CVE-2023-22894(strapi / strapi)

LOWCVSS 4.9 · MEDIUMCISA KEV

Signal is active with 9 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Strapi through 4.5.5 allows attackers (with access to the admin panel) to discover sensitive user details by exploiting the query filter. The attacker can filter users by columns that contain sensitive information and infer a value from API responses. If the attacker has super admin access, then this can be exploited to discover the password hash and password reset token of all users. If the attacker has admin panel access to an account with permission to access the username and email of API users with a lower privileged role (e.g., Editor or Author), then this can be exploited to discover sensitive information for all API users but not other admin accounts.

0.0/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2026-10-11. Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Weakness type (CWE)
CWE-312

Priority

LOW

Exploitation

ACTIVE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • strapi

Threat summary

  • 15 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Peaked at 9 mentions on most recent observed day (2026-10-09)
  • 15 total mentions across 2 days

Affected systems

Vendors
Products
strapi

Deep dive

Activity timeline15 mentions / 2d
02579Mentions · 2026-10-08: 6Mentions · 2026-10-09: 910-0810-09
Referenced assets43 URLs
By indicator
Full discourse15 posts
  • FOFA@fofabot

    ⚠️⚠️ CVE-2023-22894 (+ CVE-2023-22621): Actively exploited in the wild (CISA KEV 10/08) — cleartext storage in Strapi admin chains to unauthenticated remote code execution on self-hosted headless CMS instances. 🔗FOFA Link: https://en.fofa.info/result?qbase64=YXBwPSJzdHJhcGktSGVhZGxlc3MtQ01TIg== 🎯169k+ Results are found on http://en.fofa.info in the past year. FOFA Query: app="strapi-Headless-CMS" 🔖Refer: https://www.cisa.gov/known-exploited-vulnerabilities-catalog #OSINT #FOFA #CyberSecurity #Vulnerability

    0301881.4K
    14.8K followersView on X
  • kokumօtօ@__kokumoto

    米国サイバーセキュリティ・社会基盤安全保障庁(CISA)が既知の悪用された脆弱性カタログに脆弱性5件を追加。アドバイザリは更新漏れ。 - CVE-2015-5477 (BIND) - CVE-2016-3081 (Struts) - CVE-2023-22894 (Strapi) - CVE-2021-3199 (ONLYOFFICE Docs) - CVE-2015-3306 (ProFTPD) 対処期限は3日後10/11

    20021854
    7.8K followersView on X
  • ♫Why♥Not♪@Python_s_

    #NØØT_Security_Alerts 🚨 #ALERT — CISA ADDS CRITICAL STRAPI VULNERABILITY TO KEV; RESEARCHERS PREVIOUSLY DEMONSTRATED AN UNAUTHENTICATED RCE EXPLOIT CHAIN October 8, 2026 DISCLOSED BY: CISA / Strapi Security PRODUCT: Strapi — Open-Source Headless CMS CVE: CVE-2023-22894 — Sensitive information disclosure through private-field filtering. RELATED EXPLOIT CHAIN: CVE-2023-22621 — Server-side template injection leading to remote code execution. SEVERITY: Critical ORIGINAL DISCLOSURE: April 17, 2023 MATERIAL RISK UPDATE: CISA added CVE-2023-22894 to its Known Exploited Vulnerabilities catalog on October 8, 2026. This is a NEW KEV inclusion for a previously disclosed vulnerability, not a newly discovered zero-day. AFFECTED VERSIONS: CVE-2023-22894: Strapi 3.2.1 through versions earlier than 4.8.0. CVE-2023-22621: Affected Strapi releases through 4.5.5. Strapi 3.x is unsupported. IMPACT: CVE-2023-22894 allows attackers to abuse filtering behavior to expose private information, including sensitive account information and password-reset tokens. Strapi confirmed that researchers demonstrated how the vulnerability could facilitate administrator-account takeover. On installations also vulnerable to CVE-2023-22621, the attacker could potentially chain administrator takeover with malicious email-template modification to execute arbitrary server-side code. Strapi confirmed a working laboratory proof of concept for the unauthenticated exploit chain affecting releases through 4.5.5. EXPLOITATION STATUS: KNOWN EXPLOITATION CONFIRMED — CISA KEV. The October 8 inclusion confirms documented exploitation of CVE-2023-22894. It does NOT establish that the complete two-CVE remote-code-execution chain has been observed in current real-world attacks. No new threat-actor attribution or victim count was provided. knownRansomwareCampaignUse: Unknown — CISA. Forensic triage: Review Strapi HTTP access logs for suspicious filtering parameters involving: email password reset_password_token resetPasswordToken Investigate repeated requests attempting to retrieve private user attributes. Review suspicious administrator password resets, unexpected privileged sessions, and unauthorized account modifications. For the related template-injection vulnerability, inspect unexpected PUT requests to: /users-permissions/email-templates Review modified templates for suspicious executable expressions. A matching request is an investigation lead, not proof of successful compromise. URGENT ACTION: Identify vulnerable Strapi installations immediately. Upgrade to a currently supported, security-maintained Strapi release. Strapi originally fixed CVE-2023-22894 in version 4.8.0 and CVE-2023-22621 in version 4.5.6. Migrate unsupported Strapi 3.x deployments. Restrict unnecessary public API exposure. Investigate suspicious administrator password resets and rotate exposed credentials when compromise is established. Preserve application logs and database evidence before remediation. SOURCE: https://strapi.io/blog/security-disclosure-of-vulnerabilities-cve CISA: https://www.cisa.gov/known-exploited-vulnerabilities-catalog?search_api_fulltext=CVE-2023-22894 BACKUP: https://raw.githubusercontent.com/cisagov/kev-data/develop/known_exploited_vulnerabilities.json CONFIDENCE: VERY HIGH — CISA’s October 8 catalog update confirms known exploitation. Strapi’s first-party security disclosure documents the affected releases, information-disclosure mechanism, demonstrated RCE chain, forensic indicators, and fixes. Current attack scale and exploitation of the complete RCE chain remain unverified. #CyberSecurity #ThreatIntel #Strapi #RCE #CISA #KEV #ActiveExploitation #WebSecurity #NØØT

