CVE-2022-30190
published 2022-06-01CVE-2022-30190: A remote code execution vulnerability exists when MSDT is called using the URL protocol from a calling application such as Word. An attacker who successfully…
PriorityP188high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
KEVITWEXPLOITRansomware
CISA Known Exploited Vulnerabilitydue 2022-07-05
Exploited in the wild
EPSS
99.37%
99.9th percentile
A remote code execution vulnerability exists when MSDT is called using the URL protocol from a calling application such as Word. An attacker who successfully exploits this vulnerability can run arbitrary code with the privileges of the calling application. The attacker can then install programs, view, change, or delete data, or create new accounts in the context allowed by the user’s rights.
Please see the MSRC Blog Entry for important information about steps you can take to protect your system from this vulnerability.
Affected
47 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | windows_10_1507 | < 10.0.10240.19325 | 10.0.10240.19325 |
| microsoft | windows_10_1607 | < 10.0.14393.5192 | 10.0.14393.5192 |
| microsoft | windows_10_1809 | < 10.0.17763.3046 | 10.0.17763.3046 |
| microsoft | windows_10_20h2 | < 10.0.19042.1766 | 10.0.19042.1766 |
| microsoft | windows_10_21h1 | < 10.0.19043.1766 | 10.0.19043.1766 |
| microsoft | windows_10_21h2 | < 10.0.19044.1766 | 10.0.19044.1766 |
| microsoft | windows_10_version_1507 | >= 10.0.10240.0 < 10.0.10240.19325 | 10.0.10240.19325 |
| microsoft | windows_10_version_1607 | >= 10.0.14393.0 < 10.0.14393.5192 | 10.0.14393.5192 |
| microsoft | windows_10_version_1809 | >= 10.0.0 < 10.0.17763.3046 | 10.0.17763.3046 |
| microsoft | windows_10_version_1809 | >= 10.0.17763.0 < 10.0.17763.3046 | 10.0.17763.3046 |
| microsoft | windows_10_version_20h2 | >= 10.0.0 < 10.0.19042.1766 | 10.0.19042.1766 |
| microsoft | windows_10_version_21h1 | >= 10.0.0 < 10.0.19043.1766 | 10.0.19043.1766 |
| microsoft | windows_10_version_21h2 | >= 10.0.19043.0 < 10.0.19044.1766 | 10.0.19044.1766 |
| microsoft | windows_11_21h2 | < 10.0.22000.739 | 10.0.22000.739 |
| microsoft | windows_11_version_21h2 | >= 10.0.0 < 10.0.22000.739 | 10.0.22000.739 |
| microsoft | windows_7 | >= 6.1.0 < 6.1.7601.25984 | 6.1.7601.25984 |
| microsoft | windows_7_service_pack_1 | >= 6.1.0 < 6.1.7601.25984 | 6.1.7601.25984 |
| microsoft | windows_8.1 | >= 6.3.0 < 6.3.9600.20402 | 6.3.9600.20402 |
| microsoft | windows_server_2008 | — | — |
| microsoft | windows_server_2008_r2_service_pack_1 | >= 6.1.7601.0 < 6.1.7601.25984 | 6.1.7601.25984 |
| microsoft | windows_server_2012 | — | — |
| microsoft | windows_server_2012 | >= 6.2.9200.0 < 6.2.9200.23736 | 6.2.9200.23736 |
| microsoft | windows_server_2012_r2 | >= 6.3.9600.0 < 6.3.9600.20402 | 6.3.9600.20402 |
| microsoft | windows_server_2016 | < 10.0.14393.5192 | 10.0.14393.5192 |
| microsoft | windows_server_2016 | >= 10.0.14393.0 < 10.0.14393.5192 | 10.0.14393.5192 |
Detection & IOCsextracted from sources · hover to see the quote
yara↗
PDM:Exploit.Win32.Generic
yara↗
HEUR:Exploit.MSOffice.Agent.n
yara↗
HEUR:Exploit.MSOffice.Agent.gen
yara↗
HEUR:Exploit.MSOffice.Generic
- →RTF-format malicious documents trigger the exploit on file preview in Windows Explorer without requiring the document to be opened — monitor for MSDT spawning from explorer.exe on RTF file selection. ↗
- →Exploitation executes PowerShell code via the ms-msdt URI scheme; detect PowerShell child processes spawned by MSDT (msdt.exe). ↗
- →Cisco Talos released Snort rules and a ClamAV signature for CVE-2022-30190; deploy these signatures on network and endpoint sensors. ↗
- →QAKBOT threat actor leveraged CVE-2022-30190 (Follina) as an initial access vector; correlate QAKBOT indicators with Follina exploitation activity. ↗
- →Exploitation was observed as early as April 2022 against targets in Russia and Belarus; threat hunting should cover this timeframe in historical telemetry. ↗
- ·The exploit works even when macros are disabled and the document is opened in Protected Mode (for .docx); Protected View is only bypassed automatically for RTF files. ↗
- ·Patched versions of Office 2019 and 2021 (prior to the June 14 Patch Tuesday fix) were also vulnerable; do not assume a fully-patched pre-June-2022 Office installation is protected. ↗
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
vulncheck7.8HIGH
cisa7.8HIGH
vendor_msrc7.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA
Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability
cisa·2022-06-14·CVSS 7.8
CVE-2022-30190 [HIGH] CWE-610 Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability
Vulnerability: Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability
Affected: Microsoft Windows
A remote code execution vulnerability exists when MSDT is called using the URL protocol from a calling application such as Word. An attacker who successfully exploits this vulnerability can run code with the privileges of the calling application.
Required Action: Apply updates per vendor instructions.
Notes: https://nvd.nist.gov/vuln/detail/CVE-2022-30190
Remediation Due Date: 2022-07-05
Microsoft
Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability
vendor_msrc·2022-05-10·CVSS 7.8
CVE-2022-30190 [HIGH] Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability
Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability
Description: A remote code execution vulnerability exists when MSDT is called using the URL protocol from a calling application such as Word. An attacker who successfully exploits this vulnerability can run arbitrary code with the privileges of the calling application. The attacker can then install programs, view, change, or delete data, or create new accounts in the context allowed by the user’s rights.
Please see the MSRC Blog Entry for important information about steps you can take to protect your system from this vulnerability.
FAQ: According to the CVSS metric, the attack vector is local (AV:L). Why does the CVE title indicate that this is a remote code execution?
The word Remote in the title refers
GHSA
GHSA-4r9q-wqcj-x85j: Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability
ghsa_unreviewed·2022-06-02
CVE-2022-30190 [HIGH] CWE-610 GHSA-4r9q-wqcj-x85j: Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability
Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability.
Project0
2022 0-day In-the-Wild Exploitation…so far - Project Zero
project_zero·2022-06-01·CVSS 8.8
CVE-2016-5128 [HIGH] 2022 0-day In-the-Wild Exploitation…so far - Project Zero
Posted by Maddie Stone, Google Project Zero
This blog post is an overview of a talk, “ 0-day In-the-Wild Exploitation in 2022…so far”, that I gave at the FIRST conference in June 2022. The slides are available here.
For the last three years, we’ve published annual year-in-review reports of 0-days found exploited in the wild. The most recent of these reports is the 2021 Year in Review report, which we published just a few months ago in April. While we plan to stick with that annual cadence, we’re publishing a little bonus report today looking at the in-the-wild 0-days detected and disclosed in the first half of 2022.
As of June 15, 2022, there have been 18 0-days detected and disclosed as exploited in-the-wild in 2022. When we analyzed those 0-days, we found that at least nin
VulnCheck
Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability
vulncheck·2022·CVSS 7.8
CVE-2022-30190 [HIGH] CWE-610 Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability
Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability
A remote code execution vulnerability exists when MSDT is called using the URL protocol from a calling application such as Word. An attacker who successfully exploits this vulnerability can run code with the privileges of the calling application.
Affected: Microsoft Windows
Required Action: Apply updates per vendor instructions.
Known Ransomware Campaign Use: Known
Exploitation References: https://api.msrc.microsoft.com/cvrf/v3.0/cvrf/2022-May; https://cisa.gov/news-events/alerts/2022/05/31/microsoft-releases-workaround-guidance-msdt-follina-vulnerability; https://www.malwarebytes.com/blog/threat-intelligence/2022/06/russias-apt28-uses-fear-of-nuclear-war-to-spread-follina-docs-in-ukraine; https://doc
Suricata
ET HUNTING Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution 0-click RTF (CVE-2022-30190)
suricata·2025-01-27·CVSS 7.8
CVE-2022-30190 [HIGH] ET HUNTING Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution 0-click RTF (CVE-2022-30190)
ET HUNTING Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution 0-click RTF (CVE-2022-30190)
Rule: alert tcp any any -> $HOME_NET any (msg:"ET HUNTING Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution 0-click RTF (CVE-2022-30190)"; flow:established,to_client; file.data; content:"|7b 5c|rtf"; content:"|7b 5c 2a 5c|oleclsid |5c 27|7b00000300-0000-0000-C000-000000000046|5c 27|7d|7d|"; fast_pattern; content:"|7b 5c 2a 5c|objdata|20|0105000002000000"; content:"4f4c45324c696e6b00"; nocase; distance:8; content:"d0cf11e0a1b11ae1"; nocase; distance:0; reference:url,msrc.microsoft.com/update-guide/vulnerability/CVE-2022-30190; reference:cve,2022-30190; classtype:bad-unknown; sid:2059679; rev:1; metadata:attack_target Client_Endpoint, tls_state TLSDecrypt, crea
Suricata
ET EXPLOIT Possible Microsoft Support Diagnostic Tool Exploitation Inbound (CVE-2022-30190)
suricata·2022-05-31·CVSS 7.8
CVE-2022-30190 [HIGH] ET EXPLOIT Possible Microsoft Support Diagnostic Tool Exploitation Inbound (CVE-2022-30190)
ET EXPLOIT Possible Microsoft Support Diagnostic Tool Exploitation Inbound (CVE-2022-30190)
Rule: alert http $EXTERNAL_NET any -> $HOME_NET any (msg:"ET EXPLOIT Possible Microsoft Support Diagnostic Tool Exploitation Inbound (CVE-2022-30190)"; flow:established,to_client; file.data; bsize:>4095; content:"location.href"; nocase; pcre:"/^\s*=\s*[\x22\x27]\s*ms-msdt\x3a/Ri"; content:"ms-msdt|3a|"; fast_pattern; nocase; reference:cve,2022-30190; classtype:attempted-user; sid:2036726; rev:3; metadata:attack_target Server, created_at 2022_05_31, cve CVE_2022_30190, deployment Perimeter, deployment Internal, confidence Medium, signature_severity Major, tag Exploit, tag CISA_KEV, updated_at 2024_03_08, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access, mitre_technique_id T1190, mitre_techni
Sigma
Diagnostic Library Sdiageng.DLL Loaded By Msdt.EXE
sigma·CVSS 7.8
CVE-2022-30190 [HIGH] Diagnostic Library Sdiageng.DLL Loaded By Msdt.EXE
Diagnostic Library Sdiageng.DLL Loaded By Msdt.EXE
Detects both of CVE-2022-30190 (Follina) and DogWalk vulnerabilities exploiting msdt.exe binary to load the "sdiageng.dll" library
Detection:
condition: selection
selection:
ImageLoaded|endswith: \sdiageng.dll
Image|endswith: \msdt.exe
Log Source: category: image_load
product: windows
Sigma
Potential Arbitrary Command Execution Using Msdt.EXE
sigma·CVSS 7.8
CVE-2022-30190 [HIGH] Potential Arbitrary Command Execution Using Msdt.EXE
Potential Arbitrary Command Execution Using Msdt.EXE
Detects processes leveraging the "ms-msdt" handler or the "msdt.exe" binary to execute arbitrary commands as seen in the follina (CVE-2022-30190) vulnerability
Detection:
condition: selection_img and (selection_cmd_inline or all of selection_cmd_answerfile_*)
selection_cmd_answerfile_flag:
CommandLine|contains: ' PCWDiagnostic'
selection_cmd_answerfile_param:
CommandLine|contains|windash: ' -af '
selection_cmd_inline:
CommandLine|contains: IT_BrowseForFile=
selection_img:
- Image|endswith: \msdt.exe
- OriginalFileName: msdt.exe
Log Source: category: process_creation
product: windows
Sigma
Suspicious Cabinet File Execution Via Msdt.EXE
sigma·CVSS 7.8
CVE-2022-30190 [HIGH] Suspicious Cabinet File Execution Via Msdt.EXE
Suspicious Cabinet File Execution Via Msdt.EXE
Detects execution of msdt.exe using the "cab" flag which could indicates suspicious diagcab files with embedded answer files leveraging CVE-2022-30190
Detection:
condition: all of selection_*
selection_cmd:
CommandLine|contains|windash: ' -cab '
selection_img:
- Image|endswith: \msdt.exe
- OriginalFileName: msdt.exe
Log Source: category: process_creation
product: windows
Sigma
Troubleshooting Pack Cmdlet Execution
sigma·CVSS 7.8
CVE-2022-30190 [HIGH] Troubleshooting Pack Cmdlet Execution
Troubleshooting Pack Cmdlet Execution
Detects execution of "TroubleshootingPack" cmdlets to leverage CVE-2022-30190 or action similar to "msdt" lolbin (as described in LOLBAS)
Detection:
condition: selection
selection:
ScriptBlockText|contains|all:
- Invoke-TroubleshootingPack
- C:\Windows\Diagnostics\System\PCW
- -AnswerFile
- -Unattended
Log Source: category: ps_script
definition: 'Requirements: Script Block Logging must be enabled'
product: windows
Sigma
Sdiagnhost Calling Suspicious Child Process
sigma·CVSS 7.8
CVE-2022-30190 [HIGH] Sdiagnhost Calling Suspicious Child Process
Sdiagnhost Calling Suspicious Child Process
Detects sdiagnhost.exe calling a suspicious child process (e.g. used in exploits for Follina / CVE-2022-30190)
Detection:
condition: selection and not 1 of filter_main_*
filter_main_cmd_bits:
CommandLine|contains: bits
Image|endswith: \cmd.exe
filter_main_powershell_noprofile:
CommandLine|endswith:
- -noprofile -
- -noprofile
Image|endswith: \powershell.exe
selection:
Image|endswith:
- \powershell.exe
- \pwsh.exe
- \cmd.exe
- \mshta.exe
- \cscript.exe
- \wscript.exe
- \taskkill.exe
- \regsvr32.exe
- \rundll32.exe
- \calc.exe
ParentImage|endswith: \sdiagnhost.exe
Log Source: category: process_creation
product: windows
Sigma
Suspicious MSDT Parent Process
sigma·CVSS 7.8
CVE-2022-30190 [HIGH] Suspicious MSDT Parent Process
Suspicious MSDT Parent Process
Detects msdt.exe executed by a suspicious parent as seen in CVE-2022-30190 / Follina exploitation
Detection:
condition: all of selection_*
selection_msdt:
- Image|endswith: \msdt.exe
- OriginalFileName: msdt.exe
selection_parent:
ParentImage|endswith:
- \cmd.exe
- \cscript.exe
- \mshta.exe
- \powershell.exe
- \pwsh.exe
- \regsvr32.exe
- \rundll32.exe
- \schtasks.exe
- \wmic.exe
- \wscript.exe
- \wsl.exe
Log Source: category: process_creation
product: windows
Sigma
Execute Pcwrun.EXE To Leverage Follina
sigma·CVSS 7.8
CVE-2022-30190 [HIGH] Execute Pcwrun.EXE To Leverage Follina
Execute Pcwrun.EXE To Leverage Follina
Detects indirect command execution via Program Compatibility Assistant "pcwrun.exe" leveraging the follina (CVE-2022-30190) vulnerability
Detection:
condition: selection
selection:
CommandLine|contains: ../
Image|endswith: \pcwrun.exe
Log Source: category: process_creation
product: windows
Tenable
Inside the customer environment: Where threat actors, vulnerabilities, and exposed assets intersect
blogs_tenable·2026-05-27
CVE-2023-4966 Inside the customer environment: Where threat actors, vulnerabilities, and exposed assets intersect
