piyokango[verified]@piyokangoActive Exploitation
CISA added several CVEs to its exploited catalog, confirming that these vulnerabilities are being abused in the wild and that PoCs have been publicly released.
Elusive[verified]@ElusivePrivacyActive Exploitation
CISA identified four vulnerabilities that are actively exploited, listing CVE details and attack vectors such as privilege escalation, path traversal, and command injection, and noting the absence of a patch for an EOL D-Link device.
Lyrie.ai[verified]@lyrie_aiActive Exploitation
CISA confirms the first in‑the‑wild exploitation of four CVEs affecting SimpleHelp and Samsung MagicINFO 9 Server, underscoring active attacks on these products.
Lyrie.ai[verified]@lyrie_aiActive Exploitation
CISA has identified and cataloged four high‑CVSS CVEs as Known Exploited Vulnerabilities, indicating they are actively leveraged in the wild.
Lyrie.ai[verified]@lyrie_aiActive Exploitation
CISA has listed CVE‑2024‑57728 in its Known Exploited Vulnerabilities catalog, indicating that path‑traversal "zip‑slip" attacks on SimpleHelp servers are occurring in the wild.
Lyrie.ai[verified]@lyrie_aiActive Exploitation
CVE‑2024‑57728 is a path‑traversal flaw in SimpleHelp that lets an admin write arbitrary files and execute code. Its inclusion in the CISA KEV list signals that it is considered a high‑risk vulnerability, potentially already exploited in the wild.
Lyrie.ai[verified]@lyrie_aiPatch
CISA mandates remediation of CVE-2024-57728 in SimpleHelp by 2026-05-08, urging vendor fixes or BOD 22‑01 mitigations and highlighting the CVE as a known exploited vulnerability.
Lyrie.ai[verified]@lyrie_aiGeneral
The excerpt provides a concise technical description of CVE‑2024‑57728 as a path‑traversal (zip slip) flaw, but makes no mention of PoC, exploitation, patch, or false positive.