sector entity

technology

86 source-linked records in the current knowledge graph.

unknown

Contagious Interview malware in SVG images: DPRK campaign

A DPRK-aligned threat group is targeting developers through fake job postings and coding challenges in a campaign tracked as REF9403. Attackers post fake job offers in developer forums, then send trojanized repositories containing fully functional e-commerce projects with malicious code hidden using steganography inside SVG flag images. When developers run these projects, the malware deploys four-stage payloads aligned with OTTERCOOKIE: a browser credential and cryptocurrency wallet stealer, a file exfiltration module, a Socket.IO-based remote access trojan, and a clipboard stealer. The campaign was discovered after targeting Elastic's community Slack workspace. Multiple trojanized repositories were found with zero antivirus detections at the time of discovery, demonstrating the sophistication of this supply chain attack vector against software developers.

beavertailcryptocurrency wallet theftdeveloper targeting
AlienVault OTX ↗ · unattributed attribution · 14 IOCs
unknown

ACR Stealer: Two observed intrusion chains amid increased threat activity

Between late April and mid-June 2026, Microsoft observed heightened ACR Stealer activity targeting enterprise environments through ClickFix social engineering lures. This information-stealing malware, associated with Amatera Stealer rebranding and offered as malware-as-a-service, deployed through two distinct campaigns. The first utilized WebDAV-delivered payloads with Python loaders and blockchain-based command-and-control resolution. The second employed a fileless approach using MSHTA and steganography-concealed payloads within images. Both campaigns harvested browser credentials, authentication tokens, and sensitive documents from compromised systems. Threat actors leveraged obfuscated PowerShell scripts, scheduled task persistence, and in-memory execution techniques to evade detection. Notable tactics included masquerading as legitimate software updates, utilizing Windows DPAPI for credential decryption, and targeting PDF and Microsoft 365 documents. The blockchain dead-drop techni

acr stealeramatera stealerblockchain c2
AlienVault OTX ↗ · unattributed attribution · 16 IOCs
unknown

Novel Starland RAT and bespoke WLDR C2 implant deployed in financially motivated campaign

A sophisticated Russian-speaking financially motivated adversary designated UAT-11795 has been conducting malicious operations targeting users in the United States and Europe since June 2025. The campaign delivers a Python-based remote access tool called Starland RAT and a PowerShell-based command-and-control memory implant known as the WLDR agent. The actor distributes trojanized installers disguised as legitimate software including MobaXterm, WebEx, Zoom, DBeaver, and FACEIT through likely ClickFix social engineering techniques. The operation targets victims' credentials and cryptocurrency wallet assets while establishing persistent connections for additional payload delivery. Alternative payloads include CastleStealer and Remcos RAT. The infrastructure utilizes distributed staging and C2 domains, Telegram bots for notifications, and a Polygon smart contract as a fallback mechanism for C2 domain resolution. The WLDR agent features encrypted beaconing, task queuing, and a Runspace exe

castlestealerclickfixcredential harvesting
AlienVault OTX ↗ · unattributed attribution · 49 IOCs
unknown

June 2026 Infostealer Trend Report

During June 2026, multiple infostealer families including Remus, ACRStealer, LummaC2, and Vidar were distributed through SEO poisoning techniques, disguised as illegal software such as cracks and keygens. Attacks utilized EXE files (84.5%) and DLL side-loading (15.5%) methods, with distribution primarily through Mediafire, Mega, and cloud storage platforms. Microsoft Corporation was the most frequently impersonated entity. MacOS environments were targeted through ClickFix techniques and malicious Bash scripts, with one variant dynamically obtaining C2 addresses via Polygon smart contracts. Email-based campaigns distributed AgentTesla and DarkCloud through compressed attachments, with both variants exfiltrating data via SMTP. The stolen credentials pose significant risks for dark web trading and secondary attacks.

acrstealeragentteslaamos
AlienVault OTX ↗ · unattributed attribution · 12 IOCs
unknown

OkoBot framework infection chain

In January 2026, researchers identified a sophisticated malware framework dubbed OkoBot that targets cryptocurrency users through a multi-stage infection chain. The campaign begins with TookPS PowerShell scripts delivered via ClickFix attacks or fake software on GitHub. An automated SSH bot deploys over 20 malicious modules including HDUtil launcher, browser extension injectors installing Rilide stealer, and specialized tools like SeedHunter for wallet seed phrase theft and OkoSpyware for window capture. The framework uses VMProtect obfuscation, UAC bypass techniques, and maintains persistence through RDP access and scheduled tasks. Victims span more than 25 countries with concentrations in Brazil, Vietnam, Canada, Mexico, and Turkey. Attribution suggests Russian-speaking threat actors based on geoblocking patterns and Russian language artifacts.

browser extensioncryptocurrency thefthdutil
AlienVault OTX ↗ · unattributed attribution · 21 IOCs
unknown

