Microsoft SMBv1 Remote Code Execution Vulnerability
Why it matters: Known-exploited in the wild — Apply updates per vendor instructions. (due 2022-08-10)
Evidence ✓ CISA KEV · CISA · added 2022-02-10 · Read the advisory →
OpenTrojan unifies threat intelligence, investigations, research and enterprise operations into one trust-first platform. Every claim carries evidence, confidence and sources.
Why it matters: Known-exploited in the wild — Apply updates per vendor instructions. (due 2022-08-10)
Evidence ✓ CISA KEV · CISA · added 2022-02-10 · Read the advisory →
Why it matters: Known-exploited in the wild — For all affected software assets for which updates exist, the only acceptable remediation actions are: 1) Apply updates; OR 2) remove affected assets from agency networks. Temporary mitigations using one of the measures provided at https://www.cisa.gov/uscert/ed-22-02-apache-log4j-recommended-mitigation-measures are only acceptable until updates are available. (due 2021-12-24)
Evidence ✓ CISA KEV · CISA · added 2021-12-10 · Read the advisory →
Why it matters: Severity CRITICAL · CVSS 10 · affects Log4j2
Evidence ✓ NVD · NVD · updated 2024-11-21 · See details & verification →
Why it matters: Severity CRITICAL · CVSS 8.1 · affects Windows
Evidence ✓ NVD · NVD · updated 2024-07-29 · See details & verification →
Why it matters: Recurring new-KEV exploitation pushes
Evidence ✓ CISA KEV · 2 sources · Explore campaign →
Why it matters: FortiGate admin compromise wave
Evidence ✓ CISA advisory · 2 sources · Explore campaign →
Why it matters: Attributed to Lebanon-linked
Evidence ✓ Researchers · 3 sources · Review actor profile →
Why it matters: Attributed to China
Evidence ✓ Researchers · 3 sources · Review actor profile →
Ask the evidence-backed security assistant about any vulnerability, malware or threat-actor question — answers carry sources and confidence.
Ask a question →CVSS, severity, affected products and CISA KEV status for 2,000+ vulnerabilities synced from NVD.
Look up a CVE →Detect, normalize and check IP, domain, URL and hash indicators against OpenTrojan intelligence.
Check an indicator →Email header, JWT, DNS, hash, URL and password utilities — most run locally in your browser.
Browse all 12 tools →Follow CVEs, campaigns, actors, industries and vendors to build your feed. AI drafts a private digest — a human reviews it before anything publishes.
Start an evidence-backed investigation.
Get startedWhat changed today — critical CVEs, campaigns and actors.
Get startedQuery CVEs, malware, actors, campaigns and vendors.
Get startedTurn a question into a citation-backed report.
Get startedDraft a board-ready security briefing.
Get startedStart a deployment project or enterprise pilot.
Get startedNVD · CISA KEV · MITRE ATT&CK · vendor advisories
Every claim carries a visible evidence chain
Answered with calibrated confidence, never certainty
Staleness tracked per item — fresh / aging / stale
Content is reviewed before publication
Public dashboards for trust, status and platform SLA