Threat advisories
Vulnerabilities and active campaigns, with the affected versions and what to do.

The Return of Medusa Botnet as a Mirai-Based Variant with Ransomware Sting
Learn about the newly discovered Medusa botnet variant featuring a ransomware module and Telnet brute-forcer. Discover its attack capabilities and the…

Citrix ADC and Citrix Gateway Vulnerabilities Exploited in Targeted Attacks
Learn about the critical vulnerabilities in Citrix ADC and Gateway versions 12.1 and 13.0 before 13.0-58.32 and the recommended steps to mitigate the threat.

Supply Chain Attack Compromises 3CXDesktopApp
Protect your business from the 3CXDesktopApp malware. Our threat advisory provides technical details, exposure risks, and recommendations to help mitigate the…

MortalKombat Ransomware Campaign Targets US Systems
This threat advisory outlines the risks and exposure of the MortalKombat ransomware campaign, which is targeting systems in the United States.

Critical Unauthorized Remote Execution Code Vulnerability Found in Fortinet FortiOS and FortiProxy
Take immediate action to protect your systems from the critical unauthorized remote execution code vulnerability found in Fortinet's FortiOS and FortiProxy…

Critical Remote Code Execution Vulnerability in Sophos Firewall Devices
Enterprotect, a cybersecurity company, is issuing a threat advisory on a critical remote code execution (RCE) vulnerability found in the User Portal and…

Critical Elevation of Privilege Vulnerability Discovered in Microsoft Outlook
Microsoft Outlook users are at risk from a critical elevation of privilege vulnerability, allowing threat actors to potentially steal credentials and gain…

Vulnerability in Cisco Small Business RV016, RV042, RV042G, and RV082 Routers Exposed to Remote Command Execution
Enterprotect is issuing a threat advisory on a critical vulnerability in Cisco Small Business RV016, RV042, RV042G, and RV082 routers.

Updated Bumblebee Malware Loader with Enhanced Evasion Capabilities
Enterprotect's latest threat advisory highlights the updated Bumblebee malware loader, detailing its enhanced evasion techniques and providing recommendations…

Unpatched VMware vRealize Log Insight Appliances at Risk of Unauthorized Remote Code Execution
Cybersecurity firm Enterprotect warns VMware vRealize Log Insight users of a newly discovered exploit targeting a vulnerability chain that allows remote code…

Global Cybersecurity Advisory Breakdown: The Threat of Volt Typhoon
Discover key insights from a multi-national cybersecurity advisory on the threat posed by Volt Typhoon. This article summarizes the advisory, highlighting the…

Critical Remote Code Execution Vulnerability in Atlassian's Jira Service Management Server and Data Center
Learn about the critical remote code execution vulnerability in Atlassian's Jira Service Management Server and Data Center.

Thousands of Norton LifeLock Customers Compromised in Credential Stuffing Attack
Stay informed and protect yourself with our latest threat advisory. Learn about the recent Norton LifeLock data breach caused by a credential stuffing attack…

New Microsoft Word Vulnerability CVE-2023-36761
Enterprotect's latest threat advisory highlights the recent Microsoft Word vulnerability, CVE-2023-36761. Learn about the threat, its significance, potential…

Malicious Packages Found in Python Package Index (PyPI)
This threat advisory by Enterprotect highlights the discovery of malicious packages on the Python Package Index that can steal sensitive data from developers.

Hackers Exploit Cacti Critical Bug to Install Malware and Open Reverse Shells
Enterprotect is issuing a threat advisory regarding a critical security issue in Cacti, a network device monitoring tool.

Google Advertisements Promote Antivirus-Evading 'Virtualized' Malware
Google advertisements promoting antivirus-evading 'virtualized' malware. Discover the exposure and risk and get expert recommendations on how to protect…

Fortinet SSL VPN RCE Vulnerability - Patches Released
Discover the critical Fortinet SSL VPN RCE vulnerability, its potential risks, and how to safeguard your network. Learn about the recommended patches and…

“File Archiver in the Browser” Exploits - Protect Yourself from Deceptive ZIP Domains
Protect yourself from the emerging "File Archiver in the Browser" phishing trick that exploits ZIP domains. Learn about the risks, significance, and…

EvilExtractor Malware Spikes in Europe and the US
Stay informed and protect your organization from the rapidly spreading EvilExtractor malware, a stealthy threat targeting sensitive data.

