Skip to content

Daily Threat Intel

Cyber threat intelligence for security leaders

Menu
  • Vulnerabilities
  • Malware
  • Breaches
  • Enterprise
  • Supply Chain
  • Emerging Threats
  • Cloud
  • About us
Menu

Category: Vulnerabilities

2 Exploited and 3 Publicly Known Bugs in Microsoft’s Oct. Update to Patch Now

Posted on October 8, 2024

Image source: : Shutterstock Microsoft’s relatively moderate severity rating for the bugs belie the threat they present At least five of the 117 CVEs for which Microsoft released a patch this week…

Share

New Vuln Enables Admin Access on Domain-Joined ESXi Hypervisors

Posted on July 30, 2024

Image Source: Shutterstock Ransomware attackers are leveraging CVE-2024-37085 to drop Black Basta, Akira on vulnerable systems, Microsoft says. Ransomware operators are exploiting an authentication bypass vulnerability in ESXi hypervisors to gain full…

Share

Mandiant Updates Guidance for Protecting Against Ivanti Vulnerabilities

Posted on February 1, 2024

Image source: Shutterstock Following its disclosure of two new zero-days Jan 31, Ivanti too has updated its mitigation file. Customers who applied previous mitigation would need re-apply it to address new flaws….

Share

Critical Vulnerability in Jenkins CLI Could Enable Remote Code Execution

Posted on January 24, 2024

Image source: Shutterstock CVE-2024-23897 is the most serious of 12 vulnerabilities that the Jenkins team disclosed on Jan 24. The Jenkins infrastructure team has issued a patch for a critical remote code…

Share

CVE-2024-0204 in GoAnywhere MFT is a Ticking Time Bomb

Posted on January 24, 2024

Image source: Shutterstock More than 96% of GoAnywhere MFT assets that security vendor Tenable observed on Jan 23 were vulnerable. Mass attacks could soon begin against a critical authentication bypass flaw in…

Share

China’s UTA0178 Threat Group Backdoors 2,100 Ivanti VPN Appliances Via Recently Disclosed 0-Days

Posted on January 18, 2024

Image Source: Shutterstock Attacker stealing sensitive system data, tampering with built-in Integrity Check to hide signs of malicious activity. Multiple threat actors have joined Chinese advanced persistent threat group UTA0178 in targeting…

Share

Exploit Available for Docker Versions of ownCloud Affected by Recent Max. Severity Bug

Posted on December 1, 2023

Image credit: Shutterstock More than 4,000 ownCloud instances remain exposed to attack via CVE-2023-49103; CISA adds vuln to KEV catalog. Attack surface management vendor Onyphe has discovered a total of 4,129 Internet-connected…

Share

LockBit Ransomware Operators Targeting CitrixBleed in Coordinated Attacks

Posted on November 14, 2023

Image source: Shutterstock China’s ICBC, Boeing, Australian logistics giant DP World, major law firm among known victims so far; More than 5,000 organizations worldwide remain unpatched and vulnerable to CVE-2023-4966 Multiple LockBit…

Share

Atlassian Discloses Critical Vulnerability in Confluence Data Center & Server

Posted on October 31, 2023

Image source: Shutterstock Customers vulnerable to “significant data loss” if attackers exploit CVE-2023-22518, company CISO warns. Atlassian wants customers of its Confluence Data Center and Server to immediately upgrade to new versions…

Share

Patch for Cisco Zero Day Bug to Become Available Oct. 22

Posted on October 20, 2023

Image source: Shutterstock Company’s investigation shows attackers actually leveraged two previously unknown bugs, not one, as assumed. There are two important new developments around CVE-2023-20198, the widely exploited zero-day bug in the…

Share

Posts pagination

Previous 1 2 3 … 6 Next
  • CISA Mandates Immediate Action on Cisco Firewall Backdoor
  • CISA Adds 3 Cisco SD-WAN Manager Flaws to Actively Exploited List
  • Exploits Turn Microsoft Defender Against Itself
  • Project Glasswing FAQ: A Look at Anthropic’s Bid to Secure the Internet
  • 2 Zero-Days and 18 Other High Risk Vulns in Microsoft’s April Update
©2026 Daily Threat Intel | Design: Newspaperly WordPress Theme