## Exposure Management
## Explore By Use Case
## Explore By Industry
## Tenable is the one clear leader in Exposure Management
## Exposure management
resource center
## Accelerate your exposure management strategy with practical resources and tools.
## Explore By Use Case
## Explore By Industry
## Tenable is the one clear leader in Exposure Management
## Exposure management
resource center
## Accelerate your exposure management strategy with practical resources and tools.
## Inside the customer environment: Where threat actors, vulnerabilities, and exposed assets intersect
Tenable Research has developed a graph-based model linking 600+ threat groups to real-world customer exposures. It reveals which vulnerabilities sit at the intersection of severity, active exploit
Greynoiseio
The Noise in the Silence: Unmasking CISA's Hidden KEV Ransomware Updates
blogs_greynoiseio·2026-02-02
The Noise in the Silence: Unmasking CISA's Hidden KEV Ransomware Updates
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Find out immediately if an asset communicates with a malicious IP address
Vulnerability Prioritization Get real-time insight into active exploitation trends to better understand risk and severity
SOC Efficiency Filter out noisy, low priority and false-positive alerts from mass internet scanners
Incident Investigation Add context to incidents to speed the determinations of scope and timelines
Threat Hunting Quickly identify anomalous behavior and enrich your threat hunting campaigns
Why GreyNoise
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Fin
Wiz
Defending AI Systems Against Prompt Injection Attacks | Wiz
blogs_wiz·2025-12-29
Defending AI Systems Against Prompt Injection Attacks | Wiz
## What is a prompt injection attack?
Prompt injection is an attack where adversaries override or subvert a model’s instructions by placing malicious content in locations the model is likely to trust, often materializing as attacks on direct user input, retrieved web pages, RAG documents, chat history, or file metadata. The result can include instruction overrides, data leakage, or unintended actions through tools or APIs. OWASP lists prompt injection among the top risks to large language model (LLM) applications.
Over 85% of companies use AI, according to our State of AI in the Cloud 2025 report. As developers integrate AI and NLP systems into critical applications, like customer service chatbots and financial trading algorithms, the risk of exploitation increases, especially when the i
Tenable
Frequently Asked Questions About Iranian Cyber Operations
blogs_tenable·2025-06-27
Frequently Asked Questions About Iranian Cyber Operations
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Bleepingcomputer
Microsoft Outlook to block more risky attachments used in attacks
blogs_bleepingcomputer·2025-06-10·CVSS 7.8
[HIGH] Microsoft Outlook to block more risky attachments used in attacks
## Microsoft Outlook to block more risky attachments used in attacks
## Sergiu Gatlan
Microsoft announced it will expand the list of blocked attachments in Outlook Web and the new Outlook for Windows starting next month.
The company said on Monday in a Microsoft 365 Message Center update that Outlook will block .library-ms and .search-ms file types beginning in July.
"As part of our ongoing efforts to enhance security in Outlook Web and the New Outlook for Windows, we're updating the default list of blocked file types in OwaMailboxPolicy," Microsoft said . "Starting in early July 2025, the [.library-ms and .search-ms] file types will be added to the BlockedFileTypes list."
Windows Library files (.library-ms), which define virtual collections of folders and files in the Windows file sy
Greynoiseio
GreyNoise Detects Active Exploitation of CVEs Mentioned in Black Basta’s Leaked Chat Logs
blogs_greynoiseio·2025-02-26·CVSS 9.8
[CRITICAL] GreyNoise Detects Active Exploitation of CVEs Mentioned in Black Basta’s Leaked Chat Logs
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Find out immediately if an asset communicates with a malicious IP address
Vulnerability Prioritization Get real-time insight into active exploitation trends to better understand risk and severity
SOC Efficiency Filter out noisy, low priority and false-positive alerts from mass internet scanners
Incident Investigation Add context to incidents to speed the determinations of scope and timelines
Threat Hunting Quickly identify anomalous behavior and enrich your threat hunting campaigns
Why GreyNoise
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Fin
Qualys
Defense Lessons From the Black Basta Ransomware Playbook
blogs_qualys·2025-02-25
Defense Lessons From the Black Basta Ransomware Playbook
## Table of Contents
Know Your Enemys Playbook
Attackers Move Fast
How Qualys Can Help
The cybersecurity world was rocked last week by a massive leak of Black Basta’s internal communications that emerged from the group’s chat logs. Triggered by internal conflicts and a retaliatory data dump following attacks on Russian banks, the exposed records offer a rare glimpse into Black Basta’s tactics, operations, and leadership.
We’ve analyzed these newly unveiled tactics, and in this blog, we equip security teams with clear, actionable insights. We aim to highlight the key lessons learned—like immediate patching, tighter access controls, and rapid incident response—and provide an urgent call to action. This practical guide aims to help organizations strengthen their defenses against evolving
Qualys
Defense Lessons From the Black Basta Ransomware Playbook | Qualys
blogs_qualys·2025-02-25
Defense Lessons From the Black Basta Ransomware Playbook | Qualys
#### Table of Contents
- Know Your Enemys Playbook
- Attackers Move Fast
- How Qualys Can Help
The cybersecurity world was rocked last week by a massive leak of Black Basta’s internal communications that emerged from the group’s chat logs. Triggered by internal conflicts and a retaliatory data dump following attacks on Russian banks, the exposed records offer a rare glimpse into Black Basta’s tactics, operations, and leadership.
We’ve analyzed these newly unveiled tactics, and in this blog, we equip security teams with clear, actionable insights. We aim to highlight the key lessons learned—like immediate patching, tighter access controls, and rapid incident response—and provide an urgent call to action. This practical guide aims to help organizations strengthen their defenses against ev
Tenable
From Bugs to Breaches: 25 Significant CVEs As MITRE CVE Turns 25
blogs_tenable·2024-10-22
From Bugs to Breaches: 25 Significant CVEs As MITRE CVE Turns 25
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Securelist
Exploits and vulnerabilities in Q2 2024
blogs_securelist·2024-08-21·CVSS 7.8
CVE-2024-26169 [HIGH] Exploits and vulnerabilities in Q2 2024
Table of Contents
Statistics on registered vulnerabilities
Vulnerability exploitation statistics
Windows and Linux vulnerability exploitation
Most common exploits
Vulnerability exploitation in APT attacks
Exploiting vulnerable drivers to attack operating systems
BYOVD attack tools
Interesting vulnerabilities
CVE-2024-26169 (WerKernel.sys)
CVE-2024-26229 (csc.sys)
CVE-2024-4577 (PHP CGI)
Takeaways and recommendations
Authors
Vitaly Morgunov
Alexander Kolesnikov
Q2 2024 was eventful in terms of new interesting vulnerabilities and exploitation techniques for applications and operating systems. Attacks through vulnerable drivers have become prevalent as a general means of privilege escalation in the operating system. Such attacks are notable in that the vulnerability does not h
Securelist
Analyzing the vulnerability landscape in Q2 2024
blogs_securelist·2024-08-21·CVSS 7.8
CVE-2024-26169 [HIGH] Analyzing the vulnerability landscape in Q2 2024
Table of Contents
- Statistics on registered vulnerabilities
- Vulnerability exploitation statistics
- Vulnerability exploitation in APT attacks
- Exploiting vulnerable drivers to attack operating systems
- Interesting vulnerabilities
- CVE-2024-26169 (WerKernel.sys)
- CVE-2024-26229 (csc.sys)
- CVE-2024-4577 (PHP CGI)
- Takeaways and recommendations
Authors
- Vitaly Morgunov
- Alexander Kolesnikov
Q2 2024 was eventful in terms of new interesting vulnerabilities and exploitation techniques for applications and operating systems. Attacks through vulnerable drivers have become prevalent as a general means of privilege escalation in the operating system. Such attacks are notable in that the vulnerability does not have to be fresh, since attackers themselves deliver unpatched drivers to t
Bleepingcomputer
OpenAI blocks state-sponsored hackers from using ChatGPT
blogs_bleepingcomputer·2024-02-15·CVSS 7.8
[HIGH] OpenAI blocks state-sponsored hackers from using ChatGPT
## OpenAI blocks state-sponsored hackers from using ChatGPT
## Bill Toulas
Activity associated with the following threat groups was terminated on the platform:
Forest Blizzard (Strontium) [ Russia ]: Utilized ChatGPT to conduct research into satellite and radar technologies pertinent to military operations and to optimize its cyber operations with scripting enhancements.
Emerald Sleet (Thallium) [ North Korea ]: Leveraged ChatGPT for researching North Korea and generating spear-phishing content, alongside understanding vulnerabilities (like CVE-2022-30190 "Follina") and troubleshooting web technologies.
Crimson Sandstorm (Curium) [ Iran ]: Engaged with ChatGPT for social engineering assistance, error troubleshooting, .NET development, and developing evasion techniques.
Charcoal Typho
Bleepingcomputer
France says Russian state hackers breached numerous critical networks
blogs_bleepingcomputer·2023-10-26·CVSS 9.8
CVE-2023-38831 [CRITICAL] France says Russian state hackers breached numerous critical networks
## France says Russian state hackers breached numerous critical networks
## Bill Toulas
The Russian APT28 hacking group (aka 'Strontium' or 'Fancy Bear') has been targeting government entities, businesses, universities, research institutes, and think tanks in France since the second half of 2021.
The threat group, which is considered part of Russia's military intelligence service GRU, was recently linked to the exploitation of CVE-2023-38831 , a remote code execution vulnerability in WinRAR, and CVE-2023-23397 , a zero-day privilege elevation flaw in Microsoft Outlook.
The Russian hackers have been compromising peripheral devices on critical networks of French organizations and moving away from utilizing backdoors to evade detection.
This is according to a newly published report from
Qualys
Qualys Tackles 2022’s Top Routinely Exploited Cyber Vulnerabilities | Qualys
blogs_qualys·2023-08-24
Qualys Tackles 2022’s Top Routinely Exploited Cyber Vulnerabilities | Qualys
#### Table of Contents
- References
- Additional Contributor
A unified front against malicious cyber actors is climactic in the ever-evolving cybersecurity landscape. The joint Cybersecurity Advisory (CSA), a collaboration between leading cybersecurity agencies from the United States, Canada, United Kingdom, Australia, and New Zealand, is a critical guide to strengthen global cyber resilience. The agencies involved include the U.S.’s CISA, NSA, and FBI; Canada’s CCCS; U.K.’s NCSC-UK; Australia’s ACSC; and New Zealand’s NCSC-NZ and CERT NZ.
This collaboration among key cybersecurity agencies highlights the global nature of cybersecurity threats. Such cooperative efforts signify a unified perspective and highlight the need for shared intelligence and coordinated strategies. The realizatio
Qualys
Qualys Tackles 2022’s Top Routinely Exploited Cyber Vulnerabilities
blogs_qualys·2023-08-24
Qualys Tackles 2022’s Top Routinely Exploited Cyber Vulnerabilities
## Table of Contents
References
Additional Contributor
A unified front against malicious cyber actors is climactic in the ever-evolving cybersecurity landscape. The joint Cybersecurity Advisory (CSA), a collaboration between leading cybersecurity agencies from the United States, Canada, United Kingdom, Australia, and New Zealand, is a critical guide to strengthen global cyber resilience. The agencies involved include the U.S.’s CISA, NSA, and FBI; Canada’s CCCS; U.K.’s NCSC-UK; Australia’s ACSC; and New Zealand’s NCSC-NZ and CERT NZ.
