacks exploiting CVE-2023-28461, a critical vulnerability in Array Networks AG and vxAG secure access gateways. Ionut ArghireNovember 26, 2024
Vulnerabilities CISA Warns of Progress Kemp LoadMaster Vulnerability Exploitation CISA is warning organizations that CVE-2024-1212, a Progress Kemp LoadMaster OS command injection vulnerability, is being exploited in attacks. Eduard KovacsNovember 20, 2024
Malware & Threats Citrix, Cisco, Fortinet Zero-Days Among 2023’s Most Exploited Vulnerabilities Most of the top frequently exploited vulnerabilities in 2023 were initially exploited as zero-days, according to data from government agencies. Ionut ArghireNovember 13, 2024
Vulnerabilities Palo Alto Networks Expedition Vulnerability Exploited in Attacks, CISA Warns CISA has added a Palo Alto Networks Expedition flaw tracked as CVE-2024-5910 to its Known Exploited Vulnerabilities Catalog. Eduard KovacsNovember 8, 2024
Malware & Threats Fortinet Confirms Zero-Day Exploit Targeting FortiManager Systems Fortinet confirms zero-day exploits hitting critical (CVSS severity score 9.8/10) remote code execution bug in the FortiManager platform. Ryan NaraineOctober 23, 2024
Vulnerabilities CISA Flags Critical SolarWinds Web Help Desk Bug for In-the-Wild Exploitation CISA warns that a critical-severity hardcoded credentials vulnerability in SolarWinds Web Help Desk is exploited in attacks. Ionut ArghireOctober 16, 2024
Vulnerabilities Organizations Warned of Exploited Fortinet FortiOS Vulnerability CISA has added a FortinetFortiOS vulnerability tracked as CVE-2024-23113 to its Known Exploited Vulnerabilities (KEV) catalog. Ionut ArghireOctober 10, 2024
Malware & Threats Stealthy ‘Perfctl’ Malware Infects Thousands of Linux Servers The perfctl malware has been targeting vulnerabilities and misconfigurations in millions of Linux systems, likely infecting thousands. Ionut ArghireOctober 7, 2024
Vulnerabilities Organizations Warned of Exploited SAP, Gpac and D-Link Vulnerabilities CISA warns that years-old vulnerabilities in SAP Commerce, Gpac framework, and D-Link DIR-820 routers are exploited in the wild. Ionut ArghireOctober 1, 2024
Malware & Threats CISA: Oracle Vulnerabilities From ‘Miracle Exploit’ Targeted in Attacks CISA is warning organizations that two Oracle vulnerabilities tracked as CVE-2022-21445 and CVE-2020-14644 are being exploited in the wild. Eduard KovacsSeptember 19, 2024
Network Security DrayTek Vulnerabilities Added to CISA KEV Catalog Exploited in Global Campaign Two DrayTek vulnerabilities added by CISA to its KEV catalog have been exploited by multiple threat groups to steal data from organizations worldwide. Eduard KovacsSeptember 5, 2024
Vulnerabilities Second Apache OFBiz Vulnerability Exploited in Attacks CISA is warning organizations that a second Apache OFBiz flaw is being exploited in the wild shortly after the release of PoC exploits. Eduard KovacsAugust 28, 2024
Vulnerabilities CISA Warns of Exploited Vulnerabilities Impacting Dahua Products CISA warns that attackers are exploiting two critical-severity authentication bypass vulnerabilities impacting multiple Dahua products. Ionut ArghireAugust 22, 2024
Vulnerabilities Organizations Warned of Exploited GeoServer Vulnerability CISA says it has evidence that a recent critical-severity vulnerability in GeoServer is exploited in the wild. Ionut ArghireJuly 16, 2024
Vulnerabilities CISA Warns of Exploited GeoServer, Linux Kernel, and Roundcube Vulnerabilities CISA on Wednesday warned that three older flaws in GeoServer, Linux kernel, and Roundcube webmail are exploited in the wild. Ionut ArghireJune 27, 2024
Malware & Threats CISA Warns of Progress Telerik Vulnerability Exploitation CISA urges federal agencies to apply mitigations for an exploited Progress Telerik vulnerability as soon as possible. Ionut ArghireJune 14, 2024
Malware & Threats CISA Warns of Attacks Exploiting Old Oracle WebLogic Vulnerability CISA has added an old Oracle WebLogic flaw tracked as CVE-2017-3506 to its known exploited vulnerabilities catalog. Eduard KovacsJune 4, 2024
Vulnerabilities CISA Warns of Exploited Linux Kernel Vulnerability CISA instructs federal agencies to mitigate CVE-2024-1086, a Linux kernel flaw leading to privilege escalation. Ionut ArghireMay 31, 2024
Government CISA Warns of Attacks Exploiting NextGen Healthcare Mirth Connect Flaw CISA has added CVE-2023-43208, an unauthenticated remote code execution vulnerability, to its KEV catalog. Eduard KovacsMay 21, 2024