CVEs You Might Have Missed While Log4j Stole the Headlines
ID: 54673be2-72d7-5000-bc94-16ec23192ec2
STIX ID: report--54673be2-72d7-5000-bc94-16ec23192ec2
Feed Name: ReliaQuest Blog
This ReliaQuest blog provides vulnerability intelligence for Q4 2021, cataloguing 260 exploited CVEs and focusing on a prioritized subset of high-risk vulnerabilities (including MSHTML RCE CVE-2021-40444, OMIGOD, Win32k escalation CVE-2021-40449, ProxyShell Exchange flaws, and VMWare/Apache/QNAP issues). It describes active exploitation in the wild, malware/ransomware deployments (Cobalt Strike, FormBook, Conti, QLocker, DeadBolt, Mirai), the presence of exploits and PoCs on criminal forums, and recommends a risk-based vulnerability management approach to prioritize patching and mitigation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
