{
  "generated": "2026-08-18T12:38:30Z",
  "count": 6313,
  "iocs": [
    {
      "value": "CVE-2023-48022",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "The Hacker News"
      ],
      "articles": [
        {
          "id": "art-03",
          "title": "CISA Flags Actively Exploited Ray Flaw That Can Trigger Browser-Based RCE",
          "link": "https://thehackernews.com/2026/08/cisa-flags-actively-exploited-ray-flaw.html",
          "published": "2026-08-18",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-18"
    },
    {
      "value": "CVE-2025-62593",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "The Hacker News",
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-03",
          "title": "CISA Flags Actively Exploited Ray Flaw That Can Trigger Browser-Based RCE",
          "link": "https://thehackernews.com/2026/08/cisa-flags-actively-exploited-ray-flaw.html",
          "published": "2026-08-18",
          "sev": "crit"
        },
        {
          "id": "art-29",
          "title": "CISA KEV: CVE-2025-62593 \u2014 Ray-Project Ray Code Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-08-17",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-18"
    },
    {
      "value": "bwqqvqfgsseplyoltois92rdukv0mm5th.oast.fun",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "The Hacker News"
      ],
      "articles": [
        {
          "id": "art-03",
          "title": "CISA Flags Actively Exploited Ray Flaw That Can Trigger Browser-Based RCE",
          "link": "https://thehackernews.com/2026/08/cisa-flags-actively-exploited-ray-flaw.html",
          "published": "2026-08-18",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-18"
    },
    {
      "value": "eu.zano.k1pool.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "The Hacker News"
      ],
      "articles": [
        {
          "id": "art-03",
          "title": "CISA Flags Actively Exploited Ray Flaw That Can Trigger Browser-Based RCE",
          "link": "https://thehackernews.com/2026/08/cisa-flags-actively-exploited-ray-flaw.html",
          "published": "2026-08-18",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-18"
    },
    {
      "value": "gulf.moneroocean.stream",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "The Hacker News",
        "Unit 42 (Palo Alto)"
      ],
      "articles": [
        {
          "id": "art-03",
          "title": "CISA Flags Actively Exploited Ray Flaw That Can Trigger Browser-Based RCE",
          "link": "https://thehackernews.com/2026/08/cisa-flags-actively-exploited-ray-flaw.html",
          "published": "2026-08-18",
          "sev": "crit"
        },
        {
          "id": "art-96",
          "title": "The Permanent Threat: Analyzing Aeternum\u2019s Blockchain-Based C2 Operations and Communications",
          "link": "https://unit42.paloaltonetworks.com/aeternum-blockchain-c2-analysis/",
          "published": "2026-08-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-18"
    },
    {
      "value": "pool.supportxmr.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "The Hacker News"
      ],
      "articles": [
        {
          "id": "art-03",
          "title": "CISA Flags Actively Exploited Ray Flaw That Can Trigger Browser-Based RCE",
          "link": "https://thehackernews.com/2026/08/cisa-flags-actively-exploited-ray-flaw.html",
          "published": "2026-08-18",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-18"
    },
    {
      "value": "103.127.134.124",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "The Hacker News"
      ],
      "articles": [
        {
          "id": "art-03",
          "title": "CISA Flags Actively Exploited Ray Flaw That Can Trigger Browser-Based RCE",
          "link": "https://thehackernews.com/2026/08/cisa-flags-actively-exploited-ray-flaw.html",
          "published": "2026-08-18",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-18"
    },
    {
      "value": "104.194.151.181",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "The Hacker News"
      ],
      "articles": [
        {
          "id": "art-03",
          "title": "CISA Flags Actively Exploited Ray Flaw That Can Trigger Browser-Based RCE",
          "link": "https://thehackernews.com/2026/08/cisa-flags-actively-exploited-ray-flaw.html",
          "published": "2026-08-18",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-18"
    },
    {
      "value": "121.160.102.68",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "The Hacker News"
      ],
      "articles": [
        {
          "id": "art-03",
          "title": "CISA Flags Actively Exploited Ray Flaw That Can Trigger Browser-Based RCE",
          "link": "https://thehackernews.com/2026/08/cisa-flags-actively-exploited-ray-flaw.html",
          "published": "2026-08-18",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-18"
    },
    {
      "value": "158.160.123.117",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "The Hacker News"
      ],
      "articles": [
        {
          "id": "art-03",
          "title": "CISA Flags Actively Exploited Ray Flaw That Can Trigger Browser-Based RCE",
          "link": "https://thehackernews.com/2026/08/cisa-flags-actively-exploited-ray-flaw.html",
          "published": "2026-08-18",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-18"
    },
    {
      "value": "162.248.53.119",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "The Hacker News"
      ],
      "articles": [
        {
          "id": "art-03",
          "title": "CISA Flags Actively Exploited Ray Flaw That Can Trigger Browser-Based RCE",
          "link": "https://thehackernews.com/2026/08/cisa-flags-actively-exploited-ray-flaw.html",
          "published": "2026-08-18",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-18"
    },
    {
      "value": "18.228.3.224",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "The Hacker News"
      ],
      "articles": [
        {
          "id": "art-03",
          "title": "CISA Flags Actively Exploited Ray Flaw That Can Trigger Browser-Based RCE",
          "link": "https://thehackernews.com/2026/08/cisa-flags-actively-exploited-ray-flaw.html",
          "published": "2026-08-18",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-18"
    },
    {
      "value": "18.230.118.147",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "The Hacker News"
      ],
      "articles": [
        {
          "id": "art-03",
          "title": "CISA Flags Actively Exploited Ray Flaw That Can Trigger Browser-Based RCE",
          "link": "https://thehackernews.com/2026/08/cisa-flags-actively-exploited-ray-flaw.html",
          "published": "2026-08-18",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-18"
    },
    {
      "value": "185.215.180.70",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "The Hacker News"
      ],
      "articles": [
        {
          "id": "art-03",
          "title": "CISA Flags Actively Exploited Ray Flaw That Can Trigger Browser-Based RCE",
          "link": "https://thehackernews.com/2026/08/cisa-flags-actively-exploited-ray-flaw.html",
          "published": "2026-08-18",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-18"
    },
    {
      "value": "193.29.224.83",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "The Hacker News"
      ],
      "articles": [
        {
          "id": "art-03",
          "title": "CISA Flags Actively Exploited Ray Flaw That Can Trigger Browser-Based RCE",
          "link": "https://thehackernews.com/2026/08/cisa-flags-actively-exploited-ray-flaw.html",
          "published": "2026-08-18",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-18"
    },
    {
      "value": "45.61.150.83",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "The Hacker News"
      ],
      "articles": [
        {
          "id": "art-03",
          "title": "CISA Flags Actively Exploited Ray Flaw That Can Trigger Browser-Based RCE",
          "link": "https://thehackernews.com/2026/08/cisa-flags-actively-exploited-ray-flaw.html",
          "published": "2026-08-18",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-18"
    },
    {
      "value": "45.95.168.100",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "The Hacker News"
      ],
      "articles": [
        {
          "id": "art-03",
          "title": "CISA Flags Actively Exploited Ray Flaw That Can Trigger Browser-Based RCE",
          "link": "https://thehackernews.com/2026/08/cisa-flags-actively-exploited-ray-flaw.html",
          "published": "2026-08-18",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-18"
    },
    {
      "value": "54.154.170.233",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "The Hacker News"
      ],
      "articles": [
        {
          "id": "art-03",
          "title": "CISA Flags Actively Exploited Ray Flaw That Can Trigger Browser-Based RCE",
          "link": "https://thehackernews.com/2026/08/cisa-flags-actively-exploited-ray-flaw.html",
          "published": "2026-08-18",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-18"
    },
    {
      "value": "67.217.57.240",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "The Hacker News"
      ],
      "articles": [
        {
          "id": "art-03",
          "title": "CISA Flags Actively Exploited Ray Flaw That Can Trigger Browser-Based RCE",
          "link": "https://thehackernews.com/2026/08/cisa-flags-actively-exploited-ray-flaw.html",
          "published": "2026-08-18",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-18"
    },
    {
      "value": "1f63fa7921c2f5fb8f8ffa430d02ac4a",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "The Hacker News"
      ],
      "articles": [
        {
          "id": "art-03",
          "title": "CISA Flags Actively Exploited Ray Flaw That Can Trigger Browser-Based RCE",
          "link": "https://thehackernews.com/2026/08/cisa-flags-actively-exploited-ray-flaw.html",
          "published": "2026-08-18",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-18"
    },
    {
      "value": "779a8af3b9838a33d1e199da3fc2f02a49e7c13e",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "The Hacker News"
      ],
      "articles": [
        {
          "id": "art-03",
          "title": "CISA Flags Actively Exploited Ray Flaw That Can Trigger Browser-Based RCE",
          "link": "https://thehackernews.com/2026/08/cisa-flags-actively-exploited-ray-flaw.html",
          "published": "2026-08-18",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-18"
    },
    {
      "value": "1f6c69403678646a60925dcffe8509d22bb570c611324b93bec9aea72024ef6b",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "The Hacker News"
      ],
      "articles": [
        {
          "id": "art-03",
          "title": "CISA Flags Actively Exploited Ray Flaw That Can Trigger Browser-Based RCE",
          "link": "https://thehackernews.com/2026/08/cisa-flags-actively-exploited-ray-flaw.html",
          "published": "2026-08-18",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-18"
    },
    {
      "value": "6f445252494a0908ab51d526e09134cebc33a199384771acd58c4a87f1ffc063",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "The Hacker News"
      ],
      "articles": [
        {
          "id": "art-03",
          "title": "CISA Flags Actively Exploited Ray Flaw That Can Trigger Browser-Based RCE",
          "link": "https://thehackernews.com/2026/08/cisa-flags-actively-exploited-ray-flaw.html",
          "published": "2026-08-18",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-18"
    },
    {
      "value": "CVE-2007-3010",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "The Hacker News",
        "BleepingComputer",
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-25",
          "title": "Evooo1Bot Linux Botnet Exploits Known Flaws to Turn Edge Devices Into SOCKS5 Proxies",
          "link": "https://thehackernews.com/2026/08/evooo1bot-linux-botnet-exploits-known.html",
          "published": "2026-08-17",
          "sev": "crit"
        },
        {
          "id": "art-36",
          "title": "New Evooo1Bot Linux botnet turns routers into traffic relay nodes",
          "link": "https://www.bleepingcomputer.com/news/security/new-evooo1bot-linux-botnet-turns-routers-into-traffic-relay-nodes/",
          "published": "2026-08-15",
          "sev": "crit"
        },
        {
          "id": "art-2329",
          "title": "CISA KEV: CVE-2007-3010 \u2014 Alcatel OmniPCX Enterprise Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-04-15",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-17"
    },
    {
      "value": "CVE-2016-6277",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "The Hacker News",
        "BleepingComputer",
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-25",
          "title": "Evooo1Bot Linux Botnet Exploits Known Flaws to Turn Edge Devices Into SOCKS5 Proxies",
          "link": "https://thehackernews.com/2026/08/evooo1bot-linux-botnet-exploits-known.html",
          "published": "2026-08-17",
          "sev": "crit"
        },
        {
          "id": "art-36",
          "title": "New Evooo1Bot Linux botnet turns routers into traffic relay nodes",
          "link": "https://www.bleepingcomputer.com/news/security/new-evooo1bot-linux-botnet-turns-routers-into-traffic-relay-nodes/",
          "published": "2026-08-15",
          "sev": "crit"
        },
        {
          "id": "art-2514",
          "title": "CISA KEV: CVE-2016-6277 \u2014 NETGEAR Multiple Routers Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-07",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-17"
    },
    {
      "value": "CVE-2018-14558",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "The Hacker News",
        "BleepingComputer",
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-25",
          "title": "Evooo1Bot Linux Botnet Exploits Known Flaws to Turn Edge Devices Into SOCKS5 Proxies",
          "link": "https://thehackernews.com/2026/08/evooo1bot-linux-botnet-exploits-known.html",
          "published": "2026-08-17",
          "sev": "crit"
        },
        {
          "id": "art-36",
          "title": "New Evooo1Bot Linux botnet turns routers into traffic relay nodes",
          "link": "https://www.bleepingcomputer.com/news/security/new-evooo1bot-linux-botnet-turns-routers-into-traffic-relay-nodes/",
          "published": "2026-08-15",
          "sev": "crit"
        },
        {
          "id": "art-3050",
          "title": "CISA KEV: CVE-2018-14558 \u2014 Tenda AC7, AC9, and AC10 Routers Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-17"
    },
    {
      "value": "CVE-2019-14931",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "The Hacker News",
        "BleepingComputer"
      ],
      "articles": [
        {
          "id": "art-25",
          "title": "Evooo1Bot Linux Botnet Exploits Known Flaws to Turn Edge Devices Into SOCKS5 Proxies",
          "link": "https://thehackernews.com/2026/08/evooo1bot-linux-botnet-exploits-known.html",
          "published": "2026-08-17",
          "sev": "crit"
        },
        {
          "id": "art-36",
          "title": "New Evooo1Bot Linux botnet turns routers into traffic relay nodes",
          "link": "https://www.bleepingcomputer.com/news/security/new-evooo1bot-linux-botnet-turns-routers-into-traffic-relay-nodes/",
          "published": "2026-08-15",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-17"
    },
    {
      "value": "CVE-2020-10987",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "The Hacker News",
        "BleepingComputer",
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-25",
          "title": "Evooo1Bot Linux Botnet Exploits Known Flaws to Turn Edge Devices Into SOCKS5 Proxies",
          "link": "https://thehackernews.com/2026/08/evooo1bot-linux-botnet-exploits-known.html",
          "published": "2026-08-17",
          "sev": "crit"
        },
        {
          "id": "art-36",
          "title": "New Evooo1Bot Linux botnet turns routers into traffic relay nodes",
          "link": "https://www.bleepingcomputer.com/news/security/new-evooo1bot-linux-botnet-turns-routers-into-traffic-relay-nodes/",
          "published": "2026-08-15",
          "sev": "crit"
        },
        {
          "id": "art-3049",
          "title": "CISA KEV: CVE-2020-10987 \u2014 Tenda AC1900 Router AC15 Model Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        },
        {
          "id": "art-3050",
          "title": "CISA KEV: CVE-2018-14558 \u2014 Tenda AC7, AC9, and AC10 Routers Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-17"
    },
    {
      "value": "CVE-2021-36260",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "The Hacker News",
        "BleepingComputer",
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-25",
          "title": "Evooo1Bot Linux Botnet Exploits Known Flaws to Turn Edge Devices Into SOCKS5 Proxies",
          "link": "https://thehackernews.com/2026/08/evooo1bot-linux-botnet-exploits-known.html",
          "published": "2026-08-17",
          "sev": "crit"
        },
        {
          "id": "art-36",
          "title": "New Evooo1Bot Linux botnet turns routers into traffic relay nodes",
          "link": "https://www.bleepingcomputer.com/news/security/new-evooo1bot-linux-botnet-turns-routers-into-traffic-relay-nodes/",
          "published": "2026-08-15",
          "sev": "crit"
        },
        {
          "id": "art-908",
          "title": "CISA KEV: CVE-2020-25078 \u2014 D-Link DCS-2530L and DCS-2670L Devices Unspecified Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-08-05",
          "sev": "crit"
        },
        {
          "id": "art-2718",
          "title": "CISA KEV: CVE-2021-36260 \u2014 Hikvision Improper Input Validation",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-01-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-17"
    },
    {
      "value": "CVE-2021-46422",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "The Hacker News",
        "BleepingComputer"
      ],
      "articles": [
        {
          "id": "art-25",
          "title": "Evooo1Bot Linux Botnet Exploits Known Flaws to Turn Edge Devices Into SOCKS5 Proxies",
          "link": "https://thehackernews.com/2026/08/evooo1bot-linux-botnet-exploits-known.html",
          "published": "2026-08-17",
          "sev": "crit"
        },
        {
          "id": "art-36",
          "title": "New Evooo1Bot Linux botnet turns routers into traffic relay nodes",
          "link": "https://www.bleepingcomputer.com/news/security/new-evooo1bot-linux-botnet-turns-routers-into-traffic-relay-nodes/",
          "published": "2026-08-15",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-17"
    },
    {
      "value": "CVE-2022-20210",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "The Hacker News"
      ],
      "articles": [
        {
          "id": "art-23",
          "title": "Unisoc VoLTE Video Call Exploit Chain Can Give Attackers Full Android Kernel Access",
          "link": "https://thehackernews.com/2026/08/unisoc-volte-video-call-exploit-chain.html",
          "published": "2026-08-17",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-17"
    },
    {
      "value": "CVE-2022-26134",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "The Hacker News",
        "BleepingComputer",
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-25",
          "title": "Evooo1Bot Linux Botnet Exploits Known Flaws to Turn Edge Devices Into SOCKS5 Proxies",
          "link": "https://thehackernews.com/2026/08/evooo1bot-linux-botnet-exploits-known.html",
          "published": "2026-08-17",
          "sev": "crit"
        },
        {
          "id": "art-36",
          "title": "New Evooo1Bot Linux botnet turns routers into traffic relay nodes",
          "link": "https://www.bleepingcomputer.com/news/security/new-evooo1bot-linux-botnet-turns-routers-into-traffic-relay-nodes/",
          "published": "2026-08-15",
          "sev": "crit"
        },
        {
          "id": "art-2188",
          "title": "CISA KEV: CVE-2022-26134 \u2014 Atlassian Confluence Server and Data Center Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-06-02",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-17"
    },
    {
      "value": "CVE-2022-29464",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "The Hacker News",
        "BleepingComputer",
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-25",
          "title": "Evooo1Bot Linux Botnet Exploits Known Flaws to Turn Edge Devices Into SOCKS5 Proxies",
          "link": "https://thehackernews.com/2026/08/evooo1bot-linux-botnet-exploits-known.html",
          "published": "2026-08-17",
          "sev": "crit"
        },
        {
          "id": "art-36",
          "title": "New Evooo1Bot Linux botnet turns routers into traffic relay nodes",
          "link": "https://www.bleepingcomputer.com/news/security/new-evooo1bot-linux-botnet-turns-routers-into-traffic-relay-nodes/",
          "published": "2026-08-15",
          "sev": "crit"
        },
        {
          "id": "art-2305",
          "title": "CISA KEV: CVE-2022-29464 \u2014 WSO2 Multiple Products Unrestrictive Upload of File Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-04-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-17"
    },
    {
      "value": "CVE-2022-30525",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "The Hacker News",
        "BleepingComputer",
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-25",
          "title": "Evooo1Bot Linux Botnet Exploits Known Flaws to Turn Edge Devices Into SOCKS5 Proxies",
          "link": "https://thehackernews.com/2026/08/evooo1bot-linux-botnet-exploits-known.html",
          "published": "2026-08-17",
          "sev": "crit"
        },
        {
          "id": "art-36",
          "title": "New Evooo1Bot Linux botnet turns routers into traffic relay nodes",
          "link": "https://www.bleepingcomputer.com/news/security/new-evooo1bot-linux-botnet-turns-routers-into-traffic-relay-nodes/",
          "published": "2026-08-15",
          "sev": "crit"
        },
        {
          "id": "art-2273",
          "title": "CISA KEV: CVE-2022-30525 \u2014 Zyxel Multiple Firewalls OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-05-16",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-17"
    },
    {
      "value": "CVE-2022-37055",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "The Hacker News",
        "BleepingComputer",
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-25",
          "title": "Evooo1Bot Linux Botnet Exploits Known Flaws to Turn Edge Devices Into SOCKS5 Proxies",
          "link": "https://thehackernews.com/2026/08/evooo1bot-linux-botnet-exploits-known.html",
          "published": "2026-08-17",
          "sev": "crit"
        },
        {
          "id": "art-36",
          "title": "New Evooo1Bot Linux botnet turns routers into traffic relay nodes",
          "link": "https://www.bleepingcomputer.com/news/security/new-evooo1bot-linux-botnet-turns-routers-into-traffic-relay-nodes/",
          "published": "2026-08-15",
          "sev": "crit"
        },
        {
          "id": "art-778",
          "title": "CISA KEV: CVE-2022-37055 \u2014 D-Link Routers Buffer Overflow Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-12-08",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-17"
    },
    {
      "value": "CVE-2023-1389",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "The Hacker News",
        "BleepingComputer",
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-25",
          "title": "Evooo1Bot Linux Botnet Exploits Known Flaws to Turn Edge Devices Into SOCKS5 Proxies",
          "link": "https://thehackernews.com/2026/08/evooo1bot-linux-botnet-exploits-known.html",
          "published": "2026-08-17",
          "sev": "crit"
        },
        {
          "id": "art-36",
          "title": "New Evooo1Bot Linux botnet turns routers into traffic relay nodes",
          "link": "https://www.bleepingcomputer.com/news/security/new-evooo1bot-linux-botnet-turns-routers-into-traffic-relay-nodes/",
          "published": "2026-08-15",
          "sev": "crit"
        },
        {
          "id": "art-955",
          "title": "CISA KEV: CVE-2025-24016 \u2014 Wazuh Server Deserialization of Untrusted Data Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-06-10",
          "sev": "crit"
        },
        {
          "id": "art-1769",
          "title": "CISA KEV: CVE-2023-1389 \u2014 TP-Link Archer AX-21 Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-05-01",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-17"
    },
    {
      "value": "CVE-2023-34362",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "The Hacker News",
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-25",
          "title": "Evooo1Bot Linux Botnet Exploits Known Flaws to Turn Edge Devices Into SOCKS5 Proxies",
          "link": "https://thehackernews.com/2026/08/evooo1bot-linux-botnet-exploits-known.html",
          "published": "2026-08-17",
          "sev": "crit"
        },
        {
          "id": "art-1724",
          "title": "CISA KEV: CVE-2023-34362 \u2014 Progress MOVEit Transfer SQL Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-06-02",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-17"
    },
    {
      "value": "CVE-2024-10914",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "The Hacker News",
        "BleepingComputer"
      ],
      "articles": [
        {
          "id": "art-25",
          "title": "Evooo1Bot Linux Botnet Exploits Known Flaws to Turn Edge Devices Into SOCKS5 Proxies",
          "link": "https://thehackernews.com/2026/08/evooo1bot-linux-botnet-exploits-known.html",
          "published": "2026-08-17",
          "sev": "crit"
        },
        {
          "id": "art-36",
          "title": "New Evooo1Bot Linux botnet turns routers into traffic relay nodes",
          "link": "https://www.bleepingcomputer.com/news/security/new-evooo1bot-linux-botnet-turns-routers-into-traffic-relay-nodes/",
          "published": "2026-08-15",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-17"
    },
    {
      "value": "CVE-2024-29269",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "The Hacker News",
        "BleepingComputer"
      ],
      "articles": [
        {
          "id": "art-25",
          "title": "Evooo1Bot Linux Botnet Exploits Known Flaws to Turn Edge Devices Into SOCKS5 Proxies",
          "link": "https://thehackernews.com/2026/08/evooo1bot-linux-botnet-exploits-known.html",
          "published": "2026-08-17",
          "sev": "crit"
        },
        {
          "id": "art-36",
          "title": "New Evooo1Bot Linux botnet turns routers into traffic relay nodes",
          "link": "https://www.bleepingcomputer.com/news/security/new-evooo1bot-linux-botnet-turns-routers-into-traffic-relay-nodes/",
          "published": "2026-08-15",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-17"
    },
    {
      "value": "CVE-2024-4577",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "The Hacker News",
        "BleepingComputer",
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-25",
          "title": "Evooo1Bot Linux Botnet Exploits Known Flaws to Turn Edge Devices Into SOCKS5 Proxies",
          "link": "https://thehackernews.com/2026/08/evooo1bot-linux-botnet-exploits-known.html",
          "published": "2026-08-17",
          "sev": "crit"
        },
        {
          "id": "art-36",
          "title": "New Evooo1Bot Linux botnet turns routers into traffic relay nodes",
          "link": "https://www.bleepingcomputer.com/news/security/new-evooo1bot-linux-botnet-turns-routers-into-traffic-relay-nodes/",
          "published": "2026-08-15",
          "sev": "crit"
        },
        {
          "id": "art-1335",
          "title": "CISA KEV: CVE-2024-4577 \u2014 PHP-CGI OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-06-12",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-17"
    },
    {
      "value": "CVE-2025-10123",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "The Hacker News",
        "BleepingComputer"
      ],
      "articles": [
        {
          "id": "art-25",
          "title": "Evooo1Bot Linux Botnet Exploits Known Flaws to Turn Edge Devices Into SOCKS5 Proxies",
          "link": "https://thehackernews.com/2026/08/evooo1bot-linux-botnet-exploits-known.html",
          "published": "2026-08-17",
          "sev": "crit"
        },
        {
          "id": "art-36",
          "title": "New Evooo1Bot Linux botnet turns routers into traffic relay nodes",
          "link": "https://www.bleepingcomputer.com/news/security/new-evooo1bot-linux-botnet-turns-routers-into-traffic-relay-nodes/",
          "published": "2026-08-15",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-17"
    },
    {
      "value": "CVE-2025-1974",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "The Hacker News",
        "BleepingComputer"
      ],
      "articles": [
        {
          "id": "art-25",
          "title": "Evooo1Bot Linux Botnet Exploits Known Flaws to Turn Edge Devices Into SOCKS5 Proxies",
          "link": "https://thehackernews.com/2026/08/evooo1bot-linux-botnet-exploits-known.html",
          "published": "2026-08-17",
          "sev": "crit"
        },
        {
          "id": "art-36",
          "title": "New Evooo1Bot Linux botnet turns routers into traffic relay nodes",
          "link": "https://www.bleepingcomputer.com/news/security/new-evooo1bot-linux-botnet-turns-routers-into-traffic-relay-nodes/",
          "published": "2026-08-15",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-17"
    },
    {
      "value": "CVE-2025-31718",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "The Hacker News"
      ],
      "articles": [
        {
          "id": "art-23",
          "title": "Unisoc VoLTE Video Call Exploit Chain Can Give Attackers Full Android Kernel Access",
          "link": "https://thehackernews.com/2026/08/unisoc-volte-video-call-exploit-chain.html",
          "published": "2026-08-17",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-17"
    },
    {
      "value": "CVE-2025-55583",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "The Hacker News",
        "BleepingComputer"
      ],
      "articles": [
        {
          "id": "art-25",
          "title": "Evooo1Bot Linux Botnet Exploits Known Flaws to Turn Edge Devices Into SOCKS5 Proxies",
          "link": "https://thehackernews.com/2026/08/evooo1bot-linux-botnet-exploits-known.html",
          "published": "2026-08-17",
          "sev": "crit"
        },
        {
          "id": "art-36",
          "title": "New Evooo1Bot Linux botnet turns routers into traffic relay nodes",
          "link": "https://www.bleepingcomputer.com/news/security/new-evooo1bot-linux-botnet-turns-routers-into-traffic-relay-nodes/",
          "published": "2026-08-15",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-17"
    },
    {
      "value": "CVE-2026-12569",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "BleepingComputer",
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-22",
          "title": "Philips and GE investigating Clop ransomware data theft claims",
          "link": "https://www.bleepingcomputer.com/news/security/philips-and-ge-investigating-clop-ransomware-data-theft-claims/",
          "published": "2026-08-17",
          "sev": "high"
        },
        {
          "id": "art-347",
          "title": "CISA KEV: CVE-2026-12569 \u2014 PTC Windchill and FlexPLM Improper Input Validation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-06-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-17"
    },
    {
      "value": "CVE-2026-19478",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "The Hacker News"
      ],
      "articles": [
        {
          "id": "art-05",
          "title": "Critical GitLab GraphQL Flaw Could Let Unauthenticated Attackers Delete Public Projects",
          "link": "https://thehackernews.com/2026/08/critical-gitlab-graphql-flaw-could-let.html",
          "published": "2026-08-17",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-17"
    },
    {
      "value": "CVE-2026-19650",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "The Hacker News"
      ],
      "articles": [
        {
          "id": "art-05",
          "title": "Critical GitLab GraphQL Flaw Could Let Unauthenticated Attackers Delete Public Projects",
          "link": "https://thehackernews.com/2026/08/critical-gitlab-graphql-flaw-could-let.html",
          "published": "2026-08-17",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-17"
    },
    {
      "value": "CVE-2026-47686",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "GitHub Security Advisories"
      ],
      "articles": [
        {
          "id": "art-13",
          "title": "[GHSA / CRITICAL] CVE-2026-47686: VM2 has Missing Error.cause Sanitization that Enables Sandbox Escape to RCE",
          "link": "https://github.com/advisories/GHSA-m283-3h24-438v",
          "published": "2026-08-17",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-17"
    },
    {
      "value": "CVE-2026-47698",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "GitHub Security Advisories"
      ],
      "articles": [
        {
          "id": "art-12",
          "title": "[GHSA / CRITICAL] CVE-2026-47698: vm2: Sandbox Breakout Using Dangerous Host Proto Mutators",
          "link": "https://github.com/advisories/GHSA-cfcw-xp6x-25gj",
          "published": "2026-08-17",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-17"
    },
    {
      "value": "CVE-2026-50656",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "BleepingComputer",
        "The Hacker News"
      ],
      "articles": [
        {
          "id": "art-26",
          "title": "Microsoft working on Defender patch for ShieldBreak zero-day",
          "link": "https://www.bleepingcomputer.com/news/security/microsoft-working-on-defender-patch-for-shieldbreak-zero-day/",
          "published": "2026-08-17",
          "sev": "high"
        },
        {
          "id": "art-75",
          "title": "ShieldBreak Zero-Day PoC Claims Microsoft Defender Patch Bypass With SYSTEM Access",
          "link": "https://thehackernews.com/2026/08/shieldbreak-zero-day-poc-claims.html",
          "published": "2026-08-12",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-17"
    },
    {
      "value": "CVE-2026-55158",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "GitHub Security Advisories"
      ],
      "articles": [
        {
          "id": "art-18",
          "title": "[GHSA / CRITICAL] CVE-2026-55158: conflibot vulnerable to command injection via crafted pull request branch names under pull_request_target",
          "link": "https://github.com/advisories/GHSA-2qvg-qr73-mqxp",
          "published": "2026-08-17",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-17"
    },
    {
      "value": "CVE-2026-59309",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "The Hacker News"
      ],
      "articles": [
        {
          "id": "art-28",
          "title": "Suspected China-Nexus Actor Exploits VMware vCenter Flaw, Deploys Babuk-Derived Ransomware",
          "link": "https://thehackernews.com/2026/08/suspected-china-nexus-actor-exploits.html",
          "published": "2026-08-17",
          "sev": "crit"
        },
        {
          "id": "art-72",
          "title": "Attackers Exploit VMware vCenter Vulnerability to Gain Persistent Remote Access",
          "link": "https://thehackernews.com/2026/08/attackers-exploit-vmware-vcenter.html",
          "published": "2026-08-12",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-17"
    },
    {
      "value": "CVE-2026-59310",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "The Hacker News"
      ],
      "articles": [
        {
          "id": "art-28",
          "title": "Suspected China-Nexus Actor Exploits VMware vCenter Flaw, Deploys Babuk-Derived Ransomware",
          "link": "https://thehackernews.com/2026/08/suspected-china-nexus-actor-exploits.html",
          "published": "2026-08-17",
          "sev": "crit"
        },
        {
          "id": "art-72",
          "title": "Attackers Exploit VMware vCenter Vulnerability to Gain Persistent Remote Access",
          "link": "https://thehackernews.com/2026/08/attackers-exploit-vmware-vcenter.html",
          "published": "2026-08-12",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-17"
    },
    {
      "value": "CVE-2026-64849",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "GitHub Security Advisories"
      ],
      "articles": [
        {
          "id": "art-04",
          "title": "[GHSA / CRITICAL] CVE-2026-64849: MLflow: Unauthenticated full-read SSRF in webhook delivery: _validate_webhook_url bypassed via unvalidated HTTP redirects (and DNS rebinding)",
          "link": "https://github.com/advisories/GHSA-7gwp-5pfp-969j",
          "published": "2026-08-17",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-17"
    },
    {
      "value": "CVE-2026-64859",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "GitHub Security Advisories"
      ],
      "articles": [
        {
          "id": "art-15",
          "title": "[GHSA / CRITICAL] CVE-2026-64859: New API: User List API Leaks Root User Access Token Leading to Privilege Escalation",
          "link": "https://github.com/advisories/GHSA-6x2c-phff-wx57",
          "published": "2026-08-17",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-17"
    },
    {
      "value": "CVE-2026-71479",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "GitHub Security Advisories"
      ],
      "articles": [
        {
          "id": "art-14",
          "title": "[GHSA / CRITICAL] CVE-2026-71479: New API: Integer overflow in quota billing yields negative charges (self-crediting)",
          "link": "https://github.com/advisories/GHSA-8r8v-xf7q-rcpr",
          "published": "2026-08-17",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-17"
    },
    {
      "value": "intel.se9ly9upbhay.shop",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "The Hacker News"
      ],
      "articles": [
        {
          "id": "art-28",
          "title": "Suspected China-Nexus Actor Exploits VMware vCenter Flaw, Deploys Babuk-Derived Ransomware",
          "link": "https://thehackernews.com/2026/08/suspected-china-nexus-actor-exploits.html",
          "published": "2026-08-17",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-17"
    },
    {
      "value": "studiotikva.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "The Hacker News",
        "Securelist (Kaspersky)"
      ],
      "articles": [
        {
          "id": "art-10",
          "title": "Cavern C2 Uses DNS and Google Apps Script to Blend Into Legitimate Traffic",
          "link": "https://thehackernews.com/2026/08/cavern-c2-uses-dns-and-google-apps.html",
          "published": "2026-08-17",
          "sev": "crit"
        },
        {
          "id": "art-91",
          "title": "Project CAV3RN continues: Google Apps Script as C2 relay and DNS-based C2 channel selection",
          "link": "https://securelist.com/project-cav3rn-continues/120991/",
          "published": "2026-08-11",
          "sev": "high"
        }
      ],
      "first_seen": "2026-08-17"
    },
    {
      "value": "104.243.35.63",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "BleepingComputer",
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-22",
          "title": "Philips and GE investigating Clop ransomware data theft claims",
          "link": "https://www.bleepingcomputer.com/news/security/philips-and-ge-investigating-clop-ransomware-data-theft-claims/",
          "published": "2026-08-17",
          "sev": "high"
        },
        {
          "id": "art-347",
          "title": "CISA KEV: CVE-2026-12569 \u2014 PTC Windchill and FlexPLM Improper Input Validation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-06-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-17"
    },
    {
      "value": "146.59.252.178",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "The Hacker News"
      ],
      "articles": [
        {
          "id": "art-28",
          "title": "Suspected China-Nexus Actor Exploits VMware vCenter Flaw, Deploys Babuk-Derived Ransomware",
          "link": "https://thehackernews.com/2026/08/suspected-china-nexus-actor-exploits.html",
          "published": "2026-08-17",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-17"
    },
    {
      "value": "185.144.28.120",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "The Hacker News"
      ],
      "articles": [
        {
          "id": "art-28",
          "title": "Suspected China-Nexus Actor Exploits VMware vCenter Flaw, Deploys Babuk-Derived Ransomware",
          "link": "https://thehackernews.com/2026/08/suspected-china-nexus-actor-exploits.html",
          "published": "2026-08-17",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-17"
    },
    {
      "value": "192.255.141.13",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "The Hacker News"
      ],
      "articles": [
        {
          "id": "art-28",
          "title": "Suspected China-Nexus Actor Exploits VMware vCenter Flaw, Deploys Babuk-Derived Ransomware",
          "link": "https://thehackernews.com/2026/08/suspected-china-nexus-actor-exploits.html",
          "published": "2026-08-17",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-17"
    },
    {
      "value": "216.152.148.54",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "BleepingComputer",
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-22",
          "title": "Philips and GE investigating Clop ransomware data theft claims",
          "link": "https://www.bleepingcomputer.com/news/security/philips-and-ge-investigating-clop-ransomware-data-theft-claims/",
          "published": "2026-08-17",
          "sev": "high"
        },
        {
          "id": "art-347",
          "title": "CISA KEV: CVE-2026-12569 \u2014 PTC Windchill and FlexPLM Improper Input Validation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-06-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-17"
    },
    {
      "value": "216.152.151.204",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "BleepingComputer",
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-22",
          "title": "Philips and GE investigating Clop ransomware data theft claims",
          "link": "https://www.bleepingcomputer.com/news/security/philips-and-ge-investigating-clop-ransomware-data-theft-claims/",
          "published": "2026-08-17",
          "sev": "high"
        },
        {
          "id": "art-347",
          "title": "CISA KEV: CVE-2026-12569 \u2014 PTC Windchill and FlexPLM Improper Input Validation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-06-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-17"
    },
    {
      "value": "5.180.41.35",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "BleepingComputer",
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-22",
          "title": "Philips and GE investigating Clop ransomware data theft claims",
          "link": "https://www.bleepingcomputer.com/news/security/philips-and-ge-investigating-clop-ransomware-data-theft-claims/",
          "published": "2026-08-17",
          "sev": "high"
        },
        {
          "id": "art-347",
          "title": "CISA KEV: CVE-2026-12569 \u2014 PTC Windchill and FlexPLM Improper Input Validation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-06-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-17"
    },
    {
      "value": "5.34.176.100",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "The Hacker News"
      ],
      "articles": [
        {
          "id": "art-28",
          "title": "Suspected China-Nexus Actor Exploits VMware vCenter Flaw, Deploys Babuk-Derived Ransomware",
          "link": "https://thehackernews.com/2026/08/suspected-china-nexus-actor-exploits.html",
          "published": "2026-08-17",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-17"
    },
    {
      "value": "5.34.177.38",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "The Hacker News"
      ],
      "articles": [
        {
          "id": "art-28",
          "title": "Suspected China-Nexus Actor Exploits VMware vCenter Flaw, Deploys Babuk-Derived Ransomware",
          "link": "https://thehackernews.com/2026/08/suspected-china-nexus-actor-exploits.html",
          "published": "2026-08-17",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-17"
    },
    {
      "value": "91.92.40.118",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "The Hacker News",
        "BleepingComputer"
      ],
      "articles": [
        {
          "id": "art-25",
          "title": "Evooo1Bot Linux Botnet Exploits Known Flaws to Turn Edge Devices Into SOCKS5 Proxies",
          "link": "https://thehackernews.com/2026/08/evooo1bot-linux-botnet-exploits-known.html",
          "published": "2026-08-17",
          "sev": "crit"
        },
        {
          "id": "art-36",
          "title": "New Evooo1Bot Linux botnet turns routers into traffic relay nodes",
          "link": "https://www.bleepingcomputer.com/news/security/new-evooo1bot-linux-botnet-turns-routers-into-traffic-relay-nodes/",
          "published": "2026-08-15",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-17"
    },
    {
      "value": "4c0886349e9d348569fffe1b7a31e474d514508bf0cd6f1e5dd99c2a73525e4d",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "The Hacker News",
        "BleepingComputer"
      ],
      "articles": [
        {
          "id": "art-25",
          "title": "Evooo1Bot Linux Botnet Exploits Known Flaws to Turn Edge Devices Into SOCKS5 Proxies",
          "link": "https://thehackernews.com/2026/08/evooo1bot-linux-botnet-exploits-known.html",
          "published": "2026-08-17",
          "sev": "crit"
        },
        {
          "id": "art-36",
          "title": "New Evooo1Bot Linux botnet turns routers into traffic relay nodes",
          "link": "https://www.bleepingcomputer.com/news/security/new-evooo1bot-linux-botnet-turns-routers-into-traffic-relay-nodes/",
          "published": "2026-08-15",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-17"
    },
    {
      "value": "55a1eb4c2d3da04376df39d7ba832569c6af1a37a0cf2b95f754ac898023a30c",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "BleepingComputer",
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-22",
          "title": "Philips and GE investigating Clop ransomware data theft claims",
          "link": "https://www.bleepingcomputer.com/news/security/philips-and-ge-investigating-clop-ransomware-data-theft-claims/",
          "published": "2026-08-17",
          "sev": "high"
        },
        {
          "id": "art-347",
          "title": "CISA KEV: CVE-2026-12569 \u2014 PTC Windchill and FlexPLM Improper Input Validation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-06-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-17"
    },
    {
      "value": "f13cb360768363d3424e2192c7805b8c8015eb8706dbbbcdead6aed8cf390109",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "The Hacker News",
        "BleepingComputer"
      ],
      "articles": [
        {
          "id": "art-25",
          "title": "Evooo1Bot Linux Botnet Exploits Known Flaws to Turn Edge Devices Into SOCKS5 Proxies",
          "link": "https://thehackernews.com/2026/08/evooo1bot-linux-botnet-exploits-known.html",
          "published": "2026-08-17",
          "sev": "crit"
        },
        {
          "id": "art-36",
          "title": "New Evooo1Bot Linux botnet turns routers into traffic relay nodes",
          "link": "https://www.bleepingcomputer.com/news/security/new-evooo1bot-linux-botnet-turns-routers-into-traffic-relay-nodes/",
          "published": "2026-08-15",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-17"
    },
    {
      "value": "CVE-2026-54121",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "BleepingComputer"
      ],
      "articles": [
        {
          "id": "art-17",
          "title": "Certighost and the Privilege Hiding in Your Certificate Authority",
          "link": "https://www.bleepingcomputer.com/news/security/certighost-and-the-privilege-hiding-in-your-certificate-authority/",
          "published": "2026-08-17",
          "sev": "high"
        }
      ],
      "first_seen": "2026-08-17"
    },
    {
      "value": "CVE-2026-69414",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "BleepingComputer"
      ],
      "articles": [
        {
          "id": "art-26",
          "title": "Microsoft working on Defender patch for ShieldBreak zero-day",
          "link": "https://www.bleepingcomputer.com/news/security/microsoft-working-on-defender-patch-for-shieldbreak-zero-day/",
          "published": "2026-08-17",
          "sev": "high"
        }
      ],
      "first_seen": "2026-08-17"
    },
    {
      "value": "anonfilesnew.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "BleepingComputer"
      ],
      "articles": [
        {
          "id": "art-06",
          "title": "Hacker claims 3.6 million Azure account records stolen from major companies",
          "link": "https://www.bleepingcomputer.com/news/security/hacker-claims-36-million-azure-account-records-stolen-from-major-companies/",
          "published": "2026-08-17",
          "sev": "high"
        }
      ],
      "first_seen": "2026-08-17"
    },
    {
      "value": "d8t9ldn1onp04vb3399g5krtxh14hkh3.oast.me",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "The Hacker News"
      ],
      "articles": [
        {
          "id": "art-08",
          "title": "Snowflake GitHub Actions Flaw Lets Crafted Issues Trigger Command Injection",
          "link": "https://thehackernews.com/2026/08/snowflake-github-actions-flaw-lets_0330881554.html",
          "published": "2026-08-17",
          "sev": "high"
        }
      ],
      "first_seen": "2026-08-17"
    },
    {
      "value": "apexappliexi.dgfp.finances.gouv.fr",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "med",
      "sources": [
        "BleepingComputer"
      ],
      "articles": [
        {
          "id": "art-24",
          "title": "French tax authority data breach affects 678,000 individuals",
          "link": "https://www.bleepingcomputer.com/news/security/french-tax-authority-data-breach-affects-678-000-individuals/",
          "published": "2026-08-17",
          "sev": "med"
        }
      ],
      "first_seen": "2026-08-17"
    },
    {
      "value": "CVE-2020-9771",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "BleepingComputer",
        "The Hacker News"
      ],
      "articles": [
        {
          "id": "art-33",
          "title": "New AmnesiaStealer macOS malware hijacks browser sessions via remote control",
          "link": "https://www.bleepingcomputer.com/news/security/new-amnesiastealer-macos-malware-hijacks-browser-sessions-via-remote-control/",
          "published": "2026-08-16",
          "sev": "crit"
        },
        {
          "id": "art-55",
          "title": "AmnesiaStealer Hijacks Chromium Sessions to Give Attackers Live Browser Control on macOS",
          "link": "https://thehackernews.com/2026/08/amnesiastealer-hijacks-chromium.html",
          "published": "2026-08-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-16"
    },
    {
      "value": "debug.allllowef.space",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "BleepingComputer",
        "The Hacker News"
      ],
      "articles": [
        {
          "id": "art-33",
          "title": "New AmnesiaStealer macOS malware hijacks browser sessions via remote control",
          "link": "https://www.bleepingcomputer.com/news/security/new-amnesiastealer-macos-malware-hijacks-browser-sessions-via-remote-control/",
          "published": "2026-08-16",
          "sev": "crit"
        },
        {
          "id": "art-55",
          "title": "AmnesiaStealer Hijacks Chromium Sessions to Give Attackers Live Browser Control on macOS",
          "link": "https://thehackernews.com/2026/08/amnesiastealer-hijacks-chromium.html",
          "published": "2026-08-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-16"
    },
    {
      "value": "github.aoitour.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "BleepingComputer",
        "The Hacker News"
      ],
      "articles": [
        {
          "id": "art-33",
          "title": "New AmnesiaStealer macOS malware hijacks browser sessions via remote control",
          "link": "https://www.bleepingcomputer.com/news/security/new-amnesiastealer-macos-malware-hijacks-browser-sessions-via-remote-control/",
          "published": "2026-08-16",
          "sev": "crit"
        },
        {
          "id": "art-55",
          "title": "AmnesiaStealer Hijacks Chromium Sessions to Give Attackers Live Browser Control on macOS",
          "link": "https://thehackernews.com/2026/08/amnesiastealer-hijacks-chromium.html",
          "published": "2026-08-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-16"
    },
    {
      "value": "de5748aac4a4d4cb48cf050652679e6bc49eda33d9ffaa0d280b578122fab55a",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "BleepingComputer",
        "The Hacker News"
      ],
      "articles": [
        {
          "id": "art-33",
          "title": "New AmnesiaStealer macOS malware hijacks browser sessions via remote control",
          "link": "https://www.bleepingcomputer.com/news/security/new-amnesiastealer-macos-malware-hijacks-browser-sessions-via-remote-control/",
          "published": "2026-08-16",
          "sev": "crit"
        },
        {
          "id": "art-55",
          "title": "AmnesiaStealer Hijacks Chromium Sessions to Give Attackers Live Browser Control on macOS",
          "link": "https://thehackernews.com/2026/08/amnesiastealer-hijacks-chromium.html",
          "published": "2026-08-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-16"
    },
    {
      "value": "e853748ca8f9a5a9168263617409a9039ab09f4ffc7d860374c1e3b0b67b31a5",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "BleepingComputer",
        "The Hacker News"
      ],
      "articles": [
        {
          "id": "art-33",
          "title": "New AmnesiaStealer macOS malware hijacks browser sessions via remote control",
          "link": "https://www.bleepingcomputer.com/news/security/new-amnesiastealer-macos-malware-hijacks-browser-sessions-via-remote-control/",
          "published": "2026-08-16",
          "sev": "crit"
        },
        {
          "id": "art-55",
          "title": "AmnesiaStealer Hijacks Chromium Sessions to Give Attackers Live Browser Control on macOS",
          "link": "https://thehackernews.com/2026/08/amnesiastealer-hijacks-chromium.html",
          "published": "2026-08-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-16"
    },
    {
      "value": "safepal.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "BleepingComputer"
      ],
      "articles": [
        {
          "id": "art-30",
          "title": "SafePal data breach impacts 39,798 customers, stolen info for sale",
          "link": "https://www.bleepingcomputer.com/news/security/safepal-data-breach-impacts-39-798-customers-stolen-info-for-sale/",
          "published": "2026-08-16",
          "sev": "high"
        }
      ],
      "first_seen": "2026-08-16"
    },
    {
      "value": "CVE-2026-33634",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "StepSecurity",
        "The Hacker News",
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-35",
          "title": "Team PCP Stole 78,330 Secrets From 2,186 Organizations. CloudSEK Just Published the List.",
          "link": "https://www.stepsecurity.io/blog/teampcp-supply-chain-attack-cicd-secrets-cloudsek-disclosure",
          "published": "2026-08-15",
          "sev": "crit"
        },
        {
          "id": "art-73",
          "title": "Malicious LiteLLM Releases Tied to Trivy Hack May Have Exposed 2,100+ Organizations",
          "link": "https://thehackernews.com/2026/08/malicious-litellm-releases-tied-to.html",
          "published": "2026-08-12",
          "sev": "crit"
        },
        {
          "id": "art-324",
          "title": "10 Layers Deep: How StepSecurity Stops TeamPCP's Trivy Supply Chain Attack on GitHub Actions",
          "link": "https://www.stepsecurity.io/blog/10-layers-deep-how-stepsecurity-stops-teampcps-trivy-supply-chain-attack-on-github-actions",
          "published": "2026-07-02",
          "sev": "crit"
        },
        {
          "id": "art-600",
          "title": "CISA KEV: CVE-2026-33634 \u2014 Aquasecurity Trivy Embedded Malicious Code Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-03-26",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-15"
    },
    {
      "value": "CVE-2026-43760",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "The Hacker News"
      ],
      "articles": [
        {
          "id": "art-38",
          "title": "Apple macOS Screen Sharing Flaw Exploited on Internet-Exposed Macs to Install Monero Miner",
          "link": "https://thehackernews.com/2026/08/apple-macos-screen-sharing-flaw.html",
          "published": "2026-08-15",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-15"
    },
    {
      "value": "CVE-2026-43777",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "The Hacker News"
      ],
      "articles": [
        {
          "id": "art-38",
          "title": "Apple macOS Screen Sharing Flaw Exploited on Internet-Exposed Macs to Install Monero Miner",
          "link": "https://thehackernews.com/2026/08/apple-macos-screen-sharing-flaw.html",
          "published": "2026-08-15",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-15"
    },
    {
      "value": "CVE-2026-43779",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "The Hacker News"
      ],
      "articles": [
        {
          "id": "art-38",
          "title": "Apple macOS Screen Sharing Flaw Exploited on Internet-Exposed Macs to Install Monero Miner",
          "link": "https://thehackernews.com/2026/08/apple-macos-screen-sharing-flaw.html",
          "published": "2026-08-15",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-15"
    },
    {
      "value": "CVE-2026-58231",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "The Hacker News"
      ],
      "articles": [
        {
          "id": "art-37",
          "title": "SAP Commerce Cloud CVE-2026-58231 Targeted in Exploitation Attempts Days After Patch",
          "link": "https://thehackernews.com/2026/08/sap-commerce-cloud-cve-2026-58231.html",
          "published": "2026-08-15",
          "sev": "crit"
        },
        {
          "id": "art-74",
          "title": "SAP Commerce Cloud Flaw Could Let Unauthenticated Attackers Execute Arbitrary Code",
          "link": "https://thehackernews.com/2026/08/sap-commerce-cloud-flaw-could-let.html",
          "published": "2026-08-12",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-15"
    },
    {
      "value": "CVE-2026-65400",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "The Hacker News"
      ],
      "articles": [
        {
          "id": "art-38",
          "title": "Apple macOS Screen Sharing Flaw Exploited on Internet-Exposed Macs to Install Monero Miner",
          "link": "https://thehackernews.com/2026/08/apple-macos-screen-sharing-flaw.html",
          "published": "2026-08-15",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-15"
    },
    {
      "value": "83.142.209.203",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "StepSecurity",
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-35",
          "title": "Team PCP Stole 78,330 Secrets From 2,186 Organizations. CloudSEK Just Published the List.",
          "link": "https://www.stepsecurity.io/blog/teampcp-supply-chain-attack-cicd-secrets-cloudsek-disclosure",
          "published": "2026-08-15",
          "sev": "crit"
        },
        {
          "id": "art-324",
          "title": "10 Layers Deep: How StepSecurity Stops TeamPCP's Trivy Supply Chain Attack on GitHub Actions",
          "link": "https://www.stepsecurity.io/blog/10-layers-deep-how-stepsecurity-stops-teampcps-trivy-supply-chain-attack-on-github-actions",
          "published": "2026-07-02",
          "sev": "crit"
        },
        {
          "id": "art-578",
          "title": "TeamPCP Plants WAV Steganography Credential Stealer in telnyx PyPI Package",
          "link": "https://www.stepsecurity.io/blog/teampcp-plants-wav-steganography-credential-stealer-in-telnyx-pypi-package",
          "published": "2026-04-02",
          "sev": "crit"
        },
        {
          "id": "art-579",
          "title": "You Patched LiteLLM, But Do You Know Your AI Blast Radius?",
          "link": "https://snyk.io/blog/litellm-ai-blast-radius/",
          "published": "2026-04-02",
          "sev": "high"
        }
      ],
      "first_seen": "2026-08-15"
    },
    {
      "value": "7321caa303fe96ded0492c747d2f353c4f7d17185656fe292ab0a59e2bd0b8d9",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "StepSecurity"
      ],
      "articles": [
        {
          "id": "art-35",
          "title": "Team PCP Stole 78,330 Secrets From 2,186 Organizations. CloudSEK Just Published the List.",
          "link": "https://www.stepsecurity.io/blog/teampcp-supply-chain-attack-cicd-secrets-cloudsek-disclosure",
          "published": "2026-08-15",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-15"
    },
    {
      "value": "cd08115806662469bbedec4b03f8427b97c8a4b3bc1442dc18b72b4e19395fe3",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "StepSecurity"
      ],
      "articles": [
        {
          "id": "art-35",
          "title": "Team PCP Stole 78,330 Secrets From 2,186 Organizations. CloudSEK Just Published the List.",
          "link": "https://www.stepsecurity.io/blog/teampcp-supply-chain-attack-cicd-secrets-cloudsek-disclosure",
          "published": "2026-08-15",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-15"
    },
    {
      "value": "awqhnjewqjkl.icu",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "Aikido",
        "Unit 42 (Palo Alto)"
      ],
      "articles": [
        {
          "id": "art-39",
          "title": "Top enterprise SCA tools in 2026",
          "link": "https://www.aikido.dev/blog/top-enterprise-sca-tools",
          "published": "2026-08-14",
          "sev": "high"
        },
        {
          "id": "art-108",
          "title": "ChainDrop: Inside a Self-Propagating npm Worm",
          "link": "https://unit42.paloaltonetworks.com/chaindrop-npm-worm-analysis/",
          "published": "2026-08-06",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-14"
    },
    {
      "value": "black-popular.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "Securelist (Kaspersky)"
      ],
      "articles": [
        {
          "id": "art-48",
          "title": "APT group HoneyMyte upgrades CoolClient: the backdoor gets a kernel-level Windows rootkit",
          "link": "https://securelist.com/honeymyte-coolclient-driver-rootkit/121028/",
          "published": "2026-08-14",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-14"
    },
    {
      "value": "browser-update.pages.dev",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "The Hacker News"
      ],
      "articles": [
        {
          "id": "art-49",
          "title": "China-Linked Jewelbug Uses XG-Web for Government Espionage and Crypto Fraud",
          "link": "https://thehackernews.com/2026/08/china-linked-jewelbug-uses-xg-web-for.html",
          "published": "2026-08-14",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-14"
    },
    {
      "value": "cloudtroe.giize.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "Securelist (Kaspersky)"
      ],
      "articles": [
        {
          "id": "art-48",
          "title": "APT group HoneyMyte upgrades CoolClient: the backdoor gets a kernel-level Windows rootkit",
          "link": "https://securelist.com/honeymyte-coolclient-driver-rootkit/121028/",
          "published": "2026-08-14",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-14"
    },
    {
      "value": "dns.wizkidblogger.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "The Hacker News"
      ],
      "articles": [
        {
          "id": "art-49",
          "title": "China-Linked Jewelbug Uses XG-Web for Government Espionage and Crypto Fraud",
          "link": "https://thehackernews.com/2026/08/china-linked-jewelbug-uses-xg-web-for.html",
          "published": "2026-08-14",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-14"
    },
    {
      "value": "eastus2.wac-azure.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "The Hacker News"
      ],
      "articles": [
        {
          "id": "art-49",
          "title": "China-Linked Jewelbug Uses XG-Web for Government Espionage and Crypto Fraud",
          "link": "https://thehackernews.com/2026/08/china-linked-jewelbug-uses-xg-web-for.html",
          "published": "2026-08-14",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-14"
    },
    {
      "value": "employers.theworkpc.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "Securelist (Kaspersky)"
      ],
      "articles": [
        {
          "id": "art-48",
          "title": "APT group HoneyMyte upgrades CoolClient: the backdoor gets a kernel-level Windows rootkit",
          "link": "https://securelist.com/honeymyte-coolclient-driver-rootkit/121028/",
          "published": "2026-08-14",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-14"
    },
    {
      "value": "fonts.chrorne.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "The Hacker News"
      ],
      "articles": [
        {
          "id": "art-49",
          "title": "China-Linked Jewelbug Uses XG-Web for Government Espionage and Crypto Fraud",
          "link": "https://thehackernews.com/2026/08/china-linked-jewelbug-uses-xg-web-for.html",
          "published": "2026-08-14",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-14"
    },
    {
      "value": "fonts.tarotfree101.top",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "The Hacker News"
      ],
      "articles": [
        {
          "id": "art-49",
          "title": "China-Linked Jewelbug Uses XG-Web for Government Espionage and Crypto Fraud",
          "link": "https://thehackernews.com/2026/08/china-linked-jewelbug-uses-xg-web-for.html",
          "published": "2026-08-14",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-14"
    },
    {
      "value": "freeread.casacam.net",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "Securelist (Kaspersky)"
      ],
      "articles": [
        {
          "id": "art-48",
          "title": "APT group HoneyMyte upgrades CoolClient: the backdoor gets a kernel-level Windows rootkit",
          "link": "https://securelist.com/honeymyte-coolclient-driver-rootkit/121028/",
          "published": "2026-08-14",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-14"
    },
    {
      "value": "js-mirror.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "Aikido",
        "Unit 42 (Palo Alto)",