Escalating CACTUS Ransomware Group Targets SMBs with Advanced Techniques
Discover the escalating threat of the CACTUS ransomware group targeting SMBs with advanced techniques. Stay informed about their new variant, evasive tactics…

Critical Zero-Day Vulnerability in libwebp Image Library
A comprehensive advisory on the recent zero-day vulnerability (CVE-2023-5129) in the libwebp image library, detailing its threat, significance, risks, and…

Critical Zero-Day Vulnerability in Adobe Acrobat and Reader
Enterprotect's advisory on the recent critical zero-day vulnerability detected in Adobe Acrobat and Reader, detailing the threat, its significance, exposure…

Critical Vulnerability in QNAP Devices Allowing Remote Attackers to Inject Malicious Code
Stay protected against the recently discovered critical vulnerability in QNAP devices with our Threat Advisory. Read about the SQL injection flaw, the…

Critical Vulnerability Discovered in FortiNAC
Protect your network from the critical FortiNAC vulnerability (CVE-2023-33299) with actionable recommendations. Safeguard against unauthorized access and code…

Critical PaperCut MF and NG Vulnerability Actively Exploited
Stay one step ahead of cyber threats with our in-depth threat advisory on the critical PaperCut vulnerability (CVE-2023-27350).

Cisco Small Business Switches Remote Attack Vulnerabilities
Protect your organization from remote attack vulnerabilities in Cisco Small Business Switches. Learn about the latest threat advisory, its risks, and…

BlackCat Ransomware Targets Microsoft Azure Storage
Enterprotect's latest threat advisory highlights the BlackCat ransomware's targeting of Microsoft Azure storage. Learn about the threat, its significance…

AWS Exploited for Crypto Mining Operation
Protect your organization from the exploitation of Amazon Web Services (AWS) for illicit crypto mining activities. Learn about the GUI-vil threat group and…

3 New Apple Zero-Day Vulnerabilities in WebKit Exploited
Stay informed about the latest Apple zero-day vulnerabilities and learn how to protect your devices. This advisory provides a comprehensive analysis of three…

Malicious Open Broadcaster Software (OBS) Studio Being Delivered Through Paid Sponsored Links
Enterprotect is actively monitoring a new iteration of malware distribution through the use of sponsored links. Learn about the malicious version of Open…

Fortinet Zero-Day Vulnerability Actively Exploited in Attacks
Enterprotect warns of an actively exploited zero-day vulnerability in Fortinet's FortiOS operating system. The vulnerability, which allows attackers to…

LastPass Security Incident Update
Stay informed on the latest LastPass security incident update. Learn about the unauthorized access to LastPass's cloud storage, the exposure and risk to…

Linux Kernel Vulnerability - A New Security Flaw Discovered in Linux 5.15 SMB3 Server
A new Linux Kernel Vulnerability has been disclosed by the Zero Day Initiative that could lead to code execution in the context of the kernel.

Malicious 'Lolip0p' PyPi Packages Install Info-Stealing Malware
Learn about the recent threat of malicious 'Lolip0p' PyPi packages that install info-stealing malware. Discover why it's noteworthy, the exposure or risk and…

ESXiArgs Ransomware Attacks Targeting Vulnerable VMware ESXi Servers
Stay protected from ESXiArgs ransomware attacks with our latest threat advisory. Learn about the vulnerability and follow our recommended measures to upgrade…

Qakbot Leveraging Compromised Websites for Initial Infiltration
Learn about the rise of Qakbot as an initial access threat, its techniques, and the risks it poses. Find out how Enterprotect recommends protecting your…

Critical Zero-Day Vulnerability in MOVEit Transfer Exploited in the Wild
Protect your organization from a critical zero-day vulnerability in MOVEit Transfer. Discover the risks, exposure, and recommended mitigation steps provided…

Command Injection Flaw in Zyxel NAS Devices
Protect your organization from critical vulnerabilities in Zyxel NAS devices with Enterprotect's actionable recommendations for enhanced network security.

Earth Lusca's SprySOCKS Linux Backdoor Targets Governments
Dive into the details of the SprySOCKS Linux backdoor, a new threat from the Earth Lusca group targeting government entities.