🚨 CVE-2026-24061 - Critical Alert 🚨
A critical (CVSS 9.8) vulnerability in GNU InetUtils telnetd lets unauthenticated attackers bypass login and gain root access on affected systems. With an EPSS score ~92%, exploitation risk is extremely high.
📌 What to do:
- Patch to the latest GNU InetUtils immediately
- Disable Telnet where possible
👉 Full breakdown here: https://t.co/Nl6IjHegPR
12-hour timelapse of American Airlines, Delta, and United plane traffic after what was likely the biggest IT outage in history forced a nationwide ground stop of the three airlines.
🚨 Threat Actors Target Organizations Affected by CrowdStrike Incident 🚨
Due to a technical malfunction in the CrowdStrike product globally, CrowdStrike users have been affected. Connected devices and servers have been disabled.
This is not a hacking incident, but threat actors on the dark web and deep web are exploiting the situation by planning attack scenarios in private chat rooms. To take advantage of this situation, threat actors are targeting the affected systems and institutions. The list shared on a hacker channel highlights the seriousness of the situation. While we have serious concerns about the accuracy of the shared lists, it is important to note that the real issue lies in the perception manipulation created by threat actors.
At ThreatMon, we closely monitor the security of all our customers.
You can email [email protected] to check if your company name appears on the list shared on hacker channels.
#Crowdstrike #Windows #CyberSecurity
🕵️♂️ CISA warns of an ongoing cyber threat targeting government servers via an Adobe ColdFusion #vulnerability (CVE-2023-26360).
Learn more: https://t.co/Bos77d2txV
Update your software now.
📢 @CISAgov released a #cybersecurity advisory on threat actors exploiting Adobe #ColdFusion#CVE-2023-26360 to access servers at a government agency. Exploitation can result in arbitrary code execution. View #TTPs, #IoCs & detection methods at https://t.co/ZnvjemO3B4
INC Ransomware Case today @Huntresslabs 🧵
- Our malicious user 'access' used a combination of wmic and psexec to copy and execute a malicious script 'settings.bat' across all hosts in the org.
- This script disabled WinDefender and enabled RDP on all hosts
🕷️🚨 Joint #Cybersecurity Advisory: @CISAgov & @FBI warn of #ScatteredSpider actors targeting large companies & IT help desks using advanced social engineering techniques. Implement our recommended mitigations to guard against threats. More info & TTPs: https://t.co/dl3BFITGAv
🚨 A Joint Advisory by @CISAgov, @FBI & @CISecurity's MS-ISAC reveals #Rhysida ransomware actors’ latest #TTPs, including targeting sectors like education, manufacturing, IT & healthcare. Protect your network with recommended mitigations: https://t.co/nJWgAPvO75 #StopRansomware
🚨 Alert! 🆘 #Cisco IOS XE Software 17.6.6a is available and fixes CVE-2023-20198 and CVE-2023-20273. Update and check out our page for further guidance: https://t.co/G1t4PlXV4H #Cybersecurity
As of today, 138 orgs including 16 in the US public sector are known to have been impacted by MOVEit. The breaches have resulted in the personal info of >15 million people being compromised. 2/2
Overdue reminder that I have the best #OSINT resource document in the entire history of the Internet (I asked my mum and that's what she said).
https://t.co/3fEtf8ofWg
🚨 Ongoing espionage operation uncovered in North Africa!
Stealth Soldier #malware snoops on files, records screens/microphones, logs keystrokes, steals browser data, and more.
Learn more about it here: https://t.co/4yvcj9Al7C
#cybersecurity#hacking