Topic: cisa known exploited vulnerabilities catalog
-
Microsoft SharePoint Zero-Day Exploited in RCE Attacks - No Fix Yet
Microsoft SharePoint is under active attack via zero-day vulnerabilities (CVE-2025-53770 and CVE-2025-53771), enabling remote code execution on on-premises servers, with at least 85 servers compromised globally. Microsoft recommends mitigations like enabling AMSI, deploying Defender AV, and rotat...
Read More » -
CISA Warns: AMI MegaRAC Bug Exploited in Server Hijacks
CISA warns of active exploitation of a critical vulnerability (CVE-2024-54085) in AMI's MegaRAC BMC software, allowing attackers to bypass authentication and remotely control servers. Successful exploitation could lead to severe outcomes like malware deployment, ransomware attacks, or permanent h...
Read More » -
Trinper Backdoor Abused Chrome Zero-Day in Espionage Campaign
Google Chrome’s CVE-2025-2783 zero-day was quietly exploited by the espionage group TaxOff to deploy Trinper, a modular backdoor used in highly targeted campaigns. Before the March patch rolled out, Trinper was already stealing clipboard data and establishing covert control in high-value systems. Our breakdown of the campaign reveals how browsers are becoming the new frontline for cyber intrusion.
Read More »