Skip to content

Commit 98b89d0

Browse files
chg: Minor updates to the last post.
1 parent 4551058 commit 98b89d0

File tree

1 file changed

+4
-3
lines changed

1 file changed

+4
-3
lines changed

content/news/2025-03-01-vulnerability-report-february-2025.md

+4-3
Original file line numberDiff line numberDiff line change
@@ -62,7 +62,6 @@ The podium belongs to Ivanti, Fortinet, and Microsoft.
6262

6363

6464

65-
6665
## Evolution per week
6766

6867
### Week 6
@@ -140,7 +139,7 @@ The podium belongs to Ivanti, Fortinet, and Microsoft.
140139
#### Insights from contributors
141140

142141
* [Out-of-Cycle Security Bulletin: Session Smart Router, Session Smart Conductor, WAN Assurance Router: API Authentication Bypass Vulnerability (CVE-2025-21589)](https://vulnerability.circl.lu/comment/b45703d4-11a4-4f18-a2f4-8929ea2f08d2)
143-
* [Palantirs External Artifacts service (versions 105.110.1 through 105.115.0)](https://vulnerability.circl.lu/comment/6b5acef0-e6ed-4fe9-9181-33b50f601ae5)
142+
* [Palantir's External Artifacts service (versions 105.110.1 through 105.115.0)](https://vulnerability.circl.lu/comment/6b5acef0-e6ed-4fe9-9181-33b50f601ae5)
144143
* [SonicWall Firewall Vulnerability Exploited After PoC Publication](https://vulnerability.circl.lu/comment/b2a6b85e-5b0d-4ac4-b7a4-9227e3ff28e0)
145144
* [Potential privilege escalation in IDPKI](https://vulnerability.circl.lu/bundle/f7d3e0a5-0b01-4120-b61f-763c0f94f7c7)
146145

@@ -182,15 +181,17 @@ The sightings used for this analysis were mainly collected through
182181
On February 11, 2025, a significant leak exposed BLACKBASTA's internal Matrix chat logs.
183182

184183
[A bundle](https://vulnerability.circl.lu/bundle/fdda4963-0aa7-4d15-8a8f-969db8f304ca#combined-sightings)
184+
on Vulnerability-Lookup
185185
is tracking the observations we've detected related to Black Basta's leaked chat logs.
186+
You will find all the impacted products, such as Zimbra, Microsoft Exchange Server, JetBrains, and PAN-OS.
186187

187188
As you can see, there are plenty of sighting correlations from Shadowserver and from MISP, with continuous exploitations.
188189

189190
CVE-2017-11882 (Microsoft Office) was detected in MISP seven years ago (MISP/5a17d980-5438-4503-ba89-693b0a950b0c).
190191
Additionally, recent exploitations have been observed for other CVEs.
191192
Various Nuclei templates are available for this set of vulnerabilities.
192193

193-
You can read this interesting related comment with more details:
194+
You can read an interesting comment with more details:
194195
**[Update on SVR Cyber Operations and Vulnerability Exploitation](https://vulnerability.circl.lu/bundle/92582bf5-d92c-47fe-b891-656d271bbfef)**.
195196

196197

0 commit comments

Comments
 (0)