        "Cisco Talos",
        "Microsoft Security Blog"
      ],
      "articles": [
        {
          "id": "art-39",
          "title": "Top enterprise SCA tools in 2026",
          "link": "https://www.aikido.dev/blog/top-enterprise-sca-tools",
          "published": "2026-08-14",
          "sev": "high"
        },
        {
          "id": "art-108",
          "title": "ChainDrop: Inside a Self-Propagating npm Worm",
          "link": "https://unit42.paloaltonetworks.com/chaindrop-npm-worm-analysis/",
          "published": "2026-08-06",
          "sev": "crit"
        },
        {
          "id": "art-110",
          "title": "Why metaphor may dictate your security strategy",
          "link": "https://blog.talosintelligence.com/why-metaphor-may-dictate-your-security-strategy/",
          "published": "2026-08-06",
          "sev": "high"
        },
        {
          "id": "art-120",
          "title": "ChainDrop supply chain compromise: Anatomy of a self-propagating worm",
          "link": "https://www.microsoft.com/en-us/security/blog/2026/08/04/chaindrop-supply-chain-compromise-anatomy-self-propagating-worm/",
          "published": "2026-08-04",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-14"
    },
    {
      "value": "mailbycloud.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "The Hacker News"
      ],
      "articles": [
        {
          "id": "art-49",
          "title": "China-Linked Jewelbug Uses XG-Web for Government Espionage and Crypto Fraud",
          "link": "https://thehackernews.com/2026/08/china-linked-jewelbug-uses-xg-web-for.html",
          "published": "2026-08-14",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-14"
    },
    {
      "value": "microsoft-flash.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "The Hacker News"
      ],
      "articles": [
        {
          "id": "art-49",
          "title": "China-Linked Jewelbug Uses XG-Web for Government Espionage and Crypto Fraud",
          "link": "https://thehackernews.com/2026/08/china-linked-jewelbug-uses-xg-web-for.html",
          "published": "2026-08-14",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-14"
    },
    {
      "value": "news.dursamjbataar.org",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "Securelist (Kaspersky)"
      ],
      "articles": [
        {
          "id": "art-48",
          "title": "APT group HoneyMyte upgrades CoolClient: the backdoor gets a kernel-level Windows rootkit",
          "link": "https://securelist.com/honeymyte-coolclient-driver-rootkit/121028/",
          "published": "2026-08-14",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-14"
    },
    {
      "value": "npm-cache.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "Aikido",
        "Unit 42 (Palo Alto)",
        "Cisco Talos",
        "Microsoft Security Blog"
      ],
      "articles": [
        {
          "id": "art-39",
          "title": "Top enterprise SCA tools in 2026",
          "link": "https://www.aikido.dev/blog/top-enterprise-sca-tools",
          "published": "2026-08-14",
          "sev": "high"
        },
        {
          "id": "art-108",
          "title": "ChainDrop: Inside a Self-Propagating npm Worm",
          "link": "https://unit42.paloaltonetworks.com/chaindrop-npm-worm-analysis/",
          "published": "2026-08-06",
          "sev": "crit"
        },
        {
          "id": "art-110",
          "title": "Why metaphor may dictate your security strategy",
          "link": "https://blog.talosintelligence.com/why-metaphor-may-dictate-your-security-strategy/",
          "published": "2026-08-06",
          "sev": "high"
        },
        {
          "id": "art-120",
          "title": "ChainDrop supply chain compromise: Anatomy of a self-propagating worm",
          "link": "https://www.microsoft.com/en-us/security/blog/2026/08/04/chaindrop-supply-chain-compromise-anatomy-self-propagating-worm/",
          "published": "2026-08-04",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-14"
    },
    {
      "value": "ns1.jkskhei.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "The Hacker News"
      ],
      "articles": [
        {
          "id": "art-49",
          "title": "China-Linked Jewelbug Uses XG-Web for Government Espionage and Crypto Fraud",
          "link": "https://thehackernews.com/2026/08/china-linked-jewelbug-uses-xg-web-for.html",
          "published": "2026-08-14",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-14"
    },
    {
      "value": "peopleforce.io",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "The Hacker News"
      ],
      "articles": [
        {
          "id": "art-45",
          "title": "CTM360 Uncovers Over 3,000 Recruitment Phishing URLs Using Browser-in-the-Browser (BitB) Credential Traps",
          "link": "https://thehackernews.com/2026/08/ctm360-uncovers-over-3000-recruitment.html",
          "published": "2026-08-14",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-14"
    },
    {
      "value": "pypi-get.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "Aikido",
        "Unit 42 (Palo Alto)",
        "Cisco Talos",
        "Microsoft Security Blog"
      ],
      "articles": [
        {
          "id": "art-39",
          "title": "Top enterprise SCA tools in 2026",
          "link": "https://www.aikido.dev/blog/top-enterprise-sca-tools",
          "published": "2026-08-14",
          "sev": "high"
        },
        {
          "id": "art-108",
          "title": "ChainDrop: Inside a Self-Propagating npm Worm",
          "link": "https://unit42.paloaltonetworks.com/chaindrop-npm-worm-analysis/",
          "published": "2026-08-06",
          "sev": "crit"
        },
        {
          "id": "art-110",
          "title": "Why metaphor may dictate your security strategy",
          "link": "https://blog.talosintelligence.com/why-metaphor-may-dictate-your-security-strategy/",
          "published": "2026-08-06",
          "sev": "high"
        },
        {
          "id": "art-120",
          "title": "ChainDrop supply chain compromise: Anatomy of a self-propagating worm",
          "link": "https://www.microsoft.com/en-us/security/blog/2026/08/04/chaindrop-supply-chain-compromise-anatomy-self-propagating-worm/",
          "published": "2026-08-04",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-14"
    },
    {
      "value": "robot.avbliud.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "The Hacker News"
      ],
      "articles": [
        {
          "id": "art-49",
          "title": "China-Linked Jewelbug Uses XG-Web for Government Espionage and Crypto Fraud",
          "link": "https://thehackernews.com/2026/08/china-linked-jewelbug-uses-xg-web-for.html",
          "published": "2026-08-14",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-14"
    },
    {
      "value": "sundanish.freeddns.org",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "Securelist (Kaspersky)"
      ],
      "articles": [
        {
          "id": "art-48",
          "title": "APT group HoneyMyte upgrades CoolClient: the backdoor gets a kernel-level Windows rootkit",
          "link": "https://securelist.com/honeymyte-coolclient-driver-rootkit/121028/",
          "published": "2026-08-14",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-14"
    },
    {
      "value": "torinarlabs.webredirect.org",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "Securelist (Kaspersky)"
      ],
      "articles": [
        {
          "id": "art-48",
          "title": "APT group HoneyMyte upgrades CoolClient: the backdoor gets a kernel-level Windows rootkit",
          "link": "https://securelist.com/honeymyte-coolclient-driver-rootkit/121028/",
          "published": "2026-08-14",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-14"
    },
    {
      "value": "us.lenovoappstore.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "Securelist (Kaspersky)"
      ],
      "articles": [
        {
          "id": "art-48",
          "title": "APT group HoneyMyte upgrades CoolClient: the backdoor gets a kernel-level Windows rootkit",
          "link": "https://securelist.com/honeymyte-coolclient-driver-rootkit/121028/",
          "published": "2026-08-14",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-14"
    },
    {
      "value": "video.dursamjbataar.org",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "Securelist (Kaspersky)"
      ],
      "articles": [
        {
          "id": "art-48",
          "title": "APT group HoneyMyte upgrades CoolClient: the backdoor gets a kernel-level Windows rootkit",
          "link": "https://securelist.com/honeymyte-coolclient-driver-rootkit/121028/",
          "published": "2026-08-14",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-14"
    },
    {
      "value": "whatismybestthing.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "Securelist (Kaspersky)"
      ],
      "articles": [
        {
          "id": "art-48",
          "title": "APT group HoneyMyte upgrades CoolClient: the backdoor gets a kernel-level Windows rootkit",
          "link": "https://securelist.com/honeymyte-coolclient-driver-rootkit/121028/",
          "published": "2026-08-14",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-14"
    },
    {
      "value": "www.f1ash.org.cn",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "The Hacker News"
      ],
      "articles": [
        {
          "id": "art-49",
          "title": "China-Linked Jewelbug Uses XG-Web for Government Espionage and Crypto Fraud",
          "link": "https://thehackernews.com/2026/08/china-linked-jewelbug-uses-xg-web-for.html",
          "published": "2026-08-14",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-14"
    },
    {
      "value": "www.jkskhei.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "The Hacker News"
      ],
      "articles": [
        {
          "id": "art-49",
          "title": "China-Linked Jewelbug Uses XG-Web for Government Espionage and Crypto Fraud",
          "link": "https://thehackernews.com/2026/08/china-linked-jewelbug-uses-xg-web-for.html",
          "published": "2026-08-14",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-14"
    },
    {
      "value": "www.wps-cn.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "The Hacker News"
      ],
      "articles": [
        {
          "id": "art-49",
          "title": "China-Linked Jewelbug Uses XG-Web for Government Espionage and Crypto Fraud",
          "link": "https://thehackernews.com/2026/08/china-linked-jewelbug-uses-xg-web-for.html",
          "published": "2026-08-14",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-14"
    },
    {
      "value": "103.87.9.62",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "The Hacker News"
      ],
      "articles": [
        {
          "id": "art-49",
          "title": "China-Linked Jewelbug Uses XG-Web for Government Espionage and Crypto Fraud",
          "link": "https://thehackernews.com/2026/08/china-linked-jewelbug-uses-xg-web-for.html",
          "published": "2026-08-14",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-14"
    },
    {
      "value": "129.212.237.224",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "The Hacker News"
      ],
      "articles": [
        {
          "id": "art-49",
          "title": "China-Linked Jewelbug Uses XG-Web for Government Espionage and Crypto Fraud",
          "link": "https://thehackernews.com/2026/08/china-linked-jewelbug-uses-xg-web-for.html",
          "published": "2026-08-14",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-14"
    },
    {
      "value": "152.42.174.151",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "The Hacker News"
      ],
      "articles": [
        {
          "id": "art-49",
          "title": "China-Linked Jewelbug Uses XG-Web for Government Espionage and Crypto Fraud",
          "link": "https://thehackernews.com/2026/08/china-linked-jewelbug-uses-xg-web-for.html",
          "published": "2026-08-14",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-14"
    },
    {
      "value": "167.71.195.255",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "The Hacker News"
      ],
      "articles": [
        {
          "id": "art-49",
          "title": "China-Linked Jewelbug Uses XG-Web for Government Espionage and Crypto Fraud",
          "link": "https://thehackernews.com/2026/08/china-linked-jewelbug-uses-xg-web-for.html",
          "published": "2026-08-14",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-14"
    },
    {
      "value": "219.76.254.184",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "The Hacker News"
      ],
      "articles": [
        {
          "id": "art-49",
          "title": "China-Linked Jewelbug Uses XG-Web for Government Espionage and Crypto Fraud",
          "link": "https://thehackernews.com/2026/08/china-linked-jewelbug-uses-xg-web-for.html",
          "published": "2026-08-14",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-14"
    },
    {
      "value": "38.12.1.47",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "The Hacker News"
      ],
      "articles": [
        {
          "id": "art-49",
          "title": "China-Linked Jewelbug Uses XG-Web for Government Espionage and Crypto Fraud",
          "link": "https://thehackernews.com/2026/08/china-linked-jewelbug-uses-xg-web-for.html",
          "published": "2026-08-14",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-14"
    },
    {
      "value": "43.246.208.179",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "The Hacker News"
      ],
      "articles": [
        {
          "id": "art-49",
          "title": "China-Linked Jewelbug Uses XG-Web for Government Espionage and Crypto Fraud",
          "link": "https://thehackernews.com/2026/08/china-linked-jewelbug-uses-xg-web-for.html",
          "published": "2026-08-14",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-14"
    },
    {
      "value": "43.246.208.236",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "The Hacker News"
      ],
      "articles": [
        {
          "id": "art-49",
          "title": "China-Linked Jewelbug Uses XG-Web for Government Espionage and Crypto Fraud",
          "link": "https://thehackernews.com/2026/08/china-linked-jewelbug-uses-xg-web-for.html",
          "published": "2026-08-14",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-14"
    },
    {
      "value": "47.250.208.35",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "The Hacker News"
      ],
      "articles": [
        {
          "id": "art-49",
          "title": "China-Linked Jewelbug Uses XG-Web for Government Espionage and Crypto Fraud",
          "link": "https://thehackernews.com/2026/08/china-linked-jewelbug-uses-xg-web-for.html",
          "published": "2026-08-14",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-14"
    },
    {
      "value": "47.84.37.113",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "The Hacker News"
      ],
      "articles": [
        {
          "id": "art-49",
          "title": "China-Linked Jewelbug Uses XG-Web for Government Espionage and Crypto Fraud",
          "link": "https://thehackernews.com/2026/08/china-linked-jewelbug-uses-xg-web-for.html",
          "published": "2026-08-14",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-14"
    },
    {
      "value": "47.84.51.173",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "The Hacker News"
      ],
      "articles": [
        {
          "id": "art-49",
          "title": "China-Linked Jewelbug Uses XG-Web for Government Espionage and Crypto Fraud",
          "link": "https://thehackernews.com/2026/08/china-linked-jewelbug-uses-xg-web-for.html",
          "published": "2026-08-14",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-14"
    },
    {
      "value": "47.87.71.167",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "The Hacker News"
      ],
      "articles": [
        {
          "id": "art-49",
          "title": "China-Linked Jewelbug Uses XG-Web for Government Espionage and Crypto Fraud",
          "link": "https://thehackernews.com/2026/08/china-linked-jewelbug-uses-xg-web-for.html",
          "published": "2026-08-14",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-14"
    },
    {
      "value": "2d7c8780e97409770a9d4f31c66c9d63",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "The Hacker News",
        "Securelist (Kaspersky)"
      ],
      "articles": [
        {
          "id": "art-43",
          "title": "Mustang Panda Adds Signed Windows Rootkit to CoolClient Backdoor for Stealth",
          "link": "https://thehackernews.com/2026/08/mustang-panda-adds-signed-windows.html",
          "published": "2026-08-14",
          "sev": "high"
        },
        {
          "id": "art-48",
          "title": "APT group HoneyMyte upgrades CoolClient: the backdoor gets a kernel-level Windows rootkit",
          "link": "https://securelist.com/honeymyte-coolclient-driver-rootkit/121028/",
          "published": "2026-08-14",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-14"
    },
    {
      "value": "9460e150e1981d5c165043520c5c12fe",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "The Hacker News",
        "Securelist (Kaspersky)"
      ],
      "articles": [
        {
          "id": "art-43",
          "title": "Mustang Panda Adds Signed Windows Rootkit to CoolClient Backdoor for Stealth",
          "link": "https://thehackernews.com/2026/08/mustang-panda-adds-signed-windows.html",
          "published": "2026-08-14",
          "sev": "high"
        },
        {
          "id": "art-48",
          "title": "APT group HoneyMyte upgrades CoolClient: the backdoor gets a kernel-level Windows rootkit",
          "link": "https://securelist.com/honeymyte-coolclient-driver-rootkit/121028/",
          "published": "2026-08-14",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-14"
    },
    {
      "value": "9717f005c5fb98e08d2ad983d88f94ee",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "The Hacker News",
        "Securelist (Kaspersky)"
      ],
      "articles": [
        {
          "id": "art-43",
          "title": "Mustang Panda Adds Signed Windows Rootkit to CoolClient Backdoor for Stealth",
          "link": "https://thehackernews.com/2026/08/mustang-panda-adds-signed-windows.html",
          "published": "2026-08-14",
          "sev": "high"
        },
        {
          "id": "art-48",
          "title": "APT group HoneyMyte upgrades CoolClient: the backdoor gets a kernel-level Windows rootkit",
          "link": "https://securelist.com/honeymyte-coolclient-driver-rootkit/121028/",
          "published": "2026-08-14",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-14"
    },
    {
      "value": "eb79558b037669792652a816e2c669de",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "Securelist (Kaspersky)"
      ],
      "articles": [
        {
          "id": "art-48",
          "title": "APT group HoneyMyte upgrades CoolClient: the backdoor gets a kernel-level Windows rootkit",
          "link": "https://securelist.com/honeymyte-coolclient-driver-rootkit/121028/",
          "published": "2026-08-14",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-14"
    },
    {
      "value": "f518d8e5fe70d9090f6280c68a95998f",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "The Hacker News",
        "Securelist (Kaspersky)"
      ],
      "articles": [
        {
          "id": "art-43",
          "title": "Mustang Panda Adds Signed Windows Rootkit to CoolClient Backdoor for Stealth",
          "link": "https://thehackernews.com/2026/08/mustang-panda-adds-signed-windows.html",
          "published": "2026-08-14",
          "sev": "high"
        },
        {
          "id": "art-48",
          "title": "APT group HoneyMyte upgrades CoolClient: the backdoor gets a kernel-level Windows rootkit",
          "link": "https://securelist.com/honeymyte-coolclient-driver-rootkit/121028/",
          "published": "2026-08-14",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-14"
    },
    {
      "value": "01b5c6acb20e41799a0e96d9d1d6e1c44791883706b6285e874fcb15cc93b31a",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "The Hacker News"
      ],
      "articles": [
        {
          "id": "art-49",
          "title": "China-Linked Jewelbug Uses XG-Web for Government Espionage and Crypto Fraud",
          "link": "https://thehackernews.com/2026/08/china-linked-jewelbug-uses-xg-web-for.html",
          "published": "2026-08-14",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-14"
    },
    {
      "value": "09ef7c736bccfafefc44d9910d499173b88063b73b221fc0dc9e9105107e5cff",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "The Hacker News"
      ],
      "articles": [
        {
          "id": "art-49",
          "title": "China-Linked Jewelbug Uses XG-Web for Government Espionage and Crypto Fraud",
          "link": "https://thehackernews.com/2026/08/china-linked-jewelbug-uses-xg-web-for.html",
          "published": "2026-08-14",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-14"
    },
    {
      "value": "0c39264337a1186b2e765e24073399cbdcba118306614eb411e315887af578bd",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "The Hacker News"
      ],
      "articles": [
        {
          "id": "art-49",
          "title": "China-Linked Jewelbug Uses XG-Web for Government Espionage and Crypto Fraud",
          "link": "https://thehackernews.com/2026/08/china-linked-jewelbug-uses-xg-web-for.html",
          "published": "2026-08-14",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-14"
    },
    {
      "value": "153d077bcb58e00f5746573cba25f6b0788b809bf7b2a52fca0dc22d3bb5c94e",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "The Hacker News"
      ],
      "articles": [
        {
          "id": "art-49",
          "title": "China-Linked Jewelbug Uses XG-Web for Government Espionage and Crypto Fraud",
          "link": "https://thehackernews.com/2026/08/china-linked-jewelbug-uses-xg-web-for.html",
          "published": "2026-08-14",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-14"
    },
    {
      "value": "297413a3e49e7353bf484a3eb15ec647de729211059df8fc68678d2378b6f561",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "The Hacker News"
      ],
      "articles": [
        {
          "id": "art-49",
          "title": "China-Linked Jewelbug Uses XG-Web for Government Espionage and Crypto Fraud",
          "link": "https://thehackernews.com/2026/08/china-linked-jewelbug-uses-xg-web-for.html",
          "published": "2026-08-14",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-14"
    },
    {
      "value": "30f5122cc199b9c2e524503b343a9ee13a6f9773dcbc1df82c8b25ad20bca61d",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "The Hacker News"
      ],
      "articles": [
        {
          "id": "art-49",
          "title": "China-Linked Jewelbug Uses XG-Web for Government Espionage and Crypto Fraud",
          "link": "https://thehackernews.com/2026/08/china-linked-jewelbug-uses-xg-web-for.html",
          "published": "2026-08-14",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-14"
    },
    {
      "value": "430f12970f8d58f12edccee9019a1aa90fa232c961449bdcc69c8d348a52cf55",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "The Hacker News"
      ],
      "articles": [
        {
          "id": "art-49",
          "title": "China-Linked Jewelbug Uses XG-Web for Government Espionage and Crypto Fraud",
          "link": "https://thehackernews.com/2026/08/china-linked-jewelbug-uses-xg-web-for.html",
          "published": "2026-08-14",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-14"
    },
    {
      "value": "5ccdf53881f6c758af8d94fe67066af209b4bc0a3cb80b6a4c724fad86eb97ef",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "The Hacker News"
      ],
      "articles": [
        {
          "id": "art-49",
          "title": "China-Linked Jewelbug Uses XG-Web for Government Espionage and Crypto Fraud",
          "link": "https://thehackernews.com/2026/08/china-linked-jewelbug-uses-xg-web-for.html",
          "published": "2026-08-14",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-14"
    },
    {
      "value": "5edb8d1023b8babf302871b68fa2b26d5ca57633f64951922998e8f1d6c8f7ac",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "The Hacker News"
      ],
      "articles": [
        {
          "id": "art-49",
          "title": "China-Linked Jewelbug Uses XG-Web for Government Espionage and Crypto Fraud",
          "link": "https://thehackernews.com/2026/08/china-linked-jewelbug-uses-xg-web-for.html",
          "published": "2026-08-14",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-14"
    },
    {
      "value": "6d5fe6b6a34eeb470798b970b70f41a07ccf59b22f49ad9b3dfff7aa3256f3c2",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "The Hacker News"
      ],
      "articles": [
        {
          "id": "art-49",
          "title": "China-Linked Jewelbug Uses XG-Web for Government Espionage and Crypto Fraud",
          "link": "https://thehackernews.com/2026/08/china-linked-jewelbug-uses-xg-web-for.html",
          "published": "2026-08-14",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-14"
    },
    {
      "value": "97c3a6be1711c5340d8806e4a54f7297f3f763d0aa4240b667f1e4e1f98f2aad",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "The Hacker News"
      ],
      "articles": [
        {
          "id": "art-49",
          "title": "China-Linked Jewelbug Uses XG-Web for Government Espionage and Crypto Fraud",
          "link": "https://thehackernews.com/2026/08/china-linked-jewelbug-uses-xg-web-for.html",
          "published": "2026-08-14",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-14"
    },
    {
      "value": "9b7df409c9a89f7536d3ba7b6d43fb6dbac618c8bb52615ba34cc971ad71bbf3",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "The Hacker News"
      ],
      "articles": [
        {
          "id": "art-49",
          "title": "China-Linked Jewelbug Uses XG-Web for Government Espionage and Crypto Fraud",
          "link": "https://thehackernews.com/2026/08/china-linked-jewelbug-uses-xg-web-for.html",
          "published": "2026-08-14",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-14"
    },
    {
      "value": "9fc2570b7cef51c1b8df116d144d11ff4096357be7d2c4c6367cfc2509cf1bcc",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "Aikido",
        "Unit 42 (Palo Alto)",
        "Cisco Talos",
        "Microsoft Security Blog",
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-39",
          "title": "Top enterprise SCA tools in 2026",
          "link": "https://www.aikido.dev/blog/top-enterprise-sca-tools",
          "published": "2026-08-14",
          "sev": "high"
        },
        {
          "id": "art-108",
          "title": "ChainDrop: Inside a Self-Propagating npm Worm",
          "link": "https://unit42.paloaltonetworks.com/chaindrop-npm-worm-analysis/",
          "published": "2026-08-06",
          "sev": "crit"
        },
        {
          "id": "art-110",
          "title": "Why metaphor may dictate your security strategy",
          "link": "https://blog.talosintelligence.com/why-metaphor-may-dictate-your-security-strategy/",
          "published": "2026-08-06",
          "sev": "high"
        },
        {
          "id": "art-120",
          "title": "ChainDrop supply chain compromise: Anatomy of a self-propagating worm",
          "link": "https://www.microsoft.com/en-us/security/blog/2026/08/04/chaindrop-supply-chain-compromise-anatomy-self-propagating-worm/",
          "published": "2026-08-04",
          "sev": "crit"
        },
        {
          "id": "art-138",
          "title": "A First Look at Evo Agentic AppSec: Agentic Remediation and Malicious Code Defense",
          "link": "https://snyk.io/blog/remediation-agent-malicious-code-defense/",
          "published": "2026-08-04",
          "sev": "high"
        },
        {
          "id": "art-139",
          "title": "Inside the keyv npm Compromise: preinstall Malware, Trusted Provenance, and IDE Hooks",
          "link": "https://snyk.io/blog/inside-keyv-npm-compromise-preinstall-malware-trusted-provenance-ide-hooks/",
          "published": "2026-08-04",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-14"
    },
    {
      "value": "ac3d453d3c9b0310ebb8a67cef35e2ac954d4acdf70cf497fe43a02c7a510813",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "The Hacker News"
      ],
      "articles": [
        {
          "id": "art-49",
          "title": "China-Linked Jewelbug Uses XG-Web for Government Espionage and Crypto Fraud",
          "link": "https://thehackernews.com/2026/08/china-linked-jewelbug-uses-xg-web-for.html",
          "published": "2026-08-14",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-14"
    },
    {
      "value": "b90a4e770869c28fd2140acb3ebdc50c113bb6f096b4bbdb9ac87c349c70e85e",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "The Hacker News"
      ],
      "articles": [
        {
          "id": "art-49",
          "title": "China-Linked Jewelbug Uses XG-Web for Government Espionage and Crypto Fraud",
          "link": "https://thehackernews.com/2026/08/china-linked-jewelbug-uses-xg-web-for.html",
          "published": "2026-08-14",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-14"
    },
    {
      "value": "c11714f9fe2df1ca906585c81498cd77f5ec05b132aab73fa3a71d71d71e42cc",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "The Hacker News"
      ],
      "articles": [
        {
          "id": "art-49",
          "title": "China-Linked Jewelbug Uses XG-Web for Government Espionage and Crypto Fraud",
          "link": "https://thehackernews.com/2026/08/china-linked-jewelbug-uses-xg-web-for.html",
          "published": "2026-08-14",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-14"
    },
    {
      "value": "e2eb7703047b37b28dc34e6990205d758a2454b39bc655b460606745fadcb530",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "The Hacker News"
      ],
      "articles": [
        {
          "id": "art-49",
          "title": "China-Linked Jewelbug Uses XG-Web for Government Espionage and Crypto Fraud",
          "link": "https://thehackernews.com/2026/08/china-linked-jewelbug-uses-xg-web-for.html",
          "published": "2026-08-14",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-14"
    },
    {
      "value": "e6ff096a0562c0042b09d250bd60272ffcd8d72bd95c563842acf765a8dc8bcf",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "The Hacker News"
      ],
      "articles": [
        {
          "id": "art-49",
          "title": "China-Linked Jewelbug Uses XG-Web for Government Espionage and Crypto Fraud",
          "link": "https://thehackernews.com/2026/08/china-linked-jewelbug-uses-xg-web-for.html",
          "published": "2026-08-14",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-14"
    },
    {
      "value": "e782a6d4919f194d41e524ebd6df5894197043cf772fcf60455127b246f302c0",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "The Hacker News"
      ],
      "articles": [
        {
          "id": "art-49",
          "title": "China-Linked Jewelbug Uses XG-Web for Government Espionage and Crypto Fraud",
          "link": "https://thehackernews.com/2026/08/china-linked-jewelbug-uses-xg-web-for.html",
          "published": "2026-08-14",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-14"
    },
    {
      "value": "e7e3b0bcd6798634adf8b49d305f3a7b7682e4b76db549682a183c5a186df4bb",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "The Hacker News"
      ],
      "articles": [
        {
          "id": "art-49",
          "title": "China-Linked Jewelbug Uses XG-Web for Government Espionage and Crypto Fraud",
          "link": "https://thehackernews.com/2026/08/china-linked-jewelbug-uses-xg-web-for.html",
          "published": "2026-08-14",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-14"
    },
    {
      "value": "e809da86bd81463347fa7f922d3e088755a94a331889d32acb55aa8f57778a34",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "The Hacker News"
      ],
      "articles": [
        {
          "id": "art-49",
          "title": "China-Linked Jewelbug Uses XG-Web for Government Espionage and Crypto Fraud",
          "link": "https://thehackernews.com/2026/08/china-linked-jewelbug-uses-xg-web-for.html",
          "published": "2026-08-14",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-14"
    },
    {
      "value": "ea893abf20b00d9bfc042a88fbf7b4bd42e68ce07c116d3e3b002e5b4a853877",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "The Hacker News"
      ],
      "articles": [
        {
          "id": "art-49",
          "title": "China-Linked Jewelbug Uses XG-Web for Government Espionage and Crypto Fraud",
          "link": "https://thehackernews.com/2026/08/china-linked-jewelbug-uses-xg-web-for.html",
          "published": "2026-08-14",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-14"
    },
    {
      "value": "ed96e7f1085a50251eb8967ac53777272a617831084f0edad8a769c583a18869",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "The Hacker News"
      ],
      "articles": [
        {
          "id": "art-49",
          "title": "China-Linked Jewelbug Uses XG-Web for Government Espionage and Crypto Fraud",
          "link": "https://thehackernews.com/2026/08/china-linked-jewelbug-uses-xg-web-for.html",
          "published": "2026-08-14",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-14"
    },
    {
      "value": "f1ef5fe4c0cdcff13cc750c867728b89719f81437bdc49041edd1ae1f3edb4e8",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "The Hacker News"
      ],
      "articles": [
        {
          "id": "art-49",
          "title": "China-Linked Jewelbug Uses XG-Web for Government Espionage and Crypto Fraud",
          "link": "https://thehackernews.com/2026/08/china-linked-jewelbug-uses-xg-web-for.html",
          "published": "2026-08-14",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-14"
    },
    {
      "value": "fd3ca4007b225fdf8de7af4345a19179d5efa8c4bb9205f88cda806e5684b1eb",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "Aikido",
        "Unit 42 (Palo Alto)",
        "Cisco Talos",
        "Microsoft Security Blog"
      ],
      "articles": [
        {
          "id": "art-39",
          "title": "Top enterprise SCA tools in 2026",
          "link": "https://www.aikido.dev/blog/top-enterprise-sca-tools",
          "published": "2026-08-14",
          "sev": "high"
        },
        {
          "id": "art-108",
          "title": "ChainDrop: Inside a Self-Propagating npm Worm",
          "link": "https://unit42.paloaltonetworks.com/chaindrop-npm-worm-analysis/",
          "published": "2026-08-06",
          "sev": "crit"
        },
        {
          "id": "art-110",
          "title": "Why metaphor may dictate your security strategy",
          "link": "https://blog.talosintelligence.com/why-metaphor-may-dictate-your-security-strategy/",
          "published": "2026-08-06",
          "sev": "high"
        },
        {
          "id": "art-120",
          "title": "ChainDrop supply chain compromise: Anatomy of a self-propagating worm",
          "link": "https://www.microsoft.com/en-us/security/blog/2026/08/04/chaindrop-supply-chain-compromise-anatomy-self-propagating-worm/",
          "published": "2026-08-04",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-14"
    },
    {
      "value": "6789x.site",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "The Hacker News"
      ],
      "articles": [
        {
          "id": "art-40",
          "title": "Hackers Spend Nearly $7 Million on Expired Domains to Redirect Traffic to Scams and Malware",
          "link": "https://thehackernews.com/2026/08/hackers-spend-nearly-7-million-on.html",
          "published": "2026-08-14",
          "sev": "high"
        }
      ],
      "first_seen": "2026-08-14"
    },
    {
      "value": "90phutyy.io",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "The Hacker News"
      ],
      "articles": [
        {
          "id": "art-40",
          "title": "Hackers Spend Nearly $7 Million on Expired Domains to Redirect Traffic to Scams and Malware",
          "link": "https://thehackernews.com/2026/08/hackers-spend-nearly-7-million-on.html",
          "published": "2026-08-14",
          "sev": "high"
        }
      ],
      "first_seen": "2026-08-14"
    },
    {
      "value": "animalrampage3d.io",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "The Hacker News"
      ],
      "articles": [
        {
          "id": "art-40",
          "title": "Hackers Spend Nearly $7 Million on Expired Domains to Redirect Traffic to Scams and Malware",
          "link": "https://thehackernews.com/2026/08/hackers-spend-nearly-7-million-on.html",
          "published": "2026-08-14",
          "sev": "high"
        }
      ],
      "first_seen": "2026-08-14"
    },
    {
      "value": "api-score.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "The Hacker News"
      ],
      "articles": [
        {
          "id": "art-40",
          "title": "Hackers Spend Nearly $7 Million on Expired Domains to Redirect Traffic to Scams and Malware",
          "link": "https://thehackernews.com/2026/08/hackers-spend-nearly-7-million-on.html",
          "published": "2026-08-14",
          "sev": "high"
        }
      ],
      "first_seen": "2026-08-14"
    },
    {
      "value": "buffalomarket.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "The Hacker News"
      ],
      "articles": [
        {
          "id": "art-40",
          "title": "Hackers Spend Nearly $7 Million on Expired Domains to Redirect Traffic to Scams and Malware",
          "link": "https://thehackernews.com/2026/08/hackers-spend-nearly-7-million-on.html",
          "published": "2026-08-14",
          "sev": "high"
        }
      ],
      "first_seen": "2026-08-14"
    },
    {
      "value": "cel-robox.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "The Hacker News"
      ],
      "articles": [
        {
          "id": "art-40",
          "title": "Hackers Spend Nearly $7 Million on Expired Domains to Redirect Traffic to Scams and Malware",
          "link": "https://thehackernews.com/2026/08/hackers-spend-nearly-7-million-on.html",
          "published": "2026-08-14",
          "sev": "high"
        }
      ],
      "first_seen": "2026-08-14"
    },
    {
      "value": "colascore.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "The Hacker News"
      ],
      "articles": [
        {
          "id": "art-40",
          "title": "Hackers Spend Nearly $7 Million on Expired Domains to Redirect Traffic to Scams and Malware",
          "link": "https://thehackernews.com/2026/08/hackers-spend-nearly-7-million-on.html",
          "published": "2026-08-14",
          "sev": "high"
        }
      ],
      "first_seen": "2026-08-14"
    },
    {
      "value": "colatv88xb.cc",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "The Hacker News"
      ],
      "articles": [
        {
          "id": "art-40",
          "title": "Hackers Spend Nearly $7 Million on Expired Domains to Redirect Traffic to Scams and Malware",
          "link": "https://thehackernews.com/2026/08/hackers-spend-nearly-7-million-on.html",
          "published": "2026-08-14",
          "sev": "high"
        }
      ],
      "first_seen": "2026-08-14"
    },
    {
      "value": "gene-chips.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "The Hacker News"
      ],
      "articles": [
        {
          "id": "art-40",
          "title": "Hackers Spend Nearly $7 Million on Expired Domains to Redirect Traffic to Scams and Malware",
          "link": "https://thehackernews.com/2026/08/hackers-spend-nearly-7-million-on.html",
          "published": "2026-08-14",
          "sev": "high"
        }
      ],
      "first_seen": "2026-08-14"
    },
    {
      "value": "gvapi.cc",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "The Hacker News"
      ],
      "articles": [
        {
          "id": "art-40",
          "title": "Hackers Spend Nearly $7 Million on Expired Domains to Redirect Traffic to Scams and Malware",
          "link": "https://thehackernews.com/2026/08/hackers-spend-nearly-7-million-on.html",
          "published": "2026-08-14",
          "sev": "high"
        }
      ],
      "first_seen": "2026-08-14"
    },
    {
      "value": "healthymagination.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "The Hacker News"
      ],
      "articles": [
        {
          "id": "art-40",
          "title": "Hackers Spend Nearly $7 Million on Expired Domains to Redirect Traffic to Scams and Malware",
          "link": "https://thehackernews.com/2026/08/hackers-spend-nearly-7-million-on.html",
          "published": "2026-08-14",
          "sev": "high"
        }
      ],
      "first_seen": "2026-08-14"
    },
    {
      "value": "institutobancopalmas.org",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "The Hacker News"
      ],
      "articles": [
        {
          "id": "art-40",
          "title": "Hackers Spend Nearly $7 Million on Expired Domains to Redirect Traffic to Scams and Malware",
          "link": "https://thehackernews.com/2026/08/hackers-spend-nearly-7-million-on.html",
          "published": "2026-08-14",
          "sev": "high"
        }
      ],
      "first_seen": "2026-08-14"
    },
    {
      "value": "jurasudfoot.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "The Hacker News"
      ],
      "articles": [
        {
          "id": "art-40",
          "title": "Hackers Spend Nearly $7 Million on Expired Domains to Redirect Traffic to Scams and Malware",
          "link": "https://thehackernews.com/2026/08/hackers-spend-nearly-7-million-on.html",
          "published": "2026-08-14",
          "sev": "high"
        }
      ],
      "first_seen": "2026-08-14"
    },
    {
      "value": "krogeralbertsons.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "The Hacker News"
      ],
      "articles": [
        {
          "id": "art-40",
          "title": "Hackers Spend Nearly $7 Million on Expired Domains to Redirect Traffic to Scams and Malware",
          "link": "https://thehackernews.com/2026/08/hackers-spend-nearly-7-million-on.html",
          "published": "2026-08-14",
          "sev": "high"
        }
      ],
      "first_seen": "2026-08-14"
    },
    {
      "value": "lfastcdn.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "The Hacker News"
      ],
      "articles": [
        {
          "id": "art-40",
          "title": "Hackers Spend Nearly $7 Million on Expired Domains to Redirect Traffic to Scams and Malware",
          "link": "https://thehackernews.com/2026/08/hackers-spend-nearly-7-million-on.html",
          "published": "2026-08-14",
          "sev": "high"
        }
      ],
      "first_seen": "2026-08-14"
    },
    {
      "value": "maxfactor-international.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "The Hacker News"
      ],
      "articles": [
        {
          "id": "art-40",
          "title": "Hackers Spend Nearly $7 Million on Expired Domains to Redirect Traffic to Scams and Malware",
          "link": "https://thehackernews.com/2026/08/hackers-spend-nearly-7-million-on.html",
          "published": "2026-08-14",
          "sev": "high"
        }
      ],
      "first_seen": "2026-08-14"
    },
    {
      "value": "refvsb.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "The Hacker News"
      ],
      "articles": [
        {
          "id": "art-40",
          "title": "Hackers Spend Nearly $7 Million on Expired Domains to Redirect Traffic to Scams and Malware",
          "link": "https://thehackernews.com/2026/08/hackers-spend-nearly-7-million-on.html",
          "published": "2026-08-14",
          "sev": "high"
        }
      ],
      "first_seen": "2026-08-14"
    },
    {
      "value": "rezilion.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "The Hacker News"
      ],
      "articles": [
        {
          "id": "art-40",
          "title": "Hackers Spend Nearly $7 Million on Expired Domains to Redirect Traffic to Scams and Malware",
          "link": "https://thehackernews.com/2026/08/hackers-spend-nearly-7-million-on.html",
          "published": "2026-08-14",
          "sev": "high"
        }
      ],
      "first_seen": "2026-08-14"
    },
    {
      "value": "sadd.io",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "The Hacker News"
      ],
      "articles": [
        {
          "id": "art-40",
          "title": "Hackers Spend Nearly $7 Million on Expired Domains to Redirect Traffic to Scams and Malware",
          "link": "https://thehackernews.com/2026/08/hackers-spend-nearly-7-million-on.html",
          "published": "2026-08-14",
          "sev": "high"
        }
      ],
      "first_seen": "2026-08-14"
    },
    {
      "value": "samefacts.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "The Hacker News"
      ],
      "articles": [
        {
          "id": "art-40",
          "title": "Hackers Spend Nearly $7 Million on Expired Domains to Redirect Traffic to Scams and Malware",
          "link": "https://thehackernews.com/2026/08/hackers-spend-nearly-7-million-on.html",
          "published": "2026-08-14",
          "sev": "high"
        }
      ],
      "first_seen": "2026-08-14"
    },
    {
      "value": "snsystems.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "The Hacker News"
      ],
      "articles": [
        {
          "id": "art-40",
          "title": "Hackers Spend Nearly $7 Million on Expired Domains to Redirect Traffic to Scams and Malware",
          "link": "https://thehackernews.com/2026/08/hackers-spend-nearly-7-million-on.html",
          "published": "2026-08-14",
          "sev": "high"
        }
      ],
      "first_seen": "2026-08-14"
    },
    {
      "value": "socoliveku.cc",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "The Hacker News"
      ],
      "articles": [
        {
          "id": "art-40",
          "title": "Hackers Spend Nearly $7 Million on Expired Domains to Redirect Traffic to Scams and Malware",
          "link": "https://thehackernews.com/2026/08/hackers-spend-nearly-7-million-on.html",
          "published": "2026-08-14",
          "sev": "high"
        }
      ],
      "first_seen": "2026-08-14"
    },
    {
      "value": "sportliveapiz.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "The Hacker News"
      ],
      "articles": [
        {
          "id": "art-40",
          "title": "Hackers Spend Nearly $7 Million on Expired Domains to Redirect Traffic to Scams and Malware",
          "link": "https://thehackernews.com/2026/08/hackers-spend-nearly-7-million-on.html",
          "published": "2026-08-14",
          "sev": "high"
        }
      ],
      "first_seen": "2026-08-14"
    },
    {
      "value": "stope40.org",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "The Hacker News"
      ],
      "articles": [
        {
          "id": "art-40",
          "title": "Hackers Spend Nearly $7 Million on Expired Domains to Redirect Traffic to Scams and Malware",
          "link": "https://thehackernews.com/2026/08/hackers-spend-nearly-7-million-on.html",
          "published": "2026-08-14",
          "sev": "high"
        }
      ],
      "first_seen": "2026-08-14"
    },
    {
      "value": "trackervsb.live",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "The Hacker News"
      ],
      "articles": [
        {
          "id": "art-40",
          "title": "Hackers Spend Nearly $7 Million on Expired Domains to Redirect Traffic to Scams and Malware",
          "link": "https://thehackernews.com/2026/08/hackers-spend-nearly-7-million-on.html",
          "published": "2026-08-14",
          "sev": "high"
        }
      ],
      "first_seen": "2026-08-14"
    },
    {
      "value": "veinteractive.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "The Hacker News"
      ],
      "articles": [
        {
          "id": "art-40",
          "title": "Hackers Spend Nearly $7 Million on Expired Domains to Redirect Traffic to Scams and Malware",
          "link": "https://thehackernews.com/2026/08/hackers-spend-nearly-7-million-on.html",
          "published": "2026-08-14",
          "sev": "high"
        }
      ],
      "first_seen": "2026-08-14"
    },
    {
      "value": "vsbet276.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "The Hacker News"
      ],
      "articles": [
        {
          "id": "art-40",
          "title": "Hackers Spend Nearly $7 Million on Expired Domains to Redirect Traffic to Scams and Malware",
          "link": "https://thehackernews.com/2026/08/hackers-spend-nearly-7-million-on.html",
          "published": "2026-08-14",
          "sev": "high"
        }
      ],
      "first_seen": "2026-08-14"
    },
    {
      "value": "xemlaibongda.net",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "The Hacker News"
      ],
      "articles": [
        {
          "id": "art-40",
          "title": "Hackers Spend Nearly $7 Million on Expired Domains to Redirect Traffic to Scams and Malware",
          "link": "https://thehackernews.com/2026/08/hackers-spend-nearly-7-million-on.html",
          "published": "2026-08-14",
          "sev": "high"
        }
      ],
      "first_seen": "2026-08-14"
    },
    {
      "value": "xoilacxys.top",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "The Hacker News"
      ],
      "articles": [
        {
          "id": "art-40",
          "title": "Hackers Spend Nearly $7 Million on Expired Domains to Redirect Traffic to Scams and Malware",
          "link": "https://thehackernews.com/2026/08/hackers-spend-nearly-7-million-on.html",
          "published": "2026-08-14",
          "sev": "high"
        }
      ],
      "first_seen": "2026-08-14"
    },
    {
      "value": "xoilacz.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "The Hacker News"
      ],
      "articles": [
        {
          "id": "art-40",
          "title": "Hackers Spend Nearly $7 Million on Expired Domains to Redirect Traffic to Scams and Malware",
          "link": "https://thehackernews.com/2026/08/hackers-spend-nearly-7-million-on.html",
          "published": "2026-08-14",
          "sev": "high"
        }
      ],
      "first_seen": "2026-08-14"
    },
    {
      "value": "0464caa1c45cb753db25a95a30ce0b6814650b6f839a07cf8c2afdc143de7216",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "The Hacker News"
      ],
      "articles": [
        {
          "id": "art-40",
          "title": "Hackers Spend Nearly $7 Million on Expired Domains to Redirect Traffic to Scams and Malware",
          "link": "https://thehackernews.com/2026/08/hackers-spend-nearly-7-million-on.html",
          "published": "2026-08-14",
          "sev": "high"
        }
      ],
      "first_seen": "2026-08-14"
    },
    {
      "value": "14eb4ce01dd4307759887ff819359b70d7d9ff709ecde039a5abc1aac325b128",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "Aikido"
      ],
      "articles": [
        {
          "id": "art-39",
          "title": "Top enterprise SCA tools in 2026",
          "link": "https://www.aikido.dev/blog/top-enterprise-sca-tools",
          "published": "2026-08-14",
          "sev": "high"
        }
      ],
      "first_seen": "2026-08-14"
    },
    {
      "value": "29ac906c8bd801dfe1cb39596197df49f80fff2270b3e7fbab52287c24e4f1a7",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "Aikido"
      ],
      "articles": [
        {
          "id": "art-39",
          "title": "Top enterprise SCA tools in 2026",
          "link": "https://www.aikido.dev/blog/top-enterprise-sca-tools",
          "published": "2026-08-14",
          "sev": "high"
        }
      ],
      "first_seen": "2026-08-14"
    },
    {
      "value": "3f3f42d072bd36860ab7bd7fb5e10ac0d22c741c13c89505ccd6ec0ea572eea7",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "Aikido"
      ],
      "articles": [
        {
          "id": "art-39",
          "title": "Top enterprise SCA tools in 2026",
          "link": "https://www.aikido.dev/blog/top-enterprise-sca-tools",
          "published": "2026-08-14",
          "sev": "high"
        }
      ],
      "first_seen": "2026-08-14"
    },
    {
      "value": "619c56acf572df75b6004a6fc013c80900316a76099b241d64312da3a44f10b4",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "Aikido"
      ],
      "articles": [
        {
          "id": "art-39",
          "title": "Top enterprise SCA tools in 2026",
          "link": "https://www.aikido.dev/blog/top-enterprise-sca-tools",
          "published": "2026-08-14",
          "sev": "high"
        }
      ],
      "first_seen": "2026-08-14"
    },
    {
      "value": "927387d0cfac1118df4b383decc2ea6ba49c9d2f98b47098bcbcba1efc026e1f",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "Aikido"
      ],
      "articles": [
        {
          "id": "art-39",
          "title": "Top enterprise SCA tools in 2026",
          "link": "https://www.aikido.dev/blog/top-enterprise-sca-tools",
          "published": "2026-08-14",
          "sev": "high"
        }
      ],
      "first_seen": "2026-08-14"
    },
    {
      "value": "CVE-2024-6387",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "The Hacker News"
      ],
      "articles": [
        {
          "id": "art-53",
          "title": "New PATCHCORD Backdoor Targets Afghan Telecom and Indian Critical Infrastructure",
          "link": "https://thehackernews.com/2026/08/new-patchcord-backdoor-targets-afghan.html",
          "published": "2026-08-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-13"
    },
    {
      "value": "CVE-2026-20685",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "The Hacker News"
      ],
      "articles": [
        {
          "id": "art-51",
          "title": "ThreatsDay: GhostJacking AI Attacks, EtherHiding ClickFix, Cursor CLI Flaw + 17 More Stories",
          "link": "https://thehackernews.com/2026/08/threatsday-ghostjacking-ai-attacks.html",
          "published": "2026-08-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-13"
    },
    {
      "value": "CVE-2026-55040",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "The Hacker News"
      ],
      "articles": [
        {
          "id": "art-63",
          "title": "Attackers Exploit SharePoint Authentication Bypass After Public PoC Release",
          "link": "https://thehackernews.com/2026/08/attackers-exploit-sharepoint.html",
          "published": "2026-08-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-13"
    },
    {
      "value": "appstoore.solutions",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "The Hacker News"
      ],
      "articles": [
        {
          "id": "art-53",
          "title": "New PATCHCORD Backdoor Targets Afghan Telecom and Indian Critical Infrastructure",
          "link": "https://thehackernews.com/2026/08/new-patchcord-backdoor-targets-afghan.html",
          "published": "2026-08-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-13"
    },
    {
      "value": "ccleanerwind.top",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "The Hacker News"
      ],
      "articles": [
        {
          "id": "art-51",
          "title": "ThreatsDay: GhostJacking AI Attacks, EtherHiding ClickFix, Cursor CLI Flaw + 17 More Stories",
          "link": "https://thehackernews.com/2026/08/threatsday-ghostjacking-ai-attacks.html",
          "published": "2026-08-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-13"
    },
    {
      "value": "city-forum.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "The Hacker News"
      ],
      "articles": [
        {
          "id": "art-51",
          "title": "ThreatsDay: GhostJacking AI Attacks, EtherHiding ClickFix, Cursor CLI Flaw + 17 More Stories",
          "link": "https://thehackernews.com/2026/08/threatsday-ghostjacking-ai-attacks.html",
          "published": "2026-08-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-13"
    },
    {
      "value": "nic-support.site",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "The Hacker News"
      ],
      "articles": [
        {
          "id": "art-53",
          "title": "New PATCHCORD Backdoor Targets Afghan Telecom and Indian Critical Infrastructure",
          "link": "https://thehackernews.com/2026/08/new-patchcord-backdoor-targets-afghan.html",
          "published": "2026-08-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-13"
    },
    {
      "value": "thu-ipad-02.cfd",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "The Hacker News"
      ],
      "articles": [
        {
          "id": "art-51",
          "title": "ThreatsDay: GhostJacking AI Attacks, EtherHiding ClickFix, Cursor CLI Flaw + 17 More Stories",
          "link": "https://thehackernews.com/2026/08/threatsday-ghostjacking-ai-attacks.html",
          "published": "2026-08-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-13"
    },
    {
      "value": "thu-ipad-03.cfd",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "The Hacker News"
      ],
      "articles": [
        {
          "id": "art-51",
          "title": "ThreatsDay: GhostJacking AI Attacks, EtherHiding ClickFix, Cursor CLI Flaw + 17 More Stories",
          "link": "https://thehackernews.com/2026/08/threatsday-ghostjacking-ai-attacks.html",
          "published": "2026-08-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-13"
    },
    {
      "value": "thu-ipad-04.cfd",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "The Hacker News"
      ],
      "articles": [
        {
          "id": "art-51",
          "title": "ThreatsDay: GhostJacking AI Attacks, EtherHiding ClickFix, Cursor CLI Flaw + 17 More Stories",
          "link": "https://thehackernews.com/2026/08/threatsday-ghostjacking-ai-attacks.html",
          "published": "2026-08-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-13"
    },
    {
      "value": "thu-ipad-05.cfd",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "The Hacker News"
      ],
      "articles": [
        {
          "id": "art-51",
          "title": "ThreatsDay: GhostJacking AI Attacks, EtherHiding ClickFix, Cursor CLI Flaw + 17 More Stories",
          "link": "https://thehackernews.com/2026/08/threatsday-ghostjacking-ai-attacks.html",
          "published": "2026-08-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-13"
    },
    {
      "value": "thu-ipad-06.cfd",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "The Hacker News"
      ],
      "articles": [
        {
          "id": "art-51",
          "title": "ThreatsDay: GhostJacking AI Attacks, EtherHiding ClickFix, Cursor CLI Flaw + 17 More Stories",
          "link": "https://thehackernews.com/2026/08/threatsday-ghostjacking-ai-attacks.html",
          "published": "2026-08-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-13"
    },
    {
      "value": "thu-ipad-07.cfd",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "The Hacker News"
      ],
      "articles": [
        {
          "id": "art-51",
          "title": "ThreatsDay: GhostJacking AI Attacks, EtherHiding ClickFix, Cursor CLI Flaw + 17 More Stories",
          "link": "https://thehackernews.com/2026/08/threatsday-ghostjacking-ai-attacks.html",
          "published": "2026-08-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-13"
    },
    {
      "value": "thu-ipad-08.cfd",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "The Hacker News"
      ],
      "articles": [
        {
          "id": "art-51",
          "title": "ThreatsDay: GhostJacking AI Attacks, EtherHiding ClickFix, Cursor CLI Flaw + 17 More Stories",
          "link": "https://thehackernews.com/2026/08/threatsday-ghostjacking-ai-attacks.html",
          "published": "2026-08-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-13"
    },
    {
      "value": "thu-ipad-09.cfd",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "The Hacker News"
      ],
      "articles": [
        {
          "id": "art-51",
          "title": "ThreatsDay: GhostJacking AI Attacks, EtherHiding ClickFix, Cursor CLI Flaw + 17 More Stories",
          "link": "https://thehackernews.com/2026/08/threatsday-ghostjacking-ai-attacks.html",
          "published": "2026-08-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-13"
    },
    {
      "value": "thu-ipad-10.cfd",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "The Hacker News"
      ],
      "articles": [
        {
          "id": "art-51",
          "title": "ThreatsDay: GhostJacking AI Attacks, EtherHiding ClickFix, Cursor CLI Flaw + 17 More Stories",
          "link": "https://thehackernews.com/2026/08/threatsday-ghostjacking-ai-attacks.html",
          "published": "2026-08-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-13"
    },
    {
      "value": "thu-ipad-11.cfd",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "The Hacker News"
      ],
      "articles": [
        {
          "id": "art-51",
          "title": "ThreatsDay: GhostJacking AI Attacks, EtherHiding ClickFix, Cursor CLI Flaw + 17 More Stories",
          "link": "https://thehackernews.com/2026/08/threatsday-ghostjacking-ai-attacks.html",
          "published": "2026-08-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-13"
    },
    {
      "value": "thu-ipad-12.cfd",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "The Hacker News"
      ],
      "articles": [
        {
          "id": "art-51",
          "title": "ThreatsDay: GhostJacking AI Attacks, EtherHiding ClickFix, Cursor CLI Flaw + 17 More Stories",
          "link": "https://thehackernews.com/2026/08/threatsday-ghostjacking-ai-attacks.html",
          "published": "2026-08-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-13"
    },
    {
      "value": "WIN-FG3H2SKPOTA.TESTDOMAIN2.fritz.box",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "The Hacker News"
      ],
      "articles": [
        {
          "id": "art-63",
          "title": "Attackers Exploit SharePoint Authentication Bypass After Public PoC Release",
          "link": "https://thehackernews.com/2026/08/attackers-exploit-sharepoint.html",
          "published": "2026-08-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-13"
    },
    {
      "value": "104.250.148.58",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "The Hacker News"
      ],
      "articles": [
        {
          "id": "art-59",
          "title": "North Korean Remote Workers Are Infiltrating Government and Businesses: How to Expose Them Before Hiring",
          "link": "https://thehackernews.com/2026/08/north-korean-remote-workers-are.html",
          "published": "2026-08-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-13"
    },
    {
      "value": "107.150.38.250",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "The Hacker News"
      ],
      "articles": [
        {
          "id": "art-59",
          "title": "North Korean Remote Workers Are Infiltrating Government and Businesses: How to Expose Them Before Hiring",
          "link": "https://thehackernews.com/2026/08/north-korean-remote-workers-are.html",
          "published": "2026-08-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-13"
    },
    {
      "value": "158.220.87.79",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "The Hacker News"
      ],
      "articles": [
        {
          "id": "art-51",
          "title": "ThreatsDay: GhostJacking AI Attacks, EtherHiding ClickFix, Cursor CLI Flaw + 17 More Stories",
          "link": "https://thehackernews.com/2026/08/threatsday-ghostjacking-ai-attacks.html",
          "published": "2026-08-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-13"
    },
    {
      "value": "185.100.87.116",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "The Hacker News"
      ],
      "articles": [
        {
          "id": "art-58",
          "title": "WindRelay Android Malware Turns Victims' Phones Into NFC Relays for Payment Fraud",
          "link": "https://thehackernews.com/2026/08/windrelay-android-malware-turns-victims.html",
          "published": "2026-08-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-13"
    },
    {
      "value": "185.100.87.223",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "The Hacker News"
      ],
      "articles": [
        {
          "id": "art-58",
          "title": "WindRelay Android Malware Turns Victims' Phones Into NFC Relays for Payment Fraud",
          "link": "https://thehackernews.com/2026/08/windrelay-android-malware-turns-victims.html",
          "published": "2026-08-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-13"
    },
    {
      "value": "185.152.67.39",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "The Hacker News"
      ],
      "articles": [
        {
          "id": "art-59",
          "title": "North Korean Remote Workers Are Infiltrating Government and Businesses: How to Expose Them Before Hiring",
          "link": "https://thehackernews.com/2026/08/north-korean-remote-workers-are.html",
          "published": "2026-08-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-13"
    },
    {
      "value": "192.200.115.226",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "The Hacker News"
      ],
      "articles": [
        {
          "id": "art-59",
          "title": "North Korean Remote Workers Are Infiltrating Government and Businesses: How to Expose Them Before Hiring",
          "link": "https://thehackernews.com/2026/08/north-korean-remote-workers-are.html",
          "published": "2026-08-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-13"
    },
    {
      "value": "199.168.112.175",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "The Hacker News"
      ],
      "articles": [
        {
          "id": "art-59",
          "title": "North Korean Remote Workers Are Infiltrating Government and Businesses: How to Expose Them Before Hiring",
          "link": "https://thehackernews.com/2026/08/north-korean-remote-workers-are.html",
          "published": "2026-08-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-13"
    },
    {
      "value": "206.217.134.34",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "The Hacker News"
      ],
      "articles": [
        {
          "id": "art-59",
          "title": "North Korean Remote Workers Are Infiltrating Government and Businesses: How to Expose Them Before Hiring",
          "link": "https://thehackernews.com/2026/08/north-korean-remote-workers-are.html",
          "published": "2026-08-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-13"
    },
    {
      "value": "213.218.160.48",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "The Hacker News"
      ],
      "articles": [
        {
          "id": "art-58",
          "title": "WindRelay Android Malware Turns Victims' Phones Into NFC Relays for Payment Fraud",
          "link": "https://thehackernews.com/2026/08/windrelay-android-malware-turns-victims.html",
          "published": "2026-08-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-13"
    },
    {
      "value": "45.77.71.42",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "The Hacker News"
      ],
      "articles": [
        {
          "id": "art-59",
          "title": "North Korean Remote Workers Are Infiltrating Government and Businesses: How to Expose Them Before Hiring",
