CVE-2021-1732
published 2021-02-25CVE-2021-1732: Windows Win32k Elevation of Privilege Vulnerability
PriorityP189high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
KEVITWEXPLOITRansomware
CISA Known Exploited Vulnerabilitydue 2021-11-17
Exploited in the wild
EPSS
78.38%
99.5th percentile
Windows Win32k Elevation of Privilege Vulnerability
Affected
26 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | windows_10_version_1803 | >= 10.0.0 < publication | publication |
| microsoft | windows_10_version_1809 | >= 10.0.0 < publication | publication |
| microsoft | windows_10_version_1909 | >= 10.0.0 < publication | publication |
| microsoft | windows_10_version_2004 | >= 10.0.0 < publication | publication |
| microsoft | windows_10_version_20h2 | >= 10.0.0 < publication | publication |
| microsoft | windows_server_2019 | >= 10.0.0 < publication | publication |
| microsoft | windows_server_version_2004 | >= 10.0.0 < publication | publication |
| microsoft | windows_server_version_20h2 | >= 10.0.0 < publication | publication |
| msrc | windows_10_version_1803_for_32-bit_systems | — | — |
| msrc | windows_10_version_1803_for_arm64-based_systems | — | — |
| msrc | windows_10_version_1803_for_x64-based_systems | — | — |
| msrc | windows_10_version_1809_for_32-bit_systems | — | — |
| msrc | windows_10_version_1809_for_arm64-based_systems | — | — |
| msrc | windows_10_version_1809_for_x64-based_systems | — | — |
| msrc | windows_10_version_1909_for_32-bit_systems | — | — |
| msrc | windows_10_version_1909_for_arm64-based_systems | — | — |
| msrc | windows_10_version_1909_for_x64-based_systems | — | — |
| msrc | windows_10_version_2004_for_32-bit_systems | — | — |
| msrc | windows_10_version_2004_for_arm64-based_systems | — | — |
| msrc | windows_10_version_2004_for_x64-based_systems | — | — |
| msrc | windows_10_version_20h2_for_32-bit_systems | — | — |
| msrc | windows_10_version_20h2_for_arm64-based_systems | — | — |
| msrc | windows_server_2019 | — | — |
| msrc | windows_server_version_1909 | — | — |
| msrc | windows_server_version_2004 | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →CVE-2021-1732 exploitation targets win32kbase.sys via DirectComposition commands. Monitor for NtDCompositionCommitChannel and NtDCompositionProcessChannelBatchBuffer syscalls with anomalous SetResourceBufferProperty commands using DCOMPOSITION_EXPRESSION_TYPE=D2DVector2 and out-of-bounds propertyId values. ↗
- →Exploit uses three DirectComposition command types in sequence: CreateResource, ReleaseResource, and SetResourceBufferProperty. Detecting unusual patterns of these three commands in rapid succession from a non-DWM process may indicate exploitation. ↗
- →PurpleFox checks for specific hotfix KBs before selecting CVE-2021-1732 exploit. Absence of KB4601354, KB4601345, KB4601315, or KB4601319 on a Windows system indicates it is a viable target for this exploit chain. ↗
- →PurpleFox installs a malicious sens.dll replacement via PendingFileRenameOperations. Monitor for PendingFileRenameOperations registry value pointing to non-standard paths replacing C:\Windows\system32\sens.dll. ↗
- →FoxSocket backdoor uses WebSocket-based C2 with ECDH key exchange. The first key exchange message is AES-encrypted with a fixed length of 176 bytes; the second exchange has a fixed length of 304 bytes. These fixed-length encrypted WebSocket frames can be used as a network signature. ↗
- →BlueSky ransomware exploiting CVE-2021-1732 drops payload as javaw.exe in the Startup folder. Alert on javaw.exe executing from %APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup\. ↗
- →BITTER APT uses CVE-2021-1732 for privilege escalation as part of spearphishing campaigns delivering malicious RTF or Excel attachments. Correlate Win32k EoP with Office document execution chains.
- ·The exploit requires heap grooming in dwm.exe to bypass two property checks (storageOffset and type) before the OOB write is triggered. Detection based solely on syscall monitoring may miss the exploitation if heap state is not also considered. ↗
- ·Microsoft may need to validate property counts for all DCOMPOSITION_EXPRESSION_TYPEs beyond D2DVector2 to fully close the vulnerability class; patching only D2DVector2 may leave other expression types exploitable. ↗
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.04.6MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
vulncheck7.8HIGH
cisa7.8HIGH
vendor_msrc7.8HIGH
vendor_redhat5.5MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
kernel: ipv6: Fix KASAN: slab-out-of-bounds Read in fib6_nh_flush_exceptions
vendor_redhat·2024-03-15·CVSS 5.5
CVE-2021-47126 [MEDIUM] CWE-125 kernel: ipv6: Fix KASAN: slab-out-of-bounds Read in fib6_nh_flush_exceptions
kernel: ipv6: Fix KASAN: slab-out-of-bounds Read in fib6_nh_flush_exceptions
In the Linux kernel, the following vulnerability has been resolved:
ipv6: Fix KASAN: slab-out-of-bounds Read in fib6_nh_flush_exceptions
Reported by syzbot:
HEAD commit: 90c911ad Merge tag 'fixes' of git://git.kernel.org/pub/scm..
git tree: git://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git master
dashboard link: https://syzkaller.appspot.com/bug?extid=123aa35098fd3c000eb7
compiler: Debian clang version 11.0.1-2
BUG: KASAN: slab-out-of-bounds in fib6_nh_get_excptn_bucket net/ipv6/route.c:1604 [inline]
BUG: KASAN: slab-out-of-bounds in fib6_nh_flush_exceptions+0xbd/0x360 net/ipv6/route.c:1732
Read of size 8 at addr ffff8880145c78f8 by task syz-executor.4/17760
CPU: 0 PID: 17760 Comm: syz-executor.4 N
CISA
Microsoft Win32k Privilege Escalation Vulnerability
cisa·2021-11-03·CVSS 7.8
CVE-2021-1732 [HIGH] CWE-787 Microsoft Win32k Privilege Escalation Vulnerability
Vulnerability: Microsoft Win32k Privilege Escalation Vulnerability
Affected: Microsoft Win32k
Microsoft Win32k contains an unspecified vulnerability that allows for privilege escalation.
Required Action: Apply updates per vendor instructions.
Notes: https://nvd.nist.gov/vuln/detail/CVE-2021-1732
Remediation Due Date: 2021-11-17
Microsoft
Windows Win32k Elevation of Privilege Vulnerability
vendor_msrc·2021-02-09·CVSS 7.8
CVE-2021-1732 [HIGH] Windows Win32k Elevation of Privilege Vulnerability
Windows Win32k Elevation of Privilege Vulnerability
Windows Kernel: Windows Kernel
Microsoft: Microsoft
Impact: Elevation of Privilege
Exploit Status: Publicly Disclosed:No;Exploited:Yes;Latest Software Release:Exploitation Detected;Older Software Release:Exploitation Detected;DOS:N/A
Reference: https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB4601354
Reference: https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB4601345
Reference: https://support.microsoft.com/help/4601345
Reference: https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB4601315
Reference: https://support.microsoft.com/help/4601315
Reference: https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB4601319
Reference: https://support.microsoft.com/help/4601319
Project0
2022 0-day In-the-Wild Exploitation…so far - Project Zero
project_zero·2022-06-01·CVSS 8.8
CVE-2016-5128 [HIGH] 2022 0-day In-the-Wild Exploitation…so far - Project Zero
Posted by Maddie Stone, Google Project Zero
This blog post is an overview of a talk, “ 0-day In-the-Wild Exploitation in 2022…so far”, that I gave at the FIRST conference in June 2022. The slides are available here.
