<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom">
  <title>CIRCL publications</title>
  <link href="https://www.circl.lu/pub/atom.xml" rel="self" type="application/atom+xml" />
  <link href="https://www.circl.lu/pub/" rel="alternate" type="text/html" />
  <updated>2026-09-28T00:00:00Z</updated>
  <id>https://www.circl.lu/pub/</id>
  <author><name>CIRCL</name></author>
  <entry>
    <title>Publications and Presentations</title>
    <link href="https://www.circl.lu/pub/" rel="alternate" type="text/html" />
    <id>https://www.circl.lu/pub/</id>
    <published>2026-09-28T00:00:00Z</published>
    <updated>2026-09-28T00:00:00Z</updated>
    <summary>Publications Description Last update TR-100 - Multiple Critical Vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway 27th September 2026 TR-99 - Phishing Campaign Targeting Hotel Customers in Luxembourg 1st June 2026 TR-98 - Security Advisory Ivanti Endpoint Manager Mobile (EPMM) (CVE-2026-1281 &amp;amp; CVE-2026-1340) - Active Exploitation 9 February 2026 TR-97 - Supply Chain Compromise Propagating Through the npm Ecosystem (Shai-Hulud) 28 November 2025 TR-96 - Multiple Vulnerabilities in F5 Devices and Products - Impact and Mitigation 15 October 2025 TR-95 - Critical vulnerability - Deserialization of untrusted data in on-premises Microsoft SharePoint Server allows an unauthorized attacker to execute code over a network. CVE-2025-53770 - CVE-2025-53771 20 July 2025 CIRCL AI Strategy 20 June 2025 TR-94 - Ongoing Phishing Campaigns Targeting Microsoft 365 Tenants Lacking Multi-Factor Authentication 22 May 2025 TR-93 - Financial transaction fraud after system compromise via Remote Management and Monitoring tools 26 February 2025 TR-93 (de) - Finanzbetrug nach Systemkompromittierung über Remote-Management- und Monitoring-Tools 26 February 2025 TR-93 (fr) - Fraude financière après compromission du système via des outils de gestion et de surveillance à distance 26 February 2025 TR-92 - Unused Domain Names and the Risks of Missing DNS SPF Records 22 January 2025 TR-91 - Vulnerability identified as CVE-2024-0012, affecting Palo Alto Networks PAN-OS software 20 December 2024 TR-90 - Vulnerability identified as CVE-2023-34990, affecting Fortinet FortiWLM 20 December 2024 TR-89 - Guidelines for Notifying CSIRT/CERT of Red Teaming and Penetration Testing Exercises 12 November 2024 TR-88 - Motivation, procedure and rationale for leaked credential notifications 30 August 2024 Learning from the Recent Windows/Falcon Sensor Outage: Causes and Potential Improvement Strategies in Linux Using Open Source Solutions 23rd July 2024 TR-87 - CrowdStrike Agent causing BSOD loop on Windows - Faulty Update on Falcon Sensor 19th July 2024 TR-86 - Check Point VPN Information Disclosure (CVE-2024-24919) - Actively Exploited 31st May 2024 TR-85 - Three vulnerabilities in Cisco ASA software/appliance and FTD software being exploited 25th April 2024 TR-84 - PAN-OS (Palo Alto Networks) OS Command Injection Vulnerability in GlobalProtect Gateway - CVE-2024-3400 12th April 2024 TR-83 - Linux Boot Hardening HOWTO 3rd April 2024 TR-82 - backdoor discovered in xz-utils - CVE-2024-3094 30th March 2024 TR-81 - Critical FortiOS vulnerabilities in sslvpnd and fgfmd 9 February 2024 TR-80 - Targeted SMS and fake phone center call targeting financial/banking services 7 February 2024 TR-79 - AnyDesk Incident and Potential Associated Supply Chain Attack 5 February 2024 TR-78 - CVE-2023-46805 (Authentication Bypass) &amp;amp; CVE-2024-21887 (Command Injection) for Ivanti Connect Secure and Ivanti Policy Secure Gateways 11 January 2024 TR-77 - Spear phishing and voice call scams targeting corporate executives and their accounting department 30 August 2023 TR-76 - Multiple high severity vulnerabilities in CODESYS V3 SDK could lead to RCE or DoS 14 August 2023 TR-75 - Unauthenticated remote code execution vulnerability in NetScaler ADC (formerly Citrix ADC) and NetScaler Gateway (formerly Citrix Gateway) - CVE-2023-3519 21 July 2023 TR-74 - A heap-based buffer overflow vulnerability (CWE-122) in FortiOS - CVE-2023-27997 5 July 2023 TR-73 - Ransomware FAQ 7 March 2023 TR-72 - Vulnerable Microsoft Exchange server metrics leading to alarming situation 21 February 2023 TR-71 - FortiOS - heap-based buffer overflow in sslvpnd (exploited) - FortiOS SSL-VPN - CVE-2022-42475 13 December 2022 TR-70 - Vulnerabilities in Microsoft Exchange CVE-2022-41040 - CVE-2022-41082 30 September 2022 TR-69 - How to choose an ICT supplier from a security perspective 13 June 2022 TR-68 - Best practices in times of tense geopolitical situations 28 February 2022 TR-67 - local privilege escalation vulnerability in polkit’s pkexec utility 26 January 2022 TR-66 - Webservers with mod_status like debug modules publicly available leak information 15 December 2021 TR-65 - Vulnerabilities and Exploitation of Log4j (Remote code injection in Log4j) 10 December 2021 TR-64 - Exploited Exchange Servers - Mails with links to malware from known/valid senders 10 November 2021 TR-63 - Vulnerabilities and Exploitation of Pulse Connect Secure 21 April 2021 TR-62 - Leak of Facebook Data from 533 Million Users 6 April 2021 TR-61 - Critical vulnerabilities in Microsoft Exchange 12 March 2021 TR-60 - Phishing - Effects and precautions 26 June 2020 TR-59 - Remote Work - In times of a crisis 18 March 2020 TR-58 - CVE-2020-0796 - Critical vulnerability in Microsoft SMBv3 - status and mitigation 11 March 2020 TR-57 - Ransomware - Effects and precautions 10 December 2019 TR-56 - HTTP Strict Transport Security 19 March 2019 TR-55 - SquashFu - an alternate Open Source Backup solution, resilient to Crypto Ransomware attacks 12 September 2018 TR-54 - Sextortion scam emails - I know your password 3 August 2018 TR-53 - Statement about WHOIS and GDPR 12 April 2018 TR-52 - Forensic Analysis of an HID Attack 5 February 2018 TR-51 - How to react to fraudulent acts of third party invoicing or requesting funds without showing any purchase order 23 November 2017 TR-50 - WPA2 handshake traffic can be manipulated to induce nonce and session key reuse 16 October 2017 TR-49 - CVE-2017-7494 - A critical vulnerability in Samba - remote code execution from a writable share 26 May 2017 TR-48 - Cyber-Threats Indicators Sharing, security-related actionable information and future of Personal Data Protection framework in the EU - MISP and GDPR 6 March 2017 TR-47 - Recommendations regarding Abuse handling for ISPs and registrars 23 February 2017 TR-46 - Information Leaks Affecting Luxembourg and Recommendations 17 February 2017 TR-45 - Data recovery techniques 12 May 2016 TR-44 - Information security - laws and specific rulings in the Grand Duchy of Luxembourg 15 March 2016 TR-43 - Installing MPSS 3.6.1 to use a Intel Xeon Phi Coprocessor on Ubuntu Trusty 14.04 LTS 11 January 2016 TR-42 - CVE-2015-7755 - CVE-2015-7756 - Critical vulnerabilities in Juniper ScreenOS 21 December 2015 TR-41 (de) - Crypto Ransomware - Vorsichtsmaßnahmen und Verhalten im Infektionsfall 19 May 2016 TR-41 (fr) - Crypto Ransomware - Défenses proactives et de réponse sur incident 19 May 2016 TR-41 - Crypto Ransomware - Proactive defenses and incident response 13 May 2017 TR-40 - Allaple worm activity in 2015 and long-term persistence of worm (malware) in Local Area Networks 24 September 2015 TR-39 - CIRCL-SOPs Standard Operational Procedures 30 July 2015 TR-38 - Attacks targeting enterprise banking solutions - recommendations and remediations 9 May 2017 TR-37 - VENOM / CVE-2015-3456 - Critical vulnerability in QEMU Floppy Disk Controller (FDC) emulation 14 May 2015 TR-36 - Example setup of WordPress with static export 28 April 2015 TR-34 - How to view and extract raw messages in common email clients 13 March 2015 TR-33 - Analysis - CTB-Locker / Critroni 17 February 2015 TR-32 - key-value store and NoSQL security recommendations 10 February 2015 TR-31 - GHOST / CVE-2015-0235 - glibc vulnerability - gethostbyname 29 January 2015 TR-30 - Acquisition Support Tools for Local Incident Response Teams (LIRT) 16 December 2020 TR-29 - NTP (Network Time Protocol) daemon - ntpd - critical vulnerabilities 2 January 2015 TR-28 - The SSL protocol 3.0, as used in OpenSSL through 1.0.1i and other products, are vulnerable to critical padding oracle attack - CVE-2014-3566 15 October 2014 TR-27 - GNU Bash Critical Vulnerability - CVE-2014-6271 - CVE-2014-7169 10 October 2014 TR-26 - Security Recommendations for Web Content Management Systems and Web Servers 28 April 2015 TR-25 - Analysis - Turla/Pfinet/Snake/Uroburos/Pfinet 10 July 2014 TR-24 - Analysis - Destory RAT family 3 June 2014 TR-23 - Analysis - NetWiredRC malware 26 November 2014 TR-22 - Practical Recommendations for Readiness to Handle Computer Security Incidents 15 December 2020 TR-21 - OpenSSL Heartbeat Critical Vulnerability 17 April 2014 TR-20 - Port evolution: a software to find the shady IP profiles in Netflow 18 February 2014 Training And Technical Courses Catalogue 2014 29 January 2014 TR-19 - UDP Protocols Security - Recommendations To Avoid or Limit DDoS amplification 8 July 2015 TR-18 - PBX and VoIP Security - Recommendations 19 February 2014 TR-17 - Java.Tomdep (Apache Tomcat Malware) - Information, Detection and Recommendation 22 November 2013 TR-16 - HoneyBot Services - Client Data Collection 14 October 2013 TR-15 - Hand of Thief/Hanthie Linux Malware - Detection and Remediation 29 August 2013 TR-14 - Analysis of a stage 3 Miniduke malware sample 3 July 2014 TR-13 - Malware analysis report of a Backdoor.Snifula variant 29 May 2013 TR-12 - Analysis of a PlugX malware variant used for targeted attacks 17 January 2014 TR-11 - Security Flaws in Universal Plug and Play (UPnP) 30 January 2013 TR-10 - Red October / Sputnik malware 16 January 2013 TR-09 - Malware Discovery and potential Removal (Windows 7) 31 August 2012 CIRCL 2011 trend report 29 August 2012 TR-08 - CIRCL automatic launch object detection for Mac OS X 23 January 2015 TR-07 - HOWTO find SMTP headers in common Email clients 13 March 2015 TR-06 - DigiNotar incident and general SSL/TLS security consequences 7 September 2011 TR-05 - SSL/TLS Security of Servers in Luxembourg 22 August 2011 Academic Publications Publication Authors Date Mapping CVEs to MITRE ATT&amp;amp;CK Techniques: A Curated Gold-Set Classifier and the Limits of LLM-Assisted Label Expansion (PDF) Cédric Bonhomme, Alexandre Dulaunoy 28 July 2026 GCVE: A Decentralized Model for Vulnerability Identification, Publication, and Operational Enrichment (PDF) Alexandre Dulaunoy 30 May 2026 Modeling Sparse and Bursty Vulnerability Sightings: Forecasting Under Data Constraints (PDF) Cédric Bonhomme, Alexandre Dulaunoy 17 April 2026 VLAI: A RoBERTa-Based Model for Automated Vulnerability Severity Classification (PDF) Cédric Bonhomme, Alexandre Dulaunoy 4 July 2025 Active and Passive Collection of SSH key material for cyber threat intelligence (PDF, DOI) Alexandre Dulaunoy, Jean-Louis Huynen, Aurélien Thirion 11 April 2022 Taxonomy driven indicator scoring in MISP threat intelligence platforms (PDF) Sami Mokaddem, Gérard Wagener, Alexandre Dulaunoy, András Iklódy 8 February 2019 Decaying Indicators of Compromise (PDF) András Iklódy, Gérard Wagener, Alexandre Dulaunoy, Sami Mokaddem, Cynthia Wagner 29 March 2018 MISP: The design and implementation of a collaborative threat intelligence sharing platform (PDF) Cynthia Wagner, Alexandre Dulaunoy, Gérard Wagener, András Iklódy 2016 Torinj: Automated Exploitation Malware Targeting Tor Users (PDF) Gérard Wagener, Alexandre Dulaunoy, Radu State 14 August 2012 Presentations Description Last update GCVE at Vulnopticon 2026 28th September 2026 GCVE Workshop before Vulnopticon 2026 - slides and materials 23rd September 2026 CSIRT Tooling: Best Practices in Developing, Maintaining and Distributing Open Source Tools 8th November 2018 Fail frequently to avoid disaster or how to organically build a threat intel sharing standard 7th December 2017 How to better understand DDoS attacks from a post-mortem analysis perspective using backscatter traffic Luxembourg Internet Days 2017 15th November 2017 DDoS and Attribution: Observations of Attacks against North Korea 15th November 2017 IoT dinosaurs - don’t die out 24 October 2017 An extended analysis of an IoT malware from a blackhole network 1st June 2017 Challenges for law firms: IT security threats and incidents for law firms - practical examples 12 May 2017 Honeypots Observations and Their Usefulness 15 March 2017 Introduction to Forensic at the #cybersecurity4success conference 3 October 2016 Data Mining in Incident Response - Challenges and Opportunities 13 May 2016 Experiences with Paste-Monitoring 18 March 2016 Four years of practical information sharing MISP &amp;amp; Threat Sharing 25th February 2016 Information Sharing and Taxonomies Practical Classification of Threat Indicators using MISP 26th January 2016 Improving Data Sharing to Increase Security Research Opportunities 2nd November 2015 cve-search - a free software to collect, search and analyse common vulnerabilities and exposures in software 9th October 2015 Protect your data, protect your life. Data Destruction Day 22nd September 2015 New ZeroMQ functionality in MISP 2nd July 2015 Sharing Threat Indicators and Security Ranking, an opportunity for the Internet Community 18 November 2014 Attackers benefit from sharing information. How can you benefit, too? at ICTSpring 4 July 2014 The void - An interesting place for network security monitoring Cynthia Wagner, Marc Stiefer (RESTENA), Alexandre Dulaunoy, Gérard Wagener (CIRCL) at TNC 2014 19 May 2014 Information Sharing Cornerstone in Incident Detection and Handling at DBIR presentation in Paris 15 May 2014 Darknet and Black Hole Monitoring a Journey into Typographic Errors at Honeynet Project Workshop in Warsaw 12 May 2014 An Overview of Security Incidents Targeting Citizen How the Attackers Are Deceiving Us? 15 March 2014 Passive DNS - Common Output Format 14 February 2014 Who targets the journalists? and how? A review of the attack surface in our digital society 7 February 2014 MISP or How to Share Efficiently IOCs Within a Country 26 July 2013 BGP Ranking Scoring ASNs Based on Their Potential Maliciousness 23 June 2013 ASMATRA: Ranking ASs Providing Transit Service to Malware Hosters 29 May 2013 Another Perspective to IP-Darkspace Analysis 29 January 2013 The Digital First Aid Kit The Digital First Aid Kit aims to provide preliminary support for people facing the most common types of digital threats. The Kit offers a set of self-diagnostic tools for citizen, human rights defenders, bloggers, activists and journalists fac ing attacks themselves, as well as providing guidelines for digital first responders to assist a person under threat.&amp;#xA;</summary>
    <content type="html">&amp;lt;h2 id=&amp;#34;publications&amp;#34;&amp;gt;Publications&amp;lt;/h2&amp;gt;&amp;#xA;&amp;lt;table&amp;gt;&amp;#xA;&amp;#x9;&amp;lt;thead&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;th style=&amp;#34;text-align: left&amp;#34;&amp;gt;Description&amp;lt;/th&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;th style=&amp;#34;text-align: center&amp;#34;&amp;gt;Last update&amp;lt;/th&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;/tr&amp;gt;&amp;#xA;&amp;#x9;&amp;lt;/thead&amp;gt;&amp;#xA;&amp;#x9;&amp;lt;tbody&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: left&amp;#34;&amp;gt;&amp;lt;a href=&amp;#34;./tr-100&amp;#34;&amp;gt;TR-100 - Multiple Critical Vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway&amp;lt;/a&amp;gt;&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: center&amp;#34;&amp;gt;27th September 2026&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;/tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: left&amp;#34;&amp;gt;&amp;lt;a href=&amp;#34;./tr-99&amp;#34;&amp;gt;TR-99 - Phishing Campaign Targeting Hotel Customers in Luxembourg&amp;lt;/a&amp;gt;&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: center&amp;#34;&amp;gt;1st June 2026&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;/tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: left&amp;#34;&amp;gt;&amp;lt;a href=&amp;#34;./tr-98&amp;#34;&amp;gt;TR-98 - Security Advisory Ivanti Endpoint Manager Mobile (EPMM) (CVE-2026-1281 &amp;amp;amp; CVE-2026-1340) - Active Exploitation&amp;lt;/a&amp;gt;&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: center&amp;#34;&amp;gt;9 February 2026&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;/tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: left&amp;#34;&amp;gt;&amp;lt;a href=&amp;#34;./tr-97&amp;#34;&amp;gt;TR-97 - Supply Chain Compromise Propagating Through the npm Ecosystem (Shai-Hulud)&amp;lt;/a&amp;gt;&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: center&amp;#34;&amp;gt;28 November 2025&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;/tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: left&amp;#34;&amp;gt;&amp;lt;a href=&amp;#34;./tr-96&amp;#34;&amp;gt;TR-96 - Multiple Vulnerabilities in F5 Devices and Products - Impact and Mitigation&amp;lt;/a&amp;gt;&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: center&amp;#34;&amp;gt;15 October 2025&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;/tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: left&amp;#34;&amp;gt;&amp;lt;a href=&amp;#34;./tr-95&amp;#34;&amp;gt;TR-95 - Critical vulnerability - Deserialization of untrusted data in on-premises Microsoft SharePoint Server allows an unauthorized attacker to execute code over a network. CVE-2025-53770 - CVE-2025-53771&amp;lt;/a&amp;gt;&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: center&amp;#34;&amp;gt;20 July 2025&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;/tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: left&amp;#34;&amp;gt;&amp;lt;a href=&amp;#34;./ai-strategy/&amp;#34;&amp;gt;CIRCL AI Strategy&amp;lt;/a&amp;gt;&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: center&amp;#34;&amp;gt;20 June 2025&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;/tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: left&amp;#34;&amp;gt;&amp;lt;a href=&amp;#34;./tr-94&amp;#34;&amp;gt;TR-94 - Ongoing Phishing Campaigns Targeting Microsoft 365 Tenants Lacking Multi-Factor Authentication&amp;lt;/a&amp;gt;&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: center&amp;#34;&amp;gt;22 May 2025&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;/tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: left&amp;#34;&amp;gt;&amp;lt;a href=&amp;#34;./tr-93&amp;#34;&amp;gt;TR-93 - Financial transaction fraud after system compromise via Remote Management and Monitoring tools&amp;lt;/a&amp;gt;&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: center&amp;#34;&amp;gt;26 February 2025&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;/tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: left&amp;#34;&amp;gt;&amp;lt;a href=&amp;#34;./tr-93/de/&amp;#34;&amp;gt;TR-93 (de) - Finanzbetrug nach Systemkompromittierung über Remote-Management- und Monitoring-Tools&amp;lt;/a&amp;gt;&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: center&amp;#34;&amp;gt;26 February 2025&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;/tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: left&amp;#34;&amp;gt;&amp;lt;a href=&amp;#34;./tr-93/fr/&amp;#34;&amp;gt;TR-93 (fr) - Fraude financière après compromission du système via des outils de gestion et de surveillance à distance&amp;lt;/a&amp;gt;&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: center&amp;#34;&amp;gt;26 February 2025&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;/tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: left&amp;#34;&amp;gt;&amp;lt;a href=&amp;#34;./tr-92&amp;#34;&amp;gt;TR-92 - Unused Domain Names and the Risks of Missing DNS SPF Records&amp;lt;/a&amp;gt;&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: center&amp;#34;&amp;gt;22 January 2025&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;/tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: left&amp;#34;&amp;gt;&amp;lt;a href=&amp;#34;./tr-91&amp;#34;&amp;gt;TR-91 - Vulnerability identified as CVE-2024-0012, affecting Palo Alto Networks PAN-OS software&amp;lt;/a&amp;gt;&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: center&amp;#34;&amp;gt;20 December 2024&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;/tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: left&amp;#34;&amp;gt;&amp;lt;a href=&amp;#34;./tr-90&amp;#34;&amp;gt;TR-90 - Vulnerability identified as CVE-2023-34990, affecting Fortinet FortiWLM&amp;lt;/a&amp;gt;&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: center&amp;#34;&amp;gt;20 December 2024&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;/tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: left&amp;#34;&amp;gt;&amp;lt;a href=&amp;#34;./tr-89&amp;#34;&amp;gt;TR-89 - Guidelines for Notifying CSIRT/CERT of Red Teaming and Penetration Testing Exercises&amp;lt;/a&amp;gt;&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: center&amp;#34;&amp;gt;12 November 2024&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;/tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: left&amp;#34;&amp;gt;&amp;lt;a href=&amp;#34;./tr-88&amp;#34;&amp;gt;TR-88 - Motivation, procedure and rationale for leaked credential notifications&amp;lt;/a&amp;gt;&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: center&amp;#34;&amp;gt;30 August 2024&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;/tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: left&amp;#34;&amp;gt;&amp;lt;a href=&amp;#34;./learning-from-falcon-sensor-outage/&amp;#34;&amp;gt;Learning from the Recent Windows/Falcon Sensor Outage: Causes and Potential Improvement Strategies in Linux Using Open Source Solutions&amp;lt;/a&amp;gt;&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: center&amp;#34;&amp;gt;23rd July 2024&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;/tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: left&amp;#34;&amp;gt;&amp;lt;a href=&amp;#34;./tr-87&amp;#34;&amp;gt;TR-87 - CrowdStrike Agent causing BSOD loop on Windows - Faulty Update on Falcon Sensor&amp;lt;/a&amp;gt;&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: center&amp;#34;&amp;gt;19th July 2024&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;/tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: left&amp;#34;&amp;gt;&amp;lt;a href=&amp;#34;./tr-86&amp;#34;&amp;gt;TR-86 - Check Point VPN Information Disclosure (CVE-2024-24919) - Actively Exploited&amp;lt;/a&amp;gt;&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: center&amp;#34;&amp;gt;31st May 2024&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;/tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: left&amp;#34;&amp;gt;&amp;lt;a href=&amp;#34;./tr-85&amp;#34;&amp;gt;TR-85 - Three vulnerabilities in Cisco ASA software/appliance and FTD software being exploited&amp;lt;/a&amp;gt;&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: center&amp;#34;&amp;gt;25th April 2024&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;/tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: left&amp;#34;&amp;gt;&amp;lt;a href=&amp;#34;./tr-84&amp;#34;&amp;gt;TR-84 - PAN-OS (Palo Alto Networks) OS Command Injection Vulnerability in GlobalProtect Gateway - CVE-2024-3400&amp;lt;/a&amp;gt;&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: center&amp;#34;&amp;gt;12th April 2024&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;/tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: left&amp;#34;&amp;gt;&amp;lt;a href=&amp;#34;./tr-83&amp;#34;&amp;gt;TR-83 - Linux Boot Hardening HOWTO&amp;lt;/a&amp;gt;&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: center&amp;#34;&amp;gt;3rd April 2024&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;/tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: left&amp;#34;&amp;gt;&amp;lt;a href=&amp;#34;./tr-82&amp;#34;&amp;gt;TR-82 - backdoor discovered in xz-utils - CVE-2024-3094&amp;lt;/a&amp;gt;&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: center&amp;#34;&amp;gt;30th March 2024&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;/tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: left&amp;#34;&amp;gt;&amp;lt;a href=&amp;#34;./tr-81&amp;#34;&amp;gt;TR-81 - Critical FortiOS vulnerabilities in sslvpnd and fgfmd &amp;lt;/a&amp;gt;&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: center&amp;#34;&amp;gt;9 February 2024&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;/tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: left&amp;#34;&amp;gt;&amp;lt;a href=&amp;#34;./tr-80&amp;#34;&amp;gt;TR-80 - Targeted SMS and fake phone center call targeting financial/banking services&amp;lt;/a&amp;gt;&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: center&amp;#34;&amp;gt;7 February 2024&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;/tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: left&amp;#34;&amp;gt;&amp;lt;a href=&amp;#34;./tr-79&amp;#34;&amp;gt;TR-79 - AnyDesk Incident and Potential Associated Supply Chain Attack&amp;lt;/a&amp;gt;&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: center&amp;#34;&amp;gt;5 February 2024&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;/tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: left&amp;#34;&amp;gt;&amp;lt;a href=&amp;#34;./tr-78&amp;#34;&amp;gt;TR-78 - CVE-2023-46805 (Authentication Bypass) &amp;amp;amp; CVE-2024-21887 (Command Injection) for Ivanti Connect Secure and Ivanti Policy Secure Gateways&amp;lt;/a&amp;gt;&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: center&amp;#34;&amp;gt;11 January 2024&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;/tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: left&amp;#34;&amp;gt;&amp;lt;a href=&amp;#34;./tr-77&amp;#34;&amp;gt;TR-77 - Spear phishing and voice call scams targeting corporate executives and their accounting department&amp;lt;/a&amp;gt;&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: center&amp;#34;&amp;gt;30 August 2023&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;/tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: left&amp;#34;&amp;gt;&amp;lt;a href=&amp;#34;./tr-76&amp;#34;&amp;gt;TR-76 - Multiple high severity vulnerabilities in CODESYS V3 SDK could lead to RCE or DoS&amp;lt;/a&amp;gt;&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: center&amp;#34;&amp;gt;14 August 2023&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;/tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: left&amp;#34;&amp;gt;&amp;lt;a href=&amp;#34;./tr-75&amp;#34;&amp;gt;TR-75 - Unauthenticated remote code execution vulnerability in NetScaler ADC (formerly Citrix ADC) and NetScaler Gateway (formerly Citrix Gateway) - CVE-2023-3519&amp;lt;/a&amp;gt;&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: center&amp;#34;&amp;gt;21 July 2023&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;/tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: left&amp;#34;&amp;gt;&amp;lt;a href=&amp;#34;./tr-74&amp;#34;&amp;gt;TR-74 - A heap-based buffer overflow vulnerability (CWE-122) in FortiOS - CVE-2023-27997&amp;lt;/a&amp;gt;&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: center&amp;#34;&amp;gt;5 July 2023&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;/tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: left&amp;#34;&amp;gt;&amp;lt;a href=&amp;#34;./tr-73&amp;#34;&amp;gt;TR-73 - Ransomware FAQ&amp;lt;/a&amp;gt;&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: center&amp;#34;&amp;gt;7 March 2023&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;/tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: left&amp;#34;&amp;gt;&amp;lt;a href=&amp;#34;./tr-72&amp;#34;&amp;gt;TR-72 - Vulnerable Microsoft Exchange server metrics leading to alarming situation&amp;lt;/a&amp;gt;&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: center&amp;#34;&amp;gt;21 February 2023&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;/tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: left&amp;#34;&amp;gt;&amp;lt;a href=&amp;#34;./tr-71&amp;#34;&amp;gt;TR-71 - FortiOS - heap-based buffer overflow in sslvpnd (exploited) - FortiOS SSL-VPN - CVE-2022-42475&amp;lt;/a&amp;gt;&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: center&amp;#34;&amp;gt;13 December 2022&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;/tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: left&amp;#34;&amp;gt;&amp;lt;a href=&amp;#34;./tr-70&amp;#34;&amp;gt;TR-70 - Vulnerabilities in Microsoft Exchange CVE-2022-41040 - CVE-2022-41082&amp;lt;/a&amp;gt;&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: center&amp;#34;&amp;gt;30 September 2022&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;/tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: left&amp;#34;&amp;gt;&amp;lt;a href=&amp;#34;./tr-69&amp;#34;&amp;gt;TR-69 - How to choose an ICT supplier from a security perspective&amp;lt;/a&amp;gt;&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: center&amp;#34;&amp;gt;13 June 2022&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;/tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: left&amp;#34;&amp;gt;&amp;lt;a href=&amp;#34;./tr-68&amp;#34;&amp;gt;TR-68 - Best practices in times of tense geopolitical situations&amp;lt;/a&amp;gt;&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: center&amp;#34;&amp;gt;28 February 2022&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;/tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: left&amp;#34;&amp;gt;&amp;lt;a href=&amp;#34;./tr-67&amp;#34;&amp;gt;TR-67 - local privilege escalation vulnerability in polkit&amp;amp;rsquo;s pkexec utility&amp;lt;/a&amp;gt;&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: center&amp;#34;&amp;gt;26 January 2022&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;/tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: left&amp;#34;&amp;gt;&amp;lt;a href=&amp;#34;./tr-66&amp;#34;&amp;gt;TR-66 - Webservers with mod_status like debug modules publicly available leak information&amp;lt;/a&amp;gt;&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: center&amp;#34;&amp;gt;15 December 2021&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;/tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: left&amp;#34;&amp;gt;&amp;lt;a href=&amp;#34;./tr-65&amp;#34;&amp;gt;TR-65 - Vulnerabilities and Exploitation of Log4j (Remote code injection in Log4j)&amp;lt;/a&amp;gt;&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: center&amp;#34;&amp;gt;10 December 2021&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;/tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: left&amp;#34;&amp;gt;&amp;lt;a href=&amp;#34;./tr-64&amp;#34;&amp;gt;TR-64 - Exploited Exchange Servers - Mails with links to malware from known/valid senders&amp;lt;/a&amp;gt;&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: center&amp;#34;&amp;gt;10 November 2021&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;/tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: left&amp;#34;&amp;gt;&amp;lt;a href=&amp;#34;./tr-63&amp;#34;&amp;gt;TR-63 - Vulnerabilities and Exploitation of Pulse Connect Secure&amp;lt;/a&amp;gt;&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: center&amp;#34;&amp;gt;21 April 2021&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;/tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: left&amp;#34;&amp;gt;&amp;lt;a href=&amp;#34;./tr-62&amp;#34;&amp;gt;TR-62 - Leak of Facebook Data from 533 Million Users&amp;lt;/a&amp;gt;&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: center&amp;#34;&amp;gt;6 April 2021&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;/tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: left&amp;#34;&amp;gt;&amp;lt;a href=&amp;#34;./tr-61&amp;#34;&amp;gt;TR-61 - Critical vulnerabilities in Microsoft Exchange&amp;lt;/a&amp;gt;&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: center&amp;#34;&amp;gt;12 March 2021&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;/tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: left&amp;#34;&amp;gt;&amp;lt;a href=&amp;#34;./tr-60&amp;#34;&amp;gt;TR-60 - Phishing - Effects and precautions&amp;lt;/a&amp;gt;&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: center&amp;#34;&amp;gt;26 June 2020&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;/tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: left&amp;#34;&amp;gt;&amp;lt;a href=&amp;#34;./tr-59&amp;#34;&amp;gt;TR-59 - Remote Work - In times of a crisis&amp;lt;/a&amp;gt;&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: center&amp;#34;&amp;gt;18 March 2020&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;/tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: left&amp;#34;&amp;gt;&amp;lt;a href=&amp;#34;./tr-58&amp;#34;&amp;gt;TR-58 - CVE-2020-0796 - Critical vulnerability in Microsoft SMBv3 - status and mitigation&amp;lt;/a&amp;gt;&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: center&amp;#34;&amp;gt;11 March 2020&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;/tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: left&amp;#34;&amp;gt;&amp;lt;a href=&amp;#34;./tr-57&amp;#34;&amp;gt;TR-57 - Ransomware - Effects and precautions&amp;lt;/a&amp;gt;&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: center&amp;#34;&amp;gt;10 December 2019&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;/tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: left&amp;#34;&amp;gt;&amp;lt;a href=&amp;#34;./tr-56&amp;#34;&amp;gt;TR-56 - HTTP Strict Transport Security&amp;lt;/a&amp;gt;&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: center&amp;#34;&amp;gt;19 March 2019&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;/tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: left&amp;#34;&amp;gt;&amp;lt;a href=&amp;#34;./tr-55&amp;#34;&amp;gt;TR-55 - SquashFu - an alternate Open Source Backup solution, resilient to Crypto Ransomware attacks&amp;lt;/a&amp;gt;&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: center&amp;#34;&amp;gt;12 September 2018&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;/tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: left&amp;#34;&amp;gt;&amp;lt;a href=&amp;#34;./tr-54&amp;#34;&amp;gt;TR-54 - Sextortion scam emails - I know your password&amp;lt;/a&amp;gt;&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: center&amp;#34;&amp;gt;3 August 2018&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;/tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: left&amp;#34;&amp;gt;&amp;lt;a href=&amp;#34;./tr-53&amp;#34;&amp;gt;TR-53 - Statement about WHOIS and GDPR&amp;lt;/a&amp;gt;&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: center&amp;#34;&amp;gt;12 April 2018&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;/tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: left&amp;#34;&amp;gt;&amp;lt;a href=&amp;#34;./tr-52&amp;#34;&amp;gt;TR-52 - Forensic Analysis of an HID Attack&amp;lt;/a&amp;gt;&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: center&amp;#34;&amp;gt;5 February 2018&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;/tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: left&amp;#34;&amp;gt;&amp;lt;a href=&amp;#34;./tr-51&amp;#34;&amp;gt;TR-51 - How to react to fraudulent acts of third party invoicing or requesting funds without showing any purchase order&amp;lt;/a&amp;gt;&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: center&amp;#34;&amp;gt;23 November 2017&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;/tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: left&amp;#34;&amp;gt;&amp;lt;a href=&amp;#34;./tr-50&amp;#34;&amp;gt;TR-50 - WPA2 handshake traffic can be manipulated to induce nonce and session key reuse&amp;lt;/a&amp;gt;&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: center&amp;#34;&amp;gt;16 October 2017&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;/tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: left&amp;#34;&amp;gt;&amp;lt;a href=&amp;#34;./tr-49&amp;#34;&amp;gt;TR-49 - CVE-2017-7494 - A critical vulnerability in Samba - remote code execution from a writable share&amp;lt;/a&amp;gt;&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: center&amp;#34;&amp;gt;26 May 2017&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;/tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: left&amp;#34;&amp;gt;&amp;lt;a href=&amp;#34;./tr-48&amp;#34;&amp;gt;TR-48 - Cyber-Threats Indicators Sharing, security-related actionable information and future of Personal Data Protection framework in the EU - MISP and GDPR&amp;lt;/a&amp;gt;&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: center&amp;#34;&amp;gt;6 March 2017&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;/tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: left&amp;#34;&amp;gt;&amp;lt;a href=&amp;#34;./tr-47&amp;#34;&amp;gt;TR-47 - Recommendations regarding Abuse handling for ISPs and registrars&amp;lt;/a&amp;gt;&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: center&amp;#34;&amp;gt;23 February 2017&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;/tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: left&amp;#34;&amp;gt;&amp;lt;a href=&amp;#34;./tr-46&amp;#34;&amp;gt;TR-46 - Information Leaks Affecting Luxembourg and Recommendations&amp;lt;/a&amp;gt;&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: center&amp;#34;&amp;gt;17 February 2017&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;/tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: left&amp;#34;&amp;gt;&amp;lt;a href=&amp;#34;./tr-45&amp;#34;&amp;gt;TR-45 - Data recovery techniques&amp;lt;/a&amp;gt;&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: center&amp;#34;&amp;gt;12 May 2016&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;/tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: left&amp;#34;&amp;gt;&amp;lt;a href=&amp;#34;./tr-44&amp;#34;&amp;gt;TR-44 - Information security - laws and specific rulings in the Grand Duchy of Luxembourg&amp;lt;/a&amp;gt;&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: center&amp;#34;&amp;gt;15 March 2016&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;/tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: left&amp;#34;&amp;gt;&amp;lt;a href=&amp;#34;./tr-43&amp;#34;&amp;gt;TR-43 - Installing MPSS 3.6.1 to use a Intel Xeon Phi Coprocessor on Ubuntu Trusty 14.04 LTS&amp;lt;/a&amp;gt;&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: center&amp;#34;&amp;gt;11 January 2016&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;/tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: left&amp;#34;&amp;gt;&amp;lt;a href=&amp;#34;./tr-42/&amp;#34;&amp;gt;TR-42 - CVE-2015-7755 - CVE-2015-7756 - Critical vulnerabilities in Juniper ScreenOS&amp;lt;/a&amp;gt;&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: center&amp;#34;&amp;gt;21 December 2015&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;/tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: left&amp;#34;&amp;gt;&amp;lt;a href=&amp;#34;./tr-41/de/&amp;#34;&amp;gt;TR-41 (de) - Crypto Ransomware - Vorsichtsmaßnahmen und Verhalten im Infektionsfall&amp;lt;/a&amp;gt;&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: center&amp;#34;&amp;gt;19 May 2016&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;/tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: left&amp;#34;&amp;gt;&amp;lt;a href=&amp;#34;./tr-41/fr/&amp;#34;&amp;gt;TR-41 (fr) - Crypto Ransomware - Défenses proactives et de réponse sur incident&amp;lt;/a&amp;gt;&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: center&amp;#34;&amp;gt;19 May 2016&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;/tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: left&amp;#34;&amp;gt;&amp;lt;a href=&amp;#34;./tr-41/&amp;#34;&amp;gt;TR-41 - Crypto Ransomware - Proactive defenses and incident response&amp;lt;/a&amp;gt;&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: center&amp;#34;&amp;gt;13 May 2017&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;/tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: left&amp;#34;&amp;gt;&amp;lt;a href=&amp;#34;./tr-40/&amp;#34;&amp;gt;TR-40 - Allaple worm activity in 2015 and long-term persistence of worm (malware) in Local Area Networks&amp;lt;/a&amp;gt;&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: center&amp;#34;&amp;gt;24 September 2015&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;/tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: left&amp;#34;&amp;gt;&amp;lt;a href=&amp;#34;./tr-39&amp;#34;&amp;gt;TR-39 - CIRCL-SOPs Standard Operational Procedures&amp;lt;/a&amp;gt;&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: center&amp;#34;&amp;gt;30 July 2015&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;/tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: left&amp;#34;&amp;gt;&amp;lt;a href=&amp;#34;./tr-38&amp;#34;&amp;gt;TR-38 - Attacks targeting enterprise banking solutions - recommendations and remediations&amp;lt;/a&amp;gt;&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: center&amp;#34;&amp;gt;9 May 2017&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;/tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: left&amp;#34;&amp;gt;&amp;lt;a href=&amp;#34;./tr-37&amp;#34;&amp;gt;TR-37 - VENOM / CVE-2015-3456 - Critical vulnerability in QEMU Floppy Disk Controller (FDC) emulation&amp;lt;/a&amp;gt;&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: center&amp;#34;&amp;gt;14 May 2015&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;/tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: left&amp;#34;&amp;gt;&amp;lt;a href=&amp;#34;./tr-36/&amp;#34;&amp;gt;TR-36 - Example setup of WordPress with static export&amp;lt;/a&amp;gt;&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: center&amp;#34;&amp;gt;28 April 2015&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;/tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: left&amp;#34;&amp;gt;&amp;lt;a href=&amp;#34;./tr-34&amp;#34;&amp;gt;TR-34 - How to view and extract raw messages in common email clients&amp;lt;/a&amp;gt;&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: center&amp;#34;&amp;gt;13 March 2015&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;/tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: left&amp;#34;&amp;gt;&amp;lt;a href=&amp;#34;./tr-33&amp;#34;&amp;gt;TR-33 - Analysis - CTB-Locker / Critroni&amp;lt;/a&amp;gt;&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: center&amp;#34;&amp;gt;17 February 2015&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;/tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: left&amp;#34;&amp;gt;&amp;lt;a href=&amp;#34;./tr-32&amp;#34;&amp;gt;TR-32 - key-value store and NoSQL security recommendations&amp;lt;/a&amp;gt;&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: center&amp;#34;&amp;gt;10 February 2015&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;/tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: left&amp;#34;&amp;gt;&amp;lt;a href=&amp;#34;./tr-31&amp;#34;&amp;gt;TR-31 - GHOST / CVE-2015-0235 - glibc vulnerability - gethostbyname&amp;lt;/a&amp;gt;&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: center&amp;#34;&amp;gt;29 January 2015&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;/tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: left&amp;#34;&amp;gt;&amp;lt;a href=&amp;#34;./tr-30&amp;#34;&amp;gt;TR-30 - Acquisition Support Tools for Local