<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom">
  <updated>2026-06-07T01:58:47Z</updated>
  <generator>https://yabu.me</generator>

  <title>Nostr notes by The Shadowserver Foundation</title>
  <author>
    <name>The Shadowserver Foundation</name>
  </author>
  <link rel="self" type="application/atom+xml" href="https://yabu.me/npub1cla6jlqwtg3hhhqlg7rdz0lxtgfr0u5ee6vndqr0pzdtszzvt9gsyyl628.rss" />
  <link href="https://yabu.me/npub1cla6jlqwtg3hhhqlg7rdz0lxtgfr0u5ee6vndqr0pzdtszzvt9gsyyl628" />
  <id>https://yabu.me/npub1cla6jlqwtg3hhhqlg7rdz0lxtgfr0u5ee6vndqr0pzdtszzvt9gsyyl628</id>
  <icon>https://media.infosec.exchange/infosec.exchange/accounts/avatars/109/358/833/367/138/068/original/a15d87e2814fa3b3.png</icon>
  <logo>https://media.infosec.exchange/infosec.exchange/accounts/avatars/109/358/833/367/138/068/original/a15d87e2814fa3b3.png</logo>




  <entry>
    <id>https://yabu.me/nevent1qqst056pnpanm8e3awmajp3hfue90jv87pst45xv9lg8pcpwl6scchqzyrrlh2tupedzx77urarcd5fluedpydljn88fjd5qduyf4wqgf3v4zy684np</id>
    
      <title type="html">Attention! cPanel/WHM CVE-2026-41940 attacks ongoing, with at ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqst056pnpanm8e3awmajp3hfue90jv87pst45xv9lg8pcpwl6scchqzyrrlh2tupedzx77urarcd5fluedpydljn88fjd5qduyf4wqgf3v4zy684np" />
    <content type="html">
      Attention! &lt;br/&gt;&lt;br/&gt;cPanel/WHM CVE-2026-41940 attacks ongoing, with at least 44K IPs likely compromised &amp;amp; seen scanning our honeypots on 2026-04-30.  Follow latest guidance to track for compromise &amp;amp; patch: &lt;a href=&#34;https://support.cpanel.net/hc/en-us/articles/40073787579671-Security-CVE-2026-41940-cPanel-WHM-WP2-Security-Update-04-28-2026&#34;&gt;https://support.cpanel.net/hc/en-us/articles/40073787579671-Security-CVE-2026-41940-cPanel-WHM-WP2-Security-Update-04-28-2026&lt;/a&gt; &lt;br/&gt;&lt;br/&gt;See Public Dashboard for stats: &lt;a href=&#34;https://dashboard.shadowserver.org/statistics/honeypot/device/tree/?date_range=1&amp;amp;vendor=cpanel&amp;amp;data_set=count&amp;amp;scale=log&amp;amp;auto_update=on&#34;&gt;https://dashboard.shadowserver.org/statistics/honeypot/device/tree/?date_range=1&amp;amp;vendor=cpanel&amp;amp;data_set=count&amp;amp;scale=log&amp;amp;auto_update=on&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;44K unique IP number is based on cPanel spike of devices seen scanning/running exploits/brute force attacks against our honeypot sensors.&lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://dashboard.shadowserver.org/statistics/honeypot/device/time-series/?date_range=7&amp;amp;vendor=cpanel&amp;amp;dataset=unique_ips&amp;amp;limit=100&amp;amp;group_by=vendor&amp;amp;stacking=stacked&amp;amp;auto_update=on&#34;&gt;https://dashboard.shadowserver.org/statistics/honeypot/device/time-series/?date_range=7&amp;amp;vendor=cpanel&amp;amp;dataset=unique_ips&amp;amp;limit=100&amp;amp;group_by=vendor&amp;amp;stacking=stacked&amp;amp;auto_update=on&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;You can find likely newly compromised instances in our honeypot based reports with cPanel set in the device_vendor of the attacking device&lt;br/&gt;&lt;br/&gt;- Darknet Events Report &lt;a href=&#34;https://www.shadowserver.org/what-we-do/network-reporting/honeypot-darknet-events-report/&#34;&gt;https://www.shadowserver.org/what-we-do/network-reporting/honeypot-darknet-events-report/&lt;/a&gt;&lt;br/&gt;- Honeypot HTTP Scanner Events Report&lt;br/&gt;&lt;a href=&#34;https://www.shadowserver.org/what-we-do/network-reporting/honeypot-http-scanner-events/&#34;&gt;https://www.shadowserver.org/what-we-do/network-reporting/honeypot-http-scanner-events/&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;- Honeypot Brute Force Events Report&lt;br/&gt;&lt;a href=&#34;https://www.shadowserver.org/what-we-do/network-reporting/honeypot-brute-force-events-report/&#34;&gt;https://www.shadowserver.org/what-we-do/network-reporting/honeypot-brute-force-events-report/&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;You can also find exposed cPanel/WHM instances in our Device ID reporting with ~650K IPs seen hosting &lt;a href=&#34;https://dashboard.shadowserver.org/statistics/iot-devices/time-series/?date_range=7&amp;amp;vendor=cpanel&amp;amp;dataset=count&amp;amp;limit=1000&amp;amp;group_by=geo&amp;amp;stacking=stacked&amp;amp;auto_update=on&#34;&gt;https://dashboard.shadowserver.org/statistics/iot-devices/time-series/?date_range=7&amp;amp;vendor=cpanel&amp;amp;dataset=count&amp;amp;limit=1000&amp;amp;group_by=geo&amp;amp;stacking=stacked&amp;amp;auto_update=on&lt;/a&gt;&lt;br/&gt; &lt;img src=&#34;https://media.infosec.exchange/infosec.exchange/media_attachments/files/116/499/626/517/664/806/original/96953ed60989281b.png&#34;&gt; &lt;br/&gt; &lt;img src=&#34;https://media.infosec.exchange/infosec.exchange/media_attachments/files/116/499/626/513/854/589/original/2358d71f84242e43.png&#34;&gt; &lt;br/&gt;
    </content>
    <updated>2026-05-01T13:47:17Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsx64su44wl0sdvrr2env2y255jrwgze00eyt9lmjwjaqr7qexgwaqzyrrlh2tupedzx77urarcd5fluedpydljn88fjd5qduyf4wqgf3v4zmkundw</id>
    
      <title type="html">We added a feed of IPs/websites with ClickFix/ClearFake injected ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsx64su44wl0sdvrr2env2y255jrwgze00eyt9lmjwjaqr7qexgwaqzyrrlh2tupedzx77urarcd5fluedpydljn88fjd5qduyf4wqgf3v4zmkundw" />
    <content type="html">
      We added a feed of IPs/websites with ClickFix/ClearFake injected code in our Compromised Website reporting, tagged as &amp;#39;clickfix&amp;#39;. Visitors of the website get tricked to install malware when injected JavaScript executes. If you receive an alert review for root cause of compromise!&lt;br/&gt;&lt;br/&gt;657 instances shared for 2026-03-14. We expect to increase the volume of the feed in the future!&lt;br/&gt;&lt;br/&gt;We would like to thank our Alliance partners and Validin for the collaboration making this possible!&lt;br/&gt;&lt;br/&gt;Background on investigating ClickFix/ClearFake: &lt;a href=&#34;https://www.atea.no/siste-nytt/it-sikkerhet/investigating-a-clearfake-clickfix-etherhide-campaign/&#34;&gt;https://www.atea.no/siste-nytt/it-sikkerhet/investigating-a-clearfake-clickfix-etherhide-campaign/&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;Compromised Website Report: &lt;a href=&#34;https://www.shadowserver.org/what-we-do/network-reporting/compromised-website-report/&#34;&gt;https://www.shadowserver.org/what-we-do/network-reporting/compromised-website-report/&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;Dashboard World Map view of infected IPs:&lt;br/&gt;&lt;a href=&#34;https://dashboard.shadowserver.org/statistics/combined/map/?date_range=1&amp;amp;map_type=std&amp;amp;source=compromised_iot&amp;amp;source=compromised_website&amp;amp;source=compromised_website6&amp;amp;tag=clickfix&amp;amp;data_set=count&amp;amp;scale=log&amp;amp;auto_update=on&#34;&gt;https://dashboard.shadowserver.org/statistics/combined/map/?date_range=1&amp;amp;map_type=std&amp;amp;source=compromised_iot&amp;amp;source=compromised_website&amp;amp;source=compromised_website6&amp;amp;tag=clickfix&amp;amp;data_set=count&amp;amp;scale=log&amp;amp;auto_update=on&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;Dashboard Tree Map view of infected IPs:&lt;br/&gt;&lt;a href=&#34;https://dashboard.shadowserver.org/statistics/combined/tree/?date_range=1&amp;amp;source=compromised_iot&amp;amp;source=compromised_website&amp;amp;source=compromised_website6&amp;amp;tag=clickfix&amp;amp;data_set=count&amp;amp;scale=log&amp;amp;auto_update=on&#34;&gt;https://dashboard.shadowserver.org/statistics/combined/tree/?date_range=1&amp;amp;source=compromised_iot&amp;amp;source=compromised_website&amp;amp;source=compromised_website6&amp;amp;tag=clickfix&amp;amp;data_set=count&amp;amp;scale=log&amp;amp;auto_update=on&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;#CyberCivilDefense&lt;br/&gt; &lt;img src=&#34;https://media.infosec.exchange/infosec.exchange/media_attachments/files/116/234/013/327/561/196/original/31f2c4e7f2f96d5e.png&#34;&gt; &lt;br/&gt;
    </content>
    <updated>2026-03-15T16:05:55Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqswyfpfg2ap2uzyzrdf7e2e599v3r8jmwvsw9jr9g9xzk9hs4zg0gqzyrrlh2tupedzx77urarcd5fluedpydljn88fjd5qduyf4wqgf3v4zdhh0l3</id>
    