Public and Private Medical Community Targeted by Threat Actor Pursuing Artificial Intelligence, Cyber, Medical, and National Defense Research

A sophisticated espionage campaign attributed to UNC6508, a China-nexus threat actor, targeted North American academic, medical, and military research institutions for over a year. The adversary exploited REDCap servers, deployed custom INFINITERED malware to harvest credentials, and maintained persistent access through trojanized legitimate files that survived software upgrades. After remaining undetected for more than a year, the threat actor pivoted to administrative accounts and created malicious content compliance rules to silently exfiltrate emails containing defense intelligence, Indo-Pacific command operations, artificial intelligence research, uncrewed vehicle systems, cyber programs, and medical research data. The operation employed sophisticated techniques including obfuscation networks routing through US-based infrastructure, compromised routers, and dedicated exfiltration accounts, demonstrating advanced operational security aligned with strategic intelligence collection r

china-nexuscontent compliance abusecredential harvesting
AlienVault OTX ↗ · unattributed attribution · 7 IOCs
unknown

LabubaRAT: A Rust Based Remote Access Tool Masquerading as NVIDIA Software

A previously undocumented remote access tool named LabubaRAT has been identified, masquerading as NVIDIA software through fake metadata and runtime artifacts. This Rust-based malware creates persistent footholds enabling hands-on operator activity including host profiling, security tool identification, command execution, file transfers, screenshot capture, and traffic proxying. The implant supports multiple communication methods including HTTPS polling, WebView2-based communication, and DNS tunneling. It uses a configurable framework model with organization, group, server, and API key parameters suggesting a Malware-as-a-Service platform. The malware maintains local state in SQLite databases and provides comprehensive remote access capabilities including PowerShell and JavaScript execution, SOCKS5 proxy support, and user-level persistence through registry autoruns. Infrastructure analysis revealed LabubaPanel branding with associated command and control servers hosted on German provide

dns tunnelinglabubapanellabubarat
AlienVault OTX ↗ · unattributed attribution · 8 IOCs
unknown

The Devil, Eight Million Emails, and a Whole Lot of Milk | Phishing Stager Exposed

On May 15, 2026, Huntress agents detected an intrusion where threat actors compromised a terminal server to stage a massive phishing campaign rather than deploy ransomware. The attacker used legitimate bulk email software (Gammadyne Mailer) with a project file named 'dracii' (Romanian for 'the devils') and six recipient lists containing 8,894,920 email addresses. Operating from Romanian IP addresses, the actor impersonated UK pharmacy chain Boots through a fake customer satisfaction survey designed to harvest personal and payment card data. The phishing kit was hosted on a compromised Bolivian government website (ipelc.gob.bo), which Huntress reported to Bolivia's national CSIRT. The campaign used direct-to-MX delivery to bypass mail relays, with the mailer configured to send from 666 threads simultaneously. Evidence suggests this Romanian operator has been running multiple UK-targeting campaigns since at least July 2025, rotating between retail, tax, and cryptocurrency themes.

bulk email abusecompromised government websitecredential theft
AlienVault OTX ↗ · unattributed attribution · 11 IOCs
unknown

CrashStealer: C++ macOS Infostealer Posing as Crash Reporter

A newly discovered macOS infostealer, implemented in native C++, impersonates Apple's crash-reporting framework to harvest sensitive data. The malware is distributed through a signed and notarized dropper application that bypasses Gatekeeper, then downloads and installs the payload from attacker infrastructure. The stealer validates victim passwords locally using dscl, unlocks the login keychain, and collects browser credentials, cryptocurrency wallet extensions, password manager data, and keychain material. Collected data is encrypted using AES-GCM before being packaged into hidden ZIP archives and exfiltrated to a command-and-control server. The malware establishes persistence by copying itself to a hidden directory and installing a LaunchAgent. It employs control-flow flattening, encrypted strings, and anti-debugging techniques to resist analysis. The campaign uses GitHub for initial staging and multiple fake collaboration software domains as lures.

crashstealerinfostealermacos
AlienVault OTX ↗ · unattributed attribution · 33 IOCs
unknown

Threat Actors Achieve Persistence After SQL Injection

Threat actors gaining initial access through SQL injection exploited a web application vulnerability in a technology sector organization. After compromising an MSSQL instance via inadequate input validation, the attackers deployed base64-encoded PowerShell scripts to conduct reconnaissance using tasklist commands and exfiltrated results to an external server. They established persistence by enabling Remote Desktop Services, creating an administratively privileged user account named adminweb2$, and disabling Windows Defender. The attackers installed BadIIS modules for SEO fraud, deployed XMRig cryptocurrency miner with hidden file attributes, and utilized service creation tools. Multiple PowerShell scripts and batch files were downloaded throughout the attack to facilitate various malicious operations and maintain access.

