SonicWall SMA Zero-Days Exploited Before Disclosure to Gain Root Access
A previously undocumented threat actor, tracked as UTA0533 by Volexity, exploited two zero-day vulnerabilities in SonicWall Secure Mobile Access (SMA) 1000 series…
A previously undocumented threat actor, tracked as UTA0533 by Volexity, exploited two zero-day vulnerabilities in SonicWall Secure Mobile Access (SMA) 1000 series…
This week's cybersecurity landscape is marked by a series of critical threats and vulnerabilities. Progress has urged ShareFile customers to shut down…
SHELLSTORM is a large-scale operation that exploited 27 CVEs in WordPress plugins to deploy web shells on over 1.4 million domains. The…
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added two maximum-severity vulnerabilities affecting iCagenda and Balbooa Forms extensions for Joomla to…
A vulnerability in the Sneeit Framework exploited in a global CMS campaign for web shell deployment.
A vulnerability in the Gravity Forms WordPress plugin exploited in a global CMS campaign for web shell deployment.
A vulnerability in Craft CMS exploited in a global CMS campaign for web shell deployment.
A vulnerability in MaxSite CMS exploited in a global CMS campaign for web shell deployment.
A vulnerability in MetInfo CMS exploited in a global CMS campaign for web shell deployment.
Australian agency that issued an alert about a global exploitation campaign targeting vulnerable CMS systems and plugins, including web shell deployment.