      <title type="html">Iran Internet blackout visualized on our Public Dashboard - drop ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqswyfpfg2ap2uzyzrdf7e2e599v3r8jmwvsw9jr9g9xzk9hs4zg0gqzyrrlh2tupedzx77urarcd5fluedpydljn88fjd5qduyf4wqgf3v4zdhh0l3" />
    <content type="html">
      Iran Internet blackout visualized on our Public Dashboard - drop to near zero exposure after 2026-01-08 in scan and sinkhole telemetry:&lt;br/&gt;&lt;br/&gt;Scan results: &lt;a href=&#34;https://dashboard.shadowserver.org/statistics/combined/time-series/?date_range=30&amp;amp;source=population&amp;amp;source=population6&amp;amp;source=scan&amp;amp;source=scan6&amp;amp;geo=IR&amp;amp;geo=IQ&amp;amp;geo=PK&amp;amp;geo=SA&amp;amp;geo=TR&amp;amp;dataset=unique_ips&amp;amp;limit=100&amp;amp;group_by=geo&amp;amp;stacking=overlap&amp;amp;auto_update=on&#34;&gt;https://dashboard.shadowserver.org/statistics/combined/time-series/?date_range=30&amp;amp;source=population&amp;amp;source=population6&amp;amp;source=scan&amp;amp;source=scan6&amp;amp;geo=IR&amp;amp;geo=IQ&amp;amp;geo=PK&amp;amp;geo=SA&amp;amp;geo=TR&amp;amp;dataset=unique_ips&amp;amp;limit=100&amp;amp;group_by=geo&amp;amp;stacking=overlap&amp;amp;auto_update=on&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;Sinkhole results:&lt;br/&gt;&lt;a href=&#34;https://dashboard.shadowserver.org/statistics/combined/time-series/?date_range=30&amp;amp;source=sinkhole&amp;amp;source=sinkhole6&amp;amp;source=sinkhole_dns&amp;amp;geo=IR&amp;amp;geo=IQ&amp;amp;geo=PK&amp;amp;geo=SA&amp;amp;geo=TR&amp;amp;dataset=unique_ips&amp;amp;limit=100&amp;amp;group_by=geo&amp;amp;stacking=overlap&amp;amp;auto_update=on&#34;&gt;https://dashboard.shadowserver.org/statistics/combined/time-series/?date_range=30&amp;amp;source=sinkhole&amp;amp;source=sinkhole6&amp;amp;source=sinkhole_dns&amp;amp;geo=IR&amp;amp;geo=IQ&amp;amp;geo=PK&amp;amp;geo=SA&amp;amp;geo=TR&amp;amp;dataset=unique_ips&amp;amp;limit=100&amp;amp;group_by=geo&amp;amp;stacking=overlap&amp;amp;auto_update=on&lt;/a&gt;&lt;br/&gt; &lt;img src=&#34;https://media.infosec.exchange/infosec.exchange/media_attachments/files/115/887/451/719/821/075/original/363e59ff25ed64f6.png&#34;&gt; &lt;br/&gt; &lt;img src=&#34;https://media.infosec.exchange/infosec.exchange/media_attachments/files/115/887/451/724/952/690/original/8f4149dd94d2fd6e.png&#34;&gt; &lt;br/&gt;
    </content>
    <updated>2026-01-13T11:03:05Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsvq4d2umfylsm7d5ltg0xglpauxk89el46r8hpyen3swa40k4zu2qzyrrlh2tupedzx77urarcd5fluedpydljn88fjd5qduyf4wqgf3v4zc4hgwt</id>
    
      <title type="html">MongoBleed update: We added MongoDB CVE-2025-14847 tagging today ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsvq4d2umfylsm7d5ltg0xglpauxk89el46r8hpyen3swa40k4zu2qzyrrlh2tupedzx77urarcd5fluedpydljn88fjd5qduyf4wqgf3v4zc4hgwt" />
    <content type="html">
      MongoBleed update: We added MongoDB CVE-2025-14847 tagging today that is version based. This results in 74,854 possibly unpatched versions (out of 78,725 exposed today). IP data on vulnerable instances shared in our Open MongoDB Report:  &lt;a href=&#34;https://www.shadowserver.org/what-we-do/network-reporting/open-mongodb-report/&#34;&gt;https://www.shadowserver.org/what-we-do/network-reporting/open-mongodb-report/&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;Note FPs on CVE-2025-14847 tagging may be possible due to backporting patches without bumping versions.&lt;br/&gt;&lt;br/&gt;IP data on exposed instances is shared daily since Feb 2015!&lt;br/&gt;&lt;br/&gt;To view exposed info on Dashboard select source &amp;#39;scan&amp;#39; &amp;#39;scan6&amp;#39; &amp;amp; tag &amp;#39;mongodb&amp;#39; &lt;a href=&#34;https://dashboard.shadowserver.org/statistics/combined/time-series/?date_range=30&amp;amp;source=scan&amp;amp;source=scan6&amp;amp;tag=mongodb&amp;amp;dataset=unique_ips&amp;amp;limit=100&amp;amp;group_by=geo&amp;amp;stacking=stacked&amp;amp;auto_update=on&#34;&gt;https://dashboard.shadowserver.org/statistics/combined/time-series/?date_range=30&amp;amp;source=scan&amp;amp;source=scan6&amp;amp;tag=mongodb&amp;amp;dataset=unique_ips&amp;amp;limit=100&amp;amp;group_by=geo&amp;amp;stacking=stacked&amp;amp;auto_update=on&lt;/a&gt; &lt;br/&gt;&lt;br/&gt;Advisory &amp;amp; patch details on CVE-2025-14847 can be found at &lt;a href=&#34;https://jira.mongodb.org/browse/SERVER-115508&#34;&gt;https://jira.mongodb.org/browse/SERVER-115508&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;If you receive an alert from us, check for compromise!&lt;br/&gt;&lt;br/&gt;Upgrade to 8.2.3, 8.0.17, 7.0.28, 6.0.27, 5.0.32, or 4.4.30.&lt;br/&gt; &lt;img src=&#34;https://media.infosec.exchange/infosec.exchange/media_attachments/files/115/804/539/071/871/345/original/4b5a71716d55eb8d.png&#34;&gt; &lt;br/&gt;
    </content>
    <updated>2025-12-29T19:37:19Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqspx576dlj4s49uc9m046uup3z2zg42xav7edl0stsqa69ls3yn2dgzyrrlh2tupedzx77urarcd5fluedpydljn88fjd5qduyf4wqgf3v4zjtsree</id>
    
      <title type="html">Proud to once again support our LE partners in Operation Endgame ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqspx576dlj4s49uc9m046uup3z2zg42xav7edl0stsqa69ls3yn2dgzyrrlh2tupedzx77urarcd5fluedpydljn88fjd5qduyf4wqgf3v4zjtsree" />
    <content type="html">
      Proud to once again support our LE partners in Operation Endgame Season 3&lt;br/&gt;&lt;br/&gt;86M stolen data items from 525K victim IPs across 226 countries included in our new Rhadamanthys Historic Bot Victims Special Report, run overnight 2025-11-12&lt;br/&gt;&lt;br/&gt;More details:&lt;br/&gt;&lt;a href=&#34;https://shadowserver.org/news/rhadamanthys-historical-bot-infections-special-report/&#34;&gt;https://shadowserver.org/news/rhadamanthys-historical-bot-infections-special-report/&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;Latest Operation Endgame S03E01 video &amp;#34;STICKY FINGERS&amp;#34;:&lt;br/&gt;&lt;a href=&#34;https://operation-endgame.com&#34;&gt;https://operation-endgame.com&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;Europol Press Release:&lt;br/&gt;&lt;a href=&#34;https://europol.europa.eu/media-press/newsroom/news/end-of-game-for-cybercrime-infrastructure-1025-servers-taken-down&#34;&gt;https://europol.europa.eu/media-press/newsroom/news/end-of-game-for-cybercrime-infrastructure-1025-servers-taken-down&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;Rhadamanthys Historic Bot Victims Special Report technical details:&lt;br/&gt;&lt;a href=&#34;https://shadowserver.org/what-we-do/network-reporting/rhadamanthys-historical-bot-infections-special-report/&#34;&gt;https://shadowserver.org/what-we-do/network-reporting/rhadamanthys-historical-bot-infections-special-report/&lt;/a&gt;&lt;br/&gt; &lt;img src=&#34;https://media.infosec.exchange/infosec.exchange/media_attachments/files/115/541/853/377/753/956/original/8845c38319dc141e.jpeg&#34;&gt; &lt;br/&gt;
    </content>
    <updated>2025-11-13T10:12:55Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqs27nwr0cs35hu9qt0lqa3mqzqqh66fjvaqlrsw2u5sqcecshr2xwqzyrrlh2tupedzx77urarcd5fluedpydljn88fjd5qduyf4wqgf3v4zctgfw3</id>
    