badiisbadiis modulescncrypt protect
AlienVault OTX ↗ · unattributed attribution · 2 IOCs
high

CVE-2026-20131: Cisco Secure Firewall Management Center (FMC) Software and Cisco Security Cloud Control (SCC) Firewall Management Deserialization of Untrusted Data Vulnerability

Cisco Secure Firewall Management Center (FMC) Software and Cisco Security Cloud Control (SCC) Firewall Management contain a deserialization of untrusted data vulnerability in the web-based management interface that could allow an unauthenticated, remote attacker to execute arbitrary Java code as root on an affected device. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2026-20131EPSS 27.6%CiscoSecure Firewall Management Center (FMC)
CISA KEV ↗ · unattributed attribution
high

CVE-2021-22681: Rockwell Multiple Products Insufficient Protected Credentials Vulnerability

Multiple Rockwell products contain an insufficient protected credentials vulnerability. Studio 5000 Logix Designer software may allow a key to be discovered. This key is used to verify Logix controllers are communicating with Rockwell Automation design software. If successfully exploited, this vulnerability could allow an unauthorized application to connect with Logix controllers. To leverage this vulnerability, an unauthorized user would require network access to the controller. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2021-22681EPSS 25.5%Multiple ProductsRockwell
CISA KEV ↗ · unattributed attribution
high

CVE-2025-20393: Cisco Multiple Products Improper Input Validation Vulnerability

Cisco Secure Email Gateway, Secure Email, AsyncOS Software, and Web Manager appliances contains an improper input validation vulnerability that allows threat actors to execute arbitrary commands with root privileges on the underlying operating system of an affected appliance. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2025-20393EPSS 29.5%CiscoMultiple Products
CISA KEV ↗ · unattributed attribution
high

CVE-2025-20352: Cisco IOS and IOS XE Software SNMP Denial of Service and Remote Code Execution Vulnerability

Cisco IOS and IOS XE contains a stack-based buffer overflow vulnerability in the Simple Network Management Protocol (SNMP) subsystem that could allow for denial of service or remote code execution. A successful exploit could allow a low-privileged attacker to cause the affected system to reload, resulting in a DoS condition, or allow a high-privileged attacker to execute arbitrary code as the root user and obtain full control of the affected system. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2025-20352EPSS 37.6%CiscoIOS and IOS XE
CISA KEV ↗ · unattributed attribution
high

CVE-2025-20362: Cisco Secure Firewall Adaptive Security (ASA) Appliance and Secure Firewall Threat Defense (FTD) Missing Authorization Vulnerability

Cisco Secure Firewall Adaptive Security (ASA) Appliance and Secure Firewall Threat Defense (FTD) Software VPN Web Server contain a missing authorization vulnerability. This vulnerability could be chained with CVE-2025-20333. Required action: The KEV due date refers to the deadline by which FCEB agencies are expected to review and begin implementing the guidance outlined in Emergency Directive (ED) 25-03 (URL listed below in Notes). Agencies must follow the mitigation steps provided by CISA (URL listed below in Notes) and vendor’s instructions (URL listed below in Notes). Adhere to the applicable BOD 22-01 guidance for cloud services or discontinue use of the product if mitigations are not available.

CVE-2025-20333CVE-2025-20362EPSS 85.5%CiscoSecure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense
CISA KEV ↗ · unattributed attribution
high

CVE-2025-20333: Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) Buffer Overflow Vulnerability

Cisco Secure Firewall Adaptive Security (ASA) Appliance and Secure Firewall Threat Defense (FTD) Software VPN Web Server contain a buffer overflow vulnerability that allows for remote code execution. This vulnerability could be chained with CVE-2025-20362. Required action: The KEV due date refers to the deadline by which FCEB agencies are expected to review and begin implementing the guidance outlined in Emergency Directive (ED) 25-03 (URL listed below in Notes). Agencies must follow the mitigation steps provided by CISA (URL listed below in Notes) and vendor’s instructions (URL listed below in Notes). Adhere to the applicable BOD 22-01 guidance for cloud services or discontinue use of the product if mitigations are not available.

