CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog based on evidence of active exploitation: CVE-2024-1708 (ConnectWise ScreenConnect Path Traversal) and CVE-2026-32202 (Microsoft Windows Protection Mechanism Failure). CISA urges all organizations to prioritize timely remediation of KEV Catalog vulnerabilities as part of their vulnerability management practices, as these represent significant active threats to enterprise security.
30d signal volume
By Threat Layer
Top Signals
View all signals →Cybersecurity researchers have disclosed details of a stealthy Python-based backdoor framework called DEEP#DOOR with capabilities to establish persistent access and harvest sensitive information from compromised hosts. The intrusion chain begins with execution of a batch script that disables Windows security controls and dynamically extracts additional malicious components.