Incident Response Teams (LIRT)&amp;lt;/a&amp;gt;&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: center&amp;#34;&amp;gt;16 December 2020&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;/tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: left&amp;#34;&amp;gt;&amp;lt;a href=&amp;#34;./tr-29&amp;#34;&amp;gt;TR-29 - NTP (Network Time Protocol) daemon - ntpd - critical vulnerabilities&amp;lt;/a&amp;gt;&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: center&amp;#34;&amp;gt;2 January 2015&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;/tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: left&amp;#34;&amp;gt;&amp;lt;a href=&amp;#34;./tr-28&amp;#34;&amp;gt;TR-28 - The SSL protocol 3.0, as used in OpenSSL through 1.0.1i and other products, are vulnerable to critical padding oracle attack - CVE-2014-3566&amp;lt;/a&amp;gt;&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: center&amp;#34;&amp;gt;15 October 2014&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;/tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: left&amp;#34;&amp;gt;&amp;lt;a href=&amp;#34;./tr-27&amp;#34;&amp;gt;TR-27 - GNU Bash Critical Vulnerability - CVE-2014-6271 - CVE-2014-7169&amp;lt;/a&amp;gt;&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: center&amp;#34;&amp;gt;10 October 2014&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;/tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: left&amp;#34;&amp;gt;&amp;lt;a href=&amp;#34;./tr-26&amp;#34;&amp;gt;TR-26 - Security Recommendations for Web Content Management Systems and Web Servers&amp;lt;/a&amp;gt;&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: center&amp;#34;&amp;gt;28 April 2015&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;/tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: left&amp;#34;&amp;gt;&amp;lt;a href=&amp;#34;./tr-25&amp;#34;&amp;gt;TR-25 - Analysis - Turla/Pfinet/Snake/Uroburos/Pfinet&amp;lt;/a&amp;gt;&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: center&amp;#34;&amp;gt;10 July 2014&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;/tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: left&amp;#34;&amp;gt;&amp;lt;a href=&amp;#34;./tr-24&amp;#34;&amp;gt;TR-24 - Analysis - Destory RAT family&amp;lt;/a&amp;gt;&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: center&amp;#34;&amp;gt;3 June 2014&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;/tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: left&amp;#34;&amp;gt;&amp;lt;a href=&amp;#34;./tr-23&amp;#34;&amp;gt;TR-23 - Analysis - NetWiredRC malware&amp;lt;/a&amp;gt;&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: center&amp;#34;&amp;gt;26 November 2014&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;/tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: left&amp;#34;&amp;gt;&amp;lt;a href=&amp;#34;./tr-22&amp;#34;&amp;gt;TR-22 - Practical Recommendations for Readiness to Handle Computer Security Incidents&amp;lt;/a&amp;gt;&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: center&amp;#34;&amp;gt;15 December 2020&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;/tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: left&amp;#34;&amp;gt;&amp;lt;a href=&amp;#34;./tr-21&amp;#34;&amp;gt;TR-21 - OpenSSL Heartbeat Critical Vulnerability&amp;lt;/a&amp;gt;&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: center&amp;#34;&amp;gt;17 April 2014&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;/tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: left&amp;#34;&amp;gt;&amp;lt;a href=&amp;#34;./tr-20/&amp;#34;&amp;gt;TR-20 - Port evolution: a software to find the shady IP profiles in Netflow&amp;lt;/a&amp;gt;&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: center&amp;#34;&amp;gt; 18 February 2014&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;/tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: left&amp;#34;&amp;gt;&amp;lt;a href=&amp;#34;/assets/files/circl-training-2014.pdf&amp;#34;&amp;gt;Training And Technical Courses Catalogue 2014&amp;lt;/a&amp;gt;&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: center&amp;#34;&amp;gt; 29 January 2014&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;/tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: left&amp;#34;&amp;gt;&amp;lt;a href=&amp;#34;./tr-19/&amp;#34;&amp;gt;TR-19 - UDP Protocols Security - Recommendations To Avoid or Limit DDoS amplification&amp;lt;/a&amp;gt;&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: center&amp;#34;&amp;gt; 8 July 2015&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;/tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: left&amp;#34;&amp;gt;&amp;lt;a href=&amp;#34;./tr-18/&amp;#34;&amp;gt;TR-18 - PBX and VoIP Security - Recommendations&amp;lt;/a&amp;gt;&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: center&amp;#34;&amp;gt; 19 February 2014&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;/tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: left&amp;#34;&amp;gt;&amp;lt;a href=&amp;#34;./tr-17/&amp;#34;&amp;gt;TR-17 - Java.Tomdep (Apache Tomcat Malware) - Information, Detection and Recommendation&amp;lt;/a&amp;gt;&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: center&amp;#34;&amp;gt; 22 November 2013&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;/tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: left&amp;#34;&amp;gt;&amp;lt;a href=&amp;#34;./tr-16/&amp;#34;&amp;gt;TR-16 - HoneyBot Services - Client Data Collection&amp;lt;/a&amp;gt;&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: center&amp;#34;&amp;gt; 14 October 2013&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;/tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: left&amp;#34;&amp;gt;&amp;lt;a href=&amp;#34;./tr-15/&amp;#34;&amp;gt;TR-15 - Hand of Thief/Hanthie Linux Malware - Detection and Remediation&amp;lt;/a&amp;gt;&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: center&amp;#34;&amp;gt; 29 August 2013&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;/tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: left&amp;#34;&amp;gt;&amp;lt;a href=&amp;#34;./tr-14/&amp;#34;&amp;gt;TR-14 - Analysis of a stage 3 Miniduke malware sample&amp;lt;/a&amp;gt;&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: center&amp;#34;&amp;gt; 3 July 2014&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;/tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: left&amp;#34;&amp;gt;&amp;lt;a href=&amp;#34;./tr-13/&amp;#34;&amp;gt;TR-13 - Malware analysis report of a Backdoor.Snifula variant&amp;lt;/a&amp;gt;&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: center&amp;#34;&amp;gt;29 May 2013 &amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;/tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: left&amp;#34;&amp;gt;&amp;lt;a href=&amp;#34;./tr-12/&amp;#34;&amp;gt;TR-12 - Analysis of a PlugX malware variant used for targeted attacks&amp;lt;/a&amp;gt;&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: center&amp;#34;&amp;gt;17 January 2014&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;/tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: left&amp;#34;&amp;gt;&amp;lt;a href=&amp;#34;./tr-11/&amp;#34;&amp;gt;TR-11 - Security Flaws in Universal Plug and Play (UPnP)&amp;lt;/a&amp;gt;&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: center&amp;#34;&amp;gt;30 January 2013&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;/tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: left&amp;#34;&amp;gt;&amp;lt;a href=&amp;#34;./tr-10/&amp;#34;&amp;gt;TR-10 - Red October / Sputnik malware&amp;lt;/a&amp;gt;&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: center&amp;#34;&amp;gt;16 January 2013&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;/tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: left&amp;#34;&amp;gt;&amp;lt;a href=&amp;#34;./tr-09/&amp;#34;&amp;gt;TR-09 - Malware Discovery and potential Removal (Windows 7)&amp;lt;/a&amp;gt;&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: center&amp;#34;&amp;gt;31 August 2012&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;/tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: left&amp;#34;&amp;gt;&amp;lt;a href=&amp;#34;/assets/files/CIRCL-trendreport-2011.pdf&amp;#34;&amp;gt;CIRCL 2011 trend report&amp;lt;/a&amp;gt;&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: center&amp;#34;&amp;gt;29 August 2012&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;/tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: left&amp;#34;&amp;gt;&amp;lt;a href=&amp;#34;./tr-08/&amp;#34;&amp;gt;TR-08 - CIRCL automatic launch object detection for Mac OS X&amp;lt;/a&amp;gt;&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: center&amp;#34;&amp;gt;23 January 2015&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;/tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: left&amp;#34;&amp;gt;&amp;lt;a href=&amp;#34;./tr-07/&amp;#34;&amp;gt;TR-07 - HOWTO find SMTP headers in common Email clients&amp;lt;/a&amp;gt;&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: center&amp;#34;&amp;gt;13 March 2015&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;/tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: left&amp;#34;&amp;gt;&amp;lt;a href=&amp;#34;./tr-06/&amp;#34;&amp;gt;TR-06 - DigiNotar incident and general SSL/TLS security consequences&amp;lt;/a&amp;gt;&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: center&amp;#34;&amp;gt;7 September 2011&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;/tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: left&amp;#34;&amp;gt;&amp;lt;a href=&amp;#34;./tr-05/&amp;#34;&amp;gt;TR-05 - SSL/TLS Security of Servers in Luxembourg&amp;lt;/a&amp;gt;&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: center&amp;#34;&amp;gt;22 August 2011&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;/tr&amp;gt;&amp;#xA;&amp;#x9;&amp;lt;/tbody&amp;gt;&amp;#xA;&amp;lt;/table&amp;gt;&amp;#xA;&amp;lt;h2 id=&amp;#34;academic-publications&amp;#34;&amp;gt;Academic Publications&amp;lt;/h2&amp;gt;&amp;#xA;&amp;lt;table&amp;gt;&amp;#xA;&amp;#x9;&amp;lt;thead&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;th style=&amp;#34;text-align: left&amp;#34;&amp;gt;Publication&amp;lt;/th&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;th style=&amp;#34;text-align: left&amp;#34;&amp;gt;Authors&amp;lt;/th&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;th style=&amp;#34;text-align: center&amp;#34;&amp;gt;Date&amp;lt;/th&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;/tr&amp;gt;&amp;#xA;&amp;#x9;&amp;lt;/thead&amp;gt;&amp;#xA;&amp;#x9;&amp;lt;tbody&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: left&amp;#34;&amp;gt;&amp;lt;a href=&amp;#34;https://arxiv.org/abs/2607.25572&amp;#34;&amp;gt;Mapping CVEs to MITRE ATT&amp;amp;amp;CK Techniques: A Curated Gold-Set Classifier and the Limits of LLM-Assisted Label Expansion&amp;lt;/a&amp;gt; (&amp;lt;a href=&amp;#34;https://arxiv.org/pdf/2607.25572&amp;#34;&amp;gt;PDF&amp;lt;/a&amp;gt;)&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: left&amp;#34;&amp;gt;Cédric Bonhomme, Alexandre Dulaunoy&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: center&amp;#34;&amp;gt;28 July 2026&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;/tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: left&amp;#34;&amp;gt;&amp;lt;a href=&amp;#34;https://arxiv.org/abs/2606.00856&amp;#34;&amp;gt;GCVE: A Decentralized Model for Vulnerability Identification, Publication, and Operational Enrichment&amp;lt;/a&amp;gt; (&amp;lt;a href=&amp;#34;https://arxiv.org/pdf/2606.00856&amp;#34;&amp;gt;PDF&amp;lt;/a&amp;gt;)&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: left&amp;#34;&amp;gt;Alexandre Dulaunoy&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: center&amp;#34;&amp;gt;30 May 2026&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;/tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: left&amp;#34;&amp;gt;&amp;lt;a href=&amp;#34;https://arxiv.org/abs/2604.16038&amp;#34;&amp;gt;Modeling Sparse and Bursty Vulnerability Sightings: Forecasting Under Data Constraints&amp;lt;/a&amp;gt; (&amp;lt;a href=&amp;#34;https://arxiv.org/pdf/2604.16038&amp;#34;&amp;gt;PDF&amp;lt;/a&amp;gt;)&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: left&amp;#34;&amp;gt;Cédric Bonhomme, Alexandre Dulaunoy&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: center&amp;#34;&amp;gt;17 April 2026&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;/tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: left&amp;#34;&amp;gt;&amp;lt;a href=&amp;#34;https://arxiv.org/abs/2507.03607&amp;#34;&amp;gt;VLAI: A RoBERTa-Based Model for Automated Vulnerability Severity Classification&amp;lt;/a&amp;gt; (&amp;lt;a href=&amp;#34;https://arxiv.org/pdf/2507.03607&amp;#34;&amp;gt;PDF&amp;lt;/a&amp;gt;)&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: left&amp;#34;&amp;gt;Cédric Bonhomme, Alexandre Dulaunoy&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: center&amp;#34;&amp;gt;4 July 2025&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;/tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: left&amp;#34;&amp;gt;&amp;lt;a href=&amp;#34;https://arxiv.org/abs/2204.04922&amp;#34;&amp;gt;Active and Passive Collection of SSH key material for cyber threat intelligence&amp;lt;/a&amp;gt; (&amp;lt;a href=&amp;#34;https://arxiv.org/pdf/2204.04922&amp;#34;&amp;gt;PDF&amp;lt;/a&amp;gt;, &amp;lt;a href=&amp;#34;https://doi.org/10.1145/3491262&amp;#34;&amp;gt;DOI&amp;lt;/a&amp;gt;)&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: left&amp;#34;&amp;gt;Alexandre Dulaunoy, Jean-Louis Huynen, Aurélien Thirion&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: center&amp;#34;&amp;gt;11 April 2022&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;/tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: left&amp;#34;&amp;gt;&amp;lt;a href=&amp;#34;https://arxiv.org/abs/1902.03914&amp;#34;&amp;gt;Taxonomy driven indicator scoring in MISP threat intelligence platforms&amp;lt;/a&amp;gt; (&amp;lt;a href=&amp;#34;https://arxiv.org/pdf/1902.03914&amp;#34;&amp;gt;PDF&amp;lt;/a&amp;gt;)&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: left&amp;#34;&amp;gt;Sami Mokaddem, Gérard Wagener, Alexandre Dulaunoy, András Iklódy&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: center&amp;#34;&amp;gt;8 February 2019&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;/tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: left&amp;#34;&amp;gt;&amp;lt;a href=&amp;#34;https://arxiv.org/abs/1803.11052&amp;#34;&amp;gt;Decaying Indicators of Compromise&amp;lt;/a&amp;gt; (&amp;lt;a href=&amp;#34;https://arxiv.org/pdf/1803.11052&amp;#34;&amp;gt;PDF&amp;lt;/a&amp;gt;)&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: left&amp;#34;&amp;gt;András Iklódy, Gérard Wagener, Alexandre Dulaunoy, Sami Mokaddem, Cynthia Wagner&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: center&amp;#34;&amp;gt;29 March 2018&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;/tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: left&amp;#34;&amp;gt;&amp;lt;a href=&amp;#34;https://scholar.google.com/citations?view_op=view_citation&amp;amp;amp;hl=en&amp;amp;amp;user=SxxEvVMAAAAJ&amp;amp;amp;citation_for_view=SxxEvVMAAAAJ:XoXfffV-tXoC&amp;#34;&amp;gt;MISP: The design and implementation of a collaborative threat intelligence sharing platform&amp;lt;/a&amp;gt; (&amp;lt;a href=&amp;#34;https://dl.acm.org/doi/pdf/10.1145/2994539.2994542&amp;#34;&amp;gt;PDF&amp;lt;/a&amp;gt;)&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: left&amp;#34;&amp;gt;Cynthia Wagner, Alexandre Dulaunoy, Gérard Wagener, András Iklódy&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: center&amp;#34;&amp;gt;2016&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;/tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: left&amp;#34;&amp;gt;&amp;lt;a href=&amp;#34;https://arxiv.org/abs/1208.2877&amp;#34;&amp;gt;Torinj: Automated Exploitation Malware Targeting Tor Users&amp;lt;/a&amp;gt; (&amp;lt;a href=&amp;#34;https://arxiv.org/pdf/1208.2877&amp;#34;&amp;gt;PDF&amp;lt;/a&amp;gt;)&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: left&amp;#34;&amp;gt;Gérard Wagener, Alexandre Dulaunoy, Radu State&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: center&amp;#34;&amp;gt;14 August 2012&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;/tr&amp;gt;&amp;#xA;&amp;#x9;&amp;lt;/tbody&amp;gt;&amp;#xA;&amp;lt;/table&amp;gt;&amp;#xA;&amp;lt;h2 id=&amp;#34;presentations&amp;#34;&amp;gt;Presentations&amp;lt;/h2&amp;gt;&amp;#xA;&amp;lt;table&amp;gt;&amp;#xA;&amp;#x9;&amp;lt;thead&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;th style=&amp;#34;text-align: left&amp;#34;&amp;gt;Description&amp;lt;/th&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;th style=&amp;#34;text-align: center&amp;#34;&amp;gt;Last update&amp;lt;/th&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;/tr&amp;gt;&amp;#xA;&amp;#x9;&amp;lt;/thead&amp;gt;&amp;#xA;&amp;#x9;&amp;lt;tbody&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: left&amp;#34;&amp;gt;&amp;lt;a href=&amp;#34;https://gcve.eu/2026/09/28/gcve-at-vulnopticon-2026/&amp;#34;&amp;gt;GCVE at Vulnopticon 2026&amp;lt;/a&amp;gt;&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: center&amp;#34;&amp;gt;28th September 2026&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;/tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: left&amp;#34;&amp;gt;&amp;lt;a href=&amp;#34;https://gcve.eu/2026/09/23/gcve-workshop-before-vulnopticon-2026-slides-and-materials/&amp;#34;&amp;gt;GCVE Workshop before Vulnopticon 2026 - slides and materials&amp;lt;/a&amp;gt;&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: center&amp;#34;&amp;gt;23rd September 2026&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;/tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: left&amp;#34;&amp;gt;&amp;lt;a href=&amp;#34;/assets/files/csirt-tooling-policy.pdf&amp;#34;&amp;gt;CSIRT Tooling: Best Practices in Developing, Maintaining and Distributing Open Source Tools&amp;lt;/a&amp;gt;&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: center&amp;#34;&amp;gt;8th November 2018&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;/tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: left&amp;#34;&amp;gt;&amp;lt;a href=&amp;#34;/assets/files/20171207-FIRST-OASIS-CTI-Prague.pdf&amp;#34;&amp;gt;Fail frequently to avoid disaster or how to organically build a threat intel sharing standard&amp;lt;/a&amp;gt;&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: center&amp;#34;&amp;gt;7th December 2017&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;/tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: left&amp;#34;&amp;gt;&amp;lt;a href=&amp;#34;/assets/files/20171115-LIDS-DDOS-workshop.pdf&amp;#34;&amp;gt;How to better understand DDoS attacks from a post-mortem analysis perspective using backscatter traffic Luxembourg Internet Days 2017&amp;lt;/a&amp;gt;&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: center&amp;#34;&amp;gt;15th November 2017&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;/tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: left&amp;#34;&amp;gt;&amp;lt;a href=&amp;#34;/assets/files/20171115-LIDS-DDOS-NorthKorea.pdf&amp;#34;&amp;gt;DDoS and Attribution: Observations of Attacks against North Korea&amp;lt;/a&amp;gt;&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: center&amp;#34;&amp;gt;15th November 2017&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;/tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: left&amp;#34;&amp;gt;&amp;lt;a href=&amp;#34;/assets/files/20171024-meetup-datascience.pdf&amp;#34;&amp;gt;IoT dinosaurs - don’t die out&amp;lt;/a&amp;gt;&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: center&amp;#34;&amp;gt;24 October 2017&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;/tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: left&amp;#34;&amp;gt;&amp;lt;a href=&amp;#34;/assets/files/tnc17_paper_Fullpaper-IoTBlackholeCW.pdf&amp;#34;&amp;gt;An extended analysis of an IoT malware from a blackhole network&amp;lt;/a&amp;gt;&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: center&amp;#34;&amp;gt;1st June 2017&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;/tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: left&amp;#34;&amp;gt;&amp;lt;a href=&amp;#34;/files/20170512-Legalink.pdf&amp;#34;&amp;gt;Challenges for law firms: IT security threats and incidents for law firms - practical examples&amp;lt;/a&amp;gt;&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: center&amp;#34;&amp;gt;12 May 2017&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;/tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: left&amp;#34;&amp;gt;&amp;lt;a href=&amp;#34;/assets/files/circl-isaca-lux-20170315.pdf&amp;#34;&amp;gt;Honeypots Observations and Their Usefulness&amp;lt;/a&amp;gt;&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: center&amp;#34;&amp;gt;15 March 2017&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;/tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: left&amp;#34;&amp;gt;&amp;lt;a href=&amp;#34;/assets/files/hamm-forensic-2016.pdf&amp;#34;&amp;gt;Introduction to Forensic at the #cybersecurity4success conference&amp;lt;/a&amp;gt;&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: center&amp;#34;&amp;gt;3 October 2016&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;/tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: left&amp;#34;&amp;gt;&amp;lt;a href=&amp;#34;/assets/files/circl-datamining-incidentresponse.pdf&amp;#34;&amp;gt;Data Mining in Incident Response - Challenges and Opportunities&amp;lt;/a&amp;gt;&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: center&amp;#34;&amp;gt;13 May 2016&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;/tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: left&amp;#34;&amp;gt;&amp;lt;a href=&amp;#34;/assets/files/201603owasp_circl.pdf&amp;#34;&amp;gt;Experiences with Paste-Monitoring&amp;lt;/a&amp;gt;&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: center&amp;#34;&amp;gt;18 March 2016&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;/tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: left&amp;#34;&amp;gt;&amp;lt;a href=&amp;#34;/assets/files/2016-FIRST-TC-Munich-MISP-Threat-Sharing.pdf&amp;#34;&amp;gt;Four years of practical information sharing MISP &amp;amp;amp; Threat Sharing&amp;lt;/a&amp;gt;&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: center&amp;#34;&amp;gt;25th February 2016&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;/tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: left&amp;#34;&amp;gt;&amp;lt;a href=&amp;#34;/assets/files/2016-FIRST-MISP-taxonomies.pdf&amp;#34;&amp;gt;Information Sharing and Taxonomies Practical Classification of Threat Indicators using MISP&amp;lt;/a&amp;gt;&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: center&amp;#34;&amp;gt;26th January 2016&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;/tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: left&amp;#34;&amp;gt;&amp;lt;a href=&amp;#34;/assets/files/circl-eupi-ncsra2015.pdf&amp;#34;&amp;gt;Improving Data Sharing to Increase Security Research Opportunities&amp;lt;/a&amp;gt;&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: center&amp;#34;&amp;gt;2nd November 2015&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;/tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: left&amp;#34;&amp;gt;&amp;lt;a href=&amp;#34;/assets/files/brucon2015-cve-search.pdf&amp;#34;&amp;gt;cve-search - a free software to collect, search and analyse common vulnerabilities and exposures in software&amp;lt;/a&amp;gt;&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: center&amp;#34;&amp;gt;9th October 2015&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;/tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: left&amp;#34;&amp;gt;&amp;lt;a href=&amp;#34;/assets/files/20150919-DataDestructionDay.pdf&amp;#34;&amp;gt;Protect your data, protect your life. Data Destruction Day&amp;lt;/a&amp;gt;&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: center&amp;#34;&amp;gt;22nd September 2015&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;/tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: left&amp;#34;&amp;gt;&amp;lt;a href=&amp;#34;/assets/files/circl-misp-zmq.pdf&amp;#34;&amp;gt;New ZeroMQ functionality in MISP&amp;lt;/a&amp;gt;&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: center&amp;#34;&amp;gt;2nd July 2015&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;/tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: left&amp;#34;&amp;gt;&amp;lt;a href=&amp;#34;/assets/files/InternetRanking.pdf&amp;#34;&amp;gt;Sharing Threat Indicators and Security Ranking, an opportunity for the Internet Community&amp;lt;/a&amp;gt;&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: center&amp;#34;&amp;gt;18 November 2014&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;/tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: left&amp;#34;&amp;gt;&amp;lt;a href=&amp;#34;/assets/files/ictspring2014-attackers-infosharing.pdf&amp;#34;&amp;gt;Attackers benefit from sharing information. How can you benefit, too?&amp;lt;/a&amp;gt; at ICTSpring&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: center&amp;#34;&amp;gt;4 July 2014&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;/tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: left&amp;#34;&amp;gt;&amp;lt;a href=&amp;#34;http://www.terena.org/publications/tnc2014-proceedings/12-cynthia-wagner-Darkspace.pdf&amp;#34;&amp;gt;The void - An interesting place for network security monitoring&amp;lt;/a&amp;gt; Cynthia Wagner, Marc Stiefer (RESTENA), Alexandre Dulaunoy, Gérard Wagener (CIRCL) at &amp;lt;a href=&amp;#34;http://www.terena.org/publications/tnc2014-proceedings/&amp;#34;&amp;gt;TNC 2014&amp;lt;/a&amp;gt;&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: center&amp;#34;&amp;gt;19 May 2014&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;/tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: left&amp;#34;&amp;gt;&amp;lt;a href=&amp;#34;/assets/files/raphael-vinot-circl-DBIR-paris-20140515.pdf&amp;#34;&amp;gt;Information Sharing Cornerstone in Incident Detection and Handling&amp;lt;/a&amp;gt; at DBIR presentation in Paris&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: center&amp;#34;&amp;gt;15 May 2014&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;/tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: left&amp;#34;&amp;gt;&amp;lt;a href=&amp;#34;/assets/files/circl-blackhole-honeynetworkshop2014.pdf&amp;#34;&amp;gt;Darknet and Black Hole Monitoring a Journey into Typographic Errors&amp;lt;/a&amp;gt; at Honeynet Project Workshop in Warsaw&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: center&amp;#34;&amp;gt;12 May 2014&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;/tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: left&amp;#34;&amp;gt;&amp;lt;a href=&amp;#34;/assets/files/euparl-circl-march-2014.pdf&amp;#34;&amp;gt;An Overview of Security Incidents Targeting Citizen How the Attackers Are Deceiving Us?&amp;lt;/a&amp;gt;&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: center&amp;#34;&amp;gt;15 March 2014&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;/tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: left&amp;#34;&amp;gt;&amp;lt;a href=&amp;#34;/assets/files/tfcsirt-zurich-passivedns-circl.pdf&amp;#34;&amp;gt;Passive DNS - Common Output Format&amp;lt;/a&amp;gt;&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: center&amp;#34;&amp;gt;14 February 2014&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;/tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: left&amp;#34;&amp;gt;&amp;lt;a href=&amp;#34;/assets/files/circl-who-targets-the-journalists.pdf&amp;#34;&amp;gt;Who targets the journalists? and how?  A review of the attack surface in our digital society&amp;lt;/a&amp;gt;&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: center&amp;#34;&amp;gt;7 February 2014&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;/tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: left&amp;#34;&amp;gt;&amp;lt;a href=&amp;#34;/assets/files/CIRCL-MISP.pdf&amp;#34;&amp;gt;MISP or How to Share Efficiently IOCs Within a Country&amp;lt;/a&amp;gt;&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: center&amp;#34;&amp;gt;26 July 2013&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;/tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: left&amp;#34;&amp;gt;&amp;lt;a href=&amp;#34;/assets/files/bgp-ranking-first2013.pdf&amp;#34;&amp;gt;BGP Ranking Scoring ASNs Based on Their Potential Maliciousness&amp;lt;/a&amp;gt;&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: center&amp;#34;&amp;gt;23 June 2013&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;/tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: left&amp;#34;&amp;gt;&amp;lt;a href=&amp;#34;/assets/files/im2013-bgpranking.pdf&amp;#34;&amp;gt;ASMATRA: Ranking ASs Providing Transit Service to Malware Hosters&amp;lt;/a&amp;gt;&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: center&amp;#34;&amp;gt;29 May 2013&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;/tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: left&amp;#34;&amp;gt;&amp;lt;a href=&amp;#34;/assets/files/tf-csirt-first2013-circl-restena-blackhole.pdf&amp;#34;&amp;gt;Another Perspective to IP-Darkspace Analysis&amp;lt;/a&amp;gt;&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: center&amp;#34;&amp;gt;29 January 2013&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;/tr&amp;gt;&amp;#xA;&amp;#x9;&amp;lt;/tbody&amp;gt;&amp;#xA;&amp;lt;/table&amp;gt;&amp;#xA;&amp;lt;h2 id=&amp;#34;the-digital-first-aid-kit&amp;#34;&amp;gt;The Digital First Aid Kit&amp;lt;/h2&amp;gt;&amp;#xA;&amp;lt;p&amp;gt;The Digital First Aid Kit aims to provide preliminary support for people facing the most common types of digital threats.&amp;#xA;The Kit offers a set of self-diagnostic tools for citizen, human rights defenders, bloggers, activists and journalists fac&amp;#xA;ing attacks themselves, as well as providing guidelines for digital first responders to assist a person under threat.&amp;lt;/p&amp;gt;&amp;#xA;&amp;lt;table&amp;gt;&amp;#xA;&amp;#x9;&amp;lt;thead&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;th style=&amp;#34;text-align: left&amp;#34;&amp;gt;Description&amp;lt;/th&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;th style=&amp;#34;text-align: center&amp;#34;&amp;gt;Last update&amp;lt;/th&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;/tr&amp;gt;&amp;#xA;&amp;#x9;&amp;lt;/thead&amp;gt;&amp;#xA;&amp;#x9;&amp;lt;tbody&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: left&amp;#34;&amp;gt;&amp;lt;a href=&amp;#34;/pub/dfak/AccountHijacking/&amp;#34;&amp;gt;&amp;lt;img src=&amp;#34;/assets/images/dfak/LOGO-HIJACKING.png&amp;#34; alt=&amp;#34;Digital First Aid Kit - Account Hijacking&amp;#34;&amp;gt;&amp;lt;/a&amp;gt;&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: center&amp;#34;&amp;gt;2nd September 2014&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;/tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: left&amp;#34;&amp;gt;&amp;lt;a href=&amp;#34;/pub/dfak/DDoSMitigation/&amp;#34;&amp;gt;&amp;lt;img src=&amp;#34;/assets/images/dfak/LOGO-DDOS.png&amp;#34; alt=&amp;#34;Digital First Aid Kit - DDoS Mitigation&amp;#34;&amp;gt;&amp;lt;/a&amp;gt;&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: center&amp;#34;&amp;gt;2nd September 2014&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;/tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: left&amp;#34;&amp;gt;&amp;lt;a href=&amp;#34;/pub/dfak/DevicesSeized/&amp;#34;&amp;gt;&amp;lt;img src=&amp;#34;/assets/images/dfak/LOGO-LOST.png&amp;#34; alt=&amp;#34;Digital First Aid Kit - Devices Lost? Stolen? Seized?&amp;#34;&amp;gt;&amp;lt;/a&amp;gt;&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: center&amp;#34;&amp;gt;2nd September 2014&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;/tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: left&amp;#34;&amp;gt;&amp;lt;a href=&amp;#34;/pub/dfak/Glossary/&amp;#34;&amp;gt;&amp;lt;img src=&amp;#34;/assets/images/dfak/LOGO-GLOSSARY.png&amp;#34; alt=&amp;#34;Digital First Aid Kit - Glossary&amp;#34;&amp;gt;&amp;lt;/a&amp;gt;&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: center&amp;#34;&amp;gt;2nd September 2014&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;/tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: left&amp;#34;&amp;gt;&amp;lt;a href=&amp;#34;/pub/dfak/Malware/&amp;#34;&amp;gt;&amp;lt;img src=&amp;#34;/assets/images/dfak/LOGO-MALWARE.png&amp;#34; alt=&amp;#34;Digital First Aid Kit - Malware&amp;#34;&amp;gt;&amp;lt;/a&amp;gt;&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: center&amp;#34;&amp;gt;2nd September 2014&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;/tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: left&amp;#34;&amp;gt;&amp;lt;a href=&amp;#34;/pub/dfak/SecureCommunication&amp;#34;&amp;gt;&amp;lt;img src=&amp;#34;/assets/images/dfak/LOGO-SECURE-COM.png&amp;#34; alt=&amp;#34;Digital First Aid Kit - Secure Communication&amp;#34;&amp;gt;&amp;lt;/a&amp;gt;&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: center&amp;#34;&amp;gt;2nd September 2014&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;/tr&amp;gt;&amp;#xA;&amp;#x9;&amp;lt;/tbody&amp;gt;&amp;#xA;&amp;lt;/table&amp;gt;&amp;#xA;&amp;lt;h2 id=&amp;#34;the-digital-first-aid-kit-german-edition&amp;#34;&amp;gt;The Digital First Aid Kit (German Edition)&amp;lt;/h2&amp;gt;&amp;#xA;&amp;lt;table&amp;gt;&amp;#xA;&amp;#x9;&amp;lt;thead&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;th style=&amp;#34;text-align: left&amp;#34;&amp;gt;Description&amp;lt;/th&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;th style=&amp;#34;text-align: center&amp;#34;&amp;gt;Last update&amp;lt;/th&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;/tr&amp;gt;&amp;#xA;&amp;#x9;&amp;lt;/thead&amp;gt;&amp;#xA;&amp;#x9;&amp;lt;tbody&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: left&amp;#34;&amp;gt;&amp;lt;a href=&amp;#34;/pub/dfak/de/AccountHijacking/&amp;#34;&amp;gt;&amp;lt;img src=&amp;#34;/assets/images/dfak/LOGO-HIJACKING.png&amp;#34; alt=&amp;#34;Digital First Aid Kit - Konto-Diebstahl &amp;#34;&amp;gt;&amp;lt;/a&amp;gt;&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: center&amp;#34;&amp;gt;18th March 2015&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;/tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: left&amp;#34;&amp;gt;&amp;lt;a href=&amp;#34;/pub/dfak/de/DevicesSeized/&amp;#34;&amp;gt;&amp;lt;img src=&amp;#34;/assets/images/dfak/LOGO-LOST.png&amp;#34; alt=&amp;#34;Digital First Aid Kit - Devices Lost? Stolen? Seized?&amp;#34;&amp;gt;&amp;lt;/a&amp;gt;&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: center&amp;#34;&amp;gt;26th March 2015&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;/tr&amp;gt;&amp;#xA;&amp;#x9;&amp;lt;/tbody&amp;gt;&amp;#xA;&amp;lt;/table&amp;gt;&amp;#xA;&amp;lt;h2 id=&amp;#34;security-advisories&amp;#34;&amp;gt;Security Advisories&amp;lt;/h2&amp;gt;&amp;#xA;&amp;lt;p&amp;gt;The latest CIRCL security advisories are published by&amp;#xA;&amp;lt;a href=&amp;#34;https://vulnerability.circl.lu/&amp;#34;&amp;gt;Vulnerability-Lookup&amp;lt;/a&amp;gt;.&amp;lt;/p&amp;gt;&amp;#xA;&amp;lt;div class=&amp;#34;advisory-feed&amp;#34; data-atom-feed=&amp;#34;https://vulnerability.circl.lu/recent/gna-1.atom?date_sort=updated&amp;amp;amp;sort_order=desc&amp;#34; data-limit=&amp;#34;5&amp;#34;&amp;gt;&amp;#xA;  &amp;lt;p class=&amp;#34;advisory-feed-status&amp;#34; role=&amp;#34;status&amp;#34;&amp;gt;Loading the latest security advisories…&amp;lt;/p&amp;gt;&amp;#xA;  &amp;lt;ol class=&amp;#34;advisory-feed-list&amp;#34; aria-label=&amp;#34;Latest security advisories&amp;#34;&amp;gt;&amp;lt;/ol&amp;gt;&amp;#xA;  &amp;lt;p class=&amp;#34;advisory-feed-more&amp;#34;&amp;gt;&amp;lt;a href=&amp;#34;https://vulnerability.circl.lu/&amp;#34;&amp;gt;Browse all vulnerabilities on Vulnerability-Lookup &amp;lt;span aria-hidden=&amp;#34;true&amp;#34;&amp;gt;↗&amp;lt;/span&amp;gt;&amp;lt;/a&amp;gt;&amp;lt;/p&amp;gt;&amp;#xA;&amp;lt;/div&amp;gt;&amp;#xA;&amp;lt;script src=&amp;#34;/js/atom-reader.js&amp;#34; defer&amp;gt;&amp;lt;/script&amp;gt;&amp;#xA;&amp;lt;h2 id=&amp;#34;other-publications&amp;#34;&amp;gt;Other publications&amp;lt;/h2&amp;gt;&amp;#xA;&amp;lt;table&amp;gt;&amp;#xA;&amp;#x9;&amp;lt;thead&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;th style=&amp;#34;text-align: left&amp;#34;&amp;gt;Description&amp;lt;/th&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;th style=&amp;#34;text-align: center&amp;#34;&amp;gt;Last update&amp;lt;/th&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;/tr&amp;gt;&amp;#xA;&amp;#x9;&amp;lt;/thead&amp;gt;&amp;#xA;&amp;#x9;&amp;lt;tbody&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: left&amp;#34;&amp;gt;&amp;lt;a href=&amp;#34;/pub/coordinated-vulnerability-disclosure/&amp;#34;&amp;gt;Coordinated Vulnerability Disclosure (CVD) Policy&amp;lt;/a&amp;gt;&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: center&amp;#34;&amp;gt;18th June 2025&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;/tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: left&amp;#34;&amp;gt;&amp;lt;a href=&amp;#34;/pub/taxonomy&amp;#34;&amp;gt;CIRCL Taxonomy - Schemes of Classification in Incident Response and Detection&amp;lt;/a&amp;gt;&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: center&amp;#34;&amp;gt;15th March 2018&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;/tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: left&amp;#34;&amp;gt;&amp;lt;a href=&amp;#34;/pub/responsible-vulnerability-disclosure/&amp;#34;&amp;gt;Responsible Vulnerability Disclosure&amp;lt;/a&amp;gt;&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: center&amp;#34;&amp;gt;10th January 2015&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;/tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: left&amp;#34;&amp;gt;&amp;lt;a href=&amp;#34;/pub/traffic-light-protocol/&amp;#34;&amp;gt;Traffic Light Protocol (TLP) - Classification and Sharing of Sensitive Information&amp;lt;/a&amp;gt;&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: center&amp;#34;&amp;gt;March 2014&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;/tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: left&amp;#34;&amp;gt;&amp;lt;a href=&amp;#34;/pub/request-for-proposals/&amp;#34;&amp;gt;CIRCL - Request for Proposals&amp;lt;/a&amp;gt;&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td style=&amp;#34;text-align: center&amp;#34;&amp;gt;Regularly Updated&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;/tr&amp;gt;&amp;#xA;&amp;#x9;&amp;lt;/tbody&amp;gt;&amp;#xA;&amp;lt;/table&amp;gt;&amp;#xA;</content>
  </entry>
  <entry>
    <title>Operational guidance for incident handling</title>
    <link href="https://www.circl.lu/pub/operational-guidance-for-incident-handling/" rel="alternate" type="text/html" />
    <id>https://www.circl.lu/pub/operational-guidance-for-incident-handling/</id>
    <published>2026-09-28T00:00:00Z</published>
    <updated>2026-09-28T00:00:00Z</updated>
    <summary>The High Commission for National Protection (“HCPN”), acting in its role as the Agence Nationale de la Sécurité des Systèmes d’Information (“ANSSI”) and as the Governmental Computer Security Incident Response Team (“GOVCERT.LU”), the Computer Incident Response Center Luxembourg (“CIRCL”), the Commission de Surveillance du Secteur Financier (“CSSF”), and the Institut Luxembourgeois de Régulation (“ILR”) are pleased to announce that a team of cyber security experts of the mentioned institutions jointly wrote a set of rulebooks related to operational guidance for incident handling.&amp;#xA;</summary>