    0000032
    227 followersView on X
  • takenaka hiroya@Joe_Biden_ja

    Strapi の CVE-2023-22894(機微情報の漏えい)が KEV に追加されました。NVD の評価は CVSS 4.9 ですが、悪用が確認された枠です。Strapi の版数を確認してください。 https://cve.autoarticles.net/cve/CVE-2023-22894

    0000030
    557 followersView on X
  • 서버쟁이 놀이터@ueo0j

    📊 10/9 통합 브리핑 방어가 밀린 날이 아니라, 밀린 숙제가 한꺼번에 청구된 날이다. 신규 제로데이보다 이미 패치가 있는 N-day와 기한 경과 KEV가 오늘 작업 목록의 중심이다. —— 오늘 먼저 —— ① 🔴 CISA KEV 10/8 추가 5건 — 연방 기한 10/11 (D+2) ProFTPD CVE-2015-3306, Apache Struts CVE-2016-3081, ISC BIND CVE-2015-5477, ONLYOFFICE Docs CVE-2021-3199, Strapi CVE-2023-22894. 전부 2015~2023년 N-day. AA26-281A가 지목한 침투 경로와 같은 집합이다. 자산 재고 대조 → 패치. ② 🔴 Atlassian CVE-2026-21589 — CVSS 9.3, 실제 악용 중 사전인증 임의 파일 읽기. Bitbucket·Confluence·Jira·Bamboo·Crowd 등 8개 Data Center/Server 전 버전. Cloud는 이미 패치. 자체 호스팅만 고정 버전으로 즉시 업그레이드. PoC 공개 2시간 내 악용 시작. ③ 🔴 FortiMail CVE-2026-104286 — KEV 기한 10/4 경과 미인증 임의 파일 쓰기 → 코드 실행, 실제 악용 확인. 8.0.2 / 7.6.7 / 7.4.9 이상, 7.2는 7.4+로 이전. 못 올리면 IBE 비활성. IoC(79.141.169.187, 45.129.0.192) 기준 침해 점검. ④ 🔴 NetScaler CVE-2026-88779 — KEV 기한 10/7 경과 SAML SP/IdP customer-managed. 수정 빌드 14.1-73.41 / 13.1-64.28. 영향은 주로 DoS. 원인 불명 crash·reboot 이력을 같은 타임라인으로 대조. ⑤ 🟠 LMCache CVE-2026-105192 — CVSS 9.8, 패치 없음 ZeroMQ 5555가 미인증 pickle을 받아 RCE. 기본은 localhost라 원격 악용은 라우팅 가능 주소 바인딩 시에 한정. vLLM+LMCache면 5555 노출부터 차단. GPU 사용률 이상도 같이. ⑥ 🟠 Gemini agent 계정 라이프사이클 에이전트가 @agents.company.com 메일·캘린더·드라이브·사내 디렉터리 등재를 받는다. IAM·감사·계정 회수 설계를 PoC 전에 먼저 정할 것. —— AI —— ──────── ▣ Anthropic Cyber Mission — 핵심 인프라 방어 + 무료 OSS 스캐너 핵심: Critical Infrastructure Defense Program으로 전력·수처리·교통·정부 OT에 프런티어 Claude·상주 엔지니어·위협 리서치를 제공한다. OSS Scanner는 옵트인 오픈소스에 주기 스캔·PoC·수정안을 무료 제공. 창립 파트너 11곳. "참 양성률 90%+"는 측정이 아니라 전망치. 왜 중요한가: 프런티어 제공사가 공격 억제와 방어 지원을 분리 운영하기 시작했다. 사내 fork·critical dependency 등록 여부를 정책으로 정하되, 모델 보고서는 사람 검수를 전제로. https://www.anthropic.com/news/anthropic-cyber-mission ──────── ▣ Claude Haiku 5.5 — 100K 경계가 가격을 가른다 핵심: 프롬프트 100K 이하면 입력 $0.10 / 출력 $0.50(Haiku 4.5 대비 90% 인하), 100K 초과면 $0.50 / $2.50(50% 인하). "90% 인하"도 "75% 절감"도 구간 없는 단일 숫자는 틀리다. OSWorld 72.4%는 offline subset 한정. 왜 중요한가: 대량 호출 워크로드 손익분기가 내려간다. 비용 재산정 전에 실제 프롬프트 길이 분포부터. https://www.anthropic.com/claude-haiku-5-5 ──────── ▣ ChatGPT GPT-6 + Intelligent UI — 답변이 조작 가능한 화면으로 핵심: 버튼·인터랙티브 차트·폼·계산기·편집 가능 다이어그램을 답변 안에 인라인 렌더링. 