          "link": "https://thehackernews.com/2026/08/north-korean-remote-workers-are.html",
          "published": "2026-08-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-13"
    },
    {
      "value": "46.30.188.13",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "The Hacker News"
      ],
      "articles": [
        {
          "id": "art-53",
          "title": "New PATCHCORD Backdoor Targets Afghan Telecom and Indian Critical Infrastructure",
          "link": "https://thehackernews.com/2026/08/new-patchcord-backdoor-targets-afghan.html",
          "published": "2026-08-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-13"
    },
    {
      "value": "62.33.223.165",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "The Hacker News"
      ],
      "articles": [
        {
          "id": "art-59",
          "title": "North Korean Remote Workers Are Infiltrating Government and Businesses: How to Expose Them Before Hiring",
          "link": "https://thehackernews.com/2026/08/north-korean-remote-workers-are.html",
          "published": "2026-08-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-13"
    },
    {
      "value": "88.86.124.114",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "The Hacker News"
      ],
      "articles": [
        {
          "id": "art-58",
          "title": "WindRelay Android Malware Turns Victims' Phones Into NFC Relays for Payment Fraud",
          "link": "https://thehackernews.com/2026/08/windrelay-android-malware-turns-victims.html",
          "published": "2026-08-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-13"
    },
    {
      "value": "89.187.185.11",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "The Hacker News"
      ],
      "articles": [
        {
          "id": "art-59",
          "title": "North Korean Remote Workers Are Infiltrating Government and Businesses: How to Expose Them Before Hiring",
          "link": "https://thehackernews.com/2026/08/north-korean-remote-workers-are.html",
          "published": "2026-08-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-13"
    },
    {
      "value": "2915b3f8b703eb744fc54c81f4a9c67f",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "Cisco Talos"
      ],
      "articles": [
        {
          "id": "art-52",
          "title": "Curiouser and Curiouser",
          "link": "https://blog.talosintelligence.com/curiouser-and-curiouser/",
          "published": "2026-08-13",
          "sev": "high"
        },
        {
          "id": "art-110",
          "title": "Why metaphor may dictate your security strategy",
          "link": "https://blog.talosintelligence.com/why-metaphor-may-dictate-your-security-strategy/",
          "published": "2026-08-06",
          "sev": "high"
        },
        {
          "id": "art-165",
          "title": "You were onto something with \u201cIt\u2019s the Climb,\u201d Miley",
          "link": "https://blog.talosintelligence.com/you-were-onto-something-with-its-the-climb-miley/",
          "published": "2026-07-30",
          "sev": "crit"
        },
        {
          "id": "art-213",
          "title": "Don\u2019t swing at everything",
          "link": "https://blog.talosintelligence.com/dont-swing-at-everything/",
          "published": "2026-07-23",
          "sev": "crit"
        },
        {
          "id": "art-253",
          "title": "Begun, the Patch Wars have",
          "link": "https://blog.talosintelligence.com/begun-the-patch-wars-have/",
          "published": "2026-07-16",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-13"
    },
    {
      "value": "38de5b216c33833af710e88f7f64fc98",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "Cisco Talos"
      ],
      "articles": [
        {
          "id": "art-52",
          "title": "Curiouser and Curiouser",
          "link": "https://blog.talosintelligence.com/curiouser-and-curiouser/",
          "published": "2026-08-13",
          "sev": "high"
        },
        {
          "id": "art-110",
          "title": "Why metaphor may dictate your security strategy",
          "link": "https://blog.talosintelligence.com/why-metaphor-may-dictate-your-security-strategy/",
          "published": "2026-08-06",
          "sev": "high"
        },
        {
          "id": "art-165",
          "title": "You were onto something with \u201cIt\u2019s the Climb,\u201d Miley",
          "link": "https://blog.talosintelligence.com/you-were-onto-something-with-its-the-climb-miley/",
          "published": "2026-07-30",
          "sev": "crit"
        },
        {
          "id": "art-213",
          "title": "Don\u2019t swing at everything",
          "link": "https://blog.talosintelligence.com/dont-swing-at-everything/",
          "published": "2026-07-23",
          "sev": "crit"
        },
        {
          "id": "art-253",
          "title": "Begun, the Patch Wars have",
          "link": "https://blog.talosintelligence.com/begun-the-patch-wars-have/",
          "published": "2026-07-16",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-13"
    },
    {
      "value": "7bdbd180c081fa63ca94f9c22c457376",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "Cisco Talos",
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-52",
          "title": "Curiouser and Curiouser",
          "link": "https://blog.talosintelligence.com/curiouser-and-curiouser/",
          "published": "2026-08-13",
          "sev": "high"
        },
        {
          "id": "art-110",
          "title": "Why metaphor may dictate your security strategy",
          "link": "https://blog.talosintelligence.com/why-metaphor-may-dictate-your-security-strategy/",
          "published": "2026-08-06",
          "sev": "high"
        },
        {
          "id": "art-165",
          "title": "You were onto something with \u201cIt\u2019s the Climb,\u201d Miley",
          "link": "https://blog.talosintelligence.com/you-were-onto-something-with-its-the-climb-miley/",
          "published": "2026-07-30",
          "sev": "crit"
        },
        {
          "id": "art-1248",
          "title": "CISA KEV: CVE-2024-6670 \u2014 Progress WhatsUp Gold SQL Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-09-16",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-13"
    },
    {
      "value": "c2efb2dcacba6d3ccc175b6ce1b7ed0a",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "Cisco Talos"
      ],
      "articles": [
        {
          "id": "art-52",
          "title": "Curiouser and Curiouser",
          "link": "https://blog.talosintelligence.com/curiouser-and-curiouser/",
          "published": "2026-08-13",
          "sev": "high"
        },
        {
          "id": "art-110",
          "title": "Why metaphor may dictate your security strategy",
          "link": "https://blog.talosintelligence.com/why-metaphor-may-dictate-your-security-strategy/",
          "published": "2026-08-06",
          "sev": "high"
        },
        {
          "id": "art-165",
          "title": "You were onto something with \u201cIt\u2019s the Climb,\u201d Miley",
          "link": "https://blog.talosintelligence.com/you-were-onto-something-with-its-the-climb-miley/",
          "published": "2026-07-30",
          "sev": "crit"
        },
        {
          "id": "art-213",
          "title": "Don\u2019t swing at everything",
          "link": "https://blog.talosintelligence.com/dont-swing-at-everything/",
          "published": "2026-07-23",
          "sev": "crit"
        },
        {
          "id": "art-253",
          "title": "Begun, the Patch Wars have",
          "link": "https://blog.talosintelligence.com/begun-the-patch-wars-have/",
          "published": "2026-07-16",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-13"
    },
    {
      "value": "11f9fb29f2cc142e81c804f53599ae36282c95b3",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "The Hacker News"
      ],
      "articles": [
        {
          "id": "art-58",
          "title": "WindRelay Android Malware Turns Victims' Phones Into NFC Relays for Payment Fraud",
          "link": "https://thehackernews.com/2026/08/windrelay-android-malware-turns-victims.html",
          "published": "2026-08-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-13"
    },
    {
      "value": "1371b2b2da10ed178d26a7aad191634553f865ae",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "The Hacker News"
      ],
      "articles": [
        {
          "id": "art-58",
          "title": "WindRelay Android Malware Turns Victims' Phones Into NFC Relays for Payment Fraud",
          "link": "https://thehackernews.com/2026/08/windrelay-android-malware-turns-victims.html",
          "published": "2026-08-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-13"
    },
    {
      "value": "193078cda795dc2f12983e9b66821f7e67c6495d",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "The Hacker News"
      ],
      "articles": [
        {
          "id": "art-58",
          "title": "WindRelay Android Malware Turns Victims' Phones Into NFC Relays for Payment Fraud",
          "link": "https://thehackernews.com/2026/08/windrelay-android-malware-turns-victims.html",
          "published": "2026-08-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-13"
    },
    {
      "value": "1eac0c636edf181eec0315ffe3b5b1e310b1a352",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "The Hacker News"
      ],
      "articles": [
        {
          "id": "art-58",
          "title": "WindRelay Android Malware Turns Victims' Phones Into NFC Relays for Payment Fraud",
          "link": "https://thehackernews.com/2026/08/windrelay-android-malware-turns-victims.html",
          "published": "2026-08-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-13"
    },
    {
      "value": "217ab41d543278d0ecce797a71ef38a6bc1493fe",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "The Hacker News"
      ],
      "articles": [
        {
          "id": "art-58",
          "title": "WindRelay Android Malware Turns Victims' Phones Into NFC Relays for Payment Fraud",
          "link": "https://thehackernews.com/2026/08/windrelay-android-malware-turns-victims.html",
          "published": "2026-08-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-13"
    },
    {
      "value": "22fa5c967b0775c3f3398dcf5dbb46ff80e1708b",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "The Hacker News"
      ],
      "articles": [
        {
          "id": "art-58",
          "title": "WindRelay Android Malware Turns Victims' Phones Into NFC Relays for Payment Fraud",
          "link": "https://thehackernews.com/2026/08/windrelay-android-malware-turns-victims.html",
          "published": "2026-08-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-13"
    },
    {
      "value": "294ecf0550308dff9df0eea86ca127c064b3bfb8",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "The Hacker News"
      ],
      "articles": [
        {
          "id": "art-58",
          "title": "WindRelay Android Malware Turns Victims' Phones Into NFC Relays for Payment Fraud",
          "link": "https://thehackernews.com/2026/08/windrelay-android-malware-turns-victims.html",
          "published": "2026-08-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-13"
    },
    {
      "value": "38ca1bc31ccdc1c650720abd76bcc619532c0166",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "The Hacker News"
      ],
      "articles": [
        {
          "id": "art-58",
          "title": "WindRelay Android Malware Turns Victims' Phones Into NFC Relays for Payment Fraud",
          "link": "https://thehackernews.com/2026/08/windrelay-android-malware-turns-victims.html",
          "published": "2026-08-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-13"
    },
    {
      "value": "39060c673aefa0902cb5fc787fa53364cad9ed6f",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "The Hacker News"
      ],
      "articles": [
        {
          "id": "art-58",
          "title": "WindRelay Android Malware Turns Victims' Phones Into NFC Relays for Payment Fraud",
          "link": "https://thehackernews.com/2026/08/windrelay-android-malware-turns-victims.html",
          "published": "2026-08-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-13"
    },
    {
      "value": "48d011117eacf57128c7e473bb5d4d69e3d41ef6",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "The Hacker News"
      ],
      "articles": [
        {
          "id": "art-58",
          "title": "WindRelay Android Malware Turns Victims' Phones Into NFC Relays for Payment Fraud",
          "link": "https://thehackernews.com/2026/08/windrelay-android-malware-turns-victims.html",
          "published": "2026-08-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-13"
    },
    {
      "value": "50cf07b97ef999e9fc5c7efae19d0e5f39db39fa",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "The Hacker News"
      ],
      "articles": [
        {
          "id": "art-58",
          "title": "WindRelay Android Malware Turns Victims' Phones Into NFC Relays for Payment Fraud",
          "link": "https://thehackernews.com/2026/08/windrelay-android-malware-turns-victims.html",
          "published": "2026-08-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-13"
    },
    {
      "value": "56b819cb285dbdbc307268b4fadbddaa61319bb8",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "The Hacker News"
      ],
      "articles": [
        {
          "id": "art-58",
          "title": "WindRelay Android Malware Turns Victims' Phones Into NFC Relays for Payment Fraud",
          "link": "https://thehackernews.com/2026/08/windrelay-android-malware-turns-victims.html",
          "published": "2026-08-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-13"
    },
    {
      "value": "65ca7e9363539282c2670dfab100b75c9bfb6253",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "The Hacker News"
      ],
      "articles": [
        {
          "id": "art-58",
          "title": "WindRelay Android Malware Turns Victims' Phones Into NFC Relays for Payment Fraud",
          "link": "https://thehackernews.com/2026/08/windrelay-android-malware-turns-victims.html",
          "published": "2026-08-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-13"
    },
    {
      "value": "67e2a1e8ab963086bb768b28307cf58dadb0acc7",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "The Hacker News"
      ],
      "articles": [
        {
          "id": "art-58",
          "title": "WindRelay Android Malware Turns Victims' Phones Into NFC Relays for Payment Fraud",
          "link": "https://thehackernews.com/2026/08/windrelay-android-malware-turns-victims.html",
          "published": "2026-08-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-13"
    },
    {
      "value": "6feeba25748996d3928f11ef774122e02b4b8850",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "The Hacker News"
      ],
      "articles": [
        {
          "id": "art-58",
          "title": "WindRelay Android Malware Turns Victims' Phones Into NFC Relays for Payment Fraud",
          "link": "https://thehackernews.com/2026/08/windrelay-android-malware-turns-victims.html",
          "published": "2026-08-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-13"
    },
    {
      "value": "82a35dd0ec20791bc3161a87fdb6caa68fd3d4a6",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "The Hacker News"
      ],
      "articles": [
        {
          "id": "art-58",
          "title": "WindRelay Android Malware Turns Victims' Phones Into NFC Relays for Payment Fraud",
          "link": "https://thehackernews.com/2026/08/windrelay-android-malware-turns-victims.html",
          "published": "2026-08-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-13"
    },
    {
      "value": "850680506df7892d43b3382f0f89a06ef18837c7",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "The Hacker News"
      ],
      "articles": [
        {
          "id": "art-58",
          "title": "WindRelay Android Malware Turns Victims' Phones Into NFC Relays for Payment Fraud",
          "link": "https://thehackernews.com/2026/08/windrelay-android-malware-turns-victims.html",
          "published": "2026-08-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-13"
    },
    {
      "value": "852322e063872a025b711d5adf08531eac36a265",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "The Hacker News"
      ],
      "articles": [
        {
          "id": "art-58",
          "title": "WindRelay Android Malware Turns Victims' Phones Into NFC Relays for Payment Fraud",
          "link": "https://thehackernews.com/2026/08/windrelay-android-malware-turns-victims.html",
          "published": "2026-08-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-13"
    },
    {
      "value": "8e665c12b7d8e80c72d86ed4425663ecd74e453c",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "The Hacker News"
      ],
      "articles": [
        {
          "id": "art-58",
          "title": "WindRelay Android Malware Turns Victims' Phones Into NFC Relays for Payment Fraud",
          "link": "https://thehackernews.com/2026/08/windrelay-android-malware-turns-victims.html",
          "published": "2026-08-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-13"
    },
    {
      "value": "91e66d640b2a570bd83b408b51ebbf21e95e7469",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "The Hacker News"
      ],
      "articles": [
        {
          "id": "art-58",
          "title": "WindRelay Android Malware Turns Victims' Phones Into NFC Relays for Payment Fraud",
          "link": "https://thehackernews.com/2026/08/windrelay-android-malware-turns-victims.html",
          "published": "2026-08-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-13"
    },
    {
      "value": "a1574476a616599a202cc731a6d5dbf9b3a635f0",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "The Hacker News"
      ],
      "articles": [
        {
          "id": "art-58",
          "title": "WindRelay Android Malware Turns Victims' Phones Into NFC Relays for Payment Fraud",
          "link": "https://thehackernews.com/2026/08/windrelay-android-malware-turns-victims.html",
          "published": "2026-08-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-13"
    },
    {
      "value": "a72089566a711ed0781d5a36e3c289de0de13e2d",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "The Hacker News"
      ],
      "articles": [
        {
          "id": "art-58",
          "title": "WindRelay Android Malware Turns Victims' Phones Into NFC Relays for Payment Fraud",
          "link": "https://thehackernews.com/2026/08/windrelay-android-malware-turns-victims.html",
          "published": "2026-08-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-13"
    },
    {
      "value": "bc2bce53d71533c2eb1ccc30fd252ea2774d0100",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "The Hacker News"
      ],
      "articles": [
        {
          "id": "art-58",
          "title": "WindRelay Android Malware Turns Victims' Phones Into NFC Relays for Payment Fraud",
          "link": "https://thehackernews.com/2026/08/windrelay-android-malware-turns-victims.html",
          "published": "2026-08-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-13"
    },
    {
      "value": "bce3d9b06a3fc2312fe5be213f3d98b9350c9b22",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "The Hacker News"
      ],
      "articles": [
        {
          "id": "art-58",
          "title": "WindRelay Android Malware Turns Victims' Phones Into NFC Relays for Payment Fraud",
          "link": "https://thehackernews.com/2026/08/windrelay-android-malware-turns-victims.html",
          "published": "2026-08-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-13"
    },
    {
      "value": "dfd19ee8b550f21b99d63ce87d039d1e8e1e111b",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "The Hacker News"
      ],
      "articles": [
        {
          "id": "art-58",
          "title": "WindRelay Android Malware Turns Victims' Phones Into NFC Relays for Payment Fraud",
          "link": "https://thehackernews.com/2026/08/windrelay-android-malware-turns-victims.html",
          "published": "2026-08-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-13"
    },
    {
      "value": "e05575afe5a01d150daa8b4bb935213cc0e538f6",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "The Hacker News"
      ],
      "articles": [
        {
          "id": "art-58",
          "title": "WindRelay Android Malware Turns Victims' Phones Into NFC Relays for Payment Fraud",
          "link": "https://thehackernews.com/2026/08/windrelay-android-malware-turns-victims.html",
          "published": "2026-08-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-13"
    },
    {
      "value": "e2e836d16a1b50d4d091f7ae507b82c0a8e05376",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "The Hacker News"
      ],
      "articles": [
        {
          "id": "art-58",
          "title": "WindRelay Android Malware Turns Victims' Phones Into NFC Relays for Payment Fraud",
          "link": "https://thehackernews.com/2026/08/windrelay-android-malware-turns-victims.html",
          "published": "2026-08-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-13"
    },
    {
      "value": "ea2be784b2c08cd6f116e14079d6583ba606c556",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "The Hacker News"
      ],
      "articles": [
        {
          "id": "art-58",
          "title": "WindRelay Android Malware Turns Victims' Phones Into NFC Relays for Payment Fraud",
          "link": "https://thehackernews.com/2026/08/windrelay-android-malware-turns-victims.html",
          "published": "2026-08-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-13"
    },
    {
      "value": "ec730da64f9feae4259ebc88113c5cebdf2b1ad7",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "The Hacker News"
      ],
      "articles": [
        {
          "id": "art-58",
          "title": "WindRelay Android Malware Turns Victims' Phones Into NFC Relays for Payment Fraud",
          "link": "https://thehackernews.com/2026/08/windrelay-android-malware-turns-victims.html",
          "published": "2026-08-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-13"
    },
    {
      "value": "1774e15e8eb96eb89bc03cb4768fc0620e10c09c5f795297f36dcc2aa5d9dd94",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "The Hacker News"
      ],
      "articles": [
        {
          "id": "art-53",
          "title": "New PATCHCORD Backdoor Targets Afghan Telecom and Indian Critical Infrastructure",
          "link": "https://thehackernews.com/2026/08/new-patchcord-backdoor-targets-afghan.html",
          "published": "2026-08-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-13"
    },
    {
      "value": "378484112b4e837d3850b5b0802fc509202c232bb124d6944a59fe66525ba668",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "The Hacker News"
      ],
      "articles": [
        {
          "id": "art-53",
          "title": "New PATCHCORD Backdoor Targets Afghan Telecom and Indian Critical Infrastructure",
          "link": "https://thehackernews.com/2026/08/new-patchcord-backdoor-targets-afghan.html",
          "published": "2026-08-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-13"
    },
    {
      "value": "5e17360d32e9b272bb7e1b97c8e4dca34622ec9ce08fd240fe2758cc3f67dc4a",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "The Hacker News"
      ],
      "articles": [
        {
          "id": "art-53",
          "title": "New PATCHCORD Backdoor Targets Afghan Telecom and Indian Critical Infrastructure",
          "link": "https://thehackernews.com/2026/08/new-patchcord-backdoor-targets-afghan.html",
          "published": "2026-08-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-13"
    },
    {
      "value": "90b1456cdbe6bc2779ea0b4736ed9a998a71ae37390331b6ba87e389a49d3d59",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "Cisco Talos"
      ],
      "articles": [
        {
          "id": "art-52",
          "title": "Curiouser and Curiouser",
          "link": "https://blog.talosintelligence.com/curiouser-and-curiouser/",
          "published": "2026-08-13",
          "sev": "high"
        },
        {
          "id": "art-110",
          "title": "Why metaphor may dictate your security strategy",
          "link": "https://blog.talosintelligence.com/why-metaphor-may-dictate-your-security-strategy/",
          "published": "2026-08-06",
          "sev": "high"
        },
        {
          "id": "art-165",
          "title": "You were onto something with \u201cIt\u2019s the Climb,\u201d Miley",
          "link": "https://blog.talosintelligence.com/you-were-onto-something-with-its-the-climb-miley/",
          "published": "2026-07-30",
          "sev": "crit"
        },
        {
          "id": "art-213",
          "title": "Don\u2019t swing at everything",
          "link": "https://blog.talosintelligence.com/dont-swing-at-everything/",
          "published": "2026-07-23",
          "sev": "crit"
        },
        {
          "id": "art-253",
          "title": "Begun, the Patch Wars have",
          "link": "https://blog.talosintelligence.com/begun-the-patch-wars-have/",
          "published": "2026-07-16",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-13"
    },
    {
      "value": "9896a6fcb9bb5ac1ec5297b4a65be3f647589adf7c37b45f3f7466decd6a4a7f",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "Cisco Talos"
      ],
      "articles": [
        {
          "id": "art-52",
          "title": "Curiouser and Curiouser",
          "link": "https://blog.talosintelligence.com/curiouser-and-curiouser/",
          "published": "2026-08-13",
          "sev": "high"
        },
        {
          "id": "art-110",
          "title": "Why metaphor may dictate your security strategy",
          "link": "https://blog.talosintelligence.com/why-metaphor-may-dictate-your-security-strategy/",
          "published": "2026-08-06",
          "sev": "high"
        },
        {
          "id": "art-165",
          "title": "You were onto something with \u201cIt\u2019s the Climb,\u201d Miley",
          "link": "https://blog.talosintelligence.com/you-were-onto-something-with-its-the-climb-miley/",
          "published": "2026-07-30",
          "sev": "crit"
        },
        {
          "id": "art-213",
          "title": "Don\u2019t swing at everything",
          "link": "https://blog.talosintelligence.com/dont-swing-at-everything/",
          "published": "2026-07-23",
          "sev": "crit"
        },
        {
          "id": "art-253",
          "title": "Begun, the Patch Wars have",
          "link": "https://blog.talosintelligence.com/begun-the-patch-wars-have/",
          "published": "2026-07-16",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-13"
    },
    {
      "value": "9f1f11a708d393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "Cisco Talos"
      ],
      "articles": [
        {
          "id": "art-52",
          "title": "Curiouser and Curiouser",
          "link": "https://blog.talosintelligence.com/curiouser-and-curiouser/",
          "published": "2026-08-13",
          "sev": "high"
        },
        {
          "id": "art-110",
          "title": "Why metaphor may dictate your security strategy",
          "link": "https://blog.talosintelligence.com/why-metaphor-may-dictate-your-security-strategy/",
          "published": "2026-08-06",
          "sev": "high"
        },
        {
          "id": "art-165",
          "title": "You were onto something with \u201cIt\u2019s the Climb,\u201d Miley",
          "link": "https://blog.talosintelligence.com/you-were-onto-something-with-its-the-climb-miley/",
          "published": "2026-07-30",
          "sev": "crit"
        },
        {
          "id": "art-213",
          "title": "Don\u2019t swing at everything",
          "link": "https://blog.talosintelligence.com/dont-swing-at-everything/",
          "published": "2026-07-23",
          "sev": "crit"
        },
        {
          "id": "art-253",
          "title": "Begun, the Patch Wars have",
          "link": "https://blog.talosintelligence.com/begun-the-patch-wars-have/",
          "published": "2026-07-16",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-13"
    },
    {
      "value": "a31f222fc283227f5e7988d1ad9c0aecd66d58bb7b4d8518ae23e110308dbf91",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "Cisco Talos",
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-52",
          "title": "Curiouser and Curiouser",
          "link": "https://blog.talosintelligence.com/curiouser-and-curiouser/",
          "published": "2026-08-13",
          "sev": "high"
        },
        {
          "id": "art-110",
          "title": "Why metaphor may dictate your security strategy",
          "link": "https://blog.talosintelligence.com/why-metaphor-may-dictate-your-security-strategy/",
          "published": "2026-08-06",
          "sev": "high"
        },
        {
          "id": "art-165",
          "title": "You were onto something with \u201cIt\u2019s the Climb,\u201d Miley",
          "link": "https://blog.talosintelligence.com/you-were-onto-something-with-its-the-climb-miley/",
          "published": "2026-07-30",
          "sev": "crit"
        },
        {
          "id": "art-1248",
          "title": "CISA KEV: CVE-2024-6670 \u2014 Progress WhatsUp Gold SQL Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-09-16",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-13"
    },
    {
      "value": "cf7184c0dfe882dc6e3016f16e4ede32b75d7648f83d6f4f87eb6a703be7b8d6",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "The Hacker News"
      ],
      "articles": [
        {
          "id": "art-53",
          "title": "New PATCHCORD Backdoor Targets Afghan Telecom and Indian Critical Infrastructure",
          "link": "https://thehackernews.com/2026/08/new-patchcord-backdoor-targets-afghan.html",
          "published": "2026-08-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-13"
    },
    {
      "value": "ea0934472121848b80455581d289ce4480b1e5cc05678c1b90ecfc465b5ec350",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "The Hacker News"
      ],
      "articles": [
        {
          "id": "art-53",
          "title": "New PATCHCORD Backdoor Targets Afghan Telecom and Indian Critical Infrastructure",
          "link": "https://thehackernews.com/2026/08/new-patchcord-backdoor-targets-afghan.html",
          "published": "2026-08-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-13"
    },
    {
      "value": "managementapiservice.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "Securelist (Kaspersky)"
      ],
      "articles": [
        {
          "id": "art-62",
          "title": "Armored Likho expands its cyber-espionage toolkit",
          "link": "https://securelist.com/armored-likho-still-toolkit/121033/",
          "published": "2026-08-13",
          "sev": "high"
        }
      ],
      "first_seen": "2026-08-13"
    },
    {
      "value": "orderapiserver.info",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "Securelist (Kaspersky)"
      ],
      "articles": [
        {
          "id": "art-62",
          "title": "Armored Likho expands its cyber-espionage toolkit",
          "link": "https://securelist.com/armored-likho-still-toolkit/121033/",
          "published": "2026-08-13",
          "sev": "high"
        }
      ],
      "first_seen": "2026-08-13"
    },
    {
      "value": "screenserv.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "Securelist (Kaspersky)"
      ],
      "articles": [
        {
          "id": "art-62",
          "title": "Armored Likho expands its cyber-espionage toolkit",
          "link": "https://securelist.com/armored-likho-still-toolkit/121033/",
          "published": "2026-08-13",
          "sev": "high"
        }
      ],
      "first_seen": "2026-08-13"
    },
    {
      "value": "service8date.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "Securelist (Kaspersky)"
      ],
      "articles": [
        {
          "id": "art-62",
          "title": "Armored Likho expands its cyber-espionage toolkit",
          "link": "https://securelist.com/armored-likho-still-toolkit/121033/",
          "published": "2026-08-13",
          "sev": "high"
        }
      ],
      "first_seen": "2026-08-13"
    },
    {
      "value": "srwinservice.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "Securelist (Kaspersky)"
      ],
      "articles": [
        {
          "id": "art-62",
          "title": "Armored Likho expands its cyber-espionage toolkit",
          "link": "https://securelist.com/armored-likho-still-toolkit/121033/",
          "published": "2026-08-13",
          "sev": "high"
        }
      ],
      "first_seen": "2026-08-13"
    },
    {
      "value": "tg4service.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "Securelist (Kaspersky)"
      ],
      "articles": [
        {
          "id": "art-62",
          "title": "Armored Likho expands its cyber-espionage toolkit",
          "link": "https://securelist.com/armored-likho-still-toolkit/121033/",
          "published": "2026-08-13",
          "sev": "high"
        }
      ],
      "first_seen": "2026-08-13"
    },
    {
      "value": "updateservs.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "Securelist (Kaspersky)"
      ],
      "articles": [
        {
          "id": "art-62",
          "title": "Armored Likho expands its cyber-espionage toolkit",
          "link": "https://securelist.com/armored-likho-still-toolkit/121033/",
          "published": "2026-08-13",
          "sev": "high"
        }
      ],
      "first_seen": "2026-08-13"
    },
    {
      "value": "windowserv.net",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "Securelist (Kaspersky)"
      ],
      "articles": [
        {
          "id": "art-62",
          "title": "Armored Likho expands its cyber-espionage toolkit",
          "link": "https://securelist.com/armored-likho-still-toolkit/121033/",
          "published": "2026-08-13",
          "sev": "high"
        }
      ],
      "first_seen": "2026-08-13"
    },
    {
      "value": "145.223.68.66",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "Securelist (Kaspersky)"
      ],
      "articles": [
        {
          "id": "art-62",
          "title": "Armored Likho expands its cyber-espionage toolkit",
          "link": "https://securelist.com/armored-likho-still-toolkit/121033/",
          "published": "2026-08-13",
          "sev": "high"
        }
      ],
      "first_seen": "2026-08-13"
    },
    {
      "value": "145.223.69.143",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "Securelist (Kaspersky)"
      ],
      "articles": [
        {
          "id": "art-62",
          "title": "Armored Likho expands its cyber-espionage toolkit",
          "link": "https://securelist.com/armored-likho-still-toolkit/121033/",
          "published": "2026-08-13",
          "sev": "high"
        }
      ],
      "first_seen": "2026-08-13"
    },
    {
      "value": "159.198.37.74",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "Securelist (Kaspersky)"
      ],
      "articles": [
        {
          "id": "art-62",
          "title": "Armored Likho expands its cyber-espionage toolkit",
          "link": "https://securelist.com/armored-likho-still-toolkit/121033/",
          "published": "2026-08-13",
          "sev": "high"
        }
      ],
      "first_seen": "2026-08-13"
    },
    {
      "value": "187.127.153.38",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "Securelist (Kaspersky)"
      ],
      "articles": [
        {
          "id": "art-62",
          "title": "Armored Likho expands its cyber-espionage toolkit",
          "link": "https://securelist.com/armored-likho-still-toolkit/121033/",
          "published": "2026-08-13",
          "sev": "high"
        }
      ],
      "first_seen": "2026-08-13"
    },
    {
      "value": "188.212.124.178",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "Securelist (Kaspersky)"
      ],
      "articles": [
        {
          "id": "art-62",
          "title": "Armored Likho expands its cyber-espionage toolkit",
          "link": "https://securelist.com/armored-likho-still-toolkit/121033/",
          "published": "2026-08-13",
          "sev": "high"
        }
      ],
      "first_seen": "2026-08-13"
    },
    {
      "value": "213.252.244.123",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "Securelist (Kaspersky)"
      ],
      "articles": [
        {
          "id": "art-62",
          "title": "Armored Likho expands its cyber-espionage toolkit",
          "link": "https://securelist.com/armored-likho-still-toolkit/121033/",
          "published": "2026-08-13",
          "sev": "high"
        }
      ],
      "first_seen": "2026-08-13"
    },
    {
      "value": "23.26.237.250",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "Securelist (Kaspersky)"
      ],
      "articles": [
        {
          "id": "art-62",
          "title": "Armored Likho expands its cyber-espionage toolkit",
          "link": "https://securelist.com/armored-likho-still-toolkit/121033/",
          "published": "2026-08-13",
          "sev": "high"
        }
      ],
      "first_seen": "2026-08-13"
    },
    {
      "value": "23.27.24.30",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "Securelist (Kaspersky)"
      ],
      "articles": [
        {
          "id": "art-62",
          "title": "Armored Likho expands its cyber-espionage toolkit",
          "link": "https://securelist.com/armored-likho-still-toolkit/121033/",
          "published": "2026-08-13",
          "sev": "high"
        }
      ],
      "first_seen": "2026-08-13"
    },
    {
      "value": "439255736797bc88bd19f282449e0436",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "Securelist (Kaspersky)"
      ],
      "articles": [
        {
          "id": "art-62",
          "title": "Armored Likho expands its cyber-espionage toolkit",
          "link": "https://securelist.com/armored-likho-still-toolkit/121033/",
          "published": "2026-08-13",
          "sev": "high"
        }
      ],
      "first_seen": "2026-08-13"
    },
    {
      "value": "9a47c4d379998ade2f8f99e23a630c06",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "Cisco Talos"
      ],
      "articles": [
        {
          "id": "art-52",
          "title": "Curiouser and Curiouser",
          "link": "https://blog.talosintelligence.com/curiouser-and-curiouser/",
          "published": "2026-08-13",
          "sev": "high"
        }
      ],
      "first_seen": "2026-08-13"
    },
    {
      "value": "2ca8adbab98ebe305eacf272cf48f5a03ac41b097236a7723821848ae31ef141",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "Securelist (Kaspersky)"
      ],
      "articles": [
        {
          "id": "art-62",
          "title": "Armored Likho expands its cyber-espionage toolkit",
          "link": "https://securelist.com/armored-likho-still-toolkit/121033/",
          "published": "2026-08-13",
          "sev": "high"
        }
      ],
      "first_seen": "2026-08-13"
    },
    {
      "value": "4bd7c352ae277b0e38d07beedd4dd507d4bc09fb10ea2a5dc0bcbeeda5e5afdd",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "Securelist (Kaspersky)"
      ],
      "articles": [
        {
          "id": "art-62",
          "title": "Armored Likho expands its cyber-espionage toolkit",
          "link": "https://securelist.com/armored-likho-still-toolkit/121033/",
          "published": "2026-08-13",
          "sev": "high"
        }
      ],
      "first_seen": "2026-08-13"
    },
    {
      "value": "62801f6223e860a7cca271522e303b2d68f0365d2fa8c828d012d8859e52a773",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "Securelist (Kaspersky)"
      ],
      "articles": [
        {
          "id": "art-62",
          "title": "Armored Likho expands its cyber-espionage toolkit",
          "link": "https://securelist.com/armored-likho-still-toolkit/121033/",
          "published": "2026-08-13",
          "sev": "high"
        }
      ],
      "first_seen": "2026-08-13"
    },
    {
      "value": "c1d1ee16b92e6a138ffa048855f75d7d17674b250d8b422a50a86c9ff207186d",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "Securelist (Kaspersky)"
      ],
      "articles": [
        {
          "id": "art-62",
          "title": "Armored Likho expands its cyber-espionage toolkit",
          "link": "https://securelist.com/armored-likho-still-toolkit/121033/",
          "published": "2026-08-13",
          "sev": "high"
        }
      ],
      "first_seen": "2026-08-13"
    },
    {
      "value": "c4dd71e347a076ba24bdd2d0ee532ef991c1ef25a2431a19f850942ba2ab16b2",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "Cisco Talos"
      ],
      "articles": [
        {
          "id": "art-52",
          "title": "Curiouser and Curiouser",
          "link": "https://blog.talosintelligence.com/curiouser-and-curiouser/",
          "published": "2026-08-13",
          "sev": "high"
        }
      ],
      "first_seen": "2026-08-13"
    },
    {
      "value": "CVE-2025-49113",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "The Hacker News",
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-64",
          "title": "Lazarus Exploits Windows Zero-Day to Gain SYSTEM Access and Deploy Backdoor",
          "link": "https://thehackernews.com/2026/08/lazarus-exploits-windows-zero-day-to.html",
          "published": "2026-08-12",
          "sev": "crit"
        },
        {
          "id": "art-657",
          "title": "CISA KEV: CVE-2025-49113 \u2014 RoundCube Webmail Deserialization of Untrusted Data Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-02-20",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-12"
    },
    {
      "value": "CVE-2026-20349",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "The Hacker News",
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-76",
          "title": "Cisco ASA and FTD Flaw Exploited in the Wild Can Trigger Remote DoS",
          "link": "https://thehackernews.com/2026/08/cisco-asa-and-ftd-flaw-exploited-in.html",
          "published": "2026-08-12",
          "sev": "crit"
        },
        {
          "id": "art-93",
          "title": "CISA KEV: CVE-2026-20349 \u2014 Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) Heap Inspection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-08-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-12"
    },
    {
      "value": "CVE-2026-27302",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "The Hacker News"
      ],
      "articles": [
        {
          "id": "art-71",
          "title": "Adobe Patches Three CVSS 10.0 ColdFusion and Campaign Classic Flaws",
          "link": "https://thehackernews.com/2026/08/adobe-patches-three-cvss-100-coldfusion.html",
          "published": "2026-08-12",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-12"
    },
    {
      "value": "CVE-2026-34265",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "The Hacker News"
      ],
      "articles": [
        {
          "id": "art-74",
          "title": "SAP Commerce Cloud Flaw Could Let Unauthenticated Attackers Execute Arbitrary Code",
          "link": "https://thehackernews.com/2026/08/sap-commerce-cloud-flaw-could-let.html",
          "published": "2026-08-12",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-12"
    },
    {
      "value": "CVE-2026-44758",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "The Hacker News"
      ],
      "articles": [
        {
          "id": "art-74",
          "title": "SAP Commerce Cloud Flaw Could Let Unauthenticated Attackers Execute Arbitrary Code",
          "link": "https://thehackernews.com/2026/08/sap-commerce-cloud-flaw-could-let.html",
          "published": "2026-08-12",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-12"
    },
    {
      "value": "CVE-2026-44772",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "The Hacker News"
      ],
      "articles": [
        {
          "id": "art-74",
          "title": "SAP Commerce Cloud Flaw Could Let Unauthenticated Attackers Execute Arbitrary Code",
          "link": "https://thehackernews.com/2026/08/sap-commerce-cloud-flaw-could-let.html",
          "published": "2026-08-12",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-12"
    },
    {
      "value": "CVE-2026-48273",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "The Hacker News"
      ],
      "articles": [
        {
          "id": "art-71",
          "title": "Adobe Patches Three CVSS 10.0 ColdFusion and Campaign Classic Flaws",
          "link": "https://thehackernews.com/2026/08/adobe-patches-three-cvss-100-coldfusion.html",
          "published": "2026-08-12",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-12"
    },
    {
      "value": "CVE-2026-48362",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "The Hacker News"
      ],
      "articles": [
        {
          "id": "art-71",
          "title": "Adobe Patches Three CVSS 10.0 ColdFusion and Campaign Classic Flaws",
          "link": "https://thehackernews.com/2026/08/adobe-patches-three-cvss-100-coldfusion.html",
          "published": "2026-08-12",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-12"
    },
    {
      "value": "CVE-2026-48381",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "The Hacker News"
      ],
      "articles": [
        {
          "id": "art-71",
          "title": "Adobe Patches Three CVSS 10.0 ColdFusion and Campaign Classic Flaws",
          "link": "https://thehackernews.com/2026/08/adobe-patches-three-cvss-100-coldfusion.html",
          "published": "2026-08-12",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-12"
    },
    {
      "value": "CVE-2026-48449",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "The Hacker News"
      ],
      "articles": [
        {
          "id": "art-71",
          "title": "Adobe Patches Three CVSS 10.0 ColdFusion and Campaign Classic Flaws",
          "link": "https://thehackernews.com/2026/08/adobe-patches-three-cvss-100-coldfusion.html",
          "published": "2026-08-12",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-12"
    },
    {
      "value": "CVE-2026-62832",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "The Hacker News",
        "Cisco Talos"
      ],
      "articles": [
        {
          "id": "art-75",
          "title": "ShieldBreak Zero-Day PoC Claims Microsoft Defender Patch Bypass With SYSTEM Access",
          "link": "https://thehackernews.com/2026/08/shieldbreak-zero-day-poc-claims.html",
          "published": "2026-08-12",
          "sev": "crit"
        },
        {
          "id": "art-78",
          "title": "Microsoft Patches 398 Flaws Including a Windows Driver Zero-Day Under Active Attack",
          "link": "https://thehackernews.com/2026/08/microsoft-patches-398-flaws-including.html",
          "published": "2026-08-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-12"
    },
    {
      "value": "CVE-2026-68820",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "The Hacker News",
        "Cisco Talos",
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-64",
          "title": "Lazarus Exploits Windows Zero-Day to Gain SYSTEM Access and Deploy Backdoor",
          "link": "https://thehackernews.com/2026/08/lazarus-exploits-windows-zero-day-to.html",
          "published": "2026-08-12",
          "sev": "crit"
        },
        {
          "id": "art-75",
          "title": "ShieldBreak Zero-Day PoC Claims Microsoft Defender Patch Bypass With SYSTEM Access",
          "link": "https://thehackernews.com/2026/08/shieldbreak-zero-day-poc-claims.html",
          "published": "2026-08-12",
          "sev": "crit"
        },
        {
          "id": "art-78",
          "title": "Microsoft Patches 398 Flaws Including a Windows Driver Zero-Day Under Active Attack",
          "link": "https://thehackernews.com/2026/08/microsoft-patches-398-flaws-including.html",
          "published": "2026-08-11",
          "sev": "crit"
        },
        {
          "id": "art-94",
          "title": "CISA KEV: CVE-2026-68820 \u2014 Microsoft Windows Ancillary Function Driver for WinSock Use-After-Free Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-08-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-12"
    },
    {
      "value": "CVE-2026-71362",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "The Hacker News"
      ],
      "articles": [
        {
          "id": "art-71",
          "title": "Adobe Patches Three CVSS 10.0 ColdFusion and Campaign Classic Flaws",
          "link": "https://thehackernews.com/2026/08/adobe-patches-three-cvss-100-coldfusion.html",
          "published": "2026-08-12",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-12"
    },
    {
      "value": "CVE-2026-71384",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "The Hacker News"
      ],
      "articles": [
        {
          "id": "art-71",
          "title": "Adobe Patches Three CVSS 10.0 ColdFusion and Campaign Classic Flaws",
          "link": "https://thehackernews.com/2026/08/adobe-patches-three-cvss-100-coldfusion.html",
          "published": "2026-08-12",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-12"
    },
    {
      "value": "CVE-2026-71398",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "The Hacker News"
      ],
      "articles": [
        {
          "id": "art-71",
          "title": "Adobe Patches Three CVSS 10.0 ColdFusion and Campaign Classic Flaws",
          "link": "https://thehackernews.com/2026/08/adobe-patches-three-cvss-100-coldfusion.html",
          "published": "2026-08-12",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-12"
    },
    {
      "value": "CVE-2026-72971",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "The Hacker News"
      ],
      "articles": [
        {
          "id": "art-75",
          "title": "ShieldBreak Zero-Day PoC Claims Microsoft Defender Patch Bypass With SYSTEM Access",
          "link": "https://thehackernews.com/2026/08/shieldbreak-zero-day-poc-claims.html",
          "published": "2026-08-12",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-12"
    },
    {
      "value": "audit.checkmarx.cx",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "StepSecurity",
        "Unit 42 (Palo Alto)",
        "Aikido"
      ],
      "articles": [
        {
          "id": "art-65",
          "title": "Control Which Package Registries Your CI Jobs and Developer Machines Use",
          "link": "https://www.stepsecurity.io/blog/control-which-package-registries-your-ci-jobs-and-developer-machines-use",
          "published": "2026-08-12",
          "sev": "med"
        },
        {
          "id": "art-263",
          "title": "The npm Threat Landscape: Attack Surface and Mitigations (Updated July 15)",
          "link": "https://unit42.paloaltonetworks.com/monitoring-npm-supply-chain-attacks/",
          "published": "2026-07-15",
          "sev": "crit"
        },
        {
          "id": "art-324",
          "title": "10 Layers Deep: How StepSecurity Stops TeamPCP's Trivy Supply Chain Attack on GitHub Actions",
          "link": "https://www.stepsecurity.io/blog/10-layers-deep-how-stepsecurity-stops-teampcps-trivy-supply-chain-attack-on-github-actions",
          "published": "2026-07-02",
          "sev": "crit"
        },
        {
          "id": "art-503",
          "title": "Bitwarden CLI Hijacked on npm: Bun-Staged Credential Stealer Targets Developers, GitHub Actions, and AI Tools",
          "link": "https://www.stepsecurity.io/blog/bitwarden-cli-hijacked-on-npm-bun-staged-credential-stealer-targets-developers-github-actions-and-ai-tools",
          "published": "2026-05-04",
          "sev": "crit"
        },
        {
          "id": "art-528",
          "title": "Is Shai-Hulud Back? Compromised Bitwarden CLI Contains a Self-Propagating npm Worm",
          "link": "https://www.aikido.dev/blog/shai-hulud-npm-bitwarden-cli-compromise",
          "published": "2026-04-23",
          "sev": "high"
        }
      ],
      "first_seen": "2026-08-12"
    },
    {
      "value": "checkmarx.zone",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "StepSecurity",
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-65",
          "title": "Control Which Package Registries Your CI Jobs and Developer Machines Use",
          "link": "https://www.stepsecurity.io/blog/control-which-package-registries-your-ci-jobs-and-developer-machines-use",
          "published": "2026-08-12",
          "sev": "med"
        },
        {
          "id": "art-324",
          "title": "10 Layers Deep: How StepSecurity Stops TeamPCP's Trivy Supply Chain Attack on GitHub Actions",
          "link": "https://www.stepsecurity.io/blog/10-layers-deep-how-stepsecurity-stops-teampcps-trivy-supply-chain-attack-on-github-actions",
          "published": "2026-07-02",
          "sev": "crit"
        },
        {
          "id": "art-579",
          "title": "You Patched LiteLLM, But Do You Know Your AI Blast Radius?",
          "link": "https://snyk.io/blog/litellm-ai-blast-radius/",
          "published": "2026-04-02",
          "sev": "high"
        },
        {
          "id": "art-587",
          "title": "litellm: Credential Stealer Hidden in PyPI Wheel",
          "link": "https://www.stepsecurity.io/blog/litellm-credential-stealer-hidden-in-pypi-wheel",
          "published": "2026-03-28",
          "sev": "crit"
        },
        {
          "id": "art-591",
          "title": "Checkmarx KICS GitHub Action Compromised: Malware Injected in All Git Tags",
          "link": "https://www.stepsecurity.io/blog/checkmarx-kics-github-action-compromised-malware-injected-in-all-git-tags",
          "published": "2026-03-26",
          "sev": "high"
        },
        {
          "id": "art-605",
          "title": "How a Poisoned Security Scanner Became the Key to Backdooring LiteLLM",
          "link": "https://snyk.io/blog/poisoned-security-scanner-backdooring-litellm/",
          "published": "2026-03-24",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-12"
    },
    {
      "value": "enveil.online",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "The Hacker News"
      ],
      "articles": [
        {
          "id": "art-64",
          "title": "Lazarus Exploits Windows Zero-Day to Gain SYSTEM Access and Deploy Backdoor",
          "link": "https://thehackernews.com/2026/08/lazarus-exploits-windows-zero-day-to.html",
          "published": "2026-08-12",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-12"
    },
    {
      "value": "envell.xyz",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "The Hacker News"
      ],
      "articles": [
        {
          "id": "art-64",
          "title": "Lazarus Exploits Windows Zero-Day to Gain SYSTEM Access and Deploy Backdoor",
          "link": "https://thehackernews.com/2026/08/lazarus-exploits-windows-zero-day-to.html",
          "published": "2026-08-12",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-12"
    },
    {
      "value": "models.litellm.cloud",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "StepSecurity",
        "The Hacker News",
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-65",
          "title": "Control Which Package Registries Your CI Jobs and Developer Machines Use",
          "link": "https://www.stepsecurity.io/blog/control-which-package-registries-your-ci-jobs-and-developer-machines-use",
          "published": "2026-08-12",
          "sev": "med"
        },
        {
          "id": "art-73",
          "title": "Malicious LiteLLM Releases Tied to Trivy Hack May Have Exposed 2,100+ Organizations",
          "link": "https://thehackernews.com/2026/08/malicious-litellm-releases-tied-to.html",
          "published": "2026-08-12",
          "sev": "crit"
        },
        {
          "id": "art-324",
          "title": "10 Layers Deep: How StepSecurity Stops TeamPCP's Trivy Supply Chain Attack on GitHub Actions",
          "link": "https://www.stepsecurity.io/blog/10-layers-deep-how-stepsecurity-stops-teampcps-trivy-supply-chain-attack-on-github-actions",
          "published": "2026-07-02",
          "sev": "crit"
        },
        {
          "id": "art-579",
          "title": "You Patched LiteLLM, But Do You Know Your AI Blast Radius?",
          "link": "https://snyk.io/blog/litellm-ai-blast-radius/",
          "published": "2026-04-02",
          "sev": "high"
        },
        {
          "id": "art-587",
          "title": "litellm: Credential Stealer Hidden in PyPI Wheel",
          "link": "https://www.stepsecurity.io/blog/litellm-credential-stealer-hidden-in-pypi-wheel",
          "published": "2026-03-28",
          "sev": "crit"
        },
        {
          "id": "art-605",
          "title": "How a Poisoned Security Scanner Became the Key to Backdooring LiteLLM",
          "link": "https://snyk.io/blog/poisoned-security-scanner-backdooring-litellm/",
          "published": "2026-03-24",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-12"
    },
    {
      "value": "uxtramine.org",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "The Hacker News"
      ],
      "articles": [
        {
          "id": "art-64",
          "title": "Lazarus Exploits Windows Zero-Day to Gain SYSTEM Access and Deploy Backdoor",
          "link": "https://thehackernews.com/2026/08/lazarus-exploits-windows-zero-day-to.html",
          "published": "2026-08-12",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-12"
    },
    {
      "value": "135.181.185.158",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "The Hacker News"
      ],
      "articles": [
        {
          "id": "art-64",
          "title": "Lazarus Exploits Windows Zero-Day to Gain SYSTEM Access and Deploy Backdoor",
          "link": "https://thehackernews.com/2026/08/lazarus-exploits-windows-zero-day-to.html",
          "published": "2026-08-12",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-12"
    },
    {
      "value": "135.181.67.203",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "The Hacker News"
      ],
      "articles": [
        {
          "id": "art-64",
          "title": "Lazarus Exploits Windows Zero-Day to Gain SYSTEM Access and Deploy Backdoor",
          "link": "https://thehackernews.com/2026/08/lazarus-exploits-windows-zero-day-to.html",
          "published": "2026-08-12",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-12"
    },
    {
      "value": "83.142.209.11",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "StepSecurity",
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-65",
          "title": "Control Which Package Registries Your CI Jobs and Developer Machines Use",
          "link": "https://www.stepsecurity.io/blog/control-which-package-registries-your-ci-jobs-and-developer-machines-use",
          "published": "2026-08-12",
          "sev": "med"
        },
        {
          "id": "art-579",
          "title": "You Patched LiteLLM, But Do You Know Your AI Blast Radius?",
          "link": "https://snyk.io/blog/litellm-ai-blast-radius/",
          "published": "2026-04-02",
          "sev": "high"
        },
        {
          "id": "art-605",
          "title": "How a Poisoned Security Scanner Became the Key to Backdooring LiteLLM",
          "link": "https://snyk.io/blog/poisoned-security-scanner-backdooring-litellm/",
          "published": "2026-03-24",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-12"
    },
    {
      "value": "94.154.172.43",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "StepSecurity",
        "Unit 42 (Palo Alto)"
      ],
      "articles": [
        {
          "id": "art-65",
          "title": "Control Which Package Registries Your CI Jobs and Developer Machines Use",
          "link": "https://www.stepsecurity.io/blog/control-which-package-registries-your-ci-jobs-and-developer-machines-use",
          "published": "2026-08-12",
          "sev": "med"
        },
        {
          "id": "art-263",
          "title": "The npm Threat Landscape: Attack Surface and Mitigations (Updated July 15)",
          "link": "https://unit42.paloaltonetworks.com/monitoring-npm-supply-chain-attacks/",
          "published": "2026-07-15",
          "sev": "crit"
        },
        {
          "id": "art-324",
          "title": "10 Layers Deep: How StepSecurity Stops TeamPCP's Trivy Supply Chain Attack on GitHub Actions",
          "link": "https://www.stepsecurity.io/blog/10-layers-deep-how-stepsecurity-stops-teampcps-trivy-supply-chain-attack-on-github-actions",
          "published": "2026-07-02",
          "sev": "crit"
        },
        {
          "id": "art-503",
          "title": "Bitwarden CLI Hijacked on npm: Bun-Staged Credential Stealer Targets Developers, GitHub Actions, and AI Tools",
          "link": "https://www.stepsecurity.io/blog/bitwarden-cli-hijacked-on-npm-bun-staged-credential-stealer-targets-developers-github-actions-and-ai-tools",
          "published": "2026-05-04",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-12"
    },
    {
      "value": "18f784b3bc9a0bcdcb1a8d7f51bc5f54323fc40cbd874119354ab609bef6e4cb",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "StepSecurity",
        "Aikido"
      ],
      "articles": [
        {
          "id": "art-65",
          "title": "Control Which Package Registries Your CI Jobs and Developer Machines Use",
          "link": "https://www.stepsecurity.io/blog/control-which-package-registries-your-ci-jobs-and-developer-machines-use",
          "published": "2026-08-12",
          "sev": "med"
        },
        {
          "id": "art-503",
          "title": "Bitwarden CLI Hijacked on npm: Bun-Staged Credential Stealer Targets Developers, GitHub Actions, and AI Tools",
          "link": "https://www.stepsecurity.io/blog/bitwarden-cli-hijacked-on-npm-bun-staged-credential-stealer-targets-developers-github-actions-and-ai-tools",
          "published": "2026-05-04",
          "sev": "crit"
        },
        {
          "id": "art-528",
          "title": "Is Shai-Hulud Back? Compromised Bitwarden CLI Contains a Self-Propagating npm Worm",
          "link": "https://www.aikido.dev/blog/shai-hulud-npm-bitwarden-cli-compromise",
          "published": "2026-04-23",
          "sev": "high"
        }
      ],
      "first_seen": "2026-08-12"
    },
    {
      "value": "8605e365edf11160aad517c7d79a3b26b62290e5072ef97b102a01ddbb343f14",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "StepSecurity"
      ],
      "articles": [
        {
          "id": "art-65",
          "title": "Control Which Package Registries Your CI Jobs and Developer Machines Use",
          "link": "https://www.stepsecurity.io/blog/control-which-package-registries-your-ci-jobs-and-developer-machines-use",
          "published": "2026-08-12",
          "sev": "med"
        },
        {
          "id": "art-503",
          "title": "Bitwarden CLI Hijacked on npm: Bun-Staged Credential Stealer Targets Developers, GitHub Actions, and AI Tools",
          "link": "https://www.stepsecurity.io/blog/bitwarden-cli-hijacked-on-npm-bun-staged-credential-stealer-targets-developers-github-actions-and-ai-tools",
          "published": "2026-05-04",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-12"
    },
    {
      "value": "aquasecurtiy.org",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "StepSecurity",
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-65",
          "title": "Control Which Package Registries Your CI Jobs and Developer Machines Use",
          "link": "https://www.stepsecurity.io/blog/control-which-package-registries-your-ci-jobs-and-developer-machines-use",
          "published": "2026-08-12",
          "sev": "med"
        },
        {
          "id": "art-579",
          "title": "You Patched LiteLLM, But Do You Know Your AI Blast Radius?",
          "link": "https://snyk.io/blog/litellm-ai-blast-radius/",
          "published": "2026-04-02",
          "sev": "high"
        }
      ],
      "first_seen": "2026-08-12"
    },
    {
      "value": "atlasvpn.space",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "The Hacker News"
      ],
      "articles": [
        {
          "id": "art-66",
          "title": "737 Chrome VPN Extensions Caught Routing Traffic Through Proxies. Check If You Have One",
          "link": "https://thehackernews.com/2026/08/737-chrome-vpn-extensions-caught.html",
          "published": "2026-08-12",
          "sev": "high"
        }
      ],
      "first_seen": "2026-08-12"
    },
    {
      "value": "bezopasnet.space",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "The Hacker News"
      ],
      "articles": [
        {
          "id": "art-66",
          "title": "737 Chrome VPN Extensions Caught Routing Traffic Through Proxies. Check If You Have One",
          "link": "https://thehackernews.com/2026/08/737-chrome-vpn-extensions-caught.html",
          "published": "2026-08-12",
          "sev": "high"
        }
      ],
      "first_seen": "2026-08-12"
    },
    {
      "value": "cipherway.space",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "The Hacker News"
      ],
      "articles": [
        {
          "id": "art-66",
          "title": "737 Chrome VPN Extensions Caught Routing Traffic Through Proxies. Check If You Have One",
          "link": "https://thehackernews.com/2026/08/737-chrome-vpn-extensions-caught.html",
          "published": "2026-08-12",
          "sev": "high"
        }
      ],
      "first_seen": "2026-08-12"
    },
    {
      "value": "cloudmask.space",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "The Hacker News"
      ],
      "articles": [
        {
          "id": "art-66",
          "title": "737 Chrome VPN Extensions Caught Routing Traffic Through Proxies. Check If You Have One",
          "link": "https://thehackernews.com/2026/08/737-chrome-vpn-extensions-caught.html",
          "published": "2026-08-12",
          "sev": "high"
        }
      ],
      "first_seen": "2026-08-12"
    },
    {
      "value": "echosecure.space",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "The Hacker News"
      ],
      "articles": [
        {
          "id": "art-66",
          "title": "737 Chrome VPN Extensions Caught Routing Traffic Through Proxies. Check If You Have One",
          "link": "https://thehackernews.com/2026/08/737-chrome-vpn-extensions-caught.html",
          "published": "2026-08-12",
          "sev": "high"
        }
      ],
      "first_seen": "2026-08-12"
    },
    {
      "value": "gusenvpn.online",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "The Hacker News"
      ],
      "articles": [
        {
          "id": "art-66",
          "title": "737 Chrome VPN Extensions Caught Routing Traffic Through Proxies. Check If You Have One",
          "link": "https://thehackernews.com/2026/08/737-chrome-vpn-extensions-caught.html",
          "published": "2026-08-12",
          "sev": "high"
        }
      ],
      "first_seen": "2026-08-12"
    },
    {
      "value": "horizonguard.space",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "The Hacker News"
      ],
      "articles": [
        {
          "id": "art-66",