      <title type="html">You can track CVE-2025-20333 &amp;amp; CVE-2025-20362 vulnerable ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqs27nwr0cs35hu9qt0lqa3mqzqqh66fjvaqlrsw2u5sqcecshr2xwqzyrrlh2tupedzx77urarcd5fluedpydljn88fjd5qduyf4wqgf3v4zctgfw3" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsy0lttsdjc9a5hgh5mhk705zrgm488uznz5de5tfqmajfmjz9npwqmhvldq&#39;&gt;nevent1q…vldq&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;You can track CVE-2025-20333 &amp;amp; CVE-2025-20362 vulnerable (unpatched) Cisco ASA/FTD instances here - &lt;a href=&#34;https://dashboard.shadowserver.org/statistics/combined/time-series/?date_range=30&amp;amp;source=http_vulnerable&amp;amp;source=http_vulnerable6&amp;amp;tag=cve-2025-20333%2B&amp;amp;tag=cve-2025-20362%2B&amp;amp;dataset=unique_ips&amp;amp;limit=100&amp;amp;group_by=geo&amp;amp;stacking=stacked&amp;amp;auto_update=on&#34;&gt;https://dashboard.shadowserver.org/statistics/combined/time-series/?date_range=30&amp;amp;source=http_vulnerable&amp;amp;source=http_vulnerable6&amp;amp;tag=cve-2025-20333%2B&amp;amp;tag=cve-2025-20362%2B&amp;amp;dataset=unique_ips&amp;amp;limit=100&amp;amp;group_by=geo&amp;amp;stacking=stacked&amp;amp;auto_update=on&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;Around ~45K vulnerable seen on 2025-10-04&lt;br/&gt; &lt;img src=&#34;https://media.infosec.exchange/infosec.exchange/media_attachments/files/115/320/968/714/049/981/original/26226bd44512bba6.png&#34;&gt; &lt;br/&gt;
    </content>
    <updated>2025-10-05T09:59:01Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsy0lttsdjc9a5hgh5mhk705zrgm488uznz5de5tfqmajfmjz9npwqzyrrlh2tupedzx77urarcd5fluedpydljn88fjd5qduyf4wqgf3v4zp3tj4j</id>
    
      <title type="html">Attention! Cisco ASA/FTD CVE-2025-20333 &amp;amp; CVE-2025-20362 ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsy0lttsdjc9a5hgh5mhk705zrgm488uznz5de5tfqmajfmjz9npwqzyrrlh2tupedzx77urarcd5fluedpydljn88fjd5qduyf4wqgf3v4zp3tj4j" />
    <content type="html">
      Attention!&lt;br/&gt;&lt;br/&gt;Cisco ASA/FTD CVE-2025-20333 &amp;amp; CVE-2025-20362 incidents: we are now reporting daily vulnerable Cisco ASA/FTD instances in our Vulnerable HTTP reporting: &lt;a href=&#34;https://www.shadowserver.org/what-we-do/network-reporting/vulnerable-http-report/&#34;&gt;https://www.shadowserver.org/what-we-do/network-reporting/vulnerable-http-report/&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;Over 48.8K unpatched IPs found on 2025-09-29. Top affected: US&lt;br/&gt;&lt;br/&gt;World map view of unpatched IPs: &lt;a href=&#34;https://dashboard.shadowserver.org/statistics/combined/map/?date_range=1&amp;amp;map_type=std&amp;amp;source=http_vulnerable&amp;amp;source=http_vulnerable6&amp;amp;tag=cve-2025-20333%2B&amp;amp;tag=cve-2025-20362%2B&amp;amp;data_set=count&amp;amp;scale=log&amp;amp;auto_update=on&#34;&gt;https://dashboard.shadowserver.org/statistics/combined/map/?date_range=1&amp;amp;map_type=std&amp;amp;source=http_vulnerable&amp;amp;source=http_vulnerable6&amp;amp;tag=cve-2025-20333%2B&amp;amp;tag=cve-2025-20362%2B&amp;amp;data_set=count&amp;amp;scale=log&amp;amp;auto_update=on&lt;/a&gt; &lt;br/&gt;&lt;br/&gt;Tree map view of unpatched IPs:&lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://dashboard.shadowserver.org/statistics/combined/tree/?date_range=1&amp;amp;source=http_vulnerable&amp;amp;source=http_vulnerable6&amp;amp;tag=cve-2025-20333%2B&amp;amp;tag=cve-2025-20362%2B&amp;amp;data_set=count&amp;amp;scale=log&amp;amp;auto_update=on&#34;&gt;https://dashboard.shadowserver.org/statistics/combined/tree/?date_range=1&amp;amp;source=http_vulnerable&amp;amp;source=http_vulnerable6&amp;amp;tag=cve-2025-20333%2B&amp;amp;tag=cve-2025-20362%2B&amp;amp;data_set=count&amp;amp;scale=log&amp;amp;auto_update=on&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;Advisory from Cisco: &lt;br/&gt;&lt;br/&gt;CVE-2025-20333: &lt;a href=&#34;https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-webvpn-z5xP8EUB&#34;&gt;https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-webvpn-z5xP8EUB&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;CVE-2025-20362: &lt;a href=&#34;https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-webvpn-YROOTUW&#34;&gt;https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-webvpn-YROOTUW&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;More info: US CISA Emergency Directive Identify and Mitigate Potential Compromise of Cisco Devices: &lt;a href=&#34;https://www.cisa.gov/news-events/directives/ed-25-03-identify-and-mitigate-potential-compromise-cisco-devices&#34;&gt;https://www.cisa.gov/news-events/directives/ed-25-03-identify-and-mitigate-potential-compromise-cisco-devices&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;#CyberCivilDefense &lt;br/&gt;&lt;br/&gt;(thanks also to &lt;span itemprop=&#34;mentions&#34; itemscope itemtype=&#34;https://schema.org/Person&#34;&gt;&lt;a itemprop=&#34;url&#34; href=&#34;/npub1lcc6wn885u6k395x5j5tmdm94r6dh9zajxm8gyk82pv2s2j3el7sc6lcye&#34; class=&#34;bg-lavender dark:prose:text-neutral-50 dark:text-neutral-50 dark:bg-garnet px-1&#34;&gt;&lt;span&gt;Kevin Beaumont&lt;/span&gt; (&lt;span class=&#34;italic&#34;&gt;npub1lcc…lcye&lt;/span&gt;)&lt;/a&gt;&lt;/span&gt; for confirmation of the detection methodology!)&lt;br/&gt; &lt;img src=&#34;https://media.infosec.exchange/infosec.exchange/media_attachments/files/115/292/500/258/845/986/original/84359ef27d4546f0.png&#34;&gt; &lt;br/&gt; &lt;img src=&#34;https://media.infosec.exchange/infosec.exchange/media_attachments/files/115/292/500/199/027/045/original/2631008dd329056c.png&#34;&gt; &lt;br/&gt;
    </content>
    <updated>2025-09-30T09:19:38Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsg43gkd5kjt937d0y7g5w99nyj406v5q8467rg4vdse03d7v7lx0qzyrrlh2tupedzx77urarcd5fluedpydljn88fjd5qduyf4wqgf3v4z3cz9fx</id>
    
      <title type="html">Citrix NetScaler CVE-2025-7775 patch rate as seen in our scans: ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsg43gkd5kjt937d0y7g5w99nyj406v5q8467rg4vdse03d7v7lx0qzyrrlh2tupedzx77urarcd5fluedpydljn88fjd5qduyf4wqgf3v4z3cz9fx" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqs8sxcyna04wrdu7g2c7hrfeashfkucpwp94l6u9m05ujjeuas58asptuw7r&#39;&gt;nevent1q…uw7r&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;Citrix NetScaler CVE-2025-7775 patch rate as seen in our scans: &lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://dashboard.shadowserver.org/statistics/combined/time-series/?date_range=7&amp;amp;source=http_vulnerable&amp;amp;source=http_vulnerable6&amp;amp;tag=cve-2025-7775%2B&amp;amp;dataset=unique_ips&amp;amp;limit=100&amp;amp;group_by=geo&amp;amp;stacking=stacked&amp;amp;auto_update=on&#34;&gt;https://dashboard.shadowserver.org/statistics/combined/time-series/?date_range=7&amp;amp;source=http_vulnerable&amp;amp;source=http_vulnerable6&amp;amp;tag=cve-2025-7775%2B&amp;amp;dataset=unique_ips&amp;amp;limit=100&amp;amp;group_by=geo&amp;amp;stacking=stacked&amp;amp;auto_update=on&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://dashboard.shadowserver.org/statistics/combined/time-series/?date_range=7&amp;amp;source=http_vulnerable&amp;amp;source=http_vulnerable6&amp;amp;tag=cve-2025-7775%2B&amp;amp;dataset=unique_ips&amp;amp;limit=100&amp;amp;group_by=geo&amp;amp;stacking=overlap&amp;amp;auto_update=on&#34;&gt;https://dashboard.shadowserver.org/statistics/combined/time-series/?date_range=7&amp;amp;source=http_vulnerable&amp;amp;source=http_vulnerable6&amp;amp;tag=cve-2025-7775%2B&amp;amp;dataset=unique_ips&amp;amp;limit=100&amp;amp;group_by=geo&amp;amp;stacking=overlap&amp;amp;auto_update=on&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;Now down from 28.2K to 12.4K. Europe patching at a faster rate than North America ...&lt;br/&gt;&lt;br/&gt;(you can toggle overlapping/stacked time series on our Dashboard to compare)&lt;br/&gt; &lt;img src=&#34;https://media.infosec.exchange/infosec.exchange/media_attachments/files/115/112/268/405/501/723/original/fbe5fbbfef634d35.png&#34;&gt; &lt;br/&gt;
    </content>
    <updated>2025-08-29T13:23:51Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqs8sxcyna04wrdu7g2c7hrfeashfkucpwp94l6u9m05ujjeuas58aszyrrlh2tupedzx77urarcd5fluedpydljn88fjd5qduyf4wqgf3v4z79j64d</id>
    