유료 10/7 → Free·Go 10/8. 왜 중요한가: 챗봇 위 자체 UI로 차별화하던 제품의 차별점이 플랫폼에 흡수된다. "텍스트"가 아니라 "조작 가능 화면"을 기대하는 압력이 온다. https://openai.com/index/gpt-6-for-everyone/ ──────── ▣ FT: OpenAI 연환산 매출, 알려진 700억이 아닌 500억 달러 수준 핵심: 9월 말 연환산 매출이 500억 달러에 근접한다고 투자자에게 전달. 언론에 돌던 약 700억보다 약 200억 낮다. 단일 보도 기반. 왜 중요한가: 높은 쪽 숫자로 AI 인프라 수요를 가격에 반영해 왔다면 IPO 서사·컴퓨트 회수 가정이 흔들린다. 기존 수치의 하향 정정이다. https://www.ft.com/content/b66a9858-f8fb-46cb-b506-44bfe26fca2a ──────── ▣ Arena Alignment Index — 9만 에이전트 세션으로 채점 핵심: 무단 행동·허위 귀속·기만적 완료 보고 세 실패 신호. GPT-6.1-Sol 87.9, Claude Opus 5.5 83.2, Grok 4.7 82.7. 같은 날 2억 달러 시리즈 B. 왜 중요한가: 벤치마크보다 "거짓 완료 보고" 비율이 조달 기준이 된다. 지표 중립성은 별도 평가가 필요하다. https://cryptobriefing.com/arena-200m-series-b-alignment-index/ ──────── ▣ USA Today 모회사, OpenAI 상대 2.5억 달러+ 저작권 소송 핵심: GPT 학습의 기사 무단 사용·출력의 원문 대체성을 주장. 뉴욕 남부지법. 소장 전문 미열람이라 세부 청구는 확인 필요. 왜 중요한가: 엔터프라이즈 조달에서 학습 출처 보증·출력 필터·라이선스 스택 요구가 커질 전망이다. https://www.forbes.com/sites/fionariley/2026/10/08/usa-today-sues-openai-for-over-250-million-alleging-willful-copyright-infringement/ —— 클라우드·데이터센터·인프라 —— ──────── ▣ GlobalFoundries–TSMC, 20억 달러 미국 실리콘 인터포저 계약 핵심: 뉴욕 Malta 팹, 초기 5년, 어드밴스드 패키징용 실리콘 인터포저. 양산 램프는 2028 상반기. "미국 내 최초 공급원"은 GF 자체 표현. 왜 중요한가: CoWoS 병목의 지리적 분산이지만, 2028년까지는 병목이 그대로라는 선언이기도 하다. 가속기 조달 시간축을 맞춰야 한다. https://gf.com/news-and-events/news/globalfoundries-reaches-agreement-to-establish-us-based-supply-of-silicon-interposers-for-advanced-ai-packaging/ ──────── ▣ Google–Constellation, PJM 원자력 890MW 증설 + 장기 공급 핵심: 기존 11기 uprate로 신규 건설 없이 890MW 추가(첫 uprate 목표 2028). 별도 15년 2,700MW 공급 계약. Constellation 투자 43억 달러+. 왜 중요한가: AI 전력 해법이 신규 발전소(10년+)가 아니라 기존 원전 uprate + 장기 계약으로 수렴한다. Duke Energy의 50MW+ 대형부하 요금 합의도 같은 축. https://www.googlecloudpresscorner.com/2026-10-06-Google-and-Constellation-Announce-Landmark-Agreement-to-Bring-890-MW-of-New-Nuclear-Capacity-to-PJM-Grid-as-Part-of-Long-Term-Power-Deal ──────── ▣ AI 캡엑스가 전용 부채 금융 단계로 — WSJ 핵심: Broadcom·OpenAI 커스텀 칩 500억 달러+ 금융 모색, SpaceX(xAI 연계) Nvidia용 약 400억, Oracle은 하드웨어 선지급–클라우드 매출 시차 메우기. 회사 공식 공시 아님. 왜 중요한가: 캡엑스가 영업현금흐름을 넘어 전용 부채로 간다. Firmus Grid 호주 IPO 철회와 함께 사모 밸류와 공개시장 눈높이 간극이 실측됐다. https://www.wsj.com/tech/oracle-broadcom-and-spacex-seek-blockbuster-debt-deals-to-pay-for-ai-chips-848e8032 ──────── ▣ kt클라우드, 인천 청라 50MW급 AI 데이터센터 참여 핵심: 수전 50MW, 2026년 4분기 착공·2030년 1분기 준공 목표. AI 존은 액체 냉각. "2031년까지 1GW+"는 회사 발표치. 