GNU social JP
  • FAQ
  • Login
GNU social JPは日本のGNU socialサーバーです。
Usage/ToS/admin/test/Pleroma FE
  • Public

    • Public
    • Network
    • Groups
    • Featured
    • Popular
    • People

Notices by The Shadowserver Foundation (shadowserver@infosec.exchange)

  1. Embed this notice
    The Shadowserver Foundation (shadowserver@infosec.exchange)'s status on Monday, 16-Mar-2026 19:00:05 JST The Shadowserver Foundation The Shadowserver Foundation

    We added a feed of IPs/websites with ClickFix/ClearFake injected code in our Compromised Website reporting, tagged as 'clickfix'. Visitors of the website get tricked to install malware when injected JavaScript executes. If you receive an alert review for root cause of compromise!

    657 instances shared for 2026-03-14. We expect to increase the volume of the feed in the future!

    We would like to thank our Alliance partners and Validin for the collaboration making this possible!

    Background on investigating ClickFix/ClearFake: https://www.atea.no/siste-nytt/it-sikkerhet/investigating-a-clearfake-clickfix-etherhide-campaign/

    Compromised Website Report: https://www.shadowserver.org/what-we-do/network-reporting/compromised-website-report/

    Dashboard World Map view of infected IPs:
    https://dashboard.shadowserver.org/statistics/combined/map/?date_range=1&map_type=std&source=compromised_iot&source=compromised_website&source=compromised_website6&tag=clickfix&data_set=count&scale=log&auto_update=on

    Dashboard Tree Map view of infected IPs:
    https://dashboard.shadowserver.org/statistics/combined/tree/?date_range=1&source=compromised_iot&source=compromised_website&source=compromised_website6&tag=clickfix&data_set=count&scale=log&auto_update=on

    #CyberCivilDefense

    In conversation about 5 months ago from infosec.exchange permalink

    Attachments


    1. https://media.infosec.exchange/infosec.exchange/media_attachments/files/116/234/013/327/561/196/original/31f2c4e7f2f96d5e.png


    2. No result found on File_thumbnail lookup.
      World map · General statistics · The Shadowserver Foundation
    3. No result found on File_thumbnail lookup.
      Tree map · General statistics · The Shadowserver Foundation
  2. Embed this notice
    The Shadowserver Foundation (shadowserver@infosec.exchange)'s status on Tuesday, 30-Dec-2025 05:32:37 JST The Shadowserver Foundation The Shadowserver Foundation

    MongoBleed update: We added MongoDB CVE-2025-14847 tagging today that is version based. This results in 74,854 possibly unpatched versions (out of 78,725 exposed today). IP data on vulnerable instances shared in our Open MongoDB Report: https://www.shadowserver.org/what-we-do/network-reporting/open-mongodb-report/

    Note FPs on CVE-2025-14847 tagging may be possible due to backporting patches without bumping versions.

    IP data on exposed instances is shared daily since Feb 2015!

    To view exposed info on Dashboard select source 'scan' 'scan6' & tag 'mongodb' https://dashboard.shadowserver.org/statistics/combined/time-series/?date_range=30&source=scan&source=scan6&tag=mongodb&dataset=unique_ips&limit=100&group_by=geo&stacking=stacked&auto_update=on

    Advisory & patch details on CVE-2025-14847 can be found at https://jira.mongodb.org/browse/SERVER-115508

    If you receive an alert from us, check for compromise!

    Upgrade to 8.2.3, 8.0.17, 7.0.28, 6.0.27, 5.0.32, or 4.4.30.

    In conversation about 7 months ago from infosec.exchange permalink

    Attachments


    1. https://media.infosec.exchange/infosec.exchange/media_attachments/files/115/804/539/071/871/345/original/4b5a71716d55eb8d.png

    2. No result found on File_thumbnail lookup.
      Time series · General statistics · The Shadowserver Foundation
    3. Domain not in remote thumbnail source whitelist: jira.mongodb.org
      Loading...
  3. Embed this notice
    The Shadowserver Foundation (shadowserver@infosec.exchange)'s status on Thursday, 13-Nov-2025 22:11:03 JST The Shadowserver Foundation The Shadowserver Foundation

    Proud to once again support our LE partners in Operation Endgame Season 3

    86M stolen data items from 525K victim IPs across 226 countries included in our new Rhadamanthys Historic Bot Victims Special Report, run overnight 2025-11-12

    More details:
    https://shadowserver.org/news/rhadamanthys-historical-bot-infections-special-report/

    Latest Operation Endgame S03E01 video "STICKY FINGERS":
    https://operation-endgame.com

