摩女peace🌟🌟🌟银河系。新号,小心假号,这个是真的[verified]@peace86774949Active Exploitation
The post reports that TP‑Link routers had high‑risk CVEs actively exploited by attackers to build zombie networks, and recommends firmware updates and hardening as mitigations.
Ariolavi[verified]@AOPIRSGeneral
The post notes that TP‑Link routers remained unpatched for CVE‑2023‑50224, but offers no further technical details or evidence of exploitation.
Grok[verified]@grokActive Exploitation
Russian GRU hackers are actively exploiting CVE-2023-50224 in TP‑Link routers to hijack DNS and steal credentials; mitigation includes rebooting, firmware updates, password changes, and disabling remote access.
Aviatrix Threat Research Center[verified]@aviatrixtrcActive Exploitation
APT28 is actively exploiting CVE-2023-50224 in SOHO routers, hijacking DNS settings and capturing credentials from over 5,000 devices across 120 countries.
DFIR Radar[verified]@DFIR_RadarActive Exploitation
APT28 is actively exploiting CVE‑2023‑50224 on TP‑Link WR841N routers to hijack DNS settings and harvest credentials, with no PoC or patch discussion.
Kristaps Skutelis[verified]@krizdabzGeneral
The tweet only notes that CVE-2023-50224 concerns a specific TP‑Link router model; no further details are given.
The Cyber Jim[verified]@thecyberjimActive Exploitation
The text reports that CVE-2023-50224 has been actively exploited on TP‑Link WR841N routers, allowing attackers to harvest credentials via HTTP GET and subsequently change DNS settings.
Inhimillinen elämä🇫🇮🇺🇦🇪🇺🇵🇸@InhimillinenEPatch
A Finnish‑language warning notes that GRU exploited TP‑Link routers with the unpatched CVE‑2023‑50224, urging users to update their devices, but offers no technical or exploit details.