For the last three years, we’ve published annual year-in-review reports of 0-days found exploited in the wild. The most recent of these reports is the 2021 Year in Review report, which we published just a few months ago in April. While we plan to stick with that annual cadence, we’re publishing a little bonus report today looking at the in-the-wild 0-days detected and disclosed in the first half of 2022.
As of June 15, 2022, there have been 18 0-days detected and disclosed as exploited in-the-wild in 2022. When we analyzed those 0-days, we found that at least nin
GHSA
GHSA-gvwr-5hrc-2gr5: Windows Win32k Elevation of Privilege Vulnerability This CVE ID is unique from CVE-2021-1698
ghsa_unreviewed·2022-05-24·CVSS 7.8
CVE-2021-1732 [HIGH] CWE-269 GHSA-gvwr-5hrc-2gr5: Windows Win32k Elevation of Privilege Vulnerability This CVE ID is unique from CVE-2021-1698
Windows Win32k Elevation of Privilege Vulnerability This CVE ID is unique from CVE-2021-1698.
GHSA
GHSA-6948-8mgw-p3fh: Windows Win32k Elevation of Privilege Vulnerability This CVE ID is unique from CVE-2021-1732
ghsa_unreviewed·2022-05-24·CVSS 7.8
CVE-2021-1698 [HIGH] CWE-269 GHSA-6948-8mgw-p3fh: Windows Win32k Elevation of Privilege Vulnerability This CVE ID is unique from CVE-2021-1732
Windows Win32k Elevation of Privilege Vulnerability This CVE ID is unique from CVE-2021-1732.
Project0
The More You Know, The More You Know You Don’t Know - Project Zero
project_zero·2022-04-01
CVE-2016-4654 The More You Know, The More You Know You Don’t Know - Project Zero
A Year in Review of 0-days Used In-the-Wild in 2021
Posted by Maddie Stone, Google Project Zero
This is our third annual year in review of 0-days exploited in-the-wild [2020, 2019]. Each year we’ve looked back at all of the detected and disclosed in-the-wild 0-days as a group and synthesized what we think the trends and takeaways are. The goal of this report is not to detail each individual exploit, but instead to analyze the exploits from the year as a group, looking for trends, gaps, lessons learned, successes, etc. If you’re interested in the analysis of individual exploits, please check out our root cause analysis repository.
We perform and share this analysis in order to make 0-day hard. We want it to be more costly, more resource intensive, and overall more difficult for
VulnCheck
Microsoft Win32k Privilege Escalation Vulnerability
vulncheck·2021·CVSS 7.8
CVE-2021-1732 [HIGH] CWE-787 Microsoft Win32k Privilege Escalation Vulnerability
Microsoft Win32k Privilege Escalation Vulnerability
Microsoft Win32k contains an unspecified vulnerability that allows for privilege escalation.
Affected: Microsoft Win32k
Required Action: Apply updates per vendor instructions.
Known Ransomware Campaign Use: Known
Exploitation References: https://docs.google.com/spreadsheets/d/1lkNJ0uQwbeC1ZTRrxdtuPLCIl7mlUreoKfSIgajnSyY/edit; https://api.msrc.microsoft.com/cvrf/v3.0/cvrf/2021-Feb; https://ti.dbappsecurity.com.cn/blog/index.php/2021/02/10/windows-kernel-zero-day-exploit-is-used-by-bitter-apt-in-targeted-attack/; https://securelist.com/zero-day-vulnerability-in-desktop-window-manager-cve-2021-28310-used-in-the-wild/101898/; https://threatresearch.ext.hp.com/purple-fox-exploit-kit-now-exploits-cve-2021-26411/; https://www.trendmicro.com
Project0
Project Zero RCA: CVE-2021-1732
project_zero·CVSS 7.8
CVE-2021-1732 [HIGH] Project Zero RCA: CVE-2021-1732
# CVE-2021-1732: Windows win32k flag setting out of sync in xxCreateWindowEx
Quan Jin, DBappSecurity
## The Basics
**Disclosure or Patch Date:** 10 February 2021
**Product:** Microsoft Windows
**Advisory:** https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-1732
**Affected Versions:** For Windows 10 20H2 x64, [KB4598242](https://support.microsoft.com/en-us/topic/january-12-2021-kb4598242-os-builds-19041-746-and-19042-746-ab18a1a1-d572-598f-4d86-7137aad34056) and previous
**First Patched Version:** For Windows 10 20H2 x64, [KB4601319](https://support.microsoft.com/en-us/topic/february-9-2021-kb4601319-os-builds-19041-804-and-19042-804-87fc8417-4a81-0ebb-5baa-40cfab2fbfde)
**Issue/Bug Report:** N/A
**Patch CL:** N/A
**Bug-Introducing CL:** N/A
**Reporter(s):** JinQuan,
Project0
Project Zero RCA: CVE-2022-21882: Win32k Window Object Type Confusion
project_zero·CVSS 7.0
CVE-2022-21882 [HIGH] Project Zero RCA: CVE-2022-21882: Win32k Window Object Type Confusion
# CVE-2022-21882: Win32k Window Object Type Confusion
*RyeLv (@b2ahex)*
## The Basics
**Disclosure or Patch Date:** Jan 13, 2022
**Product:** Microsoft Windows
**Advisory:** https://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-21882
**Affected Versions:** Before the January 2022 patch update. Windows 10,Windows 11,Windows Server 2019,Windows server 2022 (Currently only full exploits found under windows10 and windows server 2019)
**First Patched Version:** CVE-2022-21882,January 2022 patch update.
**Issue/Bug Report:** N/A
**Patch CL:** N/A
**Bug-Introducing CL:** N/A
**Reporter(s):** RyeLv (@b2ahex)
## The Code
**Proof-of-concept:** N/A
**Exploit sample:** N/A
**Did you have access to the exploit sample when doing the analysis?** Yes
## The Vulnerability
**Bug cla
No detection rules found.