    Europol Press Release:
    https://europol.europa.eu/media-press/newsroom/news/end-of-game-for-cybercrime-infrastructure-1025-servers-taken-down

    Rhadamanthys Historic Bot Victims Special Report technical details:
    https://shadowserver.org/what-we-do/network-reporting/rhadamanthys-historical-bot-infections-special-report/

    In conversation about 9 months ago from infosec.exchange permalink

    Attachments


    1. https://media.infosec.exchange/infosec.exchange/media_attachments/files/115/541/853/377/753/956/original/8845c38319dc141e.jpeg



    2. No result found on File_thumbnail lookup.
      CRITICAL: Rhadamanthys Historical Bot Infections Special Report | The Shadowserver Foundation
      LAST UPDATED: 2025-11-12 DEFAULT SEVERITY LEVEL: CRITICAL This Special Report contains information about IP addresses and computer systems that are believed to have been infected with Rhadamanthys information stealing malware during the period between 2025-03-14 and 2025-11-11. It is a result of the continuing international Law Enforcement action called Operation Endgame which will be announced on […]
  4. Embed this notice
    The Shadowserver Foundation (shadowserver@infosec.exchange)'s status on Tuesday, 30-Sep-2025 20:09:22 JST The Shadowserver Foundation The Shadowserver Foundation
    • Kevin Beaumont

    Attention!

    Cisco ASA/FTD CVE-2025-20333 & CVE-2025-20362 incidents: we are now sharing daily vulnerable Cisco ASA/FTD instances in our Vulnerable HTTP reporting: https://www.shadowserver.org/what-we-do/network-reporting/vulnerable-http-report/

    Over 48.8K unpatched IPs found on 2025-09-29. Top affected: US

    World map view of unpatched IPs: https://dashboard.shadowserver.org/statistics/combined/map/?date_range=1&map_type=std&source=http_vulnerable&source=http_vulnerable6&tag=cve-2025-20333%2B&tag=cve-2025-20362%2B&data_set=count&scale=log&auto_update=on

    Tree map view of unpatched IPs:

    https://dashboard.shadowserver.org/statistics/combined/tree/?date_range=1&source=http_vulnerable&source=http_vulnerable6&tag=cve-2025-20333%2B&tag=cve-2025-20362%2B&data_set=count&scale=log&auto_update=on

    Advisory from Cisco:

    CVE-2025-20333: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-webvpn-z5xP8EUB

    CVE-2025-20362: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-asaftd-webvpn-YROOTUW

    More info: US CISA Emergency Directive Identify and Mitigate Potential Compromise of Cisco Devices: https://www.cisa.gov/news-events/directives/ed-25-03-identify-and-mitigate-potential-compromise-cisco-devices

    #CyberCivilDefense

    (thanks also to @GossiTheDog for confirmation of the detection methodology!)

    In conversation about 10 months ago from infosec.exchange permalink

    Attachments


    1. https://media.infosec.exchange/infosec.exchange/media_attachments/files/115/292/500/258/845/986/original/84359ef27d4546f0.png

    2. https://media.infosec.exchange/infosec.exchange/media_attachments/files/115/292/500/199/027/045/original/2631008dd329056c.png

    3. No result found on File_thumbnail lookup.
      World map · General statistics · The Shadowserver Foundation
    4. No result found on File_thumbnail lookup.
      Cisco Security
    5. No result found on File_thumbnail lookup.
      Cisco Security
    6. Domain not in remote thumbnail source whitelist: www.cisa.gov
      ED 25-03: Identify and Mitigate Potential Compromise of Cisco Devices | CISA
       This page contains a web-friendly version of the Cybersecurity and Infrastructure Security Agency’s Emergency Directive 25-03: Identify and Mitigate Potential
  5. Embed this notice
    The Shadowserver Foundation (shadowserver@infosec.exchange)'s status on Friday, 29-Aug-2025 22:27:16 JST The Shadowserver Foundation The Shadowserver Foundation
    in reply to

    Citrix NetScaler CVE-2025-7775 patch rate as seen in our scans:

    https://dashboard.shadowserver.org/statistics/combined/time-series/?date_range=7&source=http_vulnerable&source=http_vulnerable6&tag=cve-2025-7775%2B&dataset=unique_ips&limit=100&group_by=geo&stacking=stacked&auto_update=on

    https://dashboard.shadowserver.org/statistics/combined/time-series/?date_range=7&source=http_vulnerable&source=http_vulnerable6&tag=cve-2025-7775%2B&dataset=unique_ips&limit=100&group_by=geo&stacking=overlap&auto_update=on

    Now down from 28.2K to 12.4K. Europe patching at a faster rate than North America ...