    <content type="html">&amp;lt;p&amp;gt;The High Commission for National Protection (“HCPN”), acting in its role as the Agence Nationale de la Sécurité des Systèmes d’Information (“ANSSI”) and as the Governmental Computer Security Incident Response Team (“GOVCERT.LU”), the Computer Incident Response Center Luxembourg (“CIRCL”), the Commission de Surveillance du Secteur Financier (“CSSF”), and the Institut Luxembourgeois de Régulation (“ILR”) are pleased to announce that a team of cyber security experts of the mentioned institutions jointly wrote a set of rulebooks related to operational guidance for incident handling.&amp;lt;/p&amp;gt;&amp;#xA;&amp;lt;h2 id=&amp;#34;why-were-these-rulebooks-developed&amp;#34;&amp;gt;Why were these rulebooks developed?&amp;lt;/h2&amp;gt;&amp;#xA;&amp;lt;p&amp;gt;The &amp;lt;a href=&amp;#34;/assets/files/operational-guidance-incident-handling.pdf&amp;#34;&amp;gt;rulebooks&amp;lt;/a&amp;gt; were developed in the context of Article 14(5) of the Loi du 5 mai 2026 concernant des mesures destinées à assurer un niveau élevé de cybersécurité (“NIS2 Act”).&amp;lt;/p&amp;gt;&amp;#xA;&amp;lt;p&amp;gt;Under Article 14(5), following receipt of an initial notification of a significant incident, the competent authority provides the notifying entity with an initial response and, at the entity’s request, guidance or operational advice on the implementation of possible mitigation measures. Such guidance is provided by the competent authority in cooperation with the relevant Computer Security Incident Response Team (“CSIRT”), which may also provide additional technical support at the entity’s request.&amp;lt;/p&amp;gt;&amp;#xA;&amp;lt;p&amp;gt;The rulebooks are intended to translate this operational guidance into practical and readily usable resources, helping entities facing a cybersecurity incident to rapidly identify and implement appropriate mitigation measures and to facilitate their interaction with the competent authority and the relevant CSIRT.&amp;lt;/p&amp;gt;&amp;#xA;&amp;lt;h2 id=&amp;#34;who-are-they-intended-for&amp;#34;&amp;gt;Who are they intended for?&amp;lt;/h2&amp;gt;&amp;#xA;&amp;lt;p&amp;gt;The rulebooks are primarily intended for public and private sector entities subject to the NIS2 Act. They provide operational guidance for handling cybersecurity incidents, in particular in the context of a significant incident notified to the competent authority in accordance with the notification mechanism established by the NIS2 Act.&amp;lt;/p&amp;gt;&amp;#xA;&amp;lt;p&amp;gt;They are especially relevant for technical teams, cybersecurity officers and other staff responsible for incident handling and response.&amp;lt;/p&amp;gt;&amp;#xA;&amp;lt;p&amp;gt;The rulebooks may also serve as a practical reference for other organisations facing a cybersecurity incident or seeking to prepare and improve their incident response procedures.&amp;lt;/p&amp;gt;&amp;#xA;&amp;lt;h2 id=&amp;#34;what-do-the-rulebooks-provide&amp;#34;&amp;gt;What do the rulebooks provide?&amp;lt;/h2&amp;gt;&amp;#xA;&amp;lt;p&amp;gt;The &amp;lt;a href=&amp;#34;/assets/files/operational-guidance-incident-handling.pdf&amp;#34;&amp;gt;rulebooks&amp;lt;/a&amp;gt; provide practical, step-by-step guidance for handling specific types of cybersecurity incidents. Each rulebook addresses a particular incident scenario and structures the response across the main stages of incident handling.&amp;lt;/p&amp;gt;&amp;#xA;&amp;lt;p&amp;gt;Depending on the type of incident, the guidance covers:&amp;lt;/p&amp;gt;&amp;#xA;&amp;lt;ul&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;typical initial detection, including common signs, alerts and indicators that may reveal an incident;&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;immediate response and containment measures to limit the impact and prevent further compromise;&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;investigation steps to assess the scope, origin and consequences of the incident;&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;remediation measures to address the causes of the incident and restore a secure environment;&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;evidence keeping, including relevant information and technical artefacts that should be preserved;&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;post-incident activities to reduce the likelihood or impact of similar incidents in the future;&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;communication measures, including communication with affected users, management or other relevant parties; and&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;key watchpoints highlighting specific risks or issues requiring particular attention.&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;/ul&amp;gt;&amp;#xA;&amp;lt;p&amp;gt;The rulebooks are designed as practical reference guides that can be consulted during an incident, enabling technical and incident response teams to quickly identify relevant actions and measures for the specific situation they are facing.&amp;lt;/p&amp;gt;&amp;#xA;&amp;lt;h2 id=&amp;#34;a-collaborative-and-evolving-resource&amp;#34;&amp;gt;A collaborative and evolving resource&amp;lt;/h2&amp;gt;&amp;#xA;&amp;lt;p&amp;gt;The rulebooks were jointly developed by cybersecurity experts from the HCPN/ANSSI/GOVCERT.LU, CIRCL, CSSF and ILR.&amp;lt;/p&amp;gt;&amp;#xA;&amp;lt;p&amp;gt;To foster cyber security community feedback and ensure quality over time, the rulebooks are &amp;lt;a href=&amp;#34;https://github.com/nis2-rulebooks/nis2-rulebooks/&amp;#34;&amp;gt;hosted on GitHub&amp;lt;/a&amp;gt; in addition to the &amp;lt;a href=&amp;#34;/assets/files/operational-guidance-incident-handling.pdf&amp;#34;&amp;gt;PDF document&amp;lt;/a&amp;gt;. The contributions of cyber security professional are very welcomed and will be considered by the authors in future updates.&amp;lt;/p&amp;gt;&amp;#xA;&amp;lt;h2 id=&amp;#34;disclaimer&amp;#34;&amp;gt;Disclaimer&amp;lt;/h2&amp;gt;&amp;#xA;&amp;lt;p&amp;gt;These rulebooks are solely intended to be used as a practical guidance by an entity facing a cybersecurity incident and looking for immediate assistance from the competent authorities and the Computer Security Incident Response Teams (“CSIRT”). They have been written in the context of Article 14(5) of the Loi du 5 mai 2026 concernant des mesures destinées à assurer un niveau élevé de cybersécurité (“NIS2 Act”), and in accordance with the missions assigned to the HCPN in its role as ANSSI under Article 3, paragraph 1ter, of the Loi modifiée du 23 juillet 2016 portant création du Haut-Commissariat à la Protection nationale.&amp;lt;/p&amp;gt;&amp;#xA;&amp;lt;p&amp;gt;These rulebooks must not be used as a substitute for any policies or procedures in force at the entities. Neither the HCPN, the CIRCL, the CSSF, nor the ILR can be held liable in the event of malfunction or unforeseen circumstances or for any damages resulting from the use of the guidance.&amp;lt;/p&amp;gt;&amp;#xA;&amp;lt;p&amp;gt;These rulebooks do not address the legal obligations to be fulfilled by the concerned entities (e.g., file a complaint, notification of incidents to the CSSF, the ILR, and the Commission Nationale pour la Protection des Données (CNPD), etc.).&amp;lt;/p&amp;gt;&amp;#xA;</content>
  </entry>
  <entry>
    <title>TR-100 Multiple Critical Vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway</title>
    <link href="https://www.circl.lu/pub/tr-100/" rel="alternate" type="text/html" />
    <id>https://www.circl.lu/pub/tr-100/</id>
    <published>2026-09-27T00:00:00Z</published>
    <updated>2026-09-27T00:00:00Z</updated>
    <summary>Summary Multiple vulnerabilities have been disclosed in Citrix NetScaler ADC (formerly Citrix ADC) and Citrix NetScaler Gateway (formerly Citrix Gateway).&amp;#xA;The vulnerabilities include unauthenticated remote code execution, memory corruption, HTTP request smuggling, security-policy bypass, denial of service and TCP Initial Sequence Number (ISN) prediction issues.&amp;#xA;Two vulnerabilities, CVE-2026-88771 and CVE-2026-88772, have a CVSS v4.0 base score of 9.5 and can result in remote code execution. According to Citrix and multiple observations from third-parties, exploitation of these vulnerabilities has been observed against unmitigated NetScaler deployments.&amp;#xA;</summary>
    <content type="html">&amp;lt;h2 id=&amp;#34;summary&amp;#34;&amp;gt;Summary&amp;lt;/h2&amp;gt;&amp;#xA;&amp;lt;p&amp;gt;Multiple vulnerabilities have been disclosed in &amp;lt;strong&amp;gt;Citrix NetScaler ADC&amp;lt;/strong&amp;gt; (formerly Citrix ADC) and &amp;lt;strong&amp;gt;Citrix NetScaler Gateway&amp;lt;/strong&amp;gt; (formerly Citrix Gateway).&amp;lt;/p&amp;gt;&amp;#xA;&amp;lt;p&amp;gt;The vulnerabilities include unauthenticated remote code execution, memory corruption, HTTP request smuggling, security-policy bypass, denial of service and TCP Initial Sequence Number (ISN) prediction issues.&amp;lt;/p&amp;gt;&amp;#xA;&amp;lt;p&amp;gt;Two vulnerabilities, &amp;lt;strong&amp;gt;&amp;lt;a href=&amp;#34;https://vulnerability.circl.lu/vuln/CVE-2026-88771&amp;#34;&amp;gt;CVE-2026-88771&amp;lt;/a&amp;gt;&amp;lt;/strong&amp;gt; and &amp;lt;strong&amp;gt;&amp;lt;a href=&amp;#34;https://vulnerability.circl.lu/vuln/CVE-2026-88772&amp;#34;&amp;gt;CVE-2026-88772&amp;lt;/a&amp;gt;&amp;lt;/strong&amp;gt;, have a CVSS v4.0 base score of &amp;lt;strong&amp;gt;9.5&amp;lt;/strong&amp;gt; and can result in remote code execution. According to Citrix and multiple observations from third-parties, exploitation of these vulnerabilities has been observed against unmitigated NetScaler deployments.&amp;lt;/p&amp;gt;&amp;#xA;&amp;lt;p&amp;gt;Of particular concern, &amp;lt;strong&amp;gt;CVE-2026-88771 affects all vulnerable NetScaler ADC and NetScaler Gateway deployments, including appliances using the default configuration. No additional feature needs to be enabled for the vulnerability to be exposed.&amp;lt;/strong&amp;gt;&amp;lt;/p&amp;gt;&amp;#xA;&amp;lt;p&amp;gt;CIRCL strongly recommends administrators of affected NetScaler systems to &amp;lt;strong&amp;gt;upgrade without delay&amp;lt;/strong&amp;gt; and to investigate potentially exposed systems for signs of compromise.&amp;lt;/p&amp;gt;&amp;#xA;&amp;lt;h2 id=&amp;#34;affected-products&amp;#34;&amp;gt;Affected Products&amp;lt;/h2&amp;gt;&amp;#xA;&amp;lt;p&amp;gt;The following supported versions are affected:&amp;lt;/p&amp;gt;&amp;#xA;&amp;lt;ul&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;NetScaler ADC and NetScaler Gateway 14.1&amp;lt;/strong&amp;gt; before &amp;lt;strong&amp;gt;14.1-73.37&amp;lt;/strong&amp;gt;&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;NetScaler ADC and NetScaler Gateway 13.1&amp;lt;/strong&amp;gt; before &amp;lt;strong&amp;gt;13.1-64.23&amp;lt;/strong&amp;gt;&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;NetScaler ADC 14.1 FIPS&amp;lt;/strong&amp;gt; before &amp;lt;strong&amp;gt;14.1-73.37 FIPS&amp;lt;/strong&amp;gt;&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;NetScaler ADC 13.1 FIPS and NDcPP&amp;lt;/strong&amp;gt; before &amp;lt;strong&amp;gt;13.1-37.279&amp;lt;/strong&amp;gt;&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;/ul&amp;gt;&amp;#xA;&amp;lt;p&amp;gt;Secure Private Access Hybrid deployments using NetScaler instances are also affected and the associated NetScaler appliances must be upgraded.&amp;lt;/p&amp;gt;&amp;#xA;&amp;lt;p&amp;gt;The vulnerabilities concern &amp;lt;strong&amp;gt;customer-managed NetScaler ADC and NetScaler Gateway appliances&amp;lt;/strong&amp;gt;. Citrix-managed cloud services and Citrix-managed Adaptive Authentication are updated by Cloud Software Group.&amp;lt;/p&amp;gt;&amp;#xA;&amp;lt;h2 id=&amp;#34;vulnerabilities&amp;#34;&amp;gt;Vulnerabilities&amp;lt;/h2&amp;gt;&amp;#xA;&amp;lt;h3 id=&amp;#34;cve-2026-88771--unauthenticated-remote-code-execution&amp;#34;&amp;gt;CVE-2026-88771 — Unauthenticated Remote Code Execution&amp;lt;/h3&amp;gt;&amp;#xA;&amp;lt;p&amp;gt;A remote code execution vulnerability caused by improper input validation can allow an unauthenticated remote attacker to execute arbitrary commands.&amp;lt;/p&amp;gt;&amp;#xA;&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Precondition:&amp;lt;/strong&amp;gt; None. All affected NetScaler ADC and NetScaler Gateway deployments are concerned, including default configurations.&amp;lt;/p&amp;gt;&amp;#xA;&amp;lt;ul&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;CWE:&amp;lt;/strong&amp;gt; CWE-20 — Improper Input Validation&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;CVSS v4.0:&amp;lt;/strong&amp;gt; 9.5&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Vector:&amp;lt;/strong&amp;gt; &amp;lt;code&amp;gt;CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H&amp;lt;/code&amp;gt;&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Exploitation:&amp;lt;/strong&amp;gt; Observed in the wild&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;/ul&amp;gt;&amp;#xA;&amp;lt;p&amp;gt;This vulnerability should be considered the highest priority because exposure does not depend on an optional NetScaler feature being enabled.&amp;lt;/p&amp;gt;&amp;#xA;&amp;lt;h3 id=&amp;#34;cve-2026-88772--memory-overflow-leading-to-rce-or-dos&amp;#34;&amp;gt;CVE-2026-88772 — Memory Overflow Leading to RCE or DoS&amp;lt;/h3&amp;gt;&amp;#xA;&amp;lt;p&amp;gt;A memory overflow vulnerability can result in remote code execution or denial of service.&amp;lt;/p&amp;gt;&amp;#xA;&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Precondition:&amp;lt;/strong&amp;gt; DTLS must be enabled. DTLS is enabled by default on VPN virtual servers unless explicitly disabled.&amp;lt;/p&amp;gt;&amp;#xA;&amp;lt;ul&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;CWE:&amp;lt;/strong&amp;gt; CWE-119 — Improper Restriction of Operations within the Bounds of a Memory Buffer&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;CVSS v4.0:&amp;lt;/strong&amp;gt; 9.5&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Vector:&amp;lt;/strong&amp;gt; &amp;lt;code&amp;gt;CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H&amp;lt;/code&amp;gt;&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Exploitation:&amp;lt;/strong&amp;gt; Observed in the wild&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;/ul&amp;gt;&amp;#xA;&amp;lt;h3 id=&amp;#34;cve-2026-88773--http-request-smuggling&amp;#34;&amp;gt;CVE-2026-88773 — HTTP Request Smuggling&amp;lt;/h3&amp;gt;&amp;#xA;&amp;lt;p&amp;gt;The vulnerability allows inconsistent interpretation of HTTP requests, resulting in an HTTP request smuggling condition.&amp;lt;/p&amp;gt;&amp;#xA;&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Precondition:&amp;lt;/strong&amp;gt; HTTP functionality must be configured on the affected appliance. This includes Load Balancing, Content Switching, VPN or Authentication virtual servers using HTTP or SSL.&amp;lt;/p&amp;gt;&amp;#xA;&amp;lt;ul&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;CWE:&amp;lt;/strong&amp;gt; CWE-444 — Inconsistent Interpretation of HTTP Requests&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;CVSS v4.0:&amp;lt;/strong&amp;gt; 9.3&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Vector:&amp;lt;/strong&amp;gt; &amp;lt;code&amp;gt;CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:H/SI:H/SA:N&amp;lt;/code&amp;gt;&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;/ul&amp;gt;&amp;#xA;&amp;lt;h3 id=&amp;#34;cve-2026-88774--http-url-policy-bypass&amp;#34;&amp;gt;CVE-2026-88774 — HTTP URL Policy Bypass&amp;lt;/h3&amp;gt;&amp;#xA;&amp;lt;p&amp;gt;Improper use or interpretation of HTTP URL-based expressions can allow configured security or feature policies to be bypassed.&amp;lt;/p&amp;gt;&amp;#xA;&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Precondition:&amp;lt;/strong&amp;gt; An affected HTTP URL-based policy expression must be configured.&amp;lt;/p&amp;gt;&amp;#xA;&amp;lt;ul&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;CWE:&amp;lt;/strong&amp;gt; CWE-16 — Configuration&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;CVSS v4.0:&amp;lt;/strong&amp;gt; 7.0&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Vector:&amp;lt;/strong&amp;gt; &amp;lt;code&amp;gt;CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:H/SI:H/SA:N&amp;lt;/code&amp;gt;&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;/ul&amp;gt;&amp;#xA;&amp;lt;h3 id=&amp;#34;cve-2026-88775--memory-overflow-in-gateway-or-aaa-configurations&amp;#34;&amp;gt;CVE-2026-88775 — Memory Overflow in Gateway or AAA Configurations&amp;lt;/h3&amp;gt;&amp;#xA;&amp;lt;p&amp;gt;A memory overflow vulnerability can result in unpredictable behaviour or denial of service.&amp;lt;/p&amp;gt;&amp;#xA;&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Precondition:&amp;lt;/strong&amp;gt; NetScaler must be configured as one of the following:&amp;lt;/p&amp;gt;&amp;#xA;&amp;lt;ul&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;#xA;&amp;lt;p&amp;gt;Gateway:&amp;lt;/p&amp;gt;&amp;#xA;&amp;lt;ul&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;SSL VPN&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;ICA Proxy&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;CVPN&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;RDP Proxy&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;/ul&amp;gt;&amp;#xA;&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;#xA;&amp;lt;p&amp;gt;AAA virtual server&amp;lt;/p&amp;gt;&amp;#xA;&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;#xA;&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;CWE:&amp;lt;/strong&amp;gt; CWE-119 — Improper Restriction of Operations within the Bounds of a Memory Buffer&amp;lt;/p&amp;gt;&amp;#xA;&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;#xA;&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;CVSS v4.0:&amp;lt;/strong&amp;gt; 8.8&amp;lt;/p&amp;gt;&amp;#xA;&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;#xA;&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Vector:&amp;lt;/strong&amp;gt; &amp;lt;code&amp;gt;CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N&amp;lt;/code&amp;gt;&amp;lt;/p&amp;gt;&amp;#xA;&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;/ul&amp;gt;&amp;#xA;&amp;lt;h3 id=&amp;#34;cve-2026-88776--memory-overflow-in-oracle-load-balancing&amp;#34;&amp;gt;CVE-2026-88776 — Memory Overflow in Oracle Load Balancing&amp;lt;/h3&amp;gt;&amp;#xA;&amp;lt;p&amp;gt;A memory overflow vulnerability can lead to unpredictable behaviour or denial of service.&amp;lt;/p&amp;gt;&amp;#xA;&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Precondition:&amp;lt;/strong&amp;gt; NetScaler must be configured with a Load Balancing virtual server of type Oracle.&amp;lt;/p&amp;gt;&amp;#xA;&amp;lt;ul&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;CWE:&amp;lt;/strong&amp;gt; CWE-119 — Improper Restriction of Operations within the Bounds of a Memory Buffer&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;CVSS v4.0:&amp;lt;/strong&amp;gt; 8.8&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Vector:&amp;lt;/strong&amp;gt; &amp;lt;code&amp;gt;CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N&amp;lt;/code&amp;gt;&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;/ul&amp;gt;&amp;#xA;&amp;lt;h3 id=&amp;#34;cve-2026-88777--memory-overflow-in-non-http-l7-services&amp;#34;&amp;gt;CVE-2026-88777 — Memory Overflow in Non-HTTP L7 Services&amp;lt;/h3&amp;gt;&amp;#xA;&amp;lt;p&amp;gt;A memory overflow vulnerability can result in unpredictable behaviour or denial of service.&amp;lt;/p&amp;gt;&amp;#xA;&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Precondition:&amp;lt;/strong&amp;gt; NetScaler must be configured as an LB/CS or CGNAT-LSN/NAT64 device with a non-HTTP Layer 7 protocol feature enabled.&amp;lt;/p&amp;gt;&amp;#xA;&amp;lt;p&amp;gt;Potentially affected configurations include FTP, RTSP, DNS64 and NAT64 deployments.&amp;lt;/p&amp;gt;&amp;#xA;&amp;lt;ul&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;CWE:&amp;lt;/strong&amp;gt; CWE-119 — Improper Restriction of Operations within the Bounds of a Memory Buffer&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;CVSS v4.0:&amp;lt;/strong&amp;gt; 8.8&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Vector:&amp;lt;/strong&amp;gt; &amp;lt;code&amp;gt;CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N&amp;lt;/code&amp;gt;&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;/ul&amp;gt;&amp;#xA;&amp;lt;h3 id=&amp;#34;cve-2026-88778--tcp-initial-sequence-number-prediction&amp;#34;&amp;gt;CVE-2026-88778 — TCP Initial Sequence Number Prediction&amp;lt;/h3&amp;gt;&amp;#xA;&amp;lt;p&amp;gt;The TCP Initial Sequence Number generation mechanism can result in predictable values, potentially weakening assumptions about the integrity of TCP connections.&amp;lt;/p&amp;gt;&amp;#xA;&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Precondition:&amp;lt;/strong&amp;gt; TCP functionality is enabled and Enhanced ISN Generation is disabled.&amp;lt;/p&amp;gt;&amp;#xA;&amp;lt;ul&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;CWE:&amp;lt;/strong&amp;gt; CWE-342 — Predictable Exact Value from Previous Values&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;CVSS v4.0:&amp;lt;/strong&amp;gt; 8.8&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Vector:&amp;lt;/strong&amp;gt; &amp;lt;code&amp;gt;CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:H/VA:H/SC:L/SI:L/SA:L&amp;lt;/code&amp;gt;&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;/ul&amp;gt;&amp;#xA;&amp;lt;h2 id=&amp;#34;recommended-actions&amp;#34;&amp;gt;Recommended Actions&amp;lt;/h2&amp;gt;&amp;#xA;&amp;lt;p&amp;gt;CIRCL recommends that administrators &amp;lt;strong&amp;gt;upgrade affected NetScaler appliances as soon as possible&amp;lt;/strong&amp;gt;.&amp;lt;/p&amp;gt;&amp;#xA;&amp;lt;p&amp;gt;The following versions contain fixes:&amp;lt;/p&amp;gt;&amp;#xA;&amp;lt;table&amp;gt;&amp;#xA;&amp;#x9;&amp;lt;thead&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;th&amp;gt;Product&amp;lt;/th&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;th&amp;gt;Fixed version&amp;lt;/th&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;/tr&amp;gt;&amp;#xA;&amp;#x9;&amp;lt;/thead&amp;gt;&amp;#xA;&amp;#x9;&amp;lt;tbody&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td&amp;gt;NetScaler ADC / Gateway 14.1&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td&amp;gt;&amp;lt;strong&amp;gt;14.1-73.37 or later&amp;lt;/strong&amp;gt;&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;/tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td&amp;gt;NetScaler ADC / Gateway 13.1&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td&amp;gt;&amp;lt;strong&amp;gt;13.1-64.23 or later&amp;lt;/strong&amp;gt;&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;/tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td&amp;gt;NetScaler ADC 14.1 FIPS&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td&amp;gt;&amp;lt;strong&amp;gt;14.1-73.37 FIPS or later&amp;lt;/strong&amp;gt;&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;/tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td&amp;gt;NetScaler ADC 13.1 FIPS / NDcPP&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td&amp;gt;&amp;lt;strong&amp;gt;13.1-37.279 or later&amp;lt;/strong&amp;gt;&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;/tr&amp;gt;&amp;#xA;&amp;#x9;&amp;lt;/tbody&amp;gt;&amp;#xA;&amp;lt;/table&amp;gt;&amp;#xA;&amp;lt;p&amp;gt;Because exploitation of CVE-2026-88771 and CVE-2026-88772 has already been observed, &amp;lt;strong&amp;gt;upgrading should not be considered sufficient evidence that an appliance was not previously compromised&amp;lt;/strong&amp;gt;.&amp;lt;/p&amp;gt;&amp;#xA;&amp;lt;p&amp;gt;For Internet-facing appliances that were running an affected version, administrators should also:&amp;lt;/p&amp;gt;&amp;#xA;&amp;lt;ol&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;preserve relevant logs and forensic evidence before making significant changes where operationally possible;&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;review NetScaler and external network/security logs for suspicious activity;&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;investigate unexpected configuration, filesystem or process changes;&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;review administrative and authentication activity;&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;review activity from the appliance towards internal infrastructure;&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;use the indicators and detection mechanisms provided by Citrix;&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;follow the organisation&amp;amp;rsquo;s incident response process if compromise is suspected.&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;/ol&amp;gt;&amp;#xA;&amp;lt;p&amp;gt;External forwarding of NetScaler logs to a SIEM or other independent logging infrastructure is strongly recommended, as it can provide evidence that remains available if the appliance itself is compromised.&amp;lt;/p&amp;gt;&amp;#xA;&amp;lt;h2 id=&amp;#34;configuration-checks&amp;#34;&amp;gt;Configuration Checks&amp;lt;/h2&amp;gt;&amp;#xA;&amp;lt;p&amp;gt;Administrators can use their NetScaler configuration to identify whether additional vulnerability-specific preconditions are met.&amp;lt;/p&amp;gt;&amp;#xA;&amp;lt;h3 id=&amp;#34;cve-2026-88771&amp;#34;&amp;gt;CVE-2026-88771&amp;lt;/h3&amp;gt;&amp;#xA;&amp;lt;p&amp;gt;No configuration check is required. &amp;lt;strong&amp;gt;All affected versions meet the vulnerability precondition.&amp;lt;/strong&amp;gt;&amp;lt;/p&amp;gt;&amp;#xA;&amp;lt;h3 id=&amp;#34;cve-2026-88772&amp;#34;&amp;gt;CVE-2026-88772&amp;lt;/h3&amp;gt;&amp;#xA;&amp;lt;p&amp;gt;Review VPN and virtual-server configurations for DTLS.&amp;lt;/p&amp;gt;&amp;#xA;&amp;lt;p&amp;gt;For example:&amp;lt;/p&amp;gt;&amp;#xA;&amp;lt;div class=&amp;#34;highlight&amp;#34;&amp;gt;&amp;lt;div style=&amp;#34;background-color:#f8f8f8;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&amp;#34;&amp;gt;&amp;#xA;&amp;lt;table style=&amp;#34;border-spacing:0;padding:0;margin:0;border:0;&amp;#34;&amp;gt;&amp;lt;tr&amp;gt;&amp;lt;td style=&amp;#34;vertical-align:top;padding:0;margin:0;border:0;&amp;#34;&amp;gt;&amp;#xA;&amp;lt;pre tabindex=&amp;#34;0&amp;#34; style=&amp;#34;background-color:#f8f8f8;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&amp;#34;&amp;gt;&amp;lt;code&amp;gt;&amp;lt;span style=&amp;#34;white-space:pre;-webkit-user-select:none;user-select:none;margin-right:0.4em;padding:0 0.4em 0 0.4em;color:#7f7f7f&amp;#34;&amp;gt;1&amp;#xA;&amp;lt;/span&amp;gt;&amp;lt;/code&amp;gt;&amp;lt;/pre&amp;gt;&amp;lt;/td&amp;gt;&amp;#xA;&amp;lt;td style=&amp;#34;vertical-align:top;padding:0;margin:0;border:0;;width:100%&amp;#34;&amp;gt;&amp;#xA;&amp;lt;pre tabindex=&amp;#34;0&amp;#34; style=&amp;#34;background-color:#f8f8f8;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&amp;#34;&amp;gt;&amp;lt;code class=&amp;#34;language-text&amp;#34; data-lang=&amp;#34;text&amp;#34;&amp;gt;&amp;lt;span style=&amp;#34;display:flex;&amp;#34;&amp;gt;&amp;lt;span&amp;gt;add vpn vserver vpn1 SSL 10.0.0.0 443 -Listenpolicy NONE&amp;#xA;&amp;lt;/span&amp;gt;&amp;lt;/span&amp;gt;&amp;lt;/code&amp;gt;&amp;lt;/pre&amp;gt;&amp;lt;/td&amp;gt;&amp;lt;/tr&amp;gt;&amp;lt;/table&amp;gt;&amp;#xA;&amp;lt;/div&amp;gt;&amp;#xA;&amp;lt;/div&amp;gt;&amp;lt;p&amp;gt;DTLS is enabled by default in this configuration.&amp;lt;/p&amp;gt;&amp;#xA;&amp;lt;p&amp;gt;An explicit:&amp;lt;/p&amp;gt;&amp;#xA;&amp;lt;div class=&amp;#34;highlight&amp;#34;&amp;gt;&amp;lt;div style=&amp;#34;background-color:#f8f8f8;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&amp;#34;&amp;gt;&amp;#xA;&amp;lt;table style=&amp;#34;border-spacing:0;padding:0;margin:0;border:0;&amp;#34;&amp;gt;&amp;lt;tr&amp;gt;&amp;lt;td style=&amp;#34;vertical-align:top;padding:0;margin:0;border:0;&amp;#34;&amp;gt;&amp;#xA;&amp;lt;pre tabindex=&amp;#34;0&amp;#34; style=&amp;#34;background-color:#f8f8f8;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&amp;#34;&amp;gt;&amp;lt;code&amp;gt;&amp;lt;span style=&amp;#34;white-space:pre;-webkit-user-select:none;user-select:none;margin-right:0.4em;padding:0 0.4em 0 0.4em;color:#7f7f7f&amp;#34;&amp;gt;1&amp;#xA;&amp;lt;/span&amp;gt;&amp;lt;/code&amp;gt;&amp;lt;/pre&amp;gt;&amp;lt;/td&amp;gt;&amp;#xA;&amp;lt;td style=&amp;#34;vertical-align:top;padding:0;margin:0;border:0;;width:100%&amp;#34;&amp;gt;&amp;#xA;&amp;lt;pre tabindex=&amp;#34;0&amp;#34; style=&amp;#34;background-color:#f8f8f8;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&amp;#34;&amp;gt;&amp;lt;code class=&amp;#34;language-text&amp;#34; data-lang=&amp;#34;text&amp;#34;&amp;gt;&amp;lt;span style=&amp;#34;display:flex;&amp;#34;&amp;gt;&amp;lt;span&amp;gt;-dtls OFF&amp;#xA;&amp;lt;/span&amp;gt;&amp;lt;/span&amp;gt;&amp;lt;/code&amp;gt;&amp;lt;/pre&amp;gt;&amp;lt;/td&amp;gt;&amp;lt;/tr&amp;gt;&amp;lt;/table&amp;gt;&amp;#xA;&amp;lt;/div&amp;gt;&amp;#xA;&amp;lt;/div&amp;gt;&amp;lt;p&amp;gt;indicates that DTLS has been disabled for the VPN virtual server.&amp;lt;/p&amp;gt;&amp;#xA;&amp;lt;p&amp;gt;Also review explicitly configured DTLS virtual servers.&amp;lt;/p&amp;gt;&amp;#xA;&amp;lt;h3 id=&amp;#34;cve-2026-88773&amp;#34;&amp;gt;CVE-2026-88773&amp;lt;/h3&amp;gt;&amp;#xA;&amp;lt;p&amp;gt;Review HTTP/SSL Load Balancing, Content Switching, VPN and Authentication virtual servers:&amp;lt;/p&amp;gt;&amp;#xA;&amp;lt;div class=&amp;#34;highlight&amp;#34;&amp;gt;&amp;lt;div style=&amp;#34;background-color:#f8f8f8;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&amp;#34;&amp;gt;&amp;#xA;&amp;lt;table style=&amp;#34;border-spacing:0;padding:0;margin:0;border:0;&amp;#34;&amp;gt;&amp;lt;tr&amp;gt;&amp;lt;td style=&amp;#34;vertical-align:top;padding:0;margin:0;border:0;&amp;#34;&amp;gt;&amp;#xA;&amp;lt;pre tabindex=&amp;#34;0&amp;#34; style=&amp;#34;background-color:#f8f8f8;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&amp;#34;&amp;gt;&amp;lt;code&amp;gt;&amp;lt;span style=&amp;#34;white-space:pre;-webkit-user-select:none;user-select:none;margin-right:0.4em;padding:0 0.4em 0 0.4em;color:#7f7f7f&amp;#34;&amp;gt;1&amp;#xA;&amp;lt;/span&amp;gt;&amp;lt;span style=&amp;#34;white-space:pre;-webkit-user-select:none;user-select:none;margin-right:0.4em;padding:0 0.4em 0 0.4em;color:#7f7f7f&amp;#34;&amp;gt;2&amp;#xA;&amp;lt;/span&amp;gt;&amp;lt;span style=&amp;#34;white-space:pre;-webkit-user-select:none;user-select:none;margin-right:0.4em;padding:0 0.4em 0 0.4em;color:#7f7f7f&amp;#34;&amp;gt;3&amp;#xA;&amp;lt;/span&amp;gt;&amp;lt;span style=&amp;#34;white-space:pre;-webkit-user-select:none;user-select:none;margin-right:0.4em;padding:0 0.4em 0 0.4em;color:#7f7f7f&amp;#34;&amp;gt;4&amp;#xA;&amp;lt;/span&amp;gt;&amp;lt;/code&amp;gt;&amp;lt;/pre&amp;gt;&amp;lt;/td&amp;gt;&amp;#xA;&amp;lt;td style=&amp;#34;vertical-align:top;padding:0;margin:0;border:0;;width:100%&amp;#34;&amp;gt;&amp;#xA;&amp;lt;pre tabindex=&amp;#34;0&amp;#34; style=&amp;#34;background-color:#f8f8f8;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&amp;#34;&amp;gt;&amp;lt;code class=&amp;#34;language-text&amp;#34; data-lang=&amp;#34;text&amp;#34;&amp;gt;&amp;lt;span style=&amp;#34;display:flex;&amp;#34;&amp;gt;&amp;lt;span&amp;gt;add lb vserver &amp;amp;lt;vserver-name&amp;amp;gt; &amp;amp;lt;HTTP or SSL&amp;amp;gt;&amp;#xA;&amp;lt;/span&amp;gt;&amp;lt;/span&amp;gt;&amp;lt;span style=&amp;#34;display:flex;&amp;#34;&amp;gt;&amp;lt;span&amp;gt;add cs vserver &amp;amp;lt;vserver-name&amp;amp;gt; &amp;amp;lt;HTTP or SSL&amp;amp;gt;&amp;#xA;&amp;lt;/span&amp;gt;&amp;lt;/span&amp;gt;&amp;lt;span style=&amp;#34;display:flex;&amp;#34;&amp;gt;&amp;lt;span&amp;gt;add vpn vserver &amp;amp;lt;vserver-name&amp;amp;gt; &amp;amp;lt;HTTP or SSL&amp;amp;gt;&amp;#xA;&amp;lt;/span&amp;gt;&amp;lt;/span&amp;gt;&amp;lt;span style=&amp;#34;display:flex;&amp;#34;&amp;gt;&amp;lt;span&amp;gt;add authentication vserver &amp;amp;lt;vserver-name&amp;amp;gt; &amp;amp;lt;HTTP or SSL&amp;amp;gt;&amp;#xA;&amp;lt;/span&amp;gt;&amp;lt;/span&amp;gt;&amp;lt;/code&amp;gt;&amp;lt;/pre&amp;gt;&amp;lt;/td&amp;gt;&amp;lt;/tr&amp;gt;&amp;lt;/table&amp;gt;&amp;#xA;&amp;lt;/div&amp;gt;&amp;#xA;&amp;lt;/div&amp;gt;&amp;lt;h3 id=&amp;#34;cve-2026-88775&amp;#34;&amp;gt;CVE-2026-88775&amp;lt;/h3&amp;gt;&amp;#xA;&amp;lt;p&amp;gt;Relevant configuration entries include:&amp;lt;/p&amp;gt;&amp;#xA;&amp;lt;div class=&amp;#34;highlight&amp;#34;&amp;gt;&amp;lt;div style=&amp;#34;background-color:#f8f8f8;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&amp;#34;&amp;gt;&amp;#xA;&amp;lt;table style=&amp;#34;border-spacing:0;padding:0;margin:0;border:0;&amp;#34;&amp;gt;&amp;lt;tr&amp;gt;&amp;lt;td style=&amp;#34;vertical-align:top;padding:0;margin:0;border:0;&amp;#34;&amp;gt;&amp;#xA;&amp;lt;pre tabindex=&amp;#34;0&amp;#34; style=&amp;#34;background-color:#f8f8f8;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&amp;#34;&amp;gt;&amp;lt;code&amp;gt;&amp;lt;span style=&amp;#34;white-space:pre;-webkit-user-select:none;user-select:none;margin-right:0.4em;padding:0 0.4em 0 0.4em;color:#7f7f7f&amp;#34;&amp;gt;1&amp;#xA;&amp;lt;/span&amp;gt;&amp;lt;span style=&amp;#34;white-space:pre;-webkit-user-select:none;user-select:none;margin-right:0.4em;padding:0 0.4em 0 0.4em;color:#7f7f7f&amp;#34;&amp;gt;2&amp;#xA;&amp;lt;/span&amp;gt;&amp;lt;/code&amp;gt;&amp;lt;/pre&amp;gt;&amp;lt;/td&amp;gt;&amp;#xA;&amp;lt;td style=&amp;#34;vertical-align:top;padding:0;margin:0;border:0;;width:100%&amp;#34;&amp;gt;&amp;#xA;&amp;lt;pre tabindex=&amp;#34;0&amp;#34; style=&amp;#34;background-color:#f8f8f8;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&amp;#34;&amp;gt;&amp;lt;code class=&amp;#34;language-text&amp;#34; data-lang=&amp;#34;text&amp;#34;&amp;gt;&amp;lt;span style=&amp;#34;display:flex;&amp;#34;&amp;gt;&amp;lt;span&amp;gt;add vpn vserver .*&amp;#xA;&amp;lt;/span&amp;gt;&amp;lt;/span&amp;gt;&amp;lt;span style=&amp;#34;display:flex;&amp;#34;&amp;gt;&amp;lt;span&amp;gt;add authentication vserver .*&amp;#xA;&amp;lt;/span&amp;gt;&amp;lt;/span&amp;gt;&amp;lt;/code&amp;gt;&amp;lt;/pre&amp;gt;&amp;lt;/td&amp;gt;&amp;lt;/tr&amp;gt;&amp;lt;/table&amp;gt;&amp;#xA;&amp;lt;/div&amp;gt;&amp;#xA;&amp;lt;/div&amp;gt;&amp;lt;h3 id=&amp;#34;cve-2026-88776&amp;#34;&amp;gt;CVE-2026-88776&amp;lt;/h3&amp;gt;&amp;#xA;&amp;lt;p&amp;gt;Search for Oracle Load Balancing virtual servers:&amp;lt;/p&amp;gt;&amp;#xA;&amp;lt;div class=&amp;#34;highlight&amp;#34;&amp;gt;&amp;lt;div style=&amp;#34;background-color:#f8f8f8;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&amp;#34;&amp;gt;&amp;#xA;&amp;lt;table style=&amp;#34;border-spacing:0;padding:0;margin:0;border:0;&amp;#34;&amp;gt;&amp;lt;tr&amp;gt;&amp;lt;td style=&amp;#34;vertical-align:top;padding:0;margin:0;border:0;&amp;#34;&amp;gt;&amp;#xA;&amp;lt;pre tabindex=&amp;#34;0&amp;#34; style=&amp;#34;background-color:#f8f8f8;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&amp;#34;&amp;gt;&amp;lt;code&amp;gt;&amp;lt;span style=&amp;#34;white-space:pre;-webkit-user-select:none;user-select:none;margin-right:0.4em;padding:0 0.4em 0 0.4em;color:#7f7f7f&amp;#34;&amp;gt;1&amp;#xA;&amp;lt;/span&amp;gt;&amp;lt;/code&amp;gt;&amp;lt;/pre&amp;gt;&amp;lt;/td&amp;gt;&amp;#xA;&amp;lt;td style=&amp;#34;vertical-align:top;padding:0;margin:0;border:0;;width:100%&amp;#34;&amp;gt;&amp;#xA;&amp;lt;pre tabindex=&amp;#34;0&amp;#34; style=&amp;#34;background-color:#f8f8f8;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&amp;#34;&amp;gt;&amp;lt;code class=&amp;#34;language-text&amp;#34; data-lang=&amp;#34;text&amp;#34;&amp;gt;&amp;lt;span style=&amp;#34;display:flex;&amp;#34;&amp;gt;&amp;lt;span&amp;gt;add lb vserver.*ORACLE.*&amp;#xA;&amp;lt;/span&amp;gt;&amp;lt;/span&amp;gt;&amp;lt;/code&amp;gt;&amp;lt;/pre&amp;gt;&amp;lt;/td&amp;gt;&amp;lt;/tr&amp;gt;&amp;lt;/table&amp;gt;&amp;#xA;&amp;lt;/div&amp;gt;&amp;#xA;&amp;lt;/div&amp;gt;&amp;lt;h3 id=&amp;#34;cve-2026-88777&amp;#34;&amp;gt;CVE-2026-88777&amp;lt;/h3&amp;gt;&amp;#xA;&amp;lt;p&amp;gt;Review configurations using non-HTTP Layer 7 protocols, including:&amp;lt;/p&amp;gt;&amp;#xA;&amp;lt;div class=&amp;#34;highlight&amp;#34;&amp;gt;&amp;lt;div style=&amp;#34;background-color:#f8f8f8;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&amp;#34;&amp;gt;&amp;#xA;&amp;lt;table style=&amp;#34;border-spacing:0;padding:0;margin:0;border:0;&amp;#34;&amp;gt;&amp;lt;tr&amp;gt;&amp;lt;td style=&amp;#34;vertical-align:top;padding:0;margin:0;border:0;&amp;#34;&amp;gt;&amp;#xA;&amp;lt;pre tabindex=&amp;#34;0&amp;#34; style=&amp;#34;background-color:#f8f8f8;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&amp;#34;&amp;gt;&amp;lt;code&amp;gt;&amp;lt;span style=&amp;#34;white-space:pre;-webkit-user-select:none;user-select:none;margin-right:0.4em;padding:0 0.4em 0 0.4em;color:#7f7f7f&amp;#34;&amp;gt;1&amp;#xA;&amp;lt;/span&amp;gt;&amp;lt;span style=&amp;#34;white-space:pre;-webkit-user-select:none;user-select:none;margin-right:0.4em;padding:0 0.4em 0 0.4em;color:#7f7f7f&amp;#34;&amp;gt;2&amp;#xA;&amp;lt;/span&amp;gt;&amp;lt;span style=&amp;#34;white-space:pre;-webkit-user-select:none;user-select:none;margin-right:0.4em;padding:0 0.4em 0 0.4em;color:#7f7f7f&amp;#34;&amp;gt;3&amp;#xA;&amp;lt;/span&amp;gt;&amp;lt;span style=&amp;#34;white-space:pre;-webkit-user-select:none;user-select:none;margin-right:0.4em;padding:0 0.4em 0 0.4em;color:#7f7f7f&amp;#34;&amp;gt;4&amp;#xA;&amp;lt;/span&amp;gt;&amp;lt;span style=&amp;#34;white-space:pre;-webkit-user-select:none;user-select:none;margin-right:0.4em;padding:0 0.4em 0 0.4em;color:#7f7f7f&amp;#34;&amp;gt;5&amp;#xA;&amp;lt;/span&amp;gt;&amp;lt;span style=&amp;#34;white-space:pre;-webkit-user-select:none;user-select:none;margin-right:0.4em;padding:0 0.4em 0 0.4em;color:#7f7f7f&amp;#34;&amp;gt;6&amp;#xA;&amp;lt;/span&amp;gt;&amp;lt;span style=&amp;#34;white-space:pre;-webkit-user-select:none;user-select:none;margin-right:0.4em;padding:0 0.4em 0 0.4em;color:#7f7f7f&amp;#34;&amp;gt;7&amp;#xA;&amp;lt;/span&amp;gt;&amp;lt;span style=&amp;#34;white-space:pre;-webkit-user-select:none;user-select:none;margin-right:0.4em;padding:0 0.4em 0 0.4em;color:#7f7f7f&amp;#34;&amp;gt;8&amp;#xA;&amp;lt;/span&amp;gt;&amp;lt;/code&amp;gt;&amp;lt;/pre&amp;gt;&amp;lt;/td&amp;gt;&amp;#xA;&amp;lt;td style=&amp;#34;vertical-align:top;padding:0;margin:0;border:0;;width:100%&amp;#34;&amp;gt;&amp;#xA;&amp;lt;pre tabindex=&amp;#34;0&amp;#34; style=&amp;#34;background-color:#f8f8f8;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&amp;#34;&amp;gt;&amp;lt;code class=&amp;#34;language-text&amp;#34; data-lang=&amp;#34;text&amp;#34;&amp;gt;&amp;lt;span style=&amp;#34;display:flex;&amp;#34;&amp;gt;&amp;lt;span&amp;gt;add (lb|cs) vserver .* FTP&amp;#xA;&amp;lt;/span&amp;gt;&amp;lt;/span&amp;gt;&amp;lt;span style=&amp;#34;display:flex;&amp;#34;&amp;gt;&amp;lt;span&amp;gt;add service .* FTP&amp;#xA;&amp;lt;/span&amp;gt;&amp;lt;/span&amp;gt;&amp;lt;span style=&amp;#34;display:flex;&amp;#34;&amp;gt;&amp;lt;span&amp;gt;add lb monitor .* FTP&amp;#xA;&amp;lt;/span&amp;gt;&amp;lt;/span&amp;gt;&amp;lt;span style=&amp;#34;display:flex;&amp;#34;&amp;gt;&amp;lt;span&amp;gt;add lb monitor .* FTP-EXTENDED&amp;#xA;&amp;lt;/span&amp;gt;&amp;lt;/span&amp;gt;&amp;lt;span style=&amp;#34;display:flex;&amp;#34;&amp;gt;&amp;lt;span&amp;gt;set lsn group .* -rtspalg ENABLED&amp;#xA;&amp;lt;/span&amp;gt;&amp;lt;/span&amp;gt;&amp;lt;span style=&amp;#34;display:flex;&amp;#34;&amp;gt;&amp;lt;span&amp;gt;add lb vserver .* DNS .* -dns64 ENABLED&amp;#xA;&amp;lt;/span&amp;gt;&amp;lt;/span&amp;gt;&amp;lt;span style=&amp;#34;display:flex;&amp;#34;&amp;gt;&amp;lt;span&amp;gt;add dns policy64&amp;#xA;&amp;lt;/span&amp;gt;&amp;lt;/span&amp;gt;&amp;lt;span style=&amp;#34;display:flex;&amp;#34;&amp;gt;&amp;lt;span&amp;gt;add nat64&amp;#xA;&amp;lt;/span&amp;gt;&amp;lt;/span&amp;gt;&amp;lt;/code&amp;gt;&amp;lt;/pre&amp;gt;&amp;lt;/td&amp;gt;&amp;lt;/tr&amp;gt;&amp;lt;/table&amp;gt;&amp;#xA;&amp;lt;/div&amp;gt;&amp;#xA;&amp;lt;/div&amp;gt;&amp;lt;p&amp;gt;For LSN/CGNAT configurations, administrators should pay particular attention to FTP ALG configuration.&amp;lt;/p&amp;gt;&amp;#xA;&amp;lt;h3 id=&amp;#34;cve-2026-88778&amp;#34;&amp;gt;CVE-2026-88778&amp;lt;/h3&amp;gt;&amp;#xA;&amp;lt;p&amp;gt;Check whether Enhanced ISN Generation is disabled:&amp;lt;/p&amp;gt;&amp;#xA;&amp;lt;div class=&amp;#34;highlight&amp;#34;&amp;gt;&amp;lt;div style=&amp;#34;background-color:#f8f8f8;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&amp;#34;&amp;gt;&amp;#xA;&amp;lt;table style=&amp;#34;border-spacing:0;padding:0;margin:0;border:0;&amp;#34;&amp;gt;&amp;lt;tr&amp;gt;&amp;lt;td style=&amp;#34;vertical-align:top;padding:0;margin:0;border:0;&amp;#34;&amp;gt;&amp;#xA;&amp;lt;pre tabindex=&amp;#34;0&amp;#34; style=&amp;#34;background-color:#f8f8f8;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&amp;#34;&amp;gt;&amp;lt;code&amp;gt;&amp;lt;span style=&amp;#34;white-space:pre;-webkit-user-select:none;user-select:none;margin-right:0.4em;padding:0 0.4em 0 0.4em;color:#7f7f7f&amp;#34;&amp;gt;1&amp;#xA;&amp;lt;/span&amp;gt;&amp;lt;/code&amp;gt;&amp;lt;/pre&amp;gt;&amp;lt;/td&amp;gt;&amp;#xA;&amp;lt;td style=&amp;#34;vertical-align:top;padding:0;margin:0;border:0;;width:100%&amp;#34;&amp;gt;&amp;#xA;&amp;lt;pre tabindex=&amp;#34;0&amp;#34; style=&amp;#34;background-color:#f8f8f8;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&amp;#34;&amp;gt;&amp;lt;code class=&amp;#34;language-shell&amp;#34; data-lang=&amp;#34;shell&amp;#34;&amp;gt;&amp;lt;span style=&amp;#34;display:flex;&amp;#34;&amp;gt;&amp;lt;span&amp;gt;show ns tcpparam | grep &amp;lt;span style=&amp;#34;color:#b44&amp;#34;&amp;gt;&amp;amp;#34;Enhanced ISN Generation&amp;amp;#34;&amp;lt;/span&amp;gt;&amp;#xA;&amp;lt;/span&amp;gt;&amp;lt;/span&amp;gt;&amp;lt;/code&amp;gt;&amp;lt;/pre&amp;gt;&amp;lt;/td&amp;gt;&amp;lt;/tr&amp;gt;&amp;lt;/table&amp;gt;&amp;#xA;&amp;lt;/div&amp;gt;&amp;#xA;&amp;lt;/div&amp;gt;&amp;lt;p&amp;gt;A result containing:&amp;lt;/p&amp;gt;&amp;#xA;&amp;lt;div class=&amp;#34;highlight&amp;#34;&amp;gt;&amp;lt;div style=&amp;#34;background-color:#f8f8f8;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&amp;#34;&amp;gt;&amp;#xA;&amp;lt;table style=&amp;#34;border-spacing:0;padding:0;margin:0;border:0;&amp;#34;&amp;gt;&amp;lt;tr&amp;gt;&amp;lt;td style=&amp;#34;vertical-align:top;padding:0;margin:0;border:0;&amp;#34;&amp;gt;&amp;#xA;&amp;lt;pre tabindex=&amp;#34;0&amp;#34; style=&amp;#34;background-color:#f8f8f8;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&amp;#34;&amp;gt;&amp;lt;code&amp;gt;&amp;lt;span style=&amp;#34;white-space:pre;-webkit-user-select:none;user-select:none;margin-right:0.4em;padding:0 0.4em 0 0.4em;color:#7f7f7f&amp;#34;&amp;gt;1&amp;#xA;&amp;lt;/span&amp;gt;&amp;lt;/code&amp;gt;&amp;lt;/pre&amp;gt;&amp;lt;/td&amp;gt;&amp;#xA;&amp;lt;td style=&amp;#34;vertical-align:top;padding:0;margin:0;border:0;;width:100%&amp;#34;&amp;gt;&amp;#xA;&amp;lt;pre tabindex=&amp;#34;0&amp;#34; style=&amp;#34;background-color:#f8f8f8;-moz-tab-size:4;-o-tab-size:4;tab-size:4;-webkit-text-size-adjust:none;&amp;#34;&amp;gt;&amp;lt;code class=&amp;#34;language-text&amp;#34; data-lang=&amp;#34;text&amp;#34;&amp;gt;&amp;lt;span style=&amp;#34;display:flex;&amp;#34;&amp;gt;&amp;lt;span&amp;gt;Enhanced ISN Generation: DISABLED&amp;#xA;&amp;lt;/span&amp;gt;&amp;lt;/span&amp;gt;&amp;lt;/code&amp;gt;&amp;lt;/pre&amp;gt;&amp;lt;/td&amp;gt;&amp;lt;/tr&amp;gt;&amp;lt;/table&amp;gt;&amp;#xA;&amp;lt;/div&amp;gt;&amp;#xA;&amp;lt;/div&amp;gt;&amp;lt;p&amp;gt;indicates that the vulnerable configuration precondition may be met when applicable TCP-based virtual servers are configured.&amp;lt;/p&amp;gt;&amp;#xA;&amp;lt;p&amp;gt;Administrators affected by CVE-2026-88778 should also apply the TCP configuration changes recommended by Citrix.&amp;lt;/p&amp;gt;&amp;#xA;&amp;lt;h2 id=&amp;#34;incident-response-considerations&amp;#34;&amp;gt;Incident Response Considerations&amp;lt;/h2&amp;gt;&amp;#xA;&amp;lt;p&amp;gt;Due to the reported exploitation of the two remote-code-execution vulnerabilities, CIRCL recommends treating vulnerable Internet-exposed NetScaler appliances with additional caution.&amp;lt;/p&amp;gt;&amp;#xA;&amp;lt;p&amp;gt;Where an appliance was exposed to untrusted networks while vulnerable, organisations should consider performing a compromise assessment rather than relying exclusively on successful installation of the security update.&amp;lt;/p&amp;gt;&amp;#xA;&amp;lt;p&amp;gt;In particular, successful patching prevents subsequent exploitation of the corrected vulnerabilities but does &amp;lt;strong&amp;gt;not&amp;lt;/strong&amp;gt; remediate persistence or other changes potentially introduced before the update.&amp;lt;/p&amp;gt;&amp;#xA;&amp;lt;h2 id=&amp;#34;references&amp;#34;&amp;gt;References&amp;lt;/h2&amp;gt;&amp;#xA;&amp;lt;ul&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;a href=&amp;#34;https://vulnerability.circl.lu/bundle/6d8bc6ad-f616-4600-9f2e-18a677efbaa6&amp;#34;&amp;gt;CIRCL - Information Bundle&amp;lt;/a&amp;gt;&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;a href=&amp;#34;https://support.citrix.com/support-home/kbsearch/article?articleNumber=CTX697096&amp;amp;amp;articleTitle=Citrix_NetScaler_ADC_and_Citrix_NetScaler_Gateway_Security_Bulletin_for_CVE_2026_88771_CVE_2026_88772_CVE_2026_88773_CVE_2026_88774_CVE_2026_88775_CVE_2026_88776_CVE_2026_88777_and_CVE_2026_88778&amp;#34;&amp;gt;Citrix Support&amp;lt;/a&amp;gt;&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;a href=&amp;#34;https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-88772&amp;#34;&amp;gt;CISA&amp;lt;/a&amp;gt;&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;/ul&amp;gt;&amp;#xA;&amp;lt;h2 id=&amp;#34;classification-of-this-document&amp;#34;&amp;gt;Classification of this document&amp;lt;/h2&amp;gt;&amp;#xA;&amp;lt;p&amp;gt;&amp;lt;a href=&amp;#34;/pub/traffic-light-protocol/&amp;#34;&amp;gt;TLP:CLEAR&amp;lt;/a&amp;gt; information may be distributed without restriction, subject to copyright controls.&amp;lt;/p&amp;gt;&amp;#xA;&amp;lt;h2 id=&amp;#34;revision&amp;#34;&amp;gt;Revision&amp;lt;/h2&amp;gt;&amp;#xA;&amp;lt;ul&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;Version 1.0 - TLP:CLEAR - First version - 27th September 2026&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;/ul&amp;gt;&amp;#xA;</content>
  </entry>
  <entry>
    <title>TR-99 - Phishing Campaign Targeting Hotel Customers in Luxembourg</title>
    <link href="https://www.circl.lu/pub/tr-99/" rel="alternate" type="text/html" />
    <id>https://www.circl.lu/pub/tr-99/</id>
    <published>2026-06-01T00:00:00Z</published>
    <updated>2026-06-01T00:00:00Z</updated>
