Skip to content

Daily Threat Intel

Cyber threat intelligence for security leaders

Menu
  • Vulnerabilities
  • Malware
  • Breaches
  • Enterprise
  • Supply Chain
  • Emerging Threats
  • Cloud
  • About us
Menu

Category: Vulnerabilities

Microsoft looking into reports of a third Exchange Server zero-day?

Posted on October 12, 2022

Security vendor that discovered bug recommends organizations limit IIS app operating privileges on Exchange Server [297 words] What: Microsoft apparently is looking into a report it received from South Korean cybersecurity vendor…

Share

Here are the highlights of Microsoft’s October 2022 Security Update

Posted on October 11, 2022

Microsoft released fixes for a total of 84 CVEs across its products [300 words]. One of the vulnerabilities that Microsoft patched today is a zero-day that is being actively exploited: Windows COM+…

Share

Update: Attackers actively exploiting recently disclosed authentication bypass vulnerability in FortiOS, FortiProxy and FortiSwitchManager

Posted on October 11, 2022

Key takeaway:  Adversaries can exploit the vulnerability remotely to gain full control of affected systems [297 words]. What: Attackers have begun actively exploiting a critical authentication bypass vulnerability (CVE-2022-40684) that Fortinet privately…

Share

Critical vulnerability puts vm2 JavaScript sandbox environments at risk of remote code execution attack

Posted on October 11, 2022

Key takeaway: “Although sandboxes are meant to run untrusted code within your application, you shouldn’t automatically assume that they are safe.”—Oxeye [260 words] What: Organizations using JavaScript sandbox vm2 should immediately update…

Share

GLPI warns of massive exploit activity targeting one of two critical flaws disclosed in Sept.

Posted on October 10, 2022

Key takeaway: Update now to latest versions of the IT asset management software. If you can’t, implement GLPIs recommended mitigation. Attackers are targeting the flaw to execute arbitrary code on insecure servers…

Share

Log4j vuln tops list of CVEs that the US govt says Chinese groups are actively exploiting

Posted on October 7, 2022

Key takeaway: Ensure that you have patched these vulnerabilities—or have mitigations for them especially if your organization is in the technology, telecommunications, defense industrial base and other critical infrastructure sectors. [216 words]…

Share

Fortinet warns of critical severity remotely executable authentication bypass vulnerability

Posted on October 7, 2022

Key takeaway: Fortinet products are a popular attacker target. Update now if you have affected versions of FortiOS and FortiProxy in your environment. If you cannot patch immediately disable Internet facing HTTPS…

Share

CISA ups the ante on asset discovery and vulnerability detection on federal networks

Posted on October 6, 2022

Key takeaway: If you aren’t already doing continuous automated asset discovery and vulnerability enumeration on discovered assets, now is a good time to get started. [259 words] What: The US Cybersecurity and…

Share

Here’s what you need to know about the new (actively exploited) Microsoft Exchange Server 0-Days: CVE-2022-41040 and CVE-2022-41082

Posted on October 6, 2022

Latest update: Microsoft has updated its mitigation for the flaw. Implement it. [265 words] What: Two zero-day vulnerabilities exist in Microsoft Exchange Server 2013, 2016 and 2019. One of the flaws CVE-2022-41040,…

Share

Newly disclosed vulnerability in PHP package repository highlights growing software supply chain risks

Posted on October 6, 2022

Key takeaway: Attackers are increasingly trying to infiltrate software development environments via malicious and poisoned packages on public code repositories. Robust SBOM and SCA practices are key to mitigating the threat [289…

Share

Posts pagination

Previous 1 … 5 6
  • CISA Mandates Immediate Action on Cisco Firewall Backdoor
  • CISA Adds 3 Cisco SD-WAN Manager Flaws to Actively Exploited List
  • Exploits Turn Microsoft Defender Against Itself
  • Project Glasswing FAQ: A Look at Anthropic’s Bid to Secure the Internet
  • 2 Zero-Days and 18 Other High Risk Vulns in Microsoft’s April Update
©2026 Daily Threat Intel | Design: Newspaperly WordPress Theme