CVE-2024-23897 – Jenkins RCE Exploited in Ransomware Attacks
Introduction On August 19th, CISA added a new vulnerability to its catalog of Known Exploited Vulnerabilities (KEV). Being tracked…
CVE Advisory
CVE-2023-36884 – Nation-State RCE Targets Government Agencies with Malicious Microsoft Office Documents
Updated on 27/07/2023 On July 11th, Microsoft announced they had uncovered a zero-day bug found in numerous Windows and Office…
CVE Advisory
CVE-2023-23397 – Outlook vulnerability
On March 14, Microsoft released the regular Patch tuesday. During this patch Tuesday, Microsoft released 74 new patches addressing CVEs…
CVE Advisory
CVE 2023-21716- Microsoft Word RCE
Overview On March 5, a security researcher named Joshua J.Drake shared details about CVE-2023-21716, a Microsoft Word vulnerability that was…
CVE Advisory
Extracting Encrypted Credentials from Common Tools
Overview During our day to day research, we face the question of what can be extracted from a compromised machine…
Blog
CVE-2022-42475 – Critical RCE Fortinet Vulnerability
On December 12th, Fortinet, one of the foremost players in the firewall, AV, intrusion prevention systems, and endpoint security ecosystem,…
CVE Advisory
XM Cyber Advisory – OpenSSL Critical Vulnerability
Overview According to the OpenSSL team, on November 1st, 2022, a new version, number 3.0.7 will be released (https://mta.openssl.org/pipermail/openssl-announce/2022-October/000238.html). It’s…
Blog
XM Cyber Advisory – Follina, CVE-2022-30190, Zero Day
On May 27, a new zero day critical vulnerability called Follina was discovered by the nao_sec security research team. The…
CVE Advisory
XM Cyber Advisory – Spring4Shell, Zero Day
Overview On March 30, A new zero day critical vulnerability was leaked in another open source software library. The vulnerability…
Blog
Go beyond Log4Shell and see the entire attack path with XM Cyber
We know you’re working tirelessly to get ahead of the log4j vulnerability. Here at XM Cyber, we can help you…
Videos
Go Beyond Log4Shell and See the Entire Attack Path
We understand the facts: The most common open-source library (Java) has already been identified with 3 CVEs and counting, with…
Blog
Time to go beyond Log4Shell and see the entire attack path
Today’s organizations are overwhelmed since the world first learned about the Log4Shell vulnerability (aka Log4J CVE-2021-44228, CVE-2021-45046). If prioritizing your…
Blog
See XM Cyber In Action