Archive

Research

Incident teardowns, detection engineering, reverse engineering and network forensics. Filtered to cisa.

AnalysisMembers

CISA just added four old local privilege escalation bugs to KEV. That is the interesting part.

Between 25 and 27 August, KEV gained CVEs from 2015, 2021 and 2022 — most of them local, none of them remote entry points. A catalogue of what attackers are actively using is telling you about the second stage, and about how much end-of-life software is still running.

5 min readCVE-2015-3246CVE-2015-5287T1068T1190

Full write-up available to members subscribers. See what is included.