ThreatSynop[verified]@ThreatSynopExploit
The post announces that Metasploit 6.4.111 now contains modules enabling unauthenticated remote code execution against FreePBX, Cacti, and SmarterMail by chaining several CVEs. It emphasizes that exploitation is "push‑button," urging swift patching and segmentation.
ThreatSynop[verified]@ThreatSynopExploit
The post announces new Metasploit exploit modules for several CVEs that enable unauthenticated RCE and other attacks, urging immediate validation and patching.
0xdf@0xdf_General
The tweet mentions two CVEs with basic details of RCE and API abuse but provides no PoC, exploit code, active exploitation claim, or patch information.
ٱلطَّيِّبُ | Mustafa El Tayeb@T4T4R1SPoC
The post announces that MonitorsFour is vulnerable and shares a write‑up link that presumably contains a proof‑of‑concept for exploiting CVE‑2025‑24367, but it does not detail active wild exploitation or provide exploit code or a patch.
Sakibul Ali Khan@sakibulalikhanPoC
The tweet announces a Hack The Box machine compromised via an IDOR, a Cacti RCE (CVE-2025-24367), and an unauthenticated Docker API, provides a PoC link, but lacks details on active exploitation or patching.
r0otk3r@r0otk3rPoC
The tweet announces CVE‑2025‑24367, highlights its high severity and RCE vulnerability, and shares a PoC video, but lacks specific exploit code, patch details, or evidence of active exploitation.
Waqar Naeem@codewithpikePoC
The author notes that the Hack The Box challenge employed two CVEs, learned to escape Docker, and used publicly available POCs, but does not describe exploit code or active exploitation.