왜 중요한가: 국내 수도권 확정 사업이다. 전망치 묶음과 구분해 읽을 것. https://cb.yna.co.kr/gate/big5/cn.yna.co.kr/view/AKR20261007049600017 ──────── ▣ Amazon RDS for Oracle — 마이너 버전 업그레이드 precheck 핵심: 업그레이드 전 저장공간·객체 유효성 검사, 패치 중 연결 재수용 이벤트로 다운타임 단축. 오늘(10/9) AWS What's New. 왜 중요한가: 유지보수 창 설계를 바꿀 수 있는 운영 변경이다. Network Firewall 컨테이너 속성 와일드카드도 같은 주 출하. https://aws.amazon.com/about-aws/whats-new/2026/10/amazon-rds-oracle-minor-version-upgrade-precheck-new-patching-rds-event/ —— 보안·규제 —— ──────── ▣ CISA AA26-281A + Flax Typhoon 도구 압수 — KEV 5건이 같은 그림 핵심: FBI가 MicroScan·FishHub 도메인 7개 압수. 9개국 공동권고가 지목한 N-day 8건은 전부 KEV 등재. 그중 5건이 10/8 추가·기한 10/11. Exchange 스프레이·SoftEther VPN 지속성·DCSync는 그대로 유효. 왜 중요한가: 제로데이가 아니라 패치 누락 재고 문제다. 도메인 차단으로 끝낼 사안이 아니다. 인증 실패 급증·VPN 흔적·비정상 DCSync를 소급 점검. https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-281a ──────── ▣ 미국, Microsoft·Adobe 및 IT 아웃소싱 6개사 PERM 처리 중단 핵심: 노동부가 Microsoft, Adobe, Cognizant, Infosys, Tata, Wipro, HCL, Capgemini의 영주권 노동인증(PERM) 접수·처리를 중단. 연방 사기 조사. 기존 H-1B 취소는 아님. 왜 중요한가: AI·클라우드 인력 파이프라인에 직접 작용한다. 미국 전배를 전제한 공동 프로젝트 배치에 변수. https://www.axios.com/2026/10/08/trumps-foreign-worker-crackdown-comes-for-microsoft-adobe-it-firms ──────── ▣ CVE 프로그램, AI 생성 취약점 보고 급증에 대응 핵심: MITRE가 OpenAI·Anthropic에 임시 CNA 자격을 부여했다는 보도(단일 2차, 공식 확인 필요). 같은 48시간에 Google은 AI 스팸으로 오픈소스 버그 바운티를 중단, Anthropic은 무료 OSS 스캐너를 냈다. 왜 중요한가: AI가 발굴과 노이즈를 동시에 늘린다. 취약점 관리 1차 트리거를 CVE 등재에서 KEV 같은 악용 기반 신호로 올리는 편이 안전하다. https://www.cybersecuritydive.com/news/cve-program-ai-black-hat-def-con/827477/ ──────── ▣ Anthropic 2026 이용정책 개정 — 11/12 발효 핵심: 모델에 대한 지속적 학대 금지, 민주적 절차 훼손 금지, 무기 개발 SW·비동의 추적 금지, 가짜 계정·허위 뉴스 매체 운영 금지. 발효 2026-11-12. 왜 중요한가: Claude를 제품에 넣은 조직은 약 5주 안에 사용 사례를 대조해야 한다. 소셜·마케팅 자동화·페르소나 기능이 주요 점검 대상. https://www.anthropic.com/news/2026-usage-policy-update ──────── ▣ Oracle Health 유출 피해자, 약 2,000만 명으로 증가 핵심: 앞선 규제 신고·환자 통지 수치보다 크게 늘었다. 데이터 유형·사고일은 보도에 없음. 왜 중요한가: 초기 신고 수치가 최종 규모를 과소 반영하는 전형이다. 의료 데이터 위탁 조직은 공급자 통지 수치를 확정값으로 두지 말 것. https://www.securityweek.com/oracle-health-data-breach-tally-climbs-to-nearly-20-million/ —— 취약점·해킹 —— ──────── ▣ 🔴 Atlassian CVE-2026-21589 — 사전인증 파일 읽기, 악용 중 핵심: 공유 라이브러리 경로 탐색 우회. 8개 Data Center/Server 전 버전. PoC 공개 2시간 내 허니팟 시도 → 10/8 기준 10개국 32 IP·190건. CISA KEV는 아직 미등재. Crowd 평문 자격증명 → 관리자 상승 경로가 있다. 