GNU social JP
  • FAQ
  • Login
GNU social JPは日本のGNU socialサーバーです。
Usage/ToS/admin/test/Pleroma FE
  • Public

    • Public
    • Network
    • Groups
    • Featured
    • Popular
    • People

Conversation

Notices

  1. Embed this notice
    The Shadowserver Foundation (shadowserver@infosec.exchange)'s status on Monday, 19-May-2025 20:11:14 JST The Shadowserver Foundation The Shadowserver Foundation
    • watchTowr

    We are also scanning for Ivanti EPMM instances likely vulnerable (unpatched) to CVE-2025-4427 which can be chained with CVE-2025-4428 for RCE.

    First scans found 940 instances (2025-05-15), down to 798 (2025-05-18).

    Geo breakdown: https://dashboard.shadowserver.org/statistics/combined/tree/?date_range=1&source=http_vulnerable&source=http_vulnerable6&tag=cve-2025-4427%2B&data_set=count&scale=log&auto_update=on

    IP data in https://shadowserver.org/what-we-do/network-reporting/vulnerable-http-report/ tagged as 'cve-2025-4427'.

    Detection is based on non-intrusive check provided by @watchtowrcyber

    CVE-2025-4427 tracker: https://dashboard.shadowserver.org/statistics/combined/time-series/?date_range=30&source=exchange&source=exchange6&source=http_vulnerable&source=http_vulnerable6&tag=cve-2025-4427%2B&dataset=unique_ips&limit=100&group_by=geo&stacking=stacked&auto_update=on

    If you receive an alert, please make sure to review for any compromise - CVE-2025-4427/CVE-2025-4428 are exploited in the wild.

    Patch info from Ivanti: https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-Endpoint-Manager-Mobile-EPMM?language=en_US&_gl=1*1ylgtgu*_gcl_au*MTg5MTk4MDIzMC4xNzQ3MTU3OTQ1

    Background on vulnerabilities:
    https://labs.watchtowr.com/expression-payloads-meet-mayhem-cve-2025-4427-and-cve-2025-4428/

    In conversation about a year ago from infosec.exchange permalink

    Attachments

    1. No result found on File_thumbnail lookup.
      CRITICAL: Vulnerable HTTP Report | The Shadowserver Foundation
      DESCRIPTION LAST UPDATED: 2025-01-10 DEFAULT SEVERITY LEVEL: CRITICAL This report identifies hosts that have the Hypertext Transfer Protocol (HTTP) service running on some port that may have a vulnerability. We typically focus on pre-auth RCE vulnerabilities (or vulnerabilities that can be chained together by attackers to remotely execute code) in critical or otherwise popular software […]

    2. https://media.infosec.exchange/infosec.exchange/media_attachments/files/114/534/093/733/580/185/original/e8aed2f83e41a88c.png
    3. No result found on File_thumbnail lookup.
      Tree map · General statistics · The Shadowserver Foundation
    4. No result found on File_thumbnail lookup.
      Time series · General statistics · The Shadowserver Foundation
    5. No result found on File_thumbnail lookup.
      Ivanti Community
    6. Domain not in remote thumbnail source whitelist: labs.watchtowr.com
      Expression Payloads Meet Mayhem - Ivanti EPMM Unauth RCE Chain (CVE-2025-4427 and CVE-2025-4428)
      Keeping your ears to the ground and eyes wide open for the latest vulnerability news at watchTowr is a given. Despite rummaging through enterprise code looking for 0days on a daily basis, our interest was piqued this week when news of fresh vulnerabilities was announced in a close friend -

    Feeds

    • Activity Streams
    • RSS 2.0
    • Atom
    • Help
    • About
    • FAQ
    • TOS
    • Privacy
    • Source
    • Version
    • Contact

    GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.

    Creative Commons Attribution 3.0 All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.