      <title type="html">ALERT: On 2025-08-26 over 28K Citrix NetScaler instances were ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqs8sxcyna04wrdu7g2c7hrfeashfkucpwp94l6u9m05ujjeuas58aszyrrlh2tupedzx77urarcd5fluedpydljn88fjd5qduyf4wqgf3v4z79j64d" />
    <content type="html">
      ALERT: On 2025-08-26 over 28K Citrix NetScaler instances were unpatched to CVE-2025-7775 RCE. There is exploitation in the wild confirmed by US CISA KEV list addition.&lt;br/&gt;&lt;br/&gt;Patch info from Citrix: &lt;a href=&#34;https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX694938&#34;&gt;https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX694938&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;Top affected: US, Germany&lt;br/&gt;&lt;br/&gt;Dashboard geo breakdown: &lt;a href=&#34;https://dashboard.shadowserver.org/statistics/combined/tree/?date_range=1&amp;amp;source=exchange&amp;amp;source=exchange6&amp;amp;source=http_vulnerable&amp;amp;source=http_vulnerable6&amp;amp;tag=cve-2025-7775%2B&amp;amp;data_set=count&amp;amp;scale=log&amp;amp;auto_update=on&#34;&gt;https://dashboard.shadowserver.org/statistics/combined/tree/?date_range=1&amp;amp;source=exchange&amp;amp;source=exchange6&amp;amp;source=http_vulnerable&amp;amp;source=http_vulnerable6&amp;amp;tag=cve-2025-7775%2B&amp;amp;data_set=count&amp;amp;scale=log&amp;amp;auto_update=on&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;IP data is being shared in our Vulnerable HTTP reporting &lt;a href=&#34;https://www.shadowserver.org/what-we-do/network-reporting/vulnerable-http-report/&#34;&gt;https://www.shadowserver.org/what-we-do/network-reporting/vulnerable-http-report/&lt;/a&gt; (tagged &amp;#39;cve-2025-7775&amp;#39;)&lt;br/&gt;&lt;br/&gt;If you receive an alert from us investigate for compromise&lt;br/&gt;&lt;br/&gt;You can track CVE-2025-7775 patching progress on our Dashboard at: &lt;a href=&#34;https://dashboard.shadowserver.org/statistics/combined/time-series/?date_range=7&amp;amp;source=http_vulnerable&amp;amp;source=http_vulnerable6&amp;amp;tag=cve-2025-7775%2B&amp;amp;dataset=unique_ips&amp;amp;limit=100&amp;amp;group_by=geo&amp;amp;stacking=stacked&amp;amp;auto_update=on&#34;&gt;https://dashboard.shadowserver.org/statistics/combined/time-series/?date_range=7&amp;amp;source=http_vulnerable&amp;amp;source=http_vulnerable6&amp;amp;tag=cve-2025-7775%2B&amp;amp;dataset=unique_ips&amp;amp;limit=100&amp;amp;group_by=geo&amp;amp;stacking=stacked&amp;amp;auto_update=on&lt;/a&gt;&lt;br/&gt; &lt;img src=&#34;https://media.infosec.exchange/infosec.exchange/media_attachments/files/115/100/456/735/893/197/original/d18ce5940dbfe1cc.png&#34;&gt; &lt;br/&gt;
    </content>
    <updated>2025-08-27T11:19:56Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsqggl3tr7w87znek8kn9vqse8ynxd8gtq78cyjaru72flqfu8s3vgzyrrlh2tupedzx77urarcd5fluedpydljn88fjd5qduyf4wqgf3v4za7kddv</id>
    
      <title type="html">We are also scanning for Ivanti EPMM instances likely vulnerable ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsqggl3tr7w87znek8kn9vqse8ynxd8gtq78cyjaru72flqfu8s3vgzyrrlh2tupedzx77urarcd5fluedpydljn88fjd5qduyf4wqgf3v4za7kddv" />
    <content type="html">
      We are also scanning for Ivanti EPMM instances likely vulnerable (unpatched) to CVE-2025-4427 which can be chained with CVE-2025-4428 for RCE.&lt;br/&gt;&lt;br/&gt;First scans found 940 instances (2025-05-15), down to 798 (2025-05-18). &lt;br/&gt;&lt;br/&gt;Geo breakdown: &lt;a href=&#34;https://dashboard.shadowserver.org/statistics/combined/tree/?date_range=1&amp;amp;source=http_vulnerable&amp;amp;source=http_vulnerable6&amp;amp;tag=cve-2025-4427%2B&amp;amp;data_set=count&amp;amp;scale=log&amp;amp;auto_update=on&#34;&gt;https://dashboard.shadowserver.org/statistics/combined/tree/?date_range=1&amp;amp;source=http_vulnerable&amp;amp;source=http_vulnerable6&amp;amp;tag=cve-2025-4427%2B&amp;amp;data_set=count&amp;amp;scale=log&amp;amp;auto_update=on&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;IP data in &lt;a href=&#34;https://shadowserver.org/what-we-do/network-reporting/vulnerable-http-report/&#34;&gt;https://shadowserver.org/what-we-do/network-reporting/vulnerable-http-report/&lt;/a&gt; tagged as &amp;#39;cve-2025-4427&amp;#39;. &lt;br/&gt;&lt;br/&gt;Detection is based on non-intrusive check provided by &lt;span itemprop=&#34;mentions&#34; itemscope itemtype=&#34;https://schema.org/Person&#34;&gt;&lt;a itemprop=&#34;url&#34; href=&#34;/npub1r4a3cqjhh06tmrex84st3w20407uuq3w4q2m5v3mcu86ffzdlchqj2u230&#34; class=&#34;bg-lavender dark:prose:text-neutral-50 dark:text-neutral-50 dark:bg-garnet px-1&#34;&gt;&lt;span&gt;watchTowr&lt;/span&gt; (&lt;span class=&#34;italic&#34;&gt;npub1r4a…u230&lt;/span&gt;)&lt;/a&gt;&lt;/span&gt;  &lt;br/&gt;&lt;br/&gt;CVE-2025-4427 tracker: &lt;a href=&#34;https://dashboard.shadowserver.org/statistics/combined/time-series/?date_range=30&amp;amp;source=exchange&amp;amp;source=exchange6&amp;amp;source=http_vulnerable&amp;amp;source=http_vulnerable6&amp;amp;tag=cve-2025-4427%2B&amp;amp;dataset=unique_ips&amp;amp;limit=100&amp;amp;group_by=geo&amp;amp;stacking=stacked&amp;amp;auto_update=on&#34;&gt;https://dashboard.shadowserver.org/statistics/combined/time-series/?date_range=30&amp;amp;source=exchange&amp;amp;source=exchange6&amp;amp;source=http_vulnerable&amp;amp;source=http_vulnerable6&amp;amp;tag=cve-2025-4427%2B&amp;amp;dataset=unique_ips&amp;amp;limit=100&amp;amp;group_by=geo&amp;amp;stacking=stacked&amp;amp;auto_update=on&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;If you receive an alert, please make sure to review for any compromise - CVE-2025-4427/CVE-2025-4428 are exploited in the wild.&lt;br/&gt;&lt;br/&gt;Patch info from Ivanti: &lt;a href=&#34;https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-Endpoint-Manager-Mobile-EPMM?language=en_US&amp;amp;_gl=1*1ylgtgu*_gcl_au*MTg5MTk4MDIzMC4xNzQ3MTU3OTQ1&#34;&gt;https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-Endpoint-Manager-Mobile-EPMM?language=en_US&amp;amp;_gl=1*1ylgtgu*_gcl_au*MTg5MTk4MDIzMC4xNzQ3MTU3OTQ1&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;Background on vulnerabilities:&lt;br/&gt;&lt;a href=&#34;https://labs.watchtowr.com/expression-payloads-meet-mayhem-cve-2025-4427-and-cve-2025-4428/&#34;&gt;https://labs.watchtowr.com/expression-payloads-meet-mayhem-cve-2025-4427-and-cve-2025-4428/&lt;/a&gt;&lt;br/&gt; &lt;img src=&#34;https://media.infosec.exchange/infosec.exchange/media_attachments/files/114/534/093/733/580/185/original/e8aed2f83e41a88c.png&#34;&gt; &lt;br/&gt;
    </content>
    <updated>2025-05-19T10:46:29Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsxpa70yx7e2n9vsq0clj3djvguarep4zna5zaw03unpvtdggyuumgzyrrlh2tupedzx77urarcd5fluedpydljn88fjd5qduyf4wqgf3v4z620ty2</id>
    
