GNU social JP
  • FAQ
  • Login
GNU social JPは日本のGNU socialサーバーです。
Usage/ToS/admin/test/Pleroma FE
  • Public

    • Public
    • Network
    • Groups
    • Featured
    • Popular
    • People

Untitled attachment

Download link

https://media.infosec.exchange/infosec.exchange/media_attachments/files/114/534/093/733/580/185/original/e8aed2f83e41a88c.png

Notices where this attachment appears

  1. Embed this notice
    The Shadowserver Foundation (shadowserver@infosec.exchange)'s status on Monday, 19-May-2025 20:11:14 JST The Shadowserver Foundation The Shadowserver Foundation

    We are also scanning for Ivanti EPMM instances likely vulnerable (unpatched) to CVE-2025-4427 which can be chained with CVE-2025-4428 for RCE.

    First scans found 940 instances (2025-05-15), down to 798 (2025-05-18).

    Geo breakdown: https://dashboard.shadowserver.org/statistics/combined/tree/?date_range=1&source=http_vulnerable&source=http_vulnerable6&tag=cve-2025-4427%2B&data_set=count&scale=log&auto_update=on

    IP data in https://shadowserver.org/what-we-do/network-reporting/vulnerable-http-report/ tagged as 'cve-2025-4427'.

    Detection is based on non-intrusive check provided by @watchtowrcyber

    CVE-2025-4427 tracker: https://dashboard.shadowserver.org/statistics/combined/time-series/?date_range=30&source=exchange&source=exchange6&source=http_vulnerable&source=http_vulnerable6&tag=cve-2025-4427%2B&dataset=unique_ips&limit=100&group_by=geo&stacking=stacked&auto_update=on

    If you receive an alert, please make sure to review for any compromise - CVE-2025-4427/CVE-2025-4428 are exploited in the wild.

    Patch info from Ivanti: https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-Endpoint-Manager-Mobile-EPMM?language=en_US&_gl=1*1ylgtgu*_gcl_au*MTg5MTk4MDIzMC4xNzQ3MTU3OTQ1

    Background on vulnerabilities:
    https://labs.watchtowr.com/expression-payloads-meet-mayhem-cve-2025-4427-and-cve-2025-4428/

    In conversation about a year ago from infosec.exchange permalink
  • Help
  • About
  • FAQ
  • TOS
  • Privacy
  • Source
  • Version
  • Contact

GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.

Creative Commons Attribution 3.0 All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.