Tenable
Inside the customer environment: Where threat actors, vulnerabilities, and exposed assets intersect
blogs_tenable·2026-05-27
CVE-2023-4966 Inside the customer environment: Where threat actors, vulnerabilities, and exposed assets intersect
## Exposure Management
## Explore By Use Case
## Explore By Industry
## Tenable is the one clear leader in Exposure Management
## Exposure management
resource center
## Accelerate your exposure management strategy with practical resources and tools.
## Explore By Use Case
## Explore By Industry
## Tenable is the one clear leader in Exposure Management
## Exposure management
resource center
## Accelerate your exposure management strategy with practical resources and tools.
## Inside the customer environment: Where threat actors, vulnerabilities, and exposed assets intersect
Tenable Research has developed a graph-based model linking 600+ threat groups to real-world customer exposures. It reveals which vulnerabilities sit at the intersection of severity, active exploit
Tenable
Microsoft’s June 2024 Patch Tuesday Addresses 49 CVEs
blogs_tenable·2024-06-11
Microsoft’s June 2024 Patch Tuesday Addresses 49 CVEs
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Checkpoint
Raspberry Robin Keeps Riding the Wave of Endless 1-Days
blogs_checkpoint·2024-02-07
CVE-2023-36802 Raspberry Robin Keeps Riding the Wave of Endless 1-Days
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
AI Research 2
Android Malware 23
Artificial Intelligence 4
ChatGPT 3
Check Point Research Publications 455
Cloud Security 1
CPRadio 44
Crypto 2
Data & Threat Intelligence 2
Data Analysis 0
Demos 22
Global Cyber Attack Reports 408
How To Guides 13
Ransomware 5
Russo-Ukrainian War 1
Security Report 1
Threat and data analysis 0
Threat Research 174
Web 3.0 Security 11
Wipers 0
## Raspberry Robin Keeps Riding the Wave of Endless 1-Days
## Key Findings
Two new 1-day LPE exploits were used by the Raspberry Robin worm before they were publicly disclosed, which means
Unit42
Inside Win32k Exploitation: Analysis of CVE-2022-21882 and CVE-2021-1732
blogs_unit42·2023-06-20·CVSS 7.8
CVE-2022-21882 [HIGH] Inside Win32k Exploitation: Analysis of CVE-2022-21882 and CVE-2021-1732
Threat Research Center
Threat Research
Vulnerabilities
## Inside Win32k Exploitation: Analysis of CVE-2022-21882 and CVE-2021-1732
Shawn Westfall
Published: June 20, 2023
Threat Research
Vulnerabilities
CVE-2021-1732
CVE-2022-21882
Microsoft Windows
## Executive Summary
After seeing reports of two similar privilege escalation vulnerabilities in Microsoft Windows – CVE-2021-1732 and CVE-2022-21882 – we decided to analyze both to better understand the code involved in each. This is a continuation of Inside Win32k Exploitation , in which we discussed the Win32k internals and exploitation in general as background information to explore the issues surrounding CVE-2021-1732 and CVE-2022-21882 .
Here, we will dig deeper into CVE-2021-1732 and CVE-2022-21882 and their related proo
Unit42
Inside Win32k Exploitation: Analysis of CVE-2022-21882 and CVE-2021-1732
blogs_unit42·2023-06-20·CVSS 7.8
CVE-2021-1732 [HIGH] Inside Win32k Exploitation: Analysis of CVE-2022-21882 and CVE-2021-1732
## Executive Summary
After seeing reports of two similar privilege escalation vulnerabilities in Microsoft Windows – CVE-2021-1732 and CVE-2022-21882 – we decided to analyze both to better understand the code involved in each. This is a continuation of Inside Win32k Exploitation, in which we discussed the Win32k internals and exploitation in general as background information to explore the issues surrounding CVE-2021-1732 and CVE-2022-21882.
Here, we will dig deeper into CVE-2021-1732 and CVE-2022-21882 and their related proof-of-concept (PoC) exploits. We’ll walk through an analysis of these two exploits, and thus see why the patch for CVE-2021-1732 was not sufficient to prevent CVE-2022-21882.
Both vulnerabilities discussed in this series are detected and blocked by the Cortex XDR Ant
Unit42
Inside Win32k Exploitation: Background on Implementations of Win32k and Exploitation Methodologies
blogs_unit42·2023-06-13·CVSS 7.8
CVE-2022-21882 [HIGH] Inside Win32k Exploitation: Background on Implementations of Win32k and Exploitation Methodologies
## Executive Summary
In late January 2022, several reports on social media indicated that a new Microsoft Windows privilege escalation vulnerability (CVE-2022-21882) was being exploited in the wild. These reports prompted us to do an analysis of CVE-2022-21882, which turned out to be a vulnerability in the Win32k.sys user-mode callback function xxxClientAllocWindowClassExtraBytes.
In 2021, a very similar vulnerability (CVE-2021-1732) was reported to – and patched by – Microsoft. We decided to take a closer look at both vulnerabilities to better understand the code involved in each. In our initial analysis we wanted to determine why the patch for CVE-2021-1732 was not sufficient to prevent CVE-2022-21882.
This is part one of a series that will cover Win32k internals and exploitation in g
Unit42
Inside Win32k Exploitation: Background on Implementations of Win32k and Exploitation Methodologies
blogs_unit42·2023-06-13·CVSS 7.8
CVE-2021-1732 [HIGH] Inside Win32k Exploitation: Background on Implementations of Win32k and Exploitation Methodologies
Threat Research Center
Threat Research
Vulnerabilities
## Inside Win32k Exploitation: Background on Implementations of Win32k and Exploitation Methodologies
Shawn Westfall
Published: June 13, 2023
Threat Research
Vulnerabilities
CVE-2021-1732
CVE-2022-21882
Microsoft Windows
## Executive Summary
In late January 2022, several reports on social media indicated that a new Microsoft Windows privilege escalation vulnerability ( CVE-2022-21882 ) was being exploited in the wild. These reports prompted us to do an analysis of CVE-2022-21882, which turned out to be a vulnerability in the Win32k.sys user-mode callback function xxxClientAllocWindowClassExtraBytes .
In 2021, a very similar vulnerability ( CVE-2021-1732 ) was reported to – and patched by – Microsoft. We decided to take
Tenable
Microsoft’s May 2023 Patch Tuesday Addresses 38 CVEs (CVE-2023-29336)
blogs_tenable·2023-05-09·CVSS 7.8
[HIGH] Microsoft’s May 2023 Patch Tuesday Addresses 38 CVEs (CVE-2023-29336)
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Checkpoint
24th April – Threat Intelligence Report
blogs_checkpoint·2023-04-24
CVE-2023-20036 24th April – Threat Intelligence Report
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 24th April – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 24th April, please download our Threat_Intelligence Bulletin
TOP ATTACKS AND BREACHES
The American Bar Association (ABA), the largest global association of lawyers and legal professionals, has suffered a data breach with hackers gaining access to older credentials of 1,466,000 members. The breach was first detected on March 17th, 2023, and involved login credentials and salted passwords to ABA’s old website
Cap
Checkpoint
Raspberry Robin: Anti-Evasion How-To & Exploit Analysis
blogs_checkpoint·2023-04-18
CVE-2020-1054 Raspberry Robin: Anti-Evasion How-To & Exploit Analysis
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
AI Research 2
Android Malware 23
Artificial Intelligence 4
ChatGPT 3
Check Point Research Publications 455
Cloud Security 1
CPRadio 44
Crypto 2
Data & Threat Intelligence 2
Data Analysis 0
Demos 22
Global Cyber Attack Reports 408
How To Guides 13
Ransomware 5
Russo-Ukrainian War 1
Security Report 1
Threat and data analysis 0
Threat Research 174
Web 3.0 Security 11
Wipers 0
## Raspberry Robin: Anti-Evasion How-To & Exploit Analysis
Research by: Shavit Yosef
## Introduction
During the last year, Raspberry Robin has evolved to be one of the most distributed ma
Sentinelone
BlueSky
blogs_sentinelone·2022-11-30
BlueSky
How It Works The Singularity XDR Difference
Singularity Marketplace One-Click Integrations to Unlock the Power of XDR
Pricing & Packaging Comparisons and Guidance at a Glance
Purple AI Accelerate SecOps with Generative AI
Singularity Hyperautomation Easily Automate Security Processes
AI-SIEM The AI SIEM for the Autonomous SOC
Singularity Data Lake AI-Powered, Unified Data Lake
Singularity Data Lake for Log Analytics Seamlessly Ingest Data from On-Prem, Cloud or Hybrid Environments
Singularity Endpoint Autonomous Prevention, Detection, and Response
Singularity XDR Native & Open Protection, Detection, and Response
Singularity RemoteOps Forensics Orchestrate Forensics at Scale
Singularity
Threat Intelligence Comprehensive Adversary Intelligence
Singularity Vulnerability Management
Sentinelone
BlueSky Ransomware | AD Lateral Movement, Evasion and Fast Encryption Put Threat on the Radar
blogs_sentinelone·2022-08-25
BlueSky Ransomware | AD Lateral Movement, Evasion and Fast Encryption Put Threat on the Radar
BlueSky ransomware is an emerging threat that researchers have been paying increasing attention to since its initial discovery in late June 2022. The ransomware has been observed being spread via trojanized downloads from questionable websites as well as in phishing emails.