CVE-2025-20333CVE-2025-20362EPSS 85.5%CiscoSecure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense
CISA KEV ↗ · unattributed attribution
high

CVE-2025-24993: Microsoft Windows NTFS Heap-Based Buffer Overflow Vulnerability

Microsoft Windows New Technology File System (NTFS) contains a heap-based buffer overflow vulnerability that allows an unauthorized attacker to execute code locally. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2025-24993EPSS 2.1%MicrosoftWindows
CISA KEV ↗ · unattributed attribution
high

CVE-2025-24991: Microsoft Windows NTFS Out-Of-Bounds Read Vulnerability

Microsoft Windows New Technology File System (NTFS) contains an out-of-bounds read vulnerability that allows an authorized attacker to disclose information locally. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2025-24991EPSS 1.9%MicrosoftWindows
CISA KEV ↗ · unattributed attribution
high

CVE-2025-24984: Microsoft Windows NTFS Information Disclosure Vulnerability

Microsoft Windows New Technology File System (NTFS) contains an insertion of sensitive Information into log file vulnerability that allows an unauthorized attacker to disclose information with a physical attack. An attacker who successfully exploited this vulnerability could potentially read portions of heap memory. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2025-24984EPSS 1.8%MicrosoftWindows
CISA KEV ↗ · unattributed attribution
high

CVE-2024-57727: SimpleHelp Path Traversal Vulnerability

SimpleHelp remote support software contains multiple path traversal vulnerabilities that allow unauthenticated remote attackers to download arbitrary files from the SimpleHelp host via crafted HTTP requests. These files may include server configuration files and hashed user passwords. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2024-57727EPSS 95.2%SimpleHelpSimpleHelp
CISA KEV ↗ · unattributed attribution
high

CVE-2023-48365: Qlik Sense HTTP Tunneling Vulnerability

Qlik Sense contains an HTTP tunneling vulnerability that allows an attacker to escalate privileges and execute HTTP requests on the backend server hosting the software. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2023-48365EPSS 24.7%QlikSense
CISA KEV ↗ · unattributed attribution
unknown

ATT&CK profile: Sandworm Team

[Sandworm Team](https://attack.mitre.org/groups/G0034) is a destructive threat group that has been attributed to Russia's General Staff Main Intelligence Directorate (GRU) Main Center for Special Technologies (GTsST) military unit 74455.(Citation: US District Court Indictment GRU Unit 74455 October 2020)(Citation: UK NCSC Olympic Attacks October 2020) This group has been active since at least 2009.(Citation: iSIGHT Sandworm 2014)(Citation: CrowdStrike VOODOO BEAR)(Citation: USDOJ Sandworm Feb 2020)(Citation: NCSC Sandworm Feb 2020) In October 2020, the US indicted six GRU Unit 74455 officers associated with [Sandworm Team](https://attack.mitre.org/groups/G0034) for the following cyber operations: the 2015 and 2016 attacks against Ukrainian electrical companies and government organizations, the 2017 worldwide [NotPetya](https://attack.mitre.org/software/S0368) attack, targeting of the 2017 French presidential campaign, the 2018 [Olympic Destroyer](https://attack.mitre.org/software/S0365

Sandworm TeamBlackEnergy (Group)ELECTRUMIRIDIUM
MITRE ATT&CK ↗ · confirmed attribution · 3 IOCs
high

CVE-2024-21287: Oracle Agile Product Lifecycle Management (PLM) Incorrect Authorization Vulnerability

Oracle Agile Product Lifecycle Management (PLM) contains an incorrect authorization vulnerability in the Process Extension component of the Software Development Kit. Successful exploitation of this vulnerability may result in unauthenticated file disclosure. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2024-21287EPSS 1.5%Agile Product Lifecycle Management (PLM)Oracle
CISA KEV ↗ · unattributed attribution
high

CVE-2020-3259: Cisco ASA and FTD Information Disclosure Vulnerability

Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) contain an information disclosure vulnerability. An attacker could retrieve memory contents on an affected device, which could lead to the disclosure of confidential information due to a buffer tracking issue when the software parses invalid URLs that are requested from the web services interface. This vulnerability affects only specific AnyConnect and WebVPN configurations. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2020-3259EPSS 71.8%Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD)Cisco
CISA KEV ↗ · unattributed attribution
high

CVE-2023-41265: Qlik Sense HTTP Tunneling Vulnerability

Qlik Sense contains an HTTP tunneling vulnerability that allows an attacker to escalate privileges and execute HTTP requests on the backend server hosting the software. Required action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.

CVE-2023-41265EPSS 85.0%QlikSense
CISA KEV ↗ · unattributed attribution
high

CVE-2023-35078: Ivanti Endpoint Manager Mobile Authentication Bypass Vulnerability

Ivanti Endpoint Manager Mobile (EPMM, previously branded MobileIron Core) contains an authentication bypass vulnerability that allows unauthenticated access to specific API paths. An attacker with access to these API paths can access personally identifiable information (PII) such as names, phone numbers, and other mobile device details for users on a vulnerable system. An attacker can also make other configuration changes including installing software and modifying security profiles on registered devices. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2023-35078EPSS 100.0%Endpoint Manager Mobile (EPMM)Ivanti
CISA KEV ↗ · unattributed attribution
high

CVE-2023-25717: Multiple Ruckus Wireless Products CSRF and RCE Vulnerability

Ruckus Wireless Access Point (AP) software contains an unspecified vulnerability in the web services component. If the web services component is enabled on the AP, an attacker can perform cross-site request forgery (CSRF) or remote code execution (RCE). This vulnerability impacts Ruckus ZoneDirector, SmartZone, and Solo APs. Required action: Apply updates per vendor instructions or disconnect product if it is end-of-life.