          "title": "737 Chrome VPN Extensions Caught Routing Traffic Through Proxies. Check If You Have One",
          "link": "https://thehackernews.com/2026/08/737-chrome-vpn-extensions-caught.html",
          "published": "2026-08-12",
          "sev": "high"
        }
      ],
      "first_seen": "2026-08-12"
    },
    {
      "value": "internetprvpn.ru",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "The Hacker News"
      ],
      "articles": [
        {
          "id": "art-66",
          "title": "737 Chrome VPN Extensions Caught Routing Traffic Through Proxies. Check If You Have One",
          "link": "https://thehackernews.com/2026/08/737-chrome-vpn-extensions-caught.html",
          "published": "2026-08-12",
          "sev": "high"
        }
      ],
      "first_seen": "2026-08-12"
    },
    {
      "value": "ironproxy.space",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "The Hacker News"
      ],
      "articles": [
        {
          "id": "art-66",
          "title": "737 Chrome VPN Extensions Caught Routing Traffic Through Proxies. Check If You Have One",
          "link": "https://thehackernews.com/2026/08/737-chrome-vpn-extensions-caught.html",
          "published": "2026-08-12",
          "sev": "high"
        }
      ],
      "first_seen": "2026-08-12"
    },
    {
      "value": "korovkavpn.space",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "The Hacker News"
      ],
      "articles": [
        {
          "id": "art-66",
          "title": "737 Chrome VPN Extensions Caught Routing Traffic Through Proxies. Check If You Have One",
          "link": "https://thehackernews.com/2026/08/737-chrome-vpn-extensions-caught.html",
          "published": "2026-08-12",
          "sev": "high"
        }
      ],
      "first_seen": "2026-08-12"
    },
    {
      "value": "maskirovka.space",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "The Hacker News"
      ],
      "articles": [
        {
          "id": "art-66",
          "title": "737 Chrome VPN Extensions Caught Routing Traffic Through Proxies. Check If You Have One",
          "link": "https://thehackernews.com/2026/08/737-chrome-vpn-extensions-caught.html",
          "published": "2026-08-12",
          "sev": "high"
        }
      ],
      "first_seen": "2026-08-12"
    },
    {
      "value": "murvpn.space",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "The Hacker News"
      ],
      "articles": [
        {
          "id": "art-66",
          "title": "737 Chrome VPN Extensions Caught Routing Traffic Through Proxies. Check If You Have One",
          "link": "https://thehackernews.com/2026/08/737-chrome-vpn-extensions-caught.html",
          "published": "2026-08-12",
          "sev": "high"
        }
      ],
      "first_seen": "2026-08-12"
    },
    {
      "value": "myxasafe.space",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "The Hacker News"
      ],
      "articles": [
        {
          "id": "art-66",
          "title": "737 Chrome VPN Extensions Caught Routing Traffic Through Proxies. Check If You Have One",
          "link": "https://thehackernews.com/2026/08/737-chrome-vpn-extensions-caught.html",
          "published": "2026-08-12",
          "sev": "high"
        }
      ],
      "first_seen": "2026-08-12"
    },
    {
      "value": "myxasecure.space",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "The Hacker News"
      ],
      "articles": [
        {
          "id": "art-66",
          "title": "737 Chrome VPN Extensions Caught Routing Traffic Through Proxies. Check If You Have One",
          "link": "https://thehackernews.com/2026/08/737-chrome-vpn-extensions-caught.html",
          "published": "2026-08-12",
          "sev": "high"
        }
      ],
      "first_seen": "2026-08-12"
    },
    {
      "value": "myxavpn.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "The Hacker News"
      ],
      "articles": [
        {
          "id": "art-66",
          "title": "737 Chrome VPN Extensions Caught Routing Traffic Through Proxies. Check If You Have One",
          "link": "https://thehackernews.com/2026/08/737-chrome-vpn-extensions-caught.html",
          "published": "2026-08-12",
          "sev": "high"
        }
      ],
      "first_seen": "2026-08-12"
    },
    {
      "value": "myxavpn.pro",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "The Hacker News"
      ],
      "articles": [
        {
          "id": "art-66",
          "title": "737 Chrome VPN Extensions Caught Routing Traffic Through Proxies. Check If You Have One",
          "link": "https://thehackernews.com/2026/08/737-chrome-vpn-extensions-caught.html",
          "published": "2026-08-12",
          "sev": "high"
        }
      ],
      "first_seen": "2026-08-12"
    },
    {
      "value": "myxavpn.space",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "The Hacker News"
      ],
      "articles": [
        {
          "id": "art-66",
          "title": "737 Chrome VPN Extensions Caught Routing Traffic Through Proxies. Check If You Have One",
          "link": "https://thehackernews.com/2026/08/737-chrome-vpn-extensions-caught.html",
          "published": "2026-08-12",
          "sev": "high"
        }
      ],
      "first_seen": "2026-08-12"
    },
    {
      "value": "neoncloak.space",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "The Hacker News"
      ],
      "articles": [
        {
          "id": "art-66",
          "title": "737 Chrome VPN Extensions Caught Routing Traffic Through Proxies. Check If You Have One",
          "link": "https://thehackernews.com/2026/08/737-chrome-vpn-extensions-caught.html",
          "published": "2026-08-12",
          "sev": "high"
        }
      ],
      "first_seen": "2026-08-12"
    },
    {
      "value": "netroutehub.space",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "The Hacker News"
      ],
      "articles": [
        {
          "id": "art-66",
          "title": "737 Chrome VPN Extensions Caught Routing Traffic Through Proxies. Check If You Have One",
          "link": "https://thehackernews.com/2026/08/737-chrome-vpn-extensions-caught.html",
          "published": "2026-08-12",
          "sev": "high"
        }
      ],
      "first_seen": "2026-08-12"
    },
    {
      "value": "nimbusshield.space",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "The Hacker News"
      ],
      "articles": [
        {
          "id": "art-66",
          "title": "737 Chrome VPN Extensions Caught Routing Traffic Through Proxies. Check If You Have One",
          "link": "https://thehackernews.com/2026/08/737-chrome-vpn-extensions-caught.html",
          "published": "2026-08-12",
          "sev": "high"
        }
      ],
      "first_seen": "2026-08-12"
    },
    {
      "value": "osavpn.su",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "The Hacker News"
      ],
      "articles": [
        {
          "id": "art-66",
          "title": "737 Chrome VPN Extensions Caught Routing Traffic Through Proxies. Check If You Have One",
          "link": "https://thehackernews.com/2026/08/737-chrome-vpn-extensions-caught.html",
          "published": "2026-08-12",
          "sev": "high"
        }
      ],
      "first_seen": "2026-08-12"
    },
    {
      "value": "primeproxy.space",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "The Hacker News"
      ],
      "articles": [
        {
          "id": "art-66",
          "title": "737 Chrome VPN Extensions Caught Routing Traffic Through Proxies. Check If You Have One",
          "link": "https://thehackernews.com/2026/08/737-chrome-vpn-extensions-caught.html",
          "published": "2026-08-12",
          "sev": "high"
        }
      ],
      "first_seen": "2026-08-12"
    },
    {
      "value": "routekeeper.space",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "The Hacker News"
      ],
      "articles": [
        {
          "id": "art-66",
          "title": "737 Chrome VPN Extensions Caught Routing Traffic Through Proxies. Check If You Have One",
          "link": "https://thehackernews.com/2026/08/737-chrome-vpn-extensions-caught.html",
          "published": "2026-08-12",
          "sev": "high"
        }
      ],
      "first_seen": "2026-08-12"
    },
    {
      "value": "securepulse.space",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "The Hacker News"
      ],
      "articles": [
        {
          "id": "art-66",
          "title": "737 Chrome VPN Extensions Caught Routing Traffic Through Proxies. Check If You Have One",
          "link": "https://thehackernews.com/2026/08/737-chrome-vpn-extensions-caught.html",
          "published": "2026-08-12",
          "sev": "high"
        }
      ],
      "first_seen": "2026-08-12"
    },
    {
      "value": "shershvpn.space",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "The Hacker News"
      ],
      "articles": [
        {
          "id": "art-66",
          "title": "737 Chrome VPN Extensions Caught Routing Traffic Through Proxies. Check If You Have One",
          "link": "https://thehackernews.com/2026/08/737-chrome-vpn-extensions-caught.html",
          "published": "2026-08-12",
          "sev": "high"
        }
      ],
      "first_seen": "2026-08-12"
    },
    {
      "value": "skorostvpn.space",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "The Hacker News"
      ],
      "articles": [
        {
          "id": "art-66",
          "title": "737 Chrome VPN Extensions Caught Routing Traffic Through Proxies. Check If You Have One",
          "link": "https://thehackernews.com/2026/08/737-chrome-vpn-extensions-caught.html",
          "published": "2026-08-12",
          "sev": "high"
        }
      ],
      "first_seen": "2026-08-12"
    },
    {
      "value": "turbotunnel.space",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "The Hacker News"
      ],
      "articles": [
        {
          "id": "art-66",
          "title": "737 Chrome VPN Extensions Caught Routing Traffic Through Proxies. Check If You Have One",
          "link": "https://thehackernews.com/2026/08/737-chrome-vpn-extensions-caught.html",
          "published": "2026-08-12",
          "sev": "high"
        }
      ],
      "first_seen": "2026-08-12"
    },
    {
      "value": "vpn-myxa.ru",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "The Hacker News"
      ],
      "articles": [
        {
          "id": "art-66",
          "title": "737 Chrome VPN Extensions Caught Routing Traffic Through Proxies. Check If You Have One",
          "link": "https://thehackernews.com/2026/08/737-chrome-vpn-extensions-caught.html",
          "published": "2026-08-12",
          "sev": "high"
        }
      ],
      "first_seen": "2026-08-12"
    },
    {
      "value": "vpnmyha.shop",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "The Hacker News"
      ],
      "articles": [
        {
          "id": "art-66",
          "title": "737 Chrome VPN Extensions Caught Routing Traffic Through Proxies. Check If You Have One",
          "link": "https://thehackernews.com/2026/08/737-chrome-vpn-extensions-caught.html",
          "published": "2026-08-12",
          "sev": "high"
        }
      ],
      "first_seen": "2026-08-12"
    },
    {
      "value": "vpnmyxa.site",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "The Hacker News"
      ],
      "articles": [
        {
          "id": "art-66",
          "title": "737 Chrome VPN Extensions Caught Routing Traffic Through Proxies. Check If You Have One",
          "link": "https://thehackernews.com/2026/08/737-chrome-vpn-extensions-caught.html",
          "published": "2026-08-12",
          "sev": "high"
        }
      ],
      "first_seen": "2026-08-12"
    },
    {
      "value": "103.35.189.225",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "The Hacker News"
      ],
      "articles": [
        {
          "id": "art-66",
          "title": "737 Chrome VPN Extensions Caught Routing Traffic Through Proxies. Check If You Have One",
          "link": "https://thehackernews.com/2026/08/737-chrome-vpn-extensions-caught.html",
          "published": "2026-08-12",
          "sev": "high"
        }
      ],
      "first_seen": "2026-08-12"
    },
    {
      "value": "103.35.191.173",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "The Hacker News"
      ],
      "articles": [
        {
          "id": "art-66",
          "title": "737 Chrome VPN Extensions Caught Routing Traffic Through Proxies. Check If You Have One",
          "link": "https://thehackernews.com/2026/08/737-chrome-vpn-extensions-caught.html",
          "published": "2026-08-12",
          "sev": "high"
        }
      ],
      "first_seen": "2026-08-12"
    },
    {
      "value": "130.17.1.19",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "The Hacker News"
      ],
      "articles": [
        {
          "id": "art-66",
          "title": "737 Chrome VPN Extensions Caught Routing Traffic Through Proxies. Check If You Have One",
          "link": "https://thehackernews.com/2026/08/737-chrome-vpn-extensions-caught.html",
          "published": "2026-08-12",
          "sev": "high"
        }
      ],
      "first_seen": "2026-08-12"
    },
    {
      "value": "138.124.244.206",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "The Hacker News"
      ],
      "articles": [
        {
          "id": "art-66",
          "title": "737 Chrome VPN Extensions Caught Routing Traffic Through Proxies. Check If You Have One",
          "link": "https://thehackernews.com/2026/08/737-chrome-vpn-extensions-caught.html",
          "published": "2026-08-12",
          "sev": "high"
        }
      ],
      "first_seen": "2026-08-12"
    },
    {
      "value": "147.45.60.241",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "The Hacker News"
      ],
      "articles": [
        {
          "id": "art-66",
          "title": "737 Chrome VPN Extensions Caught Routing Traffic Through Proxies. Check If You Have One",
          "link": "https://thehackernews.com/2026/08/737-chrome-vpn-extensions-caught.html",
          "published": "2026-08-12",
          "sev": "high"
        }
      ],
      "first_seen": "2026-08-12"
    },
    {
      "value": "147.45.60.252",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "The Hacker News"
      ],
      "articles": [
        {
          "id": "art-66",
          "title": "737 Chrome VPN Extensions Caught Routing Traffic Through Proxies. Check If You Have One",
          "link": "https://thehackernews.com/2026/08/737-chrome-vpn-extensions-caught.html",
          "published": "2026-08-12",
          "sev": "high"
        }
      ],
      "first_seen": "2026-08-12"
    },
    {
      "value": "158.160.228.178",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "The Hacker News"
      ],
      "articles": [
        {
          "id": "art-66",
          "title": "737 Chrome VPN Extensions Caught Routing Traffic Through Proxies. Check If You Have One",
          "link": "https://thehackernews.com/2026/08/737-chrome-vpn-extensions-caught.html",
          "published": "2026-08-12",
          "sev": "high"
        }
      ],
      "first_seen": "2026-08-12"
    },
    {
      "value": "178.130.47.129",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "The Hacker News"
      ],
      "articles": [
        {
          "id": "art-66",
          "title": "737 Chrome VPN Extensions Caught Routing Traffic Through Proxies. Check If You Have One",
          "link": "https://thehackernews.com/2026/08/737-chrome-vpn-extensions-caught.html",
          "published": "2026-08-12",
          "sev": "high"
        }
      ],
      "first_seen": "2026-08-12"
    },
    {
      "value": "178.130.47.43",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "The Hacker News"
      ],
      "articles": [
        {
          "id": "art-66",
          "title": "737 Chrome VPN Extensions Caught Routing Traffic Through Proxies. Check If You Have One",
          "link": "https://thehackernews.com/2026/08/737-chrome-vpn-extensions-caught.html",
          "published": "2026-08-12",
          "sev": "high"
        }
      ],
      "first_seen": "2026-08-12"
    },
    {
      "value": "178.130.47.44",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "The Hacker News"
      ],
      "articles": [
        {
          "id": "art-66",
          "title": "737 Chrome VPN Extensions Caught Routing Traffic Through Proxies. Check If You Have One",
          "link": "https://thehackernews.com/2026/08/737-chrome-vpn-extensions-caught.html",
          "published": "2026-08-12",
          "sev": "high"
        }
      ],
      "first_seen": "2026-08-12"
    },
    {
      "value": "178.130.47.50",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "The Hacker News"
      ],
      "articles": [
        {
          "id": "art-66",
          "title": "737 Chrome VPN Extensions Caught Routing Traffic Through Proxies. Check If You Have One",
          "link": "https://thehackernews.com/2026/08/737-chrome-vpn-extensions-caught.html",
          "published": "2026-08-12",
          "sev": "high"
        }
      ],
      "first_seen": "2026-08-12"
    },
    {
      "value": "185.252.215.97",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "The Hacker News"
      ],
      "articles": [
        {
          "id": "art-66",
          "title": "737 Chrome VPN Extensions Caught Routing Traffic Through Proxies. Check If You Have One",
          "link": "https://thehackernews.com/2026/08/737-chrome-vpn-extensions-caught.html",
          "published": "2026-08-12",
          "sev": "high"
        }
      ],
      "first_seen": "2026-08-12"
    },
    {
      "value": "185.252.215.98",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "The Hacker News"
      ],
      "articles": [
        {
          "id": "art-66",
          "title": "737 Chrome VPN Extensions Caught Routing Traffic Through Proxies. Check If You Have One",
          "link": "https://thehackernews.com/2026/08/737-chrome-vpn-extensions-caught.html",
          "published": "2026-08-12",
          "sev": "high"
        }
      ],
      "first_seen": "2026-08-12"
    },
    {
      "value": "194.150.220.163",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "The Hacker News"
      ],
      "articles": [
        {
          "id": "art-66",
          "title": "737 Chrome VPN Extensions Caught Routing Traffic Through Proxies. Check If You Have One",
          "link": "https://thehackernews.com/2026/08/737-chrome-vpn-extensions-caught.html",
          "published": "2026-08-12",
          "sev": "high"
        }
      ],
      "first_seen": "2026-08-12"
    },
    {
      "value": "212.192.14.75",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "The Hacker News"
      ],
      "articles": [
        {
          "id": "art-66",
          "title": "737 Chrome VPN Extensions Caught Routing Traffic Through Proxies. Check If You Have One",
          "link": "https://thehackernews.com/2026/08/737-chrome-vpn-extensions-caught.html",
          "published": "2026-08-12",
          "sev": "high"
        }
      ],
      "first_seen": "2026-08-12"
    },
    {
      "value": "45.89.110.227",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "The Hacker News"
      ],
      "articles": [
        {
          "id": "art-66",
          "title": "737 Chrome VPN Extensions Caught Routing Traffic Through Proxies. Check If You Have One",
          "link": "https://thehackernews.com/2026/08/737-chrome-vpn-extensions-caught.html",
          "published": "2026-08-12",
          "sev": "high"
        }
      ],
      "first_seen": "2026-08-12"
    },
    {
      "value": "46.151.182.203",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "StepSecurity",
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-65",
          "title": "Control Which Package Registries Your CI Jobs and Developer Machines Use",
          "link": "https://www.stepsecurity.io/blog/control-which-package-registries-your-ci-jobs-and-developer-machines-use",
          "published": "2026-08-12",
          "sev": "med"
        },
        {
          "id": "art-579",
          "title": "You Patched LiteLLM, But Do You Know Your AI Blast Radius?",
          "link": "https://snyk.io/blog/litellm-ai-blast-radius/",
          "published": "2026-04-02",
          "sev": "high"
        }
      ],
      "first_seen": "2026-08-12"
    },
    {
      "value": "5.180.30.122",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "The Hacker News"
      ],
      "articles": [
        {
          "id": "art-66",
          "title": "737 Chrome VPN Extensions Caught Routing Traffic Through Proxies. Check If You Have One",
          "link": "https://thehackernews.com/2026/08/737-chrome-vpn-extensions-caught.html",
          "published": "2026-08-12",
          "sev": "high"
        }
      ],
      "first_seen": "2026-08-12"
    },
    {
      "value": "5.180.30.15",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "The Hacker News"
      ],
      "articles": [
        {
          "id": "art-66",
          "title": "737 Chrome VPN Extensions Caught Routing Traffic Through Proxies. Check If You Have One",
          "link": "https://thehackernews.com/2026/08/737-chrome-vpn-extensions-caught.html",
          "published": "2026-08-12",
          "sev": "high"
        }
      ],
      "first_seen": "2026-08-12"
    },
    {
      "value": "78.153.155.112",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "The Hacker News"
      ],
      "articles": [
        {
          "id": "art-66",
          "title": "737 Chrome VPN Extensions Caught Routing Traffic Through Proxies. Check If You Have One",
          "link": "https://thehackernews.com/2026/08/737-chrome-vpn-extensions-caught.html",
          "published": "2026-08-12",
          "sev": "high"
        }
      ],
      "first_seen": "2026-08-12"
    },
    {
      "value": "80.92.204.33",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "The Hacker News"
      ],
      "articles": [
        {
          "id": "art-66",
          "title": "737 Chrome VPN Extensions Caught Routing Traffic Through Proxies. Check If You Have One",
          "link": "https://thehackernews.com/2026/08/737-chrome-vpn-extensions-caught.html",
          "published": "2026-08-12",
          "sev": "high"
        }
      ],
      "first_seen": "2026-08-12"
    },
    {
      "value": "80.92.204.47",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "The Hacker News"
      ],
      "articles": [
        {
          "id": "art-66",
          "title": "737 Chrome VPN Extensions Caught Routing Traffic Through Proxies. Check If You Have One",
          "link": "https://thehackernews.com/2026/08/737-chrome-vpn-extensions-caught.html",
          "published": "2026-08-12",
          "sev": "high"
        }
      ],
      "first_seen": "2026-08-12"
    },
    {
      "value": "80.92.206.84",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "The Hacker News"
      ],
      "articles": [
        {
          "id": "art-66",
          "title": "737 Chrome VPN Extensions Caught Routing Traffic Through Proxies. Check If You Have One",
          "link": "https://thehackernews.com/2026/08/737-chrome-vpn-extensions-caught.html",
          "published": "2026-08-12",
          "sev": "high"
        }
      ],
      "first_seen": "2026-08-12"
    },
    {
      "value": "81.90.31.73",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "The Hacker News"
      ],
      "articles": [
        {
          "id": "art-66",
          "title": "737 Chrome VPN Extensions Caught Routing Traffic Through Proxies. Check If You Have One",
          "link": "https://thehackernews.com/2026/08/737-chrome-vpn-extensions-caught.html",
          "published": "2026-08-12",
          "sev": "high"
        }
      ],
      "first_seen": "2026-08-12"
    },
    {
      "value": "86.104.74.110",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "The Hacker News"
      ],
      "articles": [
        {
          "id": "art-66",
          "title": "737 Chrome VPN Extensions Caught Routing Traffic Through Proxies. Check If You Have One",
          "link": "https://thehackernews.com/2026/08/737-chrome-vpn-extensions-caught.html",
          "published": "2026-08-12",
          "sev": "high"
        }
      ],
      "first_seen": "2026-08-12"
    },
    {
      "value": "94.131.118.237",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "The Hacker News"
      ],
      "articles": [
        {
          "id": "art-66",
          "title": "737 Chrome VPN Extensions Caught Routing Traffic Through Proxies. Check If You Have One",
          "link": "https://thehackernews.com/2026/08/737-chrome-vpn-extensions-caught.html",
          "published": "2026-08-12",
          "sev": "high"
        }
      ],
      "first_seen": "2026-08-12"
    },
    {
      "value": "94.131.118.39",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "The Hacker News"
      ],
      "articles": [
        {
          "id": "art-66",
          "title": "737 Chrome VPN Extensions Caught Routing Traffic Through Proxies. Check If You Have One",
          "link": "https://thehackernews.com/2026/08/737-chrome-vpn-extensions-caught.html",
          "published": "2026-08-12",
          "sev": "high"
        }
      ],
      "first_seen": "2026-08-12"
    },
    {
      "value": "95.163.244.138",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "The Hacker News"
      ],
      "articles": [
        {
          "id": "art-66",
          "title": "737 Chrome VPN Extensions Caught Routing Traffic Through Proxies. Check If You Have One",
          "link": "https://thehackernews.com/2026/08/737-chrome-vpn-extensions-caught.html",
          "published": "2026-08-12",
          "sev": "high"
        }
      ],
      "first_seen": "2026-08-12"
    },
    {
      "value": "167ce57ef59a32a6a0ef4137785828077879092d7f83ddbc1755d6e69116e0ad",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "med",
      "sources": [
        "StepSecurity"
      ],
      "articles": [
        {
          "id": "art-65",
          "title": "Control Which Package Registries Your CI Jobs and Developer Machines Use",
          "link": "https://www.stepsecurity.io/blog/control-which-package-registries-your-ci-jobs-and-developer-machines-use",
          "published": "2026-08-12",
          "sev": "med"
        }
      ],
      "first_seen": "2026-08-12"
    },
    {
      "value": "CVE-2016-5195",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "Unit 42 (Palo Alto)",
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-92",
          "title": "Kimwolf v7: An Evolution of the Kimwolf Botnet",
          "link": "https://unit42.paloaltonetworks.com/kimwolf-v7-botnet-malware/",
          "published": "2026-08-11",
          "sev": "crit"
        },
        {
          "id": "art-1310",
          "title": "CISA KEV: CVE-2024-36401 \u2014 OSGeo GeoServer GeoTools Eval Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-07-15",
          "sev": "crit"
        },
        {
          "id": "art-2576",
          "title": "CISA KEV: CVE-2016-5195 \u2014 Linux Kernel Race Condition Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-11"
    },
    {
      "value": "CVE-2021-31698",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "The Hacker News"
      ],
      "articles": [
        {
          "id": "art-85",
          "title": "A Malicious SIM Card Can Run Attacker Code Inside the Modems Behind Cellular IoT Devices",
          "link": "https://thehackernews.com/2026/08/a-malicious-sim-card-can-run-attacker.html",
          "published": "2026-08-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-11"
    },
    {
      "value": "CVE-2025-48618",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "The Hacker News"
      ],
      "articles": [
        {
          "id": "art-85",
          "title": "A Malicious SIM Card Can Run Attacker Code Inside the Modems Behind Cellular IoT Devices",
          "link": "https://thehackernews.com/2026/08/a-malicious-sim-card-can-run-attacker.html",
          "published": "2026-08-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-11"
    },
    {
      "value": "CVE-2026-15903",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "The Hacker News"
      ],
      "articles": [
        {
          "id": "art-84",
          "title": "OpenAI Launches GPT-5.6-Cyber with Reduced Safeguards for Exploit Development",
          "link": "https://thehackernews.com/2026/08/openai-launches-gpt-56-cyber-with.html",
          "published": "2026-08-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-11"
    },
    {
      "value": "CVE-2026-49163",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "The Hacker News",
        "Cisco Talos"
      ],
      "articles": [
        {
          "id": "art-78",
          "title": "Microsoft Patches 398 Flaws Including a Windows Driver Zero-Day Under Active Attack",
          "link": "https://thehackernews.com/2026/08/microsoft-patches-398-flaws-including.html",
          "published": "2026-08-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-11"
    },
    {
      "value": "CVE-2026-50481",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "The Hacker News",
        "Cisco Talos"
      ],
      "articles": [
        {
          "id": "art-78",
          "title": "Microsoft Patches 398 Flaws Including a Windows Driver Zero-Day Under Active Attack",
          "link": "https://thehackernews.com/2026/08/microsoft-patches-398-flaws-including.html",
          "published": "2026-08-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-11"
    },
    {
      "value": "CVE-2026-50515",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "The Hacker News",
        "Cisco Talos"
      ],
      "articles": [
        {
          "id": "art-78",
          "title": "Microsoft Patches 398 Flaws Including a Windows Driver Zero-Day Under Active Attack",
          "link": "https://thehackernews.com/2026/08/microsoft-patches-398-flaws-including.html",
          "published": "2026-08-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-11"
    },
    {
      "value": "CVE-2026-50516",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "The Hacker News",
        "Cisco Talos"
      ],
      "articles": [
        {
          "id": "art-78",
          "title": "Microsoft Patches 398 Flaws Including a Windows Driver Zero-Day Under Active Attack",
          "link": "https://thehackernews.com/2026/08/microsoft-patches-398-flaws-including.html",
          "published": "2026-08-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-11"
    },
    {
      "value": "CVE-2026-53413",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "The Hacker News"
      ],
      "articles": [
        {
          "id": "art-80",
          "title": "Zoom Annotation Flaws Could Let a Meeting Participant Hijack Another Attendee's Client",
          "link": "https://thehackernews.com/2026/08/zoom-annotation-flaws-could-let-meeting.html",
          "published": "2026-08-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-11"
    },
    {
      "value": "CVE-2026-53414",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "The Hacker News"
      ],
      "articles": [
        {
          "id": "art-80",
          "title": "Zoom Annotation Flaws Could Let a Meeting Participant Hijack Another Attendee's Client",
          "link": "https://thehackernews.com/2026/08/zoom-annotation-flaws-could-let-meeting.html",
          "published": "2026-08-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-11"
    },
    {
      "value": "CVE-2026-53415",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "The Hacker News"
      ],
      "articles": [
        {
          "id": "art-80",
          "title": "Zoom Annotation Flaws Could Let a Meeting Participant Hijack Another Attendee's Client",
          "link": "https://thehackernews.com/2026/08/zoom-annotation-flaws-could-let-meeting.html",
          "published": "2026-08-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-11"
    },
    {
      "value": "CVE-2026-56161",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "The Hacker News",
        "Cisco Talos"
      ],
      "articles": [
        {
          "id": "art-78",
          "title": "Microsoft Patches 398 Flaws Including a Windows Driver Zero-Day Under Active Attack",
          "link": "https://thehackernews.com/2026/08/microsoft-patches-398-flaws-including.html",
          "published": "2026-08-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-11"
    },
    {
      "value": "CVE-2026-56162",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "The Hacker News",
        "Cisco Talos"
      ],
      "articles": [
        {
          "id": "art-78",
          "title": "Microsoft Patches 398 Flaws Including a Windows Driver Zero-Day Under Active Attack",
          "link": "https://thehackernews.com/2026/08/microsoft-patches-398-flaws-including.html",
          "published": "2026-08-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-11"
    },
    {
      "value": "CVE-2026-57550",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "The Hacker News"
      ],
      "articles": [
        {
          "id": "art-85",
          "title": "A Malicious SIM Card Can Run Attacker Code Inside the Modems Behind Cellular IoT Devices",
          "link": "https://thehackernews.com/2026/08/a-malicious-sim-card-can-run-attacker.html",
          "published": "2026-08-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-11"
    },
    {
      "value": "CVE-2026-58650",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "The Hacker News",
        "Cisco Talos"
      ],
      "articles": [
        {
          "id": "art-78",
          "title": "Microsoft Patches 398 Flaws Including a Windows Driver Zero-Day Under Active Attack",
          "link": "https://thehackernews.com/2026/08/microsoft-patches-398-flaws-including.html",
          "published": "2026-08-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-11"
    },
    {
      "value": "CVE-2026-59115",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "The Hacker News",
        "Cisco Talos"
      ],
      "articles": [
        {
          "id": "art-78",
          "title": "Microsoft Patches 398 Flaws Including a Windows Driver Zero-Day Under Active Attack",
          "link": "https://thehackernews.com/2026/08/microsoft-patches-398-flaws-including.html",
          "published": "2026-08-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-11"
    },
    {
      "value": "CVE-2026-59118",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "The Hacker News",
        "Cisco Talos"
      ],
      "articles": [
        {
          "id": "art-78",
          "title": "Microsoft Patches 398 Flaws Including a Windows Driver Zero-Day Under Active Attack",
          "link": "https://thehackernews.com/2026/08/microsoft-patches-398-flaws-including.html",
          "published": "2026-08-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-11"
    },
    {
      "value": "CVE-2026-59124",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "The Hacker News",
        "Cisco Talos"
      ],
      "articles": [
        {
          "id": "art-78",
          "title": "Microsoft Patches 398 Flaws Including a Windows Driver Zero-Day Under Active Attack",
          "link": "https://thehackernews.com/2026/08/microsoft-patches-398-flaws-including.html",
          "published": "2026-08-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-11"
    },
    {
      "value": "CVE-2026-59132",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "The Hacker News",
        "Cisco Talos"
      ],
      "articles": [
        {
          "id": "art-78",
          "title": "Microsoft Patches 398 Flaws Including a Windows Driver Zero-Day Under Active Attack",
          "link": "https://thehackernews.com/2026/08/microsoft-patches-398-flaws-including.html",
          "published": "2026-08-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-11"
    },
    {
      "value": "CVE-2026-59133",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "The Hacker News",
        "Cisco Talos"
      ],
      "articles": [
        {
          "id": "art-78",
          "title": "Microsoft Patches 398 Flaws Including a Windows Driver Zero-Day Under Active Attack",
          "link": "https://thehackernews.com/2026/08/microsoft-patches-398-flaws-including.html",
          "published": "2026-08-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-11"
    },
    {
      "value": "CVE-2026-61348",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "The Hacker News",
        "Cisco Talos"
      ],
      "articles": [
        {
          "id": "art-78",
          "title": "Microsoft Patches 398 Flaws Including a Windows Driver Zero-Day Under Active Attack",
          "link": "https://thehackernews.com/2026/08/microsoft-patches-398-flaws-including.html",
          "published": "2026-08-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-11"
    },
    {
      "value": "CVE-2026-61358",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "The Hacker News",
        "Cisco Talos"
      ],
      "articles": [
        {
          "id": "art-78",
          "title": "Microsoft Patches 398 Flaws Including a Windows Driver Zero-Day Under Active Attack",
          "link": "https://thehackernews.com/2026/08/microsoft-patches-398-flaws-including.html",
          "published": "2026-08-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-11"
    },
    {
      "value": "CVE-2026-61925",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "The Hacker News",
        "Cisco Talos"
      ],
      "articles": [
        {
          "id": "art-78",
          "title": "Microsoft Patches 398 Flaws Including a Windows Driver Zero-Day Under Active Attack",
          "link": "https://thehackernews.com/2026/08/microsoft-patches-398-flaws-including.html",
          "published": "2026-08-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-11"
    },
    {
      "value": "CVE-2026-61929",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "The Hacker News",
        "Cisco Talos"
      ],
      "articles": [
        {
          "id": "art-78",
          "title": "Microsoft Patches 398 Flaws Including a Windows Driver Zero-Day Under Active Attack",
          "link": "https://thehackernews.com/2026/08/microsoft-patches-398-flaws-including.html",
          "published": "2026-08-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-11"
    },
    {
      "value": "CVE-2026-61930",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "The Hacker News",
        "Cisco Talos"
      ],
      "articles": [
        {
          "id": "art-78",
          "title": "Microsoft Patches 398 Flaws Including a Windows Driver Zero-Day Under Active Attack",
          "link": "https://thehackernews.com/2026/08/microsoft-patches-398-flaws-including.html",
          "published": "2026-08-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-11"
    },
    {
      "value": "CVE-2026-62688",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "The Hacker News",
        "Cisco Talos"
      ],
      "articles": [
        {
          "id": "art-78",
          "title": "Microsoft Patches 398 Flaws Including a Windows Driver Zero-Day Under Active Attack",
          "link": "https://thehackernews.com/2026/08/microsoft-patches-398-flaws-including.html",
          "published": "2026-08-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-11"
    },
    {
      "value": "CVE-2026-62696",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "The Hacker News",
        "Cisco Talos"
      ],
      "articles": [
        {
          "id": "art-78",
          "title": "Microsoft Patches 398 Flaws Including a Windows Driver Zero-Day Under Active Attack",
          "link": "https://thehackernews.com/2026/08/microsoft-patches-398-flaws-including.html",
          "published": "2026-08-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-11"
    },
    {
      "value": "CVE-2026-62698",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "The Hacker News",
        "Cisco Talos"
      ],
      "articles": [
        {
          "id": "art-78",
          "title": "Microsoft Patches 398 Flaws Including a Windows Driver Zero-Day Under Active Attack",
          "link": "https://thehackernews.com/2026/08/microsoft-patches-398-flaws-including.html",
          "published": "2026-08-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-11"
    },
    {
      "value": "CVE-2026-62712",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "The Hacker News",
        "Cisco Talos"
      ],
      "articles": [
        {
          "id": "art-78",
          "title": "Microsoft Patches 398 Flaws Including a Windows Driver Zero-Day Under Active Attack",
          "link": "https://thehackernews.com/2026/08/microsoft-patches-398-flaws-including.html",
          "published": "2026-08-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-11"
    },
    {
      "value": "CVE-2026-62713",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "The Hacker News",
        "Cisco Talos"
      ],
      "articles": [
        {
          "id": "art-78",
          "title": "Microsoft Patches 398 Flaws Including a Windows Driver Zero-Day Under Active Attack",
          "link": "https://thehackernews.com/2026/08/microsoft-patches-398-flaws-including.html",
          "published": "2026-08-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-11"
    },
    {
      "value": "CVE-2026-62721",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "The Hacker News",
        "Cisco Talos"
      ],
      "articles": [
        {
          "id": "art-78",
          "title": "Microsoft Patches 398 Flaws Including a Windows Driver Zero-Day Under Active Attack",
          "link": "https://thehackernews.com/2026/08/microsoft-patches-398-flaws-including.html",
          "published": "2026-08-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-11"
    },
    {
      "value": "CVE-2026-62735",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "The Hacker News",
        "Cisco Talos"
      ],
      "articles": [
        {
          "id": "art-78",
          "title": "Microsoft Patches 398 Flaws Including a Windows Driver Zero-Day Under Active Attack",
          "link": "https://thehackernews.com/2026/08/microsoft-patches-398-flaws-including.html",
          "published": "2026-08-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-11"
    },
    {
      "value": "CVE-2026-62737",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "The Hacker News",
        "Cisco Talos"
      ],
      "articles": [
        {
          "id": "art-78",
          "title": "Microsoft Patches 398 Flaws Including a Windows Driver Zero-Day Under Active Attack",
          "link": "https://thehackernews.com/2026/08/microsoft-patches-398-flaws-including.html",
          "published": "2026-08-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-11"
    },
    {
      "value": "CVE-2026-62741",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "The Hacker News",
        "Cisco Talos"
      ],
      "articles": [
        {
          "id": "art-78",
          "title": "Microsoft Patches 398 Flaws Including a Windows Driver Zero-Day Under Active Attack",
          "link": "https://thehackernews.com/2026/08/microsoft-patches-398-flaws-including.html",
          "published": "2026-08-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-11"
    },
    {
      "value": "CVE-2026-62766",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "The Hacker News",
        "Cisco Talos"
      ],
      "articles": [
        {
          "id": "art-78",
          "title": "Microsoft Patches 398 Flaws Including a Windows Driver Zero-Day Under Active Attack",
          "link": "https://thehackernews.com/2026/08/microsoft-patches-398-flaws-including.html",
          "published": "2026-08-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-11"
    },
    {
      "value": "CVE-2026-62783",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "The Hacker News",
        "Cisco Talos"
      ],
      "articles": [
        {
          "id": "art-78",
          "title": "Microsoft Patches 398 Flaws Including a Windows Driver Zero-Day Under Active Attack",
          "link": "https://thehackernews.com/2026/08/microsoft-patches-398-flaws-including.html",
          "published": "2026-08-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-11"
    },
    {
      "value": "CVE-2026-62788",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "The Hacker News",
        "Cisco Talos"
      ],
      "articles": [
        {
          "id": "art-78",
          "title": "Microsoft Patches 398 Flaws Including a Windows Driver Zero-Day Under Active Attack",
          "link": "https://thehackernews.com/2026/08/microsoft-patches-398-flaws-including.html",
          "published": "2026-08-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-11"
    },
    {
      "value": "CVE-2026-62815",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "The Hacker News",
        "Cisco Talos"
      ],
      "articles": [
        {
          "id": "art-78",
          "title": "Microsoft Patches 398 Flaws Including a Windows Driver Zero-Day Under Active Attack",
          "link": "https://thehackernews.com/2026/08/microsoft-patches-398-flaws-including.html",
          "published": "2026-08-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-11"
    },
    {
      "value": "CVE-2026-62816",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "The Hacker News",
        "Cisco Talos"
      ],
      "articles": [
        {
          "id": "art-78",
          "title": "Microsoft Patches 398 Flaws Including a Windows Driver Zero-Day Under Active Attack",
          "link": "https://thehackernews.com/2026/08/microsoft-patches-398-flaws-including.html",
          "published": "2026-08-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-11"
    },
    {
      "value": "CVE-2026-62817",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "The Hacker News",
        "Cisco Talos"
      ],
      "articles": [
        {
          "id": "art-78",
          "title": "Microsoft Patches 398 Flaws Including a Windows Driver Zero-Day Under Active Attack",
          "link": "https://thehackernews.com/2026/08/microsoft-patches-398-flaws-including.html",
          "published": "2026-08-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-11"
    },
    {
      "value": "CVE-2026-62818",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "The Hacker News",
        "Cisco Talos"
      ],
      "articles": [
        {
          "id": "art-78",
          "title": "Microsoft Patches 398 Flaws Including a Windows Driver Zero-Day Under Active Attack",
          "link": "https://thehackernews.com/2026/08/microsoft-patches-398-flaws-including.html",
          "published": "2026-08-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-11"
    },
    {
      "value": "CVE-2026-62819",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "The Hacker News",
        "Cisco Talos"
      ],
      "articles": [
        {
          "id": "art-78",
          "title": "Microsoft Patches 398 Flaws Including a Windows Driver Zero-Day Under Active Attack",
          "link": "https://thehackernews.com/2026/08/microsoft-patches-398-flaws-including.html",
          "published": "2026-08-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-11"
    },
    {
      "value": "CVE-2026-62820",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "The Hacker News",
        "Cisco Talos"
      ],
      "articles": [
        {
          "id": "art-78",
          "title": "Microsoft Patches 398 Flaws Including a Windows Driver Zero-Day Under Active Attack",
          "link": "https://thehackernews.com/2026/08/microsoft-patches-398-flaws-including.html",
          "published": "2026-08-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-11"
    },
    {
      "value": "CVE-2026-62822",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "The Hacker News",
        "Cisco Talos"
      ],
      "articles": [
        {
          "id": "art-78",
          "title": "Microsoft Patches 398 Flaws Including a Windows Driver Zero-Day Under Active Attack",
          "link": "https://thehackernews.com/2026/08/microsoft-patches-398-flaws-including.html",
          "published": "2026-08-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-11"
    },
    {
      "value": "CVE-2026-62823",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "The Hacker News",
        "Cisco Talos"
      ],
      "articles": [
        {
          "id": "art-78",
          "title": "Microsoft Patches 398 Flaws Including a Windows Driver Zero-Day Under Active Attack",
          "link": "https://thehackernews.com/2026/08/microsoft-patches-398-flaws-including.html",
          "published": "2026-08-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-11"
    },
    {
      "value": "CVE-2026-62824",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "The Hacker News",
        "Cisco Talos"
      ],
      "articles": [
        {
          "id": "art-78",
          "title": "Microsoft Patches 398 Flaws Including a Windows Driver Zero-Day Under Active Attack",
          "link": "https://thehackernews.com/2026/08/microsoft-patches-398-flaws-including.html",
          "published": "2026-08-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-11"
    },
    {
      "value": "CVE-2026-62827",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "The Hacker News",
        "Cisco Talos"
      ],
      "articles": [
        {
          "id": "art-78",
          "title": "Microsoft Patches 398 Flaws Including a Windows Driver Zero-Day Under Active Attack",
          "link": "https://thehackernews.com/2026/08/microsoft-patches-398-flaws-including.html",
          "published": "2026-08-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-11"
    },
    {
      "value": "CVE-2026-62830",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "The Hacker News",
        "Cisco Talos"
      ],
      "articles": [
        {
          "id": "art-78",
          "title": "Microsoft Patches 398 Flaws Including a Windows Driver Zero-Day Under Active Attack",
          "link": "https://thehackernews.com/2026/08/microsoft-patches-398-flaws-including.html",
          "published": "2026-08-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-11"
    },
    {
      "value": "CVE-2026-62836",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "The Hacker News",
        "Cisco Talos"
      ],
      "articles": [
        {
          "id": "art-78",
          "title": "Microsoft Patches 398 Flaws Including a Windows Driver Zero-Day Under Active Attack",
          "link": "https://thehackernews.com/2026/08/microsoft-patches-398-flaws-including.html",
          "published": "2026-08-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-11"
    },
    {
      "value": "CVE-2026-62869",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "The Hacker News",
        "Cisco Talos"
      ],
      "articles": [
        {
          "id": "art-78",
          "title": "Microsoft Patches 398 Flaws Including a Windows Driver Zero-Day Under Active Attack",
          "link": "https://thehackernews.com/2026/08/microsoft-patches-398-flaws-including.html",
          "published": "2026-08-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-11"
    },
    {
      "value": "CVE-2026-62873",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "The Hacker News",
        "Cisco Talos"
      ],
      "articles": [
        {
          "id": "art-78",
          "title": "Microsoft Patches 398 Flaws Including a Windows Driver Zero-Day Under Active Attack",
          "link": "https://thehackernews.com/2026/08/microsoft-patches-398-flaws-including.html",
          "published": "2026-08-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-11"
    },
    {
      "value": "CVE-2026-62878",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "The Hacker News",
        "Cisco Talos"
      ],
      "articles": [
        {
          "id": "art-78",
          "title": "Microsoft Patches 398 Flaws Including a Windows Driver Zero-Day Under Active Attack",
          "link": "https://thehackernews.com/2026/08/microsoft-patches-398-flaws-including.html",
          "published": "2026-08-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-11"
    },
    {
      "value": "CVE-2026-62888",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "The Hacker News",
        "Cisco Talos"
      ],
      "articles": [
        {
          "id": "art-78",
          "title": "Microsoft Patches 398 Flaws Including a Windows Driver Zero-Day Under Active Attack",
          "link": "https://thehackernews.com/2026/08/microsoft-patches-398-flaws-including.html",
          "published": "2026-08-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-11"
    },
    {
      "value": "CVE-2026-62889",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "The Hacker News",
        "Cisco Talos"
      ],
      "articles": [
        {
          "id": "art-78",
          "title": "Microsoft Patches 398 Flaws Including a Windows Driver Zero-Day Under Active Attack",
          "link": "https://thehackernews.com/2026/08/microsoft-patches-398-flaws-including.html",
          "published": "2026-08-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-11"
    },
    {
      "value": "CVE-2026-62890",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "The Hacker News",
        "Cisco Talos"
      ],
      "articles": [
        {
          "id": "art-78",
          "title": "Microsoft Patches 398 Flaws Including a Windows Driver Zero-Day Under Active Attack",
          "link": "https://thehackernews.com/2026/08/microsoft-patches-398-flaws-including.html",
          "published": "2026-08-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-11"
    },
    {
      "value": "CVE-2026-62893",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "The Hacker News",
        "Cisco Talos"
      ],
      "articles": [
        {
          "id": "art-78",
          "title": "Microsoft Patches 398 Flaws Including a Windows Driver Zero-Day Under Active Attack",
          "link": "https://thehackernews.com/2026/08/microsoft-patches-398-flaws-including.html",
          "published": "2026-08-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-11"
    },
    {
      "value": "CVE-2026-62896",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "The Hacker News",
        "Cisco Talos"
      ],
      "articles": [
        {
          "id": "art-78",
          "title": "Microsoft Patches 398 Flaws Including a Windows Driver Zero-Day Under Active Attack",
          "link": "https://thehackernews.com/2026/08/microsoft-patches-398-flaws-including.html",
          "published": "2026-08-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-11"
    },
    {
      "value": "CVE-2026-62911",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "The Hacker News",
        "Cisco Talos"
      ],
      "articles": [
        {
          "id": "art-78",
          "title": "Microsoft Patches 398 Flaws Including a Windows Driver Zero-Day Under Active Attack",
          "link": "https://thehackernews.com/2026/08/microsoft-patches-398-flaws-including.html",
          "published": "2026-08-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-11"
    },
    {
      "value": "CVE-2026-62918",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "The Hacker News",
        "Cisco Talos"
      ],
      "articles": [
        {
          "id": "art-78",
          "title": "Microsoft Patches 398 Flaws Including a Windows Driver Zero-Day Under Active Attack",
          "link": "https://thehackernews.com/2026/08/microsoft-patches-398-flaws-including.html",
          "published": "2026-08-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-11"
    },
    {
      "value": "CVE-2026-63508",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "The Hacker News",
        "Cisco Talos"
      ],
      "articles": [
        {
          "id": "art-78",
          "title": "Microsoft Patches 398 Flaws Including a Windows Driver Zero-Day Under Active Attack",
          "link": "https://thehackernews.com/2026/08/microsoft-patches-398-flaws-including.html",
          "published": "2026-08-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-11"
    },
    {
      "value": "CVE-2026-63513",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "The Hacker News",
        "Cisco Talos"
      ],
      "articles": [
        {
          "id": "art-78",
          "title": "Microsoft Patches 398 Flaws Including a Windows Driver Zero-Day Under Active Attack",
          "link": "https://thehackernews.com/2026/08/microsoft-patches-398-flaws-including.html",
          "published": "2026-08-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-11"
    },
    {
      "value": "CVE-2026-63515",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "The Hacker News",
        "Cisco Talos"
      ],
      "articles": [
        {
          "id": "art-78",
          "title": "Microsoft Patches 398 Flaws Including a Windows Driver Zero-Day Under Active Attack",
          "link": "https://thehackernews.com/2026/08/microsoft-patches-398-flaws-including.html",
          "published": "2026-08-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-11"
    },
    {
      "value": "CVE-2026-63518",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "The Hacker News",
        "Cisco Talos"
      ],
      "articles": [
        {
          "id": "art-78",
          "title": "Microsoft Patches 398 Flaws Including a Windows Driver Zero-Day Under Active Attack",
          "link": "https://thehackernews.com/2026/08/microsoft-patches-398-flaws-including.html",
          "published": "2026-08-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-11"
    },
    {
      "value": "CVE-2026-63519",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "The Hacker News",
        "Cisco Talos"
      ],
      "articles": [
        {
          "id": "art-78",
          "title": "Microsoft Patches 398 Flaws Including a Windows Driver Zero-Day Under Active Attack",
          "link": "https://thehackernews.com/2026/08/microsoft-patches-398-flaws-including.html",
          "published": "2026-08-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-11"
    },
    {
      "value": "CVE-2026-63520",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "The Hacker News",
        "Cisco Talos"
      ],
      "articles": [
        {
          "id": "art-78",
          "title": "Microsoft Patches 398 Flaws Including a Windows Driver Zero-Day Under Active Attack",
          "link": "https://thehackernews.com/2026/08/microsoft-patches-398-flaws-including.html",
          "published": "2026-08-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-11"
    },
    {
      "value": "CVE-2026-63522",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "The Hacker News",
        "Cisco Talos"
      ],
      "articles": [
        {
          "id": "art-78",
          "title": "Microsoft Patches 398 Flaws Including a Windows Driver Zero-Day Under Active Attack",
          "link": "https://thehackernews.com/2026/08/microsoft-patches-398-flaws-including.html",
          "published": "2026-08-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-11"
    },
    {
      "value": "CVE-2026-63525",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "The Hacker News",
        "Cisco Talos"
      ],
      "articles": [
        {
          "id": "art-78",
          "title": "Microsoft Patches 398 Flaws Including a Windows Driver Zero-Day Under Active Attack",
          "link": "https://thehackernews.com/2026/08/microsoft-patches-398-flaws-including.html",
          "published": "2026-08-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-11"
    },
    {
      "value": "CVE-2026-63526",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "The Hacker News",
        "Cisco Talos"
      ],
      "articles": [
        {
          "id": "art-78",
          "title": "Microsoft Patches 398 Flaws Including a Windows Driver Zero-Day Under Active Attack",
          "link": "https://thehackernews.com/2026/08/microsoft-patches-398-flaws-including.html",
          "published": "2026-08-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-11"
    },
    {
      "value": "CVE-2026-63532",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "The Hacker News",
        "Cisco Talos"
      ],
      "articles": [
        {
          "id": "art-78",
          "title": "Microsoft Patches 398 Flaws Including a Windows Driver Zero-Day Under Active Attack",
          "link": "https://thehackernews.com/2026/08/microsoft-patches-398-flaws-including.html",
          "published": "2026-08-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-11"
    },
    {
      "value": "CVE-2026-64898",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "The Hacker News",
        "Cisco Talos"
      ],
      "articles": [
        {
          "id": "art-78",
          "title": "Microsoft Patches 398 Flaws Including a Windows Driver Zero-Day Under Active Attack",
          "link": "https://thehackernews.com/2026/08/microsoft-patches-398-flaws-including.html",
          "published": "2026-08-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-11"
    },
    {
      "value": "CVE-2026-64903",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "The Hacker News",
        "Cisco Talos"
      ],
      "articles": [
        {
          "id": "art-78",
          "title": "Microsoft Patches 398 Flaws Including a Windows Driver Zero-Day Under Active Attack",
          "link": "https://thehackernews.com/2026/08/microsoft-patches-398-flaws-including.html",
          "published": "2026-08-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-11"
    },
    {
      "value": "CVE-2026-64907",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "The Hacker News",
        "Cisco Talos"
      ],
      "articles": [
        {
          "id": "art-78",
          "title": "Microsoft Patches 398 Flaws Including a Windows Driver Zero-Day Under Active Attack",
          "link": "https://thehackernews.com/2026/08/microsoft-patches-398-flaws-including.html",
          "published": "2026-08-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-11"
    },
    {
      "value": "CVE-2026-64909",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "The Hacker News",
        "Cisco Talos"
      ],
      "articles": [
        {
          "id": "art-78",
          "title": "Microsoft Patches 398 Flaws Including a Windows Driver Zero-Day Under Active Attack",
          "link": "https://thehackernews.com/2026/08/microsoft-patches-398-flaws-including.html",
          "published": "2026-08-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-11"
    },
    {
      "value": "CVE-2026-64910",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "The Hacker News",
        "Cisco Talos"
      ],
      "articles": [
        {
          "id": "art-78",
          "title": "Microsoft Patches 398 Flaws Including a Windows Driver Zero-Day Under Active Attack",
          "link": "https://thehackernews.com/2026/08/microsoft-patches-398-flaws-including.html",
          "published": "2026-08-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-11"
    },
    {
      "value": "CVE-2026-64911",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "The Hacker News",
        "Cisco Talos"
      ],
      "articles": [
        {
          "id": "art-78",
          "title": "Microsoft Patches 398 Flaws Including a Windows Driver Zero-Day Under Active Attack",
          "link": "https://thehackernews.com/2026/08/microsoft-patches-398-flaws-including.html",
          "published": "2026-08-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-11"
    },
    {
      "value": "CVE-2026-64921",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "The Hacker News",
        "Cisco Talos"
      ],
      "articles": [
        {
          "id": "art-78",
          "title": "Microsoft Patches 398 Flaws Including a Windows Driver Zero-Day Under Active Attack",
          "link": "https://thehackernews.com/2026/08/microsoft-patches-398-flaws-including.html",
          "published": "2026-08-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-11"
    },
    {
      "value": "CVE-2026-65657",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "The Hacker News",
        "Cisco Talos"
      ],
      "articles": [
        {
          "id": "art-78",
          "title": "Microsoft Patches 398 Flaws Including a Windows Driver Zero-Day Under Active Attack",
          "link": "https://thehackernews.com/2026/08/microsoft-patches-398-flaws-including.html",
          "published": "2026-08-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-11"
    },
    {
      "value": "CVE-2026-65664",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "The Hacker News",
        "Cisco Talos"
      ],
      "articles": [
        {
          "id": "art-78",
          "title": "Microsoft Patches 398 Flaws Including a Windows Driver Zero-Day Under Active Attack",
          "link": "https://thehackernews.com/2026/08/microsoft-patches-398-flaws-including.html",
          "published": "2026-08-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-11"
    },
    {
      "value": "CVE-2026-65665",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "The Hacker News",
        "Cisco Talos"
      ],
      "articles": [
        {
          "id": "art-78",
          "title": "Microsoft Patches 398 Flaws Including a Windows Driver Zero-Day Under Active Attack",
          "link": "https://thehackernews.com/2026/08/microsoft-patches-398-flaws-including.html",
          "published": "2026-08-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-11"
    },
    {
      "value": "CVE-2026-65667",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "The Hacker News",
        "Cisco Talos"
      ],
      "articles": [
        {
          "id": "art-78",
          "title": "Microsoft Patches 398 Flaws Including a Windows Driver Zero-Day Under Active Attack",
          "link": "https://thehackernews.com/2026/08/microsoft-patches-398-flaws-including.html",
          "published": "2026-08-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-11"
    },
    {
      "value": "CVE-2026-65668",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "The Hacker News",
        "Cisco Talos"
      ],
      "articles": [
        {
          "id": "art-78",
          "title": "Microsoft Patches 398 Flaws Including a Windows Driver Zero-Day Under Active Attack",
          "link": "https://thehackernews.com/2026/08/microsoft-patches-398-flaws-including.html",
          "published": "2026-08-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-11"
    },
    {
      "value": "CVE-2026-65775",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "The Hacker News",
        "Cisco Talos"
      ],
      "articles": [
        {
          "id": "art-78",
          "title": "Microsoft Patches 398 Flaws Including a Windows Driver Zero-Day Under Active Attack",
          "link": "https://thehackernews.com/2026/08/microsoft-patches-398-flaws-including.html",
          "published": "2026-08-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-11"
    },
    {
      "value": "CVE-2026-65788",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "The Hacker News",
        "Cisco Talos"
      ],