      <title type="html">We started scanning for IoT devices compromised by the ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsxpa70yx7e2n9vsq0clj3djvguarep4zna5zaw03unpvtdggyuumgzyrrlh2tupedzx77urarcd5fluedpydljn88fjd5qduyf4wqgf3v4z620ty2" />
    <content type="html">
      We started scanning for IoT devices compromised by the Eleven11bot DDoS botnet, with ~86.4K discovered on 2025-03-02. IP data is shared daily in our Compromised IoT report &lt;a href=&#34;https://www.shadowserver.org/what-we-do/network-reporting/compromised-iot-report/&#34;&gt;https://www.shadowserver.org/what-we-do/network-reporting/compromised-iot-report/&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;Top affected: US (24.7K), UK (10.8K).&lt;br/&gt;&lt;br/&gt;Dashboard map view: &lt;a href=&#34;https://dashboard.shadowserver.org/statistics/combined/map/?map_type=std&amp;amp;day=2025-03-03&amp;amp;source=compromised_iot&amp;amp;tag=eleven11bot%2B&amp;amp;geo=all&amp;amp;data_set=count&amp;amp;scale=log&#34;&gt;https://dashboard.shadowserver.org/statistics/combined/map/?map_type=std&amp;amp;day=2025-03-03&amp;amp;source=compromised_iot&amp;amp;tag=eleven11bot%2B&amp;amp;geo=all&amp;amp;data_set=count&amp;amp;scale=log&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;For background, please see Nokia Deepfield Emergency Response Team (ERT) &lt;span itemprop=&#34;mentions&#34; itemscope itemtype=&#34;https://schema.org/Person&#34;&gt;&lt;a itemprop=&#34;url&#34; href=&#34;/npub1vc3sa53gknhcgzvzask6234v6d2kx8kqjz4gy6g7qc40u2ycltyss678jp&#34; class=&#34;bg-lavender dark:prose:text-neutral-50 dark:text-neutral-50 dark:bg-garnet px-1&#34;&gt;&lt;span&gt;Deepfield&lt;/span&gt; (&lt;span class=&#34;italic&#34;&gt;npub1vc3…78jp&lt;/span&gt;)&lt;/a&gt;&lt;/span&gt; announcement: &lt;a href=&#34;https://infosec.exchange/@deepfield/114086567369833954&#34;&gt;https://infosec.exchange/@deepfield/114086567369833954&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;Dashboard breakdown by US state:&lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://dashboard.shadowserver.org/statistics/combined/map/region/?map_type=std&amp;amp;day=2025-03-03&amp;amp;source=compromised_iot&amp;amp;geo=US&amp;amp;scale=log&#34;&gt;https://dashboard.shadowserver.org/statistics/combined/map/region/?map_type=std&amp;amp;day=2025-03-03&amp;amp;source=compromised_iot&amp;amp;geo=US&amp;amp;scale=log&lt;/a&gt;&lt;br/&gt; &lt;img src=&#34;https://media.infosec.exchange/infosec.exchange/media_attachments/files/114/103/924/472/469/357/original/603faa169e245410.png&#34;&gt; &lt;br/&gt; &lt;img src=&#34;https://media.infosec.exchange/infosec.exchange/media_attachments/files/114/103/924/501/203/167/original/ebb93e55c72eb2d4.png&#34;&gt; &lt;br/&gt;
    </content>
    <updated>2025-03-04T11:28:40Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsr3am6z29m8e9wtrpe0rquuf3udeuhpme35gqu6g97d7ahw8k6ffgzyrrlh2tupedzx77urarcd5fluedpydljn88fjd5qduyf4wqgf3v4zmmk3u8</id>
    
      <title type="html">We are sharing backdoored Ivanti Connect Secure devices that ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsr3am6z29m8e9wtrpe0rquuf3udeuhpme35gqu6g97d7ahw8k6ffgzyrrlh2tupedzx77urarcd5fluedpydljn88fjd5qduyf4wqgf3v4zmmk3u8" />
    <content type="html">
      We are sharing backdoored Ivanti Connect Secure devices that *may* have been compromised as part of a CVE-2025-0282 exploitation campaign (but also we believe may include older or other activity). &lt;br/&gt;&lt;br/&gt;379 new backdoored instances found on 2025-01-22: &lt;br/&gt;&lt;a href=&#34;https://dashboard.shadowserver.org/statistics/combined/tree/?day=2025-01-22&amp;amp;source=compromised_website&amp;amp;source=compromised_website6&amp;amp;tag=cve-2025-0282%2B&amp;amp;geo=all&amp;amp;data_set=count&amp;amp;scale=log&#34;&gt;https://dashboard.shadowserver.org/statistics/combined/tree/?day=2025-01-22&amp;amp;source=compromised_website&amp;amp;source=compromised_website6&amp;amp;tag=cve-2025-0282%2B&amp;amp;geo=all&amp;amp;data_set=count&amp;amp;scale=log&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;Data shared daily in our Compromised Website report &lt;a href=&#34;https://www.shadowserver.org/what-we-do/network-reporting/compromised-website-report/&#34;&gt;https://www.shadowserver.org/what-we-do/network-reporting/compromised-website-report/&lt;/a&gt; tagged &amp;#39;backdoor;ivanti-connect-secure&amp;#39;&lt;br/&gt;&lt;br/&gt;Dashboard tracker: &lt;a href=&#34;https://dashboard.shadowserver.org/statistics/combined/time-series/?date_range=7&amp;amp;source=compromised_website&amp;amp;source=compromised_website6&amp;amp;tag=backdoor%2B&amp;amp;dataset=unique_ips&amp;amp;limit=1000&amp;amp;group_by=geo&amp;amp;style=stacked&#34;&gt;https://dashboard.shadowserver.org/statistics/combined/time-series/?date_range=7&amp;amp;source=compromised_website&amp;amp;source=compromised_website6&amp;amp;tag=backdoor%2B&amp;amp;dataset=unique_ips&amp;amp;limit=1000&amp;amp;group_by=geo&amp;amp;style=stacked&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;Make sure to investigate your Ivanti Connect Secure instance if you receive an alert from us! &lt;span itemprop=&#34;mentions&#34; itemscope itemtype=&#34;https://schema.org/Person&#34;&gt;&lt;a itemprop=&#34;url&#34; href=&#34;/npub1e4qcsky02mq6rn9frj55g60lqhuqj072ktj5etjsjsjgenaeaxes7jv25r&#34; class=&#34;bg-lavender dark:prose:text-neutral-50 dark:text-neutral-50 dark:bg-garnet px-1&#34;&gt;&lt;span&gt;CISA Cyber&lt;/span&gt; (&lt;span class=&#34;italic&#34;&gt;npub1e4q…v25r&lt;/span&gt;)&lt;/a&gt;&lt;/span&gt; mitigation advice is a good start &lt;a href=&#34;https://www.cisa.gov/cisa-mitigation-instructions-cve-2025-0282&#34;&gt;https://www.cisa.gov/cisa-mitigation-instructions-cve-2025-0282&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;Thank you to &lt;span itemprop=&#34;mentions&#34; itemscope itemtype=&#34;https://schema.org/Person&#34;&gt;&lt;a itemprop=&#34;url&#34; href=&#34;/npub1duvrh6tj295e6nfmjn8haex33vlmzzgp9dkp4v2wmjjv8hj0v0wsclvh97&#34; class=&#34;bg-lavender dark:prose:text-neutral-50 dark:text-neutral-50 dark:bg-garnet px-1&#34;&gt;&lt;span&gt;Traficomin Kyberturvallisuuskeskus&lt;/span&gt; (&lt;span class=&#34;italic&#34;&gt;npub1duv…vh97&lt;/span&gt;)&lt;/a&gt;&lt;/span&gt; for the insights and detection methods!&lt;br/&gt; &lt;img src=&#34;https://media.infosec.exchange/infosec.exchange/media_attachments/files/113/879/473/928/537/367/original/8481e71dcb8c1a0a.png&#34;&gt; &lt;br/&gt;
    </content>
    <updated>2025-01-23T20:07:57Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqs82rumjyljq279qwg5h84987y3r72q9n7r3gccn9hsdgvld679yjqzyrrlh2tupedzx77urarcd5fluedpydljn88fjd5qduyf4wqgf3v4zxyklyj</id>
    