    <summary>Executive Summary CIRCL and Horesca have been informed of a phishing campaign targeting customers of hotels in Luxembourg. A significant number of hotel guests have received fraudulent messages through different communication channels, including WhatsApp messages containing malicious URLs.&amp;#xA;The phishing messages are particularly convincing because they include information related to legitimate hotel bookings. This increases the likelihood that victims will trust the message and engage with the fraudulent website or communication channel.&amp;#xA;</summary>
    <content type="html">&amp;lt;h2 id=&amp;#34;executive-summary&amp;#34;&amp;gt;Executive Summary&amp;lt;/h2&amp;gt;&amp;#xA;&amp;lt;p&amp;gt;CIRCL and &amp;lt;a href=&amp;#34;https://www.horesca.lu/actualites/8189-signalements-de-tentatives-de-phishing-visant-des-clients-dhotels&amp;#34;&amp;gt;Horesca&amp;lt;/a&amp;gt; have been informed of a phishing campaign targeting customers of hotels in Luxembourg. A significant number of hotel guests have received fraudulent messages through different communication channels, including WhatsApp messages containing malicious URLs.&amp;lt;/p&amp;gt;&amp;#xA;&amp;lt;p&amp;gt;The phishing messages are particularly convincing because they include information related to legitimate hotel bookings. This increases the likelihood that victims will trust the message and engage with the fraudulent website or communication channel.&amp;lt;/p&amp;gt;&amp;#xA;&amp;lt;p&amp;gt;The apparent objective of the campaign is to trick hotel customers into making payments to an actor-controlled account or payment infrastructure.&amp;lt;/p&amp;gt;&amp;#xA;&amp;lt;h2 id=&amp;#34;observed-activity&amp;#34;&amp;gt;Observed Activity&amp;lt;/h2&amp;gt;&amp;#xA;&amp;lt;p&amp;gt;Victims have reported receiving messages that appear to reference real hotel reservations. These messages may include booking-related information that is accurate or sufficiently close to a legitimate reservation to appear trustworthy.&amp;lt;/p&amp;gt;&amp;#xA;&amp;lt;p&amp;gt;The phishing messages typically contain a URL and encourage the recipient to take action, such as confirming a reservation, updating payment details, or completing a payment.&amp;lt;/p&amp;gt;&amp;#xA;&amp;lt;p&amp;gt;At this stage, CIRCL assesses that the information used in the phishing messages may originate from data associated with services operated by myLighthouse, a platform used in the hotel and hospitality sector.&amp;lt;/p&amp;gt;&amp;#xA;&amp;lt;p&amp;gt;The exact origin of the data exposure is currently unclear. Possible scenarios include, but are not limited to:&amp;lt;/p&amp;gt;&amp;#xA;&amp;lt;ul&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;a vulnerability affecting a service or integration;&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;abuse or compromise of one or more hotel accounts;&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;unauthorised access to or exfiltration of booking-related data;&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;misuse of legitimate access to hotel or booking-management systems.&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;/ul&amp;gt;&amp;#xA;&amp;lt;p&amp;gt;The investigation by Lighthouse has not yet clearly established the precise source of the data used in the phishing campaign.&amp;lt;/p&amp;gt;&amp;#xA;&amp;lt;h2 id=&amp;#34;impact&amp;#34;&amp;gt;Impact&amp;lt;/h2&amp;gt;&amp;#xA;&amp;lt;p&amp;gt;The campaign may affect hotel customers who have made legitimate bookings in Luxembourg (not limited) and who receive fraudulent communications referencing those bookings.&amp;lt;/p&amp;gt;&amp;#xA;&amp;lt;p&amp;gt;Potential impacts include:&amp;lt;/p&amp;gt;&amp;#xA;&amp;lt;ul&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;financial loss due to fraudulent payments;&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;disclosure of personal or payment-related information;&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;loss of trust in hotel communication channels;&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;increased workload for hotels, financial institutions, and incident response teams.&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;/ul&amp;gt;&amp;#xA;&amp;lt;h2 id=&amp;#34;recommendations-for-hotel-owners-and-operators-using-mylighthouse&amp;#34;&amp;gt;Recommendations for Hotel Owners and Operators Using myLighthouse&amp;lt;/h2&amp;gt;&amp;#xA;&amp;lt;p&amp;gt;CIRCL recommends that hotels using myLighthouse take the following actions as a priority:&amp;lt;/p&amp;gt;&amp;#xA;&amp;lt;ol&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;#xA;&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Reset credentials&amp;lt;/strong&amp;gt;&amp;lt;/p&amp;gt;&amp;#xA;&amp;lt;ul&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;Reset passwords for all accounts associated with myLighthouse.&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;Ensure that passwords are unique and not reused across other services.&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;/ul&amp;gt;&amp;#xA;&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;#xA;&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Enable and enforce multi-factor authentication&amp;lt;/strong&amp;gt;&amp;lt;/p&amp;gt;&amp;#xA;&amp;lt;ul&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;Enable MFA for all accounts where available.&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;Lighthouse has announced enforcement of MFA as of 1 June.&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;Hotels should verify that MFA is active for all relevant users and accounts.&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;/ul&amp;gt;&amp;#xA;&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;#xA;&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Review account access&amp;lt;/strong&amp;gt;&amp;lt;/p&amp;gt;&amp;#xA;&amp;lt;ul&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;Review active users and remove accounts that are no longer required.&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;Check whether any unexpected or unauthorised accounts have access.&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;Review access rights and apply the principle of least privilege.&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;/ul&amp;gt;&amp;#xA;&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;#xA;&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Inform customers about legitimate payment procedures&amp;lt;/strong&amp;gt;&amp;lt;/p&amp;gt;&amp;#xA;&amp;lt;ul&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;Clearly communicate the official payment methods used by the hotel.&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;Remind customers that unexpected payment requests received through WhatsApp, SMS, or unofficial channels should be treated with suspicion.&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;Provide customers with a trusted contact point to verify payment requests.&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;/ul&amp;gt;&amp;#xA;&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;#xA;&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Monitor for suspicious activity&amp;lt;/strong&amp;gt;&amp;lt;/p&amp;gt;&amp;#xA;&amp;lt;ul&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;Monitor customer reports of phishing attempts.&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;Review logs, where available, for unusual access patterns.&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;Report suspicious URLs and related indicators to CIRCL.&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;/ul&amp;gt;&amp;#xA;&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;/ol&amp;gt;&amp;#xA;&amp;lt;h2 id=&amp;#34;recommendations-for-victims-and-hotel-customers&amp;#34;&amp;gt;Recommendations for Victims and Hotel Customers&amp;lt;/h2&amp;gt;&amp;#xA;&amp;lt;p&amp;gt;If you receive a message via WhatsApp, SMS, email, or another channel that refers to your hotel booking and asks you to click a link or make a payment, CIRCL recommends the following:&amp;lt;/p&amp;gt;&amp;#xA;&amp;lt;ol&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;#xA;&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Do not click on the URL&amp;lt;/strong&amp;gt;&amp;lt;/p&amp;gt;&amp;#xA;&amp;lt;ul&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;Do not open links contained in suspicious or unexpected messages.&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;Do not enter personal, booking, or payment information on websites reached through such links.&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;/ul&amp;gt;&amp;#xA;&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;#xA;&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Verify directly with the hotel&amp;lt;/strong&amp;gt;&amp;lt;/p&amp;gt;&amp;#xA;&amp;lt;ul&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;Contact the hotel using contact details obtained from the official hotel website or your original booking confirmation.&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;Do not rely on phone numbers, links, or contact details provided in the suspicious message.&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;/ul&amp;gt;&amp;#xA;&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;#xA;&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;If you interacted with the phishing site&amp;lt;/strong&amp;gt;&amp;lt;/p&amp;gt;&amp;#xA;&amp;lt;ul&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;Contact your bank or financial provider immediately.&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;Notify them that you may have been targeted by payment fraud.&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;Follow their instructions regarding card blocking, transaction monitoring, or chargeback procedures.&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;Notify the policy if you want to fill a complain.&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;/ul&amp;gt;&amp;#xA;&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;#xA;&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Preserve evidence&amp;lt;/strong&amp;gt;&amp;lt;/p&amp;gt;&amp;#xA;&amp;lt;ul&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;Keep the suspicious message, phone number, URL, screenshots, and any payment details.&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;These elements can help incident responders and service providers limit the impact of the campaign.&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;/ul&amp;gt;&amp;#xA;&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;/ol&amp;gt;&amp;#xA;&amp;lt;h2 id=&amp;#34;reporting-phishing-urls-to-circl&amp;#34;&amp;gt;Reporting Phishing URLs to CIRCL&amp;lt;/h2&amp;gt;&amp;#xA;&amp;lt;p&amp;gt;CIRCL welcomes reports from users, victims, hotels, and service providers.&amp;lt;/p&amp;gt;&amp;#xA;&amp;lt;p&amp;gt;Phishing URLs can be submitted to Lookyloo at &amp;lt;a href=&amp;#34;https://lookyloo.circl.lu/capture&amp;#34;&amp;gt;https://lookyloo.circl.lu/capture&amp;lt;/a&amp;gt;&amp;lt;/p&amp;gt;&amp;#xA;&amp;lt;p&amp;gt;When submitting a URL, please mark the capture as phishing. This helps CIRCL and partners analyse the infrastructure, identify related campaigns, and support takedown or mitigation actions to reduce the impact on victims.&amp;lt;/p&amp;gt;&amp;#xA;&amp;lt;h2 id=&amp;#34;indicators-of-compromise&amp;#34;&amp;gt;Indicators of Compromise&amp;lt;/h2&amp;gt;&amp;#xA;&amp;lt;p&amp;gt;Indicators may vary depending on the hotel, the communication channel, and the infrastructure used by the threat actor.&amp;lt;/p&amp;gt;&amp;#xA;&amp;lt;p&amp;gt;A MISP event &amp;lt;a href=&amp;#34;https://misppriv.circl.lu/events/view/10a94632-a0a1-4062-a3a5-95fe321ae045&amp;#34;&amp;gt;https://misppriv.circl.lu/events/view/10a94632-a0a1-4062-a3a5-95fe321ae045&amp;lt;/a&amp;gt; is available with all the indicators collected from the reported cases.&amp;lt;/p&amp;gt;&amp;#xA;&amp;lt;p&amp;gt;The threat actor appears to rotate phishing URLs frequently and also changes the phone numbers used to send WhatsApp messages, making static blocking and indicator-based detection more difficult.&amp;lt;/p&amp;gt;&amp;#xA;&amp;lt;p&amp;gt;Hotels and victims are encouraged to report phishing URLs and related artefacts to CIRCL for analysis.&amp;lt;/p&amp;gt;&amp;#xA;&amp;lt;h2 id=&amp;#34;conclusion&amp;#34;&amp;gt;Conclusion&amp;lt;/h2&amp;gt;&amp;#xA;&amp;lt;p&amp;gt;This phishing campaign is notable because it uses legitimate booking-related information to increase credibility and pressure victims into making fraudulent payments.&amp;lt;/p&amp;gt;&amp;#xA;&amp;lt;p&amp;gt;Hotels using myLighthouse should urgently reset credentials, ensure MFA is enabled and enforced, review access rights, and communicate clearly with customers about legitimate payment methods.&amp;lt;/p&amp;gt;&amp;#xA;&amp;lt;p&amp;gt;Customers who receive suspicious booking-related messages should not click on links, should verify requests directly with the hotel, and should contact their financial provider immediately if they engaged with the phishing site or made a payment.&amp;lt;/p&amp;gt;&amp;#xA;&amp;lt;p&amp;gt;CIRCL continues to collect reports and encourages the submission of phishing URLs through Lookyloo to support analysis and mitigation.&amp;lt;/p&amp;gt;&amp;#xA;&amp;lt;h2 id=&amp;#34;classification-of-this-document&amp;#34;&amp;gt;Classification of this document&amp;lt;/h2&amp;gt;&amp;#xA;&amp;lt;p&amp;gt;&amp;lt;a href=&amp;#34;/pub/traffic-light-protocol/&amp;#34;&amp;gt;TLP:CLEAR&amp;lt;/a&amp;gt; information may be distributed without restriction, subject to copyright controls.&amp;lt;/p&amp;gt;&amp;#xA;&amp;lt;h2 id=&amp;#34;revision&amp;#34;&amp;gt;Revision&amp;lt;/h2&amp;gt;&amp;#xA;&amp;lt;ul&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;Version 1.0 - TLP:CLEAR - First version - 1st June 2026&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;/ul&amp;gt;&amp;#xA;</content>
  </entry>
  <entry>
    <title>TR-98 - Security Advisory Ivanti Endpoint Manager Mobile (EPMM) (CVE-2026-1281 &amp;amp; CVE-2026-1340) - Active Exploitation</title>
    <link href="https://www.circl.lu/pub/tr-98/" rel="alternate" type="text/html" />
    <id>https://www.circl.lu/pub/tr-98/</id>
    <published>2026-02-09T00:00:00Z</published>
    <updated>2026-02-09T00:00:00Z</updated>
    <summary>Ivanti has released security updates for Endpoint Manager Mobile (EPMM) addressing two critical-severity vulnerabilities.&amp;#xA;Successful exploitation allows unauthenticated remote code execution. Active exploitation has been confirmed in the wild, both worldwide and in Luxembourg.&amp;#xA;CIRCL strongly recommends immediately initiating a full incident response procedure for all Ivanti EPMM instances, including compromise assessment and log review.&amp;#xA;As EPMM is a mobile endpoint management solution, a compromise of the EPMM server can result in severe impact, including full control over managed devices, lateral movements and access to sensitive data.&amp;#xA;</summary>
    <content type="html">&amp;lt;p&amp;gt;Ivanti has released security updates for Endpoint Manager Mobile (EPMM) addressing two critical-severity vulnerabilities.&amp;lt;/p&amp;gt;&amp;#xA;&amp;lt;p&amp;gt;Successful exploitation allows unauthenticated remote code execution. Active exploitation has been confirmed in the wild, both worldwide and in Luxembourg.&amp;lt;/p&amp;gt;&amp;#xA;&amp;lt;p&amp;gt;CIRCL strongly recommends immediately initiating a full incident response procedure for all Ivanti EPMM instances, including compromise assessment and log review.&amp;lt;/p&amp;gt;&amp;#xA;&amp;lt;p&amp;gt;As EPMM is a mobile endpoint management solution, a compromise of the EPMM server can result in severe impact, including full control over managed devices, lateral movements and access to sensitive data.&amp;lt;/p&amp;gt;&amp;#xA;&amp;lt;h2 id=&amp;#34;affected-version&amp;#34;&amp;gt;Affected Version&amp;lt;/h2&amp;gt;&amp;#xA;&amp;lt;table&amp;gt;&amp;#xA;&amp;#x9;&amp;lt;thead&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;th&amp;gt;Product Name&amp;lt;/th&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;th&amp;gt;Affected Version(s)&amp;lt;/th&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;th&amp;gt;Affected CPE(s)&amp;lt;/th&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;th&amp;gt;Resolved Version(s)&amp;lt;/th&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;th&amp;gt;Patch Availability&amp;lt;/th&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;/tr&amp;gt;&amp;#xA;&amp;#x9;&amp;lt;/thead&amp;gt;&amp;#xA;&amp;#x9;&amp;lt;tbody&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td&amp;gt;Ivanti Endpoint Manager Mobile&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td&amp;gt;12.5.0.0 and prior 12.6.0.0 and prior 12.7.0.0 and prior&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td&amp;gt;cpe:2.3:a:ivanti:endpoint_manager_mobile:12.7.0.0&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td&amp;gt;RPM 12.x.0.x&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td&amp;gt;&amp;lt;a href=&amp;#34;https://support.mobileiron.com/mi/vsp/AB1771634/ivanti-security-update-1761642-1.0.0S-5.noarch.rpm&amp;#34;&amp;gt;https://support.mobileiron.com/mi/vsp/AB1771634/ivanti-security-update-1761642-1.0.0S-5.noarch.rpm&amp;lt;/a&amp;gt;&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;/tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;tr&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td&amp;gt;Ivanti Endpoint Manager Mobile&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td&amp;gt;12.5.1.0 and prior 12.6.1.0 and prior&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td&amp;gt;cpe:2.3:a:ivanti:endpoint_manager_mobile:12.5.1.0 cpe:2.3:a:ivanti:endpoint_manager_mobile:12.6.1.0&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td&amp;gt;RPM 12.x.1.x&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;td&amp;gt;&amp;lt;a href=&amp;#34;https://support.mobileiron.com/mi/vsp/AB1771634/ivanti-security-update-1761642-1.0.0L-5.noarch.rpm&amp;#34;&amp;gt;https://support.mobileiron.com/mi/vsp/AB1771634/ivanti-security-update-1761642-1.0.0L-5.noarch.rpm&amp;lt;/a&amp;gt;&amp;lt;/td&amp;gt;&amp;#xA;&amp;#x9;&amp;#x9;&amp;#x9;&amp;lt;/tr&amp;gt;&amp;#xA;&amp;#x9;&amp;lt;/tbody&amp;gt;&amp;#xA;&amp;lt;/table&amp;gt;&amp;#xA;&amp;lt;p&amp;gt;Previous version under EoL might be also affected by the vulnerability.&amp;lt;/p&amp;gt;&amp;#xA;&amp;lt;h2 id=&amp;#34;network-indicator&amp;#34;&amp;gt;Network Indicator&amp;lt;/h2&amp;gt;&amp;#xA;&amp;lt;ul&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;a href=&amp;#34;https://hub.ivanti.com/s/article/Analysis-Guidance-Ivanti-Endpoint-Manager-Mobile-EPMM-CVE-2026-1281-CVE-2026-1340?language=en_US&amp;#34;&amp;gt;Reviewing for post-exploit activity&amp;lt;/a&amp;gt;&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;/ul&amp;gt;&amp;#xA;&amp;lt;h2 id=&amp;#34;detection-and-forensic&amp;#34;&amp;gt;Detection and Forensic&amp;lt;/h2&amp;gt;&amp;#xA;&amp;lt;p&amp;gt;Ivanti published a detection script &amp;lt;a href=&amp;#34;https://hub.ivanti.com/s/article/Security-Advisory-Ivanti-Endpoint-Manager-Mobile-EPMM-CVE-2026-1281-CVE-2026-1340?language=en_US&amp;#34;&amp;gt;Exploitation Detection RPM package&amp;lt;/a&amp;gt;. We strongly recommend to do further detection and analysis beside the scripts provided by Ivanti.&amp;lt;/p&amp;gt;&amp;#xA;&amp;lt;h2 id=&amp;#34;references&amp;#34;&amp;gt;References&amp;lt;/h2&amp;gt;&amp;#xA;&amp;lt;ul&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;a href=&amp;#34;https://hub.ivanti.com/s/article/Security-Advisory-Ivanti-Endpoint-Manager-Mobile-EPMM-CVE-2026-1281-CVE-2026-1340?language=en_US&amp;#34;&amp;gt;Security Advisory Ivanti Endpoint Manager Mobile (EPMM) (CVE-2026-1281 &amp;amp;amp; CVE-2026-1340)&amp;lt;/a&amp;gt;&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;a href=&amp;#34;https://hub.ivanti.com/s/article/Analysis-Guidance-Ivanti-Endpoint-Manager-Mobile-EPMM-CVE-2026-1281-CVE-2026-1340?language=en_US&amp;#34;&amp;gt;Analysis Guidance Ivanti Endpoint Manager Mobile (EPMM) CVE-2026-1281 &amp;amp;amp; CVE-2026-1340&amp;lt;/a&amp;gt;&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;a href=&amp;#34;https://vulnerability.circl.lu/vuln/CVE-2026-1281&amp;#34;&amp;gt;CVE-2026-1281&amp;lt;/a&amp;gt;&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;a href=&amp;#34;https://vulnerability.circl.lu/vuln/CVE-2026-1340&amp;#34;&amp;gt;CVE-2026-1340&amp;lt;/a&amp;gt;&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;/ul&amp;gt;&amp;#xA;&amp;lt;h2 id=&amp;#34;classification-of-this-document&amp;#34;&amp;gt;Classification of this document&amp;lt;/h2&amp;gt;&amp;#xA;&amp;lt;p&amp;gt;&amp;lt;a href=&amp;#34;/pub/traffic-light-protocol/&amp;#34;&amp;gt;TLP:CLEAR&amp;lt;/a&amp;gt; information may be distributed without restriction, subject to copyright controls.&amp;lt;/p&amp;gt;&amp;#xA;&amp;lt;h2 id=&amp;#34;revision&amp;#34;&amp;gt;Revision&amp;lt;/h2&amp;gt;&amp;#xA;&amp;lt;ul&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;Version 1.0 - TLP:CLEAR - First version - 9th February 2025&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;/ul&amp;gt;&amp;#xA;</content>
  </entry>
  <entry>
    <title>TR-97 - Supply Chain Compromise Propagating Through the npm Ecosystem (Shai-Hulud)</title>
    <link href="https://www.circl.lu/pub/tr-97/" rel="alternate" type="text/html" />
    <id>https://www.circl.lu/pub/tr-97/</id>
    <published>2025-11-28T00:00:00Z</published>
    <updated>2025-11-28T00:00:00Z</updated>
    <summary>The incident involves a self-replicating worm, publicly referred to as “Shai-Hulud”, which has infected more than 500 npm packages, with an even broader impact in a second wave (Shai-Hulud 2.0) that delivered a different payload.&amp;#xA;After gaining initial access, the malicious threat actor deployed malware designed to scan affected environments for sensitive credentials and exfiltrate these. The second version included a destructive payload capable of deleting the user’s home directory.&amp;#xA;</summary>
    <content type="html">&amp;lt;p&amp;gt;The incident involves a self-replicating worm, publicly referred to as “Shai-Hulud”, which has infected more than 500 npm packages, with an even broader impact in a second wave (Shai-Hulud 2.0) that delivered a different payload.&amp;lt;/p&amp;gt;&amp;#xA;&amp;lt;p&amp;gt;After gaining initial access, the malicious threat actor deployed malware designed to scan affected environments for sensitive credentials and exfiltrate these. The second version included a destructive payload capable of deleting the user’s home directory.&amp;lt;/p&amp;gt;&amp;#xA;&amp;lt;p&amp;gt;The threat actor specifically targeted GitHub Personal Access Tokens (PATs), API keys for major cloud service providers—including Amazon Web Services (AWS), Google Cloud Platform (GCP), and Microsoft Azure as well as credentials related to software distribution channels.&amp;lt;/p&amp;gt;&amp;#xA;&amp;lt;h2 id=&amp;#34;detection&amp;#34;&amp;gt;Detection&amp;lt;/h2&amp;gt;&amp;#xA;&amp;lt;ul&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;Review all the npm packages installed by reviewing &amp;lt;code&amp;gt;package-lock.json&amp;lt;/code&amp;gt;, &amp;lt;code&amp;gt;yarn.lock&amp;lt;/code&amp;gt; and similar files. Don&amp;amp;rsquo;t forget to search recursively.&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;A list of compromised package is available at &amp;lt;a href=&amp;#34;https://github.com/wiz-sec-public/wiz-research-iocs/blob/main/reports/shai-hulud-2-packages.csv&amp;#34;&amp;gt;https://github.com/wiz-sec-public/wiz-research-iocs/blob/main/reports/shai-hulud-2-packages.csv&amp;lt;/a&amp;gt;.&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;Be careful with cached version in directory which could contain malicious packages.&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;Check for the hashes of the malware sample linked below.&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;/ul&amp;gt;&amp;#xA;&amp;lt;h2 id=&amp;#34;remediation&amp;#34;&amp;gt;Remediation&amp;lt;/h2&amp;gt;&amp;#xA;&amp;lt;ul&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;Immediately rotate all developer credentials and API keys.&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;Ensuring MFA is enabled on all developer having access to repositories and systems for software deployment.&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;Review access logs and CI pipelines if they have been modified.&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;/ul&amp;gt;&amp;#xA;&amp;lt;h2 id=&amp;#34;malware-sample&amp;#34;&amp;gt;Malware Sample&amp;lt;/h2&amp;gt;&amp;#xA;&amp;lt;ul&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;a href=&amp;#34;https://www.virustotal.com/gui/file/62ee164b9b306250c1172583f138c9614139264f889fa99614903c12755468d0&amp;#34;&amp;gt;62ee164b9b306250c1172583f138c9614139264f889fa99614903c12755468d0&amp;lt;/a&amp;gt;&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;a href=&amp;#34;https://www.virustotal.com/gui/file/f099c5d9ec417d4445a0328ac0ada9cde79fc37410914103ae9c609cbc0ee068&amp;#34;&amp;gt;f099c5d9ec417d4445a0328ac0ada9cde79fc37410914103ae9c609cbc0ee068&amp;lt;/a&amp;gt;&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;a href=&amp;#34;https://www.virustotal.com/gui/file/a3894003ad1d293ba96d77881ccd2071446dc3f65f434669b49b3da92421901a&amp;#34;&amp;gt;a3894003ad1d293ba96d77881ccd2071446dc3f65f434669b49b3da92421901a&amp;lt;/a&amp;gt;&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;/ul&amp;gt;&amp;#xA;&amp;lt;p&amp;gt;Network Indicator&amp;lt;/p&amp;gt;&amp;#xA;&amp;lt;hr&amp;gt;&amp;#xA;&amp;lt;ul&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;http[:]//bun[.]sh/install[.]ps1&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;/ul&amp;gt;&amp;#xA;&amp;lt;h2 id=&amp;#34;known-affected-software-in-luxembourg&amp;#34;&amp;gt;Known affected software in Luxembourg&amp;lt;/h2&amp;gt;&amp;#xA;&amp;lt;p&amp;gt;We received notifications about affected users and GitHub repositories. To date, the impact has been minor, affecting only a limited number of organisations in Luxembourg. We are actively monitoring the situation.&amp;lt;/p&amp;gt;&amp;#xA;&amp;lt;h2 id=&amp;#34;references&amp;#34;&amp;gt;References&amp;lt;/h2&amp;gt;&amp;#xA;&amp;lt;ul&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;Datadog &amp;lt;a href=&amp;#34;https://securitylabs.datadoghq.com/articles/shai-hulud-2.0-npm-worm/&amp;#34;&amp;gt;The Shai-Hulud 2.0 npm worm: analysis, and what you need to know&amp;lt;/a&amp;gt;&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;StepSecurity &amp;lt;a href=&amp;#34;https://www.stepsecurity.io/blog/ctrl-tinycolor-and-40-npm-packages-compromised&amp;#34;&amp;gt;Shai-Hulud: Self-Replicating Worm Compromises 500&#43; NPM Packages&amp;lt;/a&amp;gt;&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;Unit42 &amp;lt;a href=&amp;#34;https://unit42.paloaltonetworks.com/npm-supply-chain-attack/&amp;#34;&amp;gt;&amp;amp;ldquo;Shai-Hulud&amp;amp;rdquo; Worm Compromises npm Ecosystem in Supply Chain Attack (Updated November 26)&amp;lt;/a&amp;gt;&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;CISA &amp;lt;a href=&amp;#34;https://www.cisa.gov/news-events/alerts/2025/09/23/widespread-supply-chain-compromise-impacting-npm-ecosystem&amp;#34;&amp;gt;Widespread Supply Chain Compromise Impacting npm Ecosystem&amp;lt;/a&amp;gt;&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;GitLab &amp;lt;a href=&amp;#34;https://about.gitlab.com/blog/gitlab-discovers-widespread-npm-supply-chain-attack/&amp;#34;&amp;gt;GitLab discovers widespread npm supply chain attack&amp;lt;/a&amp;gt;&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;WIZ &amp;lt;a href=&amp;#34;https://www.wiz.io/blog/shai-hulud-2-0-ongoing-supply-chain-attack&amp;#34;&amp;gt;&amp;lt;/a&amp;gt;&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;CIRCL &amp;lt;a href=&amp;#34;https://vulnerability.circl.lu/recent#ossf_malicious_packages&amp;#34;&amp;gt;Malicious Packages on vulnerability-lookup&amp;lt;/a&amp;gt;&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;CSSF &amp;lt;a href=&amp;#34;https://www.cssf.lu/en/2025/11/supply-chain-attack-using-npm-packages/&amp;#34;&amp;gt;Supply-chain attack using NPM packages&amp;lt;/a&amp;gt;&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;/ul&amp;gt;&amp;#xA;&amp;lt;h2 id=&amp;#34;classification-of-this-document&amp;#34;&amp;gt;Classification of this document&amp;lt;/h2&amp;gt;&amp;#xA;&amp;lt;p&amp;gt;&amp;lt;a href=&amp;#34;/pub/traffic-light-protocol/&amp;#34;&amp;gt;TLP:CLEAR&amp;lt;/a&amp;gt; information may be distributed without restriction, subject to copyright controls.&amp;lt;/p&amp;gt;&amp;#xA;&amp;lt;h2 id=&amp;#34;revision&amp;#34;&amp;gt;Revision&amp;lt;/h2&amp;gt;&amp;#xA;&amp;lt;ul&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;Version 1.0 - TLP:CLEAR - First version - 28th November 2025&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;/ul&amp;gt;&amp;#xA;</content>
  </entry>
  <entry>
    <title>TR-96 - Multiple Vulnerabilities in F5 Devices and Products - Impact and Mitigation</title>
    <link href="https://www.circl.lu/pub/tr-96/" rel="alternate" type="text/html" />
    <id>https://www.circl.lu/pub/tr-96/</id>
    <published>2025-10-15T00:00:00Z</published>
    <updated>2025-10-15T00:00:00Z</updated>
    <summary>A nation-state actor has breached F5’s systems and stolen proprietary files, including portions of the BIG-IP source code and vulnerability details. This access gives the attacker a significant advantage, enabling them to discover new flaws and develop targeted exploits for F5 devices and software.&amp;#xA;This TR applies to a wide range of F5 products, including BIG-IP iSeries and rSeries hardware, as well as BIG-IP (TMOS), Virtual Edition (VE), BIG-IP Next, and BIG-IQ software.&amp;#xA;</summary>
    <content type="html">&amp;lt;p&amp;gt;A &amp;lt;a href=&amp;#34;https://my.f5.com/manage/s/article/K000154696&amp;#34;&amp;gt;nation-state actor has breached F5&amp;amp;rsquo;s systems&amp;lt;/a&amp;gt; and stolen proprietary files, including portions of the BIG-IP source code and vulnerability details. This access gives the attacker a significant advantage, enabling them to discover new flaws and develop targeted exploits for F5 devices and software.&amp;lt;/p&amp;gt;&amp;#xA;&amp;lt;p&amp;gt;This TR applies to a wide range of F5 products, including BIG-IP iSeries and rSeries hardware, as well as BIG-IP (TMOS), Virtual Edition (VE), BIG-IP Next, and BIG-IQ software.&amp;lt;/p&amp;gt;&amp;#xA;&amp;lt;p&amp;gt;We strongly recommend reviewing all your deployed BIG-IP products and applying the recommendations from the vendor as mentionned in &amp;lt;a href=&amp;#34;https://my.f5.com/manage/s/article/K000156572&amp;#34;&amp;gt;K000156572: Quarterly Security Notification (October 2025)&amp;lt;/a&amp;gt;.&amp;lt;/p&amp;gt;&amp;#xA;&amp;lt;h2 id=&amp;#34;known-affected-software-in-luxembourg&amp;#34;&amp;gt;Known affected software in Luxembourg&amp;lt;/h2&amp;gt;&amp;#xA;&amp;lt;p&amp;gt;A significant number of BIG-IP devices were discovered in Luxembourg, and notifications have been sent to the ISPs and available contact points.&amp;lt;/p&amp;gt;&amp;#xA;&amp;lt;p&amp;gt;Based on the information available from the disclosure, we have not found any compromised or abused systems. Many of the vulnerabilities are related to potential Denial-of-Service (DoS) attacks, which should also be monitored. We also recommend looking closely at your logs.&amp;lt;/p&amp;gt;&amp;#xA;&amp;lt;h2 id=&amp;#34;references&amp;#34;&amp;gt;References&amp;lt;/h2&amp;gt;&amp;#xA;&amp;lt;ul&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;F5 - &amp;lt;a href=&amp;#34;https://my.f5.com/manage/s/article/K000156572&amp;#34;&amp;gt;K000156572: Quarterly Security Notification (October 2025)&amp;lt;/a&amp;gt;&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;CIRCL - &amp;lt;a href=&amp;#34;https://vulnerability.circl.lu/bundle/834a30cc-c06c-49b3-9157-eb77f711c73f&amp;#34;&amp;gt;F5 - K000156572: Quarterly Security Notification (October 2025 - CVE Allocated)&amp;lt;/a&amp;gt;&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;CIRCL - RULEZET.org - &amp;lt;a href=&amp;#34;https://rulezet.org/bundle/detail/5&amp;#34;&amp;gt;Threat Hunting Methodology: F5 Security Incident (K000154696)&amp;lt;/a&amp;gt;&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;CISA - &amp;lt;a href=&amp;#34;https://www.cisa.gov/news-events/directives/ed-26-01-mitigate-vulnerabilities-f5-devices&amp;#34;&amp;gt;ED 26-01: Mitigate Vulnerabilities in F5 Devices&amp;lt;/a&amp;gt;&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;/ul&amp;gt;&amp;#xA;&amp;lt;h2 id=&amp;#34;classification-of-this-document&amp;#34;&amp;gt;Classification of this document&amp;lt;/h2&amp;gt;&amp;#xA;&amp;lt;p&amp;gt;&amp;lt;a href=&amp;#34;/pub/traffic-light-protocol/&amp;#34;&amp;gt;TLP:CLEAR&amp;lt;/a&amp;gt; information may be distributed without restriction, subject to copyright controls.&amp;lt;/p&amp;gt;&amp;#xA;&amp;lt;h2 id=&amp;#34;revision&amp;#34;&amp;gt;Revision&amp;lt;/h2&amp;gt;&amp;#xA;&amp;lt;ul&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;Version 1.1 - TLP:CLEAR - Second version - 16th October 2025 - RULEZET bundle added&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;Version 1.0 - TLP:CLEAR - First version - 15th October 2025&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;/ul&amp;gt;&amp;#xA;</content>
  </entry>
  <entry>
    <title>TR-95 - Critical vulnerability - Deserialization of untrusted data in on-premises Microsoft SharePoint Server allows an unauthorized attacker to execute code over a network. CVE-2025-53770 - CVE-2025-53771</title>
    <link href="https://www.circl.lu/pub/tr-95/" rel="alternate" type="text/html" />
    <id>https://www.circl.lu/pub/tr-95/</id>
    <published>2025-07-20T00:00:00Z</published>
    <updated>2025-07-20T00:00:00Z</updated>
    <summary>Deserialization of untrusted data in on-premises Microsoft SharePoint Server allows an unauthorized attacker to execute code over a network. Microsoft is aware that an exploit for CVE-2025-53770 exists in the wild. Microsoft is preparing and fully testing a comprehensive update to address this vulnerability. In the meantime, please make sure that the mitigation provided in this CVE documentation is in place so that you are protected from exploitation. For more details about CVE-2025-53770 and CVE-2025-53771.&amp;#xA;</summary>
    <content type="html">&amp;lt;p&amp;gt;Deserialization of untrusted data in on-premises Microsoft SharePoint Server allows an unauthorized attacker to execute code over a network. Microsoft is aware that an exploit for CVE-2025-53770 exists in the wild. Microsoft is preparing and fully testing a comprehensive update to address this vulnerability. In the meantime, please make sure that the mitigation provided in this CVE documentation is in place so that you are protected from exploitation. For more details about &amp;lt;a href=&amp;#34;https://vulnerability.circl.lu/vuln/CVE-2025-53770&amp;#34;&amp;gt;CVE-2025-53770&amp;lt;/a&amp;gt; and &amp;lt;a href=&amp;#34;https://vulnerability.circl.lu/vuln/CVE-2025-53771&amp;#34;&amp;gt;CVE-2025-53771&amp;lt;/a&amp;gt;.&amp;lt;/p&amp;gt;&amp;#xA;&amp;lt;p&amp;gt;These vulnerabilities apply to on-premises SharePoint Servers only. SharePoint Online in Microsoft 365 is not impacted.&amp;lt;/p&amp;gt;&amp;#xA;&amp;lt;p&amp;gt;CIRCL advises initiating an incident response procedure, reviewing all logs, and especially scrutinizing any potential compromise to other internal infrastructure in addition to the Microsoft SharePoint Server.&amp;lt;/p&amp;gt;&amp;#xA;&amp;lt;h2 id=&amp;#34;recommendations&amp;#34;&amp;gt;Recommendations&amp;lt;/h2&amp;gt;&amp;#xA;&amp;lt;ul&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;Review the &amp;lt;a href=&amp;#34;https://msrc.microsoft.com/blog/2025/07/customer-guidance-for-sharepoint-vulnerability-cve-2025-53770/&amp;#34;&amp;gt;Microsoft Customer guidance for SharePoint vulnerability CVE-2025-53770&amp;lt;/a&amp;gt;&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;Assume the system has been compromised, because large‑scale exploitation occurred before the patch was released.&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;Rotate the current key materials on your exposed Microsoft SharePoint Server.&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;Trigger an incident response procedure, reviewing all logs, and especially scrutinizing any potential compromise to other internal infrastructure in addition to the Microsoft SharePoint Server.&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;/ul&amp;gt;&amp;#xA;&amp;lt;h2 id=&amp;#34;impact&amp;#34;&amp;gt;Impact&amp;lt;/h2&amp;gt;&amp;#xA;&amp;lt;p&amp;gt;It can result in the full compromise of the Microsoft SharePoint Server.&amp;lt;/p&amp;gt;&amp;#xA;&amp;lt;h2 id=&amp;#34;exploitation&amp;#34;&amp;gt;Exploitation&amp;lt;/h2&amp;gt;&amp;#xA;&amp;lt;p&amp;gt;Exploitation has been confirmed and has been seen worldwide, including in Luxembourg.&amp;lt;/p&amp;gt;&amp;#xA;&amp;lt;h2 id=&amp;#34;detection&amp;#34;&amp;gt;Detection&amp;lt;/h2&amp;gt;&amp;#xA;&amp;lt;p&amp;gt;Monitor and search logs for POSTs to &amp;lt;code&amp;gt;/_layouts/15/ToolPane.aspx?DisplayMode=Edit&amp;lt;/code&amp;gt; which is the trigger for the known payload.&amp;lt;/p&amp;gt;&amp;#xA;&amp;lt;p&amp;gt;Review the Microsoft SharePoint Server for the presence of the &amp;lt;code&amp;gt;spinstall0.aspx&amp;lt;/code&amp;gt; file.&amp;lt;/p&amp;gt;&amp;#xA;&amp;lt;p&amp;gt;A scanning approach (available as a bash script) and a set of indicators are detailed in an article from &amp;lt;a href=&amp;#34;https://research.eye.security/sharepoint-under-siege/&amp;#34;&amp;gt;eye.security&amp;lt;/a&amp;gt;.&amp;lt;/p&amp;gt;&amp;#xA;&amp;lt;p&amp;gt;In addition, a set of indicators are available on the original article &amp;lt;a href=&amp;#34;https://research.eye.security/sharepoint-under-siege/&amp;#34;&amp;gt;https://research.eye.security/sharepoint-under-siege/&amp;lt;/a&amp;gt;.&amp;lt;/p&amp;gt;&amp;#xA;&amp;lt;p&amp;gt;A MISP event with the indicators is also available with the following UUID: &amp;lt;code&amp;gt;d9da16a2-8444-45cb-8bb4-d27abf23a261&amp;lt;/code&amp;gt; (CIRCL) and &amp;lt;code&amp;gt;59ed4725-5f2a-4844-8dc4-e6926dbcb5ce&amp;lt;/code&amp;gt; (Microsoft) which includes detection rules for Microsoft Sentinel and Microsoft Defender XDR.&amp;lt;/p&amp;gt;&amp;#xA;&amp;lt;h2 id=&amp;#34;affected-systems&amp;#34;&amp;gt;Affected Systems&amp;lt;/h2&amp;gt;&amp;#xA;&amp;lt;ul&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;Microsoft - Microsoft SharePoint Enterprise Server 2016 - Version: N/A&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;Microsoft - Microsoft SharePoint Server 2019 - Version: 16.0.0   &amp;amp;lt; 16.0.10417.20037&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;Microsoft - Microsoft SharePoint Server Subscription Edition - Version: 16.0.0   &amp;amp;lt; 16.0.18526.20508&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;/ul&amp;gt;&amp;#xA;&amp;lt;h2 id=&amp;#34;credits&amp;#34;&amp;gt;Credits&amp;lt;/h2&amp;gt;&amp;#xA;&amp;lt;ul&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;Thanks to &amp;lt;a href=&amp;#34;https://research.eye.security&amp;#34;&amp;gt;https://research.eye.security&amp;lt;/a&amp;gt; for the discovery.&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;/ul&amp;gt;&amp;#xA;&amp;lt;h2 id=&amp;#34;references&amp;#34;&amp;gt;References&amp;lt;/h2&amp;gt;&amp;#xA;&amp;lt;ul&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;a href=&amp;#34;https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-49706&amp;#34;&amp;gt;Original vulnerability - CVE-2025-49706&amp;lt;/a&amp;gt;&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;a href=&amp;#34;https://vulnerability.circl.lu/vuln/CVE-2025-53770&amp;#34;&amp;gt;CVE-2025-53770 (GCVE-0-2025-53770)&amp;lt;/a&amp;gt; - Deserialization of untrusted data in on-premises Microsoft SharePoint Server allows an unauthorized attacker to execute code over a network.&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;a href=&amp;#34;https://research.eye.security/sharepoint-under-siege/&amp;#34;&amp;gt;SharePoint 0-day uncovered (CVE-2025-53770)&amp;lt;/a&amp;gt;&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;Scanning - &amp;lt;a href=&amp;#34;https://github.com/righel/ms-sharepoint-version-nse&amp;#34;&amp;gt;Nmap script to detect a Microsoft SharePoint instance version&amp;lt;/a&amp;gt;&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;a href=&amp;#34;https://www.microsoft.com/en-us/security/blog/2025/07/22/disrupting-active-exploitation-of-on-premises-sharepoint-vulnerabilities/&amp;#34;&amp;gt;Disrupting active exploitation of on-premises SharePoint vulnerabilities&amp;lt;/a&amp;gt;&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;/ul&amp;gt;&amp;#xA;&amp;lt;h2 id=&amp;#34;timeline&amp;#34;&amp;gt;Timeline&amp;lt;/h2&amp;gt;&amp;#xA;&amp;lt;ul&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;2025-07-20 06:03 - &amp;lt;a href=&amp;#34;https://vulnerability.circl.lu/bundle/7eb6b389-20dd-404f-90c4-314ed370fcc5&amp;#34;&amp;gt;Customer guidance for SharePoint vulnerability CVE-2025-53770 MSRC Blog Microsoft Security Response Center&amp;lt;/a&amp;gt;&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;2025-07-18 18:00 - Initial discover of the ASPX payload by &amp;lt;a href=&amp;#34;https://research.eye.security&amp;#34;&amp;gt;https://research.eye.security&amp;lt;/a&amp;gt;.&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;/ul&amp;gt;&amp;#xA;&amp;lt;h2 id=&amp;#34;classification-of-this-document&amp;#34;&amp;gt;Classification of this document&amp;lt;/h2&amp;gt;&amp;#xA;&amp;lt;p&amp;gt;&amp;lt;a href=&amp;#34;/pub/traffic-light-protocol/&amp;#34;&amp;gt;TLP:CLEAR&amp;lt;/a&amp;gt; information may be distributed without restriction, subject to copyright controls.&amp;lt;/p&amp;gt;&amp;#xA;&amp;lt;h2 id=&amp;#34;revision&amp;#34;&amp;gt;Revision&amp;lt;/h2&amp;gt;&amp;#xA;&amp;lt;ul&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;Version 1.3 - TLP:CLEAR - References updated&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;Version 1.2 - TLP:CLEAR - Clarification for key materials and links fixed - 22nd July 2025&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;Version 1.1 - TLP:CLEAR - Second version including updates and new scanning script - 21st July 2025&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;Version 1.0 - TLP:CLEAR - First version - 20th July 2025&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;/ul&amp;gt;&amp;#xA;</content>
  </entry>
  <entry>
    <title>TR-94 - Ongoing Phishing Campaigns Targeting Microsoft 365 Tenants Lacking Multi-Factor Authentication</title>
    <link href="https://www.circl.lu/pub/tr-94/" rel="alternate" type="text/html" />
    <id>https://www.circl.lu/pub/tr-94/</id>
    <published>2025-05-22T00:00:00Z</published>
    <updated>2025-05-22T00:00:00Z</updated>