      "articles": [
        {
          "id": "art-78",
          "title": "Microsoft Patches 398 Flaws Including a Windows Driver Zero-Day Under Active Attack",
          "link": "https://thehackernews.com/2026/08/microsoft-patches-398-flaws-including.html",
          "published": "2026-08-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-11"
    },
    {
      "value": "CVE-2026-65789",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "The Hacker News",
        "Cisco Talos"
      ],
      "articles": [
        {
          "id": "art-78",
          "title": "Microsoft Patches 398 Flaws Including a Windows Driver Zero-Day Under Active Attack",
          "link": "https://thehackernews.com/2026/08/microsoft-patches-398-flaws-including.html",
          "published": "2026-08-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-11"
    },
    {
      "value": "CVE-2026-65791",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "The Hacker News",
        "Cisco Talos"
      ],
      "articles": [
        {
          "id": "art-78",
          "title": "Microsoft Patches 398 Flaws Including a Windows Driver Zero-Day Under Active Attack",
          "link": "https://thehackernews.com/2026/08/microsoft-patches-398-flaws-including.html",
          "published": "2026-08-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-11"
    },
    {
      "value": "CVE-2026-66799",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "The Hacker News",
        "Cisco Talos"
      ],
      "articles": [
        {
          "id": "art-78",
          "title": "Microsoft Patches 398 Flaws Including a Windows Driver Zero-Day Under Active Attack",
          "link": "https://thehackernews.com/2026/08/microsoft-patches-398-flaws-including.html",
          "published": "2026-08-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-11"
    },
    {
      "value": "CVE-2026-66802",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "The Hacker News",
        "Cisco Talos"
      ],
      "articles": [
        {
          "id": "art-78",
          "title": "Microsoft Patches 398 Flaws Including a Windows Driver Zero-Day Under Active Attack",
          "link": "https://thehackernews.com/2026/08/microsoft-patches-398-flaws-including.html",
          "published": "2026-08-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-11"
    },
    {
      "value": "CVE-2026-66804",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "The Hacker News",
        "Cisco Talos"
      ],
      "articles": [
        {
          "id": "art-78",
          "title": "Microsoft Patches 398 Flaws Including a Windows Driver Zero-Day Under Active Attack",
          "link": "https://thehackernews.com/2026/08/microsoft-patches-398-flaws-including.html",
          "published": "2026-08-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-11"
    },
    {
      "value": "CVE-2026-66807",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "The Hacker News",
        "Cisco Talos"
      ],
      "articles": [
        {
          "id": "art-78",
          "title": "Microsoft Patches 398 Flaws Including a Windows Driver Zero-Day Under Active Attack",
          "link": "https://thehackernews.com/2026/08/microsoft-patches-398-flaws-including.html",
          "published": "2026-08-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-11"
    },
    {
      "value": "CVE-2026-68794",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "The Hacker News",
        "Cisco Talos"
      ],
      "articles": [
        {
          "id": "art-78",
          "title": "Microsoft Patches 398 Flaws Including a Windows Driver Zero-Day Under Active Attack",
          "link": "https://thehackernews.com/2026/08/microsoft-patches-398-flaws-including.html",
          "published": "2026-08-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-11"
    },
    {
      "value": "CVE-2026-68804",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "The Hacker News",
        "Cisco Talos"
      ],
      "articles": [
        {
          "id": "art-78",
          "title": "Microsoft Patches 398 Flaws Including a Windows Driver Zero-Day Under Active Attack",
          "link": "https://thehackernews.com/2026/08/microsoft-patches-398-flaws-including.html",
          "published": "2026-08-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-11"
    },
    {
      "value": "CVE-2026-68816",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "The Hacker News",
        "Cisco Talos"
      ],
      "articles": [
        {
          "id": "art-78",
          "title": "Microsoft Patches 398 Flaws Including a Windows Driver Zero-Day Under Active Attack",
          "link": "https://thehackernews.com/2026/08/microsoft-patches-398-flaws-including.html",
          "published": "2026-08-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-11"
    },
    {
      "value": "CVE-2026-68823",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "The Hacker News",
        "Cisco Talos"
      ],
      "articles": [
        {
          "id": "art-78",
          "title": "Microsoft Patches 398 Flaws Including a Windows Driver Zero-Day Under Active Attack",
          "link": "https://thehackernews.com/2026/08/microsoft-patches-398-flaws-including.html",
          "published": "2026-08-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-11"
    },
    {
      "value": "CVE-2026-69278",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "The Hacker News",
        "Cisco Talos"
      ],
      "articles": [
        {
          "id": "art-78",
          "title": "Microsoft Patches 398 Flaws Including a Windows Driver Zero-Day Under Active Attack",
          "link": "https://thehackernews.com/2026/08/microsoft-patches-398-flaws-including.html",
          "published": "2026-08-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-11"
    },
    {
      "value": "CVE-2026-70130",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "The Hacker News",
        "Cisco Talos"
      ],
      "articles": [
        {
          "id": "art-78",
          "title": "Microsoft Patches 398 Flaws Including a Windows Driver Zero-Day Under Active Attack",
          "link": "https://thehackernews.com/2026/08/microsoft-patches-398-flaws-including.html",
          "published": "2026-08-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-11"
    },
    {
      "value": "CVE-2026-70307",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "The Hacker News",
        "Cisco Talos"
      ],
      "articles": [
        {
          "id": "art-78",
          "title": "Microsoft Patches 398 Flaws Including a Windows Driver Zero-Day Under Active Attack",
          "link": "https://thehackernews.com/2026/08/microsoft-patches-398-flaws-including.html",
          "published": "2026-08-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-11"
    },
    {
      "value": "CVE-2026-70332",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "The Hacker News",
        "Cisco Talos"
      ],
      "articles": [
        {
          "id": "art-78",
          "title": "Microsoft Patches 398 Flaws Including a Windows Driver Zero-Day Under Active Attack",
          "link": "https://thehackernews.com/2026/08/microsoft-patches-398-flaws-including.html",
          "published": "2026-08-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-11"
    },
    {
      "value": "CVE-2026-70335",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "The Hacker News",
        "Cisco Talos"
      ],
      "articles": [
        {
          "id": "art-78",
          "title": "Microsoft Patches 398 Flaws Including a Windows Driver Zero-Day Under Active Attack",
          "link": "https://thehackernews.com/2026/08/microsoft-patches-398-flaws-including.html",
          "published": "2026-08-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-11"
    },
    {
      "value": "CVE-2026-70355",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "The Hacker News",
        "Cisco Talos"
      ],
      "articles": [
        {
          "id": "art-78",
          "title": "Microsoft Patches 398 Flaws Including a Windows Driver Zero-Day Under Active Attack",
          "link": "https://thehackernews.com/2026/08/microsoft-patches-398-flaws-including.html",
          "published": "2026-08-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-11"
    },
    {
      "value": "CVE-2026-71331",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "The Hacker News",
        "Cisco Talos"
      ],
      "articles": [
        {
          "id": "art-78",
          "title": "Microsoft Patches 398 Flaws Including a Windows Driver Zero-Day Under Active Attack",
          "link": "https://thehackernews.com/2026/08/microsoft-patches-398-flaws-including.html",
          "published": "2026-08-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-11"
    },
    {
      "value": "CVE-2026-72898",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-95",
          "title": "CISA KEV: CVE-2026-72898 \u2014 Metabase SQL Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-08-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-11"
    },
    {
      "value": "CVE-2026-73080",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "GitHub Security Advisories"
      ],
      "articles": [
        {
          "id": "art-83",
          "title": "[GHSA / CRITICAL] CVE-2026-73080: SeaweedFS: Unauthenticated SSRF with response read-back via VolumeServer.FetchAndWriteNeedle",
          "link": "https://github.com/advisories/GHSA-87fv-vqqr-m4jr",
          "published": "2026-08-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-11"
    },
    {
      "value": "0xrpc.io",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "Unit 42 (Palo Alto)"
      ],
      "articles": [
        {
          "id": "art-92",
          "title": "Kimwolf v7: An Evolution of the Kimwolf Botnet",
          "link": "https://unit42.paloaltonetworks.com/kimwolf-v7-botnet-malware/",
          "published": "2026-08-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-11"
    },
    {
      "value": "avax.rpcuniverse.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "Unit 42 (Palo Alto)"
      ],
      "articles": [
        {
          "id": "art-92",
          "title": "Kimwolf v7: An Evolution of the Kimwolf Botnet",
          "link": "https://unit42.paloaltonetworks.com/kimwolf-v7-botnet-malware/",
          "published": "2026-08-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-11"
    },
    {
      "value": "bright-deals.site",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "Securelist (Kaspersky)"
      ],
      "articles": [
        {
          "id": "art-87",
          "title": "Head Mare APT is exploiting vulnerabilities in an unpatched TrueConf server to deliver PhantomCore and PhantomGraph to video conference participants",
          "link": "https://securelist.com/tr/head-mare-targets-trueconf-server-with-phantomcore/120988/",
          "published": "2026-08-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-11"
    },
    {
      "value": "cosmetic-deals.store",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "Securelist (Kaspersky)"
      ],
      "articles": [
        {
          "id": "art-87",
          "title": "Head Mare APT is exploiting vulnerabilities in an unpatched TrueConf server to deliver PhantomCore and PhantomGraph to video conference participants",
          "link": "https://securelist.com/tr/head-mare-targets-trueconf-server-with-phantomcore/120988/",
          "published": "2026-08-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-11"
    },
    {
      "value": "edctgwib2n5l34t525zkxqzk5bqb6e5il2yiq5r6zu7gtlxa4uosn3qd.onion",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "The Hacker News",
        "Unit 42 (Palo Alto)"
      ],
      "articles": [
        {
          "id": "art-79",
          "title": "Kimwolf v7 Android Botnet Makes HTTP/2 DDoS Traffic Look Like Legitimate Browsing",
          "link": "https://thehackernews.com/2026/08/kimwolf-v7-android-botnet-makes-http2.html",
          "published": "2026-08-11",
          "sev": "high"
        },
        {
          "id": "art-92",
          "title": "Kimwolf v7: An Evolution of the Kimwolf Botnet",
          "link": "https://unit42.paloaltonetworks.com/kimwolf-v7-botnet-malware/",
          "published": "2026-08-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-11"
    },
    {
      "value": "eth-protect.rpc.blxrbdn.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "Unit 42 (Palo Alto)"
      ],
      "articles": [
        {
          "id": "art-92",
          "title": "Kimwolf v7: An Evolution of the Kimwolf Botnet",
          "link": "https://unit42.paloaltonetworks.com/kimwolf-v7-botnet-malware/",
          "published": "2026-08-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-11"
    },
    {
      "value": "eth.llamarpc.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "Unit 42 (Palo Alto)"
      ],
      "articles": [
        {
          "id": "art-92",
          "title": "Kimwolf v7: An Evolution of the Kimwolf Botnet",
          "link": "https://unit42.paloaltonetworks.com/kimwolf-v7-botnet-malware/",
          "published": "2026-08-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-11"
    },
    {
      "value": "eth.merkle.io",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "Unit 42 (Palo Alto)"
      ],
      "articles": [
        {
          "id": "art-92",
          "title": "Kimwolf v7: An Evolution of the Kimwolf Botnet",
          "link": "https://unit42.paloaltonetworks.com/kimwolf-v7-botnet-malware/",
          "published": "2026-08-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-11"
    },
    {
      "value": "eth.rpcuniverse.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "Unit 42 (Palo Alto)"
      ],
      "articles": [
        {
          "id": "art-92",
          "title": "Kimwolf v7: An Evolution of the Kimwolf Botnet",
          "link": "https://unit42.paloaltonetworks.com/kimwolf-v7-botnet-malware/",
          "published": "2026-08-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-11"
    },
    {
      "value": "ethereum-rpc.publicnode.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "Unit 42 (Palo Alto)"
      ],
      "articles": [
        {
          "id": "art-92",
          "title": "Kimwolf v7: An Evolution of the Kimwolf Botnet",
          "link": "https://unit42.paloaltonetworks.com/kimwolf-v7-botnet-malware/",
          "published": "2026-08-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-11"
    },
    {
      "value": "flexish.shop",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "Securelist (Kaspersky)"
      ],
      "articles": [
        {
          "id": "art-87",
          "title": "Head Mare APT is exploiting vulnerabilities in an unpatched TrueConf server to deliver PhantomCore and PhantomGraph to video conference participants",
          "link": "https://securelist.com/tr/head-mare-targets-trueconf-server-with-phantomcore/120988/",
          "published": "2026-08-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-11"
    },
    {
      "value": "media-hub.today",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "Securelist (Kaspersky)"
      ],
      "articles": [
        {
          "id": "art-87",
          "title": "Head Mare APT is exploiting vulnerabilities in an unpatched TrueConf server to deliver PhantomCore and PhantomGraph to video conference participants",
          "link": "https://securelist.com/tr/head-mare-targets-trueconf-server-with-phantomcore/120988/",
          "published": "2026-08-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-11"
    },
    {
      "value": "nova-stream.site",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "Securelist (Kaspersky)"
      ],
      "articles": [
        {
          "id": "art-87",
          "title": "Head Mare APT is exploiting vulnerabilities in an unpatched TrueConf server to deliver PhantomCore and PhantomGraph to video conference participants",
          "link": "https://securelist.com/tr/head-mare-targets-trueconf-server-with-phantomcore/120988/",
          "published": "2026-08-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-11"
    },
    {
      "value": "penzadogshelter.site",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "Securelist (Kaspersky)"
      ],
      "articles": [
        {
          "id": "art-87",
          "title": "Head Mare APT is exploiting vulnerabilities in an unpatched TrueConf server to deliver PhantomCore and PhantomGraph to video conference participants",
          "link": "https://securelist.com/tr/head-mare-targets-trueconf-server-with-phantomcore/120988/",
          "published": "2026-08-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-11"
    },
    {
      "value": "rinomobile.ink",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "Securelist (Kaspersky)"
      ],
      "articles": [
        {
          "id": "art-87",
          "title": "Head Mare APT is exploiting vulnerabilities in an unpatched TrueConf server to deliver PhantomCore and PhantomGraph to video conference participants",
          "link": "https://securelist.com/tr/head-mare-targets-trueconf-server-with-phantomcore/120988/",
          "published": "2026-08-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-11"
    },
    {
      "value": "rpcuniverse.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "Unit 42 (Palo Alto)"
      ],
      "articles": [
        {
          "id": "art-92",
          "title": "Kimwolf v7: An Evolution of the Kimwolf Botnet",
          "link": "https://unit42.paloaltonetworks.com/kimwolf-v7-botnet-malware/",
          "published": "2026-08-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-11"
    },
    {
      "value": "soprasteria-bg.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "The Hacker News"
      ],
      "articles": [
        {
          "id": "art-81",
          "title": "Sandworm-Linked UAC-0145 Uses Fake Job Interviews to Push VPN That Can Run Commands",
          "link": "https://thehackernews.com/2026/08/sandworm-linked-uac-0145-uses-fake-job.html",
          "published": "2026-08-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-11"
    },
    {
      "value": "sourceforge.net",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "The Hacker News"
      ],
      "articles": [
        {
          "id": "art-81",
          "title": "Sandworm-Linked UAC-0145 Uses Fake Job Interviews to Push VPN That Can Run Commands",
          "link": "https://thehackernews.com/2026/08/sandworm-linked-uac-0145-uses-fake-job.html",
          "published": "2026-08-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-11"
    },
    {
      "value": "trendy-market.site",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "Securelist (Kaspersky)"
      ],
      "articles": [
        {
          "id": "art-87",
          "title": "Head Mare APT is exploiting vulnerabilities in an unpatched TrueConf server to deliver PhantomCore and PhantomGraph to video conference participants",
          "link": "https://securelist.com/tr/head-mare-targets-trueconf-server-with-phantomcore/120988/",
          "published": "2026-08-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-11"
    },
    {
      "value": "urbanpixel.store",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "Securelist (Kaspersky)"
      ],
      "articles": [
        {
          "id": "art-87",
          "title": "Head Mare APT is exploiting vulnerabilities in an unpatched TrueConf server to deliver PhantomCore and PhantomGraph to video conference participants",
          "link": "https://securelist.com/tr/head-mare-targets-trueconf-server-with-phantomcore/120988/",
          "published": "2026-08-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-11"
    },
    {
      "value": "vks.gossopka.forum",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "Securelist (Kaspersky)"
      ],
      "articles": [
        {
          "id": "art-87",
          "title": "Head Mare APT is exploiting vulnerabilities in an unpatched TrueConf server to deliver PhantomCore and PhantomGraph to video conference participants",
          "link": "https://securelist.com/tr/head-mare-targets-trueconf-server-with-phantomcore/120988/",
          "published": "2026-08-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-11"
    },
    {
      "value": "194.87.239.71",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "Securelist (Kaspersky)"
      ],
      "articles": [
        {
          "id": "art-87",
          "title": "Head Mare APT is exploiting vulnerabilities in an unpatched TrueConf server to deliver PhantomCore and PhantomGraph to video conference participants",
          "link": "https://securelist.com/tr/head-mare-targets-trueconf-server-with-phantomcore/120988/",
          "published": "2026-08-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-11"
    },
    {
      "value": "194.87.93.153",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "Securelist (Kaspersky)"
      ],
      "articles": [
        {
          "id": "art-87",
          "title": "Head Mare APT is exploiting vulnerabilities in an unpatched TrueConf server to deliver PhantomCore and PhantomGraph to video conference participants",
          "link": "https://securelist.com/tr/head-mare-targets-trueconf-server-with-phantomcore/120988/",
          "published": "2026-08-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-11"
    },
    {
      "value": "212.193.31.102",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "Unit 42 (Palo Alto)"
      ],
      "articles": [
        {
          "id": "art-92",
          "title": "Kimwolf v7: An Evolution of the Kimwolf Botnet",
          "link": "https://unit42.paloaltonetworks.com/kimwolf-v7-botnet-malware/",
          "published": "2026-08-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-11"
    },
    {
      "value": "212.193.31.119",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "Unit 42 (Palo Alto)"
      ],
      "articles": [
        {
          "id": "art-92",
          "title": "Kimwolf v7: An Evolution of the Kimwolf Botnet",
          "link": "https://unit42.paloaltonetworks.com/kimwolf-v7-botnet-malware/",
          "published": "2026-08-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-11"
    },
    {
      "value": "212.193.31.122",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "Unit 42 (Palo Alto)"
      ],
      "articles": [
        {
          "id": "art-92",
          "title": "Kimwolf v7: An Evolution of the Kimwolf Botnet",
          "link": "https://unit42.paloaltonetworks.com/kimwolf-v7-botnet-malware/",
          "published": "2026-08-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-11"
    },
    {
      "value": "212.193.31.158",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "Unit 42 (Palo Alto)"
      ],
      "articles": [
        {
          "id": "art-92",
          "title": "Kimwolf v7: An Evolution of the Kimwolf Botnet",
          "link": "https://unit42.paloaltonetworks.com/kimwolf-v7-botnet-malware/",
          "published": "2026-08-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-11"
    },
    {
      "value": "212.193.31.92",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "Unit 42 (Palo Alto)"
      ],
      "articles": [
        {
          "id": "art-92",
          "title": "Kimwolf v7: An Evolution of the Kimwolf Botnet",
          "link": "https://unit42.paloaltonetworks.com/kimwolf-v7-botnet-malware/",
          "published": "2026-08-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-11"
    },
    {
      "value": "23.94.221.104",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "Unit 42 (Palo Alto)"
      ],
      "articles": [
        {
          "id": "art-92",
          "title": "Kimwolf v7: An Evolution of the Kimwolf Botnet",
          "link": "https://unit42.paloaltonetworks.com/kimwolf-v7-botnet-malware/",
          "published": "2026-08-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-11"
    },
    {
      "value": "31.59.102.61",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "Securelist (Kaspersky)"
      ],
      "articles": [
        {
          "id": "art-87",
          "title": "Head Mare APT is exploiting vulnerabilities in an unpatched TrueConf server to deliver PhantomCore and PhantomGraph to video conference participants",
          "link": "https://securelist.com/tr/head-mare-targets-trueconf-server-with-phantomcore/120988/",
          "published": "2026-08-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-11"
    },
    {
      "value": "38.244.205.244",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "Securelist (Kaspersky)"
      ],
      "articles": [
        {
          "id": "art-87",
          "title": "Head Mare APT is exploiting vulnerabilities in an unpatched TrueConf server to deliver PhantomCore and PhantomGraph to video conference participants",
          "link": "https://securelist.com/tr/head-mare-targets-trueconf-server-with-phantomcore/120988/",
          "published": "2026-08-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-11"
    },
    {
      "value": "81.177.32.12",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "Securelist (Kaspersky)"
      ],
      "articles": [
        {
          "id": "art-87",
          "title": "Head Mare APT is exploiting vulnerabilities in an unpatched TrueConf server to deliver PhantomCore and PhantomGraph to video conference participants",
          "link": "https://securelist.com/tr/head-mare-targets-trueconf-server-with-phantomcore/120988/",
          "published": "2026-08-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-11"
    },
    {
      "value": "036bcb62be72c4663b9564955f93b05f",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "Unit 42 (Palo Alto)"
      ],
      "articles": [
        {
          "id": "art-92",
          "title": "Kimwolf v7: An Evolution of the Kimwolf Botnet",
          "link": "https://unit42.paloaltonetworks.com/kimwolf-v7-botnet-malware/",
          "published": "2026-08-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-11"
    },
    {
      "value": "0e4541c3153ec5ed01497f19cf4f63d0",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "Securelist (Kaspersky)"
      ],
      "articles": [
        {
          "id": "art-87",
          "title": "Head Mare APT is exploiting vulnerabilities in an unpatched TrueConf server to deliver PhantomCore and PhantomGraph to video conference participants",
          "link": "https://securelist.com/tr/head-mare-targets-trueconf-server-with-phantomcore/120988/",
          "published": "2026-08-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-11"
    },
    {
      "value": "0e79996d9483d1e44fea32b0a48c2c19",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "Securelist (Kaspersky)"
      ],
      "articles": [
        {
          "id": "art-87",
          "title": "Head Mare APT is exploiting vulnerabilities in an unpatched TrueConf server to deliver PhantomCore and PhantomGraph to video conference participants",
          "link": "https://securelist.com/tr/head-mare-targets-trueconf-server-with-phantomcore/120988/",
          "published": "2026-08-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-11"
    },
    {
      "value": "129462164a7d52e9ea8560b60f0412c5",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "Securelist (Kaspersky)"
      ],
      "articles": [
        {
          "id": "art-87",
          "title": "Head Mare APT is exploiting vulnerabilities in an unpatched TrueConf server to deliver PhantomCore and PhantomGraph to video conference participants",
          "link": "https://securelist.com/tr/head-mare-targets-trueconf-server-with-phantomcore/120988/",
          "published": "2026-08-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-11"
    },
    {
      "value": "12d4e8f5295f2ef7e0f9bfc0f4830939",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "Securelist (Kaspersky)"
      ],
      "articles": [
        {
          "id": "art-87",
          "title": "Head Mare APT is exploiting vulnerabilities in an unpatched TrueConf server to deliver PhantomCore and PhantomGraph to video conference participants",
          "link": "https://securelist.com/tr/head-mare-targets-trueconf-server-with-phantomcore/120988/",
          "published": "2026-08-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-11"
    },
    {
      "value": "2bb75c20e778eb5c416965bd4d4259b1",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "Securelist (Kaspersky)"
      ],
      "articles": [
        {
          "id": "art-87",
          "title": "Head Mare APT is exploiting vulnerabilities in an unpatched TrueConf server to deliver PhantomCore and PhantomGraph to video conference participants",
          "link": "https://securelist.com/tr/head-mare-targets-trueconf-server-with-phantomcore/120988/",
          "published": "2026-08-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-11"
    },
    {
      "value": "33faca1e0090f6b12eff703daf4606e4",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "Unit 42 (Palo Alto)"
      ],
      "articles": [
        {
          "id": "art-92",
          "title": "Kimwolf v7: An Evolution of the Kimwolf Botnet",
          "link": "https://unit42.paloaltonetworks.com/kimwolf-v7-botnet-malware/",
          "published": "2026-08-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-11"
    },
    {
      "value": "43f435c3c437bc879a2d7d4634f43494",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "Securelist (Kaspersky)"
      ],
      "articles": [
        {
          "id": "art-87",
          "title": "Head Mare APT is exploiting vulnerabilities in an unpatched TrueConf server to deliver PhantomCore and PhantomGraph to video conference participants",
          "link": "https://securelist.com/tr/head-mare-targets-trueconf-server-with-phantomcore/120988/",
          "published": "2026-08-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-11"
    },
    {
      "value": "489f43be558b2679284ceabed7adc4f3",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "Securelist (Kaspersky)"
      ],
      "articles": [
        {
          "id": "art-87",
          "title": "Head Mare APT is exploiting vulnerabilities in an unpatched TrueConf server to deliver PhantomCore and PhantomGraph to video conference participants",
          "link": "https://securelist.com/tr/head-mare-targets-trueconf-server-with-phantomcore/120988/",
          "published": "2026-08-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-11"
    },
    {
      "value": "4d27b4eb1c5dbb3d8160f29b8119523e",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "Securelist (Kaspersky)"
      ],
      "articles": [
        {
          "id": "art-87",
          "title": "Head Mare APT is exploiting vulnerabilities in an unpatched TrueConf server to deliver PhantomCore and PhantomGraph to video conference participants",
          "link": "https://securelist.com/tr/head-mare-targets-trueconf-server-with-phantomcore/120988/",
          "published": "2026-08-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-11"
    },
    {
      "value": "748c9f8cb1065000616204935f96207f",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "Securelist (Kaspersky)"
      ],
      "articles": [
        {
          "id": "art-87",
          "title": "Head Mare APT is exploiting vulnerabilities in an unpatched TrueConf server to deliver PhantomCore and PhantomGraph to video conference participants",
          "link": "https://securelist.com/tr/head-mare-targets-trueconf-server-with-phantomcore/120988/",
          "published": "2026-08-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-11"
    },
    {
      "value": "76554ad09897ac723a850eaf8c525efa",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "Unit 42 (Palo Alto)"
      ],
      "articles": [
        {
          "id": "art-92",
          "title": "Kimwolf v7: An Evolution of the Kimwolf Botnet",
          "link": "https://unit42.paloaltonetworks.com/kimwolf-v7-botnet-malware/",
          "published": "2026-08-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-11"
    },
    {
      "value": "7f267006cac10f341c356b62fe493527",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "Securelist (Kaspersky)"
      ],
      "articles": [
        {
          "id": "art-87",
          "title": "Head Mare APT is exploiting vulnerabilities in an unpatched TrueConf server to deliver PhantomCore and PhantomGraph to video conference participants",
          "link": "https://securelist.com/tr/head-mare-targets-trueconf-server-with-phantomcore/120988/",
          "published": "2026-08-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-11"
    },
    {
      "value": "8fcc3e4ccbf1725d9989fb464abf3561",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "Securelist (Kaspersky)"
      ],
      "articles": [
        {
          "id": "art-87",
          "title": "Head Mare APT is exploiting vulnerabilities in an unpatched TrueConf server to deliver PhantomCore and PhantomGraph to video conference participants",
          "link": "https://securelist.com/tr/head-mare-targets-trueconf-server-with-phantomcore/120988/",
          "published": "2026-08-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-11"
    },
    {
      "value": "aee9642b45b099cb7f3053b9b680b425",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "Securelist (Kaspersky)"
      ],
      "articles": [
        {
          "id": "art-87",
          "title": "Head Mare APT is exploiting vulnerabilities in an unpatched TrueConf server to deliver PhantomCore and PhantomGraph to video conference participants",
          "link": "https://securelist.com/tr/head-mare-targets-trueconf-server-with-phantomcore/120988/",
          "published": "2026-08-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-11"
    },
    {
      "value": "b348642146ea34771e5785c5857950f5",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "Securelist (Kaspersky)"
      ],
      "articles": [
        {
          "id": "art-87",
          "title": "Head Mare APT is exploiting vulnerabilities in an unpatched TrueConf server to deliver PhantomCore and PhantomGraph to video conference participants",
          "link": "https://securelist.com/tr/head-mare-targets-trueconf-server-with-phantomcore/120988/",
          "published": "2026-08-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-11"
    },
    {
      "value": "b3a6fee3307f1c26841fd5c603e2b013",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "Securelist (Kaspersky)"
      ],
      "articles": [
        {
          "id": "art-87",
          "title": "Head Mare APT is exploiting vulnerabilities in an unpatched TrueConf server to deliver PhantomCore and PhantomGraph to video conference participants",
          "link": "https://securelist.com/tr/head-mare-targets-trueconf-server-with-phantomcore/120988/",
          "published": "2026-08-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-11"
    },
    {
      "value": "c3a2abe8756910f42582b04a44ea3514",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "Securelist (Kaspersky)"
      ],
      "articles": [
        {
          "id": "art-87",
          "title": "Head Mare APT is exploiting vulnerabilities in an unpatched TrueConf server to deliver PhantomCore and PhantomGraph to video conference participants",
          "link": "https://securelist.com/tr/head-mare-targets-trueconf-server-with-phantomcore/120988/",
          "published": "2026-08-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-11"
    },
    {
      "value": "c5a460e4e68a088f6e51b2c6474642ec",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "Securelist (Kaspersky)"
      ],
      "articles": [
        {
          "id": "art-87",
          "title": "Head Mare APT is exploiting vulnerabilities in an unpatched TrueConf server to deliver PhantomCore and PhantomGraph to video conference participants",
          "link": "https://securelist.com/tr/head-mare-targets-trueconf-server-with-phantomcore/120988/",
          "published": "2026-08-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-11"
    },
    {
      "value": "c915cb6c2aeb863ee8479238e1644217",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "Securelist (Kaspersky)"
      ],
      "articles": [
        {
          "id": "art-87",
          "title": "Head Mare APT is exploiting vulnerabilities in an unpatched TrueConf server to deliver PhantomCore and PhantomGraph to video conference participants",
          "link": "https://securelist.com/tr/head-mare-targets-trueconf-server-with-phantomcore/120988/",
          "published": "2026-08-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-11"
    },
    {
      "value": "d759364844d78a728505fb0485c3adbc",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "Unit 42 (Palo Alto)"
      ],
      "articles": [
        {
          "id": "art-92",
          "title": "Kimwolf v7: An Evolution of the Kimwolf Botnet",
          "link": "https://unit42.paloaltonetworks.com/kimwolf-v7-botnet-malware/",
          "published": "2026-08-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-11"
    },
    {
      "value": "dd1fd2b459b97b7d59375cb8383cd19a",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "Securelist (Kaspersky)"
      ],
      "articles": [
        {
          "id": "art-87",
          "title": "Head Mare APT is exploiting vulnerabilities in an unpatched TrueConf server to deliver PhantomCore and PhantomGraph to video conference participants",
          "link": "https://securelist.com/tr/head-mare-targets-trueconf-server-with-phantomcore/120988/",
          "published": "2026-08-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-11"
    },
    {
      "value": "ec0bf4a2186a88874e9f26f07cfeb532",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "Securelist (Kaspersky)"
      ],
      "articles": [
        {
          "id": "art-87",
          "title": "Head Mare APT is exploiting vulnerabilities in an unpatched TrueConf server to deliver PhantomCore and PhantomGraph to video conference participants",
          "link": "https://securelist.com/tr/head-mare-targets-trueconf-server-with-phantomcore/120988/",
          "published": "2026-08-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-11"
    },
    {
      "value": "ee2861d5965e8730708cd1da8a93fa4c",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "Securelist (Kaspersky)"
      ],
      "articles": [
        {
          "id": "art-87",
          "title": "Head Mare APT is exploiting vulnerabilities in an unpatched TrueConf server to deliver PhantomCore and PhantomGraph to video conference participants",
          "link": "https://securelist.com/tr/head-mare-targets-trueconf-server-with-phantomcore/120988/",
          "published": "2026-08-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-11"
    },
    {
      "value": "14F26682D0916CDD81E37B6D61B7B526D98F0353",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "The Hacker News"
      ],
      "articles": [
        {
          "id": "art-86",
          "title": "Mozilla Revokes Firefox and Thunderbird Linux Signing Key After Key Lands in Private Repo",
          "link": "https://thehackernews.com/2026/08/mozilla-revokes-firefox-and-thunderbird.html",
          "published": "2026-08-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-11"
    },
    {
      "value": "2a1d96f1b066877812587ac94f45f82dfff5f5f9",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "Unit 42 (Palo Alto)"
      ],
      "articles": [
        {
          "id": "art-92",
          "title": "Kimwolf v7: An Evolution of the Kimwolf Botnet",
          "link": "https://unit42.paloaltonetworks.com/kimwolf-v7-botnet-malware/",
          "published": "2026-08-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-11"
    },
    {
      "value": "2ec2e85b0358e0c681cb5067489a9086ec97dbbf7e3c952dd9cd496b319d5af5",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "Unit 42 (Palo Alto)"
      ],
      "articles": [
        {
          "id": "art-92",
          "title": "Kimwolf v7: An Evolution of the Kimwolf Botnet",
          "link": "https://unit42.paloaltonetworks.com/kimwolf-v7-botnet-malware/",
          "published": "2026-08-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-11"
    },
    {
      "value": "345222bca004595977f971d76900b0c65fd9bf9d91c50cd0c5bf5a93f1ad9e49",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "Unit 42 (Palo Alto)"
      ],
      "articles": [
        {
          "id": "art-92",
          "title": "Kimwolf v7: An Evolution of the Kimwolf Botnet",
          "link": "https://unit42.paloaltonetworks.com/kimwolf-v7-botnet-malware/",
          "published": "2026-08-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-11"
    },
    {
      "value": "406647de09a0ffa279756b4ccb344b1b76a333320c5b50fd367901fa006cf0ff",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "Unit 42 (Palo Alto)"
      ],
      "articles": [
        {
          "id": "art-92",
          "title": "Kimwolf v7: An Evolution of the Kimwolf Botnet",
          "link": "https://unit42.paloaltonetworks.com/kimwolf-v7-botnet-malware/",
          "published": "2026-08-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-11"
    },
    {
      "value": "421111a57b0a4224c052fa4108d90429d579974b5b5111ed2e58516ba09422ca",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "Unit 42 (Palo Alto)"
      ],
      "articles": [
        {
          "id": "art-92",
          "title": "Kimwolf v7: An Evolution of the Kimwolf Botnet",
          "link": "https://unit42.paloaltonetworks.com/kimwolf-v7-botnet-malware/",
          "published": "2026-08-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-11"
    },
    {
      "value": "8242443dfcec66e3fe04cbfa2fbd211ad34065ee07aa93813d792a437caab212",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "Unit 42 (Palo Alto)"
      ],
      "articles": [
        {
          "id": "art-92",
          "title": "Kimwolf v7: An Evolution of the Kimwolf Botnet",
          "link": "https://unit42.paloaltonetworks.com/kimwolf-v7-botnet-malware/",
          "published": "2026-08-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-11"
    },
    {
      "value": "9470c68f9b6fe5f90d61891b95623afd7b4298815b0f95e25610e1c09008dc24",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "Unit 42 (Palo Alto)"
      ],
      "articles": [
        {
          "id": "art-92",
          "title": "Kimwolf v7: An Evolution of the Kimwolf Botnet",
          "link": "https://unit42.paloaltonetworks.com/kimwolf-v7-botnet-malware/",
          "published": "2026-08-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-11"
    },
    {
      "value": "951c94809aa6c7ab587125f9d4df30fa6a49ee0cbba76a4b7ceedaaa0e5dcd36",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "Unit 42 (Palo Alto)"
      ],
      "articles": [
        {
          "id": "art-92",
          "title": "Kimwolf v7: An Evolution of the Kimwolf Botnet",
          "link": "https://unit42.paloaltonetworks.com/kimwolf-v7-botnet-malware/",
          "published": "2026-08-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-11"
    },
    {
      "value": "f07821e313c16cbbd82def45094a22c8d474164051bdbc7648d6869e012014b4",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "Unit 42 (Palo Alto)"
      ],
      "articles": [
        {
          "id": "art-92",
          "title": "Kimwolf v7: An Evolution of the Kimwolf Botnet",
          "link": "https://unit42.paloaltonetworks.com/kimwolf-v7-botnet-malware/",
          "published": "2026-08-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-11"
    },
    {
      "value": "f3e8a55a2a3ea7c7b6676e90f4f49a2c55b13065b68ee50c51cc35fe2b5c3237",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "Unit 42 (Palo Alto)"
      ],
      "articles": [
        {
          "id": "art-92",
          "title": "Kimwolf v7: An Evolution of the Kimwolf Botnet",
          "link": "https://unit42.paloaltonetworks.com/kimwolf-v7-botnet-malware/",
          "published": "2026-08-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-11"
    },
    {
      "value": "api.studiotikva.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "Securelist (Kaspersky)"
      ],
      "articles": [
        {
          "id": "art-91",
          "title": "Project CAV3RN continues: Google Apps Script as C2 relay and DNS-based C2 channel selection",
          "link": "https://securelist.com/project-cav3rn-continues/120991/",
          "published": "2026-08-11",
          "sev": "high"
        }
      ],
      "first_seen": "2026-08-11"
    },
    {
      "value": "m.studiotikva.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "Securelist (Kaspersky)"
      ],
      "articles": [
        {
          "id": "art-91",
          "title": "Project CAV3RN continues: Google Apps Script as C2 relay and DNS-based C2 channel selection",
          "link": "https://securelist.com/project-cav3rn-continues/120991/",
          "published": "2026-08-11",
          "sev": "high"
        }
      ],
      "first_seen": "2026-08-11"
    },
    {
      "value": "ns1.studiotikva.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "Securelist (Kaspersky)"
      ],
      "articles": [
        {
          "id": "art-91",
          "title": "Project CAV3RN continues: Google Apps Script as C2 relay and DNS-based C2 channel selection",
          "link": "https://securelist.com/project-cav3rn-continues/120991/",
          "published": "2026-08-11",
          "sev": "high"
        }
      ],
      "first_seen": "2026-08-11"
    },
    {
      "value": "ns2.studiotikva.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "Securelist (Kaspersky)"
      ],
      "articles": [
        {
          "id": "art-91",
          "title": "Project CAV3RN continues: Google Apps Script as C2 relay and DNS-based C2 channel selection",
          "link": "https://securelist.com/project-cav3rn-continues/120991/",
          "published": "2026-08-11",
          "sev": "high"
        }
      ],
      "first_seen": "2026-08-11"
    },
    {
      "value": "p.studiotikva.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "Securelist (Kaspersky)"
      ],
      "articles": [
        {
          "id": "art-91",
          "title": "Project CAV3RN continues: Google Apps Script as C2 relay and DNS-based C2 channel selection",
          "link": "https://securelist.com/project-cav3rn-continues/120991/",
          "published": "2026-08-11",
          "sev": "high"
        }
      ],
      "first_seen": "2026-08-11"
    },
    {
      "value": "q.studiotikva.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "Securelist (Kaspersky)"
      ],
      "articles": [
        {
          "id": "art-91",
          "title": "Project CAV3RN continues: Google Apps Script as C2 relay and DNS-based C2 channel selection",
          "link": "https://securelist.com/project-cav3rn-continues/120991/",
          "published": "2026-08-11",
          "sev": "high"
        }
      ],
      "first_seen": "2026-08-11"
    },
    {
      "value": "script.googleusercontent.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "Securelist (Kaspersky)"
      ],
      "articles": [
        {
          "id": "art-91",
          "title": "Project CAV3RN continues: Google Apps Script as C2 relay and DNS-based C2 channel selection",
          "link": "https://securelist.com/project-cav3rn-continues/120991/",
          "published": "2026-08-11",
          "sev": "high"
        }
      ],
      "first_seen": "2026-08-11"
    },
    {
      "value": "ycz2.41414141303030.m.studiotikva.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "Securelist (Kaspersky)"
      ],
      "articles": [
        {
          "id": "art-91",
          "title": "Project CAV3RN continues: Google Apps Script as C2 relay and DNS-based C2 channel selection",
          "link": "https://securelist.com/project-cav3rn-continues/120991/",
          "published": "2026-08-11",
          "sev": "high"
        }
      ],
      "first_seen": "2026-08-11"
    },
    {
      "value": "12.121.234.120",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "Securelist (Kaspersky)"
      ],
      "articles": [
        {
          "id": "art-91",
          "title": "Project CAV3RN continues: Google Apps Script as C2 relay and DNS-based C2 channel selection",
          "link": "https://securelist.com/project-cav3rn-continues/120991/",
          "published": "2026-08-11",
          "sev": "high"
        }
      ],
      "first_seen": "2026-08-11"
    },
    {
      "value": "12.19.29.30",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "Securelist (Kaspersky)"
      ],
      "articles": [
        {
          "id": "art-91",
          "title": "Project CAV3RN continues: Google Apps Script as C2 relay and DNS-based C2 channel selection",
          "link": "https://securelist.com/project-cav3rn-continues/120991/",
          "published": "2026-08-11",
          "sev": "high"
        }
      ],
      "first_seen": "2026-08-11"
    },
    {
      "value": "138.226.236.51",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "The Hacker News"
      ],
      "articles": [
        {
          "id": "art-82",
          "title": "DeadLock Ransomware Uses Polygon Smart Contracts to Make Extortion Infra Harder to Disrupt",
          "link": "https://thehackernews.com/2026/08/deadlock-ransomware-uses-polygon-smart.html",
          "published": "2026-08-11",
          "sev": "high"
        }
      ],
      "first_seen": "2026-08-11"
    },
    {
      "value": "144.172.104.82",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "Securelist (Kaspersky)"
      ],
      "articles": [
        {
          "id": "art-91",
          "title": "Project CAV3RN continues: Google Apps Script as C2 relay and DNS-based C2 channel selection",
          "link": "https://securelist.com/project-cav3rn-continues/120991/",
          "published": "2026-08-11",
          "sev": "high"
        }
      ],
      "first_seen": "2026-08-11"
    },
    {
      "value": "144.172.115.17",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "Securelist (Kaspersky)"
      ],
      "articles": [
        {
          "id": "art-91",
          "title": "Project CAV3RN continues: Google Apps Script as C2 relay and DNS-based C2 channel selection",
          "link": "https://securelist.com/project-cav3rn-continues/120991/",
          "published": "2026-08-11",
          "sev": "high"
        }
      ],
      "first_seen": "2026-08-11"
    },
    {
      "value": "74.65.75.102",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "Securelist (Kaspersky)"
      ],
      "articles": [
        {
          "id": "art-91",
          "title": "Project CAV3RN continues: Google Apps Script as C2 relay and DNS-based C2 channel selection",
          "link": "https://securelist.com/project-cav3rn-continues/120991/",
          "published": "2026-08-11",
          "sev": "high"
        }
      ],
      "first_seen": "2026-08-11"
    },
    {
      "value": "2dcd4a8ac166404977cd3c48418a8cd9",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "Securelist (Kaspersky)"
      ],
      "articles": [
        {
          "id": "art-91",
          "title": "Project CAV3RN continues: Google Apps Script as C2 relay and DNS-based C2 channel selection",
          "link": "https://securelist.com/project-cav3rn-continues/120991/",
          "published": "2026-08-11",
          "sev": "high"
        }
      ],
      "first_seen": "2026-08-11"
    },
    {
      "value": "34d50eec364d920b8b5d885c9bc98607",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "Securelist (Kaspersky)"
      ],
      "articles": [
        {
          "id": "art-91",
          "title": "Project CAV3RN continues: Google Apps Script as C2 relay and DNS-based C2 channel selection",
          "link": "https://securelist.com/project-cav3rn-continues/120991/",
          "published": "2026-08-11",
          "sev": "high"
        }
      ],
      "first_seen": "2026-08-11"
    },
    {
      "value": "904784c9943d019da332bea2cd03996f",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "Securelist (Kaspersky)"
      ],
      "articles": [
        {
          "id": "art-91",
          "title": "Project CAV3RN continues: Google Apps Script as C2 relay and DNS-based C2 channel selection",
          "link": "https://securelist.com/project-cav3rn-continues/120991/",
          "published": "2026-08-11",
          "sev": "high"
        }
      ],
      "first_seen": "2026-08-11"
    },
    {
      "value": "981c7404d31b8ce35ec88a6b290f354d",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "Securelist (Kaspersky)"
      ],
      "articles": [
        {
          "id": "art-91",
          "title": "Project CAV3RN continues: Google Apps Script as C2 relay and DNS-based C2 channel selection",
          "link": "https://securelist.com/project-cav3rn-continues/120991/",
          "published": "2026-08-11",
          "sev": "high"
        }
      ],
      "first_seen": "2026-08-11"
    },
    {
      "value": "f9156d42410c8a5429dec43329bd72e0",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "Securelist (Kaspersky)"
      ],
      "articles": [
        {
          "id": "art-91",
          "title": "Project CAV3RN continues: Google Apps Script as C2 relay and DNS-based C2 channel selection",
          "link": "https://securelist.com/project-cav3rn-continues/120991/",
          "published": "2026-08-11",
          "sev": "high"
        }
      ],
      "first_seen": "2026-08-11"
    },
    {
      "value": "CVE-2026-33825",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "Securelist (Kaspersky)",
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-99",
          "title": "IT threat evolution in Q2 2026. Non-mobile statistics",
          "link": "https://securelist.com/malware-report-q2-2026-pc-iot-statistics/120960/",
          "published": "2026-08-10",
          "sev": "crit"
        },
        {
          "id": "art-535",
          "title": "CISA KEV: CVE-2026-33825 \u2014 Microsoft Defender Insufficient Granularity of Access Control Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-04-22",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-10"
    },
    {
      "value": "CVE-2026-50751",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "Securelist (Kaspersky)",
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-99",
          "title": "IT threat evolution in Q2 2026. Non-mobile statistics",
          "link": "https://securelist.com/malware-report-q2-2026-pc-iot-statistics/120960/",
          "published": "2026-08-10",
          "sev": "crit"
        },
        {
          "id": "art-404",
          "title": "CISA KEV: CVE-2026-50751 \u2014 Check Point Security Gateway Improper Authentication Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-06-08",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-10"
    },
    {
      "value": "CVE-2026-50752",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "Securelist (Kaspersky)",
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-99",
          "title": "IT threat evolution in Q2 2026. Non-mobile statistics",
          "link": "https://securelist.com/malware-report-q2-2026-pc-iot-statistics/120960/",
          "published": "2026-08-10",
          "sev": "crit"
        },
        {
          "id": "art-404",
          "title": "CISA KEV: CVE-2026-50751 \u2014 Check Point Security Gateway Improper Authentication Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-06-08",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-10"
    },
    {
      "value": "1rpc.io",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "Microsoft Security Blog"
      ],
      "articles": [
        {
          "id": "art-98",
          "title": "DeadLock ransomware: Breaking down a Rust-based encryptor with decentralized recovery infrastructure",
          "link": "https://www.microsoft.com/en-us/security/blog/2026/08/10/deadlock-ransomware-breaking-down-a-rust-based-encryptor-with-decentralized-recovery-infrastructure/",
          "published": "2026-08-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-10"
    },
    {
      "value": "api.noderpc.xyz",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "Unit 42 (Palo Alto)"
      ],
      "articles": [
        {
          "id": "art-96",
          "title": "The Permanent Threat: Analyzing Aeternum\u2019s Blockchain-Based C2 Operations and Communications",
          "link": "https://unit42.paloaltonetworks.com/aeternum-blockchain-c2-analysis/",
          "published": "2026-08-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-10"
    },
    {
      "value": "api.zan.top",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "Unit 42 (Palo Alto)"
      ],
      "articles": [
        {
          "id": "art-96",
          "title": "The Permanent Threat: Analyzing Aeternum\u2019s Blockchain-Based C2 Operations and Communications",
          "link": "https://unit42.paloaltonetworks.com/aeternum-blockchain-c2-analysis/",
          "published": "2026-08-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-10"
    },
    {
      "value": "cdnjsdelivr.beer",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "Unit 42 (Palo Alto)"
      ],
      "articles": [
        {
          "id": "art-96",
          "title": "The Permanent Threat: Analyzing Aeternum\u2019s Blockchain-Based C2 Operations and Communications",
          "link": "https://unit42.paloaltonetworks.com/aeternum-blockchain-c2-analysis/",
          "published": "2026-08-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-10"
    },
    {
      "value": "deadblogdbdu5wprek7wa2o4ce7rnt6u6ntqeud3hzjjcveosgpsqqqd.onion",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "Microsoft Security Blog"
      ],
      "articles": [
        {
          "id": "art-98",
          "title": "DeadLock ransomware: Breaking down a Rust-based encryptor with decentralized recovery infrastructure",
          "link": "https://www.microsoft.com/en-us/security/blog/2026/08/10/deadlock-ransomware-breaking-down-a-rust-based-encryptor-with-decentralized-recovery-infrastructure/",
          "published": "2026-08-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-10"
    },
    {
      "value": "deadlock.liveblog365.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "Microsoft Security Blog"
      ],
      "articles": [
        {
          "id": "art-98",
          "title": "DeadLock ransomware: Breaking down a Rust-based encryptor with decentralized recovery infrastructure",
          "link": "https://www.microsoft.com/en-us/security/blog/2026/08/10/deadlock-ransomware-breaking-down-a-rust-based-encryptor-with-decentralized-recovery-infrastructure/",
          "published": "2026-08-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-10"
    },
    {
      "value": "deadlockblog.great-site.net",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "Microsoft Security Blog"
      ],
      "articles": [
        {
          "id": "art-98",
          "title": "DeadLock ransomware: Breaking down a Rust-based encryptor with decentralized recovery infrastructure",
          "link": "https://www.microsoft.com/en-us/security/blog/2026/08/10/deadlock-ransomware-breaking-down-a-rust-based-encryptor-with-decentralized-recovery-infrastructure/",
          "published": "2026-08-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-10"
    },
    {
      "value": "deadlockblog.medianewsonline.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "Microsoft Security Blog"
      ],
      "articles": [
        {
          "id": "art-98",
          "title": "DeadLock ransomware: Breaking down a Rust-based encryptor with decentralized recovery infrastructure",
          "link": "https://www.microsoft.com/en-us/security/blog/2026/08/10/deadlock-ransomware-breaking-down-a-rust-based-encryptor-with-decentralized-recovery-infrastructure/",
          "published": "2026-08-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-10"
    },
    {
      "value": "dlock.liveblog365.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "Microsoft Security Blog"
      ],
      "articles": [
        {
          "id": "art-98",
          "title": "DeadLock ransomware: Breaking down a Rust-based encryptor with decentralized recovery infrastructure",
          "link": "https://www.microsoft.com/en-us/security/blog/2026/08/10/deadlock-ransomware-breaking-down-a-rust-based-encryptor-with-decentralized-recovery-infrastructure/",
          "published": "2026-08-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-10"
    },
    {
      "value": "download.sftp-api-group-wechat.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "Unit 42 (Palo Alto)"
      ],
      "articles": [
        {
          "id": "art-96",
          "title": "The Permanent Threat: Analyzing Aeternum\u2019s Blockchain-Based C2 Operations and Communications",
          "link": "https://unit42.paloaltonetworks.com/aeternum-blockchain-c2-analysis/",
          "published": "2026-08-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-10"
    },
    {
      "value": "endpoints.omniatech.io",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "Unit 42 (Palo Alto)"
      ],
      "articles": [
        {
          "id": "art-96",
          "title": "The Permanent Threat: Analyzing Aeternum\u2019s Blockchain-Based C2 Operations and Communications",
          "link": "https://unit42.paloaltonetworks.com/aeternum-blockchain-c2-analysis/",
          "published": "2026-08-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-10"
    },
    {
      "value": "gateway.tenderly.co",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "Unit 42 (Palo Alto)"
      ],
      "articles": [
        {
          "id": "art-96",
          "title": "The Permanent Threat: Analyzing Aeternum\u2019s Blockchain-Based C2 Operations and Communications",
          "link": "https://unit42.paloaltonetworks.com/aeternum-blockchain-c2-analysis/",
          "published": "2026-08-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-10"
    },
    {
      "value": "polygon-amoy.gateway.tenderly.co",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "Unit 42 (Palo Alto)"
      ],
      "articles": [
        {
          "id": "art-96",
          "title": "The Permanent Threat: Analyzing Aeternum\u2019s Blockchain-Based C2 Operations and Communications",
          "link": "https://unit42.paloaltonetworks.com/aeternum-blockchain-c2-analysis/",
          "published": "2026-08-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-10"
    },
    {
      "value": "polygon-amoy.therpc.io",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "Unit 42 (Palo Alto)"
      ],
      "articles": [
        {
          "id": "art-96",
          "title": "The Permanent Threat: Analyzing Aeternum\u2019s Blockchain-Based C2 Operations and Communications",
          "link": "https://unit42.paloaltonetworks.com/aeternum-blockchain-c2-analysis/",
          "published": "2026-08-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-10"
    },
    {
      "value": "polygon-bor-rpc.publicnode.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "Microsoft Security Blog"
      ],
      "articles": [
        {
          "id": "art-98",
          "title": "DeadLock ransomware: Breaking down a Rust-based encryptor with decentralized recovery infrastructure",
          "link": "https://www.microsoft.com/en-us/security/blog/2026/08/10/deadlock-ransomware-breaking-down-a-rust-based-encryptor-with-decentralized-recovery-infrastructure/",
          "published": "2026-08-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-10"
    },
    {
      "value": "polygon-mainnet.g.alchemy.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "Unit 42 (Palo Alto)"
      ],
      "articles": [
        {
          "id": "art-96",
          "title": "The Permanent Threat: Analyzing Aeternum\u2019s Blockchain-Based C2 Operations and Communications",
          "link": "https://unit42.paloaltonetworks.com/aeternum-blockchain-c2-analysis/",
          "published": "2026-08-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-10"
    },
    {
      "value": "polygon-mumbai-bor-rpc.publicnode.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "Unit 42 (Palo Alto)"
      ],
      "articles": [
        {
          "id": "art-96",
          "title": "The Permanent Threat: Analyzing Aeternum\u2019s Blockchain-Based C2 Operations and Communications",
          "link": "https://unit42.paloaltonetworks.com/aeternum-blockchain-c2-analysis/",
          "published": "2026-08-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-10"
    },
    {
      "value": "polygon-mumbai.g.alchemy.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "Unit 42 (Palo Alto)"
      ],
      "articles": [
        {
          "id": "art-96",
          "title": "The Permanent Threat: Analyzing Aeternum\u2019s Blockchain-Based C2 Operations and Communications",
          "link": "https://unit42.paloaltonetworks.com/aeternum-blockchain-c2-analysis/",
          "published": "2026-08-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-10"
    },
    {
      "value": "polygon-mumbai.gateway.tenderly.co",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "Unit 42 (Palo Alto)"
      ],
      "articles": [
        {
          "id": "art-96",
          "title": "The Permanent Threat: Analyzing Aeternum\u2019s Blockchain-Based C2 Operations and Communications",
          "link": "https://unit42.paloaltonetworks.com/aeternum-blockchain-c2-analysis/",
          "published": "2026-08-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-10"
    },
    {
      "value": "polygon-pokt.nodies.app",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "Unit 42 (Palo Alto)",
        "Microsoft Security Blog"
      ],
      "articles": [
        {
          "id": "art-96",
          "title": "The Permanent Threat: Analyzing Aeternum\u2019s Blockchain-Based C2 Operations and Communications",
          "link": "https://unit42.paloaltonetworks.com/aeternum-blockchain-c2-analysis/",
          "published": "2026-08-10",
          "sev": "crit"
        },
        {
          "id": "art-98",
          "title": "DeadLock ransomware: Breaking down a Rust-based encryptor with decentralized recovery infrastructure",
          "link": "https://www.microsoft.com/en-us/security/blog/2026/08/10/deadlock-ransomware-breaking-down-a-rust-based-encryptor-with-decentralized-recovery-infrastructure/",
          "published": "2026-08-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-10"
    },
    {
      "value": "polygon-rpc.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "Microsoft Security Blog",
        "Cisco Talos"
      ],
      "articles": [
        {
          "id": "art-98",
          "title": "DeadLock ransomware: Breaking down a Rust-based encryptor with decentralized recovery infrastructure",
          "link": "https://www.microsoft.com/en-us/security/blog/2026/08/10/deadlock-ransomware-breaking-down-a-rust-based-encryptor-with-decentralized-recovery-infrastructure/",
          "published": "2026-08-10",
          "sev": "crit"
        },
        {
          "id": "art-253",
          "title": "Begun, the Patch Wars have",
          "link": "https://blog.talosintelligence.com/begun-the-patch-wars-have/",
          "published": "2026-07-16",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-10"
    },
    {
