ThreatCluster[verified]@threatclusterActive Exploitation
The tweet reports that the hacking group Hacking Cat is actively exploiting CVE-2021-26855 and CVE-2026-42897 to install Gorilla RAT and tunnel into Russian internal networks.
connect24h[verified]@connect24hActive Exploitation
SharkLoader leverages several known CVEs (including ProxyLogon, Openfire, GeoServer) to gain initial access and deploy Cobalt Strike, with Kaspersky reporting active attacks on government and software‑development targets across multiple regions.
ThreatCluster[verified]@threatclusterActive Exploitation
StrikeShark actively exploits CVE-2021-26855 in Microsoft Exchange and CVE-2023-32315 in Openfire using SharkLoader and Cobalt Strike, targeting diplomatic and government sectors in Indonesia, Taiwan, and Colombia.
truemorgan[verified]@_truemorganGeneral
The text lists a number of Windows CVE identifiers without providing any additional detail or context.
BT Haberler[verified]@BTHaberlerActive Exploitation
Kaspersky disclosed three APT groups actively exploiting CVE-2019-0708 and CVE-2021-26855 against Russian organizations, deploying backdoors like GhostContainer and Bird Agent alongside RATs such as Gorilla RAT and Monkey malware.
SecureChap[verified]@SecureChapActive Exploitation
The report details multiple threat actor groups actively exploiting CVEs (CVE-2020-0688, CVE-2019-0708, CVE-2021-26855) to deploy malware, maintain persistence, and move laterally, citing specific tools and techniques but no patches or mitigations.
Echelongraph Team[verified]@echelongraphActive Exploitation
The post describes a multi‑group campaign exploiting the unpatched ProxyLogon vulnerability on Exchange servers, underscoring current active attacks and emphasizing the need for visibility before patching.
David@davidsheyiActive Exploitation
APT41 is actively exploiting CVE‑2021‑26855 against Exchange servers, so users should apply patches and monitor traffic.