This collaboration among key cybersecurity agencies highlights the global nature of cybersecurity threats. Such cooperative efforts signify a unified perspective and highlight the need for shared intelligence and coordinated strategies. The realization tha
Sentinelone
Enterprise Security Essentials | Top 12 Most Routinely Exploited Vulnerabilities
blogs_sentinelone·2023-08-08·CVSS 9.1
[CRITICAL] Enterprise Security Essentials | Top 12 Most Routinely Exploited Vulnerabilities
Leveraging known bugs and unpatched exploits continue to be an unyielding strategy for threat actors. Ranging from security bypasses and credential exposure to remote code execution, software vulnerabilities remain tools of the trade for cyber attackers looking for a way into lucrative systems.
While new flaws found in Active Directory and the MOVEit file transfer application along with those used in the AlienFox toolkit or recent IceFire ransomware campaigns have wreaked havoc this year, a number of existing vulnerabilities stand out from the rest in terms of how often they are abused to this day.
In this post, we delve into CISA’s latest round-up, which lists the top 12 most routinely exploited vulnerabilities of 2022 that continue to pose significant threats to enterprise businesses.
Sentinelone
Enterprise Security Essentials | Top 12 Most Routinely Exploited Vulnerabilities
blogs_sentinelone·2023-08-08·CVSS 9.1
[CRITICAL] Enterprise Security Essentials | Top 12 Most Routinely Exploited Vulnerabilities
Leveraging known bugs and unpatched exploits continue to be an unyielding strategy for threat actors. Ranging from security bypasses and credential exposure to remote code execution, software vulnerabilities remain tools of the trade for cyber attackers looking for a way into lucrative systems.
While new flaws found in Active Directory and the MOVEit file transfer application along with those used in the AlienFox toolkit or recent IceFire ransomware campaigns have wreaked havoc this year, a number of existing vulnerabilities stand out from the rest in terms of how often they are abused to this day.
In this post, we delve into CISA’s latest round-up, which lists the top 12 most routinely exploited vulnerabilities of 2022 that continue to pose significant threats to enterprise businesses.
Tenable
AA23-215A: 2022's Top Routinely Exploited Vulnerabilities
blogs_tenable·2023-08-03
AA23-215A: 2022's Top Routinely Exploited Vulnerabilities
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Fortinet
LokiBot Campaign Targets Microsoft Office Document Using Vulnerabilities and Macros | FortiGuard Labs
blogs_fortinet·2023-07-12·CVSS 8.8
CVE-2021-40444 [HIGH] LokiBot Campaign Targets Microsoft Office Document Using Vulnerabilities and Macros | FortiGuard Labs
FORTIGUARD LABS THREAT RESEARCH
LokiBot Campaign Targets Microsoft Office Document Using Vulnerabilities and Macros
By Cara Lin | July 12, 2023
Affected platforms: Microsoft Windows
Impacted parties: Windows users
Impact: Control and collect sensitive information from a victim’s device
Severity level: Critical
In a recent FortiGuard Labs investigation, we came across several malicious Microsoft Office documents designed to exploit known vulnerabilities. Specifically, CVE-2021-40444 and CVE-2022-30190 are remote code execution vulnerabilities. Exploiting these vulnerabilities allowed the attackers to embed malicious macros within Microsoft documents that, when executed, dropped the LokiBot malware onto the victim's system. LokiBot, also known as Loki PWS, has been a well-known informati
Fortinet
Ransomware Roundup - Black Basta | FortiGuard Labs
blogs_fortinet·2023-06-23
Ransomware Roundup - Black Basta | FortiGuard Labs
FORTIGUARD LABS THREAT RESEARCH
Ransomware Roundup - Black Basta
By James Slaughter and Shunichi Imano | June 23, 2023
On a bi-weekly basis, FortiGuard Labs gathers data on ransomware variants of interest that have been gaining traction within our datasets and the OSINT community. The Ransomware Roundup report aims to provide readers with brief insights into the evolving ransomware landscape and the Fortinet solutions that protect against those variants.
This latest edition of the Ransomware Roundup covers the Black Basta ransomware.
Affected platforms: Microsoft Windows, VMWare ESXi servers
Impacted parties: Microsoft Windows and ESXi Users
Impact: Encrypts files on the compromised machine and demands ransom for file decryption
Severity level: High
Black Basta Ransomware Overview
Ov
Qualys
Launching Qualys Cloud Threat Database
blogs_qualys·2023-02-08
Launching Qualys Cloud Threat Database
## Table of Contents
The Qualys Cloud Threat Database
Powered By Machine Learning
More Information
We are proud to announce the release of the Qualys Cloud Threat Database which correlates more than 25 different threat intelligence feeds into a single source for all Qualys products to leverage. This comprehensive vulnerability and threat intelligence database pulls from trusted sources such as the CISA Known Exploited Vulnerability Catalog, MITRE ATT&CK Framework, and many other feeds. Combined with the power of machine learning models, this enables products such as Qualys VMDR to provide rich context to the vulnerabilities detected in your environment.
In 2022 more than 25,000 vulnerabilities were published by the National Vulnerability Database (NVD). While at first glance, this see
Qualys
Launching Qualys Cloud Threat Database | Qualys
blogs_qualys·2023-02-08
Launching Qualys Cloud Threat Database | Qualys
#### Table of Contents
- The Qualys Cloud Threat Database
- Powered By Machine Learning
- More Information
We are proud to announce the release of the Qualys Cloud Threat Database which correlates more than 25 different threat intelligence feeds into a single source for all Qualys products to leverage. This comprehensive vulnerability and threat intelligence database pulls from trusted sources such as the CISA Known Exploited Vulnerability Catalog, MITRE ATT&CK Framework, and many other feeds. Combined with the power of machine learning models, this enables products such as Qualys VMDR to provide rich context to the vulnerabilities detected in your environment.
In 2022 more than 25,000 vulnerabilities were published by the National Vulnerability Database (NVD). While at first glance, th
Tenable
Sandworm APT Deploys New SwiftSlicer Wiper Using Active Directory Group Policy
blogs_tenable·2023-01-27
Sandworm APT Deploys New SwiftSlicer Wiper Using Active Directory Group Policy
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Elastic
Vulnerability summary: Follina, CVE-2022-30190 — Elastic Security Labs
blogs_elastic·2023-01-19·CVSS 7.8
CVE-2022-30190 [HIGH] Vulnerability summary: Follina, CVE-2022-30190 — Elastic Security Labs
## Vulnerability summary: Follina, CVE-2022-30190
Elastic is deploying a new malware signature to identify the use of the Follina vulnerability. Learn more in this post.
On May 27, 2022, the nao_sec independent security research group shared a VirusTotal link to a weaponized Microsoft Office document revealing a previously unknown vulnerability in the Microsoft Support Diagnostic Tool (MSDT). This vulnerability is most likely to be exploited via phishing lure attachments and is triggered when a document is opened. Readers should expect this vulnerability to be adopted by threats of all kinds and be aware that it enables arbitrary code to be executed as outlined in Microsoft’s disclosure .
## Summary
Readers may recall that template injection is an established technique enabling an atta
Elastic
Vulnerability summary: Follina, CVE-2022-30190 — Elastic Security Labs
blogs_elastic·2023-01-19·CVSS 7.8
CVE-2022-30190 [HIGH] Vulnerability summary: Follina, CVE-2022-30190 — Elastic Security Labs
19 January 2023•Devon Kerr
# Vulnerability summary: Follina, CVE-2022-30190
Elastic is deploying a new malware signature to identify the use of the Follina vulnerability. Learn more in this post.
2 min readProduct Updates, Enablement
On May 27, 2022, the nao_sec independent security research group shared a VirusTotal link to a weaponized Microsoft Office document revealing a previously unknown vulnerability in the Microsoft Support Diagnostic Tool (MSDT). This vulnerability is most likely to be exploited via phishing lure attachments and is triggered when a document is opened. Readers should expect this vulnerability to be adopted by threats of all kinds and be aware that it enables arbitrary code to be executed as outlined in Microsoft’s disclosure.
## Summary
Readers may recall tha
Tenable
2022 Threat Landscape Report
blogs_tenable·2022-12-27
2022 Threat Landscape Report
by Josef Weiss December 27, 2022
2022 began with concerns over supply chains and Software Bills of Material (SBOM) as organizations worldwide were forced to reconsider how they respond to incidents in anticipation of the next major event. Tenable’s Security Response Team (SRT) continuously monitors the threat landscape throughout the year, always at the forefront of trending vulnerabilities and security threats. This dashboard provides a summary of Tenable data that has been compiled over the past year.
In a year marked by hacktivism, ransomware and attacks targeting critical infrastructure set against a turbulent macroeconomic environment, organizations struggled to keep pace with the demands on cybersecurity teams and resources. Attacks against critical infrastructure remained a common
Tenable
2022 Threat Landscape Report
blogs_tenable·2022-12-21
2022 Threat Landscape Report
by Josef Weiss December 21, 2022
2022 began with concerns over supply chains and Software Bills of Material (SBOM) as organizations worldwide were forced to reconsider how they respond to incidents in anticipation of the next major event. Tenable’s Security Response Team (SRT) continuously monitors the threat landscape throughout the year, always at the forefront of trending vulnerabilities and security threats. This dashboard provides a summary of Tenable data that has been compiled over the past year.
In a year marked by hacktivism, ransomware and attacks targeting critical infrastructure in a turbulent macroeconomic environment, organizations struggled to keep pace with the demands on cybersecurity teams and resources. Attacks against critical infrastructure remained a common concern.
Sentinelone
Black Basta
blogs_sentinelone·2022-11-30
Black Basta
How It Works The Singularity XDR Difference
Singularity Marketplace One-Click Integrations to Unlock the Power of XDR
Pricing & Packaging Comparisons and Guidance at a Glance
Purple AI Accelerate SecOps with Generative AI
Singularity Hyperautomation Easily Automate Security Processes
AI-SIEM The AI SIEM for the Autonomous SOC
Singularity Data Lake AI-Powered, Unified Data Lake
Singularity Data Lake for Log Analytics Seamlessly Ingest Data from On-Prem, Cloud or Hybrid Environments
Singularity Endpoint Autonomous Prevention, Detection, and Response
Singularity XDR Native & Open Protection, Detection, and Response
Singularity RemoteOps Forensics Orchestrate Forensics at Scale
Singularity
Threat Intelligence Comprehensive Adversary Intelligence
Singularity Vulnerability Management
Securelist
IT threat evolution in Q3 2022. Non-mobile statistics
blogs_securelist·2022-11-18
IT threat evolution in Q3 2022. Non-mobile statistics
Table of Contents
Quarterly figures
Financial threats
Number of users attacked by banking malware
TOP 10 banking malware families
Geography of financial malware attacks
Ransomware programs
Quarterly trends and highlights
Number of new modifications
Number of users attacked by ransomware Trojans
Geography of attacked users
TOP 10 most common families of ransomware Trojans
Miners
Number of new miner modifications
Number of users attacked by miners
Geography of miner attacks
Vulnerable applications used by criminals during cyberattacks
Quarterly highlights
Vulnerability statistics
Attacks on macOS
TOP 20 threats for macOS
Geography of threats for macOS
IoT attacks
IoT threat statistics
Attacks via web resources
Countries and territories that serve as sources of web-ba
Securelist
PC malware statistics, Q3 2022
blogs_securelist·2022-11-18
PC malware statistics, Q3 2022
Table of Contents
- Quarterly figures
- Financial threats
- Ransomware programs
- Miners
- Vulnerable applications used by criminals during cyberattacks
- Attacks on macOS
- IoT attacks
- Attacks via web resources
- Local threats
Authors
- AMR
- IT threat evolution in Q3 2022
- IT threat evolution in Q3 2022. Non-mobile statistics
- IT threat evolution in Q3 2022. Mobile statistics
These statistics are based on detection verdicts of Kaspersky products and services received from users who consented to providing statistical data.
## Quarterly figures
According to Kaspersky Security Network, in Q3 2022:
- Kaspersky solutions blocked 956,074,958 attacks from online resources across the globe.
- Web Anti-Virus recognized 251,288,987 unique URLs as malicious.
- Attempts to run malware fo
Sentinelone
Black Basta Ransomware | Attacks Deploy Custom EDR Evasion Tools Tied to FIN7 Threat Actor
blogs_sentinelone·2022-11-03
Black Basta Ransomware | Attacks Deploy Custom EDR Evasion Tools Tied to FIN7 Threat Actor
## Black Basta Ransomware | Attacks Deploy Custom EDR Evasion Tools Tied to FIN7 Threat Actor
By Antonio Cocomazzi and Antonio Pirozzi
## Executive Summary
SentinelLABS researchers describe Black Basta operational TTPs in full detail, revealing previously unknown tools and techniques.
SentinelLABS assesses it is highly likely the Black Basta ransomware operation has ties with FIN7.
Black Basta maintains and deploys custom tools, including EDR evasion tools.
SentinelLABS assess it is likely the developer of these EDR evasion tools is, or was, a developer for FIN7.
Black Basta attacks use a uniquely obfuscated version of ADFind and exploit PrintNightmare, ZeroLogon and NoPac for privilege escalation.
## Overview
Black Basta ransomware emerged in April 2022 and went on a spree breach
Sentinelone
Black Basta Ransomware | Attacks Deploy Custom EDR Evasion Tools Tied to FIN7 Threat Actor
blogs_sentinelone·2022-11-03
Black Basta Ransomware | Attacks Deploy Custom EDR Evasion Tools Tied to FIN7 Threat Actor
By Antonio Cocomazzi and Antonio Pirozzi
## Executive Summary
- SentinelLABS researchers describe Black Basta operational TTPs in full detail, revealing previously unknown tools and techniques.