      "value": "polygon-zkevm-mainnet.public.blastapi.io",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "Unit 42 (Palo Alto)"
      ],
      "articles": [
        {
          "id": "art-96",
          "title": "The Permanent Threat: Analyzing Aeternum\u2019s Blockchain-Based C2 Operations and Communications",
          "link": "https://unit42.paloaltonetworks.com/aeternum-blockchain-c2-analysis/",
          "published": "2026-08-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-10"
    },
    {
      "value": "polygon-zkevm.drpc.org",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "Unit 42 (Palo Alto)"
      ],
      "articles": [
        {
          "id": "art-96",
          "title": "The Permanent Threat: Analyzing Aeternum\u2019s Blockchain-Based C2 Operations and Communications",
          "link": "https://unit42.paloaltonetworks.com/aeternum-blockchain-c2-analysis/",
          "published": "2026-08-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-10"
    },
    {
      "value": "polygon.drpc.org",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "Microsoft Security Blog"
      ],
      "articles": [
        {
          "id": "art-98",
          "title": "DeadLock ransomware: Breaking down a Rust-based encryptor with decentralized recovery infrastructure",
          "link": "https://www.microsoft.com/en-us/security/blog/2026/08/10/deadlock-ransomware-breaking-down-a-rust-based-encryptor-with-decentralized-recovery-infrastructure/",
          "published": "2026-08-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-10"
    },
    {
      "value": "polygon.meowrpc.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "Microsoft Security Blog"
      ],
      "articles": [
        {
          "id": "art-98",
          "title": "DeadLock ransomware: Breaking down a Rust-based encryptor with decentralized recovery infrastructure",
          "link": "https://www.microsoft.com/en-us/security/blog/2026/08/10/deadlock-ransomware-breaking-down-a-rust-based-encryptor-with-decentralized-recovery-infrastructure/",
          "published": "2026-08-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-10"
    },
    {
      "value": "polygon.rpc.hypersync.xyz",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "Unit 42 (Palo Alto)"
      ],
      "articles": [
        {
          "id": "art-96",
          "title": "The Permanent Threat: Analyzing Aeternum\u2019s Blockchain-Based C2 Operations and Communications",
          "link": "https://unit42.paloaltonetworks.com/aeternum-blockchain-c2-analysis/",
          "published": "2026-08-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-10"
    },
    {
      "value": "polygontestapi.terminet.io",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "Unit 42 (Palo Alto)"
      ],
      "articles": [
        {
          "id": "art-96",
          "title": "The Permanent Threat: Analyzing Aeternum\u2019s Blockchain-Based C2 Operations and Communications",
          "link": "https://unit42.paloaltonetworks.com/aeternum-blockchain-c2-analysis/",
          "published": "2026-08-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-10"
    },
    {
      "value": "public.stackup.sh",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "Unit 42 (Palo Alto)"
      ],
      "articles": [
        {
          "id": "art-96",
          "title": "The Permanent Threat: Analyzing Aeternum\u2019s Blockchain-Based C2 Operations and Communications",
          "link": "https://unit42.paloaltonetworks.com/aeternum-blockchain-c2-analysis/",
          "published": "2026-08-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-10"
    },
    {
      "value": "rpc.polygon-zkevm.gateway.fm",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "Unit 42 (Palo Alto)"
      ],
      "articles": [
        {
          "id": "art-96",
          "title": "The Permanent Threat: Analyzing Aeternum\u2019s Blockchain-Based C2 Operations and Communications",
          "link": "https://unit42.paloaltonetworks.com/aeternum-blockchain-c2-analysis/",
          "published": "2026-08-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-10"
    },
    {
      "value": "rpc.polygonsupernet.public.arianee.net",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "Unit 42 (Palo Alto)"
      ],
      "articles": [
        {
          "id": "art-96",
          "title": "The Permanent Threat: Analyzing Aeternum\u2019s Blockchain-Based C2 Operations and Communications",
          "link": "https://unit42.paloaltonetworks.com/aeternum-blockchain-c2-analysis/",
          "published": "2026-08-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-10"
    },
    {
      "value": "rpc.poolz.finance",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "Unit 42 (Palo Alto)"
      ],
      "articles": [
        {
          "id": "art-96",
          "title": "The Permanent Threat: Analyzing Aeternum\u2019s Blockchain-Based C2 Operations and Communications",
          "link": "https://unit42.paloaltonetworks.com/aeternum-blockchain-c2-analysis/",
          "published": "2026-08-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-10"
    },
    {
      "value": "sekirolegion.duckdns.org",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "Unit 42 (Palo Alto)"
      ],
      "articles": [
        {
          "id": "art-96",
          "title": "The Permanent Threat: Analyzing Aeternum\u2019s Blockchain-Based C2 Operations and Communications",
          "link": "https://unit42.paloaltonetworks.com/aeternum-blockchain-c2-analysis/",
          "published": "2026-08-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-10"
    },
    {
      "value": "test-steve.cyou",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "Unit 42 (Palo Alto)"
      ],
      "articles": [
        {
          "id": "art-96",
          "title": "The Permanent Threat: Analyzing Aeternum\u2019s Blockchain-Based C2 Operations and Communications",
          "link": "https://unit42.paloaltonetworks.com/aeternum-blockchain-c2-analysis/",
          "published": "2026-08-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-10"
    },
    {
      "value": "update-launcher.xyz",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "Unit 42 (Palo Alto)"
      ],
      "articles": [
        {
          "id": "art-96",
          "title": "The Permanent Threat: Analyzing Aeternum\u2019s Blockchain-Based C2 Operations and Communications",
          "link": "https://unit42.paloaltonetworks.com/aeternum-blockchain-c2-analysis/",
          "published": "2026-08-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-10"
    },
    {
      "value": "update.constant-path.xyz",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "Unit 42 (Palo Alto)"
      ],
      "articles": [
        {
          "id": "art-96",
          "title": "The Permanent Threat: Analyzing Aeternum\u2019s Blockchain-Based C2 Operations and Communications",
          "link": "https://unit42.paloaltonetworks.com/aeternum-blockchain-c2-analysis/",
          "published": "2026-08-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-10"
    },
    {
      "value": "193.221.200.219",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "Unit 42 (Palo Alto)"
      ],
      "articles": [
        {
          "id": "art-96",
          "title": "The Permanent Threat: Analyzing Aeternum\u2019s Blockchain-Based C2 Operations and Communications",
          "link": "https://unit42.paloaltonetworks.com/aeternum-blockchain-c2-analysis/",
          "published": "2026-08-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-10"
    },
    {
      "value": "1505eda3da68e2ff9919b55a31018bd30a991236f041aee835f3bc4e430ce505",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "Unit 42 (Palo Alto)"
      ],
      "articles": [
        {
          "id": "art-96",
          "title": "The Permanent Threat: Analyzing Aeternum\u2019s Blockchain-Based C2 Operations and Communications",
          "link": "https://unit42.paloaltonetworks.com/aeternum-blockchain-c2-analysis/",
          "published": "2026-08-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-10"
    },
    {
      "value": "4e24bbd0fabac6c3efcec943046afbfd332b2c0108a13becfda23a0e26f9ff5f",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "Unit 42 (Palo Alto)"
      ],
      "articles": [
        {
          "id": "art-96",
          "title": "The Permanent Threat: Analyzing Aeternum\u2019s Blockchain-Based C2 Operations and Communications",
          "link": "https://unit42.paloaltonetworks.com/aeternum-blockchain-c2-analysis/",
          "published": "2026-08-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-10"
    },
    {
      "value": "5bfb25b8255b61e5ffdf6804451534bcfa9f1dfd225e6c8cdcefb5f50d846898",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "Unit 42 (Palo Alto)"
      ],
      "articles": [
        {
          "id": "art-96",
          "title": "The Permanent Threat: Analyzing Aeternum\u2019s Blockchain-Based C2 Operations and Communications",
          "link": "https://unit42.paloaltonetworks.com/aeternum-blockchain-c2-analysis/",
          "published": "2026-08-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-10"
    },
    {
      "value": "81bb80d9c5a97dc41b65f6248c131963c91346eb4fb672836b3d53ae67564d9f",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "Unit 42 (Palo Alto)"
      ],
      "articles": [
        {
          "id": "art-96",
          "title": "The Permanent Threat: Analyzing Aeternum\u2019s Blockchain-Based C2 Operations and Communications",
          "link": "https://unit42.paloaltonetworks.com/aeternum-blockchain-c2-analysis/",
          "published": "2026-08-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-10"
    },
    {
      "value": "a1fdf65020ce4a0f0940c793c6425baf8a0b994ec48b9baaf72788661a9d29f4",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "Microsoft Security Blog"
      ],
      "articles": [
        {
          "id": "art-98",
          "title": "DeadLock ransomware: Breaking down a Rust-based encryptor with decentralized recovery infrastructure",
          "link": "https://www.microsoft.com/en-us/security/blog/2026/08/10/deadlock-ransomware-breaking-down-a-rust-based-encryptor-with-decentralized-recovery-infrastructure/",
          "published": "2026-08-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-10"
    },
    {
      "value": "ea1b6ff3a0c1a749b9f09d66789973321d63d8896b48f7345193bdad512950a2",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "Unit 42 (Palo Alto)"
      ],
      "articles": [
        {
          "id": "art-96",
          "title": "The Permanent Threat: Analyzing Aeternum\u2019s Blockchain-Based C2 Operations and Communications",
          "link": "https://unit42.paloaltonetworks.com/aeternum-blockchain-c2-analysis/",
          "published": "2026-08-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-10"
    },
    {
      "value": "f2a326cff405299e4ebdfaac955c52fc7e496544eaa0921ecad4816cb3ae3a27",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "Unit 42 (Palo Alto)"
      ],
      "articles": [
        {
          "id": "art-96",
          "title": "The Permanent Threat: Analyzing Aeternum\u2019s Blockchain-Based C2 Operations and Communications",
          "link": "https://unit42.paloaltonetworks.com/aeternum-blockchain-c2-analysis/",
          "published": "2026-08-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-10"
    },
    {
      "value": "CVE-2026-63221",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "GitHub Security Advisories"
      ],
      "articles": [
        {
          "id": "art-105",
          "title": "[GHSA / CRITICAL] CVE-2026-63221: CodeIgniter: SQL injection in Query Builder deleteBatch() when used with where() conditions",
          "link": "https://github.com/advisories/GHSA-c9w5-rwh3-7pm9",
          "published": "2026-08-07",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-07"
    },
    {
      "value": "CVE-2026-63223",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "GitHub Security Advisories"
      ],
      "articles": [
        {
          "id": "art-104",
          "title": "[GHSA / CRITICAL] CVE-2026-63223: CodeIgniter: Uploaded file extension validation bypass in `is_image` and `mime_in` rules",
          "link": "https://github.com/advisories/GHSA-mmj4-63m4-r6h5",
          "published": "2026-08-07",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-07"
    },
    {
      "value": "CVE-2026-71851",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "GitHub Security Advisories"
      ],
      "articles": [
        {
          "id": "art-103",
          "title": "[GHSA / CRITICAL] CVE-2026-71851: crypto-js: Insufficient Entropy in Cryptographic Secret Generation via Vulnerable CryptoJS Dependency Chain",
          "link": "https://github.com/advisories/GHSA-rg76-677x-56q9",
          "published": "2026-08-07",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-07"
    },
    {
      "value": "CVE-2026-8037",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-107",
          "title": "CISA KEV: CVE-2026-8037 \u2014 Progress LoadMaster Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-08-07",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-07"
    },
    {
      "value": "ff1f0032ff58aedfcc44eb6aa7b2c78207a98009",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "GitHub Security Advisories"
      ],
      "articles": [
        {
          "id": "art-103",
          "title": "[GHSA / CRITICAL] CVE-2026-71851: crypto-js: Insufficient Entropy in Cryptographic Secret Generation via Vulnerable CryptoJS Dependency Chain",
          "link": "https://github.com/advisories/GHSA-rg76-677x-56q9",
          "published": "2026-08-07",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-07"
    },
    {
      "value": "CVE-2026-48020",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "GitHub Security Advisories"
      ],
      "articles": [
        {
          "id": "art-111",
          "title": "[GHSA / CRITICAL] CVE-2026-65600: Traefik: Authentication Bypass via Path Traversal in ReplacePathRegex Middleware",
          "link": "https://github.com/advisories/GHSA-cxjq-mrr5-89rv",
          "published": "2026-08-06",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-06"
    },
    {
      "value": "CVE-2026-65600",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "GitHub Security Advisories"
      ],
      "articles": [
        {
          "id": "art-111",
          "title": "[GHSA / CRITICAL] CVE-2026-65600: Traefik: Authentication Bypass via Path Traversal in ReplacePathRegex Middleware",
          "link": "https://github.com/advisories/GHSA-cxjq-mrr5-89rv",
          "published": "2026-08-06",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-06"
    },
    {
      "value": "gh-token-monitor.sh",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "Unit 42 (Palo Alto)"
      ],
      "articles": [
        {
          "id": "art-108",
          "title": "ChainDrop: Inside a Self-Propagating npm Worm",
          "link": "https://unit42.paloaltonetworks.com/chaindrop-npm-worm-analysis/",
          "published": "2026-08-06",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-06"
    },
    {
      "value": "104.21.91.101",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "Unit 42 (Palo Alto)"
      ],
      "articles": [
        {
          "id": "art-108",
          "title": "ChainDrop: Inside a Self-Propagating npm Worm",
          "link": "https://unit42.paloaltonetworks.com/chaindrop-npm-worm-analysis/",
          "published": "2026-08-06",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-06"
    },
    {
      "value": "172.67.215.154",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "Unit 42 (Palo Alto)"
      ],
      "articles": [
        {
          "id": "art-108",
          "title": "ChainDrop: Inside a Self-Propagating npm Worm",
          "link": "https://unit42.paloaltonetworks.com/chaindrop-npm-worm-analysis/",
          "published": "2026-08-06",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-06"
    },
    {
      "value": "54dc7ea54a1317cca0e890a2770630cf7fa6c97813e0cb9d2caa93012b350668",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "Unit 42 (Palo Alto)",
        "Cisco Talos",
        "Microsoft Security Blog",
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-108",
          "title": "ChainDrop: Inside a Self-Propagating npm Worm",
          "link": "https://unit42.paloaltonetworks.com/chaindrop-npm-worm-analysis/",
          "published": "2026-08-06",
          "sev": "crit"
        },
        {
          "id": "art-110",
          "title": "Why metaphor may dictate your security strategy",
          "link": "https://blog.talosintelligence.com/why-metaphor-may-dictate-your-security-strategy/",
          "published": "2026-08-06",
          "sev": "high"
        },
        {
          "id": "art-120",
          "title": "ChainDrop supply chain compromise: Anatomy of a self-propagating worm",
          "link": "https://www.microsoft.com/en-us/security/blog/2026/08/04/chaindrop-supply-chain-compromise-anatomy-self-propagating-worm/",
          "published": "2026-08-04",
          "sev": "crit"
        },
        {
          "id": "art-138",
          "title": "A First Look at Evo Agentic AppSec: Agentic Remediation and Malicious Code Defense",
          "link": "https://snyk.io/blog/remediation-agent-malicious-code-defense/",
          "published": "2026-08-04",
          "sev": "high"
        },
        {
          "id": "art-139",
          "title": "Inside the keyv npm Compromise: preinstall Malware, Trusted Provenance, and IDE Hooks",
          "link": "https://snyk.io/blog/inside-keyv-npm-compromise-preinstall-malware-trusted-provenance-ide-hooks/",
          "published": "2026-08-04",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-06"
    },
    {
      "value": "b27b82afa5f15512f3856e549fb83d873fd0049759a4b62ce64c8d7d4dc2c678",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "Unit 42 (Palo Alto)"
      ],
      "articles": [
        {
          "id": "art-108",
          "title": "ChainDrop: Inside a Self-Propagating npm Worm",
          "link": "https://unit42.paloaltonetworks.com/chaindrop-npm-worm-analysis/",
          "published": "2026-08-06",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-06"
    },
    {
      "value": "d30b4ea6f68456672f5abb35e9dcf7d54226372b66e9d60a7ee26b7a52568e74",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "Unit 42 (Palo Alto)"
      ],
      "articles": [
        {
          "id": "art-108",
          "title": "ChainDrop: Inside a Self-Propagating npm Worm",
          "link": "https://unit42.paloaltonetworks.com/chaindrop-npm-worm-analysis/",
          "published": "2026-08-06",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-06"
    },
    {
      "value": "116.105.166.148",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "Unit 42 (Palo Alto)"
      ],
      "articles": [
        {
          "id": "art-112",
          "title": "Token Jacking: Cybercriminals Could Be Stealing Your AI Resources",
          "link": "https://unit42.paloaltonetworks.com/ai-token-jacking/",
          "published": "2026-08-06",
          "sev": "high"
        }
      ],
      "first_seen": "2026-08-06"
    },
    {
      "value": "172.96.142.186",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "Unit 42 (Palo Alto)"
      ],
      "articles": [
        {
          "id": "art-112",
          "title": "Token Jacking: Cybercriminals Could Be Stealing Your AI Resources",
          "link": "https://unit42.paloaltonetworks.com/ai-token-jacking/",
          "published": "2026-08-06",
          "sev": "high"
        }
      ],
      "first_seen": "2026-08-06"
    },
    {
      "value": "3.235.109.125",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "Unit 42 (Palo Alto)"
      ],
      "articles": [
        {
          "id": "art-112",
          "title": "Token Jacking: Cybercriminals Could Be Stealing Your AI Resources",
          "link": "https://unit42.paloaltonetworks.com/ai-token-jacking/",
          "published": "2026-08-06",
          "sev": "high"
        }
      ],
      "first_seen": "2026-08-06"
    },
    {
      "value": "38.46.219.166",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "Unit 42 (Palo Alto)"
      ],
      "articles": [
        {
          "id": "art-112",
          "title": "Token Jacking: Cybercriminals Could Be Stealing Your AI Resources",
          "link": "https://unit42.paloaltonetworks.com/ai-token-jacking/",
          "published": "2026-08-06",
          "sev": "high"
        }
      ],
      "first_seen": "2026-08-06"
    },
    {
      "value": "CVE-2026-63077",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-119",
          "title": "CISA KEV: CVE-2026-63077 \u2014 JetBrains TeamCity Deserialization of Untrusted Data Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-08-05",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-05"
    },
    {
      "value": "CVE-2026-71319",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "GitHub Security Advisories"
      ],
      "articles": [
        {
          "id": "art-113",
          "title": "[GHSA / CRITICAL] CVE-2026-71319: Unauthenticated Nuxt DevTools RPC allows arbitrary command execution on the developer's host",
          "link": "https://github.com/advisories/GHSA-279x-mwfv-vcqv",
          "published": "2026-08-05",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-05"
    },
    {
      "value": "applefilevault.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "Microsoft Security Blog"
      ],
      "articles": [
        {
          "id": "art-116",
          "title": "From open lures to cloaked gates: How a macOS ClickFix campaign learned to hide",
          "link": "https://www.microsoft.com/en-us/security/blog/2026/08/05/macos-clickfix-campaign-learned-hide/",
          "published": "2026-08-05",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-05"
    },
    {
      "value": "apricotfilepoint.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "Microsoft Security Blog"
      ],
      "articles": [
        {
          "id": "art-116",
          "title": "From open lures to cloaked gates: How a macOS ClickFix campaign learned to hide",
          "link": "https://www.microsoft.com/en-us/security/blog/2026/08/05/macos-clickfix-campaign-learned-hide/",
          "published": "2026-08-05",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-05"
    },
    {
      "value": "bananafastfile.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "Microsoft Security Blog"
      ],
      "articles": [
        {
          "id": "art-116",
          "title": "From open lures to cloaked gates: How a macOS ClickFix campaign learned to hide",
          "link": "https://www.microsoft.com/en-us/security/blog/2026/08/05/macos-clickfix-campaign-learned-hide/",
          "published": "2026-08-05",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-05"
    },
    {
      "value": "cloudfilebridge.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "Microsoft Security Blog"
      ],
      "articles": [
        {
          "id": "art-116",
          "title": "From open lures to cloaked gates: How a macOS ClickFix campaign learned to hide",
          "link": "https://www.microsoft.com/en-us/security/blog/2026/08/05/macos-clickfix-campaign-learned-hide/",
          "published": "2026-08-05",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-05"
    },
    {
      "value": "cloudsendhub.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "Microsoft Security Blog"
      ],
      "articles": [
        {
          "id": "art-116",
          "title": "From open lures to cloaked gates: How a macOS ClickFix campaign learned to hide",
          "link": "https://www.microsoft.com/en-us/security/blog/2026/08/05/macos-clickfix-campaign-learned-hide/",
          "published": "2026-08-05",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-05"
    },
    {
      "value": "filecedarwallet.online",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "Microsoft Security Blog"
      ],
      "articles": [
        {
          "id": "art-116",
          "title": "From open lures to cloaked gates: How a macOS ClickFix campaign learned to hide",
          "link": "https://www.microsoft.com/en-us/security/blog/2026/08/05/macos-clickfix-campaign-learned-hide/",
          "published": "2026-08-05",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-05"
    },
    {
      "value": "filecopperbasket.sbs",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "Microsoft Security Blog"
      ],
      "articles": [
        {
          "id": "art-116",
          "title": "From open lures to cloaked gates: How a macOS ClickFix campaign learned to hide",
          "link": "https://www.microsoft.com/en-us/security/blog/2026/08/05/macos-clickfix-campaign-learned-hide/",
          "published": "2026-08-05",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-05"
    },
    {
      "value": "filecrimsonsignal.online",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "Microsoft Security Blog"
      ],
      "articles": [
        {
          "id": "art-116",
          "title": "From open lures to cloaked gates: How a macOS ClickFix campaign learned to hide",
          "link": "https://www.microsoft.com/en-us/security/blog/2026/08/05/macos-clickfix-campaign-learned-hide/",
          "published": "2026-08-05",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-05"
    },
    {
      "value": "filemarblegarden.sbs",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "Microsoft Security Blog"
      ],
      "articles": [
        {
          "id": "art-116",
          "title": "From open lures to cloaked gates: How a macOS ClickFix campaign learned to hide",
          "link": "https://www.microsoft.com/en-us/security/blog/2026/08/05/macos-clickfix-campaign-learned-hide/",
          "published": "2026-08-05",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-05"
    },
    {
      "value": "fileoceanhammer.sbs",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "Microsoft Security Blog"
      ],
      "articles": [
        {
          "id": "art-116",
          "title": "From open lures to cloaked gates: How a macOS ClickFix campaign learned to hide",
          "link": "https://www.microsoft.com/en-us/security/blog/2026/08/05/macos-clickfix-campaign-learned-hide/",
          "published": "2026-08-05",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-05"
    },
    {
      "value": "filerubyfolder.sbs",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "Microsoft Security Blog"
      ],
      "articles": [
        {
          "id": "art-116",
          "title": "From open lures to cloaked gates: How a macOS ClickFix campaign learned to hide",
          "link": "https://www.microsoft.com/en-us/security/blog/2026/08/05/macos-clickfix-campaign-learned-hide/",
          "published": "2026-08-05",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-05"
    },
    {
      "value": "filevelvettractor.sbs",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "Microsoft Security Blog"
      ],
      "articles": [
        {
          "id": "art-116",
          "title": "From open lures to cloaked gates: How a macOS ClickFix campaign learned to hide",
          "link": "https://www.microsoft.com/en-us/security/blog/2026/08/05/macos-clickfix-campaign-learned-hide/",
          "published": "2026-08-05",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-05"
    },
    {
      "value": "lemonfilewave.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "Microsoft Security Blog"
      ],
      "articles": [
        {
          "id": "art-116",
          "title": "From open lures to cloaked gates: How a macOS ClickFix campaign learned to hide",
          "link": "https://www.microsoft.com/en-us/security/blog/2026/08/05/macos-clickfix-campaign-learned-hide/",
          "published": "2026-08-05",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-05"
    },
    {
      "value": "limefilescope.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "Microsoft Security Blog"
      ],
      "articles": [
        {
          "id": "art-116",
          "title": "From open lures to cloaked gates: How a macOS ClickFix campaign learned to hide",
          "link": "https://www.microsoft.com/en-us/security/blog/2026/08/05/macos-clickfix-campaign-learned-hide/",
          "published": "2026-08-05",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-05"
    },
    {
      "value": "mangocloudfile.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "Microsoft Security Blog"
      ],
      "articles": [
        {
          "id": "art-116",
          "title": "From open lures to cloaked gates: How a macOS ClickFix campaign learned to hide",
          "link": "https://www.microsoft.com/en-us/security/blog/2026/08/05/macos-clickfix-campaign-learned-hide/",
          "published": "2026-08-05",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-05"
    },
    {
      "value": "orangesmartfile.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "Microsoft Security Blog"
      ],
      "articles": [
        {
          "id": "art-116",
          "title": "From open lures to cloaked gates: How a macOS ClickFix campaign learned to hide",
          "link": "https://www.microsoft.com/en-us/security/blog/2026/08/05/macos-clickfix-campaign-learned-hide/",
          "published": "2026-08-05",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-05"
    },
    {
      "value": "syncdatavault.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "Microsoft Security Blog"
      ],
      "articles": [
        {
          "id": "art-116",
          "title": "From open lures to cloaked gates: How a macOS ClickFix campaign learned to hide",
          "link": "https://www.microsoft.com/en-us/security/blog/2026/08/05/macos-clickfix-campaign-learned-hide/",
          "published": "2026-08-05",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-05"
    },
    {
      "value": "CVE-2022-24785",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "GitHub Security Advisories",
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-129",
          "title": "[GHSA / CRITICAL] CVE-2026-69254: Flowise: RCE via NodeVM Sandbox Escape in executeJavaScriptCode() nodeVMOptions Override",
          "link": "https://github.com/advisories/GHSA-3769-jgqc-cxm7",
          "published": "2026-08-04",
          "sev": "crit"
        },
        {
          "id": "art-1547",
          "title": "Adding Snyk security to Jira and Bitbucket Cloud",
          "link": "https://snyk.io/blog/adding-snyk-security-jira-bitbucket-cloud/",
          "published": "2023-10-25",
          "sev": "high"
        }
      ],
      "first_seen": "2026-08-04"
    },
    {
      "value": "CVE-2025-24813",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-142",
          "title": "CISA KEV: CVE-2026-34486 \u2014 Apache Tomcat Missing Encryption of Sensitive Data Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-08-04",
          "sev": "crit"
        },
        {
          "id": "art-1027",
          "title": "CISA KEV: CVE-2025-24813 \u2014 Apache Tomcat Path Equivalence Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-04-01",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-04"
    },
    {
      "value": "CVE-2026-18556",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-141",
          "title": "CISA KEV: CVE-2026-18556 \u2014 N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-08-04",
          "sev": "crit"
        },
        {
          "id": "art-149",
          "title": "CISA KEV: CVE-2026-18577 \u2014 N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-08-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-04"
    },
    {
      "value": "CVE-2026-18577",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-141",
          "title": "CISA KEV: CVE-2026-18556 \u2014 N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-08-04",
          "sev": "crit"
        },
        {
          "id": "art-149",
          "title": "CISA KEV: CVE-2026-18577 \u2014 N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-08-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-04"
    },
    {
      "value": "CVE-2026-29146",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-142",
          "title": "CISA KEV: CVE-2026-34486 \u2014 Apache Tomcat Missing Encryption of Sensitive Data Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-08-04",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-04"
    },
    {
      "value": "CVE-2026-34486",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV",
        "Unit 42 (Palo Alto)"
      ],
      "articles": [
        {
          "id": "art-142",
          "title": "CISA KEV: CVE-2026-34486 \u2014 Apache Tomcat Missing Encryption of Sensitive Data Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-08-04",
          "sev": "crit"
        },
        {
          "id": "art-170",
          "title": "Chinese-Speaking Threat Actor Harnesses AI Models for Autonomous Cyberattacks",
          "link": "https://unit42.paloaltonetworks.com/autonomous-ai-cyber-attack-campaign/",
          "published": "2026-07-30",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-04"
    },
    {
      "value": "CVE-2026-41264",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "GitHub Security Advisories"
      ],
      "articles": [
        {
          "id": "art-126",
          "title": "[GHSA / CRITICAL] CVE-2026-70470: Flowise: Pyodide validator Unicode homoglyph bypass leads to RCE",
          "link": "https://github.com/advisories/GHSA-52fh-8v99-63c2",
          "published": "2026-08-04",
          "sev": "crit"
        },
        {
          "id": "art-128",
          "title": "[GHSA / CRITICAL] CVE-2026-69255: Flowise: CSV Agent Remote Code Execution via Pyodide Code Injection \u2014 Root Shell Verified",
          "link": "https://github.com/advisories/GHSA-vmv7-4m6c-3cg5",
          "published": "2026-08-04",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-04"
    },
    {
      "value": "CVE-2026-41265",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "GitHub Security Advisories"
      ],
      "articles": [
        {
          "id": "art-126",
          "title": "[GHSA / CRITICAL] CVE-2026-70470: Flowise: Pyodide validator Unicode homoglyph bypass leads to RCE",
          "link": "https://github.com/advisories/GHSA-52fh-8v99-63c2",
          "published": "2026-08-04",
          "sev": "crit"
        },
        {
          "id": "art-128",
          "title": "[GHSA / CRITICAL] CVE-2026-69255: Flowise: CSV Agent Remote Code Execution via Pyodide Code Injection \u2014 Root Shell Verified",
          "link": "https://github.com/advisories/GHSA-vmv7-4m6c-3cg5",
          "published": "2026-08-04",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-04"
    },
    {
      "value": "CVE-2026-46442",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "GitHub Security Advisories"
      ],
      "articles": [
        {
          "id": "art-128",
          "title": "[GHSA / CRITICAL] CVE-2026-69255: Flowise: CSV Agent Remote Code Execution via Pyodide Code Injection \u2014 Root Shell Verified",
          "link": "https://github.com/advisories/GHSA-vmv7-4m6c-3cg5",
          "published": "2026-08-04",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-04"
    },
    {
      "value": "CVE-2026-69251",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "GitHub Security Advisories"
      ],
      "articles": [
        {
          "id": "art-130",
          "title": "[GHSA / CRITICAL] CVE-2026-69251: Flowise RCE via TypeORM DataSource",
          "link": "https://github.com/advisories/GHSA-g32j-mmxr-gfq5",
          "published": "2026-08-04",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-04"
    },
    {
      "value": "CVE-2026-69254",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "GitHub Security Advisories"
      ],
      "articles": [
        {
          "id": "art-129",
          "title": "[GHSA / CRITICAL] CVE-2026-69254: Flowise: RCE via NodeVM Sandbox Escape in executeJavaScriptCode() nodeVMOptions Override",
          "link": "https://github.com/advisories/GHSA-3769-jgqc-cxm7",
          "published": "2026-08-04",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-04"
    },
    {
      "value": "CVE-2026-69255",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "GitHub Security Advisories"
      ],
      "articles": [
        {
          "id": "art-128",
          "title": "[GHSA / CRITICAL] CVE-2026-69255: Flowise: CSV Agent Remote Code Execution via Pyodide Code Injection \u2014 Root Shell Verified",
          "link": "https://github.com/advisories/GHSA-vmv7-4m6c-3cg5",
          "published": "2026-08-04",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-04"
    },
    {
      "value": "CVE-2026-69259",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "GitHub Security Advisories"
      ],
      "articles": [
        {
          "id": "art-127",
          "title": "[GHSA / CRITICAL] CVE-2026-69259: Flowise RCE via SQLite Record Manager Node",
          "link": "https://github.com/advisories/GHSA-x3hf-7cj6-3r4m",
          "published": "2026-08-04",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-04"
    },
    {
      "value": "CVE-2026-69264",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "GitHub Security Advisories"
      ],
      "articles": [
        {
          "id": "art-125",
          "title": "[GHSA / CRITICAL] CVE-2026-69264: Flowise: RCE via CSVAgent csvFile data URI base64 segment is interpolated into Python source without validation",
          "link": "https://github.com/advisories/GHSA-4j8x-x6v7-w9rq",
          "published": "2026-08-04",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-04"
    },
    {
      "value": "CVE-2026-70470",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "GitHub Security Advisories"
      ],
      "articles": [
        {
          "id": "art-126",
          "title": "[GHSA / CRITICAL] CVE-2026-70470: Flowise: Pyodide validator Unicode homoglyph bypass leads to RCE",
          "link": "https://github.com/advisories/GHSA-52fh-8v99-63c2",
          "published": "2026-08-04",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-04"
    },
    {
      "value": "CVE-2026-70477",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "GitHub Security Advisories"
      ],
      "articles": [
        {
          "id": "art-122",
          "title": "[GHSA / CRITICAL] CVE-2026-70477: Flowise: CSV Agent Prompt Injection Remote Code Execution Vulnerability",
          "link": "https://github.com/advisories/GHSA-5xvg-pmgg-3mxr",
          "published": "2026-08-04",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-04"
    },
    {
      "value": "CVE-2026-70478",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "GitHub Security Advisories"
      ],
      "articles": [
        {
          "id": "art-121",
          "title": "[GHSA / CRITICAL] CVE-2026-70478: Flowise: Unauthenticated OAuth2 token refresh endpoint returns access tokens \u2014 enables token theft for any connected service",
          "link": "https://github.com/advisories/GHSA-qgvm-j2hm-6m38",
          "published": "2026-08-04",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-04"
    },
    {
      "value": "CVE-2026-9198",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-143",
          "title": "CISA KEV: CVE-2026-9198 \u2014 IBM Langflow Code Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-08-04",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-04"
    },
    {
      "value": "mousears.synology.me",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-141",
          "title": "CISA KEV: CVE-2026-18556 \u2014 N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-08-04",
          "sev": "crit"
        },
        {
          "id": "art-149",
          "title": "CISA KEV: CVE-2026-18577 \u2014 N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-08-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-04"
    },
    {
      "value": "wagoosh.direct.quickconnect.to",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-141",
          "title": "CISA KEV: CVE-2026-18556 \u2014 N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-08-04",
          "sev": "crit"
        },
        {
          "id": "art-149",
          "title": "CISA KEV: CVE-2026-18577 \u2014 N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-08-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-04"
    },
    {
      "value": "who-ripped-one.direct.quickconnect.to",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-141",
          "title": "CISA KEV: CVE-2026-18556 \u2014 N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-08-04",
          "sev": "crit"
        },
        {
          "id": "art-149",
          "title": "CISA KEV: CVE-2026-18577 \u2014 N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-08-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-04"
    },
    {
      "value": "173.249.252.200",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-141",
          "title": "CISA KEV: CVE-2026-18556 \u2014 N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-08-04",
          "sev": "crit"
        },
        {
          "id": "art-149",
          "title": "CISA KEV: CVE-2026-18577 \u2014 N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-08-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-04"
    },
    {
      "value": "37.153.90.88",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-141",
          "title": "CISA KEV: CVE-2026-18556 \u2014 N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-08-04",
          "sev": "crit"
        },
        {
          "id": "art-149",
          "title": "CISA KEV: CVE-2026-18577 \u2014 N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-08-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-04"
    },
    {
      "value": "37.19.210.32",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-141",
          "title": "CISA KEV: CVE-2026-18556 \u2014 N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-08-04",
          "sev": "crit"
        },
        {
          "id": "art-149",
          "title": "CISA KEV: CVE-2026-18577 \u2014 N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-08-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-04"
    },
    {
      "value": "68.235.46.214",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-141",
          "title": "CISA KEV: CVE-2026-18556 \u2014 N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-08-04",
          "sev": "crit"
        },
        {
          "id": "art-149",
          "title": "CISA KEV: CVE-2026-18577 \u2014 N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-08-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-04"
    },
    {
      "value": "87.249.138.34",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-141",
          "title": "CISA KEV: CVE-2026-18556 \u2014 N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-08-04",
          "sev": "crit"
        },
        {
          "id": "art-149",
          "title": "CISA KEV: CVE-2026-18577 \u2014 N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-08-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-04"
    },
    {
      "value": "92.118.112.181",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-141",
          "title": "CISA KEV: CVE-2026-18556 \u2014 N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-08-04",
          "sev": "crit"
        },
        {
          "id": "art-149",
          "title": "CISA KEV: CVE-2026-18577 \u2014 N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-08-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-04"
    },
    {
      "value": "d584f9b6af48b7ed1f93713944f033783bf149e1c25e1643eb8c0e9df5dc7782",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-138",
          "title": "A First Look at Evo Agentic AppSec: Agentic Remediation and Malicious Code Defense",
          "link": "https://snyk.io/blog/remediation-agent-malicious-code-defense/",
          "published": "2026-08-04",
          "sev": "high"
        },
        {
          "id": "art-139",
          "title": "Inside the keyv npm Compromise: preinstall Malware, Trusted Provenance, and IDE Hooks",
          "link": "https://snyk.io/blog/inside-keyv-npm-compromise-preinstall-malware-trusted-provenance-ide-hooks/",
          "published": "2026-08-04",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-04"
    },
    {
      "value": "CVE-2025-12420",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-136",
          "title": "Evo Continuous Offensive Security Is Here Pentesting Grade Coverage For The 350 Days A Year You Aren't Testing",
          "link": "https://snyk.io/blog/evo-continuous-offensive-security/",
          "published": "2026-08-04",
          "sev": "high"
        },
        {
          "id": "art-614",
          "title": "AI Is Building Your Attack Surface. Are You Testing It?",
          "link": "https://snyk.io/blog/ai-is-building-your-attack-surface-are-you-testing-it/",
          "published": "2026-03-19",
          "sev": "high"
        },
        {
          "id": "art-655",
          "title": "Claude Code Security: A Welcome Evolution in the Remediation Loop",
          "link": "https://snyk.io/blog/claude-code-remediation-loop-evolution/",
          "published": "2026-02-23",
          "sev": "high"
        },
        {
          "id": "art-741",
          "title": "ServiceNow's Virtual Agent Vulnerability Shows Why AI Security Needs Traditional AppSec Foundations",
          "link": "https://snyk.io/blog/servicenow-virtual-agent-vulnerability/",
          "published": "2026-01-14",
          "sev": "high"
        }
      ],
      "first_seen": "2026-08-04"
    },
    {
      "value": "154.92.19.71",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "Unit 42 (Palo Alto)"
      ],
      "articles": [
        {
          "id": "art-132",
          "title": "Almost Half of Malware Samples Communicate Direct to IP",
          "link": "https://unit42.paloaltonetworks.com/malware-bypass-dns-direct-to-ip/",
          "published": "2026-08-04",
          "sev": "high"
        }
      ],
      "first_seen": "2026-08-04"
    },
    {
      "value": "178.16.54.109",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "Unit 42 (Palo Alto)"
      ],
      "articles": [
        {
          "id": "art-132",
          "title": "Almost Half of Malware Samples Communicate Direct to IP",
          "link": "https://unit42.paloaltonetworks.com/malware-bypass-dns-direct-to-ip/",
          "published": "2026-08-04",
          "sev": "high"
        }
      ],
      "first_seen": "2026-08-04"
    },
    {
      "value": "18.228.188.56",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "Unit 42 (Palo Alto)"
      ],
      "articles": [
        {
          "id": "art-132",
          "title": "Almost Half of Malware Samples Communicate Direct to IP",
          "link": "https://unit42.paloaltonetworks.com/malware-bypass-dns-direct-to-ip/",
          "published": "2026-08-04",
          "sev": "high"
        }
      ],
      "first_seen": "2026-08-04"
    },
    {
      "value": "194.76.227.94",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "Unit 42 (Palo Alto)"
      ],
      "articles": [
        {
          "id": "art-132",
          "title": "Almost Half of Malware Samples Communicate Direct to IP",
          "link": "https://unit42.paloaltonetworks.com/malware-bypass-dns-direct-to-ip/",
          "published": "2026-08-04",
          "sev": "high"
        }
      ],
      "first_seen": "2026-08-04"
    },
    {
      "value": "2.26.98.67",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "Unit 42 (Palo Alto)"
      ],
      "articles": [
        {
          "id": "art-132",
          "title": "Almost Half of Malware Samples Communicate Direct to IP",
          "link": "https://unit42.paloaltonetworks.com/malware-bypass-dns-direct-to-ip/",
          "published": "2026-08-04",
          "sev": "high"
        }
      ],
      "first_seen": "2026-08-04"
    },
    {
      "value": "87.120.107.33",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "Unit 42 (Palo Alto)"
      ],
      "articles": [
        {
          "id": "art-132",
          "title": "Almost Half of Malware Samples Communicate Direct to IP",
          "link": "https://unit42.paloaltonetworks.com/malware-bypass-dns-direct-to-ip/",
          "published": "2026-08-04",
          "sev": "high"
        }
      ],
      "first_seen": "2026-08-04"
    },
    {
      "value": "cc43cdbe8eb9874f55fffbe23b560b673eb9f31fb9a953926bba29464fd2dd07",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "Unit 42 (Palo Alto)"
      ],
      "articles": [
        {
          "id": "art-132",
          "title": "Almost Half of Malware Samples Communicate Direct to IP",
          "link": "https://unit42.paloaltonetworks.com/malware-bypass-dns-direct-to-ip/",
          "published": "2026-08-04",
          "sev": "high"
        }
      ],
      "first_seen": "2026-08-04"
    },
    {
      "value": "CVE-2026-69240",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "GitHub Security Advisories"
      ],
      "articles": [
        {
          "id": "art-144",
          "title": "[GHSA / CRITICAL] CVE-2026-69240: Sequelize: SQL Injection (Oracle DB)",
          "link": "https://github.com/advisories/GHSA-v8fg-2rw7-q452",
          "published": "2026-08-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-08-03"
    },
    {
      "value": "CVE-2026-52855",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "GitHub Security Advisories"
      ],
      "articles": [
        {
          "id": "art-155",
          "title": "[GHSA / CRITICAL] CVE-2026-52855: Wings exposes node configuration secrets through egg configuration-file templating",
          "link": "https://github.com/advisories/GHSA-pfvc-3p5h-x7h6",
          "published": "2026-07-31",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-31"
    },
    {
      "value": "CVE-2026-52887",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "GitHub Security Advisories"
      ],
      "articles": [
        {
          "id": "art-153",
          "title": "[GHSA / CRITICAL] CVE-2026-52887: NocoBase: SQL injection in /api/myInAppChannels:list filter to PG-superuser RCE",
          "link": "https://github.com/advisories/GHSA-p849-8hwh-84j9",
          "published": "2026-07-31",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-31"
    },
    {
      "value": "CVE-2026-53609",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "GitHub Security Advisories"
      ],
      "articles": [
        {
          "id": "art-150",
          "title": "[GHSA / CRITICAL] CVE-2026-53609: Apostrophe has Server-Side Prototype Pollution in apos.util.set via patch operators that leads to process-wide authorization bypass",
          "link": "https://github.com/advisories/GHSA-6h5j-32cf-4253",
          "published": "2026-07-31",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-31"
    },
    {
      "value": "CVE-2026-54725",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "GitHub Security Advisories"
      ],
      "articles": [
        {
          "id": "art-154",
          "title": "[GHSA / CRITICAL] CVE-2026-54725: vault-addr annotation SSRF -- webhook makes outbound HTTP call to attacker URL during admission; vault-serviceaccount enables cluster-wide SA token theft via To",
          "link": "https://github.com/advisories/GHSA-r2v3-8gwf-7ghm",
          "published": "2026-07-31",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-31"
    },
    {
      "value": "crust.testinglab.ru",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "Securelist (Kaspersky)"
      ],
      "articles": [
        {
          "id": "art-159",
          "title": "Network Anomaly Detection in KATA",
          "link": "https://securelist.com/tr/network-anomaly-detection-in-kata/120892/",
          "published": "2026-07-31",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-31"
    },
    {
      "value": "enqqnvvtgrnyl.x.pipedream.net",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "Aikido"
      ],
      "articles": [
        {
          "id": "art-156",
          "title": "Anthropic's Fever Dream: Claude's package that stole real keys",
          "link": "https://www.aikido.dev/blog/anthropic-rogue-agents-package-stole-keys",
          "published": "2026-07-31",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-31"
    },
    {
      "value": "m365-owa.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "Microsoft Security Blog"
      ],
      "articles": [
        {
          "id": "art-151",
          "title": "CaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theft",
          "link": "https://www.microsoft.com/en-us/security/blog/2026/07/31/captivecrunch-midnight-blizzard-targets-travelers-worldwide-for-malware-delivery-and-credential-theft/",
          "published": "2026-07-31",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-31"
    },
    {
      "value": "ms365-device.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "Microsoft Security Blog"
      ],
      "articles": [
        {
          "id": "art-151",
          "title": "CaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theft",
          "link": "https://www.microsoft.com/en-us/security/blog/2026/07/31/captivecrunch-midnight-blizzard-targets-travelers-worldwide-for-malware-delivery-and-credential-theft/",
          "published": "2026-07-31",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-31"
    },
    {
      "value": "ms365-live.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "Microsoft Security Blog"
      ],
      "articles": [
        {
          "id": "art-151",
          "title": "CaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theft",
          "link": "https://www.microsoft.com/en-us/security/blog/2026/07/31/captivecrunch-midnight-blizzard-targets-travelers-worldwide-for-malware-delivery-and-credential-theft/",
          "published": "2026-07-31",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-31"
    },
    {
      "value": "owa-ms365.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "Microsoft Security Blog"
      ],
      "articles": [
        {
          "id": "art-151",
          "title": "CaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theft",
          "link": "https://www.microsoft.com/en-us/security/blog/2026/07/31/captivecrunch-midnight-blizzard-targets-travelers-worldwide-for-malware-delivery-and-credential-theft/",
          "published": "2026-07-31",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-31"
    },
    {
      "value": "testinglab.ru",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "Securelist (Kaspersky)"
      ],
      "articles": [
        {
          "id": "art-159",
          "title": "Network Anomaly Detection in KATA",
          "link": "https://securelist.com/tr/network-anomaly-detection-in-kata/120892/",
          "published": "2026-07-31",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-31"
    },
    {
      "value": "104.194.159.150",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "Microsoft Security Blog"
      ],
      "articles": [
        {
          "id": "art-151",
          "title": "CaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theft",
          "link": "https://www.microsoft.com/en-us/security/blog/2026/07/31/captivecrunch-midnight-blizzard-targets-travelers-worldwide-for-malware-delivery-and-credential-theft/",
          "published": "2026-07-31",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-31"
    },
    {
      "value": "107.189.26.194",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "Microsoft Security Blog"
      ],
      "articles": [
        {
          "id": "art-151",
          "title": "CaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theft",
          "link": "https://www.microsoft.com/en-us/security/blog/2026/07/31/captivecrunch-midnight-blizzard-targets-travelers-worldwide-for-malware-delivery-and-credential-theft/",
          "published": "2026-07-31",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-31"
    },
    {
      "value": "213.145.86.112",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "Microsoft Security Blog"
      ],
      "articles": [
        {
          "id": "art-151",
          "title": "CaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theft",
          "link": "https://www.microsoft.com/en-us/security/blog/2026/07/31/captivecrunch-midnight-blizzard-targets-travelers-worldwide-for-malware-delivery-and-credential-theft/",
          "published": "2026-07-31",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-31"
    },
    {
      "value": "31.57.243.154",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "Microsoft Security Blog"
      ],
      "articles": [
        {
          "id": "art-151",
          "title": "CaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theft",
          "link": "https://www.microsoft.com/en-us/security/blog/2026/07/31/captivecrunch-midnight-blizzard-targets-travelers-worldwide-for-malware-delivery-and-credential-theft/",
          "published": "2026-07-31",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-31"
    },
    {
      "value": "38.146.28.132",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "Microsoft Security Blog"
      ],
      "articles": [
        {
          "id": "art-151",
          "title": "CaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theft",
          "link": "https://www.microsoft.com/en-us/security/blog/2026/07/31/captivecrunch-midnight-blizzard-targets-travelers-worldwide-for-malware-delivery-and-credential-theft/",
          "published": "2026-07-31",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-31"
    },
    {
      "value": "38.146.28.75",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "Microsoft Security Blog"
      ],
      "articles": [
        {
          "id": "art-151",
          "title": "CaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theft",
          "link": "https://www.microsoft.com/en-us/security/blog/2026/07/31/captivecrunch-midnight-blizzard-targets-travelers-worldwide-for-malware-delivery-and-credential-theft/",
          "published": "2026-07-31",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-31"
    },
    {
      "value": "7df12487bade710459ccea2d3570cdbc",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "Aikido"
      ],
      "articles": [
        {
          "id": "art-156",
          "title": "Anthropic's Fever Dream: Claude's package that stole real keys",
          "link": "https://www.aikido.dev/blog/anthropic-rogue-agents-package-stole-keys",
          "published": "2026-07-31",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-31"
    },
    {
      "value": "4ae13303fa1663a36cfaa70bebe77b52b12dbf17eef24db15c6c24c631d38fbf",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "Aikido"
      ],
      "articles": [
        {
          "id": "art-156",
          "title": "Anthropic's Fever Dream: Claude's package that stole real keys",
          "link": "https://www.aikido.dev/blog/anthropic-rogue-agents-package-stole-keys",
          "published": "2026-07-31",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-31"
    },
    {
      "value": "584ef638a5415f4eccf6645abbcd06198e9abecf8b75cbd9328aa58962d9b38b",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "Aikido"
      ],
      "articles": [
        {
          "id": "art-156",
          "title": "Anthropic's Fever Dream: Claude's package that stole real keys",
          "link": "https://www.aikido.dev/blog/anthropic-rogue-agents-package-stole-keys",
          "published": "2026-07-31",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-31"
    },
    {
      "value": "f3e103a8a230b5fb3066fb0a9eb7f5fdf5831d4c7b71a9d83de54d8d6673eae2",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "Aikido"
      ],
      "articles": [
        {
          "id": "art-156",
          "title": "Anthropic's Fever Dream: Claude's package that stole real keys",
          "link": "https://www.aikido.dev/blog/anthropic-rogue-agents-package-stole-keys",
          "published": "2026-07-31",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-31"
    },
    {
      "value": "ff4126bd465ae6de09a2eaa94a4fd2d7d385a5dae2c093372668d4b7ecb81633",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "Aikido"
      ],
      "articles": [
        {
          "id": "art-156",
          "title": "Anthropic's Fever Dream: Claude's package that stole real keys",
          "link": "https://www.aikido.dev/blog/anthropic-rogue-agents-package-stole-keys",
          "published": "2026-07-31",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-31"
    },
    {
      "value": "CVE-2025-4318",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "GitHub Security Advisories"
      ],
      "articles": [
        {
          "id": "art-161",
          "title": "[GHSA / CRITICAL] CVE-2025-4318: AWS Amplify Studio UI Component Properties Has an Input Validation Issue",
          "link": "https://github.com/advisories/GHSA-hf3j-86p7-mfw8",
          "published": "2026-07-30",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-30"
    },
    {
      "value": "CVE-2025-68613",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "Unit 42 (Palo Alto)",
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-170",
          "title": "Chinese-Speaking Threat Actor Harnesses AI Models for Autonomous Cyberattacks",
          "link": "https://unit42.paloaltonetworks.com/autonomous-ai-cyber-attack-campaign/",
          "published": "2026-07-30",
          "sev": "crit"
        },
        {
          "id": "art-628",
          "title": "CISA KEV: CVE-2025-68613 \u2014 n8n Improper Control of Dynamically-Managed Code Resources Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-03-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-30"
    },
    {
      "value": "CVE-2026-16232",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "Cisco Talos",
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-165",
          "title": "You were onto something with \u201cIt\u2019s the Climb,\u201d Miley",
          "link": "https://blog.talosintelligence.com/you-were-onto-something-with-its-the-climb-miley/",
          "published": "2026-07-30",
          "sev": "crit"
        },
        {
          "id": "art-226",
          "title": "CISA KEV: CVE-2026-16232 \u2014 Check Point SmartConsole Improper Authentication Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-07-22",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-30"
    },
    {
      "value": "CVE-2026-21858",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "Unit 42 (Palo Alto)"
      ],
      "articles": [
        {
          "id": "art-170",
          "title": "Chinese-Speaking Threat Actor Harnesses AI Models for Autonomous Cyberattacks",
          "link": "https://unit42.paloaltonetworks.com/autonomous-ai-cyber-attack-campaign/",
          "published": "2026-07-30",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-30"
    },
    {
      "value": "CVE-2026-3055",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "Unit 42 (Palo Alto)",
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-170",
          "title": "Chinese-Speaking Threat Actor Harnesses AI Models for Autonomous Cyberattacks",
          "link": "https://unit42.paloaltonetworks.com/autonomous-ai-cyber-attack-campaign/",
          "published": "2026-07-30",
          "sev": "crit"
        },
        {
          "id": "art-586",
          "title": "CISA KEV: CVE-2026-3055 \u2014 Citrix NetScaler Out-of-Bounds Read Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-03-30",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-30"
    },
    {
      "value": "CVE-2026-33017",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "Unit 42 (Palo Alto)",
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-170",
          "title": "Chinese-Speaking Threat Actor Harnesses AI Models for Autonomous Cyberattacks",
          "link": "https://unit42.paloaltonetworks.com/autonomous-ai-cyber-attack-campaign/",
          "published": "2026-07-30",
          "sev": "crit"
        },
        {
          "id": "art-316",
          "title": "CISA KEV: CVE-2026-55255 \u2014 Langflow Authorization Bypass Through User-Controlled Key Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-07-07",
          "sev": "crit"
        },
        {
          "id": "art-603",
          "title": "CISA KEV: CVE-2026-33017 \u2014 Langflow Code Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-03-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-30"
    },
    {
      "value": "CVE-2026-33824",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "Unit 42 (Palo Alto)"
      ],
      "articles": [
        {
          "id": "art-170",
          "title": "Chinese-Speaking Threat Actor Harnesses AI Models for Autonomous Cyberattacks",
          "link": "https://unit42.paloaltonetworks.com/autonomous-ai-cyber-attack-campaign/",
          "published": "2026-07-30",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-30"
    },
    {
      "value": "CVE-2026-39987",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "Unit 42 (Palo Alto)",
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-170",
          "title": "Chinese-Speaking Threat Actor Harnesses AI Models for Autonomous Cyberattacks",
          "link": "https://unit42.paloaltonetworks.com/autonomous-ai-cyber-attack-campaign/",
          "published": "2026-07-30",
          "sev": "crit"
        },
        {
          "id": "art-532",
          "title": "CISA KEV: CVE-2026-39987 \u2014 Marimo Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-04-23",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-30"
    },
    {
      "value": "CVE-2026-66066",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "GitHub Security Advisories"
      ],
      "articles": [
        {
          "id": "art-164",
          "title": "[GHSA / CRITICAL] CVE-2026-66066: Active Storage has possible arbitrary file read and remote code execution in Active Storage variant processing",
          "link": "https://github.com/advisories/GHSA-xr9x-r78c-5hrm",
          "published": "2026-07-30",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-30"
    },
    {
      "value": "CVE-2026-67426",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "GitHub Security Advisories"
      ],
      "articles": [
        {
          "id": "art-167",
          "title": "[GHSA / CRITICAL] CVE-2026-67426: Flyto2 Core: Unauthenticated flyto-verification /run: callback_url SSRF and internal runner-secret exfiltration",
          "link": "https://github.com/advisories/GHSA-jx74-cqjv-2c67",
          "published": "2026-07-30",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-30"
    },
    {
      "value": "CVE-2026-67429",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "GitHub Security Advisories"
      ],
      "articles": [
        {
          "id": "art-168",
          "title": "[GHSA / CRITICAL] CVE-2026-67429: Flyto2 Core: Arbitrary file write via image.download (and other file-writing modules)",
          "link": "https://github.com/advisories/GHSA-2956-977x-2w3r",