    (you can toggle overlapping/stacked time series on our Dashboard to compare)

    In conversation about a year ago from infosec.exchange permalink

    Attachments


    1. https://media.infosec.exchange/infosec.exchange/media_attachments/files/115/112/268/405/501/723/original/fbe5fbbfef634d35.png
    2. No result found on File_thumbnail lookup.
      Time series · General statistics · The Shadowserver Foundation
  6. Embed this notice
    The Shadowserver Foundation (shadowserver@infosec.exchange)'s status on Wednesday, 27-Aug-2025 20:28:54 JST The Shadowserver Foundation The Shadowserver Foundation

    ALERT: On 2025-08-26 over 28K Citrix NetScaler instances were unpatched to CVE-2025-7775 RCE. There is exploitation in the wild confirmed by US CISA KEV list addition.

    Patch info from Citrix: https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX694938

    Top affected: US, Germany

    Dashboard geo breakdown: https://dashboard.shadowserver.org/statistics/combined/tree/?date_range=1&source=exchange&source=exchange6&source=http_vulnerable&source=http_vulnerable6&tag=cve-2025-7775%2B&data_set=count&scale=log&auto_update=on

    IP data is being shared in our Vulnerable HTTP reporting https://www.shadowserver.org/what-we-do/network-reporting/vulnerable-http-report/ (tagged 'cve-2025-7775')

    If you receive an alert from us investigate for compromise

    You can track CVE-2025-7775 patching progress on our Dashboard at: https://dashboard.shadowserver.org/statistics/combined/time-series/?date_range=7&source=http_vulnerable&source=http_vulnerable6&tag=cve-2025-7775%2B&dataset=unique_ips&limit=100&group_by=geo&stacking=stacked&auto_update=on

    In conversation about a year ago from infosec.exchange permalink

    Attachments

    1. No result found on File_thumbnail lookup.
      CRITICAL: Vulnerable HTTP Report | The Shadowserver Foundation
      DESCRIPTION LAST UPDATED: 2025-01-10 DEFAULT SEVERITY LEVEL: CRITICAL This report identifies hosts that have the Hypertext Transfer Protocol (HTTP) service running on some port that may have a vulnerability. We typically focus on pre-auth RCE vulnerabilities (or vulnerabilities that can be chained together by attackers to remotely execute code) in critical or otherwise popular software […]

    2. https://media.infosec.exchange/infosec.exchange/media_attachments/files/115/100/456/735/893/197/original/d18ce5940dbfe1cc.png
    3. No result found on File_thumbnail lookup.
      Loading...
    4. No result found on File_thumbnail lookup.
      Tree map · General statistics · The Shadowserver Foundation
    5. No result found on File_thumbnail lookup.
      Time series · General statistics · The Shadowserver Foundation
  7. Embed this notice
    The Shadowserver Foundation (shadowserver@infosec.exchange)'s status on Monday, 19-May-2025 20:11:14 JST The Shadowserver Foundation The Shadowserver Foundation
    • watchTowr

    We are also scanning for Ivanti EPMM instances likely vulnerable (unpatched) to CVE-2025-4427 which can be chained with CVE-2025-4428 for RCE.

    First scans found 940 instances (2025-05-15), down to 798 (2025-05-18).

    Geo breakdown: https://dashboard.shadowserver.org/statistics/combined/tree/?date_range=1&source=http_vulnerable&source=http_vulnerable6&tag=cve-2025-4427%2B&data_set=count&scale=log&auto_update=on

    IP data in https://shadowserver.org/what-we-do/network-reporting/vulnerable-http-report/ tagged as 'cve-2025-4427'.

    Detection is based on non-intrusive check provided by @watchtowrcyber

    CVE-2025-4427 tracker: https://dashboard.shadowserver.org/statistics/combined/time-series/?date_range=30&source=exchange&source=exchange6&source=http_vulnerable&source=http_vulnerable6&tag=cve-2025-4427%2B&dataset=unique_ips&limit=100&group_by=geo&stacking=stacked&auto_update=on

    If you receive an alert, please make sure to review for any compromise - CVE-2025-4427/CVE-2025-4428 are exploited in the wild.