      <title type="html">We are sharing daily results of Fortinet CVE-2024-55591 (auth ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqs82rumjyljq279qwg5h84987y3r72q9n7r3gccn9hsdgvld679yjqzyrrlh2tupedzx77urarcd5fluedpydljn88fjd5qduyf4wqgf3v4zxyklyj" />
    <content type="html">
      We are sharing daily results of Fortinet CVE-2024-55591 (auth bypass) vulnerable instances in our Vulnerable HTTP report - &lt;a href=&#34;https://shadowserver.org/what-we-do/network-reporting/vulnerable-http-report/&#34;&gt;https://shadowserver.org/what-we-do/network-reporting/vulnerable-http-report/&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;CVE-2024-55591 is known to be exploited in the wild &amp;amp; on &lt;span itemprop=&#34;mentions&#34; itemscope itemtype=&#34;https://schema.org/Person&#34;&gt;&lt;a itemprop=&#34;url&#34; href=&#34;/npub1e4qcsky02mq6rn9frj55g60lqhuqj072ktj5etjsjsjgenaeaxes7jv25r&#34; class=&#34;bg-lavender dark:prose:text-neutral-50 dark:text-neutral-50 dark:bg-garnet px-1&#34;&gt;&lt;span&gt;CISA Cyber&lt;/span&gt; (&lt;span class=&#34;italic&#34;&gt;npub1e4q…v25r&lt;/span&gt;)&lt;/a&gt;&lt;/span&gt;  KEV.&lt;br/&gt;&lt;br/&gt;Around 50K found vulnerable: Around 50K found vulnerable: &lt;a href=&#34;https://dashboard.shadowserver.org/statistics/combined/map/?map_type=std&amp;amp;day=2025-01-19&amp;amp;source=http_vulnerable&amp;amp;source=http_vulnerable6&amp;amp;tag=cve-2024-55591%2B&amp;amp;geo=all&amp;amp;data_set=count&amp;amp;scale=log&#34;&gt;https://dashboard.shadowserver.org/statistics/combined/map/?map_type=std&amp;amp;day=2025-01-19&amp;amp;source=http_vulnerable&amp;amp;source=http_vulnerable6&amp;amp;tag=cve-2024-55591%2B&amp;amp;geo=all&amp;amp;data_set=count&amp;amp;scale=log&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;Our test is based on the methodology published by &lt;br/&gt;@watchtowrcyber&lt;br/&gt; &lt;a href=&#34;https://github.com/watchtowrlabs/fortios-auth-bypass-check-CVE-2024-55591/blob/main/CVE-2024-55591-check.py&#34;&gt;https://github.com/watchtowrlabs/fortios-auth-bypass-check-CVE-2024-55591/blob/main/CVE-2024-55591-check.py&lt;/a&gt; - thank you!&lt;br/&gt;&lt;br/&gt;CVE-2024-55591 vulnerability tracker: &lt;a href=&#34;https://dashboard.shadowserver.org/statistics/combined/time-series/?date_range=7&amp;amp;source=http_vulnerable&amp;amp;source=http_vulnerable6&amp;amp;tag=cve-2024-55591%2B&amp;amp;dataset=unique_ips&amp;amp;group_by=geo&amp;amp;style=stacked&#34;&gt;https://dashboard.shadowserver.org/statistics/combined/time-series/?date_range=7&amp;amp;source=http_vulnerable&amp;amp;source=http_vulnerable6&amp;amp;tag=cve-2024-55591%2B&amp;amp;dataset=unique_ips&amp;amp;group_by=geo&amp;amp;style=stacked&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;Fortinet advisory: &lt;a href=&#34;https://fortiguard.com/psirt/FG-IR-24-535&#34;&gt;https://fortiguard.com/psirt/FG-IR-24-535&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;Make sure to check for signs of compromise!&lt;br/&gt;&lt;br/&gt;Additional background: &lt;a href=&#34;https://arcticwolf.com/resources/blog/console-chaos-targets-fortinet-fortigate-firewalls/&#34;&gt;https://arcticwolf.com/resources/blog/console-chaos-targets-fortinet-fortigate-firewalls/&lt;/a&gt;&lt;br/&gt; &lt;img src=&#34;https://media.infosec.exchange/infosec.exchange/media_attachments/files/113/860/747/832/292/153/original/8a9dbbabbd12977b.png&#34;&gt; &lt;br/&gt;
    </content>
    <updated>2025-01-20T12:45:42Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqspg3gjh0580d0splfehjj9jwkdw9npw8tj96zn3nvntjuhffn26uszyrrlh2tupedzx77urarcd5fluedpydljn88fjd5qduyf4wqgf3v4zl4zcu4</id>
    
      <title type="html">Current Ivanti Connect Secure CVE-2025-0282 scanning results: ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqspg3gjh0580d0splfehjj9jwkdw9npw8tj96zn3nvntjuhffn26uszyrrlh2tupedzx77urarcd5fluedpydljn88fjd5qduyf4wqgf3v4zl4zcu4" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqsd7hstf4fh5pccfynd4tekns6reuq7j87px9xcp0n3hqe92ca66tshjf959&#39;&gt;nevent1q…f959&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;Current Ivanti Connect Secure CVE-2025-0282 scanning results: around 800 exposed unpatched devices (IPs) seen as of 2025-01-12 (drop from around 2000 seen 2025-01-09) &lt;br/&gt;&lt;br/&gt;CVE-2025-0282 vulnerability tracker: &lt;a href=&#34;https://dashboard.shadowserver.org/statistics/combined/time-series/?date_range=7&amp;amp;source=http_vulnerable&amp;amp;source=http_vulnerable6&amp;amp;tag=cve-2025-0282%2B&amp;amp;dataset=unique_ips&amp;amp;style=stacked&#34;&gt;https://dashboard.shadowserver.org/statistics/combined/time-series/?date_range=7&amp;amp;source=http_vulnerable&amp;amp;source=http_vulnerable6&amp;amp;tag=cve-2025-0282%2B&amp;amp;dataset=unique_ips&amp;amp;style=stacked&lt;/a&gt;&lt;br/&gt; &lt;img src=&#34;https://media.infosec.exchange/infosec.exchange/media_attachments/files/113/821/229/521/625/864/original/223ec8b001db1aa9.png&#34;&gt; &lt;br/&gt;
    </content>
    <updated>2025-01-13T13:15:34Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsd7hstf4fh5pccfynd4tekns6reuq7j87px9xcp0n3hqe92ca66tszyrrlh2tupedzx77urarcd5fluedpydljn88fjd5qduyf4wqgf3v4z9srlny</id>
    
      <title type="html">We have started reporting unpatched Ivanti Connect Secure ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsd7hstf4fh5pccfynd4tekns6reuq7j87px9xcp0n3hqe92ca66tszyrrlh2tupedzx77urarcd5fluedpydljn88fjd5qduyf4wqgf3v4z9srlny" />
    <content type="html">
      We have started reporting unpatched Ivanti Connect Secure instances likely vulnerable to the new known to be exploited in the wild CVE-2025-0282.&lt;br/&gt;&lt;br/&gt;We see 2048 likely vulnerable instances worldwide on 2025-01-09. Top: US&lt;br/&gt;&lt;br/&gt;Dashboard overview by country: &lt;a href=&#34;https://dashboard.shadowserver.org/statistics/combined/tree/?day=2025-01-09&amp;amp;source=exchange&amp;amp;source=exchange6&amp;amp;source=http_vulnerable&amp;amp;source=http_vulnerable6&amp;amp;tag=cve-2025-0282%2B&amp;amp;geo=all&amp;amp;data_set=count&amp;amp;scale=log&#34;&gt;https://dashboard.shadowserver.org/statistics/combined/tree/?day=2025-01-09&amp;amp;source=exchange&amp;amp;source=exchange6&amp;amp;source=http_vulnerable&amp;amp;source=http_vulnerable6&amp;amp;tag=cve-2025-0282%2B&amp;amp;geo=all&amp;amp;data_set=count&amp;amp;scale=log&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;Vulnerable IP data is shared daily for your network/constituency in our &lt;a href=&#34;https://shadowserver.org/what-we-do/network-reporting/vulnerable-http-report/&#34;&gt;https://shadowserver.org/what-we-do/network-reporting/vulnerable-http-report/&lt;/a&gt; tagged &amp;#39;cve-2025-0282&amp;#39;&lt;br/&gt;&lt;br/&gt;If you receive an alert from us, make sure to follow &lt;span itemprop=&#34;mentions&#34; itemscope itemtype=&#34;https://schema.org/Person&#34;&gt;&lt;a itemprop=&#34;url&#34; href=&#34;/npub1e4qcsky02mq6rn9frj55g60lqhuqj072ktj5etjsjsjgenaeaxes7jv25r&#34; class=&#34;bg-lavender dark:prose:text-neutral-50 dark:text-neutral-50 dark:bg-garnet px-1&#34;&gt;&lt;span&gt;CISA Cyber&lt;/span&gt; (&lt;span class=&#34;italic&#34;&gt;npub1e4q…v25r&lt;/span&gt;)&lt;/a&gt;&lt;/span&gt;  mitigation instructions: &lt;a href=&#34;https://cisa.gov/cisa-mitigation-instructions-cve-2025-0282&#34;&gt;https://cisa.gov/cisa-mitigation-instructions-cve-2025-0282&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;Ivanti patch info: &lt;a href=&#34;https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-Connect-Secure-Policy-Secure-ZTA-Gateways-CVE-2025-0282-CVE-2025-0283?language=en_US&#34;&gt;https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-Connect-Secure-Policy-Secure-ZTA-Gateways-CVE-2025-0282-CVE-2025-0283?language=en_US&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;Thank you to &lt;span itemprop=&#34;mentions&#34; itemscope itemtype=&#34;https://schema.org/Person&#34;&gt;&lt;a itemprop=&#34;url&#34; href=&#34;/npub1r4a3cqjhh06tmrex84st3w20407uuq3w4q2m5v3mcu86ffzdlchqj2u230&#34; class=&#34;bg-lavender dark:prose:text-neutral-50 dark:text-neutral-50 dark:bg-garnet px-1&#34;&gt;&lt;span&gt;watchTowr&lt;/span&gt; (&lt;span class=&#34;italic&#34;&gt;npub1r4a…u230&lt;/span&gt;)&lt;/a&gt;&lt;/span&gt;  for the insights and collaboration!&lt;br/&gt; &lt;img src=&#34;https://media.infosec.exchange/infosec.exchange/media_attachments/files/113/803/168/018/245/815/original/89dbf4e1908ef781.png&#34;&gt; &lt;br/&gt;
    </content>
    <updated>2025-01-10T08:42:22Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsqxdg6vh06g6fsgsz3f9rklxvwkefunu0psmevnr25a3tj9up0f5szyrrlh2tupedzx77urarcd5fluedpydljn88fjd5qduyf4wqgf3v4zss6vg2</id>
    
