Index live· 1,284 files · 148 editions
ForensicPost

Search the index

28 results
Try
Results for “Exploitation”Newest first
26-0810b
File

VMware vCenter Flaw Exploited in 47 Countries Within a Week of the Patch

361 hosts in 47 countries, and 95% of them taken inside two days of the first exploitation.

UnattributedCVE-2026-59310MultipleExploitation
Sev 5TargetVMware vCenter operatorsActorUnattributedGermany
26-0714b
File

CISA Tells SharePoint Operators to Hunt Before They Rotate Keys

Rotating the stolen key is the fix. It is also what erases the proof anyone used it.

UnattributedRemote code executionTechnologyExploitation
Sev 5TargetOn-premises SharePoint operatorsActorUnattributedUSA
26-0705
File

Qilin Affiliates Linked to Exploitation of Check Point VPN Authentication Bypass

An authentication bypass on the appliance that decides who is inside. The intruder inherits every assumption built on it.

Qilin affiliatesAuthentication bypassMultipleEdge devices
Sev 4TargetCheck Point VPN appliancesActorQilin affiliates
26-0506
File

The Disclosure-to-Exploitation Window Is Closing on the Patch Window

Exploitation is arriving before organisations can deploy. Patching in twenty days is worth less than surviving a compromised appliance.

MultipleRapid exploitationMultipleVulnerabilities
Sev 4TargetEnterprise patch managementActorMultiple
26-0315
File

The Same Capability, Pointed the Other Way

A backup does not help an attacker. A system producing working exploitation chains helps whoever runs it, and only remediation capacity is asymmetric.

MultipleDual useCloudMethod
Sev 4TargetVulnerability research capabilityActorMultiple
26-0311
File

Edge VPN and Firewall Exploitation Becomes Dominant Initial-Access Route

Four vendors, one campaign. Largest attack surface, least visibility, highest trust — and both states and criminals use the same door.

MultipleAppliance exploitationMultipleEdge devices
Sev 5TargetEdge VPN and firewall appliancesActorMultiple
25-1118
File

Researchers Documented Indirect Prompt Injection Planted in Web Content

A person reading a hostile page is not compromised by reading it. An agent is deciding what to do next on the basis of what the page says.

UnattributedIndirect prompt injectionCloudExploitation
Sev 4TargetBrowsing AI agentsActorUnattributed
25-1003
File

The Oracle Campaign Named Another One

For most of the interval the company was the victim of an incident that had already happened and had not yet surfaced.

Cl0pZero-day exploitationManufacturingExploitation
Sev 4TargetLogitechActorCl0p
25-1007
File

One Enterprise Application, Victims on Four Continents

The window between disclosure and exploitation is shortest exactly where the ability to respond is slowest.

Cl0pMass exploitationMultipleExploitation
Sev 5TargetOracle enterprise estatesActorCl0pSouth Korea
25-0820
File

Salesloft Intrusion Began in March and Stayed Dormant Until August

Five months quiet, ten days of theft. A single dwell-time figure conflates the two, and organisations optimise against the wrong phase.

UNC6395Delayed exploitationCloudMethod
Sev 4TargetIncident response practiceActorUNC6395
25-0721
File

Ninety-four per Cent of Tested Agents Could Be Hijacked by What They Read

Recruiting an insider costs money, time and exposure to prosecution. Persuading an agent costs a paragraph and works every time.

MultiplePrompt injectionCloudExploitation
Sev 4TargetAI agent deploymentsActorMultiple
25-0719
File

ToolShell SharePoint Chain Confirmed Under Exploitation, 150 Organisations Hit

Self-hosting transfers the patch obligation. In a window measured in days, that transfer decides the outcome.

MultipleZero-day exploit chainCloudExploitation
Sev 5TargetOn-premises SharePoint estatesActorMultiple
25-0624
File

CitrixBleed 2 NetScaler Flaw CVE-2025-5777 Widely Exploited From June

A sequel name is a judgement that this is the same mistake in the same place. Session tokens leak past authentication entirely.

MultipleMemory disclosureCloudExploitation
Sev 4TargetNetScaler appliancesActorMultiple
25-0424
File

Attackers Uploaded Webshells to Internet-Facing SAP NetWeaver Systems

A webshell is the least sophisticated technique in this database. That it worked against the system of record is the finding.

UnattributedUnauthorised file uploadCloudExploitation
Sev 4TargetSAP NetWeaver estatesActorUnattributed
25-0411
File

The Fourth File-Transfer Product in Five Years

A product that is exposed, trusted and full is not an unfortunate combination. It is the specification.