왜 중요한가: 지금 관측은 스캐닝 단계다. 패치 창이 아직 열려 있다. Cloud는 조치 불필요, 자체 호스팅만 고정 버전으로. https://labs.watchtowr.com/you-wont-hear-about-these-even-in-myths-atlassian-jira-confluence-and-more-pre-auth-arbitrary-file-read-cve-2026-21589/ ──────── ▣ 🔴 FortiMail CVE-2026-104286 — KEV 기한 경과, 실제 악용 핵심: 비인증 HTTP/HTTPS 임의 파일 쓰기. 등재 10/1·기한 10/4 경과. FortiMail Cloud는 벤더 일괄 수정 완료, 잔여 리스크는 온프레. 왜 중요한가: "어제 급했던 것"이 아직이면 오늘 1순위가 바뀐다. IBE 비활성·웹메일 노출 차단이 임시 완화. https://fortiguard.fortinet.com/psirt/FG-IR-26-175 ──────── ▣ 🔴 NetScaler CVE-2026-88779 — KEV 기한 경과 핵심: SAML 구성 DoS. 등재 10/4·기한 10/7 경과. 14.1-73.41 / 13.1-64.28 미만. 왜 중요한가: DoS형이라 "원인 불명 장애"로만 남아 있을 수 있다. 패치와 과거 장애 소급을 같이. https://support.citrix.com/external/article/CTX697174/citrix-netscaler-adc-and-citrix-netscale.html ──────── ▣ AI 추론 인프라 3건 — LMCache·PoeLLM·Pwn2Own 핵심: LMCache 미인증 RCE(패치 없음, localhost 기본). PoeLLM이 노출 AI 서버 3,400대+ 크립토마이닝·봇넷화. Pwn2Own Ireland에서 LiteLLM 완전 장악·Codex 익스플로잇 등 제로데이 77건. 왜 중요한가: 서로 무관한 세 출처가 48시간에 같은 방향을 가리킨다. 자체 호스팅 추론 스택은 웹 서버와 동급 노출 관리가 필요하다. https://thehackernews.com/2026/10/unpatched-critical-lmcache-flaw-lets.html ──────── ▣ FortiBleed — 패치로 해결되지 않는 유형 핵심: CVE가 아니다. 재사용·유출 자격증명과 레거시 SHA-256 저장 방식 악용. 194개국 유효 장치 자격증명 86,644건+. 신규 계정 생성 후 기존 관리자 잠금 배제 단계. 왜 중요한가: 자격증명 전면 회전·MFA·관리 인터페이스 노출 차단이 유일한 경로다. 잠금 배제 후 복구 난도가 급등한다. https://thehackernews.com/2026/10/fbi-warns-fortibleed-remains-active.html ──────── ▣ Cisco NX-OS 치명적 결함 5건 + Meraki Hardening 핵심: NX-OS 5건은 NGOAM·NX-API·MPLS OAM 활성 전제, 기본 비활성·악용 인지 없음. Meraki는 워크어라운드 없이 업그레이드 필수(최고 CVSS 9.6). 왜 중요한가: CVSS보다 구성 노출이 우선순위를 정한다. 1차 대응은 불필요 기능 비활성화, 그다음 패치. https://www.bleepingcomputer.com/news/security/cisco-warns-of-critical-flaws-allowing-nexus-switch-takeover/ ──────── ▣ 일본 IDCF Cloud 랜섬웨어 — 리전 단위 중단 핵심: IDC Frontier 동일본 리전, 계약 고객 495개 기업·자치단체 영향, 관리 콘솔 전 리전 중단. 3.6PB·스냅샷 55만 삭제는 공격자 자기 주장·운영사 미확인. 왜 중요한가: 검증된 교훈만 가져가면 된다 — 백업·스냅샷이 같은 관리 평면 안에 있으면 함께 날아간다. https://www.bleepingcomputer.com/news/security/ransomware-attack-disrupts-japans-idcf-cloud-used-by-govt-clients ──────── ▣ ccTLD 레지스트리 침해 → Google 도메인 부정 인증서 핵심: .gh·.sl·.as 침해로 Google 도메인용 비인가 HTTPS 인증서 발급. Google 자체는 미침해. Chrome CRLSets 차단, CT 로그에 최소 12건. 