Posts tagged Emergent Threat Response

Threat Research
Active Exploitation of ZK Framework CVE-2022-36537
Stephen Fewer

Vulnerabilities and Exploits
CVE-2022-21587: Rapid7 Observed Exploitation of Oracle E-Business Suite Vulnerability
Glenn Thorpe

Exposure Management
CVE-2023-22501: Critical Broken Authentication Flaw in Jira Service Management Products
Caitlin Condon

Detection and Response
Ransomware Campaign Compromising VMware ESXi Servers
Caitlin Condon

Threat Research
Exploitation of GoAnywhere MFT zero-day vulnerability
Caitlin Condon

Vulnerabilities and Exploits
Exploitation of Control Web Panel CVE-2022-44877
Caitlin Condon

Vulnerabilities and Exploits
CVE-2022-47966: Rapid7 Observed Exploitation of Critical ManageEngine Vulnerability
Glenn Thorpe

Vulnerabilities and Exploits
CVE-2022-41080, CVE-2022-41082: Rapid7 Observed Exploitation of `OWASSRF` in Exchange for RCE
Glenn Thorpe

Exposure Management
CVE-2022-27518: Critical Fix Released for Exploited Citrix ADC, Gateway Vulnerability
Glenn Thorpe

Vulnerabilities and Exploits
CVE-2022-42475: Critical Unauthenticated Remote Code Execution Vulnerability in FortiOS; Exploitation Reported
Glenn Thorpe

Threat Research
CVE-2022-27510: Critical Citrix ADC and Gateway Remote Authentication Bypass Vulnerabilities
Rapid7

Vulnerabilities and Exploits
Rapid7’s Impact from OpenSSL Buffer Overflow Vulnerabilities (CVE-2022-3786 & CVE-2022-3602)
Rapid7

Vulnerabilities and Exploits
Rapid7’s Impact from Apache Commons Text Vulnerability (CVE-2022-42889)
Rapid7

Exposure Management
CVE-2022-3786 and CVE-2022-3602: Two High-Severity Buffer Overflow Vulnerabilities in OpenSSL Fixed
Rapid7

Vulnerabilities and Exploits
CVE-2021-39144: VMware Cloud Foundation Unauthenticated Remote Code Execution
Caitlin Condon

Exposure Management
CVE-2022-42889: Keep Calm and Stop Saying "Text4Shell"
Erick Galinkin

Vulnerabilities and Exploits
CVE-2022-40684: Remote Authentication Bypass Vulnerability in Fortinet Firewalls, Web Proxies
Glenn Thorpe

Exposure Management
Exploitation of Unpatched Zero-Day Remote Code Execution Vulnerability in Zimbra Collaboration Suite (CVE-2022-41352)
Ron Bowes

Exposure Management
CVE-2022-41040 and CVE-2022-41082: Unpatched Zero-Day Vulnerabilities in Microsoft Exchange Server
Caitlin Condon

Exposure Management
CVE-2022-36804: Easily Exploitable Vulnerability in Atlassian Bitbucket Server and Data Center
Ron Bowes

Exposure Management
Active Exploitation of Multiple Vulnerabilities in Zimbra Collaboration Suite
Caitlin Condon