CYBER Threat Intelligence Reports
LATEST CTIs
Malicious npm Package “legacyreact-aws-s3-typescript” Backdoors AWS Users
A malicious npm package, "legacyreact-aws-s3-typescript," mimicking a legitimate Amazon S3 tool, was found to contain a backdoor allowing remote attackers to execute commands and gain…
Read more >

A Remote Unauthenticated Code Execution Vulnerability in OpenSSH’s server (CVE-2024-6387)
A critical Remote Unauthenticated Code Execution (RCE) vulnerability (CVE-2024-6387) in OpenSSH's server (sshd) on glibc-based Linux systems allows remote attackers to execute arbitrary code as…
Read more >

Multiple Vulnerabilities in Apache HTTP Server Demand Immediate Action (CVE-2024-36387 to CVE-2024-39573)
The Apache Software Foundation has issued an urgent advisory for multiple vulnerabilities (CVE-2024-36387 to CVE-2024-39573) in Apache HTTP Server, risking DoS attacks, remote code execution,…
Read more >

GitLab Releases Patch for CI/CD Pipeline Vulnerability (CVE-2024-5655)
GitLab has released critical security updates addressing 14 vulnerabilities, including a severe flaw (CVE-2024-5655) with a CVSS score of 9.6 that allows attackers to run…
Read more >

CVE-2024-5756: Icegram Express Flaw Puts 90,000 WordPress Sites at Risk
A critical vulnerability, CVE-2024-5756, in the Icegram Express plugin for WordPress exposes over 90,000 sites to potential data breaches. This flaw, with a CVSS score…
Read more >

CVE-2024-28397: js2py Vulnerability Exposes Millions of Python Users to Remote Code Execution (RCE)
A critical vulnerability, CVE-2024-28397, in the js2py library exposes millions of Python users to remote code execution (RCE) attacks. With a CVSS score of 8.8,…
Read more >