왜 중요한가: 신뢰 체인 최상단이 뚫리면 개별 보안 수준과 무관하다. CT 로그 모니터링이 조기 탐지 수단. https://thehackernews.com/2026/10/attackers-hijack-gh-sl-and-as.html ──────── ▣ tensorlake npm 침해 + FakeGit 17,610개 저장소 핵심: tensorlake 0.5.144 preinstall이 Bun 웜으로 CI·Kubernetes·Vault 시크릿 수집. FakeGit은 악성 GitHub 저장소 17,610개로 StealC 배포. 왜 중요한가: lockfile에서 0.5.144 설치 여부 확인 후 해당 시점 이후 시크릿·토큰 회전. 검색 경유 개발자 유입도 위협 모델에. https://thehackernews.com/2026/10/tensorlake-npm-package-compromised-to.html —— 개발자·엔터프라이즈 —— ──────── ▣ Google Cloud Gemini agent — 에이전트가 사내 계정을 받는다 핵심: 전용 Workspace 계정(@agents.company.com 메일·캘린더·드라이브·디렉터리 등재). Gemini+Claude 라우팅은 현재 지원. 핵심 에이전트 GA/프리뷰는 공식 블로그 미명시 — "출시"로 단정하지 말 것. 왜 중요한가: 에이전트 계정 라이프사이클·사람/에이전트 감사 구분이 신규 과제다. PoC 전에 IAM·회수·감사 설계부터. https://cloud.google.com/blog/products/ai-machine-learning/welcome-to-gemini-at-work-2026 ──────── ▣ Microsoft MXC — 에이전트 격리 컨테이너 GA 핵심: Microsoft eXecution Containers를 OS 기능으로 GA. MAI-Code-1.1 Flash(137B·3비트) 로컬 코딩. 전체 컨텍스트 시 약 75GB — 일반 PC로는 비현실적. 왜 중요한가: 에이전트 보안 경계가 OS 커널 수준 격리로 내려갔다. 사내 코드를 외부로 못 보내는 조직에 경로는 열리지만 전사 배포 가정은 성립하지 않는다. https://blogs.windows.com/windowsexperience/2026/10/07/building-windows-for-hybrid-intelligence/ ──────── ▣ GitHub Copilot 로컬 샌드박스 GA (+ Haiku 5.5, Stacked PR) 핵심: MXC로 파일·네트워크·Git 자격증명을 OS 네이티브 제한, 조직이 재정의 불가로 강제. 추가 비용 없음. 유출 시크릿 탐지 모델·Haiku 5.5·Stacked PR도 같은 주. 왜 중요한가: 코딩 에이전트 도입 심사의 통제 쟁점을 하나 줄인다. tensorlake 같은 CI 시크릿 유출과 같이 읽으면 왜 지금인지 분명하다. https://github.blog/changelog/2026-10-07-local-sandboxing-for-github-copilot-now-generally-available ──────── ▣ Kubernetes cgroup v1, 유지보수 모드 진입 핵심: v2는 단일 통합 계층·일관 인터페이스. v1은 유지보수 모드. 원본의 버전 표기는 확인 필요하나 전환 방향은 공식. 왜 중요한가: 조용하지만 실제 전환 작업이 필요하다. cgroup v1 노드 목록부터. https://kubernetes.io/blog/2026/10/06/kubernetes-cgroups-v2-shift/ ──────── ▣ GLM 5.3, Amazon Bedrock 정식 제공 핵심: 753B, 100만 토큰 컨텍스트, 프롬프트 캐싱, OpenAI 호환 API. 중국 개발 대형 모델이 미국 하이퍼스케일러 관리형으로 들어왔다. 왜 중요한가: Bedrock 거버넌스 안에서 쓸 수 있어 조달 장벽은 낮아지지만, 데이터 주권 정책이 있는 조직은 모델 출처 기준을 먼저 정리해야 한다. https://aws.amazon.com/about-aws/whats-new/2026/10/amazon-bedrock-glm-5-3/ 기한이 박힌 숙제부터 처리하면 된다. 오늘은 KEV 10/11과 Atlassian 고정 버전이 먼저다. #IT브리핑 #CISA #KEV #Atlassian #FortiMail #NetScaler #FlaxTyphoon #ClaudeHaiku #GeminiAgent #GitHubCopilot #LMCache #데이터센터