    <summary>Executive Summary This report details ongoing phishing campaigns specifically targeting organisations utilizing Microsoft 365, with a primary focus on Office 365 tenants where Multi-Factor Authentication (MFA) is not enforced. Attackers leverage sophisticated social engineering tactics and convincing phishing pages to harvest user credentials. Successful compromise of accounts without MFA allows attackers immediate access, leading to potential data exfiltration, business email compromise (BEC), internal spear-phishing, and deployment of further malicious payloads. This report outlines the attack methodology, observed indicators, potential impact, and critical mitigation strategies, emphasizing the urgent need for MFA deployment.&amp;#xA;</summary>
    <content type="html">&amp;lt;h2 id=&amp;#34;executive-summary&amp;#34;&amp;gt;Executive Summary&amp;lt;/h2&amp;gt;&amp;#xA;&amp;lt;p&amp;gt;This report details ongoing phishing campaigns specifically targeting organisations utilizing Microsoft 365, with a primary focus on Office 365 tenants where Multi-Factor Authentication (MFA) is not enforced. Attackers leverage sophisticated social engineering tactics and convincing phishing pages to harvest user credentials. Successful compromise of accounts without MFA allows attackers immediate access, leading to potential data exfiltration, business email compromise (BEC), internal spear-phishing, and deployment of further malicious payloads. This report outlines the attack methodology, observed indicators, potential impact, and critical mitigation strategies, emphasizing the urgent need for MFA deployment.&amp;lt;/p&amp;gt;&amp;#xA;&amp;lt;h2 id=&amp;#34;attack-vector-and-methodology&amp;#34;&amp;gt;Attack Vector and Methodology&amp;lt;/h2&amp;gt;&amp;#xA;&amp;lt;p&amp;gt;The primary attack vector is phishing emails, often crafted to bypass standard email security filters. The methodology typically follows these stages:&amp;lt;/p&amp;gt;&amp;#xA;&amp;lt;ol&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Reconnaissance (Optional but Common):&amp;lt;/strong&amp;gt; Attackers may gather information about target organisations, including employee names, roles, and M365 usage, often from public sources like LinkedIn or company websites or just MX lookup on the targeted domain.&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Lure / Phishing Email:&amp;lt;/strong&amp;gt;&amp;#xA;&amp;lt;ul&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Themes:&amp;lt;/strong&amp;gt; Common lures include fake security alerts (e.g., &amp;amp;ldquo;Unusual sign-in activity,&amp;amp;rdquo; &amp;amp;ldquo;Password expiry&amp;amp;rdquo;), notifications about shared documents, voicemail notifications, storage quota warnings, or urgent requests from &amp;amp;ldquo;IT support&amp;amp;rdquo; or &amp;amp;ldquo;management.&amp;amp;rdquo;&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Sender Spoofing:&amp;lt;/strong&amp;gt; Attackers may spoof internal email addresses, trusted third-party services, or Microsoft itself.&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Content:&amp;lt;/strong&amp;gt; Emails often contain urgent calls to action, instructing the recipient to click a link to verify their account, view a document, or prevent account suspension.&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;/ul&amp;gt;&amp;#xA;&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Phishing Page:&amp;lt;/strong&amp;gt;&amp;#xA;&amp;lt;ul&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;The link in the phishing email redirects the victim to a fake Microsoft 365 login page.&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;These pages are often pixel-perfect replicas of the legitimate Microsoft login portal, making them difficult for untrained users to distinguish.&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;Domains used for phishing pages are often typosquatted versions of legitimate domains or hosted on compromised websites.&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;/ul&amp;gt;&amp;#xA;&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Credential Harvesting:&amp;lt;/strong&amp;gt;&amp;#xA;&amp;lt;ul&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;The victim enters their M365 username and password into the fake login page.&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;These credentials are then captured by the attacker.&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;/ul&amp;gt;&amp;#xA;&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Account Access &amp;amp;amp; Exploitation (No MFA):&amp;lt;/strong&amp;gt;&amp;#xA;&amp;lt;ul&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;Since MFA is not enabled, the attacker can immediately use the harvested credentials to log into the victim&amp;amp;rsquo;s M365 account.&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;Common post-compromise activities include:&amp;#xA;&amp;lt;ul&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Email Reconnaissance:&amp;lt;/strong&amp;gt; Searching for sensitive information within emails and attachments.&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Setting up Mail Forwarding/Redirection Rules:&amp;lt;/strong&amp;gt; To silently exfiltrate incoming emails or monitor communications.&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Business Email Compromise (BEC):&amp;lt;/strong&amp;gt; Sending fraudulent emails from the compromised account (e.g., requesting wire transfers, changing payment details).&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Internal Spear-Phishing:&amp;lt;/strong&amp;gt; Using the compromised account to send phishing emails to other employees or trusted contacts, leveraging the inherent trust.&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Data Exfiltration:&amp;lt;/strong&amp;gt; Accessing and downloading files from OneDrive, SharePoint, and Teams.&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Further Compromise:&amp;lt;/strong&amp;gt; Planting malware or attempting lateral movement (less common in pure credential phishing but possible).&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;/ul&amp;gt;&amp;#xA;&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;/ul&amp;gt;&amp;#xA;&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;/ol&amp;gt;&amp;#xA;&amp;lt;h2 id=&amp;#34;observed-activity--indicators-of-compromise-iocs&amp;#34;&amp;gt;Observed Activity / Indicators of Compromise (IoCs)&amp;lt;/h2&amp;gt;&amp;#xA;&amp;lt;p&amp;gt;Organisations should monitor for the following indicators:&amp;lt;/p&amp;gt;&amp;#xA;&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Email-based IoCs:&amp;lt;/strong&amp;gt;&amp;lt;/p&amp;gt;&amp;#xA;&amp;lt;ul&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;Emails with urgent subject lines or calls to action related to account security or document access.&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;Sender addresses that are slight variations of legitimate Microsoft or internal domains (e.g., &amp;lt;code&amp;gt;microsft.com&amp;lt;/code&amp;gt;, &amp;lt;code&amp;gt;micosoftonline.com&amp;lt;/code&amp;gt;, &amp;lt;code&amp;gt;company-support.com&amp;lt;/code&amp;gt;).&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;Poor grammar or unusual phrasing in email content.&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;Hyperlinks that, when hovered over, reveal URLs not associated with Microsoft or the organisation.&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;Emails requesting direct credential entry on a linked page.&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;/ul&amp;gt;&amp;#xA;&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Login and Account Activity IoCs (within M365 Audit Logs):&amp;lt;/strong&amp;gt;&amp;lt;/p&amp;gt;&amp;#xA;&amp;lt;ul&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;Logins from unusual or geographically improbable IP addresses or countries.&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;Multiple failed login attempts from an IP followed by a successful login.&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;Logins using legacy authentication protocols (if not explicitly blocked).&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;Creation of unexpected mail forwarding rules or inbox rules (especially those that delete or move messages).&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;Changes to account recovery information (e.g., phone number, alternate email).&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;Unexpected sharing of files or folders from OneDrive or SharePoint.&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;Mass deletion of emails or files.&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;Sent items containing phishing emails or suspicious replies from the compromised account. We advise to closely monitor notification from partners receiving phishing emails from your domain name and existing Office365 accounts.&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;/ul&amp;gt;&amp;#xA;&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Network IoCs:&amp;lt;/strong&amp;gt;&amp;lt;/p&amp;gt;&amp;#xA;&amp;lt;ul&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;DNS lookups to known phishing domains or newly registered domains.&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;Outbound connections to suspicious IP addresses from user workstations after potential credential entry.&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;/ul&amp;gt;&amp;#xA;&amp;lt;h2 id=&amp;#34;impact&amp;#34;&amp;gt;Impact&amp;lt;/h2&amp;gt;&amp;#xA;&amp;lt;p&amp;gt;Successful exploitation of M365 accounts without MFA can lead to severe consequences:&amp;lt;/p&amp;gt;&amp;#xA;&amp;lt;ul&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Data Breach:&amp;lt;/strong&amp;gt; Unauthorized access to sensitive company data, customer information (PII), financial records, and intellectual property stored in emails, OneDrive, and SharePoint.&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Financial Loss:&amp;lt;/strong&amp;gt; Through BEC attacks, invoice fraud, or unauthorized wire transfers.&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Reputational Damage:&amp;lt;/strong&amp;gt; Loss of customer trust and damage to the organisation&amp;amp;rsquo;s brand.&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Operational Disruption:&amp;lt;/strong&amp;gt; Interruption of business processes due to account lockout, data deletion, or system compromise.&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Compliance Violations:&amp;lt;/strong&amp;gt; Potential breaches of data protection regulations (e.g., GDPR, HIPAA) leading to fines and legal action.&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Further Compromise:&amp;lt;/strong&amp;gt; The compromised M365 account can be used as a launchpad for further attacks against internal systems or external partners.&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;/ul&amp;gt;&amp;#xA;&amp;lt;h2 id=&amp;#34;mitigation--recommendations&amp;#34;&amp;gt;Mitigation / Recommendations&amp;lt;/h2&amp;gt;&amp;#xA;&amp;lt;p&amp;gt;The most critical mitigation is the enforcement of Multi-Factor Authentication.&amp;lt;/p&amp;gt;&amp;#xA;&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Immediate and Essential Actions:&amp;lt;/strong&amp;gt;&amp;lt;/p&amp;gt;&amp;#xA;&amp;lt;ul&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Enforce MFA:&amp;lt;/strong&amp;gt;&amp;#xA;&amp;lt;ul&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Prioritize enabling and enforcing MFA for ALL M365 accounts, especially administrative accounts.&amp;lt;/strong&amp;gt; Use strong MFA methods like authenticator apps (e.g., Microsoft Authenticator) or FIDO2 security keys. Avoid SMS-based MFA if possible due to susceptibility to SIM swapping.&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;Utilize Microsoft Entra ID (formerly Azure AD) Conditional Access policies to enforce MFA based on risk, location, or device compliance.&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;/ul&amp;gt;&amp;#xA;&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;User Training and Awareness:&amp;lt;/strong&amp;gt;&amp;#xA;&amp;lt;ul&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;Conduct regular phishing awareness training for all employees.&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;Train users to identify suspicious emails, verify sender addresses, and scrutinize URLs before clicking.&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;Establish a clear procedure for reporting suspected phishing emails.&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;/ul&amp;gt;&amp;#xA;&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;/ul&amp;gt;&amp;#xA;&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Technical Controls and Best Practices:&amp;lt;/strong&amp;gt;&amp;lt;/p&amp;gt;&amp;#xA;&amp;lt;ul&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Disable Legacy Authentication:&amp;lt;/strong&amp;gt; Protocols like POP3, IMAP, SMTP AUTH are often targeted as they may bypass MFA. Block legacy authentication protocols via Conditional Access policies or per-protocol settings.&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Review and Harden M365 Security Settings:&amp;lt;/strong&amp;gt;&amp;#xA;&amp;lt;ul&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;Regularly review M365 audit logs for suspicious activities.&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;Configure alerts for critical events (e.g., suspicious sign-ins, creation of mail forwarding rules).&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;Implement M365 Advanced Threat Protection (ATP) / Microsoft Defender for Office 365 for enhanced email filtering and link protection (Safe Links, Safe Attachments).&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;/ul&amp;gt;&amp;#xA;&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Password Policies:&amp;lt;/strong&amp;gt; Enforce strong, unique passwords for all accounts. Encourage the use of password managers.&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Email Security Gateways:&amp;lt;/strong&amp;gt; Utilize robust email security solutions with anti-phishing capabilities.&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Implement DMARC, DKIM, and SPF:&amp;lt;/strong&amp;gt; To help prevent email spoofing of your domain.&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Principle of Least Privilege:&amp;lt;/strong&amp;gt; Ensure users and administrators only have the permissions necessary for their roles. Regularly review privileged accounts.&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Incident Response Plan:&amp;lt;/strong&amp;gt; Have a well-defined incident response plan for handling compromised accounts and data breaches. This should include steps for isolating affected accounts, investigating the breach, and remediation.&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;/ul&amp;gt;&amp;#xA;&amp;lt;h2 id=&amp;#34;examples&amp;#34;&amp;gt;Examples&amp;lt;/h2&amp;gt;&amp;#xA;&amp;lt;p&amp;gt;Here we will present some anonymized samples. All the name and company details abused by the attackers are valid and the emails come from the real email addresses from your contacts. This is why this attacks are so extremely dangerous.&amp;lt;/p&amp;gt;&amp;#xA;&amp;lt;h3 id=&amp;#34;examples-emails-with-a-phishing-link&amp;#34;&amp;gt;Examples: Emails with a Phishing Link&amp;lt;/h3&amp;gt;&amp;#xA;&amp;lt;pre tabindex=&amp;#34;0&amp;#34;&amp;gt;&amp;lt;code&amp;gt;Subject: #L125673547: &amp;amp;lt;Company Name&amp;amp;gt;&amp;#xA;&amp;#xA;Content:&amp;#xA;&amp;amp;lt;Phishing Link&amp;amp;gt;&amp;#xA;Sincères salutations, mat beschte Gréiss, Best regards,&amp;#xA;&amp;lt;/code&amp;gt;&amp;lt;/pre&amp;gt;&amp;lt;pre tabindex=&amp;#34;0&amp;#34;&amp;gt;&amp;lt;code&amp;gt;Subject: Votre facture - Compte 30031798047374-3772733 Architect &amp;amp;lt;Company Name&amp;amp;gt; vom 06.03.25&amp;#xA;&amp;#xA;Content:&amp;#xA;&amp;amp;lt;Phishing Link&amp;amp;gt;&amp;#xA;Cordialement,&amp;#xA;&amp;amp;lt;Name &amp;amp;amp; Company Address&amp;amp;gt;&amp;#xA;&amp;lt;/code&amp;gt;&amp;lt;/pre&amp;gt;&amp;lt;h3 id=&amp;#34;examples-emails-with-a-rmm-tool-link&amp;#34;&amp;gt;Examples: Emails with a RMM Tool Link&amp;lt;/h3&amp;gt;&amp;#xA;&amp;lt;pre tabindex=&amp;#34;0&amp;#34;&amp;gt;&amp;lt;code&amp;gt;Subject: MISE EN DEMEURE&amp;#xA;&amp;#xA;Content:&amp;#xA;Madame, Monsieur&amp;#xA;&amp;#xA;Je me permets de vous écrire en ma qualité d&amp;amp;#39;avocat représentant les intérêts de mon client, qui m&amp;amp;#39;a mandaté pour défendre ses droits à l&amp;amp;#39;encontre de votre société concernant des impayées.&amp;#xA;Malgré plusieurs relances, la somme due pour les services rendus conformément au contrat n&amp;amp;#39;a toujours pas été effectuée.&amp;#xA;&amp;#xA;Par la présente, Nous vous prions de bien vouloir prendre connaissance de la mise en demeure ci-jointe et procéder au règlement intégral à la réception de ce courrier, à défaut de quoi nous serons contraints d&amp;amp;#39;engager toutes les procédures judiciaires nécessaires à la défense des droits de mon client.&amp;#xA;&amp;#xA;&amp;amp;lt;Link: Download RMM Tool&amp;amp;gt;&amp;#xA;&amp;#xA;Cordialement.&amp;#xA;Avocat à la Cour&amp;#xA;&amp;lt;/code&amp;gt;&amp;lt;/pre&amp;gt;&amp;lt;pre tabindex=&amp;#34;0&amp;#34;&amp;gt;&amp;lt;code&amp;gt;Subject: ATTENTION - FACTURE IMPAYEE&amp;#xA;&amp;#xA;Content:&amp;#xA;Bonjour Monsieur, Madame,&amp;#xA;&amp;#xA;Sauf erreur de notre part, après consultations de nos comptes, nous constatons que nous n&amp;amp;#39;avons toujours pas reçu le paiement de la facture ci-jointe malgré nos relances.&amp;#xA;&amp;#xA;&amp;amp;lt;Link: Download RMM Tool&amp;amp;gt;&amp;#xA;&amp;#xA;Nous vous prions de bien vouloir effectuer le paiement dans les meilleurs délais.&amp;#xA;&amp;#xA;Cordialement&amp;#xA;&amp;amp;lt;Name &amp;amp;amp; Company Address&amp;amp;gt;&amp;#xA;&amp;lt;/code&amp;gt;&amp;lt;/pre&amp;gt;&amp;lt;h2 id=&amp;#34;conclusion&amp;#34;&amp;gt;Conclusion&amp;lt;/h2&amp;gt;&amp;#xA;&amp;lt;p&amp;gt;Phishing attacks targeting Microsoft 365 tenants remain a persistent and evolving threat. Microsoft is still not enforcing by default the multi-factor authentication. Organisations that have not implemented Multi-Factor Authentication are at significantly higher risk of account compromise, leading to potentially devastating consequences. The immediate enforcement of MFA, coupled with robust security practices and ongoing user education, is paramount to defending against these attacks and safeguarding organisational assets. Ignoring this critical security layer is no longer an option in the current threat landscape.&amp;lt;/p&amp;gt;&amp;#xA;&amp;lt;h2 id=&amp;#34;8-references-optional&amp;#34;&amp;gt;8. References (Optional)&amp;lt;/h2&amp;gt;&amp;#xA;&amp;lt;ul&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;Microsoft: &amp;lt;a href=&amp;#34;https://learn.microsoft.com/en-us/microsoft-365/admin/security-and-compliance/set-up-multi-factor-authentication&amp;#34;&amp;gt;Set up multifactor authentication for users&amp;lt;/a&amp;gt;&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;Microsoft: &amp;lt;a href=&amp;#34;https://learn.microsoft.com/en-us/microsoft-365/security/office-365-security/responding-to-a-compromised-email-account&amp;#34;&amp;gt;How to investigate a compromised email account&amp;lt;/a&amp;gt;&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;/ul&amp;gt;&amp;#xA;&amp;lt;h2 id=&amp;#34;significance-for-luxembourg&amp;#34;&amp;gt;Significance for Luxembourg&amp;lt;/h2&amp;gt;&amp;#xA;&amp;lt;p&amp;gt;We observed more than 48 organisations with M365 account compromised in the past 7 days starting from 21st May 2025.&amp;lt;/p&amp;gt;&amp;#xA;&amp;lt;h2 id=&amp;#34;classification-of-this-document&amp;#34;&amp;gt;Classification of this document&amp;lt;/h2&amp;gt;&amp;#xA;&amp;lt;p&amp;gt;&amp;lt;a href=&amp;#34;/pub/traffic-light-protocol/&amp;#34;&amp;gt;TLP:CLEAR&amp;lt;/a&amp;gt; information may be distributed without restriction, subject to copyright controls.&amp;lt;/p&amp;gt;&amp;#xA;&amp;lt;h2 id=&amp;#34;revision&amp;#34;&amp;gt;Revision&amp;lt;/h2&amp;gt;&amp;#xA;&amp;lt;ul&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;Version 1.0 - TLP:CLEAR - First version - 21st May 2025&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;/ul&amp;gt;&amp;#xA;</content>
  </entry>
  <entry>
    <title>TR-93 - Fraude financière après compromission du système via des outils de gestion et de surveillance à distance</title>
    <link href="https://www.circl.lu/pub/tr-93/fr/" rel="alternate" type="text/html" />
    <id>https://www.circl.lu/pub/tr-93/fr/</id>
    <published>2025-02-26T00:00:00Z</published>
    <updated>2025-02-26T00:00:00Z</updated>
    <summary>Résumé Ce document décrit une attaque de type Malspam ciblant les entreprises via des e-mails frauduleux exploitant des outils de gestion et de surveillance à distance (Remote Monitoring &amp;amp; Management - RMM). Les attaquants trompent les destinataires en leur faisant cliquer sur un lien malveillant, déguisé en facture, qui installe un outil RMM sur leur système. Comme ces outils sont des applications légitimes, ils contournent les antivirus et permettent aux attaquants d’obtenir un accès distant complet.&amp;#xA;</summary>
    <content type="html">&amp;lt;h2 id=&amp;#34;résumé&amp;#34;&amp;gt;Résumé&amp;lt;/h2&amp;gt;&amp;#xA;&amp;lt;p&amp;gt;Ce document décrit une attaque de type &amp;lt;strong&amp;gt;Malspam&amp;lt;/strong&amp;gt; ciblant les entreprises via des e-mails frauduleux exploitant des outils de &amp;lt;strong&amp;gt;gestion et de surveillance à distance (Remote Monitoring &amp;amp;amp; Management - RMM)&amp;lt;/strong&amp;gt;. Les attaquants trompent les destinataires en leur faisant cliquer sur un lien malveillant, déguisé en facture, qui installe un &amp;lt;strong&amp;gt;outil RMM sur leur système&amp;lt;/strong&amp;gt;. Comme ces outils sont des applications légitimes, ils contournent les antivirus et permettent aux attaquants d&amp;amp;rsquo;obtenir un &amp;lt;strong&amp;gt;accès distant complet&amp;lt;/strong&amp;gt;.&amp;lt;/p&amp;gt;&amp;#xA;&amp;lt;p&amp;gt;Une fois l&amp;amp;rsquo;accès établi, les attaquants renforcent leur contrôle en installant des outils RMM supplémentaires, en diffusant des e-mails malveillants et en modifiant les paramètres du système. Leur objectif principal est d’exploiter les stations de travail compromises – souvent celles des comptables ou responsables financiers – pour &amp;lt;strong&amp;gt;intercepter les codes PIN des cartes à puce&amp;lt;/strong&amp;gt; et exécuter des &amp;lt;strong&amp;gt;transferts frauduleux&amp;lt;/strong&amp;gt;, entraînant des pertes financières considérables.&amp;lt;/p&amp;gt;&amp;#xA;&amp;lt;p&amp;gt;Ce document propose une analyse détaillée du mode opératoire, des risques encourus et des mesures de protection recommandées pour se prémunir contre ces attaques.&amp;lt;/p&amp;gt;&amp;#xA;&amp;lt;h2 id=&amp;#34;impact-au-luxembourg&amp;#34;&amp;gt;Impact au Luxembourg&amp;lt;/h2&amp;gt;&amp;#xA;&amp;lt;p&amp;gt;Ces dernières semaines, plusieurs organisations et particuliers nous ont signalé des demandes inhabituelles de leurs banques, telles que :&amp;lt;/p&amp;gt;&amp;#xA;&amp;lt;ul&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;em&amp;gt;« Voulez-vous vraiment effectuer 10 transactions pour un total de 30.000 EUR vers l&amp;amp;rsquo;étranger ? »&amp;lt;/em&amp;gt;&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;em&amp;gt;« Voulez-vous vraiment exécuter un virement de 1.000.000 EUR vers l&amp;amp;rsquo;étranger ? »&amp;lt;/em&amp;gt;&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;/ul&amp;gt;&amp;#xA;&amp;lt;p&amp;gt;Ces transactions sont &amp;lt;strong&amp;gt;réelles et ont été initiées par des attaquants&amp;lt;/strong&amp;gt;, qui ont pris le contrôle du système bancaire de la victime en installant des &amp;lt;strong&amp;gt;outils de gestion et de surveillance à distance (RMM)&amp;lt;/strong&amp;gt;.&amp;lt;br&amp;gt;&amp;#xA;L’infection initiale se fait par des &amp;lt;strong&amp;gt;attaques de phishing et de spear-phishing&amp;lt;/strong&amp;gt;, comme décrit ci-dessous.&amp;lt;/p&amp;gt;&amp;#xA;&amp;lt;h2 id=&amp;#34;mode-opératoire&amp;#34;&amp;gt;Mode opératoire&amp;lt;/h2&amp;gt;&amp;#xA;&amp;lt;ol&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;L&amp;amp;rsquo;attaquant envoie un &amp;lt;strong&amp;gt;e-mail frauduleux&amp;lt;/strong&amp;gt; contenant une fausse facture en pièce jointe.&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;La pièce jointe est en réalité &amp;lt;strong&amp;gt;un lien&amp;lt;/strong&amp;gt; qui télécharge un &amp;lt;strong&amp;gt;outil RMM&amp;lt;/strong&amp;gt; sur l’ordinateur de la victime.&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;Si la victime clique sur le lien, l’outil RMM est installé sur son système.&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;L&amp;amp;rsquo;antivirus ne détecte pas l&amp;amp;rsquo;outil RMM comme malveillant&amp;lt;/strong&amp;gt;, car il s&amp;amp;rsquo;agit d&amp;amp;rsquo;une application légitime.&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;L&amp;amp;rsquo;attaquant obtient un &amp;lt;strong&amp;gt;accès distant total&amp;lt;/strong&amp;gt; au système et peut capturer le &amp;lt;strong&amp;gt;code PIN des cartes à puce&amp;lt;/strong&amp;gt; utilisées pour l’authentification bancaire.&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;L’attaquant exécute ensuite les actions suivantes :&amp;#xA;&amp;lt;ul&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Installation d’autres outils RMM&amp;lt;/strong&amp;gt; pour assurer un accès persistant.&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;Envoi d’e-mails frauduleux aux contacts du carnet d’adresses de la victime.&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;Analyse approfondie du système compromis.&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;Modification des paramètres système pour atteindre ses objectifs.&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Exécution de transactions financières frauduleuses.&amp;lt;/strong&amp;gt;&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;/ul&amp;gt;&amp;#xA;&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;/ol&amp;gt;&amp;#xA;&amp;lt;h3 id=&amp;#34;exemples-récents&amp;#34;&amp;gt;Exemples récents&amp;lt;/h3&amp;gt;&amp;#xA;&amp;lt;pre tabindex=&amp;#34;0&amp;#34;&amp;gt;&amp;lt;code&amp;gt;Objet : Recouvrement de facture impayée – Facture no FACT#062024 et FACT#072024 datée du 15/06/2024&amp;#xA;&amp;#xA;Monsieur, Madame,&amp;#xA;&amp;#xA;La présente communication concerne la facture no FACT#032024 et FACT#042024 au montant total de 32.857€ qui Recouvrement de facture impayée – Facture no FACT#062024 et FACT#072024 datée du 15/06/2024. Vous trouverez en annexe une copie de la facture pertinente.&amp;#xA;&amp;#xA;Comme vous le savez, nous vous avons fourni le delai de recouvrement du dossier R1184521. Or, malgré le rappel effectué le 15/06/2024 à laquelle une lettre de relance a été envoyée, nous constatons que la facture demeure impayée, et ce, bien que nous ayons rempli toutes nos obligations.&amp;#xA;&amp;#xA;Ainsi, nous vous prions de nous faire parvenir un chèque certifié au montant de 32.857€ à l’ordre de notre entreprise dans les 10 jours de la réception de la présente mise en demeure. Le chèque devra être transmis au notre adresse. À défaut, une demande en justice pourrait être déposée contre vous, sans autre avis ni délai.&amp;#xA;&amp;#xA;Soyez avisé que nous considérerons de bonne foi tout mode alternatif de règlement proposé. Nous sommes d’avis qu’il est dans l’intérêt de tous que cette situation puisse être réglée à l’amiable. En ce sens, nous vous invitons à communiquer avec nous si vous désirez discuter de la présente mise en demeure.&amp;#xA;&amp;#xA;Nous vous invitons à ignorer la présente lettre si le paiement a été effectué avant la date de réception de cette communication.&amp;#xA;&amp;#xA;VEUILLEZ AGIR EN CONSÉQUENCE.                                 &amp;#xA;&amp;lt;/code&amp;gt;&amp;lt;/pre&amp;gt;&amp;lt;h2 id=&amp;#34;mesures-de-protection&amp;#34;&amp;gt;Mesures de protection&amp;lt;/h2&amp;gt;&amp;#xA;&amp;lt;p&amp;gt;Pour prévenir ces &amp;lt;strong&amp;gt;attaques de type Malspam&amp;lt;/strong&amp;gt; (e-mails malveillants contenant des liens menant à des logiciels indésirables), une &amp;lt;strong&amp;gt;approche de sécurité multicouche&amp;lt;/strong&amp;gt; est indispensable. Voici quelques &amp;lt;strong&amp;gt;mesures efficaces&amp;lt;/strong&amp;gt; :&amp;lt;/p&amp;gt;&amp;#xA;&amp;lt;h3 id=&amp;#34;1-sécurisation-des-e-mails&amp;#34;&amp;gt;1. Sécurisation des e-mails&amp;lt;/h3&amp;gt;&amp;#xA;&amp;lt;ul&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Filtres avancés&amp;lt;/strong&amp;gt; – Utilisation de &amp;lt;strong&amp;gt;passerelles sécurisées&amp;lt;/strong&amp;gt; et de &amp;lt;strong&amp;gt;filtres anti-spam&amp;lt;/strong&amp;gt;.&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Désactivation du téléchargement automatique des pièces jointes&amp;lt;/strong&amp;gt;.&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Analyse et sandboxing des liens&amp;lt;/strong&amp;gt; – Vérification des URL en temps réel.&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;CIRCL propose un &amp;lt;strong&amp;gt;service en ligne gratuit pour analyser les pièces jointes des e-mails&amp;lt;/strong&amp;gt;: &amp;lt;a href=&amp;#34;https://pandora.circl.lu&amp;#34;&amp;gt;pandora&amp;lt;/a&amp;gt;&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;/ul&amp;gt;&amp;#xA;&amp;lt;h3 id=&amp;#34;2-sensibilisation-et-formation-des-utilisateurs&amp;#34;&amp;gt;2. Sensibilisation et formation des utilisateurs&amp;lt;/h3&amp;gt;&amp;#xA;&amp;lt;ul&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Campagnes de sensibilisation&amp;lt;/strong&amp;gt; – Former les employés à &amp;lt;strong&amp;gt;ne pas cliquer sur des liens suspects&amp;lt;/strong&amp;gt;.&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Survol des liens avant de cliquer&amp;lt;/strong&amp;gt; pour vérifier leur destination.&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Simulations de phishing&amp;lt;/strong&amp;gt; – Tests réguliers pour entraîner les employés à détecter les e-mails frauduleux.&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;CIRCL propose un &amp;lt;strong&amp;gt;service en ligne gratuit pour l&amp;amp;rsquo;analyse des URL&amp;lt;/strong&amp;gt;: &amp;lt;a href=&amp;#34;https://lookyloo.circl.lu&amp;#34;&amp;gt;lookyloo&amp;lt;/a&amp;gt;&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;/ul&amp;gt;&amp;#xA;&amp;lt;h3 id=&amp;#34;3-protection-des-postes-de-travail-et-du-réseau&amp;#34;&amp;gt;3. Protection des postes de travail et du réseau&amp;lt;/h3&amp;gt;&amp;#xA;&amp;lt;ul&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Filtrage des URL malveillantes&amp;lt;/strong&amp;gt; – Blocage des domaines frauduleux via un proxy ou un outil de sécurité.&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Whitelisting des applications&amp;lt;/strong&amp;gt; – Seules les applications autorisées peuvent s’exécuter.&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Solutions avancées de détection (EDR/NGAV)&amp;lt;/strong&amp;gt; – Surveillance et blocage des comportements malveillants.&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;/ul&amp;gt;&amp;#xA;&amp;lt;h3 id=&amp;#34;4-authentification-et-protection-contre-lusurpation-didentité&amp;#34;&amp;gt;4. Authentification et protection contre l’usurpation d’identité&amp;lt;/h3&amp;gt;&amp;#xA;&amp;lt;ul&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Mise en place de DMARC, DKIM et SPF&amp;lt;/strong&amp;gt; – Protection contre le &amp;lt;strong&amp;gt;spoofing d&amp;amp;rsquo;e-mail&amp;lt;/strong&amp;gt;.&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Surveillance des noms de domaine&amp;lt;/strong&amp;gt; – Enregistrement de variantes pour prévenir l’usurpation.&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Configuration correcte du DNS&amp;lt;/strong&amp;gt; - voir &amp;lt;a href=&amp;#34;/pub/tr-92/&amp;#34;&amp;gt;TR-92&amp;lt;/a&amp;gt;.&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;/ul&amp;gt;&amp;#xA;&amp;lt;h3 id=&amp;#34;5-gestion-des-accès-et-principe-du-moindre-privilège&amp;#34;&amp;gt;5. Gestion des accès et principe du moindre privilège&amp;lt;/h3&amp;gt;&amp;#xA;&amp;lt;ul&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Restriction des droits utilisateur&amp;lt;/strong&amp;gt; – Pas de droits administrateurs sans nécessité.&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Authentification renforcée&amp;lt;/strong&amp;gt; – Vérification des actions sensibles.&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Désactivation des macros et de l&amp;amp;rsquo;exécution automatique des scripts&amp;lt;/strong&amp;gt;.&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;/ul&amp;gt;&amp;#xA;&amp;lt;h3 id=&amp;#34;6-autres-bonnes-pratiques&amp;#34;&amp;gt;6. Autres bonnes pratiques&amp;lt;/h3&amp;gt;&amp;#xA;&amp;lt;ul&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Mises à jour régulières des logiciels et du système d’exploitation&amp;lt;/strong&amp;gt;.&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Désactivation des extensions de navigateur non essentielles&amp;lt;/strong&amp;gt;.&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;/ul&amp;gt;&amp;#xA;&amp;lt;h3 id=&amp;#34;7-surveillance-et-réponse-aux-incidents&amp;#34;&amp;gt;7. Surveillance et réponse aux incidents&amp;lt;/h3&amp;gt;&amp;#xA;&amp;lt;ul&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Surveillance via SIEM&amp;lt;/strong&amp;gt; – Détection des comportements anormaux.&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Plan de réponse aux incidents&amp;lt;/strong&amp;gt; – Isolement rapide des appareils compromis.&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;/ul&amp;gt;&amp;#xA;&amp;lt;h2 id=&amp;#34;que-faire-en-cas-de-compromission-&amp;#34;&amp;gt;Que faire en cas de compromission ?&amp;lt;/h2&amp;gt;&amp;#xA;&amp;lt;ul&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Déconnecter immédiatement l’ordinateur compromis du réseau (y compris le Wi-Fi !)&amp;lt;/strong&amp;gt;.&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Contacter votre équipe de réponse aux incidents ou CIRCL&amp;lt;/strong&amp;gt;.&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Informer l’équipe IT&amp;lt;/strong&amp;gt; pour une surveillance renforcée.&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Identifier d’autres systèmes potentiellement touchés&amp;lt;/strong&amp;gt;.&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Avertir vos contacts&amp;lt;/strong&amp;gt; de ne pas ouvrir de liens provenant de votre entreprise.&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Former le personnel&amp;lt;/strong&amp;gt; à détecter ces attaques.&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Déclarer la violation à la CNPD dans les 72 heures&amp;lt;/strong&amp;gt; si des données personnelles sont compromises.&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;/ul&amp;gt;&amp;#xA;&amp;lt;h2 id=&amp;#34;contre-mesures-efficaces&amp;#34;&amp;gt;Contre-mesures efficaces&amp;lt;/h2&amp;gt;&amp;#xA;&amp;lt;h3 id=&amp;#34;les-solutions-inefficaces-proposées-par-certains-prestataires-it&amp;#34;&amp;gt;&amp;lt;strong&amp;gt;Les solutions inefficaces proposées par certains prestataires IT&amp;lt;/strong&amp;gt;&amp;lt;/h3&amp;gt;&amp;#xA;&amp;lt;p&amp;gt;Un simple scan antivirus est &amp;lt;strong&amp;gt;insuffisant&amp;lt;/strong&amp;gt;, car :&amp;lt;/p&amp;gt;&amp;#xA;&amp;lt;ul&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Les outils RMM légitimes ne sont pas détectés comme malveillants&amp;lt;/strong&amp;gt;.&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Des portes dérobées peuvent rester actives&amp;lt;/strong&amp;gt;.&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;L&amp;amp;rsquo;attaquant peut rétablir son accès rapidement&amp;lt;/strong&amp;gt;.&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;/ul&amp;gt;&amp;#xA;&amp;lt;h3 id=&amp;#34;les-bonnes-pratiques-à-adopter&amp;#34;&amp;gt;&amp;lt;strong&amp;gt;Les bonnes pratiques à adopter&amp;lt;/strong&amp;gt;&amp;lt;/h3&amp;gt;&amp;#xA;&amp;lt;ul&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Déployer une solution EDR&amp;lt;/strong&amp;gt; et mettre en place une &amp;lt;strong&amp;gt;liste blanche des outils RMM&amp;lt;/strong&amp;gt;.&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Utilisez LuxTrust Mobile ou LuxTrust Scan&amp;lt;/strong&amp;gt; au lieu d&amp;amp;rsquo;une carte à puce pour vous authentifier (voir la &amp;lt;a href=&amp;#34;https://www.multiline.lu/wp-content/uploads/2019/12/Utilisation-du-LuxTrust-Scan-et-du-LuxTrust-Mobile-dans-MultiLineV4.pdf&amp;#34;&amp;gt;documentation LuxTrust&amp;lt;/a&amp;gt;)&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Retirer la carte à puce du lecteur lorsqu’elle n’est pas utilisée&amp;lt;/strong&amp;gt;.&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Mettre en place une validation à deux personnes pour les transactions bancaires&amp;lt;/strong&amp;gt;.&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Activer des facteurs d’authentification supplémentaires&amp;lt;/strong&amp;gt;.&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Choisir une banque qui effectue une vérification des bénéficiaires&amp;lt;/strong&amp;gt;.&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;/ul&amp;gt;&amp;#xA;&amp;lt;h2 id=&amp;#34;récupération-après-compromission&amp;#34;&amp;gt;Récupération après compromission&amp;lt;/h2&amp;gt;&amp;#xA;&amp;lt;ul&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Contacter immédiatement la banque&amp;lt;/strong&amp;gt; pour tenter de bloquer les transactions frauduleuses.&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Déposer une plainte auprès de la police&amp;lt;/strong&amp;gt;.&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Contacter CIRCL&amp;lt;/strong&amp;gt; pour une analyse approfondie.&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Réinstaller complètement le système compromis&amp;lt;/strong&amp;gt;.&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Surveiller les accès à distance (RDP, VPN, etc.)&amp;lt;/strong&amp;gt;.&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Réinitialiser tous les mots de passe&amp;lt;/strong&amp;gt;.&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Activer l’authentification à deux facteurs (2FA)&amp;lt;/strong&amp;gt;.&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Renforcer la formation des employés&amp;lt;/strong&amp;gt;.&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;/ul&amp;gt;&amp;#xA;&amp;lt;h2 id=&amp;#34;conclusion&amp;#34;&amp;gt;Conclusion&amp;lt;/h2&amp;gt;&amp;#xA;&amp;lt;p&amp;gt;Un simple scan antivirus &amp;lt;strong&amp;gt;ne suffit pas&amp;lt;/strong&amp;gt;. Pour une récupération complète, il est nécessaire de &amp;lt;strong&amp;gt;réinstaller totalement le système affecté&amp;lt;/strong&amp;gt;.&amp;lt;/p&amp;gt;&amp;#xA;&amp;lt;h2 id=&amp;#34;ioc&amp;#34;&amp;gt;IoC&amp;lt;/h2&amp;gt;&amp;#xA;&amp;lt;p&amp;gt;Voir l&amp;amp;rsquo;événement MISP UUID 5f7819de-5656-4063-a76a-a39253ee5154, disponible sur l&amp;amp;rsquo;instance &amp;lt;a href=&amp;#34;https://misppriv.circl.lu/events/view/278450&amp;#34;&amp;gt;MISP pour le secteur privé&amp;lt;/a&amp;gt;.&amp;lt;/p&amp;gt;&amp;#xA;&amp;lt;h2 id=&amp;#34;classification-du-document&amp;#34;&amp;gt;Classification du document&amp;lt;/h2&amp;gt;&amp;#xA;&amp;lt;p&amp;gt;&amp;lt;a href=&amp;#34;/pub/traffic-light-protocol/&amp;#34;&amp;gt;TLP:CLEAR&amp;lt;/a&amp;gt; – Diffusion libre sous réserve du respect des droits d’auteur.&amp;lt;/p&amp;gt;&amp;#xA;&amp;lt;h2 id=&amp;#34;révision&amp;#34;&amp;gt;Révision&amp;lt;/h2&amp;gt;&amp;#xA;&amp;lt;ul&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;Version 1.0 - TLP:CLEAR - Première version - 26 février 2025&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;/ul&amp;gt;&amp;#xA;</content>
  </entry>
  <entry>
    <title>TR-93 - Finanzbetrug nach Systemkompromittierung über Remote-Management- und Monitoring-Tools</title>
    <link href="https://www.circl.lu/pub/tr-93/de/" rel="alternate" type="text/html" />
    <id>https://www.circl.lu/pub/tr-93/de/</id>
    <published>2025-02-26T00:00:00Z</published>
    <updated>2025-02-26T00:00:00Z</updated>
    <summary>Zusammenfassung Dieses Dokument beschreibt eine Malspam-Attacke, die sich gegen Unternehmen richtet, indem betrügerische E-Mails versendet werden, die Remote-Monitoring &amp;amp; Management (RMM)-Tools ausnutzen. Die Angreifer täuschen die Empfänger dazu, auf einen schädlichen Link zu klicken, der als Rechnung getarnt ist und ein RMM-Tool auf ihrem System installiert. Da diese Tools legitime Anwendungen sind, umgehen sie Antiviren-Erkennungen und ermöglichen den Angreifern vollständigen Fernzugriff.&amp;#xA;Sobald der Zugriff erlangt ist, eskalieren die Angreifer ihre Kontrolle, indem sie zusätzliche RMM-Tools zur Persistenz installieren, Malware über E-Mails verbreiten und Systemeinstellungen ändern. Besonders kritisch ist, dass sie kompromittierte Arbeitsstationen – oft von Buchhaltern oder Finanzverantwortlichen – ausnutzen, um Smartcard-PINs abzufangen und betrügerische Überweisungen auszuführen, was zu erheblichen finanziellen Verlusten führt.&amp;#xA;</summary>
