Initial Access Intelligence

Weekly Initial Access Release Notes

October 25 - October 31, 2025

Exploits and detections for Microsoft WSUS, FOG Project, Xdebug, and Spring Cloud Netflix Hystrix Dashboard. Fresh signatures for CVEs detected in the wild by VulnCheck canaries, plus a scanner for WatchGuard Fireware OS RCE.

October 18 - October 24, 2025

New exploits and detections for Gladinet CentreStack, IBM Operational Decision Manager, VICIdial, China Mobile Intelligent Home Gateways, JeecgBoot, and NETGEAR routers. Signatures for Windows Server Update Services.

October 11 - October 17, 2025

New exploits and detections for Tenda AC15 AC1900 devices, Flowise, and LG Simple Editor. New version scanner and queries for F5 BIG-IP. New Redis signatures.

October 4 - October 10, 2025

Signatures for Cisco ASA and FTD. New exploits and detections for Oracle E-Business Suite, Dell UnityVSA, and LG Simple Editor.

September 27 - October 3, 2025

Offline scanning support for Censys Platform data. GoAnywhere MFT signatures and queries. New exploits (and more) for Cisco ASDM, Kerio Control, FortiSIEM, and GL.iNet routers.

September 20 - September 26, 2025

Queries for new Cisco ASA and Cisco IOS / IOS XE vulnerabilities. New exploits for Cisco Smart Licensing Utility, Flowise AI, and FortiSIEM.

September 13 - September 19, 2025

Exploit and detection coverage for FreePBX, FortiSIEM, ARC Solo, and Django

September 6 - September 12, 2025

New exploits, queries, and detections for N-Central, Docker Desktop, the FOG Project, and XWiki

August 30 - September 5, 2025

New exploits and detections for N-able N-Central, LibreNMS, BentoML, and Shenzhen Aitemi M300 devices.

August 23 - August 29, 2025

Three auth bypasses walk into a bar: New exploits and signatures on tap for CrushFTP, Commvault, FortiWeb, Tenda AC20 routers, and WordPress.

August 16 - August 22, 2025

New exploits and detections for FortiSIEM, SharePoint, SUSE Manager, Web-Check, and CHCNAV P5E GNSS. New support for legacy Censys queries.

August 9 - August 15, 2025

New exploits and detections for WinRAR, ScriptCase, ICTBroadcast, and GeoServer. New signature coverage for Pulse Secure.

August 2 - August 8, 2025

NTLM PrivEsc, AI Framework RCE, ScriptCase Bug Chain Part 1, Lighthouse Studio RCE, and XWiki Leaves Us Disappointed

July 26 - August 1, 2025

ToolShell and Cisco ISE Updates, New Jenkins and WordPress Plugin Coverage, SQL Server Deserialization, Customer-Requested Signatures, and Expanded Attacker Infrastructure Tracking

July 19 - July 25, 2025

Fresh SharePoint & Delta Coverage, Hikvision Gets a Twist, CrushFTP in Progress

July 12 - July 18, 2025

From FortiWeb to Exchange: New Exploits and Detections

June 28 - July 11, 2025

Citrix, Cisco, SonicWall, Sitecore, Wing FTP, Sante PACS, CWP: We Hit Them All

June 21 - June 27, 2025

We’re Gonna Need Pagination for This Changelog

June 14 - June 20, 2025

Shells Across the Stack: Windows, vBulletin, and RoundCube

June 7 - June 13, 2025

Invision, Infoblox, and vBulletin Walk Into a Changelog

May 31 - June 6, 2025

Cisco Rooted, DrayTek Injected, Flowise Twisted, Samsung Popped, and Veeam Remoted

May 24 - May 30, 2025

Langflow RCEs, BioTime Raises Eyebrows, VMware Lingers, and Customer Requests Spanning More Than a Decade

May 17 - May 23, 2025

Carpe Diem: Seizing the XXEs, RCEs, and Fresh Signatures

May 10 - May 16, 2025

This Week’s Exploit and Detections Menu: GeoVision, SysAid, FUXA, and Arcserve

May 3 - May 9, 2025

SonicWall SonicBoom, Magnus Billing, Casbin Casdoor, WinZip Local with Sigma, and go-exploit 1.43 Oh My!

April 26 - May 2, 2025

New week, new exploits and detections: NetScaler, Commvault, FoxCMS, Craft CMS, and SAP.

April 19 - April 25, 2025

Content for Erlang SSH, Apache Parquet, Polkit, and a Windows Vulnerability Exploited in the Wild

April 12 - April 18, 2025

A content *bomb* including coverage for Fortinet, Ivanti, GLPI, and Netgear products. A new go-exploit release and SpiceRAT tracking

April 5 - April 11, 2025

RCE in Apache Camel, AppSmith, and MajorDoMo. Credential leaks in GLPI.

Mar 29 - April 4, 2025

CrushFTP RCE, Vite & Splunk Information Leaks, and Additional Coverage for Wordpress Plugin Exploited In the Wild

Mar 22 - Mar 28, 2025

Infosec hyped vulnerabilities: IngressNightmare and Next.js Authentication Bypass. An erroneous CISA ICS Advisory. ManageEngine and Netatalk exploits and more!

Mar 17 - Mar 21, 2025

Buffer Overflow for Netatalk, VMware vCenter Server OVA Upload, Apache Tomcat Java Deserialization RCE, and continued development of Sitecore exploits.