      <title type="html">We are seeing large numbers of sources scanning for RDP services ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsqxdg6vh06g6fsgsz3f9rklxvwkefunu0psmevnr25a3tj9up0f5szyrrlh2tupedzx77urarcd5fluedpydljn88fjd5qduyf4wqgf3v4zss6vg2" />
    <content type="html">
      We are seeing large numbers of sources scanning for RDP services - especially port 1098/TCP (!) - in our honeypot sensors last 2 weeks (up to 740 000 (!) distinct source IPs daily, incl up to 405 000 from Brazil). &lt;br/&gt;&lt;br/&gt;Tracker: &lt;a href=&#34;https://dashboard.shadowserver.org/statistics/honeypot/device/time-series/?date_range=30&amp;amp;type=rdp-scan&amp;amp;geo=BR&amp;amp;dataset=unique_ips&amp;amp;limit=1000&amp;amp;group_by=geo&amp;amp;style=stacked&#34;&gt;https://dashboard.shadowserver.org/statistics/honeypot/device/time-series/?date_range=30&amp;amp;type=rdp-scan&amp;amp;geo=BR&amp;amp;dataset=unique_ips&amp;amp;limit=1000&amp;amp;group_by=geo&amp;amp;style=stacked&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;Map of source IPs (2024-12-03): &lt;a href=&#34;https://dashboard.shadowserver.org/statistics/honeypot/device/map/?day=2024-12-03&amp;amp;type=rdp-scan&amp;amp;geo=all&amp;amp;data_set=count&amp;amp;scale=log&#34;&gt;https://dashboard.shadowserver.org/statistics/honeypot/device/map/?day=2024-12-03&amp;amp;type=rdp-scan&amp;amp;geo=all&amp;amp;data_set=count&amp;amp;scale=log&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;Make sure to limit unnecessary exposure of RDP and enable MFA.&lt;br/&gt;&lt;br/&gt;Note recent MS patch Tuesday had multiple fixes for RDP vulnerabilities:  CVE-2024-49106, CVE-2024-49108, CVE-2024-49115, CVE-2024-49119, CVE-2024-49120, CVE-2024-49123, CVE-2024-49132, CVE-2024-49116, CVE-2024-49128&lt;br/&gt;&lt;br/&gt;We observe many MikroTik routers behind the probes, but these could be other devices/residential proxies behind the routers&lt;br/&gt;&lt;br/&gt;Source IPs by device type (in cases where we are able to identify the device type): &lt;a href=&#34;https://dashboard.shadowserver.org/statistics/honeypot/device/time-series/?date_range=30&amp;amp;type=rdp-scan&amp;amp;dataset=unique_ips&amp;amp;limit=1000&amp;amp;group_by=vendor&amp;amp;style=stacked&#34;&gt;https://dashboard.shadowserver.org/statistics/honeypot/device/time-series/?date_range=30&amp;amp;type=rdp-scan&amp;amp;dataset=unique_ips&amp;amp;limit=1000&amp;amp;group_by=vendor&amp;amp;style=stacked&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;We share data on the source IPs doing the scans in our Honeypot RDP Scanner Events report &lt;a href=&#34;https://shadowserver.org/what-we-do/network-reporting/honeypot-rdp-scanner-events-report/&#34;&gt;https://shadowserver.org/what-we-do/network-reporting/honeypot-rdp-scanner-events-report/&lt;/a&gt;  &lt;br/&gt;&lt;br/&gt;The file name for that report is event4_honeypot_rdp_scan&lt;br/&gt;&lt;br/&gt;Insights welcome!&lt;br/&gt; &lt;img src=&#34;https://media.infosec.exchange/infosec.exchange/media_attachments/files/113/645/233/917/756/941/original/f088e6c868dd90b6.png&#34;&gt; &lt;br/&gt; &lt;img src=&#34;https://media.infosec.exchange/infosec.exchange/media_attachments/files/113/645/233/918/253/055/original/71310c861dc6e8ff.png&#34;&gt; &lt;br/&gt; &lt;img src=&#34;https://media.infosec.exchange/infosec.exchange/media_attachments/files/113/645/233/940/350/665/original/54db64ade996ba10.png&#34;&gt; &lt;br/&gt;
    </content>
    <updated>2024-12-13T11:17:40Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsdnynf5jt3hn2sw5mmfu2n2u52yjzmv77mzr5u7rarkkp3gvlptrczyrrlh2tupedzx77urarcd5fluedpydljn88fjd5qduyf4wqgf3v4zdf8d56</id>
    
      <title type="html">Palo Alto Networks has now updated their advisory ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsdnynf5jt3hn2sw5mmfu2n2u52yjzmv77mzr5u7rarkkp3gvlptrczyrrlh2tupedzx77urarcd5fluedpydljn88fjd5qduyf4wqgf3v4zdf8d56" />
    <content type="html">
      In reply to &lt;a href=&#39;/nevent1qqszp4wyqkvpzaqd34v9k78fpa9zct2gfw220ugs99wjkjn726txckccqr90w&#39;&gt;nevent1q…r90w&lt;/a&gt;&lt;br/&gt;_________________________&lt;br/&gt;&lt;br/&gt;Palo Alto Networks has now updated their advisory &lt;a href=&#34;https://security.paloaltonetworks.com/PAN-SA-2024-0015&#34;&gt;https://security.paloaltonetworks.com/PAN-SA-2024-0015&lt;/a&gt; saying they have &amp;#34;observed threat activity exploiting an unauthenticated remote command execution vulnerability against a limited number of firewall management interfaces which are exposed to the Internet.&amp;#34;&lt;br/&gt;&lt;br/&gt;We see a drop in exposed PAN-OS Management Interfaces (down by around 2K from previously shared observations), currently at 8726 IPs &lt;br/&gt;&lt;br/&gt;Get these Interfaces off public Internet access NOW!&lt;br/&gt; &lt;br/&gt;PAN-OS Management Interface tracker: &lt;a href=&#34;https://dashboard.shadowserver.org/statistics/iot-devices/time-series/?date_range=7&amp;amp;vendor=palo&#43;alto&#43;networks&amp;amp;model=pan-os&#43;management&#43;interface&amp;amp;dataset=count&amp;amp;limit=1000&amp;amp;group_by=geo&amp;amp;style=stacked&#34;&gt;https://dashboard.shadowserver.org/statistics/iot-devices/time-series/?date_range=7&amp;amp;vendor=palo&#43;alto&#43;networks&amp;amp;model=pan-os&#43;management&#43;interface&amp;amp;dataset=count&amp;amp;limit=1000&amp;amp;group_by=geo&amp;amp;style=stacked&lt;/a&gt;&lt;br/&gt; &lt;img src=&#34;https://media.infosec.exchange/infosec.exchange/media_attachments/files/113/486/852/283/850/949/original/a3a43a4d298e3a4f.png&#34;&gt; &lt;br/&gt;
    </content>
    <updated>2024-11-15T11:59:16Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqst9zcdh9h58uxave2s8p58rayau00ervgf5vt2dkkdr66kn883vsczyrrlh2tupedzx77urarcd5fluedpydljn88fjd5qduyf4wqgf3v4zajalxf</id>
    
