Skip to content

Daily Threat Intel

Cyber threat intelligence for security leaders

Menu
  • Vulnerabilities
  • Malware
  • Breaches
  • Enterprise
  • Supply Chain
  • Emerging Threats
  • Cloud
  • About us
Menu

Category: Emerging Threats

Researchers Report Attacks Targeting Max Severity Bug in Progress Software’s WS_FTP

Posted on October 2, 2023

Image source: Shutterstock The in-the-wild exploit activity could be a harbinger of things to come. As happened with a zero-day bug in Progress Software’s MOVEit file transfer software earlier this year, attackers…

Share

What You Need to Know About the Critical New Bugs in Progress Software’s WS_FTP Server

Posted on September 29, 2023

Image source: Shutterstock Based on the extensive targeting of the previous bug in the company’s MOVEit product, it’s safe to bet attacks targeting the WS_FTP flaws are imminent. A maximum severity vulnerability…

Share

PoC Exploit Chain for Critical SharePoint Vulns Heightens Attack Risks

Posted on September 28, 2023

Orgs should immediately apply the patches that Microsoft issued for the flaws if they haven’t done so already. Researchers at Singapore-based StarLabs have released details of a chained remote code execution exploit…

Share

Australian Federal Police say Russian threat actor behind Medibank breach

Posted on November 11, 2022

“We will be holding talks with Russian law enforcement about these individuals,” AFP Commissioner says [300 words]. What: The Australian Federal Police (AFP) has identified the threat actor behind the catastrophic attack…

Share

RomCom threat actor using spoofed SolarWinds, KeePass apps to distribute RAT

Posted on November 3, 2022

Targets have been Ukraine-based but IT companies, food brokers, and food manufacturers in the U.S., Brazil, and the Philippines are also in its crosshairs, BlackBerry says [300 words]. What: The operators of…

Share

Five useful lists and tools for identifying resources with vulnerable OpenSSL in them

Posted on October 31, 2022

The OpenSSL project team will release a new version of the OpenSSL library (version 3.0.7) on Tuesday to address a critical vulnerability in version 3.0 to 3.6 of the widely used open…

Share

Four quick things to know about the critical bug in OpenSSL that will be disclosed Nov.1

Posted on October 31, 2022

The OpenSSL project team will release a new version of the OpenSSL library (version 3.0.7) on Tuesday to address a critical vulnerability in version 3.0 to 3.6 of the widely used open…

Share

Critical Remote Code Execution Vulnerability in Apache Commons Text

Posted on October 17, 2022

Is this the next Log4J? [297 words] What: The Apache Foundation appears to have quietly fixed a critical remote code execution (RCE) in Apache Common Text versions 1.5 through 1.9. The vulnerability…

Share

More than 29K+ Fortinet systems in US have admin login screen exposed to the Internet—and two other updates on CVE-2022-40684

Posted on October 14, 2022

Here’s the latest on the authentication bypass flaw (CVE-2022-40684) in FortiOS, FortiProxy, and FortiSwitchManager [300 words] As of October 13, 2022, there were 24,924 servers in the US and 196,668 units globally,…

Share

CISA ups the ante on asset discovery and vulnerability detection on federal networks

Posted on October 6, 2022

Key takeaway: If you aren’t already doing continuous automated asset discovery and vulnerability enumeration on discovered assets, now is a good time to get started. [259 words] What: The US Cybersecurity and…

Share

Posts pagination

Previous 1 2 3 4 Next
  • Exploits Turn Microsoft Defender Against Itself
  • Project Glasswing FAQ: A Look at Anthropic’s Bid to Secure the Internet
  • 2 Zero-Days and 18 Other High Risk Vulns in Microsoft’s April Update
  • Criminals Weaponize Microsoft’s Device Code Authentication in Widescale Phishing Operation
  • Iran-Linked Actors Disrupt Rockwell/Allen Bradley PLCs
©2026 Daily Threat Intel | Design: Newspaperly WordPress Theme