CYBER Threat Intelligence Reports
LATEST CTIs
Active Exploitation of Stored XSS Vulnerabilities in WordPress Plugins (CVE-2024-2194, CVE-2023-6961, CVE-2023-40000)
Recent cyberattacks are exploiting stored XSS vulnerabilities in WordPress plugins WP Statistics, WP Meta SEO, and LiteSpeed Cache (CVE-2024-2194, CVE-2023-6961, CVE-2023-40000). These flaws allow attackers…
Read more >

Over 13,800 Checkpoint Gateways Vulnerable to CVE-2024-24919 Zero-Day Exploit
Recent analysis identifies over 13,800 Check Point gateways exposed to CVE-2024-24919, an arbitrary file read vulnerability. This flaw allows attackers to access any file on…
Read more >

CVE-2024-2771: Unauthenticated Attackers Can Hijack 400K+ WordPress Sites via Fluent Forms Bug
A critical vulnerability (CVE-2024-2771) in the Fluent Forms WordPress plugin, affecting over 400,000 sites, allows unauthenticated attackers to gain administrative access, leading to potential website…
Read more >

CVE-2024-3368: Vulnerability in All in One SEO Plugin Threatens Millions of WordPress Sites
A critical authenticated stored XSS vulnerability (CVE-2024-3368) has been discovered in the All in One SEO (AIOSEO) WordPress plugin, affecting versions up to 4.6.0. This…
Read more >

CVE-2024-4041: XSS Vulnerability in Yoast SEO Plugin
A critical security vulnerability, designated CVE-2024-4041, has been discovered in the Yoast SEO plugin used on over 5 million WordPress sites. This reflected Cross-Site Scripting…
Read more >

“Mal.Metrica” Malware Rampantly Exploiting WordPress to Compromise Over 17,000 Sites
The Mal.Metrica malware is actively exploiting WordPress vulnerabilities, impacting more than 17,000 sites. This malware deceives users with fake CAPTCHA prompts leading to scam-ridden sites,…
Read more >