    Patch info from Ivanti: https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-Endpoint-Manager-Mobile-EPMM?language=en_US&_gl=1*1ylgtgu*_gcl_au*MTg5MTk4MDIzMC4xNzQ3MTU3OTQ1

    Background on vulnerabilities:
    https://labs.watchtowr.com/expression-payloads-meet-mayhem-cve-2025-4427-and-cve-2025-4428/

    In conversation about a year ago from infosec.exchange permalink

    Attachments

    1. No result found on File_thumbnail lookup.
      CRITICAL: Vulnerable HTTP Report | The Shadowserver Foundation
      DESCRIPTION LAST UPDATED: 2025-01-10 DEFAULT SEVERITY LEVEL: CRITICAL This report identifies hosts that have the Hypertext Transfer Protocol (HTTP) service running on some port that may have a vulnerability. We typically focus on pre-auth RCE vulnerabilities (or vulnerabilities that can be chained together by attackers to remotely execute code) in critical or otherwise popular software […]

    2. https://media.infosec.exchange/infosec.exchange/media_attachments/files/114/534/093/733/580/185/original/e8aed2f83e41a88c.png
    3. No result found on File_thumbnail lookup.
      Tree map · General statistics · The Shadowserver Foundation
    4. No result found on File_thumbnail lookup.
      Time series · General statistics · The Shadowserver Foundation
    5. No result found on File_thumbnail lookup.
      Ivanti Community
    6. Domain not in remote thumbnail source whitelist: labs.watchtowr.com
      Expression Payloads Meet Mayhem - Ivanti EPMM Unauth RCE Chain (CVE-2025-4427 and CVE-2025-4428)
      Keeping your ears to the ground and eyes wide open for the latest vulnerability news at watchTowr is a given. Despite rummaging through enterprise code looking for 0days on a daily basis, our interest was piqued this week when news of fresh vulnerabilities was announced in a close friend -
  8. Embed this notice
    The Shadowserver Foundation (shadowserver@infosec.exchange)'s status on Monday, 20-Jan-2025 21:46:22 JST The Shadowserver Foundation The Shadowserver Foundation
    • CISA Cyber

    We are sharing daily results of Fortinet CVE-2024-55591 (auth bypass) vulnerable instances in our Vulnerable HTTP report - https://shadowserver.org/what-we-do/network-reporting/vulnerable-http-report/

    CVE-2024-55591 is known to be exploited in the wild & on @cisacyber KEV.

    Around 50K found vulnerable: Around 50K found vulnerable: https://dashboard.shadowserver.org/statistics/combined/map/?map_type=std&day=2025-01-19&source=http_vulnerable&source=http_vulnerable6&tag=cve-2024-55591%2B&geo=all&data_set=count&scale=log

    Our test is based on the methodology published by
    @watchtowrcyber
    https://github.com/watchtowrlabs/fortios-auth-bypass-check-CVE-2024-55591/blob/main/CVE-2024-55591-check.py - thank you!

    CVE-2024-55591 vulnerability tracker: https://dashboard.shadowserver.org/statistics/combined/time-series/?date_range=7&source=http_vulnerable&source=http_vulnerable6&tag=cve-2024-55591%2B&dataset=unique_ips&group_by=geo&style=stacked

    Fortinet advisory: https://fortiguard.com/psirt/FG-IR-24-535

    Make sure to check for signs of compromise!

    Additional background: https://arcticwolf.com/resources/blog/console-chaos-targets-fortinet-fortigate-firewalls/

    In conversation Monday, 20-Jan-2025 21:46:22 JST from infosec.exchange permalink

    Attachments


    1. https://media.infosec.exchange/infosec.exchange/media_attachments/files/113/860/747/832/292/153/original/8a9dbbabbd12977b.png

    2. No result found on File_thumbnail lookup.
      World map · General statistics · The Shadowserver Foundation
    3. Domain not in remote thumbnail source whitelist: opengraph.githubassets.com
      fortios-auth-bypass-check-CVE-2024-55591/CVE-2024-55591-check.py at main · watchtowrlabs/fortios-auth-bypass-check-CVE-2024-55591
      Contribute to watchtowrlabs/fortios-auth-bypass-check-CVE-2024-55591 development by creating an account on GitHub.
    4. No result found on File_thumbnail lookup.
      Time series · General statistics · The Shadowserver Foundation

    5. Invalid filename.
    6. Domain not in remote thumbnail source whitelist: arcticwolf.com
      Console Chaos: A Campaign Targeting Publicly Exposed Management Interfaces on Fortinet FortiGate Firewalls - Arctic Wolf
      from @AWNetworks
      Arctic Wolf Labs identified a campaign targeting Fortinet FortiGate firewall devices with exposed management interfaces.
  9. Embed this notice
    The Shadowserver Foundation (shadowserver@infosec.exchange)'s status on Monday, 13-Jan-2025 22:23:33 JST The Shadowserver Foundation The Shadowserver Foundation
    in reply to

    Current Ivanti Connect Secure CVE-2025-0282 scanning results: around 800 exposed unpatched devices (IPs) seen as of 2025-01-12 (drop from around 2000 seen 2025-01-09)