CVE-2023-25717EPSS 95.3%Multiple ProductsRuckus Wireless
CISA KEV ↗ · unattributed attribution
high

CVE-2017-6742: Cisco IOS and IOS XE Software SNMP Remote Code Execution Vulnerability

The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE contains a vulnerability that could allow an authenticated, remote attacker to remotely execute code on an affected system or cause an affected system to reload. Required action: Apply updates per vendor instructions.

CVE-2017-6742EPSS 21.4%CiscoIOS and IOS XE Software
CISA KEV ↗ · unattributed attribution
high

CVE-2022-20821: Cisco IOS XR Open Port Vulnerability

Cisco IOS XR software health check opens TCP port 6379 by default on activation. An attacker can connect to the Redis instance on the open port and allow access to the Redis instance that is running within the NOSi container. Required action: Apply updates per vendor instructions.

CVE-2022-20821EPSS 11.8%CiscoIOS XR
CISA KEV ↗ · unattributed attribution
high

CVE-2018-7841: Schneider Electric U.motion Builder SQL Injection Vulnerability

A SQL Injection vulnerability exists in U.motion Builder software which could cause unwanted code execution when an improper set of characters is entered. Required action: The impacted product is end-of-life and should be disconnected if still in use.

CVE-2018-7841EPSS 72.5%Schneider ElectricU.motion Builder
CISA KEV ↗ · unattributed attribution · 1 IOC
high

CVE-2018-0147: Cisco Secure Access Control System Java Deserialization Vulnerability

A vulnerability in Java deserialization used by Cisco Secure Access Control System (ACS) could allow an unauthenticated, remote attacker to execute arbitrary commands on an affected device. The vulnerability is due to insecure deserialization of user-supplied content by the affected software. Required action: Apply updates per vendor instructions.

CVE-2018-0147EPSS 18.3%CiscoSecure Access Control System (ACS)
CISA KEV ↗ · unattributed attribution
high

CVE-2017-3881: Cisco IOS and IOS XE Remote Code Execution Vulnerability

A vulnerability in the Cisco Cluster Management Protocol (CMP) processing code in Cisco IOS and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a reload of an affected device or remotely execute code with elevated privileges. Required action: Apply updates per vendor instructions.

CVE-2017-3881EPSS 99.0%CiscoIOS and IOS XE
CISA KEV ↗ · unattributed attribution
high

CVE-2022-20708: Cisco Small Business RV Series Routers Stack-based Buffer Overflow Vulnerability

A vulnerability in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Execute arbitrary code elevate privileges, execute arbitrary commands, bypass authentication and authorization protections, fetch and run unsigned software, or cause a denial of service (DoS). Required action: Apply updates per vendor instructions.

CVE-2022-20708EPSS 14.9%CiscoSmall Business RV160, RV260, RV340, and RV345 Series Routers
CISA KEV ↗ · unattributed attribution
high

CVE-2022-20703: Cisco Small Business RV Series Routers Stack-based Buffer Overflow Vulnerability

A vulnerability in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Execute arbitrary code elevate privileges, execute arbitrary commands, bypass authentication and authorization protections, fetch and run unsigned software, or cause a denial of service (DoS). Required action: Apply updates per vendor instructions.

CVE-2022-20703EPSS 9.2%CiscoSmall Business RV160, RV260, RV340, and RV345 Series Routers
CISA KEV ↗ · unattributed attribution
high

CVE-2022-20701: Cisco Small Business RV Series Routers Stack-based Buffer Overflow Vulnerability

A vulnerability in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Execute arbitrary code elevate privileges, execute arbitrary commands, bypass authentication and authorization protections, fetch and run unsigned software, or cause a denial of service (DoS). Required action: Apply updates per vendor instructions.

CVE-2022-20701EPSS 9.7%CiscoSmall Business RV160, RV260, RV340, and RV345 Series Routers
CISA KEV ↗ · unattributed attribution
high

CVE-2022-20700: Cisco Small Business RV Series Routers Stack-based Buffer Overflow Vulnerability

A vulnerability in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Execute arbitrary code elevate privileges, execute arbitrary commands, bypass authentication and authorization protections, fetch and run unsigned software, or cause a denial of service (DoS). Required action: Apply updates per vendor instructions.

CVE-2022-20700EPSS 5.7%CiscoSmall Business RV160, RV260, RV340, and RV345 Series Routers
CISA KEV ↗ · unattributed attribution
high

CVE-2022-20699: Cisco Small Business RV Series Routers Stack-based Buffer Overflow Vulnerability

A vulnerability in Cisco Small Business RV160, RV260, RV340, and RV345 Series Routers could allow an attacker to do any of the following: Execute arbitrary code elevate privileges, execute arbitrary commands, bypass authentication and authorization protections, fetch and run unsigned software, or cause a denial of service (DoS). Required action: Apply updates per vendor instructions.