Although infections at this time remain low, the ransomware’s characteristics, described below, suggest it has been carefully developed for a sustained campaign. In this post, we cover the latest intelligence on BlueSky ransomware to help security teams defend against this developing threat.
## Emergence of BlueSky Ransomware
BlueSky was first noted on VirusTotal by researcher @Kangxiaopao in late June 2022. Subsequently, analysts from CloudSek and Unit42 have documented some of BlueSky’s behavior.
At present, BlueS
Unit42
BlueSky Ransomware: Fast Encryption via Multithreading
blogs_unit42·2022-08-10
BlueSky Ransomware: Fast Encryption via Multithreading
## Executive Summary
BlueSky ransomware is an emerging family that has adopted modern techniques to evade security defenses.
Ransomware is a malicious program designed to encrypt a user’s data and demand a ransom for the decryption. BlueSky ransomware predominantly targets Windows hosts and utilizes multithreading to encrypt files on the host for faster encryption.
In our analysis, we found code fingerprints from samples of BlueSky ransomware that can be connected to the Conti ransomware group. In particular, the multithreaded architecture of BlueSky bears code similarities with Conti v3, and the network search module is an exact replica of it.
However, in another respect, BlueSky more closely resembles Babuk Ransomware. Both use ChaCha20, an algorithm for file encryption, along with C
Unit42
BlueSky Ransomware: Fast Encryption via Multithreading
blogs_unit42·2022-08-10
BlueSky Ransomware: Fast Encryption via Multithreading
Threat Research Center
Threat Research
Ransomware
## BlueSky Ransomware: Fast Encryption via Multithreading
Muhammad Umer Khan
Lee Wei
Yang Ji
Wenjun Hu
Published: August 10, 2022
Ransomware
Threat Research
Babuk
BlueSky Ransomware
Conti ransomware
Grumpy Scorpius
Investigation and Response
PowerShell
Redline infostealer
Threat intelligence
Zealous Scorpius
## Executive Summary
BlueSky ransomware is an emerging family that has adopted modern techniques to evade security defenses.
Ransomware is a malicious program designed to encrypt a user’s data and demand a ransom for the decryption. BlueSky ransomware predominantly targets Windows hosts and utilizes multithreading to encrypt files on the host for faster encryption.
In our analysis, we found code fingerprints f
Tenable
ContiLeaks: Chats Reveal Over 30 Vulnerabilities Used by Conti Ransomware – How Tenable Can Help
blogs_tenable·2022-03-24
ContiLeaks: Chats Reveal Over 30 Vulnerabilities Used by Conti Ransomware – How Tenable Can Help
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Qualys
Managing CISA Known Exploited Vulnerabilities with Qualys VMDR | Qualys
blogs_qualys·2022-02-23
Managing CISA Known Exploited Vulnerabilities with Qualys VMDR | Qualys
#### Table of Contents
- Situation
- Directive Scope
- CISA Catalog of Known Exploited Vulnerabilities
- Detect CISA Vulnerabilities Using Qualys VMDR
- CISA Exploited RTI
- Detailed Operational Dashboard
- Remediation
- Federal Enterprises and Agencies Can Act Now
- Summary
- Getting Started
CISA released a directive in November 2021, recommending urgent and prioritized remediation of actively exploited vulnerabilities. Both government agencies and corporations should heed this advice. This blog outlines how Qualys Vulnerability Management, Detection & Response can be used by any organization to respond to this directive efficiently and effectively.
## Situation
Last November 2021, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) released a Binding Operational Directiv
Tenable
Microsoft’s February 2022 Patch Tuesday Addresses 48 CVEs (CVE-2022-21989)
blogs_tenable·2022-02-08·CVSS 7.8
[HIGH] Microsoft’s February 2022 Patch Tuesday Addresses 48 CVEs (CVE-2022-21989)
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Securelist
APT annual review 2021
blogs_securelist·2021-11-30
APT annual review 2021
Table of Contents
Private sector vendors play a significant role in the threat landscape
Supply-chain attacks
Exploiting vulnerabilities
Firmware vulnerabilities
Authors
GReAT
In the Global Research and Analysis Team at Kaspersky, we track the ongoing activities of more than 900 advanced threat actors and activity clusters; you can find our quarterly overviews here , here and here . For this annual review, we have tried to focus on what we consider to be the most interesting trends and developments of the last 12 months. This is based on our visibility in the threat landscape and it’s important to note that no single vendor has complete visibility into the activities of all threat actors.
## Private sector vendors play a significant role in the threat landscape
Possibly the bigges
Securelist
APT annual review 2021
blogs_securelist·2021-11-30
APT annual review 2021
Table of Contents
- Private sector vendors play a significant role in the threat landscape
- Supply-chain attacks
- Exploiting vulnerabilities
- Firmware vulnerabilities
Authors
- GReAT
In the Global Research and Analysis Team at Kaspersky, we track the ongoing activities of more than 900 advanced threat actors and activity clusters; you can find our quarterly overviews here, here and here. For this annual review, we have tried to focus on what we consider to be the most interesting trends and developments of the last 12 months. This is based on our visibility in the threat landscape and it’s important to note that no single vendor has complete visibility into the activities of all threat actors.