- SentinelLABS assesses it is highly likely the Black Basta ransomware operation has ties with FIN7.
- Black Basta maintains and deploys custom tools, including EDR evasion tools.
- SentinelLABS assess it is likely the developer of these EDR evasion tools is, or was, a developer for FIN7.
- Black Basta attacks use a uniquely obfuscated version of ADFind and exploit PrintNightmare, ZeroLogon and NoPac for privilege escalation.
## Overview
Black Basta ransomware emerged in April 2022 and went on a spree breaching over 90 organizations by Sept 2022. The rapidity and volume of attacks prove that the
Dfir Report
Follina Exploit Leads to Domain Compromise
blogs_dfir_report·2022-10-31·CVSS 7.8
[HIGH] Follina Exploit Leads to Domain Compromise
From a Single Click: How Lunar Spider Enabled a Near Two-Month Intrusion Read More
- dragonforce Blurring the Lines: Intrusion Shows Connection With Three Major Ransomware Gangs Read More
Services Overview
Threat Hunting
-
Integration
CTI Program Advisory
Incident Response Playbook
About us
Contact Us
Collaboration
Careers
Analysts
Access DFIR Labs
Get in Touch
Public Reports
Products Overview
Threat intel Overview
Threat Feed
Private DFIR Reports
All Intel
Active Defense
DFIR Labs
Case Artifacts
Detection Pack
AI Training Ground
Service Overview
Threat Hunting
Integration
CTI Program Advisory
Incident Response Playbook
Company Overview
About us
Contact Us
Careers
Analyst
SQL Brute Force Leads to BlueSky Ransomware
From OneNote to RansomNote: An Ice Col
Trendmicro
Where is the Origin QAKBOT Uses Valid Code Signing
blogs_trendmicro·2022-10-27·CVSS 7.8
[HIGH] Where is the Origin QAKBOT Uses Valid Code Signing
Malware
## Where is the Origin?: QAKBOT Uses Valid Code Signing
Code signing certificates help us assure the file's validity and legitimacy. However, threat actors can use that against us. In this blog, discover how QAKBOT use such tactic and learn ways how to prevent it.
By: Hitomi Kimura 2022/10/27 Read time: ( words)
Save to Folio
A threat actor, QAKBOT, along with EMOTET, has been one of the most active threat actors over the past few years, with numerous reports regarding its actions since it was first observed in 2007. We have reported some of them in the past, however, there are two things that come to mind regarding this threat. Namely, how Black Basta ransomware operators have used QAKBOT as a means of entry , and how they used the vulnerability, CVE-2022-30190, called Follin
Trendmicro
Where is the Origin QAKBOT Uses Valid Code Signing
blogs_trendmicro·2022-10-27·CVSS 7.8
[HIGH] Where is the Origin QAKBOT Uses Valid Code Signing
Malware
## Where is the Origin?: QAKBOT Uses Valid Code Signing
Code signing certificates help us assure the file's validity and legitimacy. However, threat actors can use that against us. In this blog, discover how QAKBOT use such tactic and learn ways how to prevent it.
By: Hitomi Kimura Oct 27, 2022 Read time: ( words)
Save to Folio
A threat actor, QAKBOT, along with EMOTET, has been one of the most active threat actors over the past few years, with numerous reports regarding its actions since it was first observed in 2007. We have reported some of them in the past, however, there are two things that come to mind regarding this threat. Namely, how Black Basta ransomware operators have used QAKBOT as a means of entry , and how they used the vulnerability, CVE-2022-30190, called Foll
Trendmicro
Where is the Origin QAKBOT Uses Valid Code Signing
blogs_trendmicro·2022-10-27·CVSS 7.8
[HIGH] Where is the Origin QAKBOT Uses Valid Code Signing
Malware
# Where is the Origin?: QAKBOT Uses Valid Code Signing
Code signing certificates help us assure the file's validity and legitimacy. However, threat actors can use that against us. In this blog, discover how QAKBOT use such tactic and learn ways how to prevent it.
By: Hitomi Kimura
2022/10/27
Read time: ( words)
Save to Folio
A threat actor, QAKBOT, along with EMOTET, has been one of the most active threat actors over the past few years, with numerous reports regarding its actions since it was first observed in 2007. We have reported some of them in the past, however, there are two things that come to mind regarding this threat. Namely, how Black Basta ransomware operators have used QAKBOT as a means of entry, and how they used the vulnerability, CVE-2022-30190, called Follina
Qualys
In-Depth Look Into Data-Driven Science Behind Qualys TruRisk
blogs_qualys·2022-10-10
In-Depth Look Into Data-Driven Science Behind Qualys TruRisk
## Table of Contents
Key Takeaways
Vulnerabilities Are on the Rise
Vulnerability Threat Landscape
Challenges With CVSS Based Prioritization
Exploit Prediction Scoring System
Qualys Severity Levels
Qualys TruRisk, a Data-Driven Way To Prioritize Risks
CVSS Base Score
CISA Known Exploited Vulnerability (KEV)
Real-Time Threat Indicators (RTIs)
Exploit Code Maturity
Malware
Threat Actors / Ransomware Groups
Trending Risk
Applied Mitigation Controls
EPSS Score (from First.org)
How Does Qualys TruRisk Compare Against CVSS and EPSS?
Qualys Vulnerability Score (QVS) vs CVSS
Qualys TruRisk vs EPSS
Qualys TruRisk (QVS) vs CISA KEV
How to Interpret Qualys TruRisk Scores
Asset Risk Score (ARS)
Asset Risk Score Formula
Conclusion
Additional Contributors
Vulnerability Managemen
Fortinet
Ransomware Roundup - Bisamware and Chile Locker | Fortinet Blog
blogs_fortinet·2022-09-29·CVSS 7.8
[HIGH] Ransomware Roundup - Bisamware and Chile Locker | Fortinet Blog
FORTIGUARD LABS THREAT RESEARCH
Ransomware Roundup - Bisamware and Chile Locker
By Shunichi Imano and James Slaughter | September 29, 2022
On a bi-weekly basis, FortiGuard Labs gathers data on ransomware variants of interest that have been gaining traction within the OSINT community and our datasets. The Ransomware Roundup report aims to provide readers with brief insights into the evolving ransomware landscape and the Fortinet solutions that protect against those variants.
This latest edition of the Ransomware Roundup covers the Bisamware and Chile Locker ransomware.
Affected platforms: Microsoft Windows
Impacted parties: Microsoft Windows Users
Impact: Encrypts files on the compromised machine and demands ransom for file decryption
Severity level: High
Bisamware Ransomware
Bisamwa
Qualys
Mitigating the Risk of Zero-Day Vulnerabilities by using Compensating Controls
blogs_qualys·2022-08-23
Mitigating the Risk of Zero-Day Vulnerabilities by using Compensating Controls
## Table of Contents
Why Are Zero-Day Attacks/Exploits so Dangerous?
How Qualys Policy Compliance Helps Combat Zero-Day Threats
Benefit of Qualys Policy Compliance for Zero-Day Threats
Summary
Getting Started
Contributors
Zero-day vulnerability attacks have emerged as a major cybersecurity threat in the last few years. Organizations most often targeted include large enterprises and government/Federal agencies. However, any organization, regardless of its size, business, or industry, is a potential target for zero-day threats.
Most notably, already publicly disclosed. This means that one out of every four zero-day exploits detected could potentially have been avoided if a more thorough investigation and patching effort had been pursued. In 2021, around 58 zero-day vulnerabilities we
Tenable
Cybersecurity Snapshot: 6 Things That Matter Right Now
blogs_tenable·2022-08-19
Cybersecurity Snapshot: 6 Things That Matter Right Now
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Fortinet
Ransomware Roundup - Gwisin, Kriptor, Cuba, and More | FortiGuard Labs
blogs_fortinet·2022-08-18
Ransomware Roundup - Gwisin, Kriptor, Cuba, and More | FortiGuard Labs
FORTIGUARD LABS THREAT RESEARCH
Ransomware Roundup - Gwisin, Kriptor, Cuba, and More
By Shunichi Imano and James Slaughter | August 18, 2022
On a bi-weekly basis, FortiGuard Labs gathers data on ransomware variants of interest that have been gaining traction within the OSINT community and within our datasets. The Ransomware Roundup report aims to provide readers with brief insights into the evolving ransomware landscape and the Fortinet solutions that protect against those variants.
This latest edition of the Ransomware Roundup covers the DarkyLock, Gwisin, vvyu, Kriptor, and Cuba ransomware families.
Affected platforms: Microsoft Windows
Impacted parties: Microsoft Windows Users
Impact: Encrypts files on the compromised machine and demands ransom for file decryption
Severity level: Hi
Securelist
IT threat evolution in Q2 2022. Non-mobile statistics
blogs_securelist·2022-08-15
IT threat evolution in Q2 2022. Non-mobile statistics
Table of Contents
Quarterly figures
Financial threats
Financial threat statistics
Ransomware programs
Quarterly trends and highlights
Number of new modifications
Number of users attacked by ransomware Trojans
Geography of attacked users
TOP 10 most common families of ransomware Trojans
Miners
Number of new miner modifications
Number of users attacked by miners
Geography of miner attacks
Vulnerable applications used by criminals during cyberattacks
Quarterly highlights
Vulnerability statistics
Attacks on macOS
Geography of threats for macOS
IoT attacks
IoT threat statistics
Attacks via web resources
TOP 10 countries and territories that serve as sources of web-based attacks
Countries and territories where users faced the greatest risk of online infection
Local threat
Securelist
Non-mobile malware statistics, Q2 2022
blogs_securelist·2022-08-15
Non-mobile malware statistics, Q2 2022
Table of Contents
- Quarterly figures
- Financial threats
- Ransomware programs
- Miners
- Vulnerable applications used by criminals during cyberattacks
- Attacks on macOS
- IoT attacks
- Attacks via web resources
- Local threats
Authors
- AMR
- IT threat evolution in Q2 2022
- IT threat evolution in Q2 2022. Non-mobile statistics
- IT threat evolution in Q2 2022. Mobile statistics
These statistics are based on detection verdicts of Kaspersky products and services received from users who consented to providing statistical data.
## Quarterly figures
According to Kaspersky Security Network, in Q2 2022:
- Kaspersky solutions blocked 1,164,544,060 attacks from online resources across the globe.
- Web Anti-Virus recognized 273,033,368 unique URLs as malicious. Attempts to run malware fo
Securelist
IT threat evolution Q2 2022
blogs_securelist·2022-08-15
IT threat evolution Q2 2022
Table of Contents
- Targeted attacks
- Other malware
Authors
- David Emm
- IT threat evolution in Q2 2022
- IT threat evolution in Q2 2022. Non-mobile statistics
- IT threat evolution in Q2 2022. Mobile statistics
## Targeted attacks
### New technique for installing fileless malware
Earlier this year, we discovered a malicious campaign that employed a new technique for installing fileless malware on target machines by injecting a shellcode directly into Windows event logs. The attackers were using this to hide a last-stage Trojan in the file system.
The attack starts by driving targets to a legitimate website and tricking them into downloading a compressed RAR file that is booby-trapped with the network penetration testing tools Cobalt Strike and SilentBreak. The attackers use thes
Securelist
IT threat evolution Q2 2022
blogs_securelist·2022-08-15
IT threat evolution Q2 2022
Table of Contents
Targeted attacks
New technique for installing fileless malware
WinDealer’s man-on-the-side spyware
ToddyCat: previously unknown threat actor attacks high-profile organizations in Europe and Asia
SessionManager IIS backdoor
Other malware
Spring4Shell
Actively exploited vulnerability in Windows
Follina vulnerability in MSDT
BlackCat: a new ransomware gang
Yanluowang ransomware: how to recover encrypted files
Ransomware TTPs
Ransomware trends in 2022
Emotet’s return
Mobile subscription Trojans
The threat from stalkerware
Authors
David Emm
IT threat evolution in Q2 2022
IT threat evolution in Q2 2022. Non-mobile statistics
IT threat evolution in Q2 2022. Mobile statistics
## Targeted attacks
## New technique for installing fileless malware
Earlier this
Tenable
Microsoft’s August 2022 Patch Tuesday Addresses 118 CVEs (CVE-2022-34713)
blogs_tenable·2022-08-09·CVSS 7.8
[HIGH] Microsoft’s August 2022 Patch Tuesday Addresses 118 CVEs (CVE-2022-34713)
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Fortinet
Life After Death—SmokeLoader Continues to Haunt Using Old Vulnerabilities
blogs_fortinet·2022-08-09·CVSS 7.8
[HIGH] Life After Death—SmokeLoader Continues to Haunt Using Old Vulnerabilities
FORTIGUARD LABS THREAT RESEARCH
Life After Death—SmokeLoader Continues to Haunt Using Old Vulnerabilities
By James Slaughter | August 09, 2022
Vulnerability management and remediation are some of the most difficult problems to tackle within an organization. Multiple solutions, watchlists, and warnings are designed to ensure that companies and end users patch their software against known security vulnerabilities.
Unfortunately, even with tools available and teams forewarned with up-to-date information, this often does not happen in a timely manner or even at all. This is usually due to outdated software, overworked teams, or even negligence or incompetence—and threat actors know this. Patching is often mundane and tedious work. Organizations that are either late, inconsistent, or sloppy
Fortinet
Ransomware Roundup: Redeemer, Beamed, and More | FortiGuard Labs
blogs_fortinet·2022-08-04
Ransomware Roundup: Redeemer, Beamed, and More | FortiGuard Labs
FORTIGUARD LABS THREAT RESEARCH
Ransomware Roundup: Redeemer, Beamed, and More
By Shunichi Imano and James Slaughter | August 04, 2022
Over the past few weeks, FortiGuard Labs has observed several new ransomware variants of interest that have been gaining traction within the OSINT community, along with activity from our datasets. This isn’t a new phenomenon. This is part of a pattern of behavior that dates back several years—a pattern that is likely to continue for some time to come.