CVE-2022-20699EPSS 72.5%CiscoSmall Business RV160, RV260, RV340, and RV345 Series Routers
CISA KEV ↗ · unattributed attribution
high

CVE-2018-0180: Cisco IOS Software Denial-of-Service Vulnerability

A vulnerability in the Login Enhancements (Login Block) feature of Cisco IOS Software could allow an unauthenticated, remote attacker to trigger a reload of an affected system, resulting in a denial of service (DoS) condition. Required action: Apply updates per vendor instructions.

CVE-2018-0180EPSS 5.0%CiscoIOS Software
CISA KEV ↗ · unattributed attribution
high

CVE-2018-0179: Cisco IOS Software Denial-of-Service Vulnerability

A vulnerability in the Login Enhancements (Login Block) feature of Cisco IOS Software could allow an unauthenticated, remote attacker to trigger a reload of an affected system, resulting in a denial of service (DoS) condition. Required action: Apply updates per vendor instructions.

CVE-2018-0179EPSS 5.0%CiscoIOS Software
CISA KEV ↗ · unattributed attribution
high

CVE-2018-0175: Cisco IOS, XR, and XE Software Buffer Overflow Vulnerability

Format string vulnerability in the Link Layer Discovery Protocol (LLDP) subsystem of Cisco IOS Software, Cisco IOS XE Software, and Cisco IOS XR Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition or execute arbitrary code with elevated privileges on an affected device. Required action: Apply updates per vendor instructions.

CVE-2018-0175EPSS 3.5%CiscoIOS, XR, and XE Software
CISA KEV ↗ · unattributed attribution
high

CVE-2018-0167: Cisco IOS, XR, and XE Software Buffer Overflow Vulnerability

There is a buffer overflow vulnerability in the Link Layer Discovery Protocol (LLDP) subsystem of Cisco IOS Software, Cisco IOS XE Software, and Cisco IOS XR Software which could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition or execute arbitrary code. Required action: Apply updates per vendor instructions.

CVE-2018-0167EPSS 3.4%CiscoIOS, XR, and XE Software
CISA KEV ↗ · unattributed attribution
high

CVE-2018-0161: Cisco IOS Software Resource Management Errors Vulnerability

A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco IOS Software running on certain models of Cisco Catalyst Switches could allow an authenticated, remote attacker to cause a denial-of-service (DoS) condition. Required action: Apply updates per vendor instructions.

CVE-2018-0161EPSS 4.7%CiscoIOS Software
CISA KEV ↗ · unattributed attribution
high

CVE-2018-0159: Cisco IOS and XE Software Internet Key Exchange Version 1 Denial-of-Service Vulnerability

A vulnerability in the implementation of Internet Key Exchange Version 1 (IKEv1) functionality in Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a denial-of-service (DoS) condition. Required action: Apply updates per vendor instructions.

CVE-2018-0159EPSS 7.0%CiscoIOS Software and Cisco IOS XE Software
CISA KEV ↗ · unattributed attribution
high

CVE-2018-0158: Cisco IOS and XE Software Internet Key Exchange Memory Leak Vulnerability

A vulnerability in the implementation of Internet Key Exchange Version 1 (IKEv1) functionality in Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a denial-of-service (DoS) condition. Required action: Apply updates per vendor instructions.

CVE-2018-0158EPSS 7.3%CiscoIOS Software and Cisco IOS XE Software
CISA KEV ↗ · unattributed attribution
high

CVE-2018-0156: Cisco IOS Software and Cisco IOS XE Software Smart Install Denial-of-Service Vulnerability

A vulnerability in the Smart Install feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to trigger a reload of an affected device, resulting in a denial-of-service (DoS) condition. Required action: Apply updates per vendor instructions.

CVE-2018-0156EPSS 8.3%CiscoIOS Software and Cisco IOS XE Software
CISA KEV ↗ · unattributed attribution
high

CVE-2018-0151: Cisco IOS Software and Cisco IOS XE Software Quality of Service Remote Code Execution Vulnerability

A vulnerability in the quality of service (QoS) subsystem of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition or execute arbitrary code with elevated privileges. Required action: Apply updates per vendor instructions.

CVE-2018-0151EPSS 14.5%CiscoIOS and IOS XE Software
CISA KEV ↗ · unattributed attribution
high

CVE-2017-6744: Cisco IOS Software SNMP Remote Code Execution Vulnerability

The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS 1 contains a vulnerability that could allow an authenticated, remote attacker to remotely execute code on an affected system or cause an affected system to reload. An attacker could exploit these vulnerabilities by sending a crafted SNMP packet to an affected system via IPv4 or IPv6. Required action: Apply updates per vendor instructions.

