Home
» Risk & Exploitation
» Daily threat intelligence
» Aug 9, 2022
Aug 9, 2022 Cyber Threat Intelligence
Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.
Daily summary
Microsoft Windows added to CISA KEV — confirmed in-the-wild exploitation.
Thingsboard: public exploit or PoC linked (XSS)
3 new critical disclosures — review patch status on exposed services.
Top threats today
Three highest-priority changes — analyst brief, not a CVE dump.
Critical active threat
CVE-2022-30333
RARLAB UnRAR Directory Traversal
Actively exploited (CISA KEV)
Listed on CISA KEV
RARLAB UnRAR Directory Traversal is on CISA KEV — confirmed in-the-wild exploitation. Expect continued targeting while the issue remains on the catalog.
Active exploit activity
CVE-2020-2038
Paloaltonetworks Pan-os Command Injection
Public exploit or PoC available
Exploit activity linked
Paloaltonetworks Pan-os Command Injection now has public exploit or PoC linkage — assume opportunistic scanning and targeted follow-on activity.
Critical exposure
CVE-2022-30133
Windows Point-to-Point Protocol (PPP) Remote Code Execution Vulnerability
CVSS 9.8
Remote code execution exposure
New critical Microsoft Windows 10 RCE (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.
Active exploitation
CISA KEV — confirmed in-the-wild exploitation.
Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution
RARLAB UnRAR Directory Traversal
View KEV additions
Exploit & PoC activity
A cross-site scripting (XSS) vulnerability in Rule Engine in ThingsBoard 3.3.1 allows remote attackers (with administrative access) to in...
A cross-site scripting (XSS) vulnerability in Rule Engine in ThingsBoard 3.3.1 allows remote attackers (with administrative access) to in...
A stored cross-site scripting (XSS) vulnerability in /index.php?r=site%2Fsignup of Feehi CMS v2.1.1 allows attackers to execute arbitrary...
prestashop/blockwishlist is a prestashop extension which adds a block containing the customer's wishlists.
An OS Command Injection vulnerability in the PAN-OS management interface that allows authenticated administrators to execute arbitrary OS...
View new exploit links
Exploitation dynamics
Nothing flagged in this category for this digest.
See EPSS increases
New critical disclosures
Windows Point-to-Point Protocol (PPP) Remote Code Execution Vulnerability
Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability
Windows Network File System Remote Code Execution Vulnerability
View critical disclosures
cvelogic
Threat Intelligence