    <content type="html">&amp;lt;h2 id=&amp;#34;zusammenfassung&amp;#34;&amp;gt;Zusammenfassung&amp;lt;/h2&amp;gt;&amp;#xA;&amp;lt;p&amp;gt;Dieses Dokument beschreibt eine Malspam-Attacke, die sich gegen Unternehmen richtet, indem betrügerische E-Mails versendet werden, die Remote-Monitoring &amp;amp;amp; Management (RMM)-Tools ausnutzen. Die Angreifer täuschen die Empfänger dazu, auf einen schädlichen Link zu klicken, der als Rechnung getarnt ist und ein RMM-Tool auf ihrem System installiert. Da diese Tools legitime Anwendungen sind, umgehen sie Antiviren-Erkennungen und ermöglichen den Angreifern vollständigen Fernzugriff.&amp;lt;/p&amp;gt;&amp;#xA;&amp;lt;p&amp;gt;Sobald der Zugriff erlangt ist, eskalieren die Angreifer ihre Kontrolle, indem sie zusätzliche RMM-Tools zur Persistenz installieren, Malware über E-Mails verbreiten und Systemeinstellungen ändern. Besonders kritisch ist, dass sie kompromittierte Arbeitsstationen – oft von Buchhaltern oder Finanzverantwortlichen – ausnutzen, um Smartcard-PINs abzufangen und betrügerische Überweisungen auszuführen, was zu erheblichen finanziellen Verlusten führt.&amp;lt;/p&amp;gt;&amp;#xA;&amp;lt;p&amp;gt;Dieses Dokument bietet eine detaillierte Analyse des Modus Operandi, der Risiken und der empfohlenen Schutzmaßnahmen zur Abwehr solcher Angriffe.&amp;lt;/p&amp;gt;&amp;#xA;&amp;lt;h2 id=&amp;#34;bedeutung-für-luxemburg&amp;#34;&amp;gt;Bedeutung für Luxemburg&amp;lt;/h2&amp;gt;&amp;#xA;&amp;lt;p&amp;gt;In den letzten Wochen haben wir mehrere Berichte von Organisationen und Einzelpersonen erhalten, die verdächtige Anfragen von ihren Banken gemeldet haben, wie zum Beispiel:&amp;lt;/p&amp;gt;&amp;#xA;&amp;lt;ul&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;em&amp;gt;„Möchten Sie wirklich 10 Transaktionen im Gesamtwert von ca. 30.000 EUR ins Ausland ausführen?“&amp;lt;/em&amp;gt;&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;em&amp;gt;„Möchten Sie wirklich eine Transaktion über 1.000.000 EUR ins Ausland ausführen?“&amp;lt;/em&amp;gt;&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;/ul&amp;gt;&amp;#xA;&amp;lt;p&amp;gt;Diese Transaktionen sind &amp;lt;strong&amp;gt;echt und wurden von Angreifern ausgeführt&amp;lt;/strong&amp;gt;, die Zugriff auf das Bankensystem des Opfers erlangt haben, indem sie &amp;lt;strong&amp;gt;legitime Remote-Management- und Monitoring-Tools (RMM)&amp;lt;/strong&amp;gt; installiert haben.&amp;lt;br&amp;gt;&amp;#xA;Die Erstinfektion erfolgt über Phishing- und Spear-Phishing-Angriffe, wie unten beschrieben.&amp;lt;/p&amp;gt;&amp;#xA;&amp;lt;h2 id=&amp;#34;modus-operandi&amp;#34;&amp;gt;Modus Operandi&amp;lt;/h2&amp;gt;&amp;#xA;&amp;lt;ol&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;Der Angreifer sendet eine betrügerische geschäftliche E-Mail mit einer gefälschten Rechnung als Anhang.&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;Der Anhang ist tatsächlich ein Link, der ein Remote-Monitoring- &amp;amp;amp; Management-Tool (RMM) herunterlädt.&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;Wenn das Opfer den Link anklickt, wird das RMM-Tool auf seinem System installiert.&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Antivirus-Software erkennt das RMM-Tool nicht als bösartig, da es sich um legitime Anwendungen handelt.&amp;lt;/strong&amp;gt;&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;Das RMM-Tool gewährt dem Angreifer vollständigen Fernzugriff auf den Computer des Opfers, wodurch er die &amp;lt;strong&amp;gt;mehrstufige Smartcard-PIN&amp;lt;/strong&amp;gt; erfassen kann.&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;Der Angreifer führt dann folgende Aktionen durch:&amp;#xA;&amp;lt;ul&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Installation weiterer legitimer RMM-Tools&amp;lt;/strong&amp;gt; zur Aufrechterhaltung des Zugriffs.&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;Versenden infizierter E-Mails an Kontakte im Adressbuch des Opfers.&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;Analyse des kompromittierten Systems.&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;Modifikation von Systemeinstellungen zur Erreichung seiner Ziele.&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Durchführung betrügerischer Finanztransaktionen.&amp;lt;/strong&amp;gt;&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;/ul&amp;gt;&amp;#xA;&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;/ol&amp;gt;&amp;#xA;&amp;lt;h3 id=&amp;#34;aktuelle-beispiele-französisch&amp;#34;&amp;gt;Aktuelle Beispiele (Französisch)&amp;lt;/h3&amp;gt;&amp;#xA;&amp;lt;pre tabindex=&amp;#34;0&amp;#34;&amp;gt;&amp;lt;code&amp;gt;Objet : Recouvrement de facture impayée – Facture no FACT#062024 et FACT#072024 datée du 15/06/2024&amp;#xA;&amp;#xA;Monsieur, Madame,&amp;#xA;&amp;#xA;La présente communication concerne la facture no FACT#032024 et FACT#042024 au montant total de 32.857€ qui Recouvrement de facture impayée – Facture no FACT#062024 et FACT#072024 datée du 15/06/2024. Vous trouverez en annexe une copie de la facture pertinente.&amp;#xA;&amp;#xA;Comme vous le savez, nous vous avons fourni le delai de recouvrement du dossier R1184521. Or, malgré le rappel effectué le 15/06/2024 à laquelle une lettre de relance a été envoyée, nous constatons que la facture demeure impayée, et ce, bien que nous ayons rempli toutes nos obligations.&amp;#xA;&amp;#xA;Ainsi, nous vous prions de nous faire parvenir un chèque certifié au montant de 32.857€ à l’ordre de notre entreprise dans les 10 jours de la réception de la présente mise en demeure. Le chèque devra être transmis au notre adresse. À défaut, une demande en justice pourrait être déposée contre vous, sans autre avis ni délai.&amp;#xA;&amp;#xA;Soyez avisé que nous considérerons de bonne foi tout mode alternatif de règlement proposé. Nous sommes d’avis qu’il est dans l’intérêt de tous que cette situation puisse être réglée à l’amiable. En ce sens, nous vous invitons à communiquer avec nous si vous désirez discuter de la présente mise en demeure.&amp;#xA;&amp;#xA;Nous vous invitons à ignorer la présente lettre si le paiement a été effectué avant la date de réception de cette communication.&amp;#xA;&amp;#xA;VEUILLEZ AGIR EN CONSÉQUENCE.                                 &amp;#xA;&amp;lt;/code&amp;gt;&amp;lt;/pre&amp;gt;&amp;lt;h2 id=&amp;#34;schutzmaßnahmen&amp;#34;&amp;gt;Schutzmaßnahmen&amp;lt;/h2&amp;gt;&amp;#xA;&amp;lt;p&amp;gt;Die Verhinderung solcher &amp;lt;strong&amp;gt;Malspam-Angriffe&amp;lt;/strong&amp;gt; (bösartige Spam-Mails mit Links zum Herunterladen von Malware) erfordert einen &amp;lt;strong&amp;gt;mehrschichtigen Sicherheitsansatz&amp;lt;/strong&amp;gt;. Nachfolgend effektive &amp;lt;strong&amp;gt;Schutzmaßnahmen&amp;lt;/strong&amp;gt;:&amp;lt;/p&amp;gt;&amp;#xA;&amp;lt;h3 id=&amp;#34;1-e-mail-sicherheitsmaßnahmen&amp;#34;&amp;gt;1. E-Mail-Sicherheitsmaßnahmen&amp;lt;/h3&amp;gt;&amp;#xA;&amp;lt;ul&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Erweiterte E-Mail-Filter&amp;lt;/strong&amp;gt; – Nutzen Sie &amp;lt;strong&amp;gt;sichere E-Mail-Gateways&amp;lt;/strong&amp;gt; und &amp;lt;strong&amp;gt;Spam-Filter&amp;lt;/strong&amp;gt;, um Malspam-E-Mails zu blockieren.&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Automatisches Herunterladen von Anhängen deaktivieren&amp;lt;/strong&amp;gt; – Verhindern Sie, dass E-Mail-Clients verlinkte Dateien automatisch herunterladen.&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Link-Sandboxing &amp;amp;amp; URL-Analyse&amp;lt;/strong&amp;gt; – Implementieren Sie Sicherheitslösungen, die Links in Echtzeit analysieren.&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;CIRCL bietet einen &amp;lt;strong&amp;gt;kostenlosen Online-Dienst zur Analyse von E-Mail-Anhängen&amp;lt;/strong&amp;gt; an: &amp;lt;a href=&amp;#34;https://pandora.circl.lu&amp;#34;&amp;gt;pandora&amp;lt;/a&amp;gt;&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;/ul&amp;gt;&amp;#xA;&amp;lt;h3 id=&amp;#34;2-benutzerbewusstsein--schulung&amp;#34;&amp;gt;2. Benutzerbewusstsein &amp;amp;amp; Schulung&amp;lt;/h3&amp;gt;&amp;#xA;&amp;lt;ul&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Sensibilisierungskampagnen&amp;lt;/strong&amp;gt; – Schulen Sie Mitarbeiter darin, &amp;lt;strong&amp;gt;keine unbekannten Links zu klicken&amp;lt;/strong&amp;gt;.&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Links vor dem Klicken überprüfen&amp;lt;/strong&amp;gt; – Mitarbeiter sollten Links vor dem Klicken mit der Maus überfahren.&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Phishing-Simulationen&amp;lt;/strong&amp;gt; – Regelmäßige Tests zur Erkennung verdächtiger E-Mails.&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;CIRCL bietet einen &amp;lt;strong&amp;gt;kostenlosen Online-Dienst zur Untersuchung von URLs&amp;lt;/strong&amp;gt; an: &amp;lt;a href=&amp;#34;https://lookyloo.circl.lu&amp;#34;&amp;gt;lookyloo&amp;lt;/a&amp;gt;&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;/ul&amp;gt;&amp;#xA;&amp;lt;h3 id=&amp;#34;3-endpunktschutz--netzwerksicherheit&amp;#34;&amp;gt;3. Endpunktschutz &amp;amp;amp; Netzwerksicherheit&amp;lt;/h3&amp;gt;&amp;#xA;&amp;lt;ul&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;URL-Blockierung &amp;amp;amp; Web-Filter&amp;lt;/strong&amp;gt; – Einsatz von Web-Proxies und Sicherheitstools zum Blockieren bösartiger Domains.&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Anwendungs-Whitelisting&amp;lt;/strong&amp;gt; – Nur genehmigte Anwendungen dürfen ausgeführt werden.&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Erweiterter Endpunktschutz (EDR/NGAV)&amp;lt;/strong&amp;gt; – Erkennung und Blockierung von Malware.&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;/ul&amp;gt;&amp;#xA;&amp;lt;h3 id=&amp;#34;4-e-mail-authentifizierung--schutz-vor-spoofing&amp;#34;&amp;gt;4. E-Mail-Authentifizierung &amp;amp;amp; Schutz vor Spoofing&amp;lt;/h3&amp;gt;&amp;#xA;&amp;lt;ul&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;DMARC, DKIM und SPF implementieren&amp;lt;/strong&amp;gt; – Schutz gegen &amp;lt;strong&amp;gt;E-Mail-Spoofing&amp;lt;/strong&amp;gt;.&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Markenschutz &amp;amp;amp; Domain-Monitoring&amp;lt;/strong&amp;gt; – Registrierung ähnlicher Domains zur Phishing-Prävention.&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Korrekte DNS-Konfiguration&amp;lt;/strong&amp;gt; - siehe &amp;lt;a href=&amp;#34;/pub/tr-92/&amp;#34;&amp;gt;TR-92&amp;lt;/a&amp;gt;&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;/ul&amp;gt;&amp;#xA;&amp;lt;h3 id=&amp;#34;5-zugriffskontrolle--prinzip-der-minimalen-rechte&amp;#34;&amp;gt;5. Zugriffskontrolle &amp;amp;amp; Prinzip der minimalen Rechte&amp;lt;/h3&amp;gt;&amp;#xA;&amp;lt;ul&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Einschränkung von Benutzerrechten&amp;lt;/strong&amp;gt; – Keine Admin-Rechte ohne triftigen Grund.&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Zusätzliche Authentifizierung&amp;lt;/strong&amp;gt; – Verifikation für externe Links oder Downloads.&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Deaktivierung von Makros &amp;amp;amp; Skript-Autoausführung&amp;lt;/strong&amp;gt;.&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;/ul&amp;gt;&amp;#xA;&amp;lt;h3 id=&amp;#34;6-allgemeine-sicherheitsmaßnahmen&amp;#34;&amp;gt;6. Allgemeine Sicherheitsmaßnahmen&amp;lt;/h3&amp;gt;&amp;#xA;&amp;lt;ul&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Regelmäßige Software- und OS-Updates&amp;lt;/strong&amp;gt;.&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Unnötige Browser-Plugins deaktivieren&amp;lt;/strong&amp;gt;.&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;/ul&amp;gt;&amp;#xA;&amp;lt;h3 id=&amp;#34;7-reaktion-auf-vorfälle--monitoring&amp;#34;&amp;gt;7. Reaktion auf Vorfälle &amp;amp;amp; Monitoring&amp;lt;/h3&amp;gt;&amp;#xA;&amp;lt;ul&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;SIEM-Überwachung&amp;lt;/strong&amp;gt; – Erkennung ungewöhnlicher Aktivitäten.&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Vorfallreaktionsplan&amp;lt;/strong&amp;gt; – Infizierte Geräte schnell isolieren.&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;/ul&amp;gt;&amp;#xA;&amp;lt;h2 id=&amp;#34;maßnahmen-bei-einer-kompromittierung&amp;#34;&amp;gt;Maßnahmen bei einer Kompromittierung&amp;lt;/h2&amp;gt;&amp;#xA;&amp;lt;ul&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;Sofortige Trennung des betroffenen PCs vom Netzwerk (auch WLAN!).&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;Kontaktieren Sie Ihr Incident-Response-Team oder CIRCL.&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;IT-Team zur verstärkten Überwachung informieren.&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;Untersuchung möglicher weiterer betroffener Systeme.&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;Warnung an Kontakte, keine Links aus E-Mails Ihres Unternehmens zu öffnen.&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;Schulung der Mitarbeiter zur Wachsamkeit.&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Meldung an die CNPD innerhalb von 72 Stunden bei Datenpannen&amp;lt;/strong&amp;gt;.&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;/ul&amp;gt;&amp;#xA;&amp;lt;h2 id=&amp;#34;effektive-gegenmaßnahmen&amp;#34;&amp;gt;Effektive Gegenmaßnahmen&amp;lt;/h2&amp;gt;&amp;#xA;&amp;lt;h3 id=&amp;#34;unwirksame-lösungen-durch-it-dienstleister&amp;#34;&amp;gt;&amp;lt;strong&amp;gt;Unwirksame Lösungen durch IT-Dienstleister&amp;lt;/strong&amp;gt;&amp;lt;/h3&amp;gt;&amp;#xA;&amp;lt;p&amp;gt;Ein mehrfacher Virenscan reicht &amp;lt;strong&amp;gt;nicht&amp;lt;/strong&amp;gt; aus, da:&amp;lt;/p&amp;gt;&amp;#xA;&amp;lt;ul&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Legitime RMM-Tools&amp;lt;/strong&amp;gt; nicht erkannt werden.&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Versteckte Hintertüren&amp;lt;/strong&amp;gt; oft unentdeckt bleiben.&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Angreifer schnell wieder Zugriff erlangen&amp;lt;/strong&amp;gt;.&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;/ul&amp;gt;&amp;#xA;&amp;lt;h3 id=&amp;#34;erfolgreiche-maßnahmen&amp;#34;&amp;gt;&amp;lt;strong&amp;gt;Erfolgreiche Maßnahmen&amp;lt;/strong&amp;gt;&amp;lt;/h3&amp;gt;&amp;#xA;&amp;lt;ul&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;EDR-Lösung implementieren&amp;lt;/strong&amp;gt; und RMM-Tools auf eine &amp;lt;strong&amp;gt;Allowlist&amp;lt;/strong&amp;gt; setzen.&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Verwenden Sie LuxTrust Mobile oder LuxTrust Scan&amp;lt;/strong&amp;gt; anstelle einer Smartcard zur Authentifizierung (siehe &amp;lt;a href=&amp;#34;https://www.multiline.lu/wp-content/uploads/2019/09/Verwendung-von-LuxTrust-Scan-und-LuxTrust-Mobile-in-MultiLineV4.pdf&amp;#34;&amp;gt;LuxTrust-Dokumentation&amp;lt;/a&amp;gt;)&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Smartcard aus dem Leser entfernen&amp;lt;/strong&amp;gt;, wenn sie nicht benutzt wird.&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;4-Augen-Prinzip bei Überweisungen einführen&amp;lt;/strong&amp;gt;.&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Zusätzliche Authentifizierungsfaktoren aktivieren&amp;lt;/strong&amp;gt;.&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;Eine &amp;lt;strong&amp;gt;Bank wählen, die Empfänger prüft&amp;lt;/strong&amp;gt;.&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;/ul&amp;gt;&amp;#xA;&amp;lt;h2 id=&amp;#34;wiederherstellung-nach-einer-kompromittierung&amp;#34;&amp;gt;Wiederherstellung nach einer Kompromittierung&amp;lt;/h2&amp;gt;&amp;#xA;&amp;lt;ul&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Sofort die Bank kontaktieren&amp;lt;/strong&amp;gt;, um betrügerische Überweisungen zu stoppen.&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Strafanzeige bei der Polizei erstatten&amp;lt;/strong&amp;gt;.&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;CIRCL kontaktieren&amp;lt;/strong&amp;gt;, falls IT-Sicherheitsberatung benötigt wird.&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Das kompromittierte System vollständig neu installieren&amp;lt;/strong&amp;gt;.&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;RDP-Zugriff überwachen&amp;lt;/strong&amp;gt;.&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Alle Passwörter zurücksetzen&amp;lt;/strong&amp;gt;.&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Zwei-Faktor-Authentifizierung (2FA) aktivieren&amp;lt;/strong&amp;gt;.&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Mitarbeiter sensibilisieren&amp;lt;/strong&amp;gt;.&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;/ul&amp;gt;&amp;#xA;&amp;lt;h2 id=&amp;#34;fazit&amp;#34;&amp;gt;Fazit&amp;lt;/h2&amp;gt;&amp;#xA;&amp;lt;p&amp;gt;Ein einfacher Virenscan &amp;lt;strong&amp;gt;löst das Problem nicht&amp;lt;/strong&amp;gt;. Zur vollständigen Bereinigung muss das betroffene System &amp;lt;strong&amp;gt;komplett neu installiert&amp;lt;/strong&amp;gt; werden.&amp;lt;/p&amp;gt;&amp;#xA;&amp;lt;h2 id=&amp;#34;ioc&amp;#34;&amp;gt;IoC&amp;lt;/h2&amp;gt;&amp;#xA;&amp;lt;p&amp;gt;Siehe MISP-Ereignis UUID 5f7819de-5656-4063-a76a-a39253ee5154, verfügbar auf &amp;lt;a href=&amp;#34;https://misppriv.circl.lu/events/view/278450&amp;#34;&amp;gt;MISP für den privaten Sektor&amp;lt;/a&amp;gt;.&amp;lt;/p&amp;gt;&amp;#xA;&amp;lt;h2 id=&amp;#34;dokumentklassifikation&amp;#34;&amp;gt;Dokumentklassifikation&amp;lt;/h2&amp;gt;&amp;#xA;&amp;lt;p&amp;gt;&amp;lt;a href=&amp;#34;/pub/traffic-light-protocol/&amp;#34;&amp;gt;TLP:CLEAR&amp;lt;/a&amp;gt; – Freie Verbreitung unter Beachtung des Urheberrechts.&amp;lt;/p&amp;gt;&amp;#xA;&amp;lt;h2 id=&amp;#34;revision&amp;#34;&amp;gt;Revision&amp;lt;/h2&amp;gt;&amp;#xA;&amp;lt;ul&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;Version 1.0 - TLP:CLEAR - Erste Version - 26. Februar 2025&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;/ul&amp;gt;&amp;#xA;</content>
  </entry>
  <entry>
    <title>TR-93 - Financial transaction fraud after system compromise via Remote Management and Monitoring tools</title>
    <link href="https://www.circl.lu/pub/tr-93/" rel="alternate" type="text/html" />
    <id>https://www.circl.lu/pub/tr-93/</id>
    <published>2025-02-26T00:00:00Z</published>
    <updated>2025-02-26T00:00:00Z</updated>
    <summary>Executive Summary This document outlines a malspam attack targeting businesses through fraudulent emails that exploit Remote Monitoring &amp;amp; Management (RMM) tools. The attackers deceive recipients into clicking a malicious link disguised as an invoice, which installs an RMM tool on their system. Since these tools are legitimate applications, they evade antivirus detection, granting attackers full remote access.&amp;#xA;Once access is gained, the attackers escalate their control by installing additional RMM tools for persistence, spreading malware via email, and modifying system settings. Critically, they exploit the compromised workstation—often belonging to accountants or financial officers—to capture smart card PINs and execute fraudulent wire transfers, resulting in significant financial losses.&amp;#xA;</summary>
    <content type="html">&amp;lt;h2 id=&amp;#34;executive-summary&amp;#34;&amp;gt;Executive Summary&amp;lt;/h2&amp;gt;&amp;#xA;&amp;lt;p&amp;gt;This document outlines a malspam attack targeting businesses through fraudulent emails that exploit Remote Monitoring &amp;amp;amp; Management (RMM) tools. The attackers deceive recipients into clicking a malicious link disguised as an invoice, which installs an RMM tool on their system. Since these tools are legitimate applications, they evade antivirus detection, granting attackers full remote access.&amp;lt;/p&amp;gt;&amp;#xA;&amp;lt;p&amp;gt;Once access is gained, the attackers escalate their control by installing additional RMM tools for persistence, spreading malware via email, and modifying system settings. Critically, they exploit the compromised workstation—often belonging to accountants or financial officers—to capture smart card PINs and execute fraudulent wire transfers, resulting in significant financial losses.&amp;lt;/p&amp;gt;&amp;#xA;&amp;lt;p&amp;gt;This document provides a detailed breakdown of the modus operandi, risks, and recommended preventative measures to mitigate the threat posed by such attacks.&amp;lt;/p&amp;gt;&amp;#xA;&amp;lt;h2 id=&amp;#34;significance-for-luxembourg&amp;#34;&amp;gt;Significance for Luxembourg&amp;lt;/h2&amp;gt;&amp;#xA;&amp;lt;p&amp;gt;Over the past few weeks, we have received multiple reports from organizations and individuals regarding suspicious inquiries from their banks, such as:&amp;lt;/p&amp;gt;&amp;#xA;&amp;lt;ul&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;em&amp;gt;&amp;amp;ldquo;Do you really want to execute 10 transactions totaling approximately 30,000 EUR abroad?&amp;amp;rdquo;&amp;lt;/em&amp;gt;&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;em&amp;gt;&amp;amp;ldquo;Do you really want to execute a transaction of 1,000,000 EUR abroad?&amp;amp;rdquo;&amp;lt;/em&amp;gt;&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;/ul&amp;gt;&amp;#xA;&amp;lt;p&amp;gt;These transactions are &amp;lt;strong&amp;gt;real and executed by attackers&amp;lt;/strong&amp;gt; who have gained access to the victim’s banking system by installing &amp;lt;strong&amp;gt;legitimate Remote Monitoring and Management (RMM) tools&amp;lt;/strong&amp;gt;.&amp;lt;br&amp;gt;&amp;#xA;The initial infection occurs through phishing and spear-phishing attacks, as detailed below.&amp;lt;/p&amp;gt;&amp;#xA;&amp;lt;h2 id=&amp;#34;modus-operandi&amp;#34;&amp;gt;Modus Operandi&amp;lt;/h2&amp;gt;&amp;#xA;&amp;lt;ol&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;The attacker sends a fraudulent business email containing a fake invoice as an attachment.&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;The attachment is actually a link that downloads a Remote Monitoring &amp;amp;amp; Management (RMM) tool.&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;If the victim clicks the link, the RMM tool is installed on their system.&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Antivirus software does not detect the RMM tool as malicious since these are legitimate applications.&amp;lt;/strong&amp;gt;&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;The RMM tool grants the attacker full remote access to the victim’s computer, allowing them to capture the &amp;lt;strong&amp;gt;multiline smart card PIN&amp;lt;/strong&amp;gt;.&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;The attacker then:&amp;#xA;&amp;lt;ul&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Installs multiple other legitimate RMM tools&amp;lt;/strong&amp;gt; for persistence.&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;Sends infected emails to contacts in the victim’s address book.&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;Analyzes the compromised system.&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;Modifies system configurations to achieve their objectives.&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Executes fraudulent financial transactions.&amp;lt;/strong&amp;gt;&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;/ul&amp;gt;&amp;#xA;&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;/ol&amp;gt;&amp;#xA;&amp;lt;h3 id=&amp;#34;recent-examples-french&amp;#34;&amp;gt;Recent Examples (French)&amp;lt;/h3&amp;gt;&amp;#xA;&amp;lt;pre tabindex=&amp;#34;0&amp;#34;&amp;gt;&amp;lt;code&amp;gt;Objet : Recouvrement de facture impayée – Facture no FACT#062024 et FACT#072024 datée du 15/06/2024&amp;#xA;&amp;#xA;Monsieur, Madame,&amp;#xA;&amp;#xA;La présente communication concerne la facture no FACT#032024 et FACT#042024 au montant total de 32.857€ qui Recouvrement de facture impayée – Facture no FACT#062024 et FACT#072024 datée du 15/06/2024. Vous trouverez en annexe une copie de la facture pertinente.&amp;#xA;&amp;#xA;Comme vous le savez, nous vous avons fourni le delai de recouvrement du dossier R1184521. Or, malgré le rappel effectué le 15/06/2024 à laquelle une lettre de relance a été envoyée, nous constatons que la facture demeure impayée, et ce, bien que nous ayons rempli toutes nos obligations.&amp;#xA;&amp;#xA;Ainsi, nous vous prions de nous faire parvenir un chèque certifié au montant de 32.857€ à l’ordre de notre entreprise dans les 10 jours de la réception de la présente mise en demeure. Le chèque devra être transmis au notre adresse. À défaut, une demande en justice pourrait être déposée contre vous, sans autre avis ni délai.&amp;#xA;&amp;#xA;Soyez avisé que nous considérerons de bonne foi tout mode alternatif de règlement proposé. Nous sommes d’avis qu’il est dans l’intérêt de tous que cette situation puisse être réglée à l’amiable. En ce sens, nous vous invitons à communiquer avec nous si vous désirez discuter de la présente mise en demeure.&amp;#xA;&amp;#xA;Nous vous invitons à ignorer la présente lettre si le paiement a été effectué avant la date de réception de cette communication.&amp;#xA;&amp;#xA;VEUILLEZ AGIR EN CONSÉQUENCE.                                 &amp;#xA;&amp;lt;/code&amp;gt;&amp;lt;/pre&amp;gt;&amp;lt;h2 id=&amp;#34;prevention-strategies&amp;#34;&amp;gt;Prevention Strategies&amp;lt;/h2&amp;gt;&amp;#xA;&amp;lt;p&amp;gt;Preventing such &amp;lt;strong&amp;gt;malspam attacks&amp;lt;/strong&amp;gt; (malicious spam containing hyperlinks to download malware) in a corporate environment requires a &amp;lt;strong&amp;gt;multi-layered security approach&amp;lt;/strong&amp;gt;. Below are effective &amp;lt;strong&amp;gt;prevention strategies&amp;lt;/strong&amp;gt;:&amp;lt;/p&amp;gt;&amp;#xA;&amp;lt;h3 id=&amp;#34;1-email-security-measures&amp;#34;&amp;gt;1. Email Security Measures&amp;lt;/h3&amp;gt;&amp;#xA;&amp;lt;ul&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Advanced Email Filtering&amp;lt;/strong&amp;gt; – Use &amp;lt;strong&amp;gt;secure email gateways&amp;lt;/strong&amp;gt; and &amp;lt;strong&amp;gt;spam filters&amp;lt;/strong&amp;gt; to detect and block malspam emails before they reach inboxes.&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Disable Auto-Download of Attachments&amp;lt;/strong&amp;gt; – Prevent email clients from automatically downloading linked files.&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Link Sandboxing &amp;amp;amp; URL Analysis&amp;lt;/strong&amp;gt; – Implement email security solutions that scan and analyze hyperlinks in real-time before users click them.&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;CIRCL proposes &amp;lt;strong&amp;gt;a free online service for scanning email attachments&amp;lt;/strong&amp;gt;: &amp;lt;a href=&amp;#34;https://pandora.circl.lu&amp;#34;&amp;gt;pandora&amp;lt;/a&amp;gt;&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;/ul&amp;gt;&amp;#xA;&amp;lt;h3 id=&amp;#34;2-user-awareness--training&amp;#34;&amp;gt;2. User Awareness &amp;amp;amp; Training&amp;lt;/h3&amp;gt;&amp;#xA;&amp;lt;ul&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Security Awareness Campaigns&amp;lt;/strong&amp;gt; – Educate employees on &amp;lt;strong&amp;gt;not clicking unknown or unexpected links&amp;lt;/strong&amp;gt;, even from seemingly trusted sources.&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Hover Over Links Before Clicking&amp;lt;/strong&amp;gt; – Teach employees to hover over hyperlinks to preview URLs before clicking.&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Phishing Simulation Training&amp;lt;/strong&amp;gt; – Conduct regular phishing tests to train employees on recognizing suspicious links.&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;CIRCL proposes &amp;lt;strong&amp;gt;a free online service for investigating urls&amp;lt;/strong&amp;gt;: &amp;lt;a href=&amp;#34;https://lookyloo.circl.lu&amp;#34;&amp;gt;lookyloo&amp;lt;/a&amp;gt;&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;/ul&amp;gt;&amp;#xA;&amp;lt;h3 id=&amp;#34;3-endpoint-protection--network-security&amp;#34;&amp;gt;3. Endpoint Protection &amp;amp;amp; Network Security&amp;lt;/h3&amp;gt;&amp;#xA;&amp;lt;ul&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;URL Blocking &amp;amp;amp; Web Filtering&amp;lt;/strong&amp;gt; – Use web proxies and security tools to block known malicious domains.&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Application Whitelisting&amp;lt;/strong&amp;gt; – Restrict the execution of unapproved applications to prevent malware from running.&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Endpoint Protection Software&amp;lt;/strong&amp;gt; – Deploy &amp;lt;strong&amp;gt;next-gen antivirus (NGAV) and Endpoint Detection &amp;amp;amp; Response (EDR)&amp;lt;/strong&amp;gt; to identify and block malware from executing.&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;/ul&amp;gt;&amp;#xA;&amp;lt;h3 id=&amp;#34;4-email-authentication--domain-protection&amp;#34;&amp;gt;4. Email Authentication &amp;amp;amp; Domain Protection&amp;lt;/h3&amp;gt;&amp;#xA;&amp;lt;ul&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Implement DMARC, DKIM, and SPF&amp;lt;/strong&amp;gt; – These email authentication protocols help prevent &amp;lt;strong&amp;gt;email spoofing&amp;lt;/strong&amp;gt; and domain impersonation.&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Brand Protection &amp;amp;amp; Domain Monitoring&amp;lt;/strong&amp;gt; – Monitor for domain spoofing attempts and &amp;lt;strong&amp;gt;register similar domains&amp;lt;/strong&amp;gt; to prevent phishing.&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Correct DNS configuration&amp;lt;/strong&amp;gt; - see &amp;lt;a href=&amp;#34;/pub/tr-92/&amp;#34;&amp;gt;TR-92&amp;lt;/a&amp;gt;&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;/ul&amp;gt;&amp;#xA;&amp;lt;h3 id=&amp;#34;5-access-control--least-privilege-principle&amp;#34;&amp;gt;5. Access Control &amp;amp;amp; Least Privilege Principle&amp;lt;/h3&amp;gt;&amp;#xA;&amp;lt;ul&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Restrict User Privileges&amp;lt;/strong&amp;gt; – Users should not have &amp;lt;strong&amp;gt;admin rights&amp;lt;/strong&amp;gt; unless absolutely necessary.&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Additional Authentication&amp;lt;/strong&amp;gt; – Enforce authentication and verification for accessing external links or downloading software.&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Disable Macros &amp;amp;amp; Auto-Execution of Scripts&amp;lt;/strong&amp;gt; – Prevent execution of &amp;lt;strong&amp;gt;malicious scripts&amp;lt;/strong&amp;gt; embedded in documents.&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;/ul&amp;gt;&amp;#xA;&amp;lt;h3 id=&amp;#34;6-general-secure-software--patch-management&amp;#34;&amp;gt;6. General: Secure Software &amp;amp;amp; Patch Management&amp;lt;/h3&amp;gt;&amp;#xA;&amp;lt;ul&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Regular Software &amp;amp;amp; OS Updates&amp;lt;/strong&amp;gt; – Ensure all systems, browsers, and email clients are patched to prevent exploitation.&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Disable Unnecessary Browser Plugins&amp;lt;/strong&amp;gt; – Reduce attack surface by removing unneeded browser extensions.&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;/ul&amp;gt;&amp;#xA;&amp;lt;h3 id=&amp;#34;7-incident-response--monitoring&amp;#34;&amp;gt;7. Incident Response &amp;amp;amp; Monitoring&amp;lt;/h3&amp;gt;&amp;#xA;&amp;lt;ul&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;SIEM (Security Information and Event Management)&amp;lt;/strong&amp;gt; – Implement &amp;lt;strong&amp;gt;real-time monitoring&amp;lt;/strong&amp;gt; to detect unusual email traffic patterns.&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Incident Response Plan&amp;lt;/strong&amp;gt; – Have a response &amp;lt;strong&amp;gt;team&amp;lt;/strong&amp;gt; and &amp;lt;strong&amp;gt;strategy&amp;lt;/strong&amp;gt; ready if employees fall victim to malspam, including &amp;lt;strong&amp;gt;isolating infected devices&amp;lt;/strong&amp;gt; and &amp;lt;strong&amp;gt;removing malware&amp;lt;/strong&amp;gt;.&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;/ul&amp;gt;&amp;#xA;&amp;lt;h2 id=&amp;#34;actions-during-a-compromise&amp;#34;&amp;gt;Actions during a Compromise&amp;lt;/h2&amp;gt;&amp;#xA;&amp;lt;ul&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;Disconnect the affected PC from the network immediatly (Don&amp;amp;rsquo;t forget WiFi).&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;Talk to your local incident response team.&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;If this doesn&amp;amp;rsquo;t exist, do not hesitate to &amp;lt;strong&amp;gt;contact CIRCL&amp;lt;/strong&amp;gt; to &amp;lt;strong&amp;gt;discuss the case&amp;lt;/strong&amp;gt; and be prepared to &amp;lt;strong&amp;gt;receive an action plan&amp;lt;/strong&amp;gt;.&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;Inform your IT team to increase monitoring and the vigilance level.&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;Investigate for potential other PC affected.&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;Warn all you contacts, clients, customers and alike to not click on links in emails send by your organization.&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;Teach all your staff about the issue and make them vigilant&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;There are legal obligations in case of compromised infrastructure, e.g. to inform CNPD within 72 hours and any victims of a data breach. CIRCL will give you recommendations if necessary.&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;/ul&amp;gt;&amp;#xA;&amp;lt;h2 id=&amp;#34;mitigation-strategies&amp;#34;&amp;gt;Mitigation Strategies&amp;lt;/h2&amp;gt;&amp;#xA;&amp;lt;h3 id=&amp;#34;ineffective-solutions-from-ict-providers-what-does-not-fix-the-problem&amp;#34;&amp;gt;&amp;lt;strong&amp;gt;Ineffective Solutions from ICT Providers: What Does NOT Fix the Problem&amp;lt;/strong&amp;gt;&amp;lt;/h3&amp;gt;&amp;#xA;&amp;lt;p&amp;gt;Some service providers attempt to mitigate the issue by running multiple antivirus scans on the infected system. If no further malware is detected, they conclude that the system is clean.&amp;lt;/p&amp;gt;&amp;#xA;&amp;lt;p&amp;gt;However, this approach is ineffective because:&amp;lt;/p&amp;gt;&amp;#xA;&amp;lt;ul&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;Attackers install &amp;lt;strong&amp;gt;legitimate RMM tools&amp;lt;/strong&amp;gt; that antivirus software does not flag.&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;It is nearly impossible to detect all backdoors left by the attackers.&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;If this approach is followed, attackers will &amp;lt;strong&amp;gt;regain access quickly&amp;lt;/strong&amp;gt; and continue fraudulent activity.&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;/ul&amp;gt;&amp;#xA;&amp;lt;h3 id=&amp;#34;effective-mitigation-steps&amp;#34;&amp;gt;&amp;lt;strong&amp;gt;Effective Mitigation Steps&amp;lt;/strong&amp;gt;&amp;lt;/h3&amp;gt;&amp;#xA;&amp;lt;ul&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;Implement an &amp;lt;strong&amp;gt;Endpoint Detection and Response (EDR) solution&amp;lt;/strong&amp;gt; and enforce an &amp;lt;strong&amp;gt;allowlist for RMM tools&amp;lt;/strong&amp;gt; used within the organization.&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;Use &amp;lt;strong&amp;gt;LuxTrust Mobile or LuxTrust Scan instead of a smart card to authenticate&amp;lt;/strong&amp;gt; (see &amp;lt;a href=&amp;#34;https://multiline.lu/wp-content/uploads/2019/09/Using-LuxTrust-Scan-and-LuxTrust-Mobile-in-MultiLineV4.pdf&amp;#34;&amp;gt;luxtrust documentation&amp;lt;/a&amp;gt;).&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Remove the multiline smart card from the reader&amp;lt;/strong&amp;gt; when not in use.&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;Use &amp;lt;strong&amp;gt;4-eyes principles&amp;lt;/strong&amp;gt; for wire transfers.&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Enable additional authentication factors&amp;lt;/strong&amp;gt; for multiline banking (e.g., phone-based authentication).&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;Select a &amp;lt;strong&amp;gt;bank&amp;lt;/strong&amp;gt; that actually &amp;lt;strong&amp;gt;checks&amp;lt;/strong&amp;gt; wire transfer recipients.&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;/ul&amp;gt;&amp;#xA;&amp;lt;h2 id=&amp;#34;remediation-after-a-compromise&amp;#34;&amp;gt;Remediation After a Compromise&amp;lt;/h2&amp;gt;&amp;#xA;&amp;lt;p&amp;gt;If an organization falls victim to this attack, the following actions must be taken:&amp;lt;/p&amp;gt;&amp;#xA;&amp;lt;ul&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;Contact immediately the bank of your organisation and the destination bank to block the fraudulent wire transfer.&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;File a complaint with the local police or the “service de police judiciaire”.&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;Contact CIRCL if you need technical support or advice related to IT security incidents.&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Reinstall the compromised system from scratch.&amp;lt;/strong&amp;gt;&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Monitor Remote Desktop access.&amp;lt;/strong&amp;gt; Attackers may exploit existing RDP access to escalate privileges or move&amp;#xA;laterally within a network. Evidence of such activity can often be found in Event Logs.&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;In severe cases, &amp;lt;strong&amp;gt;all systems within the organization may need to be reinstalled.&amp;lt;/strong&amp;gt;&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Revoke and reissue all banking certificates.&amp;lt;/strong&amp;gt;&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Reset all passwords.&amp;lt;/strong&amp;gt;&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Implement Two-Factor Authentication (2FA) wherever possible.&amp;lt;/strong&amp;gt;&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Educate employees&amp;lt;/strong&amp;gt; on cybersecurity best practices to prevent future incidents.&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;/ul&amp;gt;&amp;#xA;&amp;lt;h2 id=&amp;#34;conclusion&amp;#34;&amp;gt;Conclusion&amp;lt;/h2&amp;gt;&amp;#xA;&amp;lt;p&amp;gt;A simple virus scan &amp;lt;strong&amp;gt;does not resolve this issue&amp;lt;/strong&amp;gt;. To fully mitigate the attack, the affected system must be &amp;lt;strong&amp;gt;completely reinstalled&amp;lt;/strong&amp;gt;.&amp;lt;/p&amp;gt;&amp;#xA;&amp;lt;p&amp;gt;Organizations should &amp;lt;strong&amp;gt;closely monitor their ICT service providers&amp;lt;/strong&amp;gt; to ensure proper remediation is performed.&amp;lt;/p&amp;gt;&amp;#xA;&amp;lt;h2 id=&amp;#34;ioc&amp;#34;&amp;gt;IoC&amp;lt;/h2&amp;gt;&amp;#xA;&amp;lt;p&amp;gt;See MISP event uuid 5f7819de-5656-4063-a76a-a39253ee5154, available on &amp;lt;a href=&amp;#34;https://misppriv.circl.lu/events/view/278450&amp;#34;&amp;gt;MISP for the private sector&amp;lt;/a&amp;gt;.&amp;lt;/p&amp;gt;&amp;#xA;&amp;lt;h2 id=&amp;#34;classification-of-this-document&amp;#34;&amp;gt;Classification of this document&amp;lt;/h2&amp;gt;&amp;#xA;&amp;lt;p&amp;gt;&amp;lt;a href=&amp;#34;/pub/traffic-light-protocol/&amp;#34;&amp;gt;TLP:CLEAR&amp;lt;/a&amp;gt; information may be distributed without restriction, subject to copyright controls.&amp;lt;/p&amp;gt;&amp;#xA;&amp;lt;h2 id=&amp;#34;revision&amp;#34;&amp;gt;Revision&amp;lt;/h2&amp;gt;&amp;#xA;&amp;lt;ul&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;Version 1.0 - TLP:CLEAR - First version - 26th February 2025&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;/ul&amp;gt;&amp;#xA;</content>
  </entry>
  <entry>
    <title>TR-92 - Unused Domain Names and the Risks of Missing DNS SPF Records</title>
    <link href="https://www.circl.lu/pub/tr-92/" rel="alternate" type="text/html" />
    <id>https://www.circl.lu/pub/tr-92/</id>
    <published>2025-01-22T00:00:00Z</published>
    <updated>2025-01-22T00:00:00Z</updated>
    <summary>Executive Summary Many organizations maintain a broad portfolio of domain names, acquired for branding, strategic planning, or defensive purposes. However, a significant portion of these domains often remains unused or lacks proper DNS configurations, leaving them vulnerable to exploitation. One particularly critical oversight is the absence of DNS SPF (Sender Policy Framework) TXT records, which are essential to controlling the sources from which emails for a domain can be legitimately sent. This document highlights the risks associated with improperly configured domains and provides actionable recommendations to mitigate such vulnerabilities.&amp;#xA;</summary>