## Private sector vendors play a significant role in the threat landscape
Possibly the
Qualys
Qualys Response to CISA Alert: Binding Operational Directive 22-01
blogs_qualys·2021-11-09
Qualys Response to CISA Alert: Binding Operational Directive 22-01
## Table of Contents
Overview
Directive Scope
CISA Catalog of Known Exploited Vulnerabilities
Detect CISAs Vulnerabilities Using Qualys VMDR
Remediation
Federal Enterprises and Agencies Can Act Now
Summary
Getting Started
Start your VMDR 30-day, no-cost trial today
## Overview
On November 3, 2021, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) released a Binding Operational Directive 22-01 , “Reducing the Significant Risk of Known Exploited Vulnerabilities.” This directive recommends urgent and prioritized remediation of the vulnerabilities that adversaries are actively exploiting. It establishes a CISA-managed catalog of known exploited vulnerabilities that carry significant risk to the federal government and establishes requirements for agencies to remediate
Qualys
Qualys Response to CISA Alert: Binding Operational Directive 22-01 | Qualys
blogs_qualys·2021-11-09
Qualys Response to CISA Alert: Binding Operational Directive 22-01 | Qualys
#### Table of Contents
- Overview
- Directive Scope
- CISA Catalog of Known Exploited Vulnerabilities
- Detect CISAs Vulnerabilities Using Qualys VMDR
- Remediation
- Federal Enterprises and Agencies Can Act Now
- Summary
- Getting Started
Start your VMDR 30-day, no-cost trial today
## Overview
On November 3, 2021, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) released a Binding Operational Directive 22-01, “Reducing the Significant Risk of Known Exploited Vulnerabilities.” This directive recommends urgent and prioritized remediation of the vulnerabilities that adversaries are actively exploiting. It establishes a CISA-managed catalog of known exploited vulnerabilities that carry significant risk to the federal government and establishes requirements for agencies to
Trendmicro
PurpleFox Adds New Backdoor That Uses WebSockets
blogs_trendmicro·2021-10-19·CVSS 7.8
CVE-2021-1732 [HIGH] PurpleFox Adds New Backdoor That Uses WebSockets
Ciberamenazas
## PurpleFox Adds New Backdoor That Uses WebSockets
In September 2021, the Trend Micro Managed XDR (MDR) team looked into suspicious activity related to a PurpleFox operator. Our findings led us to investigate an updated PurpleFox arsenal, which included an added vulnerability (CVE-2021-1732) and optimized rootkit capabilities leveraged in their attacks.
By: Abdelrhman Sharshar, Jay Yaneza, Sherif Magdy Oct 19, 2021 Read time: ( words)
Save to Folio
In September 2021, the Trend Micro Managed XDR (MDR) team looked into suspicious activity related to a PurpleFox operator. Our findings led us to investigate an updated PurpleFox arsenal, which included an added vulnerability (CVE-2021-1732) and optimized rootkit capabilities leveraged in their attacks.
We also found a new b
Trendmicro
PurpleFox Adds New Backdoor That Uses WebSockets
blogs_trendmicro·2021-10-19·CVSS 7.8
CVE-2021-1732 [HIGH] PurpleFox Adds New Backdoor That Uses WebSockets
Cyber Threats
## PurpleFox Adds New Backdoor That Uses WebSockets
In September 2021, the Trend Micro Managed XDR (MDR) team looked into suspicious activity related to a PurpleFox operator. Our findings led us to investigate an updated PurpleFox arsenal, which included an added vulnerability (CVE-2021-1732) and optimized rootkit capabilities leveraged in their attacks.
By: Abdelrhman Sharshar, Jay Yaneza, Sherif Magdy 2021/10/19 Read time: ( words)
Save to Folio
In September 2021, the Trend Micro Managed XDR (MDR) team looked into suspicious activity related to a PurpleFox operator. Our findings led us to investigate an updated PurpleFox arsenal, which included an added vulnerability (CVE-2021-1732) and optimized rootkit capabilities leveraged in their attacks.
We also found a new bac
Trendmicro
PurpleFox Adds New Backdoor That Uses WebSockets
blogs_trendmicro·2021-10-19·CVSS 7.8
CVE-2021-1732 [HIGH] PurpleFox Adds New Backdoor That Uses WebSockets
Cyber Threats
# PurpleFox Adds New Backdoor That Uses WebSockets
In September 2021, the Trend Micro Managed XDR (MDR) team looked into suspicious activity related to a PurpleFox operator. Our findings led us to investigate an updated PurpleFox arsenal, which included an added vulnerability (CVE-2021-1732) and optimized rootkit capabilities leveraged in their attacks.
By: Abdelrhman Sharshar, Jay Yaneza, Sherif Magdy
2021/10/19
Read time: ( words)
Save to Folio
In September 2021, the Trend Micro Managed XDR (MDR) team looked into suspicious activity related to a PurpleFox operator. Our findings led us to investigate an updated PurpleFox arsenal, which included an added vulnerability (CVE-2021-1732) and optimized rootkit capabilities leveraged in their attacks.
We also found a new bac
Trendmicro
PurpleFox Adds New Backdoor That Uses WebSockets
blogs_trendmicro·2021-10-19·CVSS 7.8
CVE-2021-1732 [HIGH] PurpleFox Adds New Backdoor That Uses WebSockets
Cyber Threats
## PurpleFox Adds New Backdoor That Uses WebSockets
In September 2021, the Trend Micro Managed XDR (MDR) team looked into suspicious activity related to a PurpleFox operator. Our findings led us to investigate an updated PurpleFox arsenal, which included an added vulnerability (CVE-2021-1732) and optimized rootkit capabilities leveraged in their attacks.
By: Abdelrhman Sharshar, Jay Yaneza, Sherif Magdy Oct 19, 2021 Read time: ( words)
Save to Folio
In September 2021, the Trend Micro Managed XDR (MDR) team looked into suspicious activity related to a PurpleFox operator. Our findings led us to investigate an updated PurpleFox arsenal, which included an added vulnerability (CVE-2021-1732) and optimized rootkit capabilities leveraged in their attacks.
We also found a new b
Trendmicro
PurpleFox Adds New Backdoor That Uses WebSockets
blogs_trendmicro·2021-10-19·CVSS 7.8
CVE-2021-1732 [HIGH] PurpleFox Adds New Backdoor That Uses WebSockets
Cyberbedrohungen
## PurpleFox Adds New Backdoor That Uses WebSockets
In September 2021, the Trend Micro Managed XDR (MDR) team looked into suspicious activity related to a PurpleFox operator. Our findings led us to investigate an updated PurpleFox arsenal, which included an added vulnerability (CVE-2021-1732) and optimized rootkit capabilities leveraged in their attacks.
By: Abdelrhman Sharshar, Jay Yaneza, Sherif Magdy Oct 19, 2021 Read time: ( words)
Save to Folio
In September 2021, the Trend Micro Managed XDR (MDR) team looked into suspicious activity related to a PurpleFox operator. Our findings led us to investigate an updated PurpleFox arsenal, which included an added vulnerability (CVE-2021-1732) and optimized rootkit capabilities leveraged in their attacks.
We also found a ne
Securelist
IT threat evolution Q2 2021
blogs_securelist·2021-08-12·CVSS 7.8
[HIGH] IT threat evolution Q2 2021
Table of Contents
- Targeted attacks
- Other malware
Authors
- David Emm
## Targeted attacks
### The leap of a Cycldek-related threat actor
It is quite common for Chinese-speaking threat actors to share tools and methodologies: one such example is the infamous “DLL side-loading triad”: a legitimate executable, a malicious DLL to be side-loaded by it and an encoded payload, generally dropped from a self-extracting archive. This was first thought to be a signature of LuckyMouse, but we have observed other groups using similar “triads”, including HoneyMyte. While it is not possible to attribute attacks based on this technique alone, efficient detection of such triads reveals more and more malicious activity.