    CVE-2025-0282 vulnerability tracker: https://dashboard.shadowserver.org/statistics/combined/time-series/?date_range=7&source=http_vulnerable&source=http_vulnerable6&tag=cve-2025-0282%2B&dataset=unique_ips&style=stacked

    In conversation Monday, 13-Jan-2025 22:23:33 JST from infosec.exchange permalink

    Attachments


    1. https://media.infosec.exchange/infosec.exchange/media_attachments/files/113/821/229/521/625/864/original/223ec8b001db1aa9.png
    2. No result found on File_thumbnail lookup.
      Time series · General statistics · The Shadowserver Foundation
  10. Embed this notice
    The Shadowserver Foundation (shadowserver@infosec.exchange)'s status on Monday, 13-Jan-2025 22:23:33 JST The Shadowserver Foundation The Shadowserver Foundation
    • watchTowr
    • CISA Cyber

    We have started reporting unpatched Ivanti Connect Secure instances likely vulnerable to the new known to be exploited in the wild CVE-2025-0282.

    We see 2048 likely vulnerable instances worldwide on 2025-01-09. Top: US

    Dashboard overview by country: https://dashboard.shadowserver.org/statistics/combined/tree/?day=2025-01-09&source=exchange&source=exchange6&source=http_vulnerable&source=http_vulnerable6&tag=cve-2025-0282%2B&geo=all&data_set=count&scale=log

    Vulnerable IP data is shared daily for your network/constituency in our https://shadowserver.org/what-we-do/network-reporting/vulnerable-http-report/ tagged 'cve-2025-0282'

    If you receive an alert from us, make sure to follow @cisacyber mitigation instructions: https://cisa.gov/cisa-mitigation-instructions-cve-2025-0282

    Ivanti patch info: https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-Connect-Secure-Policy-Secure-ZTA-Gateways-CVE-2025-0282-CVE-2025-0283?language=en_US

    Thank you to @watchtowrcyber for the insights and collaboration!

    In conversation Monday, 13-Jan-2025 22:23:33 JST from infosec.exchange permalink

    Attachments


    1. https://media.infosec.exchange/infosec.exchange/media_attachments/files/113/803/168/018/245/815/original/89dbf4e1908ef781.png
    2. No result found on File_thumbnail lookup.
      Tree map · General statistics · The Shadowserver Foundation
    3. No result found on File_thumbnail lookup.
      CRITICAL: Vulnerable HTTP Report | The Shadowserver Foundation
      DESCRIPTION LAST UPDATED: 2025-01-10 DEFAULT SEVERITY LEVEL: CRITICAL This report identifies hosts that have the Hypertext Transfer Protocol (HTTP) service running on some port that may have a vulnerability. We typically focus on pre-auth RCE vulnerabilities (or vulnerabilities that can be chained together by attackers to remotely execute code) in critical or otherwise popular software […]

    4. No result found on File_thumbnail lookup.
      Ivanti Community
  11. Embed this notice
    The Shadowserver Foundation (shadowserver@infosec.exchange)'s status on Friday, 15-Nov-2024 21:29:41 JST The Shadowserver Foundation The Shadowserver Foundation
    in reply to

    Palo Alto Networks has now updated their advisory https://security.paloaltonetworks.com/PAN-SA-2024-0015 saying they have "observed threat activity exploiting an unauthenticated remote command execution vulnerability against a limited number of firewall management interfaces which are exposed to the Internet."

    We see a drop in exposed PAN-OS Management Interfaces (down by around 2K from previously shared observations), currently at 8726 IPs

    Get these Interfaces off public Internet access NOW!

    PAN-OS Management Interface tracker: https://dashboard.shadowserver.org/statistics/iot-devices/time-series/?date_range=7&vendor=palo+alto+networks&model=pan-os+management+interface&dataset=count&limit=1000&group_by=geo&style=stacked

    In conversation Friday, 15-Nov-2024 21:29:41 JST from infosec.exchange permalink

    Attachments


    1. https://media.infosec.exchange/infosec.exchange/media_attachments/files/113/486/852/283/850/949/original/a3a43a4d298e3a4f.png
    2. Domain not in remote thumbnail source whitelist: security.paloaltonetworks.com
      PAN-SA-2024-0015 Critical Security Bulletin: Ensure Access to Management Interface is Secured
      from PAN PSIRT
      Palo Alto Networks has observed threat activity exploiting an unauthenticated remote command execution vulnerability against a limited number of firewall management interfaces which are exposed to th...
    3. No result found on File_thumbnail lookup.
      Time series · IoT device statistics · The Shadowserver Foundation
  12. Embed this notice
    The Shadowserver Foundation (shadowserver@infosec.exchange)'s status on Friday, 15-Nov-2024 21:29:41 JST The Shadowserver Foundation The Shadowserver Foundation

    Palo Alto Networks published an advisory on 2024-11-08 warning of a claim of an RCE via the PAN-OS management interface. While no exploitation activity has yet been observed, we added fingerprinting for exposed PAN-OS mgmt interfaces in our Device ID report to warn recipients of potential attack surface exposure.