Ransomware infections continue to have a significant impact on organizations, including—but not limited to—disruptions to operations, theft of confidential information, monetary loss due to ransom payout, and more. It’s why we feel it's imperative that we increase our efforts to raise awareness about existi
Fortinet
A Journey to Network Protocol Fuzzing – Dissecting Microsoft IMAP Client Protocol | FortiGuard Labs
blogs_fortinet·2022-08-04
A Journey to Network Protocol Fuzzing – Dissecting Microsoft IMAP Client Protocol | FortiGuard Labs
FORTIGUARD LABS THREAT RESEARCH
A Journey to Network Protocol Fuzzing – Dissecting Microsoft IMAP Client Protocol
By Wayne Chin Yick Low | August 04, 2022
In networking, a protocol is a set of rules that defines standard formats and processes for interpreting raw data sent by computers. Network protocols are like a common language for computers. The computers within a network may use vastly different software and hardware; however, protocols enable them to communicate with each other regardless.
Many network protocols on the Internet serve different purposes, some of which can be complex and sophisticated. Because of their inherent complexity, security vulnerabilities in network applications are inevitable. Security holes in network applications often yield a more significant security i
Tenable
Analyzing the Vulnerabilities Associated with the Top Malware Strains of 2021
blogs_tenable·2022-08-04
Analyzing the Vulnerabilities Associated with the Top Malware Strains of 2021
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Fortinet
Fileless Malware: What It Is and How It Works | Fortinet Blog
blogs_fortinet·2022-08-01
Fileless Malware: What It Is and How It Works | Fortinet Blog
INDUSTRY TRENDS & INSIGHTS
Fileless Malware: What It Is and How It Works
By Aamir Lakhani | August 01, 2022
Fileless malware uses a computer system’s built-in tools to execute a cyberattack. In other words, fileless malware takes advantage of the vulnerabilities present in installed software to facilitate an attack. This type of malware does not require the attacker to sneak malicious code onto a potential victim’s system’s hard drive to be successful. Therefore, fileless malware can be extremely hard to detect—and extremely dangerous.
This blog will outline the basics of what fileless malware is along with the stages of an attack, the common techniques used by cybercriminals employing fileless malware, and tips for detecting these types of threats.
What is Fileless Malware?
Fileless
Fortinet
FortiGuard Labs Discovers Three Vulnerabilities in Siemens’ Teamcenter Solutions | FortiGuard Labs
blogs_fortinet·2022-07-19·CVSS 7.8
CVE-2022-28807 [HIGH] FortiGuard Labs Discovers Three Vulnerabilities in Siemens’ Teamcenter Solutions | FortiGuard Labs
FORTIGUARD LABS THREAT RESEARCH
FortiGuard Labs Discovers Three Vulnerabilities in Siemens’ Teamcenter Solutions
By Yonghui Han | July 19, 2022
In early 2022, I discovered and reported three zero-day vulnerabilities in Siemens JT2Go and Teamcenter Visualization to the Siemens Product CERT team. On Tuesday, July 12, 2022, Siemens and Open Design Alliance respectively released security patches(1 & 2) that addressed these vulnerabilities.
These vulnerabilities are identified as CVE-2022-28807, CVE-2022-28808, and CVE-2022-28809. They have been assigned a severity rating of Important.
Each of these vulnerabilities has a different root cause related to Open Design Alliance Drawings SDK affecting Siemens JT2Go and Teamcenter Visualization via a DWG file format. We suggest users apply the Sie
Fortinet
New Variant of QakBot Being Spread by HTML File Attached to Phishing Emails
blogs_fortinet·2022-07-19
New Variant of QakBot Being Spread by HTML File Attached to Phishing Emails
FORTIGUARD LABS THREAT RESEARCH
New Variant of QakBot Being Spread by HTML File Attached to Phishing Emails
By Xiaopeng Zhang | July 19, 2022
Fortinet’s FortiGuard Labs captured a phishing email as part of a phishing campaign spreading a new variant of QakBot. Also known as QBot, QuackBot, or Pinkslipbot, QakBot is an information stealer and banking Trojan that has been captured and analyzed by security researchers since 2007.
I performed a deep analysis on this phishing campaign and the new QakBot variant using the captured email. In this analysis, you will learn how the attached HTML file leads to downloading and executing the new QakBot variant, what actions it takes on the victim’s device, and how it sends the collected data from the victim’s device to its C2 server.
Affected platf
Checkpoint
11th July – Threat Intelligence Report
blogs_checkpoint·2022-07-11
CVE-2022-30190 11th July – Threat Intelligence Report
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 11th July – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 11th July, please download our Threat Intelligence Bulletin .
Top Attacks and Breaches
An anonymous hacker identified as “ChinaDan” has claimed to have a stolen a database from the Shanghai National Police (SHGA) that includes sensitive data of 1 billion Chinese citizens, and offered to sell it for 10 bitcoins (approximately $200,000). He allegedly stole more than 22 terabytes of data including names, addresses,
Fortinet
From Follina to Rozena - Leveraging Discord to Distribute a Backdoor | FortiGuard Labs
blogs_fortinet·2022-07-06·CVSS 7.8
CVE-2022-30190 [HIGH] From Follina to Rozena - Leveraging Discord to Distribute a Backdoor | FortiGuard Labs
FORTIGUARD LABS THREAT RESEARCH
From Follina to Rozena - Leveraging Discord to Distribute a Backdoor
By Cara Lin | July 06, 2022
In May 2022, Microsoft published an advisory about CVE-2022-30190, which is about a Microsoft Windows Support Diagnostic Tool (MSDT) remote code execution vulnerability. Attackers can inject a malicious external link to an OLE Object in a Microsoft Office document, then lure victims to click or simply preview the document in order to trigger this exploit. It will then execute a payload on the victim’s machine. Since this vulnerability is a public exploit and has high severity, FortiGuard Labs published an Outbreak Alert on 31st May and a blog article to address it on June 1, 2022.
During our tracking last month, we found a document that exploited CVE-2022-3019
Trendmicro
Black Basta Ransomware Operators Expand Their Attack Arsenal With QakBot Trojan and PrintNightmare Exploit
blogs_trendmicro·2022-06-30·CVSS 8.8
[HIGH] Black Basta Ransomware Operators Expand Their Attack Arsenal With QakBot Trojan and PrintNightmare Exploit
Ransomware
# Black Basta Ransomware Operators Expand Their Attack Arsenal With QakBot Trojan and PrintNightmare Exploit
We look into a recent attack orchestrated by the Black Basta ransomware group that used the banking trojan QakBot as a means of entry and movement and took advantage of the PrintNightmare vulnerability to perform privileged file operations.
By: Kenneth Adrian Apostol, Paolo Ronniel Labrador, Mirah Manlapig, James Panlilio, Emmanuel Panopio, John Kenneth Reyes, Melvin Singwa
2022/06/30
Read time: ( words)
Save to Folio
Since it became operational in April, Black Basta has garnered notoriety for its recent attacks on 50 organizations around the world and its use of double extortion, a modern ransomware tactic in which attackers encrypt confidential data and threaten t
Trendmicro
Black Basta Ransomware Operators Expand Their Attack Arsenal With QakBot Trojan and PrintNightmare Exploit
blogs_trendmicro·2022-06-30·CVSS 8.8
[HIGH] Black Basta Ransomware Operators Expand Their Attack Arsenal With QakBot Trojan and PrintNightmare Exploit
Ransomware
# Black Basta Ransomware Operators Expand Their Attack Arsenal With QakBot Trojan and PrintNightmare Exploit
We look into a recent attack orchestrated by the Black Basta ransomware group that used the banking trojan QakBot as a means of entry and movement and took advantage of the PrintNightmare vulnerability to perform privileged file operations.
By: Kenneth Adrian Apostol, Paolo Ronniel Labrador, Mirah Manlapig, James Panlilio, Emmanuel Panopio, John Kenneth Reyes, Melvin Singwa
Jun 30, 2022
Read time: ( words)
Save to Folio
Since it became operational in April, Black Basta has garnered notoriety for its recent attacks on 50 organizations around the world and its use of double extortion, a modern ransomware tactic in which attackers encrypt confidential data and threaten
Trendmicro
Black Basta Ransomware Operators Expand Their Attack Arsenal With QakBot Trojan and PrintNightmare Exploit
blogs_trendmicro·2022-06-30·CVSS 8.8
[HIGH] Black Basta Ransomware Operators Expand Their Attack Arsenal With QakBot Trojan and PrintNightmare Exploit
Ransomware
## Black Basta Ransomware Operators Expand Their Attack Arsenal With QakBot Trojan and PrintNightmare Exploit
We look into a recent attack orchestrated by the Black Basta ransomware group that used the banking trojan QakBot as a means of entry and movement and took advantage of the PrintNightmare vulnerability to perform privileged file operations.
By: Kenneth Adrian Apostol, Paolo Ronniel Labrador, Mirah Manlapig, James Panlilio, Emmanuel Panopio, John Kenneth Reyes, Melvin Singwa Jun 30, 2022 Read time: ( words)
Save to Folio
Since it became operational in April, Black Basta has garnered notoriety for its recent attacks on 50 organizations around the world and its use of double extortion , a modern ransomware tactic in which attackers encrypt confidential data and threate
Trendmicro
Black Basta Ransomware Operators Expand Their Attack Arsenal With QakBot Trojan and PrintNightmare Exploit
blogs_trendmicro·2022-06-30·CVSS 8.8
[HIGH] Black Basta Ransomware Operators Expand Their Attack Arsenal With QakBot Trojan and PrintNightmare Exploit
Ransomware
## Black Basta Ransomware Operators Expand Their Attack Arsenal With QakBot Trojan and PrintNightmare Exploit
We look into a recent attack orchestrated by the Black Basta ransomware group that used the banking trojan QakBot as a means of entry and movement and took advantage of the PrintNightmare vulnerability to perform privileged file operations.
By: Kenneth Adrian Apostol, Paolo Ronniel Labrador, Mirah Manlapig, James Panlilio, Emmanuel Panopio, John Kenneth Reyes, Melvin Singwa 2022/06/30 Read time: ( words)
Save to Folio
Since it became operational in April, Black Basta has garnered notoriety for its recent attacks on 50 organizations around the world and its use of double extortion , a modern ransomware tactic in which attackers encrypt confidential data and threaten
Fortinet
Ukraine Targeted by Dark Crystal RAT (DCRat) | FortiGuard Labs
blogs_fortinet·2022-06-27·CVSS 7.8
[HIGH] Ukraine Targeted by Dark Crystal RAT (DCRat) | FortiGuard Labs
FORTIGUARD LABS THREAT RESEARCH
Ukraine Targeted by Dark Crystal RAT (DCRat)
By Shunichi Imano, James Slaughter, and Fred Gutierrez | June 27, 2022
CERT-UA broke news on June 10, 2022 that various media outlets in Ukraine were targeted with emails containing a malicious document “СПИСОК_посилань_на_інтерактивні_карти.docx” (translated to English as “LIST_of_links_interactive_maps.docx”). According to the report, the document leverages a then zero-day vulnerability in the Microsoft Support Diagnostic Tool (MSDT), CVE-2022-30190 (Follina). The result is the download and execution of an unknown remote file on the compromised machine. Unfortunately, the payload has not been identified as the file was not available at the time of the investigation.
FortiGuard Labs came across another file th
Sentinelone
Top 6 Cyber Security Myths
blogs_sentinelone·2022-06-23
Top 6 Cyber Security Myths
The days when cyber security was merely a technical or niche issue to be dealt with by some small department in the basement are long behind us. Boards now have CISOs and CIOs, and yet there is still a need for all directors to understand the impact of cyber security risk when making strategic business decisions as well as to understand what to ask when a breach takes place.
Failing to grasp the nature of cyber security in today’s business environment can have dire consequences. Proper board preparedness and planning are critical both to protecting the business and to insulating officers and directors from liability. Accordingly, directors must ensure that the business is ready to face cyber risks and the potential legal ramifications of those risks by aligning the organization’s cyber ri
Sentinelone
Top 6 Cyber Security Myths
blogs_sentinelone·2022-06-23
Top 6 Cyber Security Myths
The days when cyber security was merely a technical or niche issue to be dealt with by some small department in the basement are long behind us. Boards now have CISOs and CIOs, and yet there is still a need for all directors to understand the impact of cyber security risk when making strategic business decisions as well as to understand what to ask when a breach takes place.
Failing to grasp the nature of cyber security in today’s business environment can have dire consequences. Proper board preparedness and planning are critical both to protecting the business and to insulating officers and directors from liability. Accordingly, directors must ensure that the business is ready to face cyber risks and the potential legal ramifications of those risks by aligning the organization’s cyber ri
Checkpoint
20th June – Threat Intelligence Report
blogs_checkpoint·2022-06-20·CVSS 7.8
CVE-2022-30190 [HIGH] 20th June – Threat Intelligence Report
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 20th June – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 20th June, please download our Threat Intelligence Bulletin .
Top Attacks and Breaches
Check Point Research has exposed an Iranian spear-phishing operation targeting high profile Israeli and US executives. As part of their operations, the attackers take over existing accounts of the executives and create impersonating accounts to lure their targets into long email conversations. The operation aims at stealing per
Krebs
Microsoft Patch Tuesday, June 2022 Edition
blogs_krebs·2022-06-15·CVSS 7.8
[HIGH] Microsoft Patch Tuesday, June 2022 Edition
Microsoft on Tuesday released software updates to fix 60 security vulnerabilities in its Windows operating systems and other software, including a zero-day flaw in all supported Microsoft Office versions on all flavors of Windows that’s seen active exploitation for at least two months now. On a lighter note, Microsoft is officially retiring its Internet Explorer (IE) web browser, which turns 27 years old this year.
