logo

Zero-Day Vulnerabilities in Platforms Could Leave MSPs Exposed

ID: b2653279-5a64-561d-8cc8-b7f7ee9948f7

STIX ID: report--b2653279-5a64-561d-8cc8-b7f7ee9948f7

Feed Name: Huntress Blog

Threat Score
72/100

Date Published: 2024-04-12

Date Updated: 2026-04-28

...
...

**Executive summary:** Huntress discovered zero-day vulnerabilities and misconfigurations in major virtual event platforms (webcasts.com/6Connex and VFairs) that enabled exposure of attendee PII (names, emails, IPs, addresses), profile tampering, SQL injection, and possible remote code execution; these issues affected events used by large organizations and were responsibly disclosed and patched. The report also describes a separate SMB supply-chain breach (Axial) leaking 250k+ confidential financing and M&A records, and urges MSPs to rigorously vet third-party vendors and treat supply-chain risk as a critical security concern.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.