          "published": "2026-07-30",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-30"
    },
    {
      "value": "about.blsouqs.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "Securelist (Kaspersky)"
      ],
      "articles": [
        {
          "id": "art-169",
          "title": "OctLurk and SilkLurk: newly identified tailored backdoors in cyber-espionage campaign in Central Asia",
          "link": "https://securelist.com/octlurk-silklurk-backdoors-central-asia/120840/",
          "published": "2026-07-30",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-30"
    },
    {
      "value": "api.trongrid.io",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "StepSecurity"
      ],
      "articles": [
        {
          "id": "art-163",
          "title": "Compromised npm Packages: @joyfill/components and @joyfill/layouts Ship an Obfuscated Remote Access Trojan",
          "link": "https://www.stepsecurity.io/blog/joyfill-npm-supply-chain-compromise",
          "published": "2026-07-30",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-30"
    },
    {
      "value": "api2.annoyingremote.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "Securelist (Kaspersky)"
      ],
      "articles": [
        {
          "id": "art-169",
          "title": "OctLurk and SilkLurk: newly identified tailored backdoors in cyber-espionage campaign in Central Asia",
          "link": "https://securelist.com/octlurk-silklurk-backdoors-central-asia/120840/",
          "published": "2026-07-30",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-30"
    },
    {
      "value": "bsc-dataseed.binance.org",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "StepSecurity"
      ],
      "articles": [
        {
          "id": "art-163",
          "title": "Compromised npm Packages: @joyfill/components and @joyfill/layouts Ship an Obfuscated Remote Access Trojan",
          "link": "https://www.stepsecurity.io/blog/joyfill-npm-supply-chain-compromise",
          "published": "2026-07-30",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-30"
    },
    {
      "value": "bsc-rpc.publicnode.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "StepSecurity"
      ],
      "articles": [
        {
          "id": "art-163",
          "title": "Compromised npm Packages: @joyfill/components and @joyfill/layouts Ship an Obfuscated Remote Access Trojan",
          "link": "https://www.stepsecurity.io/blog/joyfill-npm-supply-chain-compromise",
          "published": "2026-07-30",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-30"
    },
    {
      "value": "code.newcli.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "Unit 42 (Palo Alto)"
      ],
      "articles": [
        {
          "id": "art-170",
          "title": "Chinese-Speaking Threat Actor Harnesses AI Models for Autonomous Cyberattacks",
          "link": "https://unit42.paloaltonetworks.com/autonomous-ai-cyber-attack-campaign/",
          "published": "2026-07-30",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-30"
    },
    {
      "value": "confbase.mdpsupport.net",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "Securelist (Kaspersky)"
      ],
      "articles": [
        {
          "id": "art-169",
          "title": "OctLurk and SilkLurk: newly identified tailored backdoors in cyber-espionage campaign in Central Asia",
          "link": "https://securelist.com/octlurk-silklurk-backdoors-central-asia/120840/",
          "published": "2026-07-30",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-30"
    },
    {
      "value": "ctyuhjerf.kozow.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "Securelist (Kaspersky)"
      ],
      "articles": [
        {
          "id": "art-169",
          "title": "OctLurk and SilkLurk: newly identified tailored backdoors in cyber-espionage campaign in Central Asia",
          "link": "https://securelist.com/octlurk-silklurk-backdoors-central-asia/120840/",
          "published": "2026-07-30",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-30"
    },
    {
      "value": "digital.leroymerlin.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "Securelist (Kaspersky)"
      ],
      "articles": [
        {
          "id": "art-169",
          "title": "OctLurk and SilkLurk: newly identified tailored backdoors in cyber-espionage campaign in Central Asia",
          "link": "https://securelist.com/octlurk-silklurk-backdoors-central-asia/120840/",
          "published": "2026-07-30",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-30"
    },
    {
      "value": "dns.multitoconference.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "Securelist (Kaspersky)"
      ],
      "articles": [
        {
          "id": "art-169",
          "title": "OctLurk and SilkLurk: newly identified tailored backdoors in cyber-espionage campaign in Central Asia",
          "link": "https://securelist.com/octlurk-silklurk-backdoors-central-asia/120840/",
          "published": "2026-07-30",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-30"
    },
    {
      "value": "dns.ssentialserv.xyz",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "Securelist (Kaspersky)"
      ],
      "articles": [
        {
          "id": "art-169",
          "title": "OctLurk and SilkLurk: newly identified tailored backdoors in cyber-espionage campaign in Central Asia",
          "link": "https://securelist.com/octlurk-silklurk-backdoors-central-asia/120840/",
          "published": "2026-07-30",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-30"
    },
    {
      "value": "fm01.clouddevicemetrics.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "Securelist (Kaspersky)"
      ],
      "articles": [
        {
          "id": "art-169",
          "title": "OctLurk and SilkLurk: newly identified tailored backdoors in cyber-espionage campaign in Central Asia",
          "link": "https://securelist.com/octlurk-silklurk-backdoors-central-asia/120840/",
          "published": "2026-07-30",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-30"
    },
    {
      "value": "fullnode.mainnet.aptoslabs.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "StepSecurity"
      ],
      "articles": [
        {
          "id": "art-163",
          "title": "Compromised npm Packages: @joyfill/components and @joyfill/layouts Ship an Obfuscated Remote Access Trojan",
          "link": "https://www.stepsecurity.io/blog/joyfill-npm-supply-chain-compromise",
          "published": "2026-07-30",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-30"
    },
    {
      "value": "gycudore.kozow.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "Securelist (Kaspersky)"
      ],
      "articles": [
        {
          "id": "art-169",
          "title": "OctLurk and SilkLurk: newly identified tailored backdoors in cyber-espionage campaign in Central Asia",
          "link": "https://securelist.com/octlurk-silklurk-backdoors-central-asia/120840/",
          "published": "2026-07-30",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-30"
    },
    {
      "value": "ip-api.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "StepSecurity"
      ],
      "articles": [
        {
          "id": "art-163",
          "title": "Compromised npm Packages: @joyfill/components and @joyfill/layouts Ship an Obfuscated Remote Access Trojan",
          "link": "https://www.stepsecurity.io/blog/joyfill-npm-supply-chain-compromise",
          "published": "2026-07-30",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-30"
    },
    {
      "value": "is-01-ast.ols-img-12.workers.dev",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "Cisco Talos"
      ],
      "articles": [
        {
          "id": "art-165",
          "title": "You were onto something with \u201cIt\u2019s the Climb,\u201d Miley",
          "link": "https://blog.talosintelligence.com/you-were-onto-something-with-its-the-climb-miley/",
          "published": "2026-07-30",
          "sev": "crit"
        },
        {
          "id": "art-213",
          "title": "Don\u2019t swing at everything",
          "link": "https://blog.talosintelligence.com/dont-swing-at-everything/",
          "published": "2026-07-23",
          "sev": "crit"
        },
        {
          "id": "art-218",
          "title": "Chaos ransomware's msaRAT: Living off the browser to build a covert C2 channel",
          "link": "https://blog.talosintelligence.com/chaos-msarat-living-off-the-browser-to-build-covert-c2-channel/",
          "published": "2026-07-23",
          "sev": "high"
        }
      ],
      "first_seen": "2026-07-30"
    },
    {
      "value": "rgnojb.casacam.net",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "Securelist (Kaspersky)"
      ],
      "articles": [
        {
          "id": "art-169",
          "title": "OctLurk and SilkLurk: newly identified tailored backdoors in cyber-espionage campaign in Central Asia",
          "link": "https://securelist.com/octlurk-silklurk-backdoors-central-asia/120840/",
          "published": "2026-07-30",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-30"
    },
    {
      "value": "ssl.blsouqs.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "Securelist (Kaspersky)"
      ],
      "articles": [
        {
          "id": "art-169",
          "title": "OctLurk and SilkLurk: newly identified tailored backdoors in cyber-espionage campaign in Central Asia",
          "link": "https://securelist.com/octlurk-silklurk-backdoors-central-asia/120840/",
          "published": "2026-07-30",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-30"
    },
    {
      "value": "tj.tajikistandip.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "Securelist (Kaspersky)"
      ],
      "articles": [
        {
          "id": "art-169",
          "title": "OctLurk and SilkLurk: newly identified tailored backdoors in cyber-espionage campaign in Central Asia",
          "link": "https://securelist.com/octlurk-silklurk-backdoors-central-asia/120840/",
          "published": "2026-07-30",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-30"
    },
    {
      "value": "tyhbgtyuj.gleeze.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "Securelist (Kaspersky)"
      ],
      "articles": [
        {
          "id": "art-169",
          "title": "OctLurk and SilkLurk: newly identified tailored backdoors in cyber-espionage campaign in Central Asia",
          "link": "https://securelist.com/octlurk-silklurk-backdoors-central-asia/120840/",
          "published": "2026-07-30",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-30"
    },
    {
      "value": "uyhvfredc.accesscam.org",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "Securelist (Kaspersky)"
      ],
      "articles": [
        {
          "id": "art-169",
          "title": "OctLurk and SilkLurk: newly identified tailored backdoors in cyber-espionage campaign in Central Asia",
          "link": "https://securelist.com/octlurk-silklurk-backdoors-central-asia/120840/",
          "published": "2026-07-30",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-30"
    },
    {
      "value": "wedfcvbn.gleeze.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "Securelist (Kaspersky)"
      ],
      "articles": [
        {
          "id": "art-169",
          "title": "OctLurk and SilkLurk: newly identified tailored backdoors in cyber-espionage campaign in Central Asia",
          "link": "https://securelist.com/octlurk-silklurk-backdoors-central-asia/120840/",
          "published": "2026-07-30",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-30"
    },
    {
      "value": "154.196.162.76",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "Securelist (Kaspersky)"
      ],
      "articles": [
        {
          "id": "art-169",
          "title": "OctLurk and SilkLurk: newly identified tailored backdoors in cyber-espionage campaign in Central Asia",
          "link": "https://securelist.com/octlurk-silklurk-backdoors-central-asia/120840/",
          "published": "2026-07-30",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-30"
    },
    {
      "value": "154.196.187.73",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "Securelist (Kaspersky)"
      ],
      "articles": [
        {
          "id": "art-169",
          "title": "OctLurk and SilkLurk: newly identified tailored backdoors in cyber-espionage campaign in Central Asia",
          "link": "https://securelist.com/octlurk-silklurk-backdoors-central-asia/120840/",
          "published": "2026-07-30",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-30"
    },
    {
      "value": "166.88.134.62",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "StepSecurity"
      ],
      "articles": [
        {
          "id": "art-163",
          "title": "Compromised npm Packages: @joyfill/components and @joyfill/layouts Ship an Obfuscated Remote Access Trojan",
          "link": "https://www.stepsecurity.io/blog/joyfill-npm-supply-chain-compromise",
          "published": "2026-07-30",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-30"
    },
    {
      "value": "172.86.126.18",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "Cisco Talos"
      ],
      "articles": [
        {
          "id": "art-165",
          "title": "You were onto something with \u201cIt\u2019s the Climb,\u201d Miley",
          "link": "https://blog.talosintelligence.com/you-were-onto-something-with-its-the-climb-miley/",
          "published": "2026-07-30",
          "sev": "crit"
        },
        {
          "id": "art-213",
          "title": "Don\u2019t swing at everything",
          "link": "https://blog.talosintelligence.com/dont-swing-at-everything/",
          "published": "2026-07-23",
          "sev": "crit"
        },
        {
          "id": "art-218",
          "title": "Chaos ransomware's msaRAT: Living off the browser to build a covert C2 channel",
          "link": "https://blog.talosintelligence.com/chaos-msarat-living-off-the-browser-to-build-covert-c2-channel/",
          "published": "2026-07-23",
          "sev": "high"
        }
      ],
      "first_seen": "2026-07-30"
    },
    {
      "value": "195.86.120.2",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "Securelist (Kaspersky)"
      ],
      "articles": [
        {
          "id": "art-169",
          "title": "OctLurk and SilkLurk: newly identified tailored backdoors in cyber-espionage campaign in Central Asia",
          "link": "https://securelist.com/octlurk-silklurk-backdoors-central-asia/120840/",
          "published": "2026-07-30",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-30"
    },
    {
      "value": "198.105.127.210",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "StepSecurity"
      ],
      "articles": [
        {
          "id": "art-163",
          "title": "Compromised npm Packages: @joyfill/components and @joyfill/layouts Ship an Obfuscated Remote Access Trojan",
          "link": "https://www.stepsecurity.io/blog/joyfill-npm-supply-chain-compromise",
          "published": "2026-07-30",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-30"
    },
    {
      "value": "212.11.39.138",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "Securelist (Kaspersky)"
      ],
      "articles": [
        {
          "id": "art-169",
          "title": "OctLurk and SilkLurk: newly identified tailored backdoors in cyber-espionage campaign in Central Asia",
          "link": "https://securelist.com/octlurk-silklurk-backdoors-central-asia/120840/",
          "published": "2026-07-30",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-30"
    },
    {
      "value": "23.27.13.43",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "StepSecurity"
      ],
      "articles": [
        {
          "id": "art-163",
          "title": "Compromised npm Packages: @joyfill/components and @joyfill/layouts Ship an Obfuscated Remote Access Trojan",
          "link": "https://www.stepsecurity.io/blog/joyfill-npm-supply-chain-compromise",
          "published": "2026-07-30",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-30"
    },
    {
      "value": "23.27.202.27",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "StepSecurity"
      ],
      "articles": [
        {
          "id": "art-163",
          "title": "Compromised npm Packages: @joyfill/components and @joyfill/layouts Ship an Obfuscated Remote Access Trojan",
          "link": "https://www.stepsecurity.io/blog/joyfill-npm-supply-chain-compromise",
          "published": "2026-07-30",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-30"
    },
    {
      "value": "45.138.157.165",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "Securelist (Kaspersky)"
      ],
      "articles": [
        {
          "id": "art-169",
          "title": "OctLurk and SilkLurk: newly identified tailored backdoors in cyber-espionage campaign in Central Asia",
          "link": "https://securelist.com/octlurk-silklurk-backdoors-central-asia/120840/",
          "published": "2026-07-30",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-30"
    },
    {
      "value": "45.32.152.50",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "Securelist (Kaspersky)"
      ],
      "articles": [
        {
          "id": "art-169",
          "title": "OctLurk and SilkLurk: newly identified tailored backdoors in cyber-espionage campaign in Central Asia",
          "link": "https://securelist.com/octlurk-silklurk-backdoors-central-asia/120840/",
          "published": "2026-07-30",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-30"
    },
    {
      "value": "45.61.149.112",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "Securelist (Kaspersky)"
      ],
      "articles": [
        {
          "id": "art-169",
          "title": "OctLurk and SilkLurk: newly identified tailored backdoors in cyber-espionage campaign in Central Asia",
          "link": "https://securelist.com/octlurk-silklurk-backdoors-central-asia/120840/",
          "published": "2026-07-30",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-30"
    },
    {
      "value": "45.77.136.228",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "Securelist (Kaspersky)"
      ],
      "articles": [
        {
          "id": "art-169",
          "title": "OctLurk and SilkLurk: newly identified tailored backdoors in cyber-espionage campaign in Central Asia",
          "link": "https://securelist.com/octlurk-silklurk-backdoors-central-asia/120840/",
          "published": "2026-07-30",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-30"
    },
    {
      "value": "64.7.198.130",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "Securelist (Kaspersky)"
      ],
      "articles": [
        {
          "id": "art-169",
          "title": "OctLurk and SilkLurk: newly identified tailored backdoors in cyber-espionage campaign in Central Asia",
          "link": "https://securelist.com/octlurk-silklurk-backdoors-central-asia/120840/",
          "published": "2026-07-30",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-30"
    },
    {
      "value": "95.179.141.26",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "Securelist (Kaspersky)"
      ],
      "articles": [
        {
          "id": "art-169",
          "title": "OctLurk and SilkLurk: newly identified tailored backdoors in cyber-espionage campaign in Central Asia",
          "link": "https://securelist.com/octlurk-silklurk-backdoors-central-asia/120840/",
          "published": "2026-07-30",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-30"
    },
    {
      "value": "95.179.210.138",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "Securelist (Kaspersky)"
      ],
      "articles": [
        {
          "id": "art-169",
          "title": "OctLurk and SilkLurk: newly identified tailored backdoors in cyber-espionage campaign in Central Asia",
          "link": "https://securelist.com/octlurk-silklurk-backdoors-central-asia/120840/",
          "published": "2026-07-30",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-30"
    },
    {
      "value": "082d49ef9f14e6811d68c7e0e82e5069",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "Securelist (Kaspersky)"
      ],
      "articles": [
        {
          "id": "art-169",
          "title": "OctLurk and SilkLurk: newly identified tailored backdoors in cyber-espionage campaign in Central Asia",
          "link": "https://securelist.com/octlurk-silklurk-backdoors-central-asia/120840/",
          "published": "2026-07-30",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-30"
    },
    {
      "value": "1415a78b75de7db4ba3d1e61d7db4501",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "Securelist (Kaspersky)"
      ],
      "articles": [
        {
          "id": "art-169",
          "title": "OctLurk and SilkLurk: newly identified tailored backdoors in cyber-espionage campaign in Central Asia",
          "link": "https://securelist.com/octlurk-silklurk-backdoors-central-asia/120840/",
          "published": "2026-07-30",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-30"
    },
    {
      "value": "18dc8bff47cc282508354771d0c8cf8c",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "Securelist (Kaspersky)"
      ],
      "articles": [
        {
          "id": "art-169",
          "title": "OctLurk and SilkLurk: newly identified tailored backdoors in cyber-espionage campaign in Central Asia",
          "link": "https://securelist.com/octlurk-silklurk-backdoors-central-asia/120840/",
          "published": "2026-07-30",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-30"
    },
    {
      "value": "2a571f6cee42a17d873f4c942649813f",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "Securelist (Kaspersky)"
      ],
      "articles": [
        {
          "id": "art-169",
          "title": "OctLurk and SilkLurk: newly identified tailored backdoors in cyber-espionage campaign in Central Asia",
          "link": "https://securelist.com/octlurk-silklurk-backdoors-central-asia/120840/",
          "published": "2026-07-30",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-30"
    },
    {
      "value": "32a5985543433a4f60da2fafd873b927",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "Securelist (Kaspersky)"
      ],
      "articles": [
        {
          "id": "art-169",
          "title": "OctLurk and SilkLurk: newly identified tailored backdoors in cyber-espionage campaign in Central Asia",
          "link": "https://securelist.com/octlurk-silklurk-backdoors-central-asia/120840/",
          "published": "2026-07-30",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-30"
    },
    {
      "value": "37dc84e4bcad92fa28f1e7778d088283",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "Securelist (Kaspersky)"
      ],
      "articles": [
        {
          "id": "art-169",
          "title": "OctLurk and SilkLurk: newly identified tailored backdoors in cyber-espionage campaign in Central Asia",
          "link": "https://securelist.com/octlurk-silklurk-backdoors-central-asia/120840/",
          "published": "2026-07-30",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-30"
    },
    {
      "value": "3c9a1ba8e0c7475706adc6376e9d7b7c",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "Securelist (Kaspersky)"
      ],
      "articles": [
        {
          "id": "art-169",
          "title": "OctLurk and SilkLurk: newly identified tailored backdoors in cyber-espionage campaign in Central Asia",
          "link": "https://securelist.com/octlurk-silklurk-backdoors-central-asia/120840/",
          "published": "2026-07-30",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-30"
    },
    {
      "value": "45cf5916fab4272a1313c26e67aa9220",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "Securelist (Kaspersky)"
      ],
      "articles": [
        {
          "id": "art-169",
          "title": "OctLurk and SilkLurk: newly identified tailored backdoors in cyber-espionage campaign in Central Asia",
          "link": "https://securelist.com/octlurk-silklurk-backdoors-central-asia/120840/",
          "published": "2026-07-30",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-30"
    },
    {
      "value": "4e6d5c4770d5a822d7fcce6a74f7ad73",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "Securelist (Kaspersky)"
      ],
      "articles": [
        {
          "id": "art-169",
          "title": "OctLurk and SilkLurk: newly identified tailored backdoors in cyber-espionage campaign in Central Asia",
          "link": "https://securelist.com/octlurk-silklurk-backdoors-central-asia/120840/",
          "published": "2026-07-30",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-30"
    },
    {
      "value": "5e26df131ff0a679a0a2699b723b46e3",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "Securelist (Kaspersky)"
      ],
      "articles": [
        {
          "id": "art-169",
          "title": "OctLurk and SilkLurk: newly identified tailored backdoors in cyber-espionage campaign in Central Asia",
          "link": "https://securelist.com/octlurk-silklurk-backdoors-central-asia/120840/",
          "published": "2026-07-30",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-30"
    },
    {
      "value": "6ecf84fb18f6747ed08d7598364d853a",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "Securelist (Kaspersky)"
      ],
      "articles": [
        {
          "id": "art-169",
          "title": "OctLurk and SilkLurk: newly identified tailored backdoors in cyber-espionage campaign in Central Asia",
          "link": "https://securelist.com/octlurk-silklurk-backdoors-central-asia/120840/",
          "published": "2026-07-30",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-30"
    },
    {
      "value": "7c2f64461bb519c6cbf1fc687675514c",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "Securelist (Kaspersky)"
      ],
      "articles": [
        {
          "id": "art-169",
          "title": "OctLurk and SilkLurk: newly identified tailored backdoors in cyber-espionage campaign in Central Asia",
          "link": "https://securelist.com/octlurk-silklurk-backdoors-central-asia/120840/",
          "published": "2026-07-30",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-30"
    },
    {
      "value": "8269d6ba1b6842f9152c90cf7add9b93",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "Securelist (Kaspersky)"
      ],
      "articles": [
        {
          "id": "art-169",
          "title": "OctLurk and SilkLurk: newly identified tailored backdoors in cyber-espionage campaign in Central Asia",
          "link": "https://securelist.com/octlurk-silklurk-backdoors-central-asia/120840/",
          "published": "2026-07-30",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-30"
    },
    {
      "value": "9a1dd1d96481d61934dcc2d568971d06",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "Securelist (Kaspersky)"
      ],
      "articles": [
        {
          "id": "art-169",
          "title": "OctLurk and SilkLurk: newly identified tailored backdoors in cyber-espionage campaign in Central Asia",
          "link": "https://securelist.com/octlurk-silklurk-backdoors-central-asia/120840/",
          "published": "2026-07-30",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-30"
    },
    {
      "value": "a0cc7accc79abb0287aaba825d0351f0",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "Securelist (Kaspersky)"
      ],
      "articles": [
        {
          "id": "art-169",
          "title": "OctLurk and SilkLurk: newly identified tailored backdoors in cyber-espionage campaign in Central Asia",
          "link": "https://securelist.com/octlurk-silklurk-backdoors-central-asia/120840/",
          "published": "2026-07-30",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-30"
    },
    {
      "value": "a4d550a3ba0cd073fe3839b99d98a7a8",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "Securelist (Kaspersky)"
      ],
      "articles": [
        {
          "id": "art-169",
          "title": "OctLurk and SilkLurk: newly identified tailored backdoors in cyber-espionage campaign in Central Asia",
          "link": "https://securelist.com/octlurk-silklurk-backdoors-central-asia/120840/",
          "published": "2026-07-30",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-30"
    },
    {
      "value": "a56cce62930a6bee80d679b4c495a340",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "Securelist (Kaspersky)"
      ],
      "articles": [
        {
          "id": "art-169",
          "title": "OctLurk and SilkLurk: newly identified tailored backdoors in cyber-espionage campaign in Central Asia",
          "link": "https://securelist.com/octlurk-silklurk-backdoors-central-asia/120840/",
          "published": "2026-07-30",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-30"
    },
    {
      "value": "b874123a80fc4f40e06872b9cb54ebc6",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "Securelist (Kaspersky)"
      ],
      "articles": [
        {
          "id": "art-169",
          "title": "OctLurk and SilkLurk: newly identified tailored backdoors in cyber-espionage campaign in Central Asia",
          "link": "https://securelist.com/octlurk-silklurk-backdoors-central-asia/120840/",
          "published": "2026-07-30",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-30"
    },
    {
      "value": "cf903e4a1629aa0582fd0363b5786676",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "Securelist (Kaspersky)"
      ],
      "articles": [
        {
          "id": "art-169",
          "title": "OctLurk and SilkLurk: newly identified tailored backdoors in cyber-espionage campaign in Central Asia",
          "link": "https://securelist.com/octlurk-silklurk-backdoors-central-asia/120840/",
          "published": "2026-07-30",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-30"
    },
    {
      "value": "ded73d04bb3e3525226de64c38a332e3",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "Cisco Talos"
      ],
      "articles": [
        {
          "id": "art-165",
          "title": "You were onto something with \u201cIt\u2019s the Climb,\u201d Miley",
          "link": "https://blog.talosintelligence.com/you-were-onto-something-with-its-the-climb-miley/",
          "published": "2026-07-30",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-30"
    },
    {
      "value": "ef59aad625eebda8650aec5820d6ce69",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "Securelist (Kaspersky)"
      ],
      "articles": [
        {
          "id": "art-169",
          "title": "OctLurk and SilkLurk: newly identified tailored backdoors in cyber-espionage campaign in Central Asia",
          "link": "https://securelist.com/octlurk-silklurk-backdoors-central-asia/120840/",
          "published": "2026-07-30",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-30"
    },
    {
      "value": "f4578e869a735cfad691f927bae3e638",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "Securelist (Kaspersky)"
      ],
      "articles": [
        {
          "id": "art-169",
          "title": "OctLurk and SilkLurk: newly identified tailored backdoors in cyber-espionage campaign in Central Asia",
          "link": "https://securelist.com/octlurk-silklurk-backdoors-central-asia/120840/",
          "published": "2026-07-30",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-30"
    },
    {
      "value": "26351aed0397158d3a3b8cc8fd3047d4c015d264c9895f10f20f1521b974ed18",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "StepSecurity"
      ],
      "articles": [
        {
          "id": "art-163",
          "title": "Compromised npm Packages: @joyfill/components and @joyfill/layouts Ship an Obfuscated Remote Access Trojan",
          "link": "https://www.stepsecurity.io/blog/joyfill-npm-supply-chain-compromise",
          "published": "2026-07-30",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-30"
    },
    {
      "value": "36ff00b45e67baa7e3674b0c80f48e88737264c61e5c6b3b091200972de8157c",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "StepSecurity"
      ],
      "articles": [
        {
          "id": "art-163",
          "title": "Compromised npm Packages: @joyfill/components and @joyfill/layouts Ship an Obfuscated Remote Access Trojan",
          "link": "https://www.stepsecurity.io/blog/joyfill-npm-supply-chain-compromise",
          "published": "2026-07-30",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-30"
    },
    {
      "value": "cb46f12d70824ea24ed1f8bcf45bf3f86680e02a9089aafc03b27f691be57be3",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "StepSecurity"
      ],
      "articles": [
        {
          "id": "art-163",
          "title": "Compromised npm Packages: @joyfill/components and @joyfill/layouts Ship an Obfuscated Remote Access Trojan",
          "link": "https://www.stepsecurity.io/blog/joyfill-npm-supply-chain-compromise",
          "published": "2026-07-30",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-30"
    },
    {
      "value": "fc18d4060c6dad3057c0b5a70a2081473e066951720cafbd2aa159d3aaccf2e1",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "Cisco Talos"
      ],
      "articles": [
        {
          "id": "art-165",
          "title": "You were onto something with \u201cIt\u2019s the Climb,\u201d Miley",
          "link": "https://blog.talosintelligence.com/you-were-onto-something-with-its-the-climb-miley/",
          "published": "2026-07-30",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-30"
    },
    {
      "value": "CVE-2026-20316",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-181",
          "title": "CISA KEV: CVE-2026-20316 \u2014 Cisco Secure Firewall Management Center Use of Hard-coded Password Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-07-29",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-29"
    },
    {
      "value": "CVE-2026-54680",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "GitHub Security Advisories"
      ],
      "articles": [
        {
          "id": "art-176",
          "title": "[GHSA / CRITICAL] CVE-2026-54680: Logging operator has Fluentd configuration injection that allows remote code execution",
          "link": "https://github.com/advisories/GHSA-mjqf-28ph-426h",
          "published": "2026-07-29",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-29"
    },
    {
      "value": "CVE-2026-54735",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "GitHub Security Advisories"
      ],
      "articles": [
        {
          "id": "art-177",
          "title": "[GHSA / CRITICAL] CVE-2026-54735: prebid-server's request forgery vulnerability allows for possible host environment data extraction",
          "link": "https://github.com/advisories/GHSA-4p3g-4hcj-wpvx",
          "published": "2026-07-29",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-29"
    },
    {
      "value": "CVE-2026-40884",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "GitHub Security Advisories"
      ],
      "articles": [
        {
          "id": "art-185",
          "title": "[GHSA / CRITICAL] CVE-2026-62325: goshs SFTP authentication bypass via empty password (incomplete fix of CVE-2026-40884)",
          "link": "https://github.com/advisories/GHSA-rjrw-mjq6-hpmm",
          "published": "2026-07-28",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-28"
    },
    {
      "value": "CVE-2026-45321",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "StepSecurity",
        "CISA KEV",
        "Aikido",
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-182",
          "title": "2026 Mid-Year Update: On Pace for Our Biggest Year Yet",
          "link": "https://www.stepsecurity.io/blog/2026-mid-year-update-on-pace-for-our-biggest-year-yet",
          "published": "2026-07-28",
          "sev": "crit"
        },
        {
          "id": "art-439",
          "title": "CISA KEV: CVE-2026-48027 \u2014 Nx Console Embedded Malicious Code Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-05-27",
          "sev": "crit"
        },
        {
          "id": "art-440",
          "title": "CISA KEV: CVE-2026-45321 \u2014 TanStack Unspecified Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-05-27",
          "sev": "crit"
        },
        {
          "id": "art-483",
          "title": "TeamPCP's Mini Shai-Hulud Is Back: A Self-Spreading Supply Chain Attack Compromises TanStack npm Packages",
          "link": "https://www.stepsecurity.io/blog/mini-shai-hulud-is-back-a-self-spreading-supply-chain-attack-hits-the-npm-ecosystem",
          "published": "2026-05-12",
          "sev": "crit"
        },
        {
          "id": "art-486",
          "title": "Mini Shai-Hulud Is Back: npm Worm Hits over 160 Packages, including Mistral and Tanstack",
          "link": "https://www.aikido.dev/blog/mini-shai-hulud-is-back-tanstack-compromised",
          "published": "2026-05-11",
          "sev": "crit"
        },
        {
          "id": "art-488",
          "title": "TanStack Npm Packages Compromised Inside The Mini Shai Hulud Supply Chain Attack",
          "link": "https://snyk.io/blog/tanstack-npm-packages-compromised/",
          "published": "2026-05-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-28"
    },
    {
      "value": "CVE-2026-48027",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "StepSecurity",
        "CISA KEV",
        "Aikido"
      ],
      "articles": [
        {
          "id": "art-182",
          "title": "2026 Mid-Year Update: On Pace for Our Biggest Year Yet",
          "link": "https://www.stepsecurity.io/blog/2026-mid-year-update-on-pace-for-our-biggest-year-yet",
          "published": "2026-07-28",
          "sev": "crit"
        },
        {
          "id": "art-439",
          "title": "CISA KEV: CVE-2026-48027 \u2014 Nx Console Embedded Malicious Code Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-05-27",
          "sev": "crit"
        },
        {
          "id": "art-457",
          "title": "The Wild West of VS Code extensions and how a poisoned extension breached GitHub",
          "link": "https://www.aikido.dev/blog/vs-code-extension-github-breach",
          "published": "2026-05-20",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-28"
    },
    {
      "value": "CVE-2026-50138",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "GitHub Security Advisories"
      ],
      "articles": [
        {
          "id": "art-184",
          "title": "[GHSA / CRITICAL] CVE-2026-64863: goshs --no-delete WebDAV MOVE bypass allows file deletion/overwrite",
          "link": "https://github.com/advisories/GHSA-hq33-8jgp-8qq3",
          "published": "2026-07-28",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-28"
    },
    {
      "value": "CVE-2026-54588",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "GitHub Security Advisories"
      ],
      "articles": [
        {
          "id": "art-186",
          "title": "[GHSA / CRITICAL] CVE-2026-54588: Poweradmin has Host Header Injection in OIDC redirect_uri, SAML ACS/SLO URL, and Logout Redirect Construction.",
          "link": "https://github.com/advisories/GHSA-3735-5339-xfwx",
          "published": "2026-07-28",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-28"
    },
    {
      "value": "CVE-2026-54658",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "GitHub Security Advisories"
      ],
      "articles": [
        {
          "id": "art-183",
          "title": "[GHSA / CRITICAL] CVE-2026-54658: @hypequery/clickhouse has SQL Injection in parameter escaping that allows arbitrary SQL execution",
          "link": "https://github.com/advisories/GHSA-6wcc-39rp-hh9p",
          "published": "2026-07-28",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-28"
    },
    {
      "value": "CVE-2026-62325",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "GitHub Security Advisories"
      ],
      "articles": [
        {
          "id": "art-185",
          "title": "[GHSA / CRITICAL] CVE-2026-62325: goshs SFTP authentication bypass via empty password (incomplete fix of CVE-2026-40884)",
          "link": "https://github.com/advisories/GHSA-rjrw-mjq6-hpmm",
          "published": "2026-07-28",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-28"
    },
    {
      "value": "CVE-2026-64863",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "GitHub Security Advisories"
      ],
      "articles": [
        {
          "id": "art-184",
          "title": "[GHSA / CRITICAL] CVE-2026-64863: goshs --no-delete WebDAV MOVE bypass allows file deletion/overwrite",
          "link": "https://github.com/advisories/GHSA-hq33-8jgp-8qq3",
          "published": "2026-07-28",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-28"
    },
    {
      "value": "check.git-service.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "StepSecurity",
        "Aikido",
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-182",
          "title": "2026 Mid-Year Update: On Pace for Our Biggest Year Yet",
          "link": "https://www.stepsecurity.io/blog/2026-mid-year-update-on-pace-for-our-biggest-year-yet",
          "published": "2026-07-28",
          "sev": "crit"
        },
        {
          "id": "art-397",
          "title": "Miasma Worm Hits Microsoft Again: Azure Functions Action and 72 Other Repositories Disabled After Supply Chain Attack Targeting AI Coding Agents",
          "link": "https://www.stepsecurity.io/blog/miasma-worm-hits-microsoft-again-azure-functions-action-and-72-other-repositories-disabled-after-supply-chain-attack-targeting-ai-coding-agents",
          "published": "2026-06-09",
          "sev": "high"
        },
        {
          "id": "art-415",
          "title": "Why EDR and proxy won\u2019t save you from supply chain malware",
          "link": "https://www.aikido.dev/blog/edr-proxy-wont-protect-supply-chain-malware",
          "published": "2026-06-02",
          "sev": "high"
        },
        {
          "id": "art-452",
          "title": "5 Supply Chain Attacks in 48 Hours: Why Securing One Layer Is Not Enough",
          "link": "https://www.stepsecurity.io/blog/5-supply-chain-attacks-in-48-hours-why-securing-one-layer-is-not-enough",
          "published": "2026-05-21",
          "sev": "crit"
        },
        {
          "id": "art-458",
          "title": "GitHub breached via a malicious VS Code extension: why developer devices are the real target",
          "link": "https://www.aikido.dev/blog/github-breached-vs-code-extension",
          "published": "2026-05-20",
          "sev": "high"
        },
        {
          "id": "art-468",
          "title": "The AntV Supply Chain Campaign Expands: Microsoft's `durabletask` PyPI Package Compromised",
          "link": "https://snyk.io/blog/durabletask-pypi-supply-chain-attack/",
          "published": "2026-05-19",
          "sev": "high"
        },
        {
          "id": "art-469",
          "title": "Microsoft's durabletask package on PyPi Compromised. Mini Shai Hulud attacks again... again!",
          "link": "https://www.aikido.dev/blog/durabletask-package-compromised-mini-shai-hulud",
          "published": "2026-05-19",
          "sev": "high"
        }
      ],
      "first_seen": "2026-07-28"
    },
    {
      "value": "clear90489058903-document.workers.dev",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "Cisco Talos"
      ],
      "articles": [
        {
          "id": "art-188",
          "title": "IR Trends Q2 2026: Phishing and weaponized remote management tools drive attack chains",
          "link": "https://blog.talosintelligence.com/ir-trends-q2-2026/",
          "published": "2026-07-28",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-28"
    },
    {
      "value": "dashboard-bl.pamconj.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "Cisco Talos"
      ],
      "articles": [
        {
          "id": "art-188",
          "title": "IR Trends Q2 2026: Phishing and weaponized remote management tools drive attack chains",
          "link": "https://blog.talosintelligence.com/ir-trends-q2-2026/",
          "published": "2026-07-28",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-28"
    },
    {
      "value": "git-tanstack.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "StepSecurity",
        "CISA KEV",
        "Aikido"
      ],
      "articles": [
        {
          "id": "art-182",
          "title": "2026 Mid-Year Update: On Pace for Our Biggest Year Yet",
          "link": "https://www.stepsecurity.io/blog/2026-mid-year-update-on-pace-for-our-biggest-year-yet",
          "published": "2026-07-28",
          "sev": "crit"
        },
        {
          "id": "art-440",
          "title": "CISA KEV: CVE-2026-45321 \u2014 TanStack Unspecified Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-05-27",
          "sev": "crit"
        },
        {
          "id": "art-442",
          "title": "Why developer machines are now the number one target for supply chain attacks",
          "link": "https://www.aikido.dev/blog/developer-machines-supply-chain-attacks",
          "published": "2026-05-26",
          "sev": "high"
        },
        {
          "id": "art-483",
          "title": "TeamPCP's Mini Shai-Hulud Is Back: A Self-Spreading Supply Chain Attack Compromises TanStack npm Packages",
          "link": "https://www.stepsecurity.io/blog/mini-shai-hulud-is-back-a-self-spreading-supply-chain-attack-hits-the-npm-ecosystem",
          "published": "2026-05-12",
          "sev": "crit"
        },
        {
          "id": "art-486",
          "title": "Mini Shai-Hulud Is Back: npm Worm Hits over 160 Packages, including Mistral and Tanstack",
          "link": "https://www.aikido.dev/blog/mini-shai-hulud-is-back-tanstack-compromised",
          "published": "2026-05-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-28"
    },
    {
      "value": "spx.pamconj.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "Cisco Talos"
      ],
      "articles": [
        {
          "id": "art-188",
          "title": "IR Trends Q2 2026: Phishing and weaponized remote management tools drive attack chains",
          "link": "https://blog.talosintelligence.com/ir-trends-q2-2026/",
          "published": "2026-07-28",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-28"
    },
    {
      "value": "83.142.209.194",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "StepSecurity",
        "Aikido"
      ],
      "articles": [
        {
          "id": "art-182",
          "title": "2026 Mid-Year Update: On Pace for Our Biggest Year Yet",
          "link": "https://www.stepsecurity.io/blog/2026-mid-year-update-on-pace-for-our-biggest-year-yet",
          "published": "2026-07-28",
          "sev": "crit"
        },
        {
          "id": "art-452",
          "title": "5 Supply Chain Attacks in 48 Hours: Why Securing One Layer Is Not Enough",
          "link": "https://www.stepsecurity.io/blog/5-supply-chain-attacks-in-48-hours-why-securing-one-layer-is-not-enough",
          "published": "2026-05-21",
          "sev": "crit"
        },
        {
          "id": "art-483",
          "title": "TeamPCP's Mini Shai-Hulud Is Back: A Self-Spreading Supply Chain Attack Compromises TanStack npm Packages",
          "link": "https://www.stepsecurity.io/blog/mini-shai-hulud-is-back-a-self-spreading-supply-chain-attack-hits-the-npm-ecosystem",
          "published": "2026-05-12",
          "sev": "crit"
        },
        {
          "id": "art-486",
          "title": "Mini Shai-Hulud Is Back: npm Worm Hits over 160 Packages, including Mistral and Tanstack",
          "link": "https://www.aikido.dev/blog/mini-shai-hulud-is-back-tanstack-compromised",
          "published": "2026-05-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-28"
    },
    {
      "value": "12f35b1081b17d21815b35feb57ab03d02482116",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "StepSecurity",
        "Aikido"
      ],
      "articles": [
        {
          "id": "art-182",
          "title": "2026 Mid-Year Update: On Pace for Our Biggest Year Yet",
          "link": "https://www.stepsecurity.io/blog/2026-mid-year-update-on-pace-for-our-biggest-year-yet",
          "published": "2026-07-28",
          "sev": "crit"
        },
        {
          "id": "art-483",
          "title": "TeamPCP's Mini Shai-Hulud Is Back: A Self-Spreading Supply Chain Attack Compromises TanStack npm Packages",
          "link": "https://www.stepsecurity.io/blog/mini-shai-hulud-is-back-a-self-spreading-supply-chain-attack-hits-the-npm-ecosystem",
          "published": "2026-05-12",
          "sev": "crit"
        },
        {
          "id": "art-486",
          "title": "Mini Shai-Hulud Is Back: npm Worm Hits over 160 Packages, including Mistral and Tanstack",
          "link": "https://www.aikido.dev/blog/mini-shai-hulud-is-back-tanstack-compromised",
          "published": "2026-05-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-28"
    },
    {
      "value": "820fa07a7328b6cf2b417078e103721d4d8f2e79",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "StepSecurity",
        "Aikido"
      ],
      "articles": [
        {
          "id": "art-182",
          "title": "2026 Mid-Year Update: On Pace for Our Biggest Year Yet",
          "link": "https://www.stepsecurity.io/blog/2026-mid-year-update-on-pace-for-our-biggest-year-yet",
          "published": "2026-07-28",
          "sev": "crit"
        },
        {
          "id": "art-483",
          "title": "TeamPCP's Mini Shai-Hulud Is Back: A Self-Spreading Supply Chain Attack Compromises TanStack npm Packages",
          "link": "https://www.stepsecurity.io/blog/mini-shai-hulud-is-back-a-self-spreading-supply-chain-attack-hits-the-npm-ecosystem",
          "published": "2026-05-12",
          "sev": "crit"
        },
        {
          "id": "art-486",
          "title": "Mini Shai-Hulud Is Back: npm Worm Hits over 160 Packages, including Mistral and Tanstack",
          "link": "https://www.aikido.dev/blog/mini-shai-hulud-is-back-tanstack-compromised",
          "published": "2026-05-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-28"
    },
    {
      "value": "e7d582b98ca80690883175470e96f703ef6dc497",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "StepSecurity",
        "Aikido"
      ],
      "articles": [
        {
          "id": "art-182",
          "title": "2026 Mid-Year Update: On Pace for Our Biggest Year Yet",
          "link": "https://www.stepsecurity.io/blog/2026-mid-year-update-on-pace-for-our-biggest-year-yet",
          "published": "2026-07-28",
          "sev": "crit"
        },
        {
          "id": "art-483",
          "title": "TeamPCP's Mini Shai-Hulud Is Back: A Self-Spreading Supply Chain Attack Compromises TanStack npm Packages",
          "link": "https://www.stepsecurity.io/blog/mini-shai-hulud-is-back-a-self-spreading-supply-chain-attack-hits-the-npm-ecosystem",
          "published": "2026-05-12",
          "sev": "crit"
        },
        {
          "id": "art-486",
          "title": "Mini Shai-Hulud Is Back: npm Worm Hits over 160 Packages, including Mistral and Tanstack",
          "link": "https://www.aikido.dev/blog/mini-shai-hulud-is-back-tanstack-compromised",
          "published": "2026-05-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-28"
    },
    {
      "value": "1e8538c6e0563d50da0f2e097e979ebd5294ce1defe01d0b9fe361ba3bed1898",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "StepSecurity"
      ],
      "articles": [
        {
          "id": "art-182",
          "title": "2026 Mid-Year Update: On Pace for Our Biggest Year Yet",
          "link": "https://www.stepsecurity.io/blog/2026-mid-year-update-on-pace-for-our-biggest-year-yet",
          "published": "2026-07-28",
          "sev": "crit"
        },
        {
          "id": "art-483",
          "title": "TeamPCP's Mini Shai-Hulud Is Back: A Self-Spreading Supply Chain Attack Compromises TanStack npm Packages",
          "link": "https://www.stepsecurity.io/blog/mini-shai-hulud-is-back-a-self-spreading-supply-chain-attack-hits-the-npm-ecosystem",
          "published": "2026-05-12",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-28"
    },
    {
      "value": "2258284d65f63829bd67eaba01ef6f1ada2f593f9bbe41678b2df360bd90d3df",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "StepSecurity",
        "Aikido"
      ],
      "articles": [
        {
          "id": "art-182",
          "title": "2026 Mid-Year Update: On Pace for Our Biggest Year Yet",
          "link": "https://www.stepsecurity.io/blog/2026-mid-year-update-on-pace-for-our-biggest-year-yet",
          "published": "2026-07-28",
          "sev": "crit"
        },
        {
          "id": "art-483",
          "title": "TeamPCP's Mini Shai-Hulud Is Back: A Self-Spreading Supply Chain Attack Compromises TanStack npm Packages",
          "link": "https://www.stepsecurity.io/blog/mini-shai-hulud-is-back-a-self-spreading-supply-chain-attack-hits-the-npm-ecosystem",
          "published": "2026-05-12",
          "sev": "crit"
        },
        {
          "id": "art-486",
          "title": "Mini Shai-Hulud Is Back: npm Worm Hits over 160 Packages, including Mistral and Tanstack",
          "link": "https://www.aikido.dev/blog/mini-shai-hulud-is-back-tanstack-compromised",
          "published": "2026-05-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-28"
    },
    {
      "value": "2ec78d556d696e208927cc503d48e4b5eb56b31abc2870c2ed2e98d6be27fc96",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "StepSecurity",
        "Aikido",
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-182",
          "title": "2026 Mid-Year Update: On Pace for Our Biggest Year Yet",
          "link": "https://www.stepsecurity.io/blog/2026-mid-year-update-on-pace-for-our-biggest-year-yet",
          "published": "2026-07-28",
          "sev": "crit"
        },
        {
          "id": "art-432",
          "title": "What MDM can't protect on developer machines (and what to do about it)",
          "link": "https://www.aikido.dev/blog/what-mdm-cant-protect",
          "published": "2026-05-28",
          "sev": "high"
        },
        {
          "id": "art-440",
          "title": "CISA KEV: CVE-2026-45321 \u2014 TanStack Unspecified Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-05-27",
          "sev": "crit"
        },
        {
          "id": "art-442",
          "title": "Why developer machines are now the number one target for supply chain attacks",
          "link": "https://www.aikido.dev/blog/developer-machines-supply-chain-attacks",
          "published": "2026-05-26",
          "sev": "high"
        },
        {
          "id": "art-483",
          "title": "TeamPCP's Mini Shai-Hulud Is Back: A Self-Spreading Supply Chain Attack Compromises TanStack npm Packages",
          "link": "https://www.stepsecurity.io/blog/mini-shai-hulud-is-back-a-self-spreading-supply-chain-attack-hits-the-npm-ecosystem",
          "published": "2026-05-12",
          "sev": "crit"
        },
        {
          "id": "art-486",
          "title": "Mini Shai-Hulud Is Back: npm Worm Hits over 160 Packages, including Mistral and Tanstack",
          "link": "https://www.aikido.dev/blog/mini-shai-hulud-is-back-tanstack-compromised",
          "published": "2026-05-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-28"
    },
    {
      "value": "ab4fcadaec49c03278063dd269ea5eef82d24f2124a8e15d7b90f2fa8601266c",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "StepSecurity",
        "Aikido",
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-182",
          "title": "2026 Mid-Year Update: On Pace for Our Biggest Year Yet",
          "link": "https://www.stepsecurity.io/blog/2026-mid-year-update-on-pace-for-our-biggest-year-yet",
          "published": "2026-07-28",
          "sev": "crit"
        },
        {
          "id": "art-432",
          "title": "What MDM can't protect on developer machines (and what to do about it)",
          "link": "https://www.aikido.dev/blog/what-mdm-cant-protect",
          "published": "2026-05-28",
          "sev": "high"
        },
        {
          "id": "art-440",
          "title": "CISA KEV: CVE-2026-45321 \u2014 TanStack Unspecified Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-05-27",
          "sev": "crit"
        },
        {
          "id": "art-442",
          "title": "Why developer machines are now the number one target for supply chain attacks",
          "link": "https://www.aikido.dev/blog/developer-machines-supply-chain-attacks",
          "published": "2026-05-26",
          "sev": "high"
        },
        {
          "id": "art-483",
          "title": "TeamPCP's Mini Shai-Hulud Is Back: A Self-Spreading Supply Chain Attack Compromises TanStack npm Packages",
          "link": "https://www.stepsecurity.io/blog/mini-shai-hulud-is-back-a-self-spreading-supply-chain-attack-hits-the-npm-ecosystem",
          "published": "2026-05-12",
          "sev": "crit"
        },
        {
          "id": "art-486",
          "title": "Mini Shai-Hulud Is Back: npm Worm Hits over 160 Packages, including Mistral and Tanstack",
          "link": "https://www.aikido.dev/blog/mini-shai-hulud-is-back-tanstack-compromised",
          "published": "2026-05-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-28"
    },
    {
      "value": "CVE-2022-42475",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-191",
          "title": "CISA KEV: CVE-2025-68686 \u2014 Fortinet FortiOS Exposure of Sensitive Information to an Unauthorized Actor Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-07-27",
          "sev": "crit"
        },
        {
          "id": "art-1912",
          "title": "CISA KEV: CVE-2022-42475 \u2014 Fortinet FortiOS Heap-Based Buffer Overflow Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-12-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-27"
    },
    {
      "value": "CVE-2023-27997",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-191",
          "title": "CISA KEV: CVE-2025-68686 \u2014 Fortinet FortiOS Exposure of Sensitive Information to an Unauthorized Actor Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-07-27",
          "sev": "crit"
        },
        {
          "id": "art-1158",
          "title": "CISA KEV: CVE-2023-45727 \u2014 North Grid Proself Improper Restriction of XML External Entity (XXE) Reference Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-12-03",
          "sev": "crit"
        },
        {
          "id": "art-1710",
          "title": "CISA KEV: CVE-2023-27997 \u2014 Fortinet FortiOS and FortiProxy SSL-VPN Heap-Based Buffer Overflow Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-06-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-27"
    },
    {
      "value": "CVE-2024-21762",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-191",
          "title": "CISA KEV: CVE-2025-68686 \u2014 Fortinet FortiOS Exposure of Sensitive Information to an Unauthorized Actor Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-07-27",
          "sev": "crit"
        },
        {
          "id": "art-1432",
          "title": "CISA KEV: CVE-2024-21762 \u2014 Fortinet FortiOS Out-of-Bound Write Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-02-09",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-27"
    },
    {
      "value": "CVE-2025-68686",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-191",
          "title": "CISA KEV: CVE-2025-68686 \u2014 Fortinet FortiOS Exposure of Sensitive Information to an Unauthorized Actor Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-07-27",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-27"
    },
    {
      "value": "CVE-2026-16812",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-192",
          "title": "CISA KEV: CVE-2026-16812 \u2014 Arista VeloCloud Orchestrator On-Prem OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-07-27",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-27"
    },
    {
      "value": "femboy.energy",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "StepSecurity"
      ],
      "articles": [
        {
          "id": "art-193",
          "title": "Compromised PyPI Package: mrmustard 0.7.4 Steals SSH, Cloud, and Kubernetes Credentials",
          "link": "https://www.stepsecurity.io/blog/compromised-pypi-mrmustard-0-7-4-credential-stealer",
          "published": "2026-07-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-25"
    },
    {
      "value": "metrics.femboy.energy",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "StepSecurity"
      ],
      "articles": [
        {
          "id": "art-193",
          "title": "Compromised PyPI Package: mrmustard 0.7.4 Steals SSH, Cloud, and Kubernetes Credentials",
          "link": "https://www.stepsecurity.io/blog/compromised-pypi-mrmustard-0-7-4-credential-stealer",
          "published": "2026-07-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-25"
    },
    {
      "value": "0404f8590fdaef95280c1d908068f31bf2321fe887faabf0c2329ba67c7203cb",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "StepSecurity"
      ],
      "articles": [
        {
          "id": "art-193",
          "title": "Compromised PyPI Package: mrmustard 0.7.4 Steals SSH, Cloud, and Kubernetes Credentials",
          "link": "https://www.stepsecurity.io/blog/compromised-pypi-mrmustard-0-7-4-credential-stealer",
          "published": "2026-07-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-25"
    },
    {
      "value": "81f0d1291a975d012d1b892cf9967557fdbb1ad4e1ac0545702ad235ace1cac5",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "StepSecurity"
      ],
      "articles": [
        {
          "id": "art-193",
          "title": "Compromised PyPI Package: mrmustard 0.7.4 Steals SSH, Cloud, and Kubernetes Credentials",
          "link": "https://www.stepsecurity.io/blog/compromised-pypi-mrmustard-0-7-4-credential-stealer",
          "published": "2026-07-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-25"
    },
    {
      "value": "CVE-2026-59864",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "GitHub Security Advisories"
      ],
      "articles": [
        {
          "id": "art-210",
          "title": "[GHSA / CRITICAL] CVE-2026-59864: Microsoft Kiota: Path/URL injection into generated Copilot plugin manifest via x-ai-* extensions",
          "link": "https://github.com/advisories/GHSA-4jwf-m4wg-8p66",
          "published": "2026-07-24",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-24"
    },
    {
      "value": "CVE-2026-59865",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "GitHub Security Advisories"
      ],
      "articles": [
        {
          "id": "art-209",
          "title": "[GHSA / CRITICAL] CVE-2026-59865: Microsoft Kiota: Command injection via x-ms-kiota-info dependencyInstallCommand surfaced by `kiota info`",
          "link": "https://github.com/advisories/GHSA-hq9q-27g5-qwpj",
          "published": "2026-07-24",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-24"
    },
    {
      "value": "CVE-2026-59940",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "GitHub Security Advisories"
      ],
      "articles": [
        {
          "id": "art-208",
          "title": "[GHSA / CRITICAL] CVE-2026-59940: seroval: `seroval.fromJSON()` Promise resolver type confusion invokes attacker-controlled methods during deserialization",
          "link": "https://github.com/advisories/GHSA-mv8w-475r-vwqw",
          "published": "2026-07-24",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-24"
    },
    {
      "value": "CVE-2026-62263",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "GitHub Security Advisories"
      ],
      "articles": [
        {
          "id": "art-203",
          "title": "[GHSA / CRITICAL] CVE-2026-62263: OpenAM: WebAuthn Java deserialization RCE via ObjectInputFilter depth>1 bypass",
          "link": "https://github.com/advisories/GHSA-gf8h-gq53-288j",
          "published": "2026-07-24",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-24"
    },
    {
      "value": "CVE-2026-62379",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "GitHub Security Advisories"
      ],
      "articles": [
        {
          "id": "art-202",
          "title": "[GHSA / CRITICAL] CVE-2026-62379: OpenAM: Unauthenticated Remote Code Execution via Class.forName in AuthXMLUtils.createCustomCallback",
          "link": "https://github.com/advisories/GHSA-wg5r-wc3x-39vc",
          "published": "2026-07-24",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-24"
    },
    {
      "value": "CVE-2026-73300",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "GitHub Security Advisories"
      ],
      "articles": [
        {
          "id": "art-201",
          "title": "[GHSA / CRITICAL] CVE-2026-73300: Budibase: SQL Injection via `multipleStatements: true`",
          "link": "https://github.com/advisories/GHSA-q6x4-v3qx-85qw",
          "published": "2026-07-24",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-24"
    },
    {
      "value": "CVE-2026-73302",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "GitHub Security Advisories"
      ],
      "articles": [
        {
          "id": "art-200",
          "title": "[GHSA / CRITICAL] CVE-2026-73302: Budibase: OIDC SSO account takeover: incoming identity linked by email without checking email_verified",
          "link": "https://github.com/advisories/GHSA-hp6v-6jw7-gv2f",
          "published": "2026-07-24",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-24"
    },
    {
      "value": "CVE-2026-73414",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "GitHub Security Advisories"
      ],
      "articles": [
        {
          "id": "art-194",
          "title": "[GHSA / CRITICAL] CVE-2026-73414: Shescape: Shell injection via unescaped parentheses on Windows with CMD",
          "link": "https://github.com/advisories/GHSA-w4hw-qcx7-56pr",
          "published": "2026-07-24",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-24"
    },
    {
      "value": "CVE-2026-73567",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "GitHub Security Advisories"
      ],
      "articles": [
        {
          "id": "art-196",
          "title": "[GHSA / CRITICAL] CVE-2026-73567: sm-crypto: Predictable SM2 key generation in Node.js: default RNG uses Math.random + wall clock",
          "link": "https://github.com/advisories/GHSA-vh45-f885-3848",
          "published": "2026-07-24",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-24"
    },
    {
      "value": "CVE-2026-73644",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "GitHub Security Advisories"
      ],
      "articles": [
        {
          "id": "art-197",
          "title": "[GHSA / CRITICAL] CVE-2026-73644: OpenDJ SASL PLAIN authzid bypassing the proxy ACI scope check",
          "link": "https://github.com/advisories/GHSA-p279-2cqp-84jg",
          "published": "2026-07-24",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-24"
    },
    {
      "value": "CVE-2026-73649",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "GitHub Security Advisories"
      ],
      "articles": [
        {
          "id": "art-207",
          "title": "[GHSA / CRITICAL] CVE-2026-73649: Velocity.js: Remote Code Execution via property-read to Function constructor (bypass of GHSA-j658-c2gf-x6pq fix)",
