Microsoft SMBv1 Remote Code Execution Vulnerability
为何重要: Known-exploited in the wild — Apply updates per vendor instructions. (due 2022-08-10)
证据 ✓ CISA KEV · CISA · added 2022-02-10 · 阅读公告 →
OpenTrojan 将威胁情报、调查、研究与企业运营统一到一个以信任为先的平台。每一条声明都带有 证据、置信度与来源。
为何重要: Known-exploited in the wild — Apply updates per vendor instructions. (due 2022-08-10)
证据 ✓ CISA KEV · CISA · added 2022-02-10 · 阅读公告 →
为何重要: Known-exploited in the wild — For all affected software assets for which updates exist, the only acceptable remediation actions are: 1) Apply updates; OR 2) remove affected assets from agency networks. Temporary mitigations using one of the measures provided at https://www.cisa.gov/uscert/ed-22-02-apache-log4j-recommended-mitigation-measures are only acceptable until updates are available. (due 2021-12-24)
证据 ✓ CISA KEV · CISA · added 2021-12-10 · 阅读公告 →
为何重要: Severity CRITICAL · CVSS 10 · affects Log4j2
证据 ✓ NVD · NVD · updated 2024-11-21 · 查看详情与验证 →
为何重要: Severity CRITICAL · CVSS 8.1 · affects Windows
证据 ✓ NVD · NVD · updated 2024-07-29 · 查看详情与验证 →
为何重要: Recurring new-KEV exploitation pushes
证据 ✓ CISA KEV · 2 sources · 探索活动 →
为何重要: FortiGate admin compromise wave
证据 ✓ CISA advisory · 2 sources · 探索活动 →
为何重要: Attributed to Lebanon-linked
证据 ✓ Researchers · 3 sources · 查看主体档案 →
为何重要: Attributed to China
证据 ✓ Researchers · 3 sources · 查看主体档案 →
NVD · CISA KEV · MITRE ATT&CK · 厂商公告
每一条声明都带有可见的证据链
以校准的置信度回答,从不宣称确定
逐项跟踪时效——新鲜 / 老化 / 过期
内容发布前经过审核
信任、状态与平台 SLA 的公开仪表盘