Threats Tagged 'active exploitation'
View all threats tagged with 'active exploitation'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'active exploitation'
Click on any threat for detailed analysis and mitigation recommendations
0 A security update addresses multiple vulnerabilities discovered during routine security review, including authentication bypass issues affecting management products. One vulnerability (CVE-2026-16232) has been exploited in the wild against a limited number of customers with specific configurations where Management is exposed directly to the internet without IP restrictions. The affected systems include Security Management and Multi-Domain Management across multiple versions. Two additional vulnerabilities address authentication bypass with privilege escalation and local privilege escalation in GaiaOS WebUI. All impacted customers have been notified, and Smart-1 Cloud customers are already protected. Indicators of compromise include six IP addresses associated with the exploitation activity. Installation of the latest Jumbo hotfix is recommended along with implementation of security best practices. Join the discussion | CVE Database V5 | 07/24/2026, 14:24:56 UTC Added: 06/08/2026, 11:33:51 UTC |
0 A critical remote code execution vulnerability (CVE-2025-59287) exists in Microsoft Windows Server Update Services (WSUS) affecting versions from Windows Server 2012 through 2025 with the WSUS role enabled. This flaw allows unauthenticated attackers to execute code with system privileges by targeting exposed WSUS instances on ports 8530 and 8531. Initial patching on October 14, 2025, was incomplete, necessitating an emergency update on October 23. Exploitation has been observed within hours of patch release, with attackers leveraging malicious PowerShell commands for reconnaissance and data exfiltration. Approximately 5,500 WSUS instances are exposed globally, representing a significant attack surface. The vulnerability facilitates initial access and lateral movement within networks. European organizations using WSUS for patch management are at risk of compromise, data theft, and broader network infiltration. Immediate patching and network exposure reduction are critical to mitigate this threat. Join the discussion | AlienVault OTX General | 12/07/2025, 08:53:15 UTC Added: 12/08/2025, 18:23:52 UTC |
Showing 1 to 2 of 2 results