CYBER Threat Intelligence Reports
LATEST CTIs
Code Injection Vulnerability in MongoDB Compass (CVE-2024-6376)
A critical security vulnerability, CVE-2024-6376, has been discovered in MongoDB Compass, exposing systems to code injection risks. Due to insufficient sandbox protection in the ejson…
Read more >

Malicious npm Package “legacyreact-aws-s3-typescript” Backdoors AWS Users
A malicious npm package, "legacyreact-aws-s3-typescript," mimicking a legitimate Amazon S3 tool, was found to contain a backdoor allowing remote attackers to execute commands and gain…
Read more >

A Remote Unauthenticated Code Execution Vulnerability in OpenSSH’s server (CVE-2024-6387)
A critical Remote Unauthenticated Code Execution (RCE) vulnerability (CVE-2024-6387) in OpenSSH's server (sshd) on glibc-based Linux systems allows remote attackers to execute arbitrary code as…
Read more >

Multiple Vulnerabilities in Apache HTTP Server Demand Immediate Action (CVE-2024-36387 to CVE-2024-39573)
The Apache Software Foundation has issued an urgent advisory for multiple vulnerabilities (CVE-2024-36387 to CVE-2024-39573) in Apache HTTP Server, risking DoS attacks, remote code execution,…
Read more >

GitLab Releases Patch for CI/CD Pipeline Vulnerability (CVE-2024-5655)
GitLab has released critical security updates addressing 14 vulnerabilities, including a severe flaw (CVE-2024-5655) with a CVSS score of 9.6 that allows attackers to run…
Read more >

CVE-2024-5756: Icegram Express Flaw Puts 90,000 WordPress Sites at Risk
A critical vulnerability, CVE-2024-5756, in the Icegram Express plugin for WordPress exposes over 90,000 sites to potential data breaches. This flaw, with a CVSS score…
Read more >
