Resources

CVE-2024-23897 – Jenkins RCE Exploited in Ransomware Attacks

Introduction   On August 19th, CISA added a new vulnerability to its catalog of Known Exploited Vulnerabilities (KEV). Being tracked…
CVE Advisory

CVE-2023-36884 – Nation-State RCE Targets Government Agencies with Malicious Microsoft Office Documents

Updated on 27/07/2023 On July 11th, Microsoft announced they had uncovered a zero-day bug found in numerous Windows and Office…
CVE Advisory

CVE-2023-23397 – Outlook vulnerability

On March 14, Microsoft released the regular Patch tuesday. During this patch Tuesday, Microsoft released 74 new patches addressing CVEs…
CVE Advisory

CVE 2023-21716- Microsoft Word RCE

Overview On March 5, a security researcher named Joshua J.Drake shared details about CVE-2023-21716, a Microsoft Word vulnerability that was…
CVE Advisory

Extracting Encrypted Credentials from Common Tools

Overview During our day to day research, we face the question of what can be extracted from a  compromised machine…
Blog

CVE-2022-42475 – Critical RCE Fortinet Vulnerability 

On December 12th, Fortinet, one of the foremost players in the firewall, AV, intrusion prevention systems, and endpoint security ecosystem,…
CVE Advisory

XM Cyber Advisory – OpenSSL Critical Vulnerability

Overview According to the OpenSSL team, on November 1st, 2022, a new version, number 3.0.7 will be released (https://mta.openssl.org/pipermail/openssl-announce/2022-October/000238.html). It’s…
Blog

XM Cyber Advisory – Follina, CVE-2022-30190, Zero Day

On May 27, a new zero day critical vulnerability called Follina was discovered by the nao_sec security research team. The…
CVE Advisory

XM Cyber Advisory – Spring4Shell, Zero Day

Overview On March 30, A new zero day critical vulnerability was leaked in another open source software library. The vulnerability…
Blog

Go beyond Log4Shell and see the entire attack path with XM Cyber

We know you’re working tirelessly to get ahead of the log4j vulnerability. Here at XM Cyber, we can help you…
Videos

Go Beyond Log4Shell and See the Entire Attack Path

We understand the facts: The most common open-source library (Java) has already been identified with 3 CVEs and counting, with…
Blog

Time to go beyond Log4Shell and see the entire attack path

Today’s organizations are overwhelmed since the world first learned about the Log4Shell vulnerability (aka Log4J CVE-2021-44228, CVE-2021-45046). If prioritizing your…
Blog
1 2

See XM Cyber In Action

See what attackers see, so you can stop them from doing what attackers do.