Cl0pEdge product exploitationMultipleConcentration
Sev 5TargetFile-transfer estateActorCl0p
25-0403
File

Hertz Confirms Customer and Employee Data Taken Through Cleo Flaw

A privately held operator using the same product would have had the same exposure and, quite possibly, produced no public record at all.

Cl0pSupplier product exploitationTravelDisclosure
Sev 4TargetHertzActorCl0pUSA
25-0217
File

A Hundred and Eighty-Two Names, Posted in One Go

An organisation appears on the list because it did not pay, or paid late. An organisation absent from the list may have paid.

Cl0pEdge product exploitationMultipleMass exploitation
Sev 4TargetCleo customersActorCl0p
25-0214
File

The File-Transfer Product Is the Bank’s Weakest Wall

Internet-facing, authentication-heavy, holding the files too sensitive for email. Managed file transfer keeps producing portfolios of victims.

UnattributedZero-day exploitationFinanceFinance
Sev 3TargetWestern Alliance BankActorUnattributed
25-0212
File

Leaked Black Basta Chats Referenced 62 CVEs, 53 Exploited in the Wild

Patch windows are argued about as though the attacker learns of a flaw when the defender does. Here the advisory was not the starting gun.

Black BastaVulnerability exploitationMultipleExploitation
Sev 4TargetEnterprise edge estateActorBlack Basta
25-0109
File

Ivanti Connect Secure Flaw CVE-2025-0282 Exploited From January 2025

The identity boundary expressed as hardware. And a vendor exploited recently is more likely, not less, to be exploited again.

MultipleZero-day exploitationCloudExploitation
Sev 4TargetIvanti Connect Secure estatesActorMultiple
24-0110
File

Ivanti Connect Secure Auth Bypass and Command Injection Chained for Remote Code Execution

The first flaw supplies the authentication the second one requires. A pair of medium problems is not a medium problem.

MultipleVulnerability chainingCloudExploitation
Sev 4TargetIvanti Connect Secure operatorsActorMultipleUSA
23-1010b
File

HTTP/2 Rapid Reset Drove DDoS Peaks of 398 Million Requests per Second

No vendor to patch and no version to check. Every implementation had to fix it separately.

UnattributedCVE-2023-44487TechnologyExploitation
Sev 4TargetHTTP/2 implementationsActorUnattributedUSA
23-0724
File

Ivanti Zero-Day Breached 12 Norwegian Ministries; Four Kept off the Platform Escaped

A decision made years earlier for classification reasons turned out to be the security control.

UnattributedCVE-2023-35078 — zero-dayGovernmentExploitation
Sev 5TargetNorwegian government ministriesActorUnattributedNorway
23-0518
File

Barracuda Told Customers to Replace ESG Appliances Rather Than Patch Them

The vendor did not tell customers to update the appliance. It told them to throw it away.

UNC4841Zero-day exploitationMultipleEdge devices
Sev 5TargetBarracuda ESG appliancesActorUNC4841
23-0413
File

Cl0p and LockBit Both Exploited PaperCut a Month After the Patch Shipped

High privilege, low attention, reachable. The vulnerable thing is rarely the one anyone would name.

Cl0p, LockBitCVE-2023-27350TechnologyExploitation
Sev 4TargetPaperCut MF/NG operatorsActorCl0p, LockBitUSA
23-0208
File

ESXiArgs Encrypted Thousands of Hypervisors Through a Two-Year-Old Flaw

The patch had existed for two years. The campaign needed no new capability, only servers nobody had looked at.

UnattributedUnpatched vulnerabilityMultipleExploitation
Sev 4TargetVMware ESXi serversActorUnattributed
22-0930
File

ProxyNotShell Mitigation Described One Exploit and Was Bypassed Twice

Blocking a URL pattern encodes the exploit you have seen, not the defect that allows it.

UnattributedCVE-2022-41040 → CVE-2022-41082TechnologyExploitation
Sev 4TargetOn-premises Exchange operatorsActorUnattributedUSA
22-0527
File

Follina Exploited Word Documents With No Macro and No Protected View Warning

Ten years of telling people not to enable macros, and this one did not ask.

UnattributedCVE-2022-30190 — zero-dayTechnologyExploitation
Sev 4TargetWindows usersActorUnattributedUSA
© 2026 ForensicPost Media · the desk · newsletterGlossaryNo search logging