Skip to content

Vulnerabilities & Exploits

CVEs, zero-days, exploit chains and the technical analysis behind them.

CVE-Alert October 2023 -FireCompass

(CVE Update August 2023) New and Critical CVEs Exploited In Wild

For the Last 2 Weeks, FireCompass research identified a huge number of CVEs that are high in severity and ransomware, botnet, threat actors creating havoc. Some of the CVEs identified are of popular commercial products used by variants of industries and some new & well know malwares targeting industries for this week. In this, we… Read More »(CVE Update August 2023) New and Critical CVEs Exploited In Wild

Critical CVE Alert - Blog header - Firecompass

(CVE Update March 2023) New and Critical CVEs Exploited In Wild

For the last 2 weeks, Firecompass Research Team focused on 9 brand-new vulnerabilities which are Critical in severity, published by the global security research community. Ransomwares are targeting many of these vulnerabilities to get initial Access. All the vulnerabilities have Proof of Concepts (PoC) exploit code publicly available on Github making it is easy for… Read More »(CVE Update March 2023) New and Critical CVEs Exploited In Wild

Critical “SMBleed”, Vulnerability: Why Should You Be Worried?

This blog is contributed by Apoorv Saxena, technical team, FireCompass. At the end of May a researcher by the pseudonym “chompie”  published a tweet that showed a working PoC for CVE-2020-0976(SMBGhost), expecting a similar disclosure from the ZecOps security. As part of Microsoft June 2020 Patch release on June 9, ZecOps Researcher disclosed a new… Read More »Critical “SMBleed”, Vulnerability: Why Should You Be Worried?

RDP:Remote, ‘Wormable’ Pre-Authentication Windows Vulnerability”

Microsoft has issued an warning that another ransomware outbreak similar to Wannacry can shut down the internet. There is a critical vulnerability (CVE-2019-0708) in its RDP/Remote Desktop Services that can be exploited remotely, via RDP, without authentication and can be used to run arbitrary code. An attacker could then install programs, view, change, or delete data; or create… Read More »RDP:Remote, ‘Wormable’ Pre-Authentication Windows Vulnerability”

Firecompass ranked #1 AI on HackerOne. Read more →