Home
» Risk & Exploitation
» Daily threat intelligence
» Aug 18, 2022
Aug 18, 2022 Cyber Threat Intelligence
Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.
Daily summary
Apple IOS And MacOS: 2 CVEs added to CISA KEV today.
10 new critical disclosures — review patch status on exposed services.
Top threats today
Three highest-priority changes — analyst brief, not a CVE dump.
Critical active threat
CVE-2017-15944
Palo Alto Networks PAN-OS Remote Code Execution
Actively exploited (CISA KEV)
Listed on CISA KEV
Remote code execution exposure
Palo Alto Networks PAN-OS RCE is on CISA KEV — confirmed in-the-wild exploitation. Expect continued targeting while the issue remains on the catalog.
Critical exposure
CVE-2022-25899
Intel Open Active Management Technology Cloud Toolkit Auth Bypass
CVSS 9.8
Authentication bypass — unauthenticated access risk
New critical Intel Open Active Management Technology Cloud Toolkit Auth Bypass (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.
Critical exposure
CVE-2022-30601
Intel Active Management Technology Firmware Info Disclosure
New critical Intel Active Management Technology Firmware Info Disclosure (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.
Active exploitation
CISA KEV — confirmed in-the-wild exploitation.
Google Chromium Intents Insufficient Input Validation
Apple iOS and macOS Out-of-Bounds Write
Apple iOS and macOS Out-of-Bounds Write
Microsoft Active Directory Domain Services Privilege Escalation
Microsoft Windows Runtime Remote Code Execution
SAP Multiple Products HTTP Request Smuggling
Palo Alto Networks PAN-OS Remote Code Execution
View KEV additions
Exploitation dynamics
Nothing flagged in this category for this digest.
See EPSS increases
New critical disclosures
lib/omniauth/failure_endpoint.rb in OmniAuth before 1.9.2 (and before 2.0) does not escape the message_key value.
Authentication bypass for the Open AMT Cloud Toolkit software maintained by Intel(R) before versions 2.0.2 and 2.2.2 may allow an unauthe...
Insufficiently protected credentials for Intel(R) AMT and Intel(R) Standard Manageability may allow an unauthenticated user to potentiall...
Hardcoded JWT Secret in AgileConfig <1.6.8 Server allows remote attackers to use the generated JWT token to gain administrator access.
Library Management System v1.0 was discovered to contain a SQL injection vulnerability via the title parameter at /librarian/history.php.
Library Management System v1.0 was discovered to contain a SQL injection vulnerability via the M_Id parameter at /student/dele.php.
Library Management System v1.0 was discovered to contain a SQL injection vulnerability via the bookId parameter at /staff/delete.php.
Library Management System v1.0 was discovered to contain a SQL injection vulnerability via the RollNo parameter at /staff/delstu.php.
Library Management System v1.0 was discovered to contain a SQL injection vulnerability via the M_Id parameter at /librarian/del.php.
Unsafe Parsing of a PNG tRNS chunk in FastStone Image Viewer through 7.5 results in a stack buffer overflow.
View critical disclosures
cvelogic
Threat Intelligence