We recently described one such file, called “FoundCore”, which caught our atte
Securelist
APT trends report Q2 2021
blogs_securelist·2021-07-29
APT trends report Q2 2021
Table of Contents
The most remarkable findings
Russian-speaking activity
Chinese-speaking activity
Middle East
Southeast Asia and Korean Peninsula
Other interesting discoveries
Final thoughts
Authors
GReAT
For more than four years, the Global Research and Analysis Team (GReAT) at Kaspersky has been publishing quarterly summaries of advanced persistent threat (APT) activity. The summaries are based on our threat intelligence research and provide a representative snapshot of what we have published and discussed in greater detail in our private APT reports. They are designed to highlight the significant events and findings that we feel people should be aware of.
This is our latest installment, focusing on activities that we observed during Q2 2021.
Readers who would like to learn
Securelist
APT trends report Q2 2021
blogs_securelist·2021-07-29
APT trends report Q2 2021
Table of Contents
- The most remarkable findings
- Russian-speaking activity
- Chinese-speaking activity
- Middle East
- Southeast Asia and Korean Peninsula
- Other interesting discoveries
- Final thoughts
Authors
- GReAT
For more than four years, the Global Research and Analysis Team (GReAT) at Kaspersky has been publishing quarterly summaries of advanced persistent threat (APT) activity. The summaries are based on our threat intelligence research and provide a representative snapshot of what we have published and discussed in greater detail in our private APT reports. They are designed to highlight the significant events and findings that we feel people should be aware of.
This is our latest installment, focusing on activities that we observed during Q2 2021.
Readers who would lik
Tenable
Microsoft’s June 2021 Patch Tuesday Addresses 49 CVEs (CVE-2021-31955, CVE-2021-31956 and CVE-2021-33742)
blogs_tenable·2021-06-08·CVSS 5.5
[MEDIUM] Microsoft’s June 2021 Patch Tuesday Addresses 49 CVEs (CVE-2021-31955, CVE-2021-31956 and CVE-2021-33742)
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Securelist
IT threat evolution Q1 2021. Non-mobile statistics
blogs_securelist·2021-05-31
IT threat evolution Q1 2021. Non-mobile statistics
Table of Contents
Quarterly figures
Financial threats
Financial threat statistics
Ransomware programs
Quarterly trends and highlights
Number of new modifications
Number of users attacked by ransomware Trojans
Attack geography
Top 10 most common families of ransomware Trojans
Miners
Number of new modifications
Number of users attacked by miners
Attack geography
Vulnerable applications used by cybercriminals during cyber attacks
Attacks on macOS
Threat geography
IoT attacks
IoT threat statistics
SSH-based attacks
Threats loaded into traps
Attacks via web resources
Countries that are sources of web-based attacks: Top 10
Countries where users faced the greatest risk of online infection
Local threats
Countries where users faced the highest risk of local infection
Autho
Securelist
IT threat evolution Q1 2021. Non-mobile statistics
blogs_securelist·2021-05-31
IT threat evolution Q1 2021. Non-mobile statistics
Table of Contents
- Quarterly figures
- Financial threats
- Ransomware programs
- Miners
- Vulnerable applications used by cybercriminals during cyber attacks
- Attacks on macOS
- IoT attacks
- Attacks via web resources
- Local threats
Authors
- AMR
These statistics are based on detection verdicts of Kaspersky products received from users who consented to provide statistical data.
## Quarterly figures
According to Kaspersky Security Network, in Q1 2021:
- Kaspersky solutions blocked 2,023,556,082 attacks launched from online resources across the globe.
- 613,968,631 unique URLs were recognized as malicious by Web Anti-Virus components.
- Attempts to run malware designed to steal money via online access to bank accounts were stopped on the computers of 118,099 users.
- Ransomware att
Securelist
APT trends report Q1 2021
blogs_securelist·2021-04-27
APT trends report Q1 2021
Table of Contents
- The most remarkable findings
- Europe
- Russian-speaking activity
- Chinese-speaking activity
- Middle East
- Southeast Asia and Korean Peninsula
- Other interesting discoveries
- Final thoughts
Authors
- GReAT
For four years, the Global Research and Analysis Team (GReAT) at Kaspersky has been publishing quarterly summaries of advanced persistent threat (APT) activity. The summaries are based on our threat intelligence research and provide a representative snapshot of what we have published and discussed in greater detail in our private APT reports. They are designed to highlight the significant events and findings that we feel people should be aware of.
This is our latest installment, focusing on activities that we observed during Q1 2021.
Readers who would like
Securelist
APT trends report Q1 2021
blogs_securelist·2021-04-27
APT trends report Q1 2021
Table of Contents
The most remarkable findings
Europe
Russian-speaking activity
Chinese-speaking activity
Middle East
Southeast Asia and Korean Peninsula
Other interesting discoveries
Final thoughts
Authors
GReAT
For four years, the Global Research and Analysis Team (GReAT) at Kaspersky has been publishing quarterly summaries of advanced persistent threat (APT) activity. The summaries are based on our threat intelligence research and provide a representative snapshot of what we have published and discussed in greater detail in our private APT reports. They are designed to highlight the significant events and findings that we feel people should be aware of.
This is our latest installment, focusing on activities that we observed during Q1 2021.
Readers who would like to learn mo
Securelist
Zero-day vulnerability in Desktop Window Manager (CVE-2021-28310) used in the wild
blogs_securelist·2021-04-13·CVSS 7.8
CVE-2021-1732 [HIGH] Zero-day vulnerability in Desktop Window Manager (CVE-2021-28310) used in the wild
Authors
Boris Larin
Costin Raiu
Brian Bartholomew
While analyzing the CVE-2021-1732 exploit originally discovered by the DBAPPSecurity Threat Intelligence Center and used by the BITTER APT group, we discovered another zero-day exploit we believe is linked to the same actor. We reported this new exploit to Microsoft in February and after confirmation that it is indeed a zero-day, it received the designation CVE-2021-28310. Microsoft released a patch to this vulnerability as a part of its April security updates.
We believe this exploit is used in the wild, potentially by several threat actors. It is an escalation of privilege (EoP) exploit that is likely used together with other browser exploits to escape sandboxes or get system privileges for further access. Unfortunately, we weren’t a
Securelist
Zero-day vulnerability in Desktop Window Manager (CVE-2021-28310) used in the wild
blogs_securelist·2021-04-13·CVSS 7.8
CVE-2021-28310 [HIGH] Zero-day vulnerability in Desktop Window Manager (CVE-2021-28310) used in the wild
Authors
- Boris Larin
- Costin Raiu
- Brian Bartholomew
While analyzing the CVE-2021-1732 exploit originally discovered by the DBAPPSecurity Threat Intelligence Center and used by the BITTER APT group, we discovered another zero-day exploit we believe is linked to the same actor. We reported this new exploit to Microsoft in February and after confirmation that it is indeed a zero-day, it received the designation CVE-2021-28310. Microsoft released a patch to this vulnerability as a part of its April security updates.
We believe this exploit is used in the wild, potentially by several threat actors. It is an escalation of privilege (EoP) exploit that is likely used together with other browser exploits to escape sandboxes or get system privileges for further access. Unfortunately, we weren
Checkpoint
15th February – Threat Intelligence Report
blogs_checkpoint·2021-02-15
CVE-2021-1732 15th February – Threat Intelligence Report
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 15th February – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 15th February, please download our Threat Intelligence Bulletin .