    <content type="html">&amp;lt;h2 id=&amp;#34;executive-summary&amp;#34;&amp;gt;Executive Summary&amp;lt;/h2&amp;gt;&amp;#xA;&amp;lt;p&amp;gt;Many organizations maintain a broad portfolio of domain names, acquired for branding, strategic planning, or defensive purposes. However, a significant portion of these domains often remains unused or lacks proper DNS configurations, leaving them vulnerable to exploitation. One particularly critical oversight is the absence of DNS SPF (Sender Policy Framework) TXT records, which are essential to controlling the sources from which emails for a domain can be legitimately sent. This document highlights the risks associated with improperly configured domains and provides actionable recommendations to mitigate such vulnerabilities.&amp;lt;/p&amp;gt;&amp;#xA;&amp;lt;p&amp;gt;Unused domains can refer to domains registered by an organization but not actively used. They can also include domains that are utilized for other services, such as HTTP/web services, without the need to send emails.&amp;lt;/p&amp;gt;&amp;#xA;&amp;lt;h2 id=&amp;#34;problem-statement&amp;#34;&amp;gt;Problem Statement&amp;lt;/h2&amp;gt;&amp;#xA;&amp;lt;p&amp;gt;Attackers frequently exploit domains without SPF records or other DNS-based email authentication mechanisms. These misconfigured or dormant domains can become avenues for phishing, spamming, or distributing malware under the guise of legitimate organizational communication. Recipients, seeing a recognizable domain, may trust the malicious email, leading to financial losses, reputational damage, and compromised security for both the recipient and the originating organization.&amp;lt;/p&amp;gt;&amp;#xA;&amp;lt;h3 id=&amp;#34;recent-examples&amp;#34;&amp;gt;Recent Examples&amp;lt;/h3&amp;gt;&amp;#xA;&amp;lt;p&amp;gt;In recent incidents, attackers have exploited unused or poorly configured domains belonging to various organizations. Common scenarios include:&amp;lt;/p&amp;gt;&amp;#xA;&amp;lt;ol&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;Sending phishing emails that appear to originate from legitimate-looking email addresses tied to the organization.&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;Targeting partners, suppliers, or customers with malicious links or fraudulent invoices.&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;Compromising recipients’ systems by leveraging the trust associated with the recognizable domain name.&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;/ol&amp;gt;&amp;#xA;&amp;lt;p&amp;gt;These examples demonstrate the importance of ensuring that all domains in an organization’s portfolio are properly secured and configured, regardless of their current usage status.&amp;lt;/p&amp;gt;&amp;#xA;&amp;lt;h2 id=&amp;#34;understanding-spf-records&amp;#34;&amp;gt;Understanding SPF Records&amp;lt;/h2&amp;gt;&amp;#xA;&amp;lt;p&amp;gt;SPF records are a type of DNS TXT record that specifies which mail servers are authorized to send emails on behalf of a domain. For example, the following SPF record:&amp;lt;/p&amp;gt;&amp;#xA;&amp;lt;pre tabindex=&amp;#34;0&amp;#34;&amp;gt;&amp;lt;code&amp;gt;v=spf1 include:mail.example.com -all&amp;#xA;&amp;lt;/code&amp;gt;&amp;lt;/pre&amp;gt;&amp;lt;ul&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;&amp;lt;code&amp;gt;v=spf1&amp;lt;/code&amp;gt;&amp;lt;/strong&amp;gt;: Indicates the SPF version being used.&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;&amp;lt;code&amp;gt;include:mail.example.com&amp;lt;/code&amp;gt;&amp;lt;/strong&amp;gt;: Specifies the authorized mail server(s).&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;&amp;lt;code&amp;gt;-all&amp;lt;/code&amp;gt;&amp;lt;/strong&amp;gt;: Indicates that all other servers are unauthorized.&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;/ul&amp;gt;&amp;#xA;&amp;lt;p&amp;gt;If a domain lacks an SPF record, any mail server can claim to send emails on its behalf, making it susceptible to spoofing.&amp;lt;/p&amp;gt;&amp;#xA;&amp;lt;h2 id=&amp;#34;recommendations&amp;#34;&amp;gt;Recommendations&amp;lt;/h2&amp;gt;&amp;#xA;&amp;lt;p&amp;gt;To safeguard your organization’s domain portfolio and reduce the risk of abuse, follow these best practices:&amp;lt;/p&amp;gt;&amp;#xA;&amp;lt;ol&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;#xA;&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Inventory All Domains&amp;lt;/strong&amp;gt;&amp;lt;/p&amp;gt;&amp;#xA;&amp;lt;ul&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;Maintain an updated inventory of all domains owned by the organization, including inactive and defensive registrations.&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;/ul&amp;gt;&amp;#xA;&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;#xA;&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Implement SPF Records&amp;lt;/strong&amp;gt;&amp;lt;/p&amp;gt;&amp;#xA;&amp;lt;ul&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;Configure SPF records for all domains, even those not actively in use.&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;Example for a domain with no legitimate email traffic:&amp;#xA;&amp;lt;pre tabindex=&amp;#34;0&amp;#34;&amp;gt;&amp;lt;code&amp;gt;v=spf1 -all&amp;#xA;&amp;lt;/code&amp;gt;&amp;lt;/pre&amp;gt;This record explicitly denies any mail servers from sending emails on behalf of the domain.&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;/ul&amp;gt;&amp;#xA;&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;#xA;&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Extend Protections with DKIM and DMARC&amp;lt;/strong&amp;gt;&amp;lt;/p&amp;gt;&amp;#xA;&amp;lt;ul&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;Use &amp;lt;strong&amp;gt;DKIM (DomainKeys Identified Mail)&amp;lt;/strong&amp;gt; to sign emails, ensuring their integrity.&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;Implement &amp;lt;strong&amp;gt;DMARC (Domain-based Message Authentication, Reporting, and Conformance)&amp;lt;/strong&amp;gt; to provide instructions on handling authentication failures.&amp;#xA;Example DMARC policy:&amp;#xA;&amp;lt;pre tabindex=&amp;#34;0&amp;#34;&amp;gt;&amp;lt;code&amp;gt;v=DMARC1; p=reject; rua=mailto:dmarc-reports@example.com&amp;#xA;&amp;lt;/code&amp;gt;&amp;lt;/pre&amp;gt;&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;/ul&amp;gt;&amp;#xA;&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;#xA;&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Monitor DNS Configurations&amp;lt;/strong&amp;gt;&amp;lt;/p&amp;gt;&amp;#xA;&amp;lt;ul&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;Regularly audit DNS records for accuracy and completeness.&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;Utilize tools or managed services to detect and mitigate unauthorized use of domains.&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;/ul&amp;gt;&amp;#xA;&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;#xA;&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Educate Stakeholders&amp;lt;/strong&amp;gt;&amp;lt;/p&amp;gt;&amp;#xA;&amp;lt;ul&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;Raise awareness among IT staff and decision-makers about the importance of securing all domains.&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;Include DNS management in your organization’s cybersecurity training and policies.&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;/ul&amp;gt;&amp;#xA;&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;/ol&amp;gt;&amp;#xA;&amp;lt;h2 id=&amp;#34;references&amp;#34;&amp;gt;References&amp;lt;/h2&amp;gt;&amp;#xA;&amp;lt;ul&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;RFC 7208&amp;lt;/strong&amp;gt;: Sender Policy Framework (SPF) for Authorizing Use of Domains in Email, Version 1. &amp;lt;a href=&amp;#34;https://datatracker.ietf.org/doc/html/rfc7208&amp;#34;&amp;gt;Available here&amp;lt;/a&amp;gt;&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;RFC 6376&amp;lt;/strong&amp;gt;: DomainKeys Identified Mail (DKIM) Signatures. &amp;lt;a href=&amp;#34;https://datatracker.ietf.org/doc/html/rfc6376&amp;#34;&amp;gt;Available here&amp;lt;/a&amp;gt;&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;RFC 7489&amp;lt;/strong&amp;gt;: Domain-based Message Authentication, Reporting, and Conformance (DMARC). &amp;lt;a href=&amp;#34;https://datatracker.ietf.org/doc/html/rfc7489&amp;#34;&amp;gt;Available here&amp;lt;/a&amp;gt;&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;/ul&amp;gt;&amp;#xA;&amp;lt;h2 id=&amp;#34;conclusion&amp;#34;&amp;gt;Conclusion&amp;lt;/h2&amp;gt;&amp;#xA;&amp;lt;p&amp;gt;Unused or misconfigured domains represent a significant security risk for organizations. By proactively managing your domain portfolio and implementing robust email authentication mechanisms like SPF, DKIM, and DMARC, you can prevent attackers from exploiting your domains and protect your organization’s reputation and stakeholders. Addressing these issues is not just a technical necessity but a critical component of responsible cybersecurity management.&amp;lt;/p&amp;gt;&amp;#xA;&amp;lt;h2 id=&amp;#34;classification-of-this-document&amp;#34;&amp;gt;Classification of this document&amp;lt;/h2&amp;gt;&amp;#xA;&amp;lt;p&amp;gt;&amp;lt;a href=&amp;#34;/pub/traffic-light-protocol/&amp;#34;&amp;gt;TLP:CLEAR&amp;lt;/a&amp;gt; information may be distributed without restriction, subject to copyright controls.&amp;lt;/p&amp;gt;&amp;#xA;&amp;lt;h2 id=&amp;#34;revision&amp;#34;&amp;gt;Revision&amp;lt;/h2&amp;gt;&amp;#xA;&amp;lt;ul&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;Version 1.1 - TLP:CLEAR - Updated version to clarify the meaning of unused domains - 23rd January 2025&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;Version 1.0 - TLP:CLEAR - First version - 21st January 2025&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;/ul&amp;gt;&amp;#xA;</content>
  </entry>
  <entry>
    <title>TR-91 - Vulnerability identified as CVE-2024-0012, affecting Palo Alto Networks PAN-OS software</title>
    <link href="https://www.circl.lu/pub/tr-91/" rel="alternate" type="text/html" />
    <id>https://www.circl.lu/pub/tr-91/</id>
    <published>2024-12-20T00:00:00Z</published>
    <updated>2024-12-20T00:00:00Z</updated>
    <summary>An authentication bypass in Palo Alto Networks PAN-OS software enables an unauthenticated attacker with network access to the management web interface to gain PAN-OS administrator privileges. This allows the attacker to perform administrative actions, tamper with the configuration, or exploit other authenticated privilege escalation vulnerabilities like CVE-2024-9474.&amp;#xA;The risk is greatly reduced if access to the management web interface is restricted to trusted internal IP addresses, adhering to best practice deployment guidelines.&amp;#xA;</summary>
    <content type="html">&amp;lt;p&amp;gt;An authentication bypass in Palo Alto Networks PAN-OS software enables an unauthenticated attacker with network access to the management web interface to gain PAN-OS administrator privileges. This allows the attacker to perform administrative actions, tamper with the configuration, or exploit other authenticated privilege escalation vulnerabilities like &amp;lt;a href=&amp;#34;https://security.paloaltonetworks.com/CVE-2024-9474&amp;#34;&amp;gt;CVE-2024-9474&amp;lt;/a&amp;gt;.&amp;lt;/p&amp;gt;&amp;#xA;&amp;lt;p&amp;gt;The risk is greatly reduced if access to the management web interface is restricted to trusted internal IP addresses, adhering to &amp;lt;a href=&amp;#34;https://live.paloaltonetworks.com/t5/community-blogs/tips-amp-tricks-how-to-secure-the-management-access-of-your-palo/ba-p/464431&amp;#34;&amp;gt;best practice deployment guidelines&amp;lt;/a&amp;gt;.&amp;lt;/p&amp;gt;&amp;#xA;&amp;lt;p&amp;gt;This issue impacts PAN-OS versions 10.2, 11.0, 11.1, and 11.2. Cloud NGFW and Prisma Access are not affected.&amp;lt;/p&amp;gt;&amp;#xA;&amp;lt;h2 id=&amp;#34;impact&amp;#34;&amp;gt;Impact&amp;lt;/h2&amp;gt;&amp;#xA;&amp;lt;ul&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;CAPEC ID:&amp;lt;/strong&amp;gt; CAPEC-115&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;CAPEC Description:&amp;lt;/strong&amp;gt; Authentication Bypass&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;/ul&amp;gt;&amp;#xA;&amp;lt;h2 id=&amp;#34;exploitation&amp;#34;&amp;gt;Exploitation&amp;lt;/h2&amp;gt;&amp;#xA;&amp;lt;p&amp;gt;Palo Alto Networks observed threat activity exploiting this vulnerability against exposed management web interfaces.&amp;lt;/p&amp;gt;&amp;#xA;&amp;lt;h3 id=&amp;#34;problem-type&amp;#34;&amp;gt;Problem Type&amp;lt;/h3&amp;gt;&amp;#xA;&amp;lt;ul&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;CWE ID:&amp;lt;/strong&amp;gt; CWE-306&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;CWE Description:&amp;lt;/strong&amp;gt; Missing Authentication for Critical Function&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;/ul&amp;gt;&amp;#xA;&amp;lt;h2 id=&amp;#34;affected-systems&amp;#34;&amp;gt;Affected Systems&amp;lt;/h2&amp;gt;&amp;#xA;&amp;lt;h3 id=&amp;#34;palo-alto-networks-products&amp;#34;&amp;gt;Palo Alto Networks Products&amp;lt;/h3&amp;gt;&amp;#xA;&amp;lt;ul&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Cloud NGFW:&amp;lt;/strong&amp;gt; Not Affected, All versions unaffected.&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;PAN-OS:&amp;lt;/strong&amp;gt;&amp;#xA;&amp;lt;ul&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Affected Versions:&amp;lt;/strong&amp;gt;&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;10.2.0 versions up to but not including 10.2.12-h2&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;11.0.0 versions up to but not including 11.0.6-h1&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;11.1.0 versions up to but not including 11.1.5-h1&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;11.2.0 versions up to but not including 11.2.4-h1&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Unaffected Versions:&amp;lt;/strong&amp;gt; 10.1.0 and all versions that include the fix. (See solution section)&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;/ul&amp;gt;&amp;#xA;&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Prisma Access:&amp;lt;/strong&amp;gt; Not Affected, All versions unaffected.&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;/ul&amp;gt;&amp;#xA;&amp;lt;h2 id=&amp;#34;mitigation-and-solutions&amp;#34;&amp;gt;Mitigation and Solutions&amp;lt;/h2&amp;gt;&amp;#xA;&amp;lt;h3 id=&amp;#34;workarounds&amp;#34;&amp;gt;Workarounds&amp;lt;/h3&amp;gt;&amp;#xA;&amp;lt;p&amp;gt;The primary mitigation is to restrict access to the management interface to only trusted internal IP addresses. Review these resources for more information:&amp;lt;/p&amp;gt;&amp;#xA;&amp;lt;ul&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;Palo Alto Networks LIVEcommunity article: &amp;lt;a href=&amp;#34;https://live.paloaltonetworks.com/t5/community-blogs/tips-amp-tricks-how-to-secure-the-management-access-of-your-palo/ba-p/464431&amp;#34;&amp;gt;https://live.paloaltonetworks.com/t5/community-blogs/tips-amp-tricks-how-to-secure-the-management-access-of-your-palo/ba-p/464431&amp;lt;/a&amp;gt;&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;Palo Alto Networks official documentation: &amp;lt;a href=&amp;#34;https://docs.paloaltonetworks.com/best-practices/10-1/administrative-access-best-practices/administrative-access-best-practices/deploy-administrative-access-best-practices&amp;#34;&amp;gt;https://docs.paloaltonetworks.com/best-practices/10-1/administrative-access-best-practices/administrative-access-best-practices/deploy-administrative-access-best-practices&amp;lt;/a&amp;gt;&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;/ul&amp;gt;&amp;#xA;&amp;lt;p&amp;gt;If you have a Threat Prevention subscription, you can block attacks using Threat IDs 95746, 95747, 95752, 95753, 95759, and 95763 (Applications and Threats content version 8915-9075 or later).&amp;lt;/p&amp;gt;&amp;#xA;&amp;lt;h3 id=&amp;#34;solutions&amp;#34;&amp;gt;Solutions&amp;lt;/h3&amp;gt;&amp;#xA;&amp;lt;p&amp;gt;The issue is fixed in:&amp;lt;/p&amp;gt;&amp;#xA;&amp;lt;ul&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;PAN-OS 10.2.12-h2&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;PAN-OS 11.0.6-h1&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;PAN-OS 11.1.5-h1&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;PAN-OS 11.2.4-h1&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;All later PAN-OS versions&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;/ul&amp;gt;&amp;#xA;&amp;lt;p&amp;gt;Additional fixes are available for other commonly deployed maintenance releases, including:&amp;lt;/p&amp;gt;&amp;#xA;&amp;lt;ul&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;PAN-OS 11.2: 11.2.0-h1, 11.2.1-h1, 11.2.2-h2, 11.2.3-h3&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;PAN-OS 11.1: 11.1.0-h4, 11.1.1-h2, 11.1.2-h15, 11.1.3-h11, 11.1.4-h7&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;PAN-OS 11.0: 11.0.0-h4, 11.0.1-h5, 11.0.2-h5, 11.0.3-h13, 11.0.4-h6, 11.0.5-h2&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;PAN-OS 10.2: 10.2.0-h4, 10.2.1-h3, 10.2.2-h6, 10.2.3-h14, 10.2.4-h32, 10.2.5-h9, 10.2.6-h6, 10.2.7-h18, 10.2.8-h15, 10.2.9-h16, 10.2.10-h9, 10.2.11-h6&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;/ul&amp;gt;&amp;#xA;&amp;lt;h2 id=&amp;#34;cvss-metrics&amp;#34;&amp;gt;CVSS Metrics&amp;lt;/h2&amp;gt;&amp;#xA;&amp;lt;h3 id=&amp;#34;cvss-v40-highest-risk-scenario&amp;#34;&amp;gt;CVSS v4.0 (Highest Risk Scenario)&amp;lt;/h3&amp;gt;&amp;#xA;&amp;lt;ul&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Vector String:&amp;lt;/strong&amp;gt; CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:N/SA:N/AU:N/R:U/V:C/RE:H/U:Red&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Base Score:&amp;lt;/strong&amp;gt; 9.3&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Base Severity:&amp;lt;/strong&amp;gt; CRITICAL&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Scenario&amp;lt;/strong&amp;gt;: The risk is highest when you allow access to the management interface from external IP addresses on the internet.&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;/ul&amp;gt;&amp;#xA;&amp;lt;h3 id=&amp;#34;cvss-v40-restricted-access-scenario&amp;#34;&amp;gt;CVSS v4.0 (Restricted Access Scenario)&amp;lt;/h3&amp;gt;&amp;#xA;&amp;lt;ul&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Vector String:&amp;lt;/strong&amp;gt; CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/AU:N/R:U/V:C/RE:H/U:Red&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Base Score:&amp;lt;/strong&amp;gt; 5.9&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Base Severity:&amp;lt;/strong&amp;gt; MEDIUM&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Scenario&amp;lt;/strong&amp;gt;:  If you configure restricted access to a jump box that is the only system allowed to access the management interface, you greatly reduce the risk of exploitation because attacks would require privileged access using only those IP addresses.&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;/ul&amp;gt;&amp;#xA;&amp;lt;h2 id=&amp;#34;credits&amp;#34;&amp;gt;Credits&amp;lt;/h2&amp;gt;&amp;#xA;&amp;lt;ul&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;Palo Alto Networks thanks our Deep Product Security Research Team for discovering this issue internally from threat activity.&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;/ul&amp;gt;&amp;#xA;&amp;lt;h2 id=&amp;#34;references&amp;#34;&amp;gt;References&amp;lt;/h2&amp;gt;&amp;#xA;&amp;lt;ul&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;a href=&amp;#34;https://vulnerability.circl.lu/vuln/cve-2024-0012&amp;#34;&amp;gt;CVE-2024-0012&amp;lt;/a&amp;gt; and &amp;lt;a href=&amp;#34;https://vulnerability.circl.lu/vuln/cve-2024-9474&amp;#34;&amp;gt;CVE-2024-9474&amp;lt;/a&amp;gt;&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;a href=&amp;#34;https://vulnerability.circl.lu/bundle/d6006baf-209a-4a38-8a58-394ea67eab2a&amp;#34;&amp;gt;Palo Alto - Privilege Escalation (PE) Vulnerability in the Web Management Interface versus : Authentication Bypass in the Management Web Interface&amp;lt;/a&amp;gt;&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;a href=&amp;#34;https://security.paloaltonetworks.com/CVE-2024-0012&amp;#34;&amp;gt;Palo Alto Networks Advisory&amp;lt;/a&amp;gt;&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;a href=&amp;#34;https://labs.watchtowr.com/pots-and-pans-aka-an-sslvpn-palo-alto-pan-os-cve-2024-0012-and-cve-2024-9474/&amp;#34;&amp;gt;WatchTowr Labs Analysis&amp;lt;/a&amp;gt;&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;a href=&amp;#34;https://unit42.paloaltonetworks.com/cve-2024-0012-cve-2024-9474/&amp;#34;&amp;gt;Unit 42 Analysis&amp;lt;/a&amp;gt;&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;/ul&amp;gt;&amp;#xA;&amp;lt;h2 id=&amp;#34;timeline&amp;#34;&amp;gt;Timeline&amp;lt;/h2&amp;gt;&amp;#xA;&amp;lt;ul&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;2024-11-18T14:20:00.000Z:&amp;lt;/strong&amp;gt; CVE-2024-0012 assigned, vulnerability identified and fixed.&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;2024-11-15T22:00:00.000Z:&amp;lt;/strong&amp;gt; FAQ about indicators of compromise answered.&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;2024-11-14T22:18:00.000Z:&amp;lt;/strong&amp;gt; Severity of PAN-SA-2024-0015 bulletin raised due to observed threat activity.&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;2024-11-11T01:03:00.000Z:&amp;lt;/strong&amp;gt; Added instructions to find devices with an internet-facing management interface discovered in scans.&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;2024-11-08T13:00:00.000Z:&amp;lt;/strong&amp;gt; Initially published as PAN-SA-2024-0015.&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;/ul&amp;gt;&amp;#xA;&amp;lt;h2 id=&amp;#34;additional-information&amp;#34;&amp;gt;Additional Information&amp;lt;/h2&amp;gt;&amp;#xA;&amp;lt;h3 id=&amp;#34;configuration-notes&amp;#34;&amp;gt;Configuration Notes&amp;lt;/h3&amp;gt;&amp;#xA;&amp;lt;p&amp;gt;The risk is highest if the management interface is configured to enable access from the internet or untrusted networks either:&amp;lt;/p&amp;gt;&amp;#xA;&amp;lt;ul&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;Directly or,&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;Through a data plane interface that includes a management interface profile&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;/ul&amp;gt;&amp;#xA;&amp;lt;p&amp;gt;The risk is greatly reduced by limiting access to the management interface to only trusted internal IP addresses.&amp;lt;/p&amp;gt;&amp;#xA;&amp;lt;p&amp;gt;Use the following steps to identify recently detected devices:&amp;lt;/p&amp;gt;&amp;#xA;&amp;lt;ol&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;Visit the Assets section of Customer Support Portal at &amp;lt;a href=&amp;#34;https://support.paloaltonetworks.com&amp;#34;&amp;gt;https://support.paloaltonetworks.com&amp;lt;/a&amp;gt; (Products → Assets → All Assets → Remediation Required).&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;Devices with an internet-facing management interface discovered in scans are tagged with PAN-SA-2024-0015. A last seen timestamp is shown in UTC. If no such devices are listed, scans did not find any devices with an internet-facing management interface within the last three days.&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;/ol&amp;gt;&amp;#xA;&amp;lt;h3 id=&amp;#34;cisa-adp-information&amp;#34;&amp;gt;CISA ADP Information&amp;lt;/h3&amp;gt;&amp;#xA;&amp;lt;ul&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;#xA;&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;CISA Known Exploited Vulnerabilities (KEV):&amp;lt;/strong&amp;gt;&amp;lt;/p&amp;gt;&amp;#xA;&amp;lt;ul&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Date Added:&amp;lt;/strong&amp;gt; 2024-11-18&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Reference:&amp;lt;/strong&amp;gt; &amp;lt;a href=&amp;#34;https://www.cisa.gov/known-exploited-vulnerabilities-catalog?search_api_fulltext=CVE-2024-0012&amp;#34;&amp;gt;https://www.cisa.gov/known-exploited-vulnerabilities-catalog?search_api_fulltext=CVE-2024-0012&amp;lt;/a&amp;gt;&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;/ul&amp;gt;&amp;#xA;&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;#xA;&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;SSVC Metrics&amp;lt;/strong&amp;gt;:&amp;lt;/p&amp;gt;&amp;#xA;&amp;lt;ul&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Timestamp:&amp;lt;/strong&amp;gt; 2024-11-19T04:55:47.202753Z&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;ID:&amp;lt;/strong&amp;gt; CVE-2024-0012&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Options:&amp;lt;/strong&amp;gt; Exploitation: active, Automatable: yes, Technical Impact: total&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Role:&amp;lt;/strong&amp;gt; CISA Coordinator&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Version:&amp;lt;/strong&amp;gt; 2.0.3&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;/ul&amp;gt;&amp;#xA;&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;/ul&amp;gt;&amp;#xA;&amp;lt;h3 id=&amp;#34;nvd-information&amp;#34;&amp;gt;NVD Information&amp;lt;/h3&amp;gt;&amp;#xA;&amp;lt;ul&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;#xA;&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;NVD Description&amp;lt;/strong&amp;gt;: An authentication bypass in Palo Alto Networks PAN-OS software enables an unauthenticated attacker with network access to the management web interface to gain PAN-OS administrator privileges to perform administrative actions, tamper with the configuration, or exploit other authenticated privilege escalation vulnerabilities like  CVE-2024-9474.&amp;#xA;The risk of this issue is greatly reduced if you secure access to the management web interface by restricting access to only trusted internal IP addresses according to our recommended  best practice deployment guidelines.&amp;#xA;This issue is applicable only to PAN-OS 10.2, PAN-OS 11.0, PAN-OS 11.1, and PAN-OS 11.2 software. Cloud NGFW and Prisma Access are not impacted by this vulnerability.&amp;lt;/p&amp;gt;&amp;#xA;&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;#xA;&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;NVD CVSS v3.1 Metrics:&amp;lt;/strong&amp;gt;&amp;lt;/p&amp;gt;&amp;#xA;&amp;lt;ul&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Vector String:&amp;lt;/strong&amp;gt; CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Base Score:&amp;lt;/strong&amp;gt; 9.8&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Base Severity:&amp;lt;/strong&amp;gt; CRITICAL&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;/ul&amp;gt;&amp;#xA;&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;/ul&amp;gt;&amp;#xA;&amp;lt;h3 id=&amp;#34;linked-csaf-documents&amp;#34;&amp;gt;Linked CSAF Documents&amp;lt;/h3&amp;gt;&amp;#xA;&amp;lt;ul&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;CISA:&amp;lt;/strong&amp;gt;&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;a href=&amp;#34;https://www.cisa.gov/news-events/ics-advisories/icsa-24-338-02&amp;#34;&amp;gt;ICSA-24-338-02&amp;lt;/a&amp;gt; - Siemens RUGGEDCOM APE1808 devices&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;NCSC-NL:&amp;lt;/strong&amp;gt;&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;a href=&amp;#34;https://advisories.ncsc.nl/advisory?id=NCSC-2024-0451&amp;#34;&amp;gt;ncsc-2024-0451&amp;lt;/a&amp;gt; - Kwetsbaarheden verholpen in Palo Alto PAN-OS&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;/ul&amp;gt;&amp;#xA;&amp;lt;h3 id=&amp;#34;github-advisory&amp;#34;&amp;gt;GitHub Advisory&amp;lt;/h3&amp;gt;&amp;#xA;&amp;lt;ul&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;a href=&amp;#34;https://github.com/advisories/GHSA-mw9x-2qwv-599p&amp;#34;&amp;gt;GHSA-mw9x-2qwv-599p&amp;lt;/a&amp;gt;&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;/ul&amp;gt;&amp;#xA;&amp;lt;h3 id=&amp;#34;vulnerability-lookup-bundles&amp;#34;&amp;gt;Vulnerability Lookup Bundles&amp;lt;/h3&amp;gt;&amp;#xA;&amp;lt;ul&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Palo Alto - &amp;lt;a href=&amp;#34;https://vulnerability.circl.lu/bundle/d6006baf-209a-4a38-8a58-394ea67eab2a&amp;#34;&amp;gt;Privilege Escalation (PE) Vulnerability in the Web Management Interface versus : Authentication Bypass in the Management Web Interface&amp;lt;/a&amp;gt;&amp;lt;/strong&amp;gt;&amp;#xA;&amp;lt;ul&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;Description: This bundle highlights the relationship between CVE-2024-0012 and CVE-2024-9474. It notes they are often used in a chain to gain superuser access to PAN-OS systems&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;Related Vulnerabilities: CVE-2024-0012, CVE-2024-9474&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;/ul&amp;gt;&amp;#xA;&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;/ul&amp;gt;&amp;#xA;&amp;lt;h3 id=&amp;#34;vulnerability-sightings&amp;#34;&amp;gt;Vulnerability Sightings&amp;lt;/h3&amp;gt;&amp;#xA;&amp;lt;p&amp;gt;The &amp;lt;a href=&amp;#34;https://vulnerability.circl.lu/bundle/d6006baf-209a-4a38-8a58-394ea67eab2a&amp;#34;&amp;gt;vulnerability has been observed and discussed in various sources&amp;lt;/a&amp;gt;, including:&amp;lt;/p&amp;gt;&amp;#xA;&amp;lt;ul&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;Infosec.exchange user posts (multiple)&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;a href=&amp;#34;https://github.com/projectdiscovery/nuclei-templates/tree/main/http/cves/2024/CVE-2024-0012.yaml&amp;#34;&amp;gt;Projectdiscovery Nuclei Template&amp;lt;/a&amp;gt;&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;MISP Instance (MISP/3c19819c-1dac-4ef2-bfed-be5efa7e0123)&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;Feedsin.space (&amp;lt;a href=&amp;#34;https://feedsin.space/feed/CISAKevBot/items/2704493&amp;#34;&amp;gt;https://feedsin.space/feed/CISAKevBot/items/2704493&amp;lt;/a&amp;gt;)&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;Mastodon posts (multiple)&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;/ul&amp;gt;&amp;#xA;&amp;lt;h2 id=&amp;#34;classification-of-this-document&amp;#34;&amp;gt;Classification of this document&amp;lt;/h2&amp;gt;&amp;#xA;&amp;lt;p&amp;gt;&amp;lt;a href=&amp;#34;/pub/traffic-light-protocol/&amp;#34;&amp;gt;TLP:CLEAR&amp;lt;/a&amp;gt; information may be distributed without restriction, subject to copyright controls.&amp;lt;/p&amp;gt;&amp;#xA;&amp;lt;h2 id=&amp;#34;revision&amp;#34;&amp;gt;Revision&amp;lt;/h2&amp;gt;&amp;#xA;&amp;lt;ul&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;Version 1.0 - TLP:CLEAR - First version - 20th December 2024&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;/ul&amp;gt;&amp;#xA;</content>
  </entry>
  <entry>
    <title>TR-90 - Vulnerability identified as CVE-2023-34990, affecting Fortinet FortiWLM</title>
    <link href="https://www.circl.lu/pub/tr-90/" rel="alternate" type="text/html" />
    <id>https://www.circl.lu/pub/tr-90/</id>
    <published>2024-12-20T00:00:00Z</published>
    <updated>2024-12-20T00:00:00Z</updated>
    <summary>A relative path traversal vulnerability has been discovered in Fortinet FortiWLM versions 8.6.0 through 8.6.5 and 8.5.0 through 8.5.4. This vulnerability allows an attacker to execute unauthorized code or commands by sending specially crafted web requests.&amp;#xA;Affected Products Vendor: Fortinet Product: FortiWLM Versions: 8.6.0 through 8.6.5 (inclusive) 8.5.0 through 8.5.4 (inclusive) Vulnerability Class CWE-23: Relative Path Traversal CWE-94: Improper Control of Generation of Code (‘Code Injection’) Impact Successful exploitation of this vulnerability could lead to the execution of arbitrary code or commands on the affected system.&amp;#xA;</summary>
    <content type="html">&amp;lt;p&amp;gt;A relative path traversal vulnerability has been discovered in Fortinet FortiWLM versions 8.6.0 through 8.6.5 and 8.5.0 through 8.5.4. This vulnerability allows an attacker to execute unauthorized code or commands by sending specially crafted web requests.&amp;lt;/p&amp;gt;&amp;#xA;&amp;lt;h2 id=&amp;#34;affected-products&amp;#34;&amp;gt;Affected Products&amp;lt;/h2&amp;gt;&amp;#xA;&amp;lt;ul&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Vendor:&amp;lt;/strong&amp;gt; Fortinet&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Product:&amp;lt;/strong&amp;gt; FortiWLM&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Versions:&amp;lt;/strong&amp;gt;&amp;#xA;&amp;lt;ul&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;8.6.0 through 8.6.5 (inclusive)&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;8.5.0 through 8.5.4 (inclusive)&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;/ul&amp;gt;&amp;#xA;&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;/ul&amp;gt;&amp;#xA;&amp;lt;h2 id=&amp;#34;vulnerability-class&amp;#34;&amp;gt;Vulnerability Class&amp;lt;/h2&amp;gt;&amp;#xA;&amp;lt;ul&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;CWE-23:&amp;lt;/strong&amp;gt; Relative Path Traversal&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;CWE-94:&amp;lt;/strong&amp;gt; Improper Control of Generation of Code (&amp;amp;lsquo;Code Injection&amp;amp;rsquo;)&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;/ul&amp;gt;&amp;#xA;&amp;lt;h2 id=&amp;#34;impact&amp;#34;&amp;gt;Impact&amp;lt;/h2&amp;gt;&amp;#xA;&amp;lt;p&amp;gt;Successful exploitation of this vulnerability could lead to the execution of arbitrary code or commands on the affected system.&amp;lt;/p&amp;gt;&amp;#xA;&amp;lt;h2 id=&amp;#34;technical-analysis&amp;#34;&amp;gt;Technical Analysis&amp;lt;/h2&amp;gt;&amp;#xA;&amp;lt;h3 id=&amp;#34;attack-vector&amp;#34;&amp;gt;Attack Vector&amp;lt;/h3&amp;gt;&amp;#xA;&amp;lt;ul&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Attack Vector:&amp;lt;/strong&amp;gt; Network&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Attack Complexity:&amp;lt;/strong&amp;gt; Low&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Privileges Required:&amp;lt;/strong&amp;gt; None&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;User Interaction:&amp;lt;/strong&amp;gt; None&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Scope:&amp;lt;/strong&amp;gt; Unchanged&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;/ul&amp;gt;&amp;#xA;&amp;lt;h3 id=&amp;#34;cvss-metrics&amp;#34;&amp;gt;CVSS Metrics&amp;lt;/h3&amp;gt;&amp;#xA;&amp;lt;h4 id=&amp;#34;cna-cvss-score&amp;#34;&amp;gt;CNA CVSS Score&amp;lt;/h4&amp;gt;&amp;#xA;&amp;lt;ul&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;CVSS v3.1 Base Score:&amp;lt;/strong&amp;gt; 9.6&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;CVSS v3.1 Base Severity:&amp;lt;/strong&amp;gt; CRITICAL&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Vector String:&amp;lt;/strong&amp;gt; &amp;lt;code&amp;gt;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H&amp;lt;/code&amp;gt;&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Attack Vector (AV):&amp;lt;/strong&amp;gt; Network (N)&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Attack Complexity (AC):&amp;lt;/strong&amp;gt; Low (L)&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Privileges Required (PR):&amp;lt;/strong&amp;gt; None (N)&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;User Interaction (UI):&amp;lt;/strong&amp;gt; None (N)&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Scope (S):&amp;lt;/strong&amp;gt; Unchanged (U)&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Confidentiality Impact (C):&amp;lt;/strong&amp;gt; High (H)&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Integrity Impact (I):&amp;lt;/strong&amp;gt; High (H)&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Availability Impact (A):&amp;lt;/strong&amp;gt; High (H)&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;/ul&amp;gt;&amp;#xA;&amp;lt;h4 id=&amp;#34;cisa-adp-cvss-score&amp;#34;&amp;gt;CISA ADP CVSS Score&amp;lt;/h4&amp;gt;&amp;#xA;&amp;lt;ul&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;CVSS v3.1 Base Score:&amp;lt;/strong&amp;gt; 9.8&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;CVSS v3.1 Base Severity:&amp;lt;/strong&amp;gt; CRITICAL&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Vector String:&amp;lt;/strong&amp;gt; &amp;lt;code&amp;gt;CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H&amp;lt;/code&amp;gt;&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Attack Vector (AV):&amp;lt;/strong&amp;gt; Network (N)&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Attack Complexity (AC):&amp;lt;/strong&amp;gt; Low (L)&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Privileges Required (PR):&amp;lt;/strong&amp;gt; None (N)&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;User Interaction (UI):&amp;lt;/strong&amp;gt; None (N)&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Scope (S):&amp;lt;/strong&amp;gt; Unchanged (U)&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Confidentiality Impact (C):&amp;lt;/strong&amp;gt; High (H)&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Integrity Impact (I):&amp;lt;/strong&amp;gt; High (H)&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Availability Impact (A):&amp;lt;/strong&amp;gt; High (H)&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;/ul&amp;gt;&amp;#xA;&amp;lt;h3 id=&amp;#34;cisa-adp-ssvc&amp;#34;&amp;gt;CISA ADP SSVC&amp;lt;/h3&amp;gt;&amp;#xA;&amp;lt;ul&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;SSVC Version:&amp;lt;/strong&amp;gt; 2.0.3&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;SSVC ID:&amp;lt;/strong&amp;gt; CVE-2023-34990&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Timestamp:&amp;lt;/strong&amp;gt; 2024-12-19T00:00:00&#43;00:00&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Options:&amp;lt;/strong&amp;gt;&amp;#xA;&amp;lt;ul&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;Exploitation: None&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;Automatable: Yes&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;Technical Impact: Total&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Role:&amp;lt;/strong&amp;gt; CISA Coordinator&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;/ul&amp;gt;&amp;#xA;&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;/ul&amp;gt;&amp;#xA;&amp;lt;h2 id=&amp;#34;mitigation&amp;#34;&amp;gt;Mitigation&amp;lt;/h2&amp;gt;&amp;#xA;&amp;lt;ul&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;Upgrade to FortiWLM version 8.6.6 or later.&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;Upgrade to FortiWLM version 8.5.5 or later.&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;/ul&amp;gt;&amp;#xA;&amp;lt;h2 id=&amp;#34;references&amp;#34;&amp;gt;References&amp;lt;/h2&amp;gt;&amp;#xA;&amp;lt;ul&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;a href=&amp;#34;https://fortiguard.com/psirt/FG-IR-23-144&amp;#34;&amp;gt;Fortiguard Advisory&amp;lt;/a&amp;gt;&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;a href=&amp;#34;https://vulnerability.circl.lu/vuln/CVE-2023-34990&amp;#34;&amp;gt;NIST NVD CVE Details&amp;lt;/a&amp;gt;&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;a href=&amp;#34;https://vulnerability.circl.lu/vuln/ghsa-2pp3-2hr3-936m&amp;#34;&amp;gt;GitHub Security Advisory&amp;lt;/a&amp;gt;&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;a href=&amp;#34;https://vulnerability.circl.lu/vuln/GSD-2023-34990&amp;#34;&amp;gt;GSD Vulnerability ID&amp;lt;/a&amp;gt;&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;/ul&amp;gt;&amp;#xA;&amp;lt;h2 id=&amp;#34;additional-sightings&amp;#34;&amp;gt;Additional Sightings&amp;lt;/h2&amp;gt;&amp;#xA;&amp;lt;h3 id=&amp;#34;mastodon&amp;#34;&amp;gt;Mastodon&amp;lt;/h3&amp;gt;&amp;#xA;&amp;lt;ul&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;a href=&amp;#34;https://infosec.exchange/users/mttaggart/statuses/113676180752563416&amp;#34;&amp;gt;https://infosec.exchange/users/mttaggart/statuses/113676180752563416&amp;lt;/a&amp;gt;&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;a href=&amp;#34;https://infosec.exchange/users/cve/statuses/113673904010874634&amp;#34;&amp;gt;https://infosec.exchange/users/cve/statuses/113673904010874634&amp;lt;/a&amp;gt;&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;a href=&amp;#34;https://infosec.exchange/users/screaminggoat/statuses/113674791142313324&amp;#34;&amp;gt;https://infosec.exchange/users/screaminggoat/statuses/113674791142313324&amp;lt;/a&amp;gt;&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;a href=&amp;#34;https://infosec.exchange/users/screaminggoat/statuses/113674904259060282&amp;#34;&amp;gt;https://infosec.exchange/users/screaminggoat/statuses/113674904259060282&amp;lt;/a&amp;gt;&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;a href=&amp;#34;https://infosec.exchange/users/adulau/statuses/113674914309627637&amp;#34;&amp;gt;https://infosec.exchange/users/adulau/statuses/113674914309627637&amp;lt;/a&amp;gt;&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;a href=&amp;#34;https://infosec.exchange/users/screaminggoat/statuses/113674927052267535&amp;#34;&amp;gt;https://infosec.exchange/users/screaminggoat/statuses/113674927052267535&amp;lt;/a&amp;gt;&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;a href=&amp;#34;https://infosec.exchange/users/screaminggoat/statuses/113675208676939403&amp;#34;&amp;gt;https://infosec.exchange/users/screaminggoat/statuses/113675208676939403&amp;lt;/a&amp;gt;&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;a href=&amp;#34;https://cyberplace.social/users/GossiTheDog/statuses/113674232166302816&amp;#34;&amp;gt;https://cyberplace.social/users/GossiTheDog/statuses/113674232166302816&amp;lt;/a&amp;gt;&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;a href=&amp;#34;https://social.circl.lu/users/circl/statuses/113674370374104492&amp;#34;&amp;gt;https://social.circl.lu/users/circl/statuses/113674370374104492&amp;lt;/a&amp;gt;&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;a href=&amp;#34;https://infosec.exchange/users/edwardk/statuses/113679655471686245&amp;#34;&amp;gt;https://infosec.exchange/users/edwardk/statuses/113679655471686245&amp;lt;/a&amp;gt;&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;a href=&amp;#34;https://infosec.exchange/users/jbhall56/statuses/113679787983720927&amp;#34;&amp;gt;https://infosec.exchange/users/jbhall56/statuses/113679787983720927&amp;lt;/a&amp;gt;&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;/ul&amp;gt;&amp;#xA;&amp;lt;h3 id=&amp;#34;bluesky&amp;#34;&amp;gt;Bluesky&amp;lt;/h3&amp;gt;&amp;#xA;&amp;lt;ul&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;a href=&amp;#34;https://bsky.app/profile/nimblenerd.social/post/3ldnubko4bc2n&amp;#34;&amp;gt;https://bsky.app/profile/nimblenerd.social/post/3ldnubko4bc2n&amp;lt;/a&amp;gt;&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;a href=&amp;#34;https://bsky.app/profile/nimblenerd.social/post/3ldnuagu2lw2e&amp;#34;&amp;gt;https://bsky.app/profile/nimblenerd.social/post/3ldnuagu2lw2e&amp;lt;/a&amp;gt;&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;a href=&amp;#34;https://bsky.app/profile/nimblenerd.social/post/3ldnuh5j6z72k&amp;#34;&amp;gt;https://bsky.app/profile/nimblenerd.social/post/3ldnuh5j6z72k&amp;lt;/a&amp;gt;&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;a href=&amp;#34;https://bsky.app/profile/potato.software/post/3ldnuipavmq2c&amp;#34;&amp;gt;https://bsky.app/profile/potato.software/post/3ldnuipavmq2c&amp;lt;/a&amp;gt;&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;a href=&amp;#34;https://bsky.app/profile/hackingne.ws/post/3ldnwrxvui22v&amp;#34;&amp;gt;https://bsky.app/profile/hackingne.ws/post/3ldnwrxvui22v&amp;lt;/a&amp;gt;&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;a href=&amp;#34;https://bsky.app/profile/nimblenerd.social/post/3ldogmyckhc2e&amp;#34;&amp;gt;https://bsky.app/profile/nimblenerd.social/post/3ldogmyckhc2e&amp;lt;/a&amp;gt;&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;a href=&amp;#34;https://bsky.app/profile/bolhasec.com/post/3ldnrh54g5i2b&amp;#34;&amp;gt;https://bsky.app/profile/bolhasec.com/post/3ldnrh54g5i2b&amp;lt;/a&amp;gt;&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;a href=&amp;#34;https://bsky.app/profile/nihonmatsu.bsky.social/post/3ldnrwzdzps2b&amp;#34;&amp;gt;https://bsky.app/profile/nihonmatsu.bsky.social/post/3ldnrwzdzps2b&amp;lt;/a&amp;gt;&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;a href=&amp;#34;https://bsky.app/profile/nidouille.bsky.social/post/3ldnywp2izk2f&amp;#34;&amp;gt;https://bsky.app/profile/nidouille.bsky.social/post/3ldnywp2izk2f&amp;lt;/a&amp;gt;&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;a href=&amp;#34;https://bsky.app/profile/jbhall56.bsky.social/post/3ldnyyoiymc2g&amp;#34;&amp;gt;https://bsky.app/profile/jbhall56.bsky.social/post/3ldnyyoiymc2g&amp;lt;/a&amp;gt;&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;/ul&amp;gt;&amp;#xA;&amp;lt;h3 id=&amp;#34;news&amp;#34;&amp;gt;News&amp;lt;/h3&amp;gt;&amp;#xA;&amp;lt;ul&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;a href=&amp;#34;https://thehackernews.com/2024/12/fortinet-warns-of-critical-fortiwlm.html&amp;#34;&amp;gt;https://thehackernews.com/2024/12/fortinet-warns-of-critical-fortiwlm.html&amp;lt;/a&amp;gt;&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;a href=&amp;#34;https://www.darkreading.com/vulnerabilities-threats/fortinet-addresses-unpatched-critical-rce-vector&amp;#34;&amp;gt;https://www.darkreading.com/vulnerabilities-threats/fortinet-addresses-unpatched-critical-rce-vector&amp;lt;/a&amp;gt;&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;/ul&amp;gt;&amp;#xA;&amp;lt;h2 id=&amp;#34;classification-of-this-document&amp;#34;&amp;gt;Classification of this document&amp;lt;/h2&amp;gt;&amp;#xA;&amp;lt;p&amp;gt;&amp;lt;a href=&amp;#34;/pub/traffic-light-protocol/&amp;#34;&amp;gt;TLP:CLEAR&amp;lt;/a&amp;gt; information may be distributed without restriction, subject to copyright controls.&amp;lt;/p&amp;gt;&amp;#xA;&amp;lt;h2 id=&amp;#34;revision&amp;#34;&amp;gt;Revision&amp;lt;/h2&amp;gt;&amp;#xA;&amp;lt;ul&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;Version 1.0 - TLP:CLEAR - First version - 20th December 2024&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;/ul&amp;gt;&amp;#xA;</content>
  </entry>
  <entry>
    <title>TR-89 - Guidelines for Notifying CSIRT/CERT of Red Teaming and Penetration Testing Exercises - Enhancing Detection and Coordination</title>
    <link href="https://www.circl.lu/pub/tr-89/" rel="alternate" type="text/html" />
    <id>https://www.circl.lu/pub/tr-89/</id>
    <published>2024-11-12T00:00:00Z</published>
    <updated>2024-11-12T00:00:00Z</updated>
    <summary>Objective This document outlines recommended practices for notifying Computer Security Incident Response Teams (CSIRT) and Computer Emergency Response Teams (CERT) when organizations plan to conduct red teaming, penetration testing, or other cybersecurity exercises. It highlights the importance of communication, coordination, and technical readiness to detect and differentiate simulated attacks from real threats.&amp;#xA;Who The guidelines are applicable to organizations (in Luxembourg or abroad) performing security exercises that involve simulated attacks on production or critical infrastructure, especially those that could trigger alerts in national or sectoral CSIRTs and CERTs.&amp;#xA;</summary>