Three of the bugs tackled this month earned Microsoft’s most dire “critical” label, meaning they can be exploited remotely by malware or miscreants to seize complete control over a vulnerable system. On top of the critical heap this month is CVE-2022-30190, a vulnerability in the Microsoft Support Diagnostics Tool (MSDT), a service built into Windows.
Dubbed “Follina,” the fla
Fortinet
Guidance On an Ongoing Hacktivist Operation #Opspatuk Conducted by The Malaysian Hacktivist Threat Group 'DragonForce' Against Indian Organizations | FortiGuard Labs
blogs_fortinet·2022-06-15
Guidance On an Ongoing Hacktivist Operation #Opspatuk Conducted by The Malaysian Hacktivist Threat Group 'DragonForce' Against Indian Organizations | FortiGuard Labs
FORTIGUARD LABS THREAT RESEARCH
Guidance On an Ongoing Hacktivist Operation #Opspatuk Conducted by The Malaysian Hacktivist Threat Group 'DragonForce' Against Indian Organizations
By Carl Windsor, Simran Kothari, Ankita Dasgupta, and FortiRecon Team | June 15, 2022
The 'OpsPatuk' operation began on June 6, 2022. That’s when the Malaysian hacktivist group known as DragonForce began targeting India in retaliation for controversial comments made by a BJP spokesperson.
At the time of writing, this operation has compromised over 102 websites and continues to list new targets on various social media platforms, including Telegram, Twitter, and their own DragonForce website.
Widely targeted sectors include financial organizations, government entities, and educational institutions. FortiGuard T
Fortinet
New IceXLoader 3.0 – Developers Warm Up to Nim | FortiGuard Labs
blogs_fortinet·2022-06-15
New IceXLoader 3.0 – Developers Warm Up to Nim | FortiGuard Labs
FORTIGUARD LABS THREAT RESEARCH
New IceXLoader 3.0 – Developers Warm Up to Nim
By Joie Salvio and Roy Tay | June 15, 2022
FortiGuard Labs has encountered version 3.0 of what is now dubbed IceXLoader, a new malware loader being advertised in malware hacking forums.
IceXLoader is a commercial malware used to download and deploy additional malware on infected machines. The latest version is written in Nim, a relatively new language utilized by threat actors the past two years, most notably by the NimzaLoader variant of BazarLoader used by the TrickBot group.
This article discusses the technical details of how IceXLoader behaves and the potential malware that it can deliver in an infected system.
Affected Platforms: Windows
Impacted Parties: Windows users
Impact: Potential to deploy addit
Krebs
Microsoft Patch Tuesday, June 2022 Edition
blogs_krebs·2022-06-15·CVSS 7.8
[HIGH] Microsoft Patch Tuesday, June 2022 Edition
Microsoft on Tuesday released software updates to fix 60 security vulnerabilities in its Windows operating systems and other software, including a zero-day flaw in all supported Microsoft Office versions on all flavors of Windows that’s seen active exploitation for at least two months now. On a lighter note, Microsoft is officially retiring its Internet Explorer (IE) web browser, which turns 27 years old this year.
Three of the bugs tackled this month earned Microsoft’s most dire “critical” label, meaning they can be exploited remotely by malware or miscreants to seize complete control over a vulnerable system. On top of the critical heap this month is CVE-2022-30190 , a vulnerability in the Microsoft Support Diagnostics Tool (MSDT), a service built into Windows.
Dubbed “ Follina ,” the
Tenable
Microsoft’s June 2022 Patch Tuesday Addresses 55 CVEs (CVE-2022-30190)
blogs_tenable·2022-06-14·CVSS 7.8
[HIGH] Microsoft’s June 2022 Patch Tuesday Addresses 55 CVEs (CVE-2022-30190)
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Qualys
June 2022 Patch Tuesday | Microsoft Releases 55 Vulnerabilities With 3 Critical; Adobe Releases 6 Advisories, 46 Vulnerabilities With 40 Critical.
blogs_qualys·2022-06-14·CVSS 7.8
[HIGH] June 2022 Patch Tuesday | Microsoft Releases 55 Vulnerabilities With 3 Critical; Adobe Releases 6 Advisories, 46 Vulnerabilities With 40 Critical.
## Table of Contents
Microsoft Patch Tuesday Summary
The June 2022 Microsoft Vulnerabilities Are Classified As Follows:
Notable Microsoft Vulnerabilities Patched
Microsoft Guidance on Intel Processor MMIO Stale Data Vulnerabilities
Windows Server 2022 Azure Edition Core Hotpatch (KB5014677) OS Build 20348.770
Microsoft Critical and Important Vulnerability Highlights
Microsoft Last But Not Least
Adobe Security Bulletins and Advisories
About Qualys Patch Tuesday
Discover and Prioritize Vulnerabilities in Vulnerability Management Detection Response (VMDR)
Rapid Response With Patch Management (PM)
Qualys Monthly Webinar Series
Join the webinar This Month in Vulnerabilities & Patches
## Microsoft Patch Tuesday Summary
Microsoft has fixed 55 vulnerabilities (aka flaws) in the June
Qualys
Detect the Follina MSDT Vulnerability (CVE-2022-30190) with Qualys Multi-Vector EDR
blogs_qualys·2022-06-14·CVSS 7.8
CVE-2022-30190 [HIGH] Detect the Follina MSDT Vulnerability (CVE-2022-30190) with Qualys Multi-Vector EDR
## Table of Contents
Phases of an Attack Exploiting the Follina Vulnerability
Technical Details of Follina: CVE-2022-30190
Qualys Multi-Vector EDR Can Detect Follina
How to Detect Folina Exploitation Attempts (CVE-2022-30190)
Conclusion
Update
IOCs
MITRE ATT&CK Mapping
Contributors
A new remote code execution vulnerability called “Follina” has been found lurking in most Microsoft products. In this blog, we examine a potential attack vector as well as technical details of Follina, and chart the ability to detect this new vulnerability using both Qualys Multi-Vector EDR.
On May 27, 2022, a security researcher tweeted about a malicious Microsoft Word document with alarmingly low detection rates that he had found on VirusTotal. Only four vendors detected the document back then. Even
Qualys
CVE-2022-30190 Follina Zero-Day Vulnerability | Qualys
blogs_qualys·2022-06-14·CVSS 7.8
CVE-2022-30190 [HIGH] CVE-2022-30190 Follina Zero-Day Vulnerability | Qualys
#### Table of Contents
- Phases of an Attack Exploiting the Follina Vulnerability
- Technical Details of Follina: CVE-2022-30190
- Qualys Multi-Vector EDR Can Detect Follina
- How to Detect Folina Exploitation Attempts (CVE-2022-30190)
- Conclusion
- Update
- IOCs
- MITRE ATT&CK Mapping
- Contributors
A new remote code execution vulnerability called “Follina” has been found lurking in most Microsoft products. In this blog, we examine a potential attack vector as well as technical details of Follina, and chart the ability to detect this new vulnerability using both Qualys Multi-Vector EDR.
On May 27, 2022, a security researcher tweeted about a malicious Microsoft Word document with alarmingly low detection rates that he had found on VirusTotal. Only four vendors detected the document bac
Qualys
June 2022 Patch Tuesday | Microsoft Releases 55 Vulnerabilities With 3 Critical; Adobe Releases 6 Advisories, 46 Vulnerabilities With 40 Critical. | Qualys
blogs_qualys·2022-06-14·CVSS 7.8
[HIGH] June 2022 Patch Tuesday | Microsoft Releases 55 Vulnerabilities With 3 Critical; Adobe Releases 6 Advisories, 46 Vulnerabilities With 40 Critical. | Qualys
#### Table of Contents
- Microsoft Patch Tuesday Summary
- The June 2022 Microsoft Vulnerabilities Are Classified As Follows:
- Notable Microsoft Vulnerabilities Patched
- Microsoft Guidance on Intel Processor MMIO Stale Data Vulnerabilities
- Windows Server 2022 Azure Edition Core Hotpatch (KB5014677) OS Build 20348.770
- Microsoft Critical and Important Vulnerability Highlights
- Microsoft Last But Not Least
- Adobe Security Bulletins and Advisories
- About Qualys Patch Tuesday
- Discover and Prioritize Vulnerabilities in Vulnerability Management Detection Response (VMDR)
- Rapid Response With Patch Management (PM)
- Qualys Monthly Webinar Series
- Join the webinar This Month in Vulnerabilities & Patches
## Microsoft Patch Tuesday Summary
Microsoft has fixed 55 vulnerabilities (aka fl
Checkpoint
13th June – Threat Intelligence Report
blogs_checkpoint·2022-06-13
CVE-2022-30190 13th June – Threat Intelligence Report
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 13th June – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 13th June, please download our Threat Intelligence Bulletin .
Top Attacks and Breaches
The Italian municipality of Palermo has been victim of a ransomware attack that caused a large-scale service outage affecting over a million people. The attack was claimed by the Vice Society ransomware group, which used the double extortion ransomware
Shields Health Care Group, Massachusetts-based medical services provider, h
Securelist
CVE-2022-30190 (Follina) vulnerability in MSDT: description and counteraction
blogs_securelist·2022-06-06·CVSS 7.8
CVE-2022-30190 [HIGH] CVE-2022-30190 (Follina) vulnerability in MSDT: description and counteraction
Table of Contents
CVE-2022-30190 technical details
Protecting against Follina
Authors
AMR
At the end of May, researchers from the nao_sec team reported a new zero-day vulnerability in Microsoft Support Diagnostic Tool (MSDT) that can be exploited using Microsoft Office documents. It allowed attackers to remotely execute code on Windows systems, while the victim could not even open the document containing the exploit, or open it in Protected Mode. The vulnerability, which the researchers dubbed Follina, later received the identifier CVE-2022-30190 .
## CVE-2022-30190 technical details
Briefly, the exploitation of the CVE-2022-30190 vulnerability can be described as follows. The attacker creates an MS Office document with a link to an external malicious OLE object ( word/_rels/documen
Checkpoint
6th June – Threat Intelligence Report
blogs_checkpoint·2022-06-06·CVSS 7.8
CVE-2022-30190 [HIGH] 6th June – Threat Intelligence Report
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 6th June – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 6th June, please download our Threat Intelligence Bulletin .
Top Attacks and Breaches
An unaffiliated threat actor has been initialing a phishing campaign targeting government entities in Europe and the U.S, exploiting the recently disclosed Microsoft Office “Follina” vulnerability, tracked CVE-2022-30190.
Check Point IPS, Threat Emulation and Harmony Endpoint provide protection against this threat (Microsoft Sup
Securelist
CVE-2022-30190 (Follina) vulnerability in MSDT: description and counteraction
blogs_securelist·2022-06-06·CVSS 7.8
CVE-2022-30190 [HIGH] CVE-2022-30190 (Follina) vulnerability in MSDT: description and counteraction
Table of Contents
- CVE-2022-30190 technical details
- Protecting against Follina
Authors
- AMR
At the end of May, researchers from the nao_sec team reported a new zero-day vulnerability in Microsoft Support Diagnostic Tool (MSDT) that can be exploited using Microsoft Office documents. It allowed attackers to remotely execute code on Windows systems, while the victim could not even open the document containing the exploit, or open it in Protected Mode. The vulnerability, which the researchers dubbed Follina, later received the identifier CVE-2022-30190.
## CVE-2022-30190 technical details
Briefly, the exploitation of the CVE-2022-30190 vulnerability can be described as follows. The attacker creates an MS Office document with a link to an external malicious OLE object (word/_rels/doc
Talos
Threat Source newsletter (June 2, 2022) — An RSA Conference primer
blogs_talos·2022-06-02
Threat Source newsletter (June 2, 2022) — An RSA Conference primer
## Threat Source newsletter (June 2, 2022) — An RSA Conference primer
Welcome to this week’s edition of the Threat Source newsletter.
Many of you readers may be gearing up for a West Coast swing over the next few weeks through San Francisco and Las Vegas for RSA and Cisco Live, respectively. And we’re right behind you!
Talos will have plenty of representation at both conferences, including giving lightning talks at the Cisco Secure booth, several features talks and spots, live podcast recordings, and more. To get you ready for RSA, I wanted to highlight a few special things we’re doing at the conference you should know about before you go.
As always, you can keep posted on our latest plans and talk schedule by following us on Twitter.
Main booth
Stop by the main Talos and Cisco Secur
Zscaler
Coverage Advisory for CVE-2022-30190 | Zscaler
blogs_zscaler·2022-06-02·CVSS 7.8
[HIGH] Coverage Advisory for CVE-2022-30190 | Zscaler
Provide users with seamless, secure, reliable access to applications and data.
Build and run secure cloud apps, enable zero trust cloud connectivity, and protect workloads from data center to cloud.
Provide zero trust connectivity for IoT and OT devices and secure remote access to OT systems.
Provide zero trust site-to-site connectivity and reliable access to B2B apps for partners.
Industry Report
Zscaler: A Leader in the 2025 Gartner® Magic Quadrant™ for Security Service Edge (SSE)
USE CASES
INDUSTRY & MARKET SOLUTIONS
PARTNERS
TECHNOLOGY PARTNERS
Resource Center
Events & Trainings
Security Research & Services
Tools
Community & Support
CXO REVOLUTIONARIES
Amplifying the voices of real-world digital and zero trust pioneers
Discover how it began and where it’s going
Meet o
Talos
Threat Source newsletter (June 2, 2022) — An RSA Conference primer
blogs_talos·2022-06-02
Threat Source newsletter (June 2, 2022) — An RSA Conference primer
Welcome to this week’s edition of the Threat Source newsletter.