    We see around 11K IPs exposed (2024-11-10 scan).

    You can view exposure on our Dashboard selecting "IoT device statistics" in the top nav bar and setting vendor to "Palo Alto Networks" and model to "PAN-OS Management Interface"

    World map view: https://dashboard.shadowserver.org/statistics/iot-devices/map/?day=2024-11-10&vendor=palo+alto+networks&model=pan-os+management+interface&geo=all&data_set=count&scale=log

    PAN-OS mgmt exposure tracker:
    https://dashboard.shadowserver.org/statistics/iot-devices/time-series/?date_range=7&vendor=palo+alto+networks&model=pan-os+management+interface&dataset=count&limit=1000&group_by=geo&style=stacked

    IP data is now shared daily in our Device ID report https://shadowserver.org/what-we-do/network-reporting/device-identification-report/

    Palo Alto Networks security alert advisory https://security.paloaltonetworks.com/PAN-SA-2024-0015

    Guidance on "How to Secure the Management Access of Your Palo Alto Networks Device" by Palo Alto Networks: https://live.paloaltonetworks.com/t5/community-blogs/tips-amp-tricks-how-to-secure-the-management-access-of-your-palo/ba-p/464431

    PAN-OS Management Exposure by US state:
    https://dashboard.shadowserver.org/statistics/iot-devices/map/?day=2024-11-10&vendor=palo+alto+networks&model=pan-os+management+interface&geo=all&data_set=count&scale=log

    In conversation Friday, 15-Nov-2024 21:29:41 JST from infosec.exchange permalink

    Attachments


    1. https://media.infosec.exchange/infosec.exchange/media_attachments/files/113/465/054/840/811/396/original/18e46137863c1075.png

    2. https://media.infosec.exchange/infosec.exchange/media_attachments/files/113/465/054/838/904/285/original/24505d8672a587a1.png
    3. No result found on File_thumbnail lookup.
      World map · IoT device statistics · The Shadowserver Foundation
    4. No result found on File_thumbnail lookup.
      Time series · IoT device statistics · The Shadowserver Foundation



    5. No result found on File_thumbnail lookup.
      World map · IoT device statistics · The Shadowserver Foundation
  13. Embed this notice
    The Shadowserver Foundation (shadowserver@infosec.exchange)'s status on Tuesday, 03-Sep-2024 17:46:53 JST The Shadowserver Foundation The Shadowserver Foundation

    We started seeing some Progress WhatsUp Gold CVE-2024-6670 (CVSS 9.8) SQLi exploit attempts against our honeypot sensors that match recently published PoC (/NmConsole/Platform/PerformanceMonitorErrors/HasErrors endpoint)

    Progress advisory & patch info: https://community.progress.com/s/article/WhatsUp-Gold-Security-Bulletin-August-2024

    In conversation Tuesday, 03-Sep-2024 17:46:53 JST from infosec.exchange permalink

    Attachments

    1. No result found on File_thumbnail lookup.
      Progress Customer Community
  14. Embed this notice
    The Shadowserver Foundation (shadowserver@infosec.exchange)'s status on Wednesday, 24-Jan-2024 20:28:11 JST The Shadowserver Foundation The Shadowserver Foundation

    Running GitLab? We are sharing instances vulnerable to CVE-2023-7028 (Account Takeover via Password Reset without user interactions) - 5379 instances found worldwide (on 2024-01-23). Top: US (964) & Germany (730)

    Check for signs of compromise and patch: https://about.gitlab.com/releases/2024/01/11/critical-security-release-gitlab-16-7-2-released/

    IP Data shared in our Vulnerable HTTP Report (filtered by your network/constituency): https://shadowserver.org/what-we-do/network-reporting/vulnerable-http-report/

    Dashboard World Map: https://dashboard.shadowserver.org/statistics/combined/map/?map_type=std&day=2024-01-23&source=http_vulnerable&source=http_vulnerable6&tag=cve-2023-7028%2B&geo=all&data_set=count&scale=log

    In conversation Wednesday, 24-Jan-2024 20:28:11 JST from infosec.exchange permalink

    Attachments


    1. https://media.infosec.exchange/infosec.exchange/media_attachments/files/111/810/656/956/349/784/original/ffd9b1c0497b3934.png


