View Ridge Security
Back to Cyber HoseActive Exploits & Incidents

CISA Urges Immediate Patching of Exploited SharePoint Vulnerabilities

🚨 ACTIVE EXPLOITS & INCIDENTS

🔓 VULNERABILITIES & CVEs

🕵️ THREAT RESEARCH & DEEP DIVES

  • We built a vulnerability vending machine: AI tokens in, zero-days out — BleepingComputer
    Researchers detail an AI-powered system combining code slicing and large language models to autonomously discover complex zero-day vulnerabilities. The tool recently uncovered and exploited a previously unknown WordPress plugin zero-day, with multiple additional zero-days responsibly disclosed. This marks a significant evolution in automated vulnerability discovery and exploitation.

📋 VENDOR BULLETINS & ADVISORIES

  • Establishing a Coordinated Vulnerability Disclosure Program — CISA Advisories
    Joint guidance from CISA, NSA, and partners outlines best practices for software vendors and service providers to implement coordinated vulnerability disclosure (CVD) programs. It covers policy design, triage, remediation, CVE assignment, and leveraging third-party intermediaries to improve transparency and security collaboration.

📰 LESSER-KNOWN / UNDER-REPORTED

  • Alleged Russian Cyber Spy in Boston Previously Worked for Kaspersky — @metacurity on Infosec.exchange
    New reporting reveals the alleged Russian cyber espionage suspect arrested in Boston has prior employment history with Kaspersky. This connection may have implications for attribution and insider threat assessments in espionage investigations.

Need help assessing your exposure?

Start with the free Posture Self-Check to see where you stand against the current threat landscape.

Free Posture Self-Check