Many of you readers may be gearing up for a West Coast swing over the next few weeks through San Francisco and Las Vegas for RSA and Cisco Live, respectively. And we’re right behind you!
Talos will have plenty of representation at both conferences, including giving lightning talks at the Cisco Secure booth, several features talks and spots, live podcast recordings, and more. To get you ready for RSA, I wanted to highlight a few special things we’re doing at the conference you should know about before you go.
As always, you can keep posted on our latest plans and talk schedule by following us on Twitter.
Main booth
Stop by the main Talos and Cisco Secure booth at Moscone North Hall to say hi, ask questions and get the late
Fortinet
CVE-2022-30190: Microsoft Support Diagnostic Tool (MSDT) RCE Vulnerability “Follina” | FortiGuard Labs
blogs_fortinet·2022-06-01·CVSS 7.8
CVE-2022-30190 [HIGH] CVE-2022-30190: Microsoft Support Diagnostic Tool (MSDT) RCE Vulnerability “Follina” | FortiGuard Labs
FORTIGUARD LABS THREAT RESEARCH
CVE-2022-30190: Microsoft Support Diagnostic Tool (MSDT) RCE Vulnerability “Follina”
By Shunichi Imano, James Slaughter, Fred Gutierrez, and FortiRecon Team | June 01, 2022
At the end of last week, @nao_sec, an independent cyber security research team, tweeted about a malicious Microsoft Word document submitted from Belarus that leverages remote templates to execute a PowerShell payload using the "ms-msdt" MSProtocol URI scheme. Additional developments over the weekend identified the issue as a new unpatched vulnerability in Windows. A successful attack results in a remote, unauthenticated attacker taking control of an affected system. A publicly available Proof-of-Concept soon followed.
This issue is referred to as “Follina’ and has a CVE assignment of C
Talos
Threat Advisory: Zero-day vulnerability in Microsoft diagnostic tool MSDT could lead to code execution
blogs_talos·2022-06-01·CVSS 7.8
CVE-2022-30190 [HIGH] Threat Advisory: Zero-day vulnerability in Microsoft diagnostic tool MSDT could lead to code execution
## Threat Advisory: Zero-day vulnerability in Microsoft diagnostic tool MSDT could lead to code execution
A recently discovered zero-day vulnerability in the Microsoft Windows Support Diagnostic Tool (MSDT) made headlines over the past few days. CVE-2022-30190 , also known under the name "Follina," exists when MSDT is called using the URL protocol from an application, such as Microsoft Office, Microsoft Word or via an RTF file. An attacker could exploit this vulnerability to gain the ability to run arbitrary code on the targeted system.
Although a patch hasn't been released yet, Microsoft has provided workarounds and Windows Defender protections for the CVE and malware exploiting this vulnerability. Cisco Talos has also released coverage to protect against this vulnerability, the full de
Talos
Threat Advisory: Zero-day vulnerability in Microsoft diagnostic tool MSDT could lead to code execution
blogs_talos·2022-06-01·CVSS 7.8
CVE-2022-30190 [HIGH] Threat Advisory: Zero-day vulnerability in Microsoft diagnostic tool MSDT could lead to code execution
A recently discovered zero-day vulnerability in the Microsoft Windows Support Diagnostic Tool (MSDT) made headlines over the past few days. CVE-2022-30190, also known under the name "Follina," exists when MSDT is called using the URL protocol from an application, such as Microsoft Office, Microsoft Word or via an RTF file. An attacker could exploit this vulnerability to gain the ability to run arbitrary code on the targeted system.
Although a patch hasn't been released yet, Microsoft has provided workaroundsand Windows Defender protections for the CVE and malware exploiting this vulnerability. Cisco Talos has also released coverage to protect against this vulnerability, the full details of which are available below.
The most direct workaround is to disable the MSDT URL protocol by launch
Tenable
CVE-2022-30190: Zero Click Zero Day in Microsoft Support Diagnostic Tool Exploited in the Wild
blogs_tenable·2022-05-31·CVSS 7.8
[HIGH] CVE-2022-30190: Zero Click Zero Day in Microsoft Support Diagnostic Tool Exploited in the Wild
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Unit42
Threat Brief: CVE-2022-30190 – MSDT Code Execution Vulnerability
blogs_unit42·2022-05-31·CVSS 7.8
CVE-2022-30190 [HIGH] Threat Brief: CVE-2022-30190 – MSDT Code Execution Vulnerability
## Executive Summary
On May 27, 2022, details began to emerge of malicious Word documents leveraging remote templates to execute PowerShell via the ms-msdt Office URL protocol. The use of this technique appeared to allow attackers to bypass local Office macro policies to execute code within the context of Word. Microsoft has since released protection guidance and assigned CVE-2022-30190 to this vulnerability.
Due to the amount of publicly available information, ease of use, and the extreme effectiveness of this exploit, Palo Alto Networks is providing this threat brief to make our customers aware of this critical vulnerability and the options available to ensure proper protections are put into place until a patch can be issued by Microsoft.
The vulnerability enables remote code executio
Sentinelone
SentinelOne VS CVE-2022-30190 (Follina)
blogs_sentinelone·2022-05-31·CVSS 7.8
CVE-2022-30190 [HIGH] SentinelOne VS CVE-2022-30190 (Follina)
Platform
- Platform Overview
- Singularity Platform
Welcome to IntegratedEnterprise Security
- AI Security Portfolio
Leading the Way in AI-Powered Security Solutions
- How It Works
The Singularity XDR Difference
- Singularity Marketplace
One-Click Integrations to Unlock the Power of XDR
- Pricing & Packaging
Comparisons and Guidance at a Glance
- Data & AI
- Purple AI
Accelerate SecOps with Generative AI
- Singularity Hyperautomation
Easily Automate Security Processes
- AI-SIEM
The AI SIEM for the Autonomous SOC
- Singularity Data Lake
AI-Powered, Unified Data Lake
- Singularity Data Lake for Log Analytics
Seamlessly Ingest Data from On-Prem, Cloud or Hybrid Environments
- Endpoint Security
- Singularity Endpoint
Autonomous Prevention, Detection, and Response
- Singularity XDR
Native &
Unit42
Threat Brief: CVE-2022-30190 – MSDT Code Execution Vulnerability
blogs_unit42·2022-05-31·CVSS 7.8
CVE-2022-30190 [HIGH] Threat Brief: CVE-2022-30190 – MSDT Code Execution Vulnerability
Threat Research Center
High Profile Threats
Vulnerabilities
## Threat Brief: CVE-2022-30190 – MSDT Code Execution Vulnerability
Shawn Westfall
Published: May 31, 2022
High Profile Threats
Vulnerabilities
CVE-2022-30190
Follina
Microsoft Office
Remote Code Execution
Zero-click
## Executive Summary
On May 27, 2022, details began to emerge of malicious Word documents leveraging remote templates to execute PowerShell via the ms-msdt Office URL protocol. The use of this technique appeared to allow attackers to bypass local Office macro policies to execute code within the context of Word. Microsoft has since released protection guidance and assigned CVE-2022-30190 to this vulnerability.
Due to the amount of publicly available information, ease of use, and the extreme effective
Sentinelone
SentinelOne VS CVE-2022-30190 (Follina)
blogs_sentinelone·2022-05-31·CVSS 7.8
[HIGH] SentinelOne VS CVE-2022-30190 (Follina)
How It Works The Singularity XDR Difference
Singularity Marketplace One-Click Integrations to Unlock the Power of XDR
Pricing & Packaging Comparisons and Guidance at a Glance
Purple AI Accelerate SecOps with Generative AI
Singularity Hyperautomation Easily Automate Security Processes
AI-SIEM The AI SIEM for the Autonomous SOC
Singularity Data Lake AI-Powered, Unified Data Lake
Singularity Data Lake for Log Analytics Seamlessly Ingest Data from On-Prem, Cloud or Hybrid Environments
Singularity Endpoint Autonomous Prevention, Detection, and Response
Singularity XDR Native & Open Protection, Detection, and Response
Singularity RemoteOps Forensics Orchestrate Forensics at Scale
Singularity
Threat Intelligence Comprehensive Adversary Intelligence
Singularity Vulnerability Management
Sentinelone
CVE-2022-30190 (Follina): Detection and Mitigation
blogs_sentinelone·2022-05-31·CVSS 7.8
CVE-2022-30190 [HIGH] CVE-2022-30190 (Follina): Detection and Mitigation
## Executive Summary
- On May 27th 2022, @nao_sec identified a malicious Microsoft Word document using a “ms-msdt” protocol scheme for arbitrary code execution.
- As the industry continues to identify novel ways to abuse this ability over the weekend, Microsoft assigned it as CVE-2022-30190.
- Similar to what we observed with Log4j, the methods of execution and outcomes of this vulnerability continue to expand as it gains more researcher and attacker attention.
- Specific attackers have been observed exploiting the vulnerability. Chinese APTs have potentially made use of it around May 20th, 2022, but first samples identified as easily as mid-April 2022.
- Defenders should consider it a critical vulnerability and seek mitigation steps immediately. Additional effort should then be made to h
Sentinelone
CVE-2022-30190 (Follina): Detection and Mitigation
blogs_sentinelone·2022-05-31·CVSS 7.8
CVE-2022-30190 [HIGH] CVE-2022-30190 (Follina): Detection and Mitigation
## Executive Summary
On May 27th 2022, @nao_sec identified a malicious Microsoft Word document using a “ms-msdt” protocol scheme for arbitrary code execution.
As the industry continues to identify novel ways to abuse this ability over the weekend, Microsoft assigned it as CVE-2022-30190.
Similar to what we observed with Log4j, the methods of execution and outcomes of this vulnerability continue to expand as it gains more researcher and attacker attention.
Specific attackers have been observed exploiting the vulnerability. Chinese APTs have potentially made use of it around May 20th, 2022, but first samples identified as easily as mid-April 2022.
Defenders should consider it a critical vulnerability and seek mitigation steps immediately. Additional effort should then be made to hunt fo
Huntress
Rapid Response: Microsoft Office RCE - “Follina” MSDT Attack | Huntress
blogs_huntress·2022-05-30·CVSS 7.8
[HIGH] Rapid Response: Microsoft Office RCE - “Follina” MSDT Attack | Huntress
This post, as is the norm for emerging threats, is a developing article and may be subject to change as the Huntress team learns more about this attack vector and new information is available.
UPDATE 4:51pm ET June 14, 2022:
Microsoft announced an available patch for the Follina exploit. Our team has been working to validate the patch, and we have tested and verified that the patch is effective both for Windows 10 and Windows 11:
Just to note, your KB# may vary based on your operating system—check out Microsoft's update for the full list.
Below, the code fails to execute on Windows 10:
In the below image, the raw command fails on Windows 10:
UPDATE 11:16pm ET May 30, 2022:
Microsoft has now revealed the CVE identifier for this vulnerability is CVE-2022-30190 , including a Security U
Fortinet
Analysis of Microsoft CVE-2022-21907 | FortiGuard Labs
blogs_fortinet·2022-02-15·CVSS 9.8
CVE-2022-21907 [CRITICAL] Analysis of Microsoft CVE-2022-21907 | FortiGuard Labs
FORTIGUARD LABS THREAT RESEARCH
Analysis of Microsoft CVE-2022-21907
By Tim Lau | February 15, 2022
On January 11th, 2022 Microsoft released a patch for CVE-2022-21907 as part of Microsoft’s Patch Tuesday. CVE-2022-21907 attracted special attentions from industry insiders due to the claim that the vulnerability is worm-able. In this analysis we will look at the cause of the vulnerability and how attackers can exploit it.
Affected Platforms: Windows Server 2022, Windows Server 2019, Windows 10
Impacted Users: Any organization with affected Windows system
Impact: Denial of service to affected systems
Severity Level: High
CVE-2022-21907 is a remote code execution vulnerability in Windows’ Internet Information Services (IIS) component. More specifically, it affects the kernel module insi
Fortinet
Exploiting an RCE bug in the UDP Protocol implemented in FreeRTOS
blogs_fortinet·2018-12-04·CVSS 8.1
CVE-2018-16525 [HIGH] Exploiting an RCE bug in the UDP Protocol implemented in FreeRTOS
FORTIGUARD LABS THREAT RESEARCH
Exploiting an RCE bug in the UDP Protocol implemented in FreeRTOS
By Amir Zali | December 04, 2018
Recently, I saw a report about several bugs that were found on FreeRTOS. Curiosity got the best of me, and I started to take a look to see what can be done from the IPS side to protect our customers because of importance of IoT devices and the popularity of this operating system. (Since the initial report more details have been made available here, CVE-2018-16525.)
In this post I will just elaborate on a single RCE bug that I have managed to exploit in the UDP protocol which is implemented in FreeRTOS+TCP.
RTOS, Real Time Operating System, is a type of operating system that provides deterministic execution. AWS FreeRTOS is a class of RTOS from Amazon Web Se
Crowdstrike
August Patch Tuesday 2022: Updates and Analysis
blogs_crowdstrike·CVSS 7.5
CVE-2026-20929 [HIGH] August Patch Tuesday 2022: Updates and Analysis
How CrowdStrike is Accelerating Exposure Evaluation as Adversaries Gain Speed Apr 06, 2026
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
How CrowdStrike is Accelerating Exposure Evaluation as Adversaries Gain Speed Apr 06, 2026
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
Video Highlights the 4 Key Steps to Successful Incident Response Dec 02, 2019
Helping Non-Security Stakeholders Understand AT
Recorded Future
Chinese State-Sponsored Group TA413 Adopts New Capabilities in Pursuit of Tibetan Targets
blogs_recorded_future·CVSS 9.8
[CRITICAL] Chinese State-Sponsored Group TA413 Adopts New Capabilities in Pursuit of Tibetan Targets
# Chinese State-Sponsored Group TA413 Adopts New Capabilities in Pursuit of Tibetan Targets
Editor’s Note: The following post is an excerpt of a full report. To read the entire analysis, click here to download the report as a PDF.