Top Attacks and Breaches
Russian Internet and e-Commerce giant Yandex has suffered a breach that led to the exposure of almost 5,000 customer accounts. The breach was enabled by a system admin that sold unauthorized access to customer mailboxes.
Threat actors have gained access to the industrial control system at a US drinking water treatment
Krebs
Microsoft Patch Tuesday, February 2021 Edition
blogs_krebs·2021-02-09·CVSS 7.8
[HIGH] Microsoft Patch Tuesday, February 2021 Edition
Microsoft today rolled out updates to plug at least 56 security holes in its Windows operating systems and other software. One of the bugs is already being actively exploited, and six of them were publicized prior to today, potentially giving attackers a head start in figuring out how to exploit the flaws.
Nine of the 56 vulnerabilities earned Microsoft’s most urgent “critical” rating, meaning malware or miscreants could use them to seize remote control over unpatched systems with little or no help from users.
The flaw being exploited in the wild already — CVE-2021-1732 — affects Windows 10, Server 2016 and later editions. It received a slightly less dire “important” rating and mainly because it is a vulnerability that lets an attacker increase their authority and control on a device, wh
Talos
Microsoft Patch Tuesday for Feb. 2021 — Snort rules and prominent vulnerabilities
blogs_talos·2021-02-09·CVSS 7.8
[HIGH] Microsoft Patch Tuesday for Feb. 2021 — Snort rules and prominent vulnerabilities
## Microsoft Patch Tuesday for Feb. 2021 — Snort rules and prominent vulnerabilities
By Jon Munshaw, with contributions from Bill Largent.
Microsoft released its monthly security update Tuesday, disclosing 56 vulnerabilities across its suite of products. This is the smallest amount of vulnerabilities Microsoft has disclosed in a month since January 2020.
There are only 11 critical vulnerabilities as part of this release, while there are three moderate-severity exploits, and the remainder are considered “important.” Users of all Microsoft and Windows products are urged to update their software as soon as possible to avoid possible exploitation of all these bugs.
The security updates cover several different products and services, including the Microsoft Office suite of products, the Wind
Tenable
Microsoft’s February 2021 Patch Tuesday Addresses 56 CVEs (CVE-2021-24074, CVE-2021-24094, CVE-2021-24086)
blogs_tenable·2021-02-09·CVSS 9.8
[CRITICAL] Microsoft’s February 2021 Patch Tuesday Addresses 56 CVEs (CVE-2021-24074, CVE-2021-24094, CVE-2021-24086)
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Talos
Microsoft Patch Tuesday for Feb. 2021 — Snort rules and prominent vulnerabilities
blogs_talos·2021-02-09·CVSS 7.8
[HIGH] Microsoft Patch Tuesday for Feb. 2021 — Snort rules and prominent vulnerabilities
By Jon Munshaw, with contributions from Bill Largent.
Microsoft released its monthly security update Tuesday, disclosing 56 vulnerabilities across its suite of products. This is the smallest amount of vulnerabilities Microsoft has disclosed in a month since January 2020.
There are only 11 critical vulnerabilities as part of this release, while there are three moderate-severity exploits, and the remainder are considered “important.” Users of all Microsoft and Windows products are urged to update their software as soon as possible to avoid possible exploitation of all these bugs.
The security updates cover several different products and services, including the Microsoft Office suite of products, the Windows DNS server and the SharePoint file-sharing service.
Talos also released a new set
Krebs
Microsoft Patch Tuesday, February 2021 Edition
blogs_krebs·2021-02-09·CVSS 7.8
[HIGH] Microsoft Patch Tuesday, February 2021 Edition
Microsoft today rolled out updates to plug at least 56 security holes in its Windows operating systems and other software. One of the bugs is already being actively exploited, and six of them were publicized prior to today, potentially giving attackers a head start in figuring out how to exploit the flaws.
Nine of the 56 vulnerabilities earned Microsoft’s most urgent “critical” rating, meaning malware or miscreants could use them to seize remote control over unpatched systems with little or no help from users.
The flaw being exploited in the wild already — CVE-2021-1732 — affects Windows 10, Server 2016 and later editions. It received a slightly less dire “important” rating and mainly because it is a vulnerability that lets an attacker increase their authority and control on a device, wh
Qualys
February 2021 Patch Tuesday – 56 Vulnerabilities, 11 Critical, Adobe
blogs_qualys·2021-02-09·CVSS 7.8
CVE-2021-24074 [HIGH] February 2021 Patch Tuesday – 56 Vulnerabilities, 11 Critical, Adobe
This month’s Microsoft Patch Tuesday addresses 56 vulnerabilities, of which 11 are rated as Critical. Adobe released patches today for Reader, Acrobat, Magento, Photoshop, Animate, Illustrator, and Dreamweaver.
## TCP/IP Trio
Microsoft released a set of fixes affecting Windows TCP/IP implementation that include two Critical Remote Code Execution (RCE) vulnerabilities (CVE-2021-24074 and CVE-2021-24094) and an Important Denial of Service (DoS) vulnerability (CVE-2021-24086). While there is no evidence that these vulnerabilities are exploited in wild, these vulnerabilities should be prioritized given their impact.
## Windows Fax Service
Microsoft released patches to fix a remote code execution vulnerability in Windows Fax Service (CVE-2021-24077). This vulnerability has a CVSSv3 base sco
Qualys
February 2021 Patch Tuesday – 56 Vulnerabilities, 11 Critical, Adobe | Qualys
blogs_qualys·2021-02-09·CVSS 7.8
CVE-2021-24074 [HIGH] February 2021 Patch Tuesday – 56 Vulnerabilities, 11 Critical, Adobe | Qualys
This month’s Microsoft Patch Tuesday addresses 56 vulnerabilities, of which 11 are rated as Critical. Adobe released patches today for Reader, Acrobat, Magento, Photoshop, Animate, Illustrator, and Dreamweaver.
### TCP/IP Trio
Microsoft released a set of fixes affecting Windows TCP/IP implementation that include two Critical Remote Code Execution (RCE) vulnerabilities (CVE-2021-24074 and CVE-2021-24094) and an Important Denial of Service (DoS) vulnerability (CVE-2021-24086). While there is no evidence that these vulnerabilities are exploited in wild, these vulnerabilities should be prioritized given their impact.
### Windows Fax Service
Microsoft released patches to fix a remote code execution vulnerability in Windows Fax Service (CVE-2021-24077). This vulnerability has a CVSSv3 base s
Crowdstrike
Patch Tuesday 2021: A Vulnerability Deep Dive
blogs_crowdstrike·CVSS 7.5
CVE-2026-20929 [HIGH] Patch Tuesday 2021: A Vulnerability Deep Dive
How CrowdStrike is Accelerating Exposure Evaluation as Adversaries Gain Speed Apr 06, 2026
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
How CrowdStrike is Accelerating Exposure Evaluation as Adversaries Gain Speed Apr 06, 2026
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
Video Highlights the 4 Key Steps to Successful Incident Response Dec 02, 2019
Helping Non-Security Stakeholders Understand AT
Threat Intel
BITTER (BITTER, T-APT-17)
threat_intel·CVSS 8.8
[HIGH] BITTER (BITTER, T-APT-17)
# Threat Actor Profile: BITTER
ATT&CK ID: G1002
Also known as: BITTER, T-APT-17
Suspected origin: China
## Overview
BITTER is a suspected South Asian cyber espionage threat group that has been active since at least 2013. BITTER has targeted government, energy, and engineering organizations in Pakistan, China, Bangladesh, and Saudi Arabia.(Citation: Cisco Talos Bitter Bangladesh May 2022)(Citation: Forcepoint BITTER Pakistan Oct 2016)
## Techniques (TTPs)
### Resource Development
- T1588.002 Tool
Usage: BITTER has obtained tools such as PuTTY for use in their operations.(Citation: Forcepoint BITTER Pakistan Oct 2016)
- T1608.001 Upload Malware
Usage: BITTER has registered domains to stage payloads.(Citation: Forcepoint BITTER Pakistan Oct 2016)
- T1583.001 Domains
Usage: BITTER has regis
Crowdstrike
What is Patch Management?
blogs_crowdstrike·CVSS 7.8
[HIGH] What is Patch Management?