    <content type="html">&amp;lt;h2 id=&amp;#34;objective&amp;#34;&amp;gt;Objective&amp;lt;/h2&amp;gt;&amp;#xA;&amp;lt;p&amp;gt;This document outlines recommended practices for notifying Computer Security Incident Response Teams (CSIRT) and Computer Emergency Response Teams (CERT) when organizations plan to conduct red teaming, penetration testing, or other cybersecurity exercises. It highlights the importance of communication, coordination, and technical readiness to detect and differentiate simulated attacks from real threats.&amp;lt;/p&amp;gt;&amp;#xA;&amp;lt;h2 id=&amp;#34;who&amp;#34;&amp;gt;Who&amp;lt;/h2&amp;gt;&amp;#xA;&amp;lt;p&amp;gt;The guidelines are applicable to organizations (in Luxembourg or abroad) performing security exercises that involve simulated attacks on production or critical infrastructure, especially those that could trigger alerts in national or sectoral CSIRTs and CERTs.&amp;lt;/p&amp;gt;&amp;#xA;&amp;lt;h2 id=&amp;#34;why&amp;#34;&amp;gt;Why&amp;lt;/h2&amp;gt;&amp;#xA;&amp;lt;ul&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;Reducing Misinterpretation: Why notifying CSIRTs/CERTs is essential to avoid misinterpreting simulated attacks as real threats, potentially disrupting incident response processes.&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;Enhancing Collaboration: The role of CSIRTs/CERTs in monitoring and threat intelligence and how advance notification strengthens collaboration but also improve existing detection mechanisms.&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;/ul&amp;gt;&amp;#xA;&amp;lt;h2 id=&amp;#34;notification&amp;#34;&amp;gt;Notification&amp;lt;/h2&amp;gt;&amp;#xA;&amp;lt;h3 id=&amp;#34;what-to-notify&amp;#34;&amp;gt;What to Notify&amp;lt;/h3&amp;gt;&amp;#xA;&amp;lt;ul&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;Scope and objectives of the exercise. We don&amp;amp;rsquo;t require a lot of details just a minimal description with the parties involved.&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;Timeframe (start and end) and schedule of testing activities in UTC.&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;Technical indicators and selectors to facilitate the detection by CIRCL.&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;A contact person or organisation if we have any question or specific issues during a potential detection.&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;/ul&amp;gt;&amp;#xA;&amp;lt;h3 id=&amp;#34;when-to-notify&amp;#34;&amp;gt;When to Notify&amp;lt;/h3&amp;gt;&amp;#xA;&amp;lt;ul&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;We recommend to notify us at least one week in advance before the scheduled testing activities start.&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;/ul&amp;gt;&amp;#xA;&amp;lt;h2 id=&amp;#34;technical-recommendations&amp;#34;&amp;gt;Technical Recommendations&amp;lt;/h2&amp;gt;&amp;#xA;&amp;lt;h3 id=&amp;#34;indicators-and-selectors&amp;#34;&amp;gt;Indicators and Selectors&amp;lt;/h3&amp;gt;&amp;#xA;&amp;lt;ul&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;Techniques for tagging or otherwise marking payloads and simulated malicious infrastructure to aid in detection.&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;It is recommended to assign a randomly generated unique tag (such as a SHA256 hex value or even YARA rule for detecting the payload) to be embedded in malicious payloads, scripts, or even in the headers of infrastructure components.&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;Classification such as &amp;lt;code&amp;gt;exercise:generic=&amp;amp;quot;red-teaming&amp;amp;quot;&amp;lt;/code&amp;gt; in the &amp;lt;a href=&amp;#34;https://www.misp-project.org/taxonomies.html#_exercise&amp;#34;&amp;gt;exercise taxonomy&amp;lt;/a&amp;gt; is recommended if a detection is shared after the timetrame period of the exercise. In case of detection in the wild, CIRCL will tag and share the information with reporting parties if it&amp;amp;rsquo;s publicly detected.&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;/ul&amp;gt;&amp;#xA;&amp;lt;h2 id=&amp;#34;references&amp;#34;&amp;gt;References&amp;lt;/h2&amp;gt;&amp;#xA;&amp;lt;ul&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;a href=&amp;#34;https://csrc.nist.gov/pubs/sp/800/115/final&amp;#34;&amp;gt;NIST SP 800-115 Technical Guide to Information Security Testing and Assessment&amp;lt;/a&amp;gt;&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;/ul&amp;gt;&amp;#xA;&amp;lt;h2 id=&amp;#34;classification-of-this-document&amp;#34;&amp;gt;Classification of this document&amp;lt;/h2&amp;gt;&amp;#xA;&amp;lt;p&amp;gt;&amp;lt;a href=&amp;#34;/pub/traffic-light-protocol/&amp;#34;&amp;gt;TLP:CLEAR&amp;lt;/a&amp;gt; information may be distributed without restriction, subject to copyright controls.&amp;lt;/p&amp;gt;&amp;#xA;&amp;lt;h2 id=&amp;#34;revision&amp;#34;&amp;gt;Revision&amp;lt;/h2&amp;gt;&amp;#xA;&amp;lt;ul&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;Version 1.0 - TLP:CLEAR - First version - 12th November 2024&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;/ul&amp;gt;&amp;#xA;</content>
  </entry>
  <entry>
    <title>TR-88 - Motivation, procedure and rationale for leaked credential notifications</title>
    <link href="https://www.circl.lu/pub/tr-88/" rel="alternate" type="text/html" />
    <id>https://www.circl.lu/pub/tr-88/</id>
    <published>2024-08-30T00:00:00Z</published>
    <updated>2024-08-30T00:00:00Z</updated>
    <summary>Motivation, Procedure, and Rationale for Leaked Credential Notifications Summary In today’s digital landscape, protecting user data is essential for every organization. When public data leaks expose customer credentials, it is critical to respond promptly to mitigate risks. This document outlines why CIRCL sends notifications about such leaks and explains the procedure we expect organizations to follow. The goal is to safeguard both the organization’s infrastructure and its customers, while ensuring compliance with legal requirements and maintaining trust.&amp;#xA;</summary>
    <content type="html">&amp;lt;h2 id=&amp;#34;motivation-procedure-and-rationale-for-leaked-credential-notifications&amp;#34;&amp;gt;Motivation, Procedure, and Rationale for Leaked Credential Notifications&amp;lt;/h2&amp;gt;&amp;#xA;&amp;lt;h3 id=&amp;#34;summary&amp;#34;&amp;gt;Summary&amp;lt;/h3&amp;gt;&amp;#xA;&amp;lt;p&amp;gt;In today’s digital landscape, protecting user data is essential for every organization.&amp;#xA;When public data leaks expose customer credentials, it is critical to respond promptly to mitigate risks.&amp;#xA;This document outlines why CIRCL sends notifications about such leaks and explains the procedure we expect organizations to follow.&amp;#xA;The goal is to safeguard both the organization&amp;amp;rsquo;s infrastructure and its customers, while ensuring compliance with legal requirements and maintaining trust.&amp;lt;/p&amp;gt;&amp;#xA;&amp;lt;h3 id=&amp;#34;motivation&amp;#34;&amp;gt;Motivation&amp;lt;/h3&amp;gt;&amp;#xA;&amp;lt;p&amp;gt;We believe it is both necessary and beneficial for any organization to be informed about public data leaks involving their customers. The main objectives are:&amp;lt;/p&amp;gt;&amp;#xA;&amp;lt;ul&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;To protect the organization&amp;amp;rsquo;s sensitive information and assets.&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;To help safeguard the customer’s personal data and prevent further misuse.&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;/ul&amp;gt;&amp;#xA;&amp;lt;h3 id=&amp;#34;procedure&amp;#34;&amp;gt;Procedure&amp;lt;/h3&amp;gt;&amp;#xA;&amp;lt;p&amp;gt;When CIRCL receives information about leaked credentials affecting user accounts for services in Luxembourg, we are committed to promptly informing the impacted service owners.&amp;#xA;Typically, we compile and share relevant information with the identified contact of the organization. &amp;lt;strong&amp;gt;This process relies heavily on the accuracy of WHOIS data, emphasizing the importance of keeping this information current.&amp;lt;/strong&amp;gt;&amp;lt;/p&amp;gt;&amp;#xA;&amp;lt;p&amp;gt;We expect the organization to take the following steps:&amp;lt;/p&amp;gt;&amp;#xA;&amp;lt;ul&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Reset the leaked passwords&amp;lt;/strong&amp;gt; for the affected accounts.&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Inform their customers&amp;lt;/strong&amp;gt; about the breach, advising them to reset passwords on other services where they may have used the same credentials.&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Investigate potential abuse&amp;lt;/strong&amp;gt; of leaked accounts, for instance by analyzing login activity for unusual IP addresses or patterns.&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Notify the CNPD within 72 hours&amp;lt;/strong&amp;gt; if there is evidence of unauthorized access to accounts, as required by GDPR. Such incidents are classified as data breaches and must be reported accordingly.&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;strong&amp;gt;Improve Authentication and Auditing&amp;lt;/strong&amp;gt; if MFA (Multi-factor authentication) is available, we recommend to enable MFA for the users accessing the organization&amp;amp;rsquo;s infrastructure.&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;/ul&amp;gt;&amp;#xA;&amp;lt;h3 id=&amp;#34;rationale&amp;#34;&amp;gt;Rationale&amp;lt;/h3&amp;gt;&amp;#xA;&amp;lt;p&amp;gt;While we understand the operational and financial implications of handling security notifications, prioritizing data protection is essential for both the organization and its customers.&amp;#xA;As the CERT for Luxembourg&amp;amp;rsquo;s private sector, operating under NIS regulations, our goal is to minimize the economic and reputational damage of security incidents while ensuring regulatory compliance.&amp;lt;/p&amp;gt;&amp;#xA;&amp;lt;p&amp;gt;Here are the key reasons why this approach is critical:&amp;lt;/p&amp;gt;&amp;#xA;&amp;lt;ul&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;#xA;&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Legal Obligations:&amp;lt;/strong&amp;gt; Organizations have a legal duty to protect customer data. Unauthorized access must be reported to the CNPD within the 72-hour window required by GDPR. Failing to do so can lead to significant legal penalties.&amp;lt;/p&amp;gt;&amp;#xA;&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;#xA;&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Customer Trust:&amp;lt;/strong&amp;gt; Customers are more likely to trust notifications from their service provider rather than from a third-party CERT. Direct communication from the organization can reassure users and prompt them to take action, such as resetting their passwords. Additionally, the organization can automate mass password resets and provide tailored guidance, further reducing risks to its infrastructure and customers.&amp;lt;/p&amp;gt;&amp;#xA;&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;#xA;&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Direct Contact Limitations:&amp;lt;/strong&amp;gt; In many cases, the leaks lack customers&amp;amp;rsquo; email addresses and contain only user names, limiting our ability to notify users directly. Organizations, however, have this access and can communicate with their customers more efficiently and effectively.&amp;lt;/p&amp;gt;&amp;#xA;&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;#xA;&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Proactive Security:&amp;lt;/strong&amp;gt; Organizations should take immediate actions such as resetting passwords, notifying users, and conducting forensic investigations into potential breaches. Early and decisive action helps identify compromised accounts and limits further exposure, improving overall security posture. Incorporating these steps into regular risk assessments and technical controls is a proactive way to ensure readiness for potential incidents.&amp;lt;/p&amp;gt;&amp;#xA;&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;/ul&amp;gt;&amp;#xA;&amp;lt;p&amp;gt;In conclusion, we believe that involving organizations in the communication process with their customers is the most effective strategy. This ensures compliance with legal obligations, maintains customer trust, and allows for a more comprehensive investigation of potential risks to the organization’s infrastructure.&amp;lt;/p&amp;gt;&amp;#xA;&amp;lt;h2 id=&amp;#34;references&amp;#34;&amp;gt;References&amp;lt;/h2&amp;gt;&amp;#xA;&amp;lt;ul&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;a href=&amp;#34;/pub/tr-46/&amp;#34;&amp;gt;TR-46 - Information Leaks Affecting Luxembourg and Recommendations&amp;lt;/a&amp;gt;&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;/ul&amp;gt;&amp;#xA;&amp;lt;h2 id=&amp;#34;classification-of-this-document&amp;#34;&amp;gt;Classification of this document&amp;lt;/h2&amp;gt;&amp;#xA;&amp;lt;p&amp;gt;&amp;lt;a href=&amp;#34;/pub/traffic-light-protocol/&amp;#34;&amp;gt;TLP:CLEAR&amp;lt;/a&amp;gt; information may be distributed without restriction, subject to copyright controls.&amp;lt;/p&amp;gt;&amp;#xA;&amp;lt;h2 id=&amp;#34;revision&amp;#34;&amp;gt;Revision&amp;lt;/h2&amp;gt;&amp;#xA;&amp;lt;ul&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;Version 1.0 - TLP:CLEAR - First version - 29th August 2024&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;/ul&amp;gt;&amp;#xA;</content>
  </entry>
  <entry>
    <title>Learning from the Recent Windows/Falcon Sensor Outage - Causes and Potential Improvement Strategies in Linux with Open Source</title>
    <link href="https://www.circl.lu/pub/learning-from-falcon-sensor-outage/" rel="alternate" type="text/html" />
    <id>https://www.circl.lu/pub/learning-from-falcon-sensor-outage/</id>
    <published>2024-07-23T00:00:00Z</published>
    <updated>2024-07-23T00:00:00Z</updated>
    <summary>Learning from the Recent Windows/Falcon Sensor Outage: Causes and Potential Improvement Strategies in Linux Using Open Source Solutions At the time of writing, most people have probably heard about the massive Windows outage caused by a faulty kernel driver in Falcon Sensor, a CrowdStrike software. On Friday, July 19, 2024, a software configuration update designed to target newly observed malicious artifacts used in cyberattacks prevented several million Windows machines to boot. How can a configuration file crash an OS? Because the real issue is not the configuration file itself, but the kernel driver using it. Let’s take a quick, non-technical tour of the potential reasons behind this situation, how it is addressed in the Linux kernel, and what you as users or customers can do to avoid such issues.&amp;#xA;</summary>
    <content type="html">&amp;lt;h2 id=&amp;#34;learning-from-the-recent-windowsfalcon-sensor-outage-causes-and-potential-improvement-strategies-in-linux-using-open-source-solutions&amp;#34;&amp;gt;Learning from the Recent Windows/Falcon Sensor Outage: Causes and Potential Improvement Strategies in Linux Using Open Source Solutions&amp;lt;/h2&amp;gt;&amp;#xA;&amp;lt;p&amp;gt;At the time of writing, most people have probably heard about the massive &amp;lt;a href=&amp;#34;/pub/tr-87/&amp;#34;&amp;gt;Windows outage caused by a faulty kernel driver in &amp;lt;strong&amp;gt;Falcon Sensor&amp;lt;/strong&amp;gt;&amp;lt;/a&amp;gt;, a CrowdStrike software. On &amp;lt;strong&amp;gt;Friday, July 19, 2024&amp;lt;/strong&amp;gt;, a software configuration update designed to target newly observed malicious artifacts used in cyberattacks prevented several million Windows machines to boot. How can a configuration file crash an OS? Because the real issue is not the configuration file itself, but the kernel driver using it. Let&amp;amp;rsquo;s take a quick, non-technical tour of the potential reasons behind this situation, how it is addressed in the Linux kernel, and what you &amp;lt;strong&amp;gt;as users or customers&amp;lt;/strong&amp;gt; can do to avoid such issues.&amp;lt;/p&amp;gt;&amp;#xA;&amp;lt;h2 id=&amp;#34;developing-kernel-drivers-is-hard&amp;#34;&amp;gt;Developing Kernel Drivers is Hard&amp;lt;/h2&amp;gt;&amp;#xA;&amp;lt;p&amp;gt;Kernel drivers allow code to be executed at the kernel level without modifying the kernel itself. This method is used by several software developers for the purposes of low level interactions, such as connecting to specific hardware, firewalling, and security monitoring. Bugs in these drivers are often critical, as they may be exploited by attackers or lead to a denial of service of the operating system.&amp;lt;/p&amp;gt;&amp;#xA;&amp;lt;p&amp;gt;Creating flawless code is a significant challenge for any developer. Most drivers are still developed in &amp;lt;strong&amp;gt;C&amp;lt;/strong&amp;gt; or &amp;lt;strong&amp;gt;C&#43;&#43;&amp;lt;/strong&amp;gt;, which are powerful but complex and &amp;lt;strong&amp;gt;not inherently memory-safe&amp;lt;/strong&amp;gt; languages. Moreover, achieving full code coverage through thorough testing of kernel drivers can be difficult due to the complexity of tracing a running kernel. These challenges, along with other factors such as dealing with undocumented kernel structures, closed-source kernels, and legacy code, can unfortunately lead to bugs and security vulnerabilities.&amp;lt;/p&amp;gt;&amp;#xA;&amp;lt;p&amp;gt;While we respect third-party companies, some may have less rigorous code review and development processes compared to OS kernel developers. This is a common issue in the software industry, where the focus may sometimes be on rapid feature development rather than code quality or stability. Consequently, as long as third-party companies continue to rely on kernel drivers, the risk of kernel panic (&amp;lt;em&amp;gt;A kernel panic is a safety measure in an operating system, triggered by a critical error from which it cannot safely recover, causing the system to halt or restart&amp;lt;/em&amp;gt;) is likely to be higher compared to the risk from the OS kernel itself. Robust testing and advanced development practices are essential to mitigate these risks, but completely eliminating such errors remains a challenging task.&amp;lt;/p&amp;gt;&amp;#xA;&amp;lt;h2 id=&amp;#34;can-this-happen-to-linux&amp;#34;&amp;gt;Can This Happen to Linux?&amp;lt;/h2&amp;gt;&amp;#xA;&amp;lt;p&amp;gt;Kernel panics &amp;lt;strong&amp;gt;can occur on any operating system&amp;lt;/strong&amp;gt;. However, the Linux kernel has been moving away from relying on third party kernel drivers. How is this being achieved? The answer is &amp;lt;strong&amp;gt;eBPF&amp;lt;/strong&amp;gt; (Extended Berkeley Packet Filter). This technology enables code to run within the Linux kernel without the need to modify kernel source code or load kernel modules. A full explanation of how eBPF works is beyond the scope of this post; if you&amp;amp;rsquo;re interested in learning more, please refer to the &amp;lt;a href=&amp;#34;#ebpf&amp;#34;&amp;gt;references section&amp;lt;/a&amp;gt;.&amp;lt;/p&amp;gt;&amp;#xA;&amp;lt;p&amp;gt;The power of eBPF lies in the fact that the code executed is not machine code but bytecode, which is interpreted by a virtual machine running in the kernel. Before execution, the bytecode is subjected to &amp;lt;a href=&amp;#34;https://www.kernel.org/doc/html/latest/bpf/verifier.html&amp;#34;&amp;gt;a code verifier&amp;lt;/a&amp;gt; that checks for any potential programming mistakes that could impact kernel functionality. Since every eBPF program has a maximum number of instructions it can execute (no endless loops are possible), the verifier can check &amp;lt;strong&amp;gt;every single&amp;lt;/strong&amp;gt; instruction. If &amp;lt;strong&amp;gt;the verifier&amp;lt;/strong&amp;gt; detects issues, it will reject the bytecode, preventing it from being loaded into the kernel. This mechanism aims to ensure that &amp;lt;strong&amp;gt;faulty code never reaches the kernel&amp;lt;/strong&amp;gt;, so the only component that may fail is your userland application trying to load eBPF code—a clever way to avoid kernel panics, don&amp;amp;rsquo;t you think?&amp;lt;/p&amp;gt;&amp;#xA;&amp;lt;p&amp;gt;Of course, no software is entirely free from bugs, and eBPF sub-system is no exception. While it is true that bugs can occur, the current design and verification process make the likelihood of eBPF bytecode causing a kernel panic &amp;lt;strong&amp;gt;extremely low&amp;lt;/strong&amp;gt;.&amp;lt;/p&amp;gt;&amp;#xA;&amp;lt;h2 id=&amp;#34;why-not-ebpf-on-windows&amp;#34;&amp;gt;Why Not eBPF on Windows?&amp;lt;/h2&amp;gt;&amp;#xA;&amp;lt;p&amp;gt;&amp;lt;strong&amp;gt;Microsoft&amp;lt;/strong&amp;gt; is currently working on bringing eBPF to &amp;lt;strong&amp;gt;Windows&amp;lt;/strong&amp;gt;, and you can track their progress in the &amp;lt;a href=&amp;#34;https://github.com/microsoft/ebpf-for-windows&amp;#34;&amp;gt;ebpf-for-windows repository&amp;lt;/a&amp;gt;. However, it&amp;amp;rsquo;s important to note that it is still far from offering the same functionality as eBPF on Linux. This limitation restricts its use to specific networking tasks, leaving out critical areas such as performance monitoring and security tracing. For security vendors, these capabilities are essential for building robust and feature-rich products. As a result, they are likely to continue using traditional kernel drivers until eBPF for Windows meets all their requirements.&amp;lt;/p&amp;gt;&amp;#xA;&amp;lt;h2 id=&amp;#34;what-do-we-do-at-circl&amp;#34;&amp;gt;What Do We Do at CIRCL?&amp;lt;/h2&amp;gt;&amp;#xA;&amp;lt;p&amp;gt;At &amp;lt;strong&amp;gt;CIRCL&amp;lt;/strong&amp;gt;, we are strong advocates of open source. Consequently, we are investing time and resources to provide &amp;lt;strong&amp;gt;an open-source alternative to monitoring products&amp;lt;/strong&amp;gt; for Linux. Introducing &amp;lt;a href=&amp;#34;https://github.com/kunai-project/kunai&amp;#34;&amp;gt;Kunai&amp;lt;/a&amp;gt;, a security monitoring tool for Linux written in &amp;lt;strong&amp;gt;Rust&amp;lt;/strong&amp;gt; and powered by &amp;lt;strong&amp;gt;eBPF&amp;lt;/strong&amp;gt;.&amp;lt;/p&amp;gt;&amp;#xA;&amp;lt;p&amp;gt;Inspired by &amp;lt;a href=&amp;#34;https://learn.microsoft.com/en-us/sysinternals/downloads/sysmon&amp;#34;&amp;gt;Sysmon for Windows&amp;lt;/a&amp;gt;, we developed this project to offer a similar experience for &amp;lt;strong&amp;gt;Linux&amp;lt;/strong&amp;gt; users. Like its Windows counterpart, &amp;lt;strong&amp;gt;Kunai&amp;lt;/strong&amp;gt; monitors various system events, including binary and script execution, shared objects being loaded, network connections, and &amp;lt;a href=&amp;#34;https://why.kunai.rocks/docs/category/kunai---events&amp;#34;&amp;gt;many other events&amp;lt;/a&amp;gt; that can be used to build robust &amp;lt;strong&amp;gt;threat detection and hunting&amp;lt;/strong&amp;gt; scenarios. It also tracks security events generated by any Linux container technology, allowing users to monitor activities within their containers. Additionally, it features a &amp;lt;a href=&amp;#34;https://why.kunai.rocks/docs/advanced/rule_configuration&amp;#34;&amp;gt;rule engine&amp;lt;/a&amp;gt; for creating powerful detection and log filtering primitives. Furthermore, it can be integrated with any &amp;lt;strong&amp;gt;Threat Intelligence Provider&amp;lt;/strong&amp;gt;, enabling &amp;lt;strong&amp;gt;real-time, IoC (&amp;lt;a href=&amp;#34;https://why.kunai.rocks/docs/advanced/ioc_configuration&amp;#34;&amp;gt;Indicators of Compromise&amp;lt;/a&amp;gt;) based scanning&amp;lt;/strong&amp;gt; .&amp;lt;/p&amp;gt;&amp;#xA;&amp;lt;p&amp;gt;Although &amp;lt;strong&amp;gt;Kunai&amp;lt;/strong&amp;gt; is primarily designed for &amp;lt;strong&amp;gt;threat detection and hunting&amp;lt;/strong&amp;gt;, it can also be a valuable ally for &amp;lt;strong&amp;gt;forensic analysis&amp;lt;/strong&amp;gt; on Linux systems. Its logs provide detailed insights into the &amp;lt;strong&amp;gt;full activity&amp;lt;/strong&amp;gt; of a given process, which is crucial for understanding what happened on a system.&amp;lt;/p&amp;gt;&amp;#xA;&amp;lt;p&amp;gt;If you have any &amp;lt;strong&amp;gt;security monitoring&amp;lt;/strong&amp;gt; needs for your Linux hosts, consider giving &amp;lt;a href=&amp;#34;https://github.com/kunai-project/kunai&amp;#34;&amp;gt;Kunai&amp;lt;/a&amp;gt; a try. Don’t hesitate to open issues on GitHub or reach out to us if you encounter problems or want to contribute to its improvement.&amp;lt;/p&amp;gt;&amp;#xA;&amp;lt;h2 id=&amp;#34;what-you-can-do-as-a-customer&amp;#34;&amp;gt;What You Can Do as a Customer?&amp;lt;/h2&amp;gt;&amp;#xA;&amp;lt;p&amp;gt;As a customer, &amp;lt;strong&amp;gt;you have the power to choose&amp;lt;/strong&amp;gt; the best solutions and should thoroughly understand and review the technologies you use. Failing to do so can lead to &amp;lt;strong&amp;gt;vulnerabilities&amp;lt;/strong&amp;gt; (including potential outages) in your infrastructure, making you partly responsible for any issues that arise. It is essential to have &amp;lt;strong&amp;gt;a robust&amp;lt;/strong&amp;gt; technology and product evaluation process. If you find a vendor or technology that meets most of your requirements but falls short in some areas, request a roadmap to address these gaps and ensure your needs are fully met. As a general rule, &amp;lt;strong&amp;gt;running third-party kernel drivers should be avoided&amp;lt;/strong&amp;gt; when viable alternatives are available.&amp;lt;/p&amp;gt;&amp;#xA;&amp;lt;p&amp;gt;If &amp;lt;strong&amp;gt;any product&amp;lt;/strong&amp;gt; requires kernel drivers, a good evaluation metric is to check whether these drivers are implemented in a &amp;lt;strong&amp;gt;memory-safe language&amp;lt;/strong&amp;gt; such as &amp;lt;strong&amp;gt;safe Rust&amp;lt;/strong&amp;gt;. In addition to its memory safety capabilities, &amp;lt;strong&amp;gt;safe Rust&amp;lt;/strong&amp;gt; enforces a number of good programming practices by design and provides strong guarantees about the code. This ultimately improves the overall quality of critical code running inside the kernel. Even though Rust is very attractive for kernel level applications, it will likely be necessary to use &amp;lt;strong&amp;gt;unsafe Rust&amp;lt;/strong&amp;gt; (similar to C/C&#43;&#43;), but its use should be minimized to the strictest extent possible. It is worth noting that while kernel code implemented in &amp;lt;strong&amp;gt;Rust&amp;lt;/strong&amp;gt; will not prevent kernel panics, it will provide &amp;lt;strong&amp;gt;most&amp;lt;/strong&amp;gt; of the &amp;lt;strong&amp;gt;Rust&amp;lt;/strong&amp;gt; guarantees and inherently reduce the risk.&amp;lt;/p&amp;gt;&amp;#xA;&amp;lt;h2 id=&amp;#34;conclusions&amp;#34;&amp;gt;Conclusions&amp;lt;/h2&amp;gt;&amp;#xA;&amp;lt;p&amp;gt;Kernel panics have existed for ages and will continue to occur. However, operating system developers take this issue very seriously. While alternatives to relying on traditional C or C&#43;&#43; written kernel modules exist, such as using a &amp;lt;strong&amp;gt;safer&amp;lt;/strong&amp;gt; programming language or another technology like eBPF, some software providers may prefer the conventional approach, likely because developing something from scratch using a completely different method can be too costly. In such cases, remember that &amp;lt;strong&amp;gt;as a user or customer&amp;lt;/strong&amp;gt;, it is your responsibility to push for improvements or opt out of such practices if you do not agree with them.&amp;lt;/p&amp;gt;&amp;#xA;&amp;lt;h2 id=&amp;#34;references&amp;#34;&amp;gt;References&amp;lt;/h2&amp;gt;&amp;#xA;&amp;lt;ul&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;a href=&amp;#34;/pub/tr-87/&amp;#34;&amp;gt;CIRCL Technical Report&amp;lt;/a&amp;gt;&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;a href=&amp;#34;https://www.crowdstrike.com/blog/falcon-update-for-windows-hosts-technical-details/&amp;#34;&amp;gt;CrowdStrike Windows Outage&amp;lt;/a&amp;gt;&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;a href=&amp;#34;https://www.theregister.com/2024/07/21/crowdstrike_linux_crashes_restoration_tools/&amp;#34;&amp;gt;CrowdStrike Linux Kernel Crash&amp;lt;/a&amp;gt;&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;/ul&amp;gt;&amp;#xA;&amp;lt;h2 id=&amp;#34;ebpf&amp;#34;&amp;gt;eBPF&amp;lt;/h2&amp;gt;&amp;#xA;&amp;lt;ul&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;a href=&amp;#34;https://ebpf.io/what-is-ebpf/&amp;#34;&amp;gt;What is eBPF&amp;lt;/a&amp;gt;&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;a href=&amp;#34;https://en.wikipedia.org/wiki/EBPF&amp;#34;&amp;gt;Wikipedia: eBPF&amp;lt;/a&amp;gt;&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;a href=&amp;#34;https://www.kernel.org/doc/html/latest/bpf/index.html&amp;#34;&amp;gt;BPF kernel documentation&amp;lt;/a&amp;gt;&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;a href=&amp;#34;https://www.kernel.org/doc/html/latest/bpf/verifier.html&amp;#34;&amp;gt;eBPF verifier&amp;lt;/a&amp;gt;&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;/ul&amp;gt;&amp;#xA;&amp;lt;h2 id=&amp;#34;classification-of-this-document&amp;#34;&amp;gt;Classification of this document&amp;lt;/h2&amp;gt;&amp;#xA;&amp;lt;p&amp;gt;&amp;lt;a href=&amp;#34;/pub/traffic-light-protocol/&amp;#34;&amp;gt;TLP:CLEAR&amp;lt;/a&amp;gt; information may be distributed without restriction, subject to copyright controls.&amp;lt;/p&amp;gt;&amp;#xA;&amp;lt;h2 id=&amp;#34;revision&amp;#34;&amp;gt;Revision&amp;lt;/h2&amp;gt;&amp;#xA;&amp;lt;ul&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;Version 1.0 - TLP:CLEAR - First version - 22nd July 2024&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;/ul&amp;gt;&amp;#xA;</content>
  </entry>
  <entry>
    <title>TR-87 - CrowdStrike Agent causing BSOD loop on Windows - Faulty Update on Falcon Sensor</title>
    <link href="https://www.circl.lu/pub/tr-87/" rel="alternate" type="text/html" />
    <id>https://www.circl.lu/pub/tr-87/</id>
    <published>2024-07-19T00:00:00Z</published>
    <updated>2024-07-19T00:00:00Z</updated>
    <summary>CrowdStrike Agent causing BSOD loop on Windows - Faulty Update on Falcon Sensor.&amp;#xA;Vulnerable Version And Products Latest version of CrowdStrike Falcon Agent on Windows Fixes and workaround Boot Windows into Safe Mode or the Windows Recovery Environment Navigate to the C:\Windows\System32\drivers\CrowdStrike directory Locate the file matching C-00000291*.sys, and delete it. Boot the host normally. We received reports that only the Windows Recovery Environment mode works, as the driver still seems to be loaded in safe mode.&amp;#xA;</summary>
    <content type="html">&amp;lt;p&amp;gt;CrowdStrike Agent causing BSOD loop on Windows - Faulty Update on Falcon Sensor.&amp;lt;/p&amp;gt;&amp;#xA;&amp;lt;h2 id=&amp;#34;vulnerable-version-and-products&amp;#34;&amp;gt;Vulnerable Version And Products&amp;lt;/h2&amp;gt;&amp;#xA;&amp;lt;ul&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;Latest version of CrowdStrike Falcon Agent on Windows&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;/ul&amp;gt;&amp;#xA;&amp;lt;h2 id=&amp;#34;fixes-and-workaround&amp;#34;&amp;gt;Fixes and workaround&amp;lt;/h2&amp;gt;&amp;#xA;&amp;lt;ul&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;Boot Windows into Safe Mode or the Windows Recovery Environment&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;Navigate to the C:\Windows\System32\drivers\CrowdStrike directory&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;Locate the file matching &amp;lt;code&amp;gt;C-00000291*.sys&amp;lt;/code&amp;gt;, and delete it.&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;Boot the host normally.&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;/ul&amp;gt;&amp;#xA;&amp;lt;p&amp;gt;We received reports that only the Windows Recovery Environment mode works, as the driver still seems to be loaded in safe mode.&amp;lt;/p&amp;gt;&amp;#xA;&amp;lt;h2 id=&amp;#34;detection-and-investigative-assessment-before-the-latest-patchrelease-from-crowdstrike&amp;#34;&amp;gt;Detection and investigative assessment (before the latest patch/release from CrowdStrike)&amp;lt;/h2&amp;gt;&amp;#xA;&amp;lt;ul&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;Windows system stuck in a boot loop. There is a blue screen where the mention is &amp;amp;ldquo;What failed: csagent.sys&amp;amp;rdquo;.&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;/ul&amp;gt;&amp;#xA;&amp;lt;p&amp;gt;The &amp;amp;ldquo;buggy&amp;amp;rdquo; driver has the following hashes:&amp;lt;/p&amp;gt;&amp;#xA;&amp;lt;ul&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;#xA;&amp;lt;p&amp;gt;MD5 - 1618cd13c5263720ec958c3b24b9d1c8&amp;lt;/p&amp;gt;&amp;#xA;&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;#xA;&amp;lt;p&amp;gt;SHA-1 - cb8a27c7347d19bc0b23093a99816dfd8240dbc5&amp;lt;/p&amp;gt;&amp;#xA;&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;#xA;&amp;lt;p&amp;gt;SHA-256 - ad492bc8b884f9c9a5ce0c96087e722a2732cdb31612e092cdbf4a9555b44362&amp;lt;/p&amp;gt;&amp;#xA;&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;#xA;&amp;lt;p&amp;gt;SSDEEP - 384:bIy44Wo45c59r/qQqu1QhSn88MyU64guxkP5O84VLv8xB0&#43;Cn:9495c59rSQBG8CJxfexBl0&amp;lt;/p&amp;gt;&amp;#xA;&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;#xA;&amp;lt;p&amp;gt;TLSH - T1EF03B83AFA108F99D071C0F7D9370B9EB394AD9C2B8257A37A5DBB3D48B55180DC046A&amp;lt;/p&amp;gt;&amp;#xA;&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;#xA;&amp;lt;p&amp;gt;&amp;lt;a href=&amp;#34;https://www.virustotal.com/gui/file/ad492bc8b884f9c9a5ce0c96087e722a2732cdb31612e092cdbf4a9555b44362/detection&amp;#34;&amp;gt;Virustotal reference&amp;lt;/a&amp;gt;&amp;lt;/p&amp;gt;&amp;#xA;&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;#xA;&amp;lt;p&amp;gt;&amp;lt;a href=&amp;#34;https://www.circl.lu/doc/misp/feed-osint/10a54888-bba3-4af5-bc5b-fcda933ac0e2.json&amp;#34;&amp;gt;MISP event with the &amp;amp;ldquo;buggy&amp;amp;rdquo; file&amp;lt;/a&amp;gt; available in the MISP OSINT feed&amp;lt;/p&amp;gt;&amp;#xA;&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;/ul&amp;gt;&amp;#xA;&amp;lt;h2 id=&amp;#34;crowdstrike-themed-malwarephishing-campaigns&amp;#34;&amp;gt;CrowdStrike-themed malware/phishing campaigns&amp;lt;/h2&amp;gt;&amp;#xA;&amp;lt;p&amp;gt;There are ongoing CrowdStrike-themed malware/phishing campaigns such as &amp;lt;a href=&amp;#34;https://www.virustotal.com/gui/file/96dec6e07229201a02f538310815c695cf6147c548ff1c6a0def2fe38f3dcbc8&amp;#34;&amp;gt;this malware sample using fake updates.&amp;lt;/a&amp;gt;.&amp;lt;/p&amp;gt;&amp;#xA;&amp;lt;h2 id=&amp;#34;known-affected-software-in-luxembourg&amp;#34;&amp;gt;Known affected software in Luxembourg&amp;lt;/h2&amp;gt;&amp;#xA;&amp;lt;ul&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;Impact currently unknown in Luxembourg but impact seen at least in US, Australia and India.&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;/ul&amp;gt;&amp;#xA;&amp;lt;h2 id=&amp;#34;references&amp;#34;&amp;gt;References&amp;lt;/h2&amp;gt;&amp;#xA;&amp;lt;ul&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;CrowdStrike &amp;lt;a href=&amp;#34;https://supportportal.crowdstrike.com/s/article/Tech-Alert-Windows-crashes-related-to-Falcon-Sensor-2024-07-19&amp;#34;&amp;gt;Falcon Sensor Windows Crashes&amp;lt;/a&amp;gt;&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;CrowdStrike &amp;lt;a href=&amp;#34;https://www.crowdstrike.com/blog/technical-details-on-todays-outage/&amp;#34;&amp;gt;Technical Details on Today’s Outage&amp;lt;/a&amp;gt;&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;CIRCL &amp;lt;a href=&amp;#34;/pub/learning-from-falcon-sensor-outage/&amp;#34;&amp;gt;Learning from the Recent Windows/Falcon Sensor Outage - Causes and Potential Improvement Strategies in Linux with Open Source&amp;lt;/a&amp;gt;&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;/ul&amp;gt;&amp;#xA;&amp;lt;h2 id=&amp;#34;classification-of-this-document&amp;#34;&amp;gt;Classification of this document&amp;lt;/h2&amp;gt;&amp;#xA;&amp;lt;p&amp;gt;&amp;lt;a href=&amp;#34;/pub/traffic-light-protocol/&amp;#34;&amp;gt;TLP:CLEAR&amp;lt;/a&amp;gt; information may be distributed without restriction, subject to copyright controls.&amp;lt;/p&amp;gt;&amp;#xA;&amp;lt;h2 id=&amp;#34;revision&amp;#34;&amp;gt;Revision&amp;lt;/h2&amp;gt;&amp;#xA;&amp;lt;ul&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;Version 1.0 - TLP:CLEAR - First version - 19th July 2024&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;Version 1.1 - TLP:CLEAR - Recovery versus safe mode from users &#43; clarification of the BSOD - 19th July 2024&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;Version 1.2 - TLP:CLEAR - IOC of the buggy driver added &#43; MISP reference - 19th July 2024&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;Version 1.3 - TLP:CLEAR - Updated TR after the CrowdStrike updates - 20th July 2024&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;Version 1.4 - TLP:CLEAR - CrowdStrike-themed malware/phishing campaigns - 21st July 2024&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;Version 1.5 - TLP:CLEAR - Learning from the recent outage reference added - 23rd July 2024&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;/ul&amp;gt;&amp;#xA;</content>
  </entry>
  <entry>
    <title>TR-86 - Check Point VPN Information Disclosure (CVE-2024-24919) - Actively Exploited</title>
    <link href="https://www.circl.lu/pub/tr-86/" rel="alternate" type="text/html" />
    <id>https://www.circl.lu/pub/tr-86/</id>
    <published>2024-05-31T00:00:00Z</published>
    <updated>2024-05-31T00:00:00Z</updated>
    <summary>A critical information disclosure vulnerability (CVE-2024-24919) exists in Check Point VPN. Successful exploitation of this vulnerability allows a remote attacker to obtain sensitive information, including key materials, user credentials, and configuration files from the operating system.&amp;#xA;Vulnerable Version And Products Check Point Quantum Gateway and CloudGuard Network versions R81.20, R81.10, R81, R80.40. Check Point Spark versions R81.10, R80.20. CloudGuard Network Quantum Maestro Quantum Scalable Chassis Quantum Security Gateways Quantum Spark Appliances Fixes Check point published Preventative Hotfix for CVE-2024-24919 - Quantum Gateway Information Disclosure which includes the details about the hotfix to prevent the exploitation of the vulnerability.&amp;#xA;</summary>
    <content type="html">&amp;lt;p&amp;gt;A critical information disclosure vulnerability (CVE-2024-24919) exists in Check Point VPN. Successful exploitation of this vulnerability allows a remote attacker to obtain sensitive information, including key materials, user credentials, and configuration files from the operating system.&amp;lt;/p&amp;gt;&amp;#xA;&amp;lt;h2 id=&amp;#34;vulnerable-version-and-products&amp;#34;&amp;gt;Vulnerable Version And Products&amp;lt;/h2&amp;gt;&amp;#xA;&amp;lt;ul&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;Check Point Quantum Gateway and CloudGuard Network versions R81.20, R81.10, R81, R80.40.&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;Check Point Spark versions R81.10, R80.20.&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;CloudGuard Network&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;Quantum Maestro&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;Quantum Scalable Chassis&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;Quantum Security Gateways&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;Quantum Spark Appliances&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;/ul&amp;gt;&amp;#xA;&amp;lt;h2 id=&amp;#34;fixes&amp;#34;&amp;gt;Fixes&amp;lt;/h2&amp;gt;&amp;#xA;&amp;lt;p&amp;gt;Check point published &amp;lt;a href=&amp;#34;https://support.checkpoint.com/results/sk/sk182336&amp;#34;&amp;gt;Preventative Hotfix for CVE-2024-24919 - Quantum Gateway Information Disclosure&amp;lt;/a&amp;gt; which includes the details about the hotfix to prevent the exploitation of the vulnerability.&amp;lt;/p&amp;gt;&amp;#xA;&amp;lt;p&amp;gt;The document also includes important extra measures to reset the sensitive information from an exposed device. We strongly recommend to apply those extra measures especially for publicly exposed VPN services.&amp;lt;/p&amp;gt;&amp;#xA;&amp;lt;p&amp;gt;Check Point mentions a &amp;lt;a href=&amp;#34;https://support.checkpoint.com/results/download/132862&amp;#34;&amp;gt;script to check for local users&amp;lt;/a&amp;gt; with password-only authentication, but the vulnerability can affect much more than just the credentials. Therefore, we strongly recommend not only relying on information from the vendors but also from &amp;lt;a href=&amp;#34;https://labs.watchtowr.com/check-point-wrong-check-point-cve-2024-24919/&amp;#34;&amp;gt;organizations evaluating the vulnerability&amp;lt;/a&amp;gt;.&amp;lt;/p&amp;gt;&amp;#xA;&amp;lt;h2 id=&amp;#34;detection-and-investigative-assessment&amp;#34;&amp;gt;Detection and investigative assessment&amp;lt;/h2&amp;gt;&amp;#xA;&amp;lt;ul&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;Review any suspicious access and audit log.&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;/ul&amp;gt;&amp;#xA;&amp;lt;h2 id=&amp;#34;known-affected-software-in-luxembourg&amp;#34;&amp;gt;Known affected software in Luxembourg&amp;lt;/h2&amp;gt;&amp;#xA;&amp;lt;p&amp;gt;A significant number of vulnerable devices were discovered in Luxembourg, and notifications have been sent to the ISPs and available contact points.&amp;lt;/p&amp;gt;&amp;#xA;&amp;lt;p&amp;gt;Due to the simplicity of exploitation, threat actors may have already collected various credentials and could conduct additional actions in the coming weeks.&amp;lt;/p&amp;gt;&amp;#xA;&amp;lt;h2 id=&amp;#34;references&amp;#34;&amp;gt;References&amp;lt;/h2&amp;gt;&amp;#xA;&amp;lt;ul&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;a href=&amp;#34;https://vulnerability.circl.lu/cve/CVE-2024-24919&amp;#34;&amp;gt;CIRCL - CVE-2024-24919&amp;lt;/a&amp;gt;&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;a href=&amp;#34;https://www.misp-project.org/&amp;#34;&amp;gt;MISP&amp;lt;/a&amp;gt; OSINT event - OSINT - Advisory: Active exploitation of Check Point Remote Access VPN vulnerability (CVE-2024-24919) - UUID b1a15b0e-d143-4e93-9a8c-45968fd29936&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;a href=&amp;#34;https://labs.watchtowr.com/check-point-wrong-check-point-cve-2024-24919/&amp;#34;&amp;gt;Watchtowr - Check Point - Wrong Check Point (CVE-2024-24919)&amp;lt;/a&amp;gt;&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;a href=&amp;#34;https://www.mnemonic.io/resources/blog/advisory-check-point-remote-access-vpn-vulnerability-cve-2024-24919/&amp;#34;&amp;gt;Mnemonic - Advisory: Active exploitation of Check Point Remote Access VPN vulnerability (CVE-2024-24919)&amp;lt;/a&amp;gt;&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;&amp;lt;a href=&amp;#34;https://support.checkpoint.com/results/sk/sk182336&amp;#34;&amp;gt;Checkpoint - Preventative Hotfix for CVE-2024-24919 - Quantum Gateway Information Disclosure&amp;lt;/a&amp;gt;&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;/ul&amp;gt;&amp;#xA;&amp;lt;h2 id=&amp;#34;classification-of-this-document&amp;#34;&amp;gt;Classification of this document&amp;lt;/h2&amp;gt;&amp;#xA;&amp;lt;p&amp;gt;&amp;lt;a href=&amp;#34;/pub/traffic-light-protocol/&amp;#34;&amp;gt;TLP:CLEAR&amp;lt;/a&amp;gt; information may be distributed without restriction, subject to copyright controls.&amp;lt;/p&amp;gt;&amp;#xA;&amp;lt;h2 id=&amp;#34;revision&amp;#34;&amp;gt;Revision&amp;lt;/h2&amp;gt;&amp;#xA;&amp;lt;ul&amp;gt;&amp;#xA;&amp;lt;li&amp;gt;Version 1.0 - TLP:CLEAR - First version - 31st May 2024&amp;lt;/li&amp;gt;&amp;#xA;&amp;lt;/ul&amp;gt;&amp;#xA;</content>
  </entry>
</feed>
