Actionable security intelligence from vulnerabilit…
Should KEV outrank CVSS in vulnerability triage? **Yes.** The attached CISA and EPSS sources support an exploitation-led triage model: confirmed exploitation in CISA KEV should outrank severity-only CVSS scoring, while EPSS is used as a probability signal when active exploitation is not already evid...
ViewHow does a public GeoServer bug turn into full intrusion? CISA says CVE-2024-36401 was exploited on public-facing GeoServer systems, then the campaign moved through web shells, cron jobs, valid accounts, brute force, PowerShell, BITS jobs, and Stowaway.[[cite:1]] The sequence mattered: attackers use...
ViewHunt DMZ web shells that precede RDP lateral movement to domain controllers and VMware vCenter. Flag PsExec activity that creates an inbound RDP rule on port 3389, especially `openrdp.bat`. Watch for VPN access without MFA, especially tied to CVE-2024-40766 or stolen VPN credentials. Alert on POSTs ...
ViewIranian-Affiliated Targeting of Internet-Exposed PLCs CISA warns that Iranian-affiliated cyber actors have been exploiting internet-connected PLCs across U.S. critical infrastructure, with activity observed in Government Services and Facilities, Water and Wastewater Systems, and Energy. The advisory...
ViewHow did a single Zimbra phishing email turn into mailbox theft? CISA says LAUNDRY BEAR used CVE-2025-66376 so that just viewing the message could execute JavaScript in the webmail client and start mail theft[[cite:1]][[cite:2]]. The initial payload was hidden in an SVG onload field, wrapped in Base6...
ViewQ1. How do the attached sources describe ATT&CK at a high level? - A globally-accessible knowledge base of adversary tactics and techniques based on real-world observations - A catalog of only malware hashes and file signatures - A framework that lists only vulnerability severity scores - A patch-ma...
View