    2. No result found on File_thumbnail lookup.
      World map · General statistics · The Shadowserver Foundation
  15. Embed this notice
    The Shadowserver Foundation (shadowserver@infosec.exchange)'s status on Saturday, 20-Jan-2024 21:29:02 JST The Shadowserver Foundation The Shadowserver Foundation
    in reply to

    Additional IPs compromised with credential stealers injected into vulnerable Ivanti Connect Secure VPN devices now shared daily in our Compromised Website report https://shadowserver.org/what-we-do/network-reporting/compromised-website-report/

    168 compromised IPs found in our scans on 2023-01-19: https://dashboard.shadowserver.org/statistics/combined/tree/?day=2024-01-19&source=compromised_website&source=compromised_website6&tag=credential-stealer%3Binjected-code%3Bivanti-connect-secure%3Bssl&geo=all&data_set=count&scale=log

    Total for 2023-01-19: 550 IPs still compromised (includes GIFTEDVISITOR variant webshells) - https://dashboard.shadowserver.org/statistics/combined/time-series/?date_range=7&source=compromised_website&source=compromised_website6&tag=ivanti-connect-secure%2B&group_by=geo&style=stacked

    Recovery guidance from Ivanti - https://forums.ivanti.com/s/article/Recovery-Steps-Related-to-CVE-2023-46805-and-CVE-2024-21887?language=en_US

    In conversation Saturday, 20-Jan-2024 21:29:02 JST from infosec.exchange permalink

    Attachments


    1. https://media.infosec.exchange/infosec.exchange/media_attachments/files/111/788/251/414/764/496/original/ff0025bea2fc8e8e.png

    2. No result found on File_thumbnail lookup.
      Tree map · General statistics · The Shadowserver Foundation
    3. No result found on File_thumbnail lookup.
      Time series · General statistics · The Shadowserver Foundation
    4. No result found on File_thumbnail lookup.
      Ivanti Community
  16. Embed this notice
    The Shadowserver Foundation (shadowserver@infosec.exchange)'s status on Friday, 19-Jan-2024 20:03:30 JST The Shadowserver Foundation The Shadowserver Foundation

    Scanning for vulnerable Ivanti Connect Secure (CVE-2023-46805 & CVE-2024-21887) instances has been added to our daily scan list. 6809 found vulnerable for 2024-01-15 scans using methodology from
    @watchtowrcyber
    - https://labs.watchtowr.com/welcome-to-2024-the-sslvpn-chaos-continues-ivanti-cve-2023-46805-cve-2024-21887/

    More details: https://shadowserver.org/what-we-do/network-reporting/vulnerable-http-report/

    These are instances that we believe have NOT applied the mitigation provided by Ivanti: https://forums.ivanti.com/s/article/KB-CVE-2023-46805-Authentication-Bypass-CVE-2024-21887-Command-Injection-for-Ivanti-Connect-Secure-and-Ivanti-Policy-Secure-Gateways?language=en_US

    IP data will start being reported out tomorrow (2024-01-16) along with Dashboard stats updates.

    Subscribe for free vulnerability data (and more) for your network: https://shadowserver.org/what-we-do/network-reporting/get-reports/

    In conversation Friday, 19-Jan-2024 20:03:30 JST from infosec.exchange permalink

    Attachments

    1. No result found on File_thumbnail lookup.
      Ivanti Community

    2. https://media.infosec.exchange/infosec.exchange/media_attachments/files/111/760/913/269/703/369/original/60aec7a93429078d.png

    3. https://media.infosec.exchange/infosec.exchange/media_attachments/files/111/760/913/613/954/532/original/24ded0a82e0f3d4b.png


    4. No result found on File_thumbnail lookup.
      Subscribe to Reports | The Shadowserver Foundation
      Request detailed daily reports about the state of your networks. We’ll evaluate your request and follow up with you. There is no charge for this service.
  17. Embed this notice
    The Shadowserver Foundation (shadowserver@infosec.exchange)'s status on Friday, 19-Jan-2024 20:03:29 JST The Shadowserver Foundation The Shadowserver Foundation
    in reply to

    Data on vulnerable Ivanti Connect Secure devices now available on our Dashboard, for example

    World map: https://dashboard.shadowserver.org/statistics/combined/map/?map_type=std&day=2024-01-15&source=http_vulnerable&source=http_vulnerable6&tag=cve-2023-46805%2B&geo=all&data_set=count&scale=log

    Tree map:
    https://dashboard.shadowserver.org/statistics/combined/tree/?day=2024-01-15&source=http_vulnerable&source=http_vulnerable6&tag=cve-2023-46805%2B&geo=all&data_set=count&scale=log