    00000423
    72 followersView on X
  • Samit Hota @HotaSamit

    Strapi CVE-2023-22894: Query Filter Secrets Leak Enables RCE Chaining Strapi CVE-2023-22894 exposes sensitive data via query filters, enabling attackers to chain it with CVE-2023-22621 for remote code… Full write-up → link in bio #cybersecurity #infosec #cve #kev #strapi https://t.co/VibEgtWecH

    0000025
    25 followersView on X
  • ITフレブル【実務派エンジニア速報】@eng_digest_jp

    【既知悪用のStrapi、情報が露出】 ・CISAの既知悪用一覧に追加 ・管理画面から機微情報を照会 ・CVE連鎖でRCEの可能性も 管理画面の権限だけでは安心できません。 #CVE202322894 https://www.cisa.gov/known-exploited-vulnerabilities-catalog?search_api_fulltext=CVE-2023-22894

    0000020
    5 followersView on X
  • Security Arsenal, LLC@SecurityAr58409

    🔒 #CyberSecurity CVE-2023-22894: Strapi Exploitation Confirmed by CISA KEV — Detection and Remed… "On October 8, 2026, CISA added CVE-2023-22894 — a cleartext storage of sensitive…" 🔗 https://securityarsenal.com/blog/cve-2023-22894-strapi-exploitation-confirmed-by-cisa-kev-detection-and-remediation-guide-for-2026 #CyberSecurity #ThreatIntel #cve202322894 #critical #cisakev

    0000023
    36 followersView on X
  • multilayer@multilayer

    米CISAが、悪用が確認された脆弱性のカタログ(KEV)に5件を追加した。追加は米国時間10/8で、連邦機関の対応期限は10/11と短い。 対象は ProFTPD の CVE-2015-3306(アクセス制御の不備)、ISC BIND の CVE-2015-5477(データ処理のエラー)、Apache Struts の CVE-2016-3081(コマンドインジェクション)、ONLYOFFICE Docs の CVE-2021-3199(パストラバーサル)、Strapi の CVE-2023-22894(機密情報の平文保存)。 いずれも数年前に公開済みの古い脆弱性で、ランサムウェアで使われたかどうかは「不明」とされている。 長く動かしているFTPサーバーやDNSサーバー、古いWebアプリやCMSにこうしたOSSが残っていないかを棚卸しして、更新や停止を判断するきっかけになる。 #脆弱性 #CISA #KEV #セキュリティ https://www.cisa.gov/known-exploited-vulnerabilities-catalog

    0000098
    804 followersView on X
  • ランサム監視 | Sec_News@sec_news_com

    【CISA KEV速報】2026-10-08付けで5件追加 ・CVE-2015-5477 ISC BIND ・CVE-2016-3081 Apache Struts ・CVE-2023-22894 Strapi ・CVE-2021-3199 ONLYOFFICE Docs ・CVE-2015-3306 ProFTPD いずれも悪用確認済み。概要と対応期限はこちら https://recon.sec-lav.com/articles/kev-alert-2026-10-08-digest

