Threats Tagged 'misp-galaxy:mitre-attack-pattern="external remote services - t1133"'
View all threats tagged with 'misp-galaxy:mitre-attack-pattern="external remote services - t1133"'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'misp-galaxy:mitre-attack-pattern="external remote services - t1133"'
Click on any threat for detailed analysis and mitigation recommendations
0 A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0 including the following packages: react-server-dom-parcel, react-server-dom-turbopack, and react-server-dom-webpack. The vulnerable code unsafely deserializes payloads from HTTP requests to Server Function endpoints. Join the discussion | CVE Database V5 | 01/29/2026, 00:00:00 UTC Added: 12/03/2025, 15:54:37 UTC |
The XCTDH Crypto Heist Part 2 is a medium-severity threat involving multiple MITRE ATT&CK techniques such as exploitation of external remote services, automated data exfiltration, user execution, and compromise of software dependencies. It appears linked to North Korean threat actors and involves persistence, payload delivery, and network activity. No specific affected products or versions are identified, and no patches or known exploits in the wild are reported. The attack likely leverages social engineering and supply chain compromise to infiltrate targets and exfiltrate sensitive data. European organizations could be impacted if targeted via compromised software dependencies or remote service vulnerabilities. Mitigation requires enhanced supply chain security, strict remote access controls, user awareness training, and network monitoring for unusual exfiltration patterns. Countries with significant financial sectors and software development industries, such as Germany, France, and the UK, are more likely to be affected. The threat is assessed as medium severity due to the complexity of exploitation, potential data loss, and moderate ease of execution requiring user interaction and supply chain compromise. MediumUnknown Join the discussion | CIRCL OSINT Feed | 10/29/2025, 00:00:00 UTC Added: 10/30/2025, 21:55:36 UTC |
OSINT - Backmydata Ransomware Indicators of Compromise (IOCs) - alerts - dnsc.ro Join the discussion | CIRCL OSINT Feed | 02/19/2024, 00:00:00 UTC Added: 05/27/2025, 11:06:06 UTC |
Showing 1 to 3 of 3 results