This report details multiple campaigns conducted by the likely Chinese state-sponsored threat activity group TA413. The activity was identified through a combination of large-scale automated network traffic analytics and expert analysis. This report will be of most interest to individuals and organizations with strategic and operational intelligence requirements relating to Chinese cyber threat activity, as well as humanitarian and other organizations concerned with Tibetan interests. With thanks to our colleagues at Sophos for early sharing and collaboration.
Recorded Future
Top 5 Attack Surface Risks of 2022
blogs_recorded_future
Top 5 Attack Surface Risks of 2022
# Top 5 Attack Surface Risks of 2022
In a bid to contend with this year’s most prominent cyber threats, security teams everywhere have been forced to duly advance their understanding of what constitutes an attack surface.
A typical response from the community at large abides somewhere between the glaring redefinition of the traditional perimeter—that which incorporates the eroding, or blurring, of former demarcation lines—and the incidental yet insidious role of social engineering techniques ever threatening to run aground any significant defensive posture.
By contrast, cyber defense programs remain largely reactive and, frankly, quite disappointing at times. The idea of having an immersive, lessons-learned approach to security, whereby we generally assume to be faster in detecting atta
Huntress
Rapid Response: Microsoft Office RCE - “Follina” MSDT Attack | Huntress
blogs_huntress·CVSS 7.8
[HIGH] Rapid Response: Microsoft Office RCE - “Follina” MSDT Attack | Huntress
This post, as is the norm for emerging threats, is a developing article and may be subject to change as the Huntress team learns more about this attack vector and new information is available.
UPDATE 4:51pm ET June 14, 2022:
Microsoft announced an available patch for the Follina exploit. Our team has been working to validate the patch, and we have tested and verified that the patch is effective both for Windows 10 and Windows 11:
Just to note, your KB# may vary based on your operating system—check out Microsoft's update for the full list.
Below, the code fails to execute on Windows 10:
In the below image, the raw command fails on Windows 10:
UPDATE 11:16pm ET May 30, 2022:
Microsoft has now revealed the CVE identifier for this vulnerability is CVE-2022-30190, including a Security Up
Crowdstrike
June Patch Tuesday 2022: Updates and Analysis
blogs_crowdstrike·CVSS 7.5
CVE-2026-20929 [HIGH] June Patch Tuesday 2022: Updates and Analysis
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
How Charlotte AI AgentWorks Fuels Security's Agentic Ecosystem Mar 25, 2026
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
How Charlotte AI AgentWorks Fuels Security's Agentic Ecosystem Mar 25, 2026
Video Highlights the 4 Key Steps to Successful Incident Response Dec 02, 2019
Helping Non-Security Stakeholders Understand ATT&CK in 10 Minutes or Less [VI
Sentinelone
Black Basta
blogs_sentinelone
Black Basta
# Black Basta Ransomware: In-Depth Analysis, Detection, and Mitigation
## Summary of Black Basta Ransomware
Black Basta first emerged in early 2022. The ransomware family is an evolution of the Hermes/Ryuk/Conti families. Black Basta was heavily advertised in underground cybercrime markets. Black Basta practices double extortion – demanding payment for a decryptor, as well as for the non-release of stolen data. There are Windows and LInux variants of Black Basta ransomware. The group is responsible for hundreds of attacks against global targets of varying sectors.
February 2025 Update: Nearly a year’s worth of Black Basta chat logs have been released on Telegram, providing detailed insight into the groups operational workflow, reconnaissance activities, and specific userID and details o
Crowdstrike
August Patch Tuesday 2022: Updates and Analysis
blogs_crowdstrike·CVSS 7.5
CVE-2026-20929 [HIGH] August Patch Tuesday 2022: Updates and Analysis
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
How Charlotte AI AgentWorks Fuels Security's Agentic Ecosystem Mar 25, 2026
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
How Charlotte AI AgentWorks Fuels Security's Agentic Ecosystem Mar 25, 2026
Video Highlights the 4 Key Steps to Successful Incident Response Dec 02, 2019
Helping Non-Security Stakeholders Understand ATT&CK in 10 Minutes or Less [VI
Recorded Future
Chinese State-Sponsored Group TA413 Adopts New Capabilities in Pursuit of Tibetan Targets | Recorded Future
blogs_recorded_future·CVSS 9.8
[CRITICAL] Chinese State-Sponsored Group TA413 Adopts New Capabilities in Pursuit of Tibetan Targets | Recorded Future
## Chinese State-Sponsored Group TA413 Adopts New Capabilities in Pursuit of Tibetan Targets
This report details multiple campaigns conducted by the likely Chinese state-sponsored threat activity group TA413. The activity was identified through a combination of large-scale automated network traffic analytics and expert analysis. This report will be of most interest to individuals and organizations with strategic and operational intelligence requirements relating to Chinese cyber threat activity, as well as humanitarian and other organizations concerned with Tibetan interests. With thanks to our colleagues at Sophos for early sharing and collaboration.
## Executive Summary
Recorded Future's analysts continue to observe targeting of ethnic and religious minority communities by Chinese sta
Recorded Future
Top 5 Attack Surface Risks of 2022 | Recorded Future
blogs_recorded_future
Top 5 Attack Surface Risks of 2022 | Recorded Future
## Top 5 Attack Surface Risks of 2022
In a bid to contend with this year’s most prominent cyber threats, security teams everywhere have been forced to duly advance their understanding of what constitutes an attack surface .
A typical response from the community at large abides somewhere between the glaring redefinition of the traditional perimeter—that which incorporates the eroding, or blurring, of former demarcation lines—and the incidental yet insidious role of social engineering techniques ever threatening to run aground any significant defensive posture.
By contrast, cyber defense programs remain largely reactive and, frankly, quite disappointing at times. The idea of having an immersive, lessons-learned approach to security, whereby we generally assume to be faster in detecting at
Crowdstrike
How CrowdStrike Falcon® Protects Against Follina (CVE-2022-30190)
blogs_crowdstrike·CVSS 7.8
CVE-2026-20929 [HIGH] How CrowdStrike Falcon® Protects Against Follina (CVE-2022-30190)
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
How Charlotte AI AgentWorks Fuels Security's Agentic Ecosystem Mar 25, 2026
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
How Charlotte AI AgentWorks Fuels Security's Agentic Ecosystem Mar 25, 2026
Video Highlights the 4 Key Steps to Successful Incident Response Dec 02, 2019
Helping Non-Security Stakeholders Understand ATT&CK in 10 Minutes or Less [VI
Huntress
CVE-2022-30190 Vulnerability: Analysis, Detection, Removal | Huntress
blogs_huntress·CVSS 7.8
CVE-2022-30190 [HIGH] CVE-2022-30190 Vulnerability: Analysis, Detection, Removal | Huntress
## CVE-2022-30190 Vulnerability
Published: 12/12/2025
Written by: Nadine Rozell
CVEs are Common Vulnerabilities and Exposures—unique identifiers for publicly known cybersecurity vulnerabilities. CVE-2022-30190, widely known as "Follina," is a remote code execution vulnerability that weaponizes an unlikely suspect: the Microsoft Support Diagnostic Tool (MSDT). This clever bug allows attackers to run malicious code just by getting a user to open a booby-trapped document.
This page will dissect how Follina works, its impact, and the steps you need to take to detect and mitigate it. Let's make sure your Office documents aren't secretly opening a backdoor.
## What is CVE-2022-30190 Vulnerability?
CVE-2022-30190 (Follina) is a remote code execution (RCE) vulnerability that abuses the ms-ms
Recorded Future
RedNovember Targets Government, Defense, and Technology Organizations
blogs_recorded_future
RedNovember Targets Government, Defense, and Technology Organizations
# RedNovember Targets Government, Defense, and Technology Organizations
Note: The analysis cut-off date for this report was July 25, 2025
## Executive Summary
In July 2024, Insikt Group publicly reported on TAG-100, a threat activity group conducting suspected cyber-espionage activity targeting high-profile government, intergovernmental, and private sector organizations globally using the open-source, multi-platform Go backdoor Pantegana. At the time, we did not attribute this activity to a particular country; however, after reviewing all available evidence, we assess that TAG-100 is highly likely a Chinese state-sponsored threat activity group. Accordingly, Insikt Group now tracks this group under the designation RedNovember.
Between June 2024 and July 2025, RedNovember (which overlap
arXiv
Frontier AI's Impact on the Cybersecurity Landscape
arxiv_fulltext·2025-11-27
Frontier AI's Impact on the Cybersecurity Landscape
Frontier AI's Impact on the Cybersecurity Landscape
Yujin Potter^1*, Wenbo Guo^2*, Zhun Wang^1, Tianneng Shi^1, Hongwei Li^2, Andy Zhang^1,
-2mm
Patrick Gage Kelley^3, Kurt Thomas^3, and Dawn Song^1
5mm
1UC Berkeley
2UC Santa Barbara
3Google
*Co-first authors
## Abstract
The impact of frontier AI (i.e., AI agents and foundation models) in cybersecurity is rapidly increasing.
In this paper, we comprehensively analyze this trend through multiple aspects: quantitative benchmarks, qualitative literature review, empirical evaluation, and expert survey.
Our analyses consistently show that AI’s capabilities and applications in attacks have exceeded those on the defensive side.
Our empirical evaluation of widely used agent systems on cybersecurity benchmarks highlights that current AI agents s
arXiv
ChatGPT for Digital Forensic Investigation: The Good, The Bad, and The Unknown
arxiv_fulltext·2023-07-10
ChatGPT for Digital Forensic Investigation: The Good, The Bad, and The Unknown
frontmatter
ChatGPT for Digital Forensic Investigation: The Good, The Bad, and The Unknown
[add1]Mark Scanlonfirstcorr
[email protected]
[firstcorr]Corresponding author
[add1]Forensics and Security Research Group, School of Computer Science, University College Dublin, Ireland
[add2]Frank Breitinger
[email protected]
[add2]School of Criminal Justice, University of Lausanne, Lausanne, Switzerland
[add3]Christopher Hargreaves
[email protected]
[add3]Department of Computer Science, University of Oxford, United Kingdom
[add4]Jan-Niclas Hilgert
[email protected]
[add4]Fraunhofer FKIE, Bonn, Germany
[add5]John Sheppard
[email protected]
[add5]Department of Computing and Mathematics, South East Technological University, Waterford, Ireland
## Abstract
CTF
Outdated / README
ctf_writeups·CVSS 7.8
CVE-2022-30190 [HIGH] Outdated / README
# Outdated - HackTheBox - Writeup
Linux, 30 Base Points, Medium
## Machine
## TL;DR
To solve this machine, we begin by enumerating open services using ```namp```.
***User 1***: Found PDF on SMB share, From the PDF we know that we need to use ```CVE-2022-30190 (folina)```, Sending mail with URL to folina to ```[email protected]``` and we get a reverse shell as ```btables```.
***User 2***: By running ```bloodhound``` we can see that we can use ```AddKeyCredentialLink``` This technique allows an attacker to take over an AD user or computer account if the attacker can modify the target object's (user or computer account) attribute ```msDS-KeyCredentialLink``` and append it with alternate credentials in the form of certificates, Using that we get the user ```sflowers````.
***Root*
HackerOne
Unrestricted File Upload on reddit.secure.force.com
hackerone·2022-09-30·CVSS 7.8
CVE-2022-30190 [HIGH] Unrestricted File Upload on reddit.secure.force.com
Unrestricted File Upload on reddit.secure.force.com
## Summary:
Reddit.secure.force.com is Reddit SalesForce instance. Attacker is able to send attachments of disallowed filetypes to this server. The attacker is able to send malicious documents such as CVE-2022-30190 Follina to the victim.
## Impact:
Attacker can send malicious files to whoever handles the form behind https://reddit.secure.force.com/adhelp
## Steps To Reproduce:
1. Go to https://reddit.secure.force.com/adhelp
2. Notice that the specified allowed filetype is: jpg jpeg gif png pdf as you can see with the image below:
{F1780944}
3. If you try dragging and dropping a docx file to that box, there is a Javascript which forbids such action. But if you used the "Click to browse" option you can start uploading the file.
{F178
Bugzilla
Extensions are not prompted before opening external schemes, leading to security issues
bugzilla·2022-09-23
Extensions are not prompted before opening external schemes, leading to security issues
Extensions are not prompted before opening external schemes, leading to security issues
Created attachment 9295918
Mozilla Add-on to desmontrate the attack
VERSION
Firefox Version: 105.0 (64-bits)
Operating System: Windows 10 Pro Version 21H1 (Build 19043.2006)
VULNERABILITY DETAILS
This report covers an extension who could abuse default protocol handlers acceptance from the browser
to download any arbitrary file and tries to load with a windows default installed program.
Impact:
An extension can create an `obscured` window using the protocol print3d (default accepted by firefox), which
leads to the user downloading any type of files from an URL to the system and try to load this file using print3d software on Windows.
Here in this report, I'm covering the usage of the print3d prot
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2022-30190http://packetstormsecurity.com/files/167438/Microsoft-Office-Word-MSDTJS-Code-Execution.htmlhttps://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2022-30190https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2022-30190
2022-06-01
Published
2022-06-14
Added to CISA KEV
Exploited in the wild