Actionable security intelligence from vulnerability records, advisories, ATT&CK, exploitability data, and vendor notices.
Should KEV outrank CVSS in vulnerability triage? **Yes.** The attached CISA and EPSS sources support an exploitation-led triage model: confirmed exploitation in CISA KEV should outrank severity-only CVSS scoring, while EPSS is used as a probability signal when active exploitation is not already evid...
ViewHunt DMZ web shells that precede RDP lateral movement to domain controllers and VMware vCenter. Flag PsExec activity that creates an inbound RDP rule on port 3389, especially `openrdp.bat`. Watch for VPN access without MFA, especially tied to CVE-2024-40766 or stolen VPN credentials. Alert on POSTs ...
ViewIf your ICS can be reached from the Internet, it is already too exposed. CISA’s recurring advice is to reduce reachability first, then layer in segmentation, firewalls, and controlled remote access[[cite:1]][[cite:2]]. Step 1: review the advisory’s affected software or firmware versions and confirm ...
ViewQ1. How do the attached sources describe ATT&CK at a high level? - A globally-accessible knowledge base of adversary tactics and techniques based on real-world observations - A catalog of only malware hashes and file signatures - A framework that lists only vulnerability severity scores - A patch-ma...
ViewExploitation-led vulnerability triage model Use a simple order of operations: **1) CISA KEV first**, because KEV is the strongest signal of confirmed active exploitation; **2) EPSS next** when you do not yet have direct exploitation evidence, because EPSS is built to prioritize likely exploitation u...
ViewQ1. Which pattern is best described as vishing, spearphishing, or impersonation aimed at help desk staff to reset passwords or transfer MFA tokens? - Help desk social engineering - Cloud valid account access - Session token abuse - Cloud infrastructure discovery Answer: Help desk social engineering[...
View