CVE-2017-6744EPSS 7.2%CiscoIOS software
CISA KEV ↗ · unattributed attribution
high

CVE-2017-6740: Cisco IOS and IOS XE Software SNMP Remote Code Execution Vulnerability

The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE contains a vulnerability that could allow an authenticated, remote attacker to remotely execute code on an affected system or cause an affected system to reload. Required action: Apply updates per vendor instructions.

CVE-2017-6740EPSS 10.8%CiscoIOS and IOS XE Software
CISA KEV ↗ · unattributed attribution
high

CVE-2017-6739: Cisco IOS and IOS XE Software SNMP Remote Code Execution Vulnerability

The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE contains a vulnerability that could allow an authenticated, remote attacker to remotely execute code on an affected system or cause an affected system to reload. Required action: Apply updates per vendor instructions.

CVE-2017-6739EPSS 10.5%CiscoIOS and IOS XE Software
CISA KEV ↗ · unattributed attribution
high

CVE-2017-6663: Cisco IOS Software and Cisco IOS XE Software Denial-of-Service Vulnerability

A vulnerability in the Autonomic Networking feature of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticated, adjacent attacker to cause autonomic nodes of an affected system to reload, resulting in denial-of-service (DoS). Required action: Apply updates per vendor instructions.

CVE-2017-6663EPSS 2.1%CiscoIOS and IOS XE Software
CISA KEV ↗ · unattributed attribution
high

CVE-2017-6627: Cisco IOS Software and Cisco IOS XE Software UDP Packet Processing Denial-of-Service Vulnerability

A vulnerability in the UDP processing code of Cisco IOS and IOS XE could allow an unauthenticated, remote attacker to cause the input queue of an affected system to hold UDP packets, causing an interface queue wedge and denial of service. Required action: Apply updates per vendor instructions.

CVE-2017-6627EPSS 6.0%CiscoIOS and IOS XE Software
CISA KEV ↗ · unattributed attribution
high

CVE-2017-12319: Cisco IOS XE Software Ethernet Virtual Private Network Border Gateway Protocol Denial-of-Service Vulnerability

A vulnerability in the Border Gateway Protocol (BGP) over an Ethernet Virtual Private Network (EVPN) for Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause the device to reload, resulting in a denial of service (DoS) condition, or potentially corrupt the BGP routing table, which could result in network instability. Required action: Apply updates per vendor instructions.

CVE-2017-12319EPSS 5.3%CiscoIOS XE Software
CISA KEV ↗ · unattributed attribution
high

CVE-2017-12240: Cisco IOS and IOS XE Software DHCP Remote Code Execution Vulnerability

The Dynamic Host Configuration Protocol (DHCP) relay subsystem of Cisco IOS and Cisco IOS XE Software contains a vulnerability that could allow an unauthenticated, remote attacker to execute arbitrary code and gain full control of an affected system. Required action: Apply updates per vendor instructions.

CVE-2017-12240EPSS 13.9%CiscoIOS and IOS XE Software
CISA KEV ↗ · unattributed attribution
high

CVE-2017-12237: Cisco IOS and IOS XE Software Internet Key Exchange Denial-of-Service Vulnerability

A vulnerability in the Internet Key Exchange Version 2 (IKEv2) module of Cisco IOS and Cisco IOS XE could allow an unauthenticated, remote attacker to cause high CPU utilization, traceback messages, or a reload of an affected device that leads to a denial of service. Required action: Apply updates per vendor instructions.

CVE-2017-12237EPSS 7.1%CiscoIOS and IOS XE Software
CISA KEV ↗ · unattributed attribution
high

CVE-2017-12235: Cisco IOS Software for Cisco Industrial Ethernet Switches PROFINET Denial-of-Service Vulnerability

A vulnerability in the implementation of the PROFINET Discovery and Configuration Protocol (PN-DCP) for Cisco IOS could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a denial of service. Required action: Apply updates per vendor instructions.

CVE-2017-12235EPSS 7.1%CiscoIOS software
CISA KEV ↗ · unattributed attribution
high

CVE-2017-12232: Cisco IOS Software for Cisco Integrated Services Routers Denial-of-Service Vulnerability

A vulnerability in the implementation of a protocol in Cisco Integrated Services Routers Generation 2 (ISR G2) Routers running Cisco IOS could allow an unauthenticated, adjacent attacker to cause an affected device to reload, resulting in a denial of service. Required action: Apply updates per vendor instructions.

CVE-2017-12232EPSS 2.2%CiscoIOS software
CISA KEV ↗ · unattributed attribution
high

CVE-2017-11826: Microsoft Office Remote Code Execution Vulnerability

A remote code execution vulnerability exists in Microsoft Office software when the software fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user. Required action: Apply updates per vendor instructions.