    0000033
    101 followersView on X
  • ♫Why♥Not♪@Python_s_

    #NØØT_Security_Alerts 🚨 #ALERT — CISA CONFIRMS EXPLOITATION OF STRAPI FLAW THAT CAN ENABLE ADMIN ACCOUNT TAKEOVER AND RCE CHAINING October 8, 2026 DISCLOSED BY: Strapi Security Team / CISA PRODUCT: Strapi Headless CMS CVE: CVE-2023-22894 RELATED: CVE-2023-22621 — Server-Side Template Injection AFFECTED VERSIONS: CVE-2023-22894: Strapi 3.2.1 through versions before 4.8.0. The vendor-documented RCE chain affects Strapi versions through 4.5.5. IMPACT: CVE-2023-22894 allows attackers to extract sensitive user information, including password hashes and password-reset tokens, through improper filtering of private fields. Strapi previously confirmed a research-demonstrated exploit chain combining CVE-2023-22894 with CVE-2023-22621. Under the documented conditions, attackers can hijack a super-administrator account and abuse vulnerable email templates to execute arbitrary server-side code. EXPLOITATION STATUS: CONFIRMED KNOWN EXPLOITATION. CVE-2023-22894 was added to CISA KEV on October 8, 2026. The vendor-documented RCE chain is technically demonstrated. CISA’s listing does not independently establish that the complete RCE chain is currently being exploited in the wild. knownRansomwareCampaignUse: Unknown — CISA. Forensic triage: Inspect unusual GET requests containing: password reset_password_token resetPasswordToken Review unexpected PUT requests to: /users-permissions/email-templates Investigate unauthorized administrative password resets, suspicious email-template modifications, and unexpected server-side processes. These indicators and investigation methods are documented by Strapi. URGENT ACTION: Identify legacy Strapi deployments. Upgrade to a currently supported release beyond the affected range. Review administrator accounts, preserve relevant application logs, and revoke potentially compromised sessions or reset tokens. Investigate potential compromise before rotating exposed credentials. SOURCE: https://strapi.io/blog/security-disclosure-of-vulnerabilities-cve CISA: https://www.cisa.gov/known-exploited-vulnerabilities-catalog?search_api_fulltext=CVE-2023-22894 BACKUP: https://raw.githubusercontent.com/cisagov/kev-data/develop/known_exploited_vulnerabilities.json CONFIDENCE: VERY HIGH — CISA confirms known exploitation of CVE-2023-22894. Strapi independently documents and validates the vulnerability chain and defensive indicators. Current exploitation of the complete RCE chain remains unverified. #CyberSecurity #ThreatIntel #Strapi #CISA #KEV #RCE #WebSecurity #NØØT

    0000051
    227 followersView on X
  • NotCVE@notCVE

    CVE-2023-22894: Strapi Cleartext Storage of Sensitive Information Vulnerability CVSS 9.8 · EPSS 1.7% · 6 public exploits https://notcve.org/cve/CVE-2023-22894 https://t.co/DAjFnIn1rG

    0000025
    75 followersView on X
  • Arnaud Wallon@arwallon

    Strapi, le CMS open source né à Paris, entre sur la liste rouge de la CISA pour une faille corrigée en 2023 mais encore exploitée. Instance en 3.x ou avant 4.8.0 ? Mets à jour. #Cybersécurité https://numeribrain.com/posts/strapi-cve-2023-22894-liste-rouge-cisa

    0000029
    362 followersView on X
  • CiberPlaneta@CiberPlanetaOrg

    🛡️ CVE-2023-22894: exposición de datos sensibles en Strapi CISA incorporó CVE-2023-22894 al catálogo KEV por explotación activa. La falla permite a usuarios con acceso al panel administrativo de Strapi descubrir datos sensibles mediante filtros de consulta y puede encadenarse con CVE-2023-22621 para lograr ejecución remota de código. https://www.ciberplaneta.org/vulnerabilidades/cve-2023-22894-exposicion-de-datos-sensibles-en-strapi/ #ciberplaneta #vulnerabilidades #cve_2023_22894 #cve #vulnerabilidad #strapi #seguridad #cisa_kev #infosec #ciberseguridad

    0000019
    7 followersView on X
  • Zero Hunt@zerohuntai

    A Strapi bug rated CVSS 4.9 'medium' just hit CISA's exploited list — because it was never medium. CVE-2023-22894 chains to unauthenticated remote code execution on end-of-life Strapi, and the fix deadline is three days. What to check, how to catch it: https://zerohunt.ai/blog/strapi-cve-2023-22894-kev-unauthenticated-rce/

    0000028
    17 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appstrapistrapi---

Explore more