Timeline
CVE-2023-50224
TP-Link WR841N router vulnerability exploited by APT28 to rewrite DNS settings and steal Microsoft 365 credentials.
13 of 13 entries (13 events, 0 interactions)
Filters
#7 8 Jun
Enabled unauthenticated VPN session establishment via IKEv1 logic flaw
Cybersecurity: Threats and Defences: VPN zero-day open a month pre-patch#6 3 Jun
Exploited in the wild against Magento stores before the federal deadline
Cybersecurity: Threats and Defences: Magento RCE forces 9-day patch race#6 2 Jun
Exploited to break out of Linux containers and reach root on host systems
Cybersecurity: Threats and Defences: Old Linux container bug back in the wild#4 15 May
Exchange repeats the CISA deadline-before-patch trap
Cybersecurity: Threats and Defences#4 13 May
Mentioned in: Patch Tuesday clean streak hides out-of-band KEVs
Cybersecurity: Threats and Defences#4 11 May
UNC6780 takes Cisco AI Defense source code
Cybersecurity: Threats and Defences#3 7 May
Added to KEV on 7 May with 10 May deadline, confirmed limited exploitation in the wild
Cybersecurity: Threats and Defences: Ivanti EPMM logs fourth KEV zero-day since 2023#3 30 Apr
Disclosed by WatchTowr Labs and added to KEV on 30 April with 3 May deadline
Cybersecurity: Threats and Defences: cPanel zero-day ran 65 days before patch; Sorry ransomware active#2 24 Apr
FIRESTARTER implant survives every Cisco firewall patch
Cybersecurity: Threats and Defences#2 24 Apr
Mentioned in: Federal agency stayed compromised six months
Cybersecurity: Threats and Defences#3 19 Apr
Mentioned in: KB5091157, Gentlemen C2 intel, ENISA CNAs: in brief
Cybersecurity: Threats and Defences#1 7 Apr
Enabled APT28 to extract router credentials and modify DNS settings on TP-Link WR841N devices
Cybersecurity: Threats and Defences: GRU hijacks home routers for M365 logins#1 28 Mar