    Tracker:
    https://dashboard.shadowserver.org/statistics/combined/time-series/?date_range=7&source=http_vulnerable&source=http_vulnerable6&tag=cve-2023-46805%2B&group_by=geo&style=stacked

    In conversation Friday, 19-Jan-2024 20:03:29 JST from infosec.exchange permalink

    Attachments

    1. No result found on File_thumbnail lookup.
      World map · General statistics · The Shadowserver Foundation
    2. No result found on File_thumbnail lookup.
      Tree map · General statistics · The Shadowserver Foundation
    3. No result found on File_thumbnail lookup.
      Time series · General statistics · The Shadowserver Foundation
  18. Embed this notice
    The Shadowserver Foundation (shadowserver@infosec.exchange)'s status on Friday, 19-Jan-2024 20:03:27 JST The Shadowserver Foundation The Shadowserver Foundation
    in reply to
    • Volexity :verified:

    In collaboration with @volexity we have added daily scans & reports of compromised Ivanti Connect Secure VPN instances. Data shared in our Compromised Website report, tagged "ivanti-connect-secure".

    609 IPs found on 2023-01-16: https://shadowserver.org/what-we-do/network-reporting/compromised-website-report/

    https://dashboard.shadowserver.org/statistics/combined/tree/?day=2024-01-16&source=compromised_website&tag=ivanti-connect-secure%2B&geo=all&data_set=count&scale=log

    Background: https://www.volexity.com/blog/2024/01/15/ivanti-connect-secure-vpn-exploitation-goes-global/

    In conversation Friday, 19-Jan-2024 20:03:27 JST from infosec.exchange permalink

    Attachments


    1. https://media.infosec.exchange/infosec.exchange/media_attachments/files/111/770/495/009/654/673/original/37ae18a8aede998d.png

    2. Domain not in remote thumbnail source whitelist: www.volexity.com
      Ivanti Connect Secure VPN Exploitation Goes Global
      from Volexity
      On January 10, 2024, Volexity publicly shared details of targeted attacks by UTA0178 exploiting two zero-day vulnerabilities (CVE-2024-21887 and CVE-2023-46805) in Ivanti Connect Secure (ICS) VPN appliances. On the same day, Ivanti published a mitigation that could be applied to ICS VPN appliances to prevent exploitation of these vulnerabilities. Since publication of these details, Volexity has continued to monitor its existing customers for exploitation. Volexity has also been contacted by multiple organizations that saw signs of compromise by way of mismatched file detections. Volexity has been actively working multiple new cases of organizations with compromised ICS VPN appliances.
  19. Embed this notice
    The Shadowserver Foundation (shadowserver@infosec.exchange)'s status on Friday, 19-Jan-2024 20:03:26 JST The Shadowserver Foundation The Shadowserver Foundation
    in reply to

    Lots of exploitation of Ivanti Connect Secure VPN CVE-2023-46805 & CVE-2024-21887 seen by our sensors. Assume compromise on exposed endpoints if you have not applied the mitigation. You can track Ivanti CVE exploitation attempts on our Dashboard:

    https://dashboard.shadowserver.org/statistics/honeypot/time-series/?date_range=7&host_type=src&vendor=ivanti&group_by=vulnerability&style=stacked

    Note you can track latest trends in CVE exploitation on our Dashboard at https://dashboard.shadowserver.org/statistics/honeypot/monitoring/vulnerability/?category=anomaly&statistic=unique_ips&limit=100

    In conversation Friday, 19-Jan-2024 20:03:26 JST from infosec.exchange permalink

    Attachments


    1. https://media.infosec.exchange/infosec.exchange/media_attachments/files/111/781/816/945/490/830/original/d310d85dcaa147db.png

    2. https://media.infosec.exchange/infosec.exchange/media_attachments/files/111/781/817/548/315/158/original/070a380a4e3f9ca6.png
    3. No result found on File_thumbnail lookup.
      Time series · Attack statistics · The Shadowserver Foundation
    4. No result found on File_thumbnail lookup.
      Vulnerabilities · Attack statistics · The Shadowserver Foundation

User actions

    The Shadowserver Foundation

    The Shadowserver Foundation

    Our mission is to make the Internet more secure by bringing to light vulnerabilities, malicious activity and emerging threats. Join our Alliance!

    Tags
    • (None)

    Following 0

      Followers 0

        Groups 0

          Statistics

          User ID
          233023
          Member since
          17 Jan 2024
          Notices
          19
          Daily average
          0

          Feeds

          • Atom
          • Help
          • About
          • FAQ
          • TOS
          • Privacy
          • Source
          • Version
          • Contact

          GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.

          Creative Commons Attribution 3.0 All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.