Mar 08 - Mar 14, 2025

Exploits for SiteCore, SolarView, and ThinVNC. New Scanners for Sophos UTM. A new go-exploit release and an IP-Intel update.

Mar 3 - Mar 7, 2025

Delivered exploits and coverage for NAKIVO Backup & Replication information disclosure, MITRE Caldera RCE, Wazuh authenticated RCE, and updated D-Tale exploits to support variants.

Feb 22 - Feb 28, 2025

New Initial Access Intelligence coverage developed for Xwiki, Cisco RV-Series, D-Tale, and BeyondTrust. New IP-Intel coverage for BeyondTrust Remote Support honeypots.

Feb 15 - Feb 21, 2025

Major security updates including PAN-OS auth bypass, SonicWall VPN auth bypass, and CyberPanel RCE exploits with comprehensive detection coverage.

Feb 08 - Feb 14, 2025

Integration of VulnCheck with OpenCTI platform completed. New exploits for Vinchin Backup, Chamilo file upload, and mySCADA PRO vulnerabilities.

Feb 01 - Feb 07, 2025

Key developments include exploits for RudderStack, NetAlertX, OpenTSDB and Netatalk vulnerabilities. Major updates to go-exploit framework.

Jan 25 - Jan 31, 2025

Delivered WSO2 account creation exploit, Reposilite directory traversal, and Nexus Repository RCE exploits. Enhanced API capabilities.

Jan 18 - Jan 24, 2025

Focused on SimpleHelp path traversal, PAN Expedition Spark RCE, and FortiOS auth bypass exploits. Updated exploit catalog metadata.

Jan 11 - Jan 17, 2025

Focused on Ivanti Connect IF-T buffer overflow, ShowDoc RCE, VoIP Monitor SQLi, and mySCADA PRO info leak exploits. Artica Proxy auth bypass covered.

Dec 21 - Dec 27, 2024

Major security updates for Apache Tomcat TOCTOU, SoftEther VPN, Jorani leave management system, and CHAOS RAT exploits.

Dec 14 - Dec 20, 2024

Added tracking for new C2 infrastructure, delivered exploits for Four-Faith routers, Acronis products, and Apache Solr vulnerabilities.

Dec 7 - Dec 13, 2024

Rapid response for Cleo products, delivered OwnCloud Ghostscript RCE chain, and Cobbler XML-RPC auth bypass. PAN Expedition SQLi covered.

Nov 30 - Dec 6, 2024

Delivered exploits for Mitel MiCollab file disclosure, OwnCloud Ghostscript RCE, WordPress plugin auth bypass. New syscall reflector tool developed.

Nov 23 - Nov 29, 2024

Delivered ProjectSend CVE-2024-11680 exploit chain, Alibaba Nacos RCE, and Draytek Vigor vulnerabilities. New fortigate exploit in development.

Nov 18 - Nov 22, 2024

Developed exploits for Citrix Session Recording, PAN-OS auth bypass chain, and D-Link ShareCenter DNS injection. Major API and tracking updates.

Nov 9 - Nov 17, 2024

Status update on Fortinet FortiManager auth bypass, delivered detections for Netgear WAX206. Added RedGuard C2 tracking capabilities.

Nov 2 - Nov 8, 2024

Released exploits for Acronis products, Apache Solr auth bypass, and pgAdmin OAuth2 info disclosure. Enhanced API query capabilities.

Oct 26 - Nov 1, 2024

Major updates for Spring WebFlux, CyberPanel RCE, Delta Electronics InfraSuite, and FortiOS vulnerabilities. Integration with OpenCTI platform.

Oct 19 - Oct 25, 2024

Major updates focused on exploits for Palo Alto Expedition chain, LiteSpeed Cache WordPress vulnerabilities, and network detection enhancements.

Oct 12 - Oct 18, 2024

Added ZoomEye/FOFA queries, delivered exploits for ABB ASPECT, Laravel credential leak, and Magento exploit chain.

Oct 5 - Oct 11, 2024

Developed Four Faith router exploits, WhatsUp Gold webshell, and discovered Zyxel CPE zero-days. Updated PCAP naming conventions.

Sept 28 - Oct 4, 2024

Released exploits for AVideo RCE, XWiki RCE, Progress MOVEit Transfer bypass. Enhanced IP Intel with new C2 infrastructure tracking.

August 31 - September 6, 2024

Delivered Traccar exploit chain, analyzed D-Link vulnerabilities, and created GLIBC Tunables exploit. Updated IP Intel tracking.

August 24 - August 30, 2024

Released exploits for Acronis products, SolarWinds Web Help Desk, and Anyscale Ray vulnerabilities. Enhanced API query capabilities.

August 17 - August 23, 2024

Delivered SPIP plugin RCE, Fortra FileCatalyst SQLi, and Exim auth bypass exploits. Added RedGuard C2 redirector tracking.

August 10 - August 16, 2024

Released exploits for Ivanti vTM auth bypass, ReCrystallize Server RCE, and Cisco SSM account takeover. Enhanced detection capabilities.

August 3 - August 9, 2024

Major updates for Windows RCE, Apache OFBiz, Delta Electronics, and Calibre exploits. Released go-exploit v1.24.0 documentation features.

July 27 - August 2, 2024

Released exploits for Bazarr secrets leak, AJ-Report auth bypass, and Ghostscript RCE. Added RunZero integration for go-exploit cache.