Upcoming events
Conference
CrowdTour
Find a city near you
Your Cart
Added to Cart
There's nothing in your cart
per endpoint / per year
per endpoint / per month
Login
Login
Experienced a breach?
Contact us
## What is Patch Management
Patch management is the process of identifying and deploying software updates, or “patches,” to a variety of endpoints, including computers, mobile devices, and servers.
A “patch” is a specific change or set of updates provided by software developers to fix known security vulnerabilities or technical issues. Patches can also include the addition of new features and functions to the application. It’s important to note that patches are typically short-term solutions intended to be used until the next full software release.
## What Is the Patch
Zscaler
Zscaler protects against 4 new vulnerabilities for MS-Window
blogs_zscaler·CVSS 7.8
[HIGH] Zscaler protects against 4 new vulnerabilities for MS-Window
Provide users with seamless, secure, reliable access to applications and data.
Build and run secure cloud apps, enable zero trust cloud connectivity, and protect workloads from data center to cloud.
Provide zero trust connectivity for IoT and OT devices and secure remote access to OT systems.
Provide zero trust site-to-site connectivity and reliable access to B2B apps for partners.
Industry Report
Zscaler: A Leader in the 2025 Gartner® Magic Quadrant™ for Security Service Edge (SSE)
USE CASES
INDUSTRY & MARKET SOLUTIONS
PARTNERS
TECHNOLOGY PARTNERS
Resource Center
Events & Trainings
Security Research & Services
Tools
Community & Support
CXO REVOLUTIONARIES
Amplifying the voices of real-world digital and zero trust pioneers
Discover how it began and where it’s going
Meet o
Crowdstrike
What is Patch Management?
blogs_crowdstrike·CVSS 7.8
[HIGH] What is Patch Management?
Upcoming events
Conference
CrowdTour
Find a city near you
Login
Your Cart
Added to Cart
There's nothing in your cart
per endpoint / per year
per endpoint / per month
Login
Experienced a breach?
Contact us
## What is Patch Management
Patch management is the process of identifying and deploying software updates, or “patches,” to a variety of endpoints, including computers, mobile devices, and servers.
A “patch” is a specific change or set of updates provided by software developers to fix known security vulnerabilities or technical issues. Patches can also include the addition of new features and functions to the application. It’s important to note that patches are typically short-term solutions intended to be used until the next full software release.
## What Is the Patch
Crowdstrike
¿Qué es la gestión de parches?
blogs_crowdstrike
¿Qué es la gestión de parches?
Próximos eventos
Conferencia
CrowdTour
Encuentra la ciudad más cercana
Inicio de sesión
Tu cesta
Añadido a la cesta
Tu cesta está vacía
por endpoint / por año
al mes por endpoint
Inicio de sesión
¿Has sufrido una brecha de seguridad?
Contacto
## Qué es la gestión de parches
La gestión de parches es el proceso de identificación e implementación de actualizaciones de software, o "parches", en diversos endpoints, tales como ordenadores, dispositivos móviles y servidores.
Un "parche" es un cambio específico o un conjunto de actualizaciones proporcionadas por los desarrolladores de software para corregir vulnerabilidades de seguridad o problemas técnicos conocidos. Los parches también pueden incluir la incorporación de nuevas características y funciones a la aplicación. Es impo
Crowdstrike
Patch Tuesday 2021: A Vulnerability Deep Dive
blogs_crowdstrike·CVSS 7.5
CVE-2026-20929 [HIGH] Patch Tuesday 2021: A Vulnerability Deep Dive
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
How Charlotte AI AgentWorks Fuels Security's Agentic Ecosystem Mar 25, 2026
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
How Charlotte AI AgentWorks Fuels Security's Agentic Ecosystem Mar 25, 2026
Video Highlights the 4 Key Steps to Successful Incident Response Dec 02, 2019
Helping Non-Security Stakeholders Understand ATT&CK in 10 Minutes or Less [VI
Threat Intel
MoustachedBouncer (MoustachedBouncer)
threat_intel·CVSS 7.8
[HIGH] MoustachedBouncer (MoustachedBouncer)
# Threat Actor Profile: MoustachedBouncer
ATT&CK ID: G1019
Also known as: MoustachedBouncer
## Overview
MoustachedBouncer is a cyberespionage group that has been active since at least 2014 targeting foreign embassies in Belarus.(Citation: MoustachedBouncer ESET August 2023)
## Techniques (TTPs)
### Initial Access
- T1659 Content Injection
Usage: MoustachedBouncer has injected content into DNS, HTTP, and SMB replies to redirect specifically-targeted victims to a fake Windows Update page to download malware.(Citation: MoustachedBouncer ESET August 2023)
### Execution
- T1059.001 PowerShell
Usage: MoustachedBouncer has used plugins to execute PowerShell scripts.(Citation: MoustachedBouncer ESET August 2023)
- T1059.007 JavaScript
Usage: MoustachedBouncer has used JavaScript to deliver mal
Sentinelone
BlueSky
blogs_sentinelone
BlueSky
# BlueSky Ransomware: In-Depth Analysis, Detection, and Mitigation
## What is BlueSky Ransomware?
BlueSky ransomware emerged in July 2022 and is known to distribute their payload through trojanized downloads from risky websites. Based on current observations, BlueSky operators currently do not operate a victim data listing blog.
## What Does BlueSky Ransomware Target?
BlueSky ransomware is known to target large enterprises and high-value targets as well as small and medium-sized businesses (SMBs).
## How Does BlueSky Ransomware Work?
BlueSkyThanos ransomware targets its victims through trojanized downloads. Once active, the ransomware has the ability to move laterally (spreading via SMB).
## BlueSky Ransomware Technical Details
Initial delivery can vary by affiliate. However, some
http://packetstormsecurity.com/files/161880/Win32k-ConsoleControl-Offset-Confusion.htmlhttp://packetstormsecurity.com/files/166169/Win32k-ConsoleControl-Offset-Confusion-Privilege-Escalation.htmlhttps://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-1732http://packetstormsecurity.com/files/161880/Win32k-ConsoleControl-Offset-Confusion.htmlhttp://packetstormsecurity.com/files/166169/Win32k-ConsoleControl-Offset-Confusion-Privilege-Escalation.htmlhttps://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-1732https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-1732
2021-02-25
Published
2021-11-03
Added to CISA KEV
Exploited in the wild