CVE-2017-11826EPSS 81.5%MicrosoftOffice
CISA KEV ↗ · unattributed attribution
high

CVE-2021-27860: FatPipe WARP, IPVPN, and MPVPN Configuration Upload exploit

A vulnerability in the web management interface of FatPipe WARP, IPVPN, and MPVPN software allows a remote, unauthenticated attacker to upload a file to any location on the filesystem. Required action: Apply updates per vendor instructions.

CVE-2021-27860EPSS 39.8%FatPipeWARP, IPVPN, and MPVPN software
CISA KEV ↗ · unattributed attribution
high

CVE-2021-44228: Apache Log4j2 Remote Code Execution Vulnerability

Apache Log4j2 contains a vulnerability where JNDI features do not protect against attacker-controlled JNDI-related endpoints, allowing for remote code execution. Required action: For all affected software assets for which updates exist, the only acceptable remediation actions are: 1) Apply updates; OR 2) remove affected assets from agency networks. Temporary mitigations using one of the measures provided at https://www.cisa.gov/uscert/ed-22-02-apache-log4j-recommended-mitigation-measures are only acceptable until updates are available.

CVE-2021-44228EPSS 100.0%ApacheLog4j2
CISA KEV ↗ · unattributed attribution · 1 IOC
high

CVE-2020-3118: Cisco IOS XR Software Discovery Protocol Format String Vulnerability

Cisco IOS XR improperly validates string input from certain fields in Cisco Discovery Protocol messages. Exploitation could allow an unauthenticated, adjacent attacker to execute code with administrative privileges or cause a reload on an affected device. Required action: Apply updates per vendor instructions.

CVE-2020-3118EPSS 11.7%CiscoIOS XR
CISA KEV ↗ · unattributed attribution
high

CVE-2020-3566: Cisco IOS XR Software DVMRP Memory Exhaustion Vulnerability

Cisco IOS XR Distance Vector Multicast Routing Protocol (DVMRP) incorrectly handles Internet Group Management Protocol (IGMP) packets. Exploitation could allow an unauthenticated, remote attacker to immediately crash the IGMP process or make it consume available memory and eventually crash. Required action: Apply updates per vendor instructions.

CVE-2020-3566EPSS 3.6%CiscoIOS XR
CISA KEV ↗ · unattributed attribution
high

CVE-2020-3569: Cisco IOS XR Software DVMRP Memory Exhaustion Vulnerability

Cisco IOS XR Distance Vector Multicast Routing Protocol (DVMRP) incorrectly handles Internet Group Management Protocol (IGMP) packets. Exploitation could allow an unauthenticated, remote attacker to immediately crash the IGMP process or make it consume available memory and eventually crash. Required action: Apply updates per vendor instructions.

CVE-2020-3569EPSS 3.3%CiscoIOS XR
CISA KEV ↗ · unattributed attribution
high

CVE-2020-15999: Google Chrome FreeType Heap Buffer Overflow Vulnerability

Google Chrome uses FreeType, an open-source software library to render fonts, which contains a heap buffer overflow vulnerability in the function Load_SBit_Png when processing PNG images embedded into fonts. This vulnerability is part of an exploit chain with CVE-2020-17087 on Windows and CVE-2020-16010 on Android. Required action: Apply updates per vendor instructions.

CVE-2020-15999CVE-2020-16010EPSS 50.6%Chrome FreeTypeGoogle
CISA KEV ↗ · unattributed attribution
high

CVE-2020-0601: Microsoft Windows CryptoAPI Spoofing Vulnerability

Microsoft Windows CryptoAPI (Crypt32.dll) contains a spoofing vulnerability in the way it validates Elliptic Curve Cryptography (ECC) certificates. An attacker could exploit the vulnerability by using a spoofed code-signing certificate to sign a malicious executable, making it appear the file was from a trusted, legitimate source. A successful exploit could also allow the attacker to conduct man-in-the-middle attacks and decrypt confidential information on user connections to the affected software. The vulnerability is also known under the moniker of CurveBall. Required action: Apply updates per vendor instructions.

CVE-2020-0601EPSS 89.4%MicrosoftWindows
CISA KEV ↗ · unattributed attribution · 1 IOC
high

CVE-2020-1147: Microsoft .NET Framework, SharePoint, and Visual Studio Remote Code Execution Vulnerability

Microsoft .NET Framework, Microsoft SharePoint, and Visual Studio contain a remote code execution vulnerability when the software fails to check the source markup of XML file input. Successful exploitation allows an attacker to execute code in the context of the process responsible for deserialization of the XML content. Required action: Apply updates per vendor instructions.

CVE-2020-1147EPSS 94.2%.NET Framework, SharePoint, Visual StudioMicrosoft
CISA KEV ↗ · unattributed attribution