      <title type="html">We have observed D-Link NAS CVE-2024-10914 ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqst9zcdh9h58uxave2s8p58rayau00ervgf5vt2dkkdr66kn883vsczyrrlh2tupedzx77urarcd5fluedpydljn88fjd5qduyf4wqgf3v4zajalxf" />
    <content type="html">
      We have observed D-Link NAS CVE-2024-10914 /cgi-bin/account_mgr.cgi command injection exploitation attempts starting Nov 12th. This vuln affects EOL/EOS devices, which should be removed  from the Internet: &lt;a href=&#34;https://supportannouncement.us.dlink.com/security/publication.aspx?name=SAP10413&#34;&gt;https://supportannouncement.us.dlink.com/security/publication.aspx?name=SAP10413&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;We see ~1100 exposed.&lt;br/&gt;&lt;br/&gt;&lt;a href=&#34;https://dashboard.shadowserver.org/statistics/iot-devices/tree/?day=2024-11-12&amp;amp;vendor=d-link&amp;amp;type=nas&amp;amp;geo=all&amp;amp;data_set=count&amp;amp;scale=log&#34;&gt;https://dashboard.shadowserver.org/statistics/iot-devices/tree/?day=2024-11-12&amp;amp;vendor=d-link&amp;amp;type=nas&amp;amp;geo=all&amp;amp;data_set=count&amp;amp;scale=log&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;We share IP data on exposed D-Link NAS instances for your network/constituency in our Device ID reports (vendor D-Link, type: nas): &lt;a href=&#34;https://shadowserver.org/what-we-do/network-reporting/device-identification-report/&#34;&gt;https://shadowserver.org/what-we-do/network-reporting/device-identification-report/&lt;/a&gt; &lt;br/&gt;&lt;br/&gt;D-Link NAS exposure tracker &lt;a href=&#34;https://dashboard.shadowserver.org/statistics/iot-devices/time-series/?date_range=7&amp;amp;vendor=d-link&amp;amp;type=nas&amp;amp;model=sharecenter&amp;amp;dataset=count&amp;amp;limit=1000&amp;amp;group_by=geo&amp;amp;style=stacked&#34;&gt;https://dashboard.shadowserver.org/statistics/iot-devices/time-series/?date_range=7&amp;amp;vendor=d-link&amp;amp;type=nas&amp;amp;model=sharecenter&amp;amp;dataset=count&amp;amp;limit=1000&amp;amp;group_by=geo&amp;amp;style=stacked&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;NVD entry:  &lt;a href=&#34;https://nvd.nist.gov/vuln/detail/CVE-2024-10914&#34;&gt;https://nvd.nist.gov/vuln/detail/CVE-2024-10914&lt;/a&gt;&lt;br/&gt; &lt;img src=&#34;https://media.infosec.exchange/infosec.exchange/media_attachments/files/113/475/031/265/868/369/original/0c61bb79a06800a8.png&#34;&gt; &lt;br/&gt;
    </content>
    <updated>2024-11-13T09:52:48Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqszp4wyqkvpzaqd34v9k78fpa9zct2gfw220ugs99wjkjn726txckczyrrlh2tupedzx77urarcd5fluedpydljn88fjd5qduyf4wqgf3v4zgh5vks</id>
    
      <title type="html">Palo Alto Networks published an advisory on 2024-11-08 warning of ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqszp4wyqkvpzaqd34v9k78fpa9zct2gfw220ugs99wjkjn726txckczyrrlh2tupedzx77urarcd5fluedpydljn88fjd5qduyf4wqgf3v4zgh5vks" />
    <content type="html">
      Palo Alto Networks published an advisory on 2024-11-08 warning of a claim of an RCE via the PAN-OS management interface. While no exploitation activity has yet been observed, we added fingerprinting for exposed PAN-OS mgmt interfaces in our Device ID report to warn recipients of potential attack surface exposure.&lt;br/&gt;&lt;br/&gt;We see around 11K IPs exposed (2024-11-10 scan).&lt;br/&gt;&lt;br/&gt;You can view exposure on our Dashboard  selecting &amp;#34;IoT device statistics&amp;#34;  in the top nav bar and setting vendor to &amp;#34;Palo Alto Networks&amp;#34; and model to &amp;#34;PAN-OS Management Interface&amp;#34;&lt;br/&gt;&lt;br/&gt;World map view: &lt;a href=&#34;https://dashboard.shadowserver.org/statistics/iot-devices/map/?day=2024-11-10&amp;amp;vendor=palo&#43;alto&#43;networks&amp;amp;model=pan-os&#43;management&#43;interface&amp;amp;geo=all&amp;amp;data_set=count&amp;amp;scale=log&#34;&gt;https://dashboard.shadowserver.org/statistics/iot-devices/map/?day=2024-11-10&amp;amp;vendor=palo&#43;alto&#43;networks&amp;amp;model=pan-os&#43;management&#43;interface&amp;amp;geo=all&amp;amp;data_set=count&amp;amp;scale=log&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;PAN-OS mgmt exposure tracker:&lt;br/&gt;&lt;a href=&#34;https://dashboard.shadowserver.org/statistics/iot-devices/time-series/?date_range=7&amp;amp;vendor=palo&#43;alto&#43;networks&amp;amp;model=pan-os&#43;management&#43;interface&amp;amp;dataset=count&amp;amp;limit=1000&amp;amp;group_by=geo&amp;amp;style=stacked&#34;&gt;https://dashboard.shadowserver.org/statistics/iot-devices/time-series/?date_range=7&amp;amp;vendor=palo&#43;alto&#43;networks&amp;amp;model=pan-os&#43;management&#43;interface&amp;amp;dataset=count&amp;amp;limit=1000&amp;amp;group_by=geo&amp;amp;style=stacked&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;IP data is now shared daily in our Device ID report  &lt;a href=&#34;https://shadowserver.org/what-we-do/network-reporting/device-identification-report/&#34;&gt;https://shadowserver.org/what-we-do/network-reporting/device-identification-report/&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;Palo Alto Networks security alert advisory &lt;a href=&#34;https://security.paloaltonetworks.com/PAN-SA-2024-0015&#34;&gt;https://security.paloaltonetworks.com/PAN-SA-2024-0015&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;Guidance on &amp;#34;How to Secure the Management Access of Your Palo Alto Networks Device&amp;#34; by Palo Alto Networks: &lt;a href=&#34;https://live.paloaltonetworks.com/t5/community-blogs/tips-amp-tricks-how-to-secure-the-management-access-of-your-palo/ba-p/464431&#34;&gt;https://live.paloaltonetworks.com/t5/community-blogs/tips-amp-tricks-how-to-secure-the-management-access-of-your-palo/ba-p/464431&lt;/a&gt;&lt;br/&gt;&lt;br/&gt;PAN-OS Management Exposure by US state:&lt;br/&gt;&lt;a href=&#34;https://dashboard.shadowserver.org/statistics/iot-devices/map/?day=2024-11-10&amp;amp;vendor=palo&#43;alto&#43;networks&amp;amp;model=pan-os&#43;management&#43;interface&amp;amp;geo=all&amp;amp;data_set=count&amp;amp;scale=log&#34;&gt;https://dashboard.shadowserver.org/statistics/iot-devices/map/?day=2024-11-10&amp;amp;vendor=palo&#43;alto&#43;networks&amp;amp;model=pan-os&#43;management&#43;interface&amp;amp;geo=all&amp;amp;data_set=count&amp;amp;scale=log&lt;/a&gt;&lt;br/&gt; &lt;img src=&#34;https://media.infosec.exchange/infosec.exchange/media_attachments/files/113/465/054/840/811/396/original/18e46137863c1075.png&#34;&gt; &lt;br/&gt; &lt;img src=&#34;https://media.infosec.exchange/infosec.exchange/media_attachments/files/113/465/054/838/904/285/original/24505d8672a587a1.png&#34;&gt; &lt;br/&gt;
    </content>
    <updated>2024-11-11T15:35:52Z</updated>
  </entry>

  <entry>
    <id>https://yabu.me/nevent1qqsyeuc4nvh8alykwy28647fnzqu4d76d242dv6cehsgkdafsq8pavgzyrrlh2tupedzx77urarcd5fluedpydljn88fjd5qduyf4wqgf3v4z8v6ld3</id>
    
      <title type="html">We started seeing some Progress WhatsUp Gold CVE-2024-6670 (CVSS ...</title>
    
    <link rel="alternate" href="https://yabu.me/nevent1qqsyeuc4nvh8alykwy28647fnzqu4d76d242dv6cehsgkdafsq8pavgzyrrlh2tupedzx77urarcd5fluedpydljn88fjd5qduyf4wqgf3v4z8v6ld3" />
    <content type="html">
      We started seeing some Progress WhatsUp Gold CVE-2024-6670 (CVSS 9.8) SQLi exploit attempts against our honeypot sensors that match recently published PoC (/NmConsole/Platform/PerformanceMonitorErrors/HasErrors endpoint)&lt;br/&gt;&lt;br/&gt;Progress advisory &amp;amp; patch info: &lt;a href=&#34;https://community.progress.com/s/article/WhatsUp-Gold-Security-Bulletin-August-2024&#34;&gt;https://community.progress.com/s/article/WhatsUp-Gold-Security-Bulletin-August-2024&lt;/a&gt;
    </content>
    <updated>2024-09-03T08:44:48Z</updated>
  </entry>

</feed>