          "link": "https://github.com/advisories/GHSA-7gfh-x38p-prh3",
          "published": "2026-07-24",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-24"
    },
    {
      "value": "143268fa0939b4da09eab8c9a2e027a04555b6c433fef4f54fc5edd517c0a6b1",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "GitHub Security Advisories"
      ],
      "articles": [
        {
          "id": "art-196",
          "title": "[GHSA / CRITICAL] CVE-2026-73567: sm-crypto: Predictable SM2 key generation in Node.js: default RNG uses Math.random + wall clock",
          "link": "https://github.com/advisories/GHSA-vh45-f885-3848",
          "published": "2026-07-24",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-24"
    },
    {
      "value": "6072e45733a4187791ec28ce906fef18c7d33c8529969e1a852833c4349cfc38",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "GitHub Security Advisories"
      ],
      "articles": [
        {
          "id": "art-196",
          "title": "[GHSA / CRITICAL] CVE-2026-73567: sm-crypto: Predictable SM2 key generation in Node.js: default RNG uses Math.random + wall clock",
          "link": "https://github.com/advisories/GHSA-vh45-f885-3848",
          "published": "2026-07-24",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-24"
    },
    {
      "value": "CVE-2025-66376",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "Unit 42 (Palo Alto)",
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-217",
          "title": "Russian Global Webmail Espionage",
          "link": "https://unit42.paloaltonetworks.com/russian-webmail-espionage/",
          "published": "2026-07-23",
          "sev": "crit"
        },
        {
          "id": "art-617",
          "title": "CISA KEV: CVE-2025-66376 \u2014 Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-03-18",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-23"
    },
    {
      "value": "CVE-2026-16723",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "GitHub Security Advisories"
      ],
      "articles": [
        {
          "id": "art-220",
          "title": "[GHSA / CRITICAL] CVE-2026-16723: fastjson has a remote code execution (RCE) vulnerability",
          "link": "https://github.com/advisories/GHSA-crf3-v9rr-v7hj",
          "published": "2026-07-23",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-23"
    },
    {
      "value": "CVE-2026-60137",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "Cisco Talos",
        "Aikido",
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-213",
          "title": "Don\u2019t swing at everything",
          "link": "https://blog.talosintelligence.com/dont-swing-at-everything/",
          "published": "2026-07-23",
          "sev": "crit"
        },
        {
          "id": "art-224",
          "title": "SQL injection isn't dead",
          "link": "https://www.aikido.dev/blog/sql-injection-isnt-dead",
          "published": "2026-07-22",
          "sev": "high"
        },
        {
          "id": "art-238",
          "title": "CISA KEV: CVE-2026-60137 \u2014 WordPress Core SQL Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-07-21",
          "sev": "crit"
        },
        {
          "id": "art-247",
          "title": "Unauthenticated RCE in WordPress core (wp2shell), via SQL injection",
          "link": "https://www.aikido.dev/blog/unauthenticated-rce-in-wordpress-wp2shell",
          "published": "2026-07-17",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-23"
    },
    {
      "value": "CVE-2026-63030",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "Cisco Talos",
        "Aikido",
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-213",
          "title": "Don\u2019t swing at everything",
          "link": "https://blog.talosintelligence.com/dont-swing-at-everything/",
          "published": "2026-07-23",
          "sev": "crit"
        },
        {
          "id": "art-224",
          "title": "SQL injection isn't dead",
          "link": "https://www.aikido.dev/blog/sql-injection-isnt-dead",
          "published": "2026-07-22",
          "sev": "high"
        },
        {
          "id": "art-238",
          "title": "CISA KEV: CVE-2026-60137 \u2014 WordPress Core SQL Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-07-21",
          "sev": "crit"
        },
        {
          "id": "art-247",
          "title": "Unauthenticated RCE in WordPress core (wp2shell), via SQL injection",
          "link": "https://www.aikido.dev/blog/unauthenticated-rce-in-wordpress-wp2shell",
          "published": "2026-07-17",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-23"
    },
    {
      "value": "CVE-2026-73420",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "GitHub Security Advisories"
      ],
      "articles": [
        {
          "id": "art-216",
          "title": "[GHSA / CRITICAL] CVE-2026-73420: Auth.js: Email normalizer validates the address before Unicode normalization, allowing a homoglyph @ bypass",
          "link": "https://github.com/advisories/GHSA-7rqj-j65f-68wh",
          "published": "2026-07-23",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-23"
    },
    {
      "value": "CVE-2026-73421",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "GitHub Security Advisories"
      ],
      "articles": [
        {
          "id": "art-215",
          "title": "[GHSA / CRITICAL] CVE-2026-73421: Auth.js: Configuration errors can cause existence-based auth checks to fail open (auth object populated with an error)",
          "link": "https://github.com/advisories/GHSA-8fpg-xm3f-6cx3",
          "published": "2026-07-23",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-23"
    },
    {
      "value": "analyticemailmeter.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "Unit 42 (Palo Alto)"
      ],
      "articles": [
        {
          "id": "art-217",
          "title": "Russian Global Webmail Espionage",
          "link": "https://unit42.paloaltonetworks.com/russian-webmail-espionage/",
          "published": "2026-07-23",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-23"
    },
    {
      "value": "emailanalytics.com.ua",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "Unit 42 (Palo Alto)"
      ],
      "articles": [
        {
          "id": "art-217",
          "title": "Russian Global Webmail Espionage",
          "link": "https://unit42.paloaltonetworks.com/russian-webmail-espionage/",
          "published": "2026-07-23",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-23"
    },
    {
      "value": "istc-cloud.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "Unit 42 (Palo Alto)"
      ],
      "articles": [
        {
          "id": "art-217",
          "title": "Russian Global Webmail Espionage",
          "link": "https://unit42.paloaltonetworks.com/russian-webmail-espionage/",
          "published": "2026-07-23",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-23"
    },
    {
      "value": "mailnalysis.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "Unit 42 (Palo Alto)"
      ],
      "articles": [
        {
          "id": "art-217",
          "title": "Russian Global Webmail Espionage",
          "link": "https://unit42.paloaltonetworks.com/russian-webmail-espionage/",
          "published": "2026-07-23",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-23"
    },
    {
      "value": "synacorzimbra.nl",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "Unit 42 (Palo Alto)"
      ],
      "articles": [
        {
          "id": "art-217",
          "title": "Russian Global Webmail Espionage",
          "link": "https://unit42.paloaltonetworks.com/russian-webmail-espionage/",
          "published": "2026-07-23",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-23"
    },
    {
      "value": "zimbra-metadata.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "Unit 42 (Palo Alto)"
      ],
      "articles": [
        {
          "id": "art-217",
          "title": "Russian Global Webmail Espionage",
          "link": "https://unit42.paloaltonetworks.com/russian-webmail-espionage/",
          "published": "2026-07-23",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-23"
    },
    {
      "value": "zimbrasoft.com.ua",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "Unit 42 (Palo Alto)"
      ],
      "articles": [
        {
          "id": "art-217",
          "title": "Russian Global Webmail Espionage",
          "link": "https://unit42.paloaltonetworks.com/russian-webmail-espionage/",
          "published": "2026-07-23",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-23"
    },
    {
      "value": "zimbrastat.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "Unit 42 (Palo Alto)"
      ],
      "articles": [
        {
          "id": "art-217",
          "title": "Russian Global Webmail Espionage",
          "link": "https://unit42.paloaltonetworks.com/russian-webmail-espionage/",
          "published": "2026-07-23",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-23"
    },
    {
      "value": "zmailanalytics.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "Unit 42 (Palo Alto)"
      ],
      "articles": [
        {
          "id": "art-217",
          "title": "Russian Global Webmail Espionage",
          "link": "https://unit42.paloaltonetworks.com/russian-webmail-espionage/",
          "published": "2026-07-23",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-23"
    },
    {
      "value": "104.248.134.194",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "Unit 42 (Palo Alto)"
      ],
      "articles": [
        {
          "id": "art-217",
          "title": "Russian Global Webmail Espionage",
          "link": "https://unit42.paloaltonetworks.com/russian-webmail-espionage/",
          "published": "2026-07-23",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-23"
    },
    {
      "value": "185.86.79.95",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "Unit 42 (Palo Alto)"
      ],
      "articles": [
        {
          "id": "art-217",
          "title": "Russian Global Webmail Espionage",
          "link": "https://unit42.paloaltonetworks.com/russian-webmail-espionage/",
          "published": "2026-07-23",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-23"
    },
    {
      "value": "193.238.152.66",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "Unit 42 (Palo Alto)"
      ],
      "articles": [
        {
          "id": "art-217",
          "title": "Russian Global Webmail Espionage",
          "link": "https://unit42.paloaltonetworks.com/russian-webmail-espionage/",
          "published": "2026-07-23",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-23"
    },
    {
      "value": "194.156.103.193",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "Unit 42 (Palo Alto)"
      ],
      "articles": [
        {
          "id": "art-217",
          "title": "Russian Global Webmail Espionage",
          "link": "https://unit42.paloaltonetworks.com/russian-webmail-espionage/",
          "published": "2026-07-23",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-23"
    },
    {
      "value": "216.252.238.104",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "Unit 42 (Palo Alto)"
      ],
      "articles": [
        {
          "id": "art-217",
          "title": "Russian Global Webmail Espionage",
          "link": "https://unit42.paloaltonetworks.com/russian-webmail-espionage/",
          "published": "2026-07-23",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-23"
    },
    {
      "value": "216.252.238.18",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "Unit 42 (Palo Alto)"
      ],
      "articles": [
        {
          "id": "art-217",
          "title": "Russian Global Webmail Espionage",
          "link": "https://unit42.paloaltonetworks.com/russian-webmail-espionage/",
          "published": "2026-07-23",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-23"
    },
    {
      "value": "216.252.238.64",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "Unit 42 (Palo Alto)"
      ],
      "articles": [
        {
          "id": "art-217",
          "title": "Russian Global Webmail Espionage",
          "link": "https://unit42.paloaltonetworks.com/russian-webmail-espionage/",
          "published": "2026-07-23",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-23"
    },
    {
      "value": "37.120.247.228",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "Unit 42 (Palo Alto)"
      ],
      "articles": [
        {
          "id": "art-217",
          "title": "Russian Global Webmail Espionage",
          "link": "https://unit42.paloaltonetworks.com/russian-webmail-espionage/",
          "published": "2026-07-23",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-23"
    },
    {
      "value": "64.226.124.190",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "Unit 42 (Palo Alto)"
      ],
      "articles": [
        {
          "id": "art-217",
          "title": "Russian Global Webmail Espionage",
          "link": "https://unit42.paloaltonetworks.com/russian-webmail-espionage/",
          "published": "2026-07-23",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-23"
    },
    {
      "value": "770dbe473180366d7b539ff2c188e551",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "Cisco Talos"
      ],
      "articles": [
        {
          "id": "art-213",
          "title": "Don\u2019t swing at everything",
          "link": "https://blog.talosintelligence.com/dont-swing-at-everything/",
          "published": "2026-07-23",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-23"
    },
    {
      "value": "dbd8dbecaa80795c135137d69921fdba",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "Cisco Talos"
      ],
      "articles": [
        {
          "id": "art-213",
          "title": "Don\u2019t swing at everything",
          "link": "https://blog.talosintelligence.com/dont-swing-at-everything/",
          "published": "2026-07-23",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-23"
    },
    {
      "value": "633bd79d1efd3730234d907a2a0d98e3e253a5f0e222e4e4bf3badb3fd6aea0a",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "Cisco Talos"
      ],
      "articles": [
        {
          "id": "art-213",
          "title": "Don\u2019t swing at everything",
          "link": "https://blog.talosintelligence.com/dont-swing-at-everything/",
          "published": "2026-07-23",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-23"
    },
    {
      "value": "e60ab99da105ee27ee09ea64ed8eb46d8edc92ee37f039dbc3e2bb9f587a33ba",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "Cisco Talos"
      ],
      "articles": [
        {
          "id": "art-213",
          "title": "Don\u2019t swing at everything",
          "link": "https://blog.talosintelligence.com/dont-swing-at-everything/",
          "published": "2026-07-23",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-23"
    },
    {
      "value": "bold-dhawan.45-139-104-115.plesk.page",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "StepSecurity"
      ],
      "articles": [
        {
          "id": "art-221",
          "title": "Find Unused, Stale, and OIDC-Replaceable GitHub Actions Secrets Across Your GitHub Organization",
          "link": "https://www.stepsecurity.io/blog/find-unused-stale-and-oidc-replaceable-github-actions-secrets-across-your-github-organization",
          "published": "2026-07-23",
          "sev": "high"
        },
        {
          "id": "art-292",
          "title": "GitHub Secret Scanning Public Monitoring for Enterprises: Coverage and Gaps",
          "link": "https://www.stepsecurity.io/blog/github-secret-scanning-public-monitoring-for-enterprises-coverage-and-gaps",
          "published": "2026-07-12",
          "sev": "high"
        }
      ],
      "first_seen": "2026-07-23"
    },
    {
      "value": "carte-avantage.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "StepSecurity"
      ],
      "articles": [
        {
          "id": "art-221",
          "title": "Find Unused, Stale, and OIDC-Replaceable GitHub Actions Secrets Across Your GitHub Organization",
          "link": "https://www.stepsecurity.io/blog/find-unused-stale-and-oidc-replaceable-github-actions-secrets-across-your-github-organization",
          "published": "2026-07-23",
          "sev": "high"
        },
        {
          "id": "art-292",
          "title": "GitHub Secret Scanning Public Monitoring for Enterprises: Coverage and Gaps",
          "link": "https://www.stepsecurity.io/blog/github-secret-scanning-public-monitoring-for-enterprises-coverage-and-gaps",
          "published": "2026-07-12",
          "sev": "high"
        }
      ],
      "first_seen": "2026-07-23"
    },
    {
      "value": "objective-hopper.45-139-104-115.plesk.page",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "StepSecurity"
      ],
      "articles": [
        {
          "id": "art-221",
          "title": "Find Unused, Stale, and OIDC-Replaceable GitHub Actions Secrets Across Your GitHub Organization",
          "link": "https://www.stepsecurity.io/blog/find-unused-stale-and-oidc-replaceable-github-actions-secrets-across-your-github-organization",
          "published": "2026-07-23",
          "sev": "high"
        },
        {
          "id": "art-292",
          "title": "GitHub Secret Scanning Public Monitoring for Enterprises: Coverage and Gaps",
          "link": "https://www.stepsecurity.io/blog/github-secret-scanning-public-monitoring-for-enterprises-coverage-and-gaps",
          "published": "2026-07-12",
          "sev": "high"
        }
      ],
      "first_seen": "2026-07-23"
    },
    {
      "value": "216.126.225.129",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "StepSecurity"
      ],
      "articles": [
        {
          "id": "art-221",
          "title": "Find Unused, Stale, and OIDC-Replaceable GitHub Actions Secrets Across Your GitHub Organization",
          "link": "https://www.stepsecurity.io/blog/find-unused-stale-and-oidc-replaceable-github-actions-secrets-across-your-github-organization",
          "published": "2026-07-23",
          "sev": "high"
        },
        {
          "id": "art-258",
          "title": "Harden-Runner Block Mode Now Available for macOS and Windows GitHub-Hosted Runners",
          "link": "https://www.stepsecurity.io/blog/harden-runner-block-mode-now-available-for-macos-and-windows-github-hosted-runners",
          "published": "2026-07-16",
          "sev": "high"
        },
        {
          "id": "art-292",
          "title": "GitHub Secret Scanning Public Monitoring for Enterprises: Coverage and Gaps",
          "link": "https://www.stepsecurity.io/blog/github-secret-scanning-public-monitoring-for-enterprises-coverage-and-gaps",
          "published": "2026-07-12",
          "sev": "high"
        },
        {
          "id": "art-447",
          "title": "Megalodon: Mass GitHub Actions Secret Exfiltration Across 5,500+ Public Repositories",
          "link": "https://www.stepsecurity.io/blog/megalodon-mass-github-actions-secret-exfiltration-across-5-500-public-repositories",
          "published": "2026-05-22",
          "sev": "high"
        }
      ],
      "first_seen": "2026-07-23"
    },
    {
      "value": "45.139.104.115",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "StepSecurity"
      ],
      "articles": [
        {
          "id": "art-221",
          "title": "Find Unused, Stale, and OIDC-Replaceable GitHub Actions Secrets Across Your GitHub Organization",
          "link": "https://www.stepsecurity.io/blog/find-unused-stale-and-oidc-replaceable-github-actions-secrets-across-your-github-organization",
          "published": "2026-07-23",
          "sev": "high"
        },
        {
          "id": "art-292",
          "title": "GitHub Secret Scanning Public Monitoring for Enterprises: Coverage and Gaps",
          "link": "https://www.stepsecurity.io/blog/github-secret-scanning-public-monitoring-for-enterprises-coverage-and-gaps",
          "published": "2026-07-12",
          "sev": "high"
        }
      ],
      "first_seen": "2026-07-23"
    },
    {
      "value": "acac5a9854650c4ae2883c4740bf87d34120c038",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "StepSecurity"
      ],
      "articles": [
        {
          "id": "art-221",
          "title": "Find Unused, Stale, and OIDC-Replaceable GitHub Actions Secrets Across Your GitHub Organization",
          "link": "https://www.stepsecurity.io/blog/find-unused-stale-and-oidc-replaceable-github-actions-secrets-across-your-github-organization",
          "published": "2026-07-23",
          "sev": "high"
        },
        {
          "id": "art-447",
          "title": "Megalodon: Mass GitHub Actions Secret Exfiltration Across 5,500+ Public Repositories",
          "link": "https://www.stepsecurity.io/blog/megalodon-mass-github-actions-secret-exfiltration-across-5-500-public-repositories",
          "published": "2026-05-22",
          "sev": "high"
        }
      ],
      "first_seen": "2026-07-23"
    },
    {
      "value": "CVE-2026-50522",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-227",
          "title": "CISA KEV: CVE-2026-50522 \u2014 Microsoft SharePoint Deserialization of Untrusted Data Vulnerability ",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-07-22",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-22"
    },
    {
      "value": "npmjs.help",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "Aikido",
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-225",
          "title": "The upgrade trap: when upgrading is the wrong answer to a CVE",
          "link": "https://www.aikido.dev/blog/cve-upgrade-breaking-changes-open-source",
          "published": "2026-07-22",
          "sev": "high"
        },
        {
          "id": "art-287",
          "title": "What is a dependency firewall?",
          "link": "https://www.aikido.dev/blog/what-is-a-dependency-firewall",
          "published": "2026-07-13",
          "sev": "crit"
        },
        {
          "id": "art-878",
          "title": "npm Supply Chain Attack via Open Source maintainer compromise",
          "link": "https://snyk.io/blog/npm-supply-chain-attack-via-open-source-maintainer-compromise/",
          "published": "2025-09-08",
          "sev": "high"
        }
      ],
      "first_seen": "2026-07-22"
    },
    {
      "value": "139.28.37.250",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-226",
          "title": "CISA KEV: CVE-2026-16232 \u2014 Check Point SmartConsole Improper Authentication Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-07-22",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-22"
    },
    {
      "value": "151.241.99.207",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-226",
          "title": "CISA KEV: CVE-2026-16232 \u2014 Check Point SmartConsole Improper Authentication Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-07-22",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-22"
    },
    {
      "value": "151.241.99.233",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-226",
          "title": "CISA KEV: CVE-2026-16232 \u2014 Check Point SmartConsole Improper Authentication Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-07-22",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-22"
    },
    {
      "value": "158.62.198.182",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-226",
          "title": "CISA KEV: CVE-2026-16232 \u2014 Check Point SmartConsole Improper Authentication Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-07-22",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-22"
    },
    {
      "value": "192.142.10.99",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-226",
          "title": "CISA KEV: CVE-2026-16232 \u2014 Check Point SmartConsole Improper Authentication Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-07-22",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-22"
    },
    {
      "value": "194.213.18.137",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-226",
          "title": "CISA KEV: CVE-2026-16232 \u2014 Check Point SmartConsole Improper Authentication Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-07-22",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-22"
    },
    {
      "value": "CVE-2024-42005",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "Aikido"
      ],
      "articles": [
        {
          "id": "art-224",
          "title": "SQL injection isn't dead",
          "link": "https://www.aikido.dev/blog/sql-injection-isnt-dead",
          "published": "2026-07-22",
          "sev": "high"
        }
      ],
      "first_seen": "2026-07-22"
    },
    {
      "value": "CVE-2026-48937",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "Aikido"
      ],
      "articles": [
        {
          "id": "art-225",
          "title": "The upgrade trap: when upgrading is the wrong answer to a CVE",
          "link": "https://www.aikido.dev/blog/cve-upgrade-breaking-changes-open-source",
          "published": "2026-07-22",
          "sev": "high"
        }
      ],
      "first_seen": "2026-07-22"
    },
    {
      "value": "attacker.tld",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "Aikido"
      ],
      "articles": [
        {
          "id": "art-222",
          "title": "Finding eight high-severity vulnerabilities in NodeBB in six hours",
          "link": "https://www.aikido.dev/blog/eight-high-severity-vulnerabilities-nodebb",
          "published": "2026-07-22",
          "sev": "high"
        }
      ],
      "first_seen": "2026-07-22"
    },
    {
      "value": "rhythm-broke-heath-kernel.trycloudflare.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "Aikido"
      ],
      "articles": [
        {
          "id": "art-222",
          "title": "Finding eight high-severity vulnerabilities in NodeBB in six hours",
          "link": "https://www.aikido.dev/blog/eight-high-severity-vulnerabilities-nodebb",
          "published": "2026-07-22",
          "sev": "high"
        }
      ],
      "first_seen": "2026-07-22"
    },
    {
      "value": "4.245.3.4",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "Aikido"
      ],
      "articles": [
        {
          "id": "art-222",
          "title": "Finding eight high-severity vulnerabilities in NodeBB in six hours",
          "link": "https://www.aikido.dev/blog/eight-high-severity-vulnerabilities-nodebb",
          "published": "2026-07-22",
          "sev": "high"
        }
      ],
      "first_seen": "2026-07-22"
    },
    {
      "value": "0ff6abe0252d4f37a196a1231fae5f26",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "SentinelLabs"
      ],
      "articles": [
        {
          "id": "art-223",
          "title": "Sol Searching | Can Frontier Models Tackle Autonomous Long-Horizon Malware Analysis?",
          "link": "https://www.sentinelone.com/labs/frontier-models-tackle-autonomous-long-horizon-malware-analysis/",
          "published": "2026-07-22",
          "sev": "high"
        }
      ],
      "first_seen": "2026-07-22"
    },
    {
      "value": "410eddfc19de44249897986ecc8ac449",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "SentinelLabs"
      ],
      "articles": [
        {
          "id": "art-223",
          "title": "Sol Searching | Can Frontier Models Tackle Autonomous Long-Horizon Malware Analysis?",
          "link": "https://www.sentinelone.com/labs/frontier-models-tackle-autonomous-long-horizon-malware-analysis/",
          "published": "2026-07-22",
          "sev": "high"
        }
      ],
      "first_seen": "2026-07-22"
    },
    {
      "value": "dbe51eabebf9d4ef9581ef99844a2944",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "SentinelLabs"
      ],
      "articles": [
        {
          "id": "art-223",
          "title": "Sol Searching | Can Frontier Models Tackle Autonomous Long-Horizon Malware Analysis?",
          "link": "https://www.sentinelone.com/labs/frontier-models-tackle-autonomous-long-horizon-malware-analysis/",
          "published": "2026-07-22",
          "sev": "high"
        }
      ],
      "first_seen": "2026-07-22"
    },
    {
      "value": "675cb83cec5f25ebbe8d9f90dea3d836fcb1c234",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "SentinelLabs"
      ],
      "articles": [
        {
          "id": "art-223",
          "title": "Sol Searching | Can Frontier Models Tackle Autonomous Long-Horizon Malware Analysis?",
          "link": "https://www.sentinelone.com/labs/frontier-models-tackle-autonomous-long-horizon-malware-analysis/",
          "published": "2026-07-22",
          "sev": "high"
        }
      ],
      "first_seen": "2026-07-22"
    },
    {
      "value": "92e9dcaf7249110047ef121b7586c81d4b8cb4e5",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "SentinelLabs"
      ],
      "articles": [
        {
          "id": "art-223",
          "title": "Sol Searching | Can Frontier Models Tackle Autonomous Long-Horizon Malware Analysis?",
          "link": "https://www.sentinelone.com/labs/frontier-models-tackle-autonomous-long-horizon-malware-analysis/",
          "published": "2026-07-22",
          "sev": "high"
        }
      ],
      "first_seen": "2026-07-22"
    },
    {
      "value": "de584703c78a60a56028f9834086facd1401b355",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "SentinelLabs"
      ],
      "articles": [
        {
          "id": "art-223",
          "title": "Sol Searching | Can Frontier Models Tackle Autonomous Long-Horizon Malware Analysis?",
          "link": "https://www.sentinelone.com/labs/frontier-models-tackle-autonomous-long-horizon-malware-analysis/",
          "published": "2026-07-22",
          "sev": "high"
        }
      ],
      "first_seen": "2026-07-22"
    },
    {
      "value": "07c69fc33271cf5a2ce03ac1fed7a3b16357aec093c5bf9ef61fbfa4348d0529",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "SentinelLabs"
      ],
      "articles": [
        {
          "id": "art-223",
          "title": "Sol Searching | Can Frontier Models Tackle Autonomous Long-Horizon Malware Analysis?",
          "link": "https://www.sentinelone.com/labs/frontier-models-tackle-autonomous-long-horizon-malware-analysis/",
          "published": "2026-07-22",
          "sev": "high"
        }
      ],
      "first_seen": "2026-07-22"
    },
    {
      "value": "8fcb4d3d4df61719ee3da98241393779290e0efcd88a49e363e2a2dfbc04dae9",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "SentinelLabs"
      ],
      "articles": [
        {
          "id": "art-223",
          "title": "Sol Searching | Can Frontier Models Tackle Autonomous Long-Horizon Malware Analysis?",
          "link": "https://www.sentinelone.com/labs/frontier-models-tackle-autonomous-long-horizon-malware-analysis/",
          "published": "2026-07-22",
          "sev": "high"
        }
      ],
      "first_seen": "2026-07-22"
    },
    {
      "value": "9a10e1faa86a5d39417cae44da5adf38824dfb9a16432e34df766aa1dc9e3525",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "SentinelLabs"
      ],
      "articles": [
        {
          "id": "art-223",
          "title": "Sol Searching | Can Frontier Models Tackle Autonomous Long-Horizon Malware Analysis?",
          "link": "https://www.sentinelone.com/labs/frontier-models-tackle-autonomous-long-horizon-malware-analysis/",
          "published": "2026-07-22",
          "sev": "high"
        }
      ],
      "first_seen": "2026-07-22"
    },
    {
      "value": "CVE-2021-27137",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-240",
          "title": "CISA KEV: CVE-2021-27137 \u2014 DD-WRT Stack-Based Buffer Overflow Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-07-21",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-21"
    },
    {
      "value": "CVE-2026-0770",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-239",
          "title": "CISA KEV: CVE-2026-0770 \u2014 Langflow Inclusion of Functionality from Untrusted Control Sphere Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-07-21",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-21"
    },
    {
      "value": "CVE-2026-20896",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "GitHub Security Advisories"
      ],
      "articles": [
        {
          "id": "art-230",
          "title": "[GHSA / CRITICAL] CVE-2026-20896: Gitea Docker image: `REVERSE_PROXY_TRUSTED_PROXIES = *` default lets any source IP impersonate any user via `X-WEBAUTH-USER`",
          "link": "https://github.com/advisories/GHSA-f75j-4cw6-rmx4",
          "published": "2026-07-21",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-21"
    },
    {
      "value": "CVE-2026-22874",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "GitHub Security Advisories"
      ],
      "articles": [
        {
          "id": "art-231",
          "title": "[GHSA / CRITICAL] CVE-2026-22874: Gitea: Incomplete SSRF Protection in Webhook and Migration Allow-list Default Filter",
          "link": "https://github.com/advisories/GHSA-2r5c-gw76-rh3w",
          "published": "2026-07-21",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-21"
    },
    {
      "value": "CVE-2026-56750",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "GitHub Security Advisories"
      ],
      "articles": [
        {
          "id": "art-232",
          "title": "[GHSA / CRITICAL] CVE-2026-56750: Gitea Remember-Me Token Theft Not Invalidating Attacker Session",
          "link": "https://github.com/advisories/GHSA-rgv6-xp99-6mgj",
          "published": "2026-07-21",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-21"
    },
    {
      "value": "CVE-2026-58426",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "GitHub Security Advisories"
      ],
      "articles": [
        {
          "id": "art-229",
          "title": "[GHSA / CRITICAL] CVE-2026-58426: Gitea Actions Artifacts V4 signed URL HMAC ambiguity allows cross-repository artifact read and cross-task upload-state write",
          "link": "https://github.com/advisories/GHSA-hg5r-vq93-9fv6",
          "published": "2026-07-21",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-21"
    },
    {
      "value": "CVE-2026-58443",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "GitHub Security Advisories"
      ],
      "articles": [
        {
          "id": "art-228",
          "title": "[GHSA / CRITICAL] CVE-2026-58443: Gitea: Public-only repository tokens can update private PR head branches",
          "link": "https://github.com/advisories/GHSA-xxjv-752h-3vp2",
          "published": "2026-07-21",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-21"
    },
    {
      "value": "CVE-2026-59891",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "GitHub Security Advisories"
      ],
      "articles": [
        {
          "id": "art-235",
          "title": "[GHSA / CRITICAL] CVE-2026-59891: Credential confusion in @sigstore/oci can leak registry credentials to an attacker-controlled registry",
          "link": "https://github.com/advisories/GHSA-pf56-329r-95rw",
          "published": "2026-07-21",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-21"
    },
    {
      "value": "CVE-2026-64825",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "GitHub Security Advisories"
      ],
      "articles": [
        {
          "id": "art-236",
          "title": "[GHSA / CRITICAL] CVE-2026-64825: Home Assistant Core vulnerable to Path Traversal via backup upload during onboarding",
          "link": "https://github.com/advisories/GHSA-5hxg-r395-fqxx",
          "published": "2026-07-21",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-21"
    },
    {
      "value": "CVE-2026-73653",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "GitHub Security Advisories"
      ],
      "articles": [
        {
          "id": "art-234",
          "title": "[GHSA / CRITICAL] CVE-2026-73653: @vitest/browser: Browser Mode provider commands bypass the file-access permission gate",
          "link": "https://github.com/advisories/GHSA-p63j-vcc4-9vmv",
          "published": "2026-07-21",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-21"
    },
    {
      "value": "159.26.98.241",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "GitHub Security Advisories"
      ],
      "articles": [
        {
          "id": "art-230",
          "title": "[GHSA / CRITICAL] CVE-2026-20896: Gitea Docker image: `REVERSE_PROXY_TRUSTED_PROXIES = *` default lets any source IP impersonate any user via `X-WEBAUTH-USER`",
          "link": "https://github.com/advisories/GHSA-f75j-4cw6-rmx4",
          "published": "2026-07-21",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-21"
    },
    {
      "value": "CVE-2026-59873",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "GitHub Security Advisories"
      ],
      "articles": [
        {
          "id": "art-241",
          "title": "[GHSA / CRITICAL] CVE-2026-59873: node-tar: Decompression/parse DoS via unlimited input",
          "link": "https://github.com/advisories/GHSA-23hp-3jrh-7fpw",
          "published": "2026-07-20",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-20"
    },
    {
      "value": "CVE-2026-61736",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "GitHub Security Advisories"
      ],
      "articles": [
        {
          "id": "art-243",
          "title": "[GHSA / CRITICAL] CVE-2026-61736: LightRAG: CORS Wildcard + Credentials Enables Any-Origin Credentialed Requests",
          "link": "https://github.com/advisories/GHSA-6x6h-qqr7-855w",
          "published": "2026-07-20",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-20"
    },
    {
      "value": "CVE-2026-61740",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "GitHub Security Advisories"
      ],
      "articles": [
        {
          "id": "art-242",
          "title": "[GHSA / CRITICAL] CVE-2026-61740: LightRAG is Vulnerable to Authentication Bypass: hardcoded DEFAULT_TOKEN_SECRET and public /auth-status defeat LIGHTRAG_API_KEY protection",
          "link": "https://github.com/advisories/GHSA-f4vv-55c2-5789",
          "published": "2026-07-20",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-20"
    },
    {
      "value": "git.disroot.org",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "StepSecurity",
        "Aikido"
      ],
      "articles": [
        {
          "id": "art-245",
          "title": "SleeperGem: Compromised git_credential_manager, Dendreo, and fastlane RubyGems Drop a Persistent Backdoor",
          "link": "https://www.stepsecurity.io/blog/sleepergem-compromised-rubygems-drop-persistent-backdoor",
          "published": "2026-07-19",
          "sev": "high"
        },
        {
          "id": "art-246",
          "title": "SleeperGem: RubyGems supply chain attack targets dormant maintainer accounts",
          "link": "https://www.aikido.dev/blog/sleepergem-rubygems-supply-chain-attack",
          "published": "2026-07-19",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-19"
    },
    {
      "value": "CVE-2025-40947",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "Unit 42 (Palo Alto)"
      ],
      "articles": [
        {
          "id": "art-249",
          "title": "Three Steps to the Terminal: A Siemens ROX II Zero-Day Trilogy",
          "link": "https://unit42.paloaltonetworks.com/siemens-rox-ii-zero-day-vulnerabilities/",
          "published": "2026-07-17",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-17"
    },
    {
      "value": "CVE-2025-40948",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "Unit 42 (Palo Alto)"
      ],
      "articles": [
        {
          "id": "art-249",
          "title": "Three Steps to the Terminal: A Siemens ROX II Zero-Day Trilogy",
          "link": "https://unit42.paloaltonetworks.com/siemens-rox-ii-zero-day-vulnerabilities/",
          "published": "2026-07-17",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-17"
    },
    {
      "value": "CVE-2025-40949",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "Unit 42 (Palo Alto)"
      ],
      "articles": [
        {
          "id": "art-249",
          "title": "Three Steps to the Terminal: A Siemens ROX II Zero-Day Trilogy",
          "link": "https://unit42.paloaltonetworks.com/siemens-rox-ii-zero-day-vulnerabilities/",
          "published": "2026-07-17",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-17"
    },
    {
      "value": "CVE-2026-25089",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-261",
          "title": "CISA KEV: CVE-2026-25089 \u2014 Fortinet FortiSandbox OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-07-16",
          "sev": "crit"
        },
        {
          "id": "art-262",
          "title": "CISA KEV: CVE-2026-39808 \u2014 Fortinet FortiSandbox OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-07-16",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-16"
    },
    {
      "value": "CVE-2026-39808",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-262",
          "title": "CISA KEV: CVE-2026-39808 \u2014 Fortinet FortiSandbox OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-07-16",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-16"
    },
    {
      "value": "CVE-2026-39813",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-262",
          "title": "CISA KEV: CVE-2026-39808 \u2014 Fortinet FortiSandbox OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-07-16",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-16"
    },
    {
      "value": "CVE-2026-50661",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "Cisco Talos"
      ],
      "articles": [
        {
          "id": "art-253",
          "title": "Begun, the Patch Wars have",
          "link": "https://blog.talosintelligence.com/begun-the-patch-wars-have/",
          "published": "2026-07-16",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-16"
    },
    {
      "value": "CVE-2026-53713",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "GitHub Security Advisories"
      ],
      "articles": [
        {
          "id": "art-252",
          "title": "[GHSA / CRITICAL] CVE-2026-53713: Envoy Gateway: Authentication Bypass via Improper Input Validation in EnvoyExtensionPolicy Lua Allows Secret Disclosure",
          "link": "https://github.com/advisories/GHSA-wcrf-9vrr-854f",
          "published": "2026-07-16",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-16"
    },
    {
      "value": "CVE-2026-55579",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "GitHub Security Advisories"
      ],
      "articles": [
        {
          "id": "art-251",
          "title": "[GHSA / CRITICAL] CVE-2026-55579: Pheditor: Hardcoded default password 'admin' with no forced change enables full application compromise",
          "link": "https://github.com/advisories/GHSA-p4h7-p9rj-2pq2",
          "published": "2026-07-16",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-16"
    },
    {
      "value": "CVE-2026-56155",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "Cisco Talos",
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-253",
          "title": "Begun, the Patch Wars have",
          "link": "https://blog.talosintelligence.com/begun-the-patch-wars-have/",
          "published": "2026-07-16",
          "sev": "crit"
        },
        {
          "id": "art-279",
          "title": "CISA KEV: CVE-2026-56155 \u2014 Microsoft Active Directory Federation Services Insufficient Granularity of Access Control Vulnerability ",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-07-14",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-16"
    },
    {
      "value": "CVE-2026-56164",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "Cisco Talos",
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-253",
          "title": "Begun, the Patch Wars have",
          "link": "https://blog.talosintelligence.com/begun-the-patch-wars-have/",
          "published": "2026-07-16",
          "sev": "crit"
        },
        {
          "id": "art-280",
          "title": "CISA KEV: CVE-2026-56164 \u2014 Microsoft SharePoint Server Missing Authentication for Critical Function Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-07-14",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-16"
    },
    {
      "value": "CVE-2026-58644",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-260",
          "title": "CISA KEV: CVE-2026-58644 \u2014 Microsoft SharePoint Deserialization of Untrusted Data Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-07-16",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-16"
    },
    {
      "value": "aipythondevs.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "Cisco Talos"
      ],
      "articles": [
        {
          "id": "art-253",
          "title": "Begun, the Patch Wars have",
          "link": "https://blog.talosintelligence.com/begun-the-patch-wars-have/",
          "published": "2026-07-16",
          "sev": "crit"
        },
        {
          "id": "art-256",
          "title": "UAT-11795 deploys novel Starland RAT and bespoke WLDR C2 implant in financially motivated campaign",
          "link": "https://blog.talosintelligence.com/uat-11795-deploys-novel-starland-rat-and-bespoke-wldr-c2-implant-in-financially-motivated-campaign/",
          "published": "2026-07-16",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-16"
    },
    {
      "value": "dht.transmissionbt.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "StepSecurity"
      ],
      "articles": [
        {
          "id": "art-259",
          "title": "Coordinated AsyncAPI Supply Chain Attack: Miasma RAT Delivered via Compromised CI/CD Pipelines in Two Repositories",
          "link": "https://www.stepsecurity.io/blog/compromised-next-branch-pushes-malicious-asyncapi-generator-generator-helpers-and-generator-components-to-npm",
          "published": "2026-07-16",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-16"
    },
    {
      "value": "eorthopaedics.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "Cisco Talos"
      ],
      "articles": [
        {
          "id": "art-253",
          "title": "Begun, the Patch Wars have",
          "link": "https://blog.talosintelligence.com/begun-the-patch-wars-have/",
          "published": "2026-07-16",
          "sev": "crit"
        },
        {
          "id": "art-256",
          "title": "UAT-11795 deploys novel Starland RAT and bespoke WLDR C2 implant in financially motivated campaign",
          "link": "https://blog.talosintelligence.com/uat-11795-deploys-novel-starland-rat-and-bespoke-wldr-c2-implant-in-financially-motivated-campaign/",
          "published": "2026-07-16",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-16"
    },
    {
      "value": "relay.damus.io",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "StepSecurity"
      ],
      "articles": [
        {
          "id": "art-259",
          "title": "Coordinated AsyncAPI Supply Chain Attack: Miasma RAT Delivered via Compromised CI/CD Pipelines in Two Repositories",
          "link": "https://www.stepsecurity.io/blog/compromised-next-branch-pushes-malicious-asyncapi-generator-generator-helpers-and-generator-components-to-npm",
          "published": "2026-07-16",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-16"
    },
    {
      "value": "relay.nostr.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "StepSecurity"
      ],
      "articles": [
        {
          "id": "art-259",
          "title": "Coordinated AsyncAPI Supply Chain Attack: Miasma RAT Delivered via Compromised CI/CD Pipelines in Two Repositories",
          "link": "https://www.stepsecurity.io/blog/compromised-next-branch-pushes-malicious-asyncapi-generator-generator-helpers-and-generator-components-to-npm",
          "published": "2026-07-16",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-16"
    },
    {
      "value": "router.bittorrent.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "StepSecurity"
      ],
      "articles": [
        {
          "id": "art-259",
          "title": "Coordinated AsyncAPI Supply Chain Attack: Miasma RAT Delivered via Compromised CI/CD Pipelines in Two Repositories",
          "link": "https://www.stepsecurity.io/blog/compromised-next-branch-pushes-malicious-asyncapi-generator-generator-helpers-and-generator-components-to-npm",
          "published": "2026-07-16",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-16"
    },
    {
      "value": "sastoro.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "Cisco Talos"
      ],
      "articles": [
        {
          "id": "art-253",
          "title": "Begun, the Patch Wars have",
          "link": "https://blog.talosintelligence.com/begun-the-patch-wars-have/",
          "published": "2026-07-16",
          "sev": "crit"
        },
        {
          "id": "art-256",
          "title": "UAT-11795 deploys novel Starland RAT and bespoke WLDR C2 implant in financially motivated campaign",
          "link": "https://blog.talosintelligence.com/uat-11795-deploys-novel-starland-rat-and-bespoke-wldr-c2-implant-in-financially-motivated-campaign/",
          "published": "2026-07-16",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-16"
    },
    {
      "value": "web-devtools.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "Cisco Talos"
      ],
      "articles": [
        {
          "id": "art-253",
          "title": "Begun, the Patch Wars have",
          "link": "https://blog.talosintelligence.com/begun-the-patch-wars-have/",
          "published": "2026-07-16",
          "sev": "crit"
        },
        {
          "id": "art-256",
          "title": "UAT-11795 deploys novel Starland RAT and bespoke WLDR C2 implant in financially motivated campaign",
          "link": "https://blog.talosintelligence.com/uat-11795-deploys-novel-starland-rat-and-bespoke-wldr-c2-implant-in-financially-motivated-campaign/",
          "published": "2026-07-16",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-16"
    },
    {
      "value": "windowscreenrepairnearme.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "Cisco Talos"
      ],
      "articles": [
        {
          "id": "art-253",
          "title": "Begun, the Patch Wars have",
          "link": "https://blog.talosintelligence.com/begun-the-patch-wars-have/",
          "published": "2026-07-16",
          "sev": "crit"
        },
        {
          "id": "art-256",
          "title": "UAT-11795 deploys novel Starland RAT and bespoke WLDR C2 implant in financially motivated campaign",
          "link": "https://blog.talosintelligence.com/uat-11795-deploys-novel-starland-rat-and-bespoke-wldr-c2-implant-in-financially-motivated-campaign/",
          "published": "2026-07-16",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-16"
    },
    {
      "value": "zynaris.io",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "Cisco Talos"
      ],
      "articles": [
        {
          "id": "art-253",
          "title": "Begun, the Patch Wars have",
          "link": "https://blog.talosintelligence.com/begun-the-patch-wars-have/",
          "published": "2026-07-16",
          "sev": "crit"
        },
        {
          "id": "art-256",
          "title": "UAT-11795 deploys novel Starland RAT and bespoke WLDR C2 implant in financially motivated campaign",
          "link": "https://blog.talosintelligence.com/uat-11795-deploys-novel-starland-rat-and-bespoke-wldr-c2-implant-in-financially-motivated-campaign/",
          "published": "2026-07-16",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-16"
    },
    {
      "value": "85.137.53.71",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "StepSecurity",
        "Aikido"
      ],
      "articles": [
        {
          "id": "art-259",
          "title": "Coordinated AsyncAPI Supply Chain Attack: Miasma RAT Delivered via Compromised CI/CD Pipelines in Two Repositories",
          "link": "https://www.stepsecurity.io/blog/compromised-next-branch-pushes-malicious-asyncapi-generator-generator-helpers-and-generator-components-to-npm",
          "published": "2026-07-16",
          "sev": "crit"
        },
        {
          "id": "art-276",
          "title": "AsyncAPI npm packages backdoored via GitHub Actions",
          "link": "https://www.aikido.dev/blog/asyncapi-npm-packages-backdoored-via-github-actions",
          "published": "2026-07-14",
          "sev": "high"
        }
      ],
      "first_seen": "2026-07-16"
    },
    {
      "value": "0398df5a18f71efcfeef4571a2cef577",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "Cisco Talos"
      ],
      "articles": [
        {
          "id": "art-253",
          "title": "Begun, the Patch Wars have",
          "link": "https://blog.talosintelligence.com/begun-the-patch-wars-have/",
          "published": "2026-07-16",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-16"
    },
    {
      "value": "24b9ee242f21a73b55f7bb3297eafb33c60840907386b542ed79fc6b72365168",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "StepSecurity"
      ],
      "articles": [
        {
          "id": "art-259",
          "title": "Coordinated AsyncAPI Supply Chain Attack: Miasma RAT Delivered via Compromised CI/CD Pipelines in Two Repositories",
          "link": "https://www.stepsecurity.io/blog/compromised-next-branch-pushes-malicious-asyncapi-generator-generator-helpers-and-generator-components-to-npm",
          "published": "2026-07-16",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-16"
    },
    {
      "value": "6e78713b75bd34828d49896176627f7face7aa9036cd874f2e02d9f23a9a9c71",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "StepSecurity"
      ],
      "articles": [
        {
          "id": "art-259",
          "title": "Coordinated AsyncAPI Supply Chain Attack: Miasma RAT Delivered via Compromised CI/CD Pipelines in Two Repositories",
          "link": "https://www.stepsecurity.io/blog/compromised-next-branch-pushes-malicious-asyncapi-generator-generator-helpers-and-generator-components-to-npm",
          "published": "2026-07-16",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-16"
    },
    {
      "value": "b270bdf8e2274ea1af0a6eed74d8f10e5fe61012d6cc226a43cc7cc7fd9f6292",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "StepSecurity"
      ],
      "articles": [
        {
          "id": "art-259",
          "title": "Coordinated AsyncAPI Supply Chain Attack: Miasma RAT Delivered via Compromised CI/CD Pipelines in Two Repositories",
          "link": "https://www.stepsecurity.io/blog/compromised-next-branch-pushes-malicious-asyncapi-generator-generator-helpers-and-generator-components-to-npm",
          "published": "2026-07-16",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-16"
    },
    {
      "value": "b8be9a5e0a191050f9099c11c155b436863e9bc43bc904cdb842e249679aa35a",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "Cisco Talos"
      ],
      "articles": [
        {
          "id": "art-253",
          "title": "Begun, the Patch Wars have",
          "link": "https://blog.talosintelligence.com/begun-the-patch-wars-have/",
          "published": "2026-07-16",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-16"
    },
    {
      "value": "byte-io.us",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "StepSecurity"
      ],
      "articles": [
        {
          "id": "art-257",
          "title": "Runtime Security for Third-Party GitHub Actions Runners: Bitrise, Blacksmith, Depot, Namespace, and Warp",
          "link": "https://www.stepsecurity.io/blog/runtime-security-for-third-party-github-actions-runners",
          "published": "2026-07-16",
          "sev": "high"
        }
      ],
      "first_seen": "2026-07-16"
    },
    {
      "value": "cloud-sync.online",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "StepSecurity"
      ],
      "articles": [
        {
          "id": "art-257",
          "title": "Runtime Security for Third-Party GitHub Actions Runners: Bitrise, Blacksmith, Depot, Namespace, and Warp",
          "link": "https://www.stepsecurity.io/blog/runtime-security-for-third-party-github-actions-runners",
          "published": "2026-07-16",
          "sev": "high"
        }
      ],
      "first_seen": "2026-07-16"
    },
    {
      "value": "datahub.ink",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "StepSecurity"
      ],
      "articles": [
        {
          "id": "art-257",
          "title": "Runtime Security for Third-Party GitHub Actions Runners: Bitrise, Blacksmith, Depot, Namespace, and Warp",
          "link": "https://www.stepsecurity.io/blog/runtime-security-for-third-party-github-actions-runners",
          "published": "2026-07-16",
          "sev": "high"
        }
      ],
      "first_seen": "2026-07-16"
    },
    {
      "value": "208.115.220.17",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "StepSecurity"
      ],
      "articles": [
        {
          "id": "art-257",
          "title": "Runtime Security for Third-Party GitHub Actions Runners: Bitrise, Blacksmith, Depot, Namespace, and Warp",
          "link": "https://www.stepsecurity.io/blog/runtime-security-for-third-party-github-actions-runners",
          "published": "2026-07-16",
          "sev": "high"
        }
      ],
      "first_seen": "2026-07-16"
    },
    {
      "value": "89.36.224.5",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "StepSecurity"
      ],
      "articles": [
        {
          "id": "art-257",
          "title": "Runtime Security for Third-Party GitHub Actions Runners: Bitrise, Blacksmith, Depot, Namespace, and Warp",
          "link": "https://www.stepsecurity.io/blog/runtime-security-for-third-party-github-actions-runners",
          "published": "2026-07-16",
          "sev": "high"
        },
        {
          "id": "art-258",
          "title": "Harden-Runner Block Mode Now Available for macOS and Windows GitHub-Hosted Runners",
          "link": "https://www.stepsecurity.io/blog/harden-runner-block-mode-now-available-for-macos-and-windows-github-hosted-runners",
          "published": "2026-07-16",
          "sev": "high"
        },
        {
          "id": "art-566",
          "title": "@velora-dex/sdk Compromised on npm: Malicious Version Drops macOS Backdoor via launchctl Persistence",
          "link": "https://www.stepsecurity.io/blog/velora-dex-sdk-compromised-on-npm-malicious-version-drops-macos-backdoor-via-launchctl-persistence",
          "published": "2026-04-09",
          "sev": "high"
        }
      ],
      "first_seen": "2026-07-16"
    },
    {
      "value": "0a8ab3d16b12d3a453ee5a3208fe04744ad54514ef8ea27bb8fe32679efad270",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "StepSecurity"
      ],
      "articles": [
        {
          "id": "art-257",
          "title": "Runtime Security for Third-Party GitHub Actions Runners: Bitrise, Blacksmith, Depot, Namespace, and Warp",
          "link": "https://www.stepsecurity.io/blog/runtime-security-for-third-party-github-actions-runners",
          "published": "2026-07-16",
          "sev": "high"
        }
      ],
      "first_seen": "2026-07-16"
    },
    {
      "value": "0b028b781950641818800fee2b4bf68e4ef2bcee53fe71a21755275ba108783d",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "StepSecurity"
      ],
      "articles": [
        {
          "id": "art-257",
          "title": "Runtime Security for Third-Party GitHub Actions Runners: Bitrise, Blacksmith, Depot, Namespace, and Warp",
          "link": "https://www.stepsecurity.io/blog/runtime-security-for-third-party-github-actions-runners",
          "published": "2026-07-16",
          "sev": "high"
        }
      ],
      "first_seen": "2026-07-16"
    },
    {
      "value": "CVE-2023-4346",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-269",
          "title": "CISA KEV: CVE-2023-4346 \u2014 KNX Association KNX Protocol Connection Authorization Option 1 Overly Restrictive Account Lockout Mechanism Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-07-15",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-15"
    },
    {
      "value": "CVE-2026-46817",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-268",
          "title": "CISA KEV: CVE-2026-46817 \u2014 Oracle E-Business Suite Improper Privilege Management Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-07-15",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-15"
    },
    {
      "value": "CVE-2026-47156",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "GitHub Security Advisories"
      ],
      "articles": [
        {
          "id": "art-266",
          "title": "[GHSA / CRITICAL] CVE-2026-47156: MantisBT: SOAP API Authentication Bypass with Privilege Escalation to Administrator",
          "link": "https://github.com/advisories/GHSA-c2xg-qjqw-2v98",
          "published": "2026-07-15",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-15"
    },
    {
      "value": "CVE-2026-52847",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "GitHub Security Advisories"
      ],
      "articles": [
        {
          "id": "art-265",
          "title": "[GHSA / CRITICAL] CVE-2026-52881: MantisBT: Reflected XSS in admin/install.php via unescaped printf",
          "link": "https://github.com/advisories/GHSA-vcrw-4xvv-jh49",
          "published": "2026-07-15",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-15"
    },
    {
      "value": "CVE-2026-52881",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "GitHub Security Advisories"
      ],
      "articles": [
        {
          "id": "art-265",
          "title": "[GHSA / CRITICAL] CVE-2026-52881: MantisBT: Reflected XSS in admin/install.php via unescaped printf",
          "link": "https://github.com/advisories/GHSA-vcrw-4xvv-jh49",
          "published": "2026-07-15",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-15"
    },
    {
      "value": "digikalas.online",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "Unit 42 (Palo Alto)"
      ],
      "articles": [
        {
          "id": "art-267",
          "title": "TuxBot v3: Inside an IoT Botnet Framework With LLM-Assisted Development",
          "link": "https://unit42.paloaltonetworks.com/tuxbot-v3-evolution-iot-botnet/",
          "published": "2026-07-15",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-15"
    },
    {
      "value": "newtuxdev.sevielw.digikalas.online",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "Unit 42 (Palo Alto)"
      ],
      "articles": [
        {
          "id": "art-267",
          "title": "TuxBot v3: Inside an IoT Botnet Framework With LLM-Assisted Development",
          "link": "https://unit42.paloaltonetworks.com/tuxbot-v3-evolution-iot-botnet/",
          "published": "2026-07-15",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-15"
    },
    {
      "value": "185.10.68.127",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "Unit 42 (Palo Alto)"
      ],
      "articles": [
        {
          "id": "art-267",
          "title": "TuxBot v3: Inside an IoT Botnet Framework With LLM-Assisted Development",
          "link": "https://unit42.paloaltonetworks.com/tuxbot-v3-evolution-iot-botnet/",
          "published": "2026-07-15",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-15"
    },
    {
      "value": "209.182.237.133",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "Unit 42 (Palo Alto)"
      ],
      "articles": [
        {
          "id": "art-267",
          "title": "TuxBot v3: Inside an IoT Botnet Framework With LLM-Assisted Development",
          "link": "https://unit42.paloaltonetworks.com/tuxbot-v3-evolution-iot-botnet/",
          "published": "2026-07-15",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-15"
    },
    {
      "value": "71dfbb171eca4ef9d02ff630b56e5283bbef7b375d4dbe9e8c9531bef312fa8d",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "Unit 42 (Palo Alto)"
      ],
      "articles": [
        {
          "id": "art-267",
          "title": "TuxBot v3: Inside an IoT Botnet Framework With LLM-Assisted Development",
          "link": "https://unit42.paloaltonetworks.com/tuxbot-v3-evolution-iot-botnet/",
          "published": "2026-07-15",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-15"
    },
    {
      "value": "CVE-2026-15409",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-281",
          "title": "CISA KEV: CVE-2026-15409 \u2014 SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-07-14",
          "sev": "crit"
        },
        {
          "id": "art-282",
          "title": "CISA KEV: CVE-2026-15410 \u2014 SonicWall SMA1000 Appliances Code Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-07-14",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-14"
    },
    {
      "value": "CVE-2026-15410",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-281",
          "title": "CISA KEV: CVE-2026-15409 \u2014 SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-07-14",
          "sev": "crit"
        },
        {
          "id": "art-282",
          "title": "CISA KEV: CVE-2026-15410 \u2014 SonicWall SMA1000 Appliances Code Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-07-14",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-14"
    },
    {
      "value": "CVE-2026-45262",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "GitHub Security Advisories"
      ],
      "articles": [
        {
          "id": "art-274",
          "title": "[GHSA / CRITICAL] CVE-2026-45262: FacturaScripts: Authenticated SQL injection in the FacturaScripts REST API filter parameter via parenthesis bypass in `Where::sqlColumn`",
          "link": "https://github.com/advisories/GHSA-5qmh-x653-g8qj",
          "published": "2026-07-14",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-14"
    },
    {
      "value": "CVE-2026-50006",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "GitHub Security Advisories"
      ],
      "articles": [
        {
          "id": "art-273",
          "title": "[GHSA / CRITICAL] CVE-2026-50006: Anyquery: Arbitrary File Write (AFW) which could lead to Remote Code Execution (RCE) via Unrestricted ATTACH DATABASE in Server Mode",
          "link": "https://github.com/advisories/GHSA-xrcf-6jh3-ggvx",
          "published": "2026-07-14",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-14"
    },
    {
      "value": "CVE-2026-52824",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "GitHub Security Advisories"
      ],
      "articles": [
        {
          "id": "art-278",
          "title": "[GHSA / CRITICAL] CVE-2026-52824: Kimai: Default APP_SECRET in Docker Image Enables Cookie Forgery and Account Takeover",
          "link": "https://github.com/advisories/GHSA-jr9p-4h4j-6c58",
          "published": "2026-07-14",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-14"
    },
    {
      "value": "CVE-2026-54052",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "GitHub Security Advisories"
      ],
      "articles": [
        {
          "id": "art-272",
          "title": "[GHSA / CRITICAL] CVE-2026-54052: n8n-MCP: Cross-tenant access to workflow version backups in multi-tenant HTTP deployments",
          "link": "https://github.com/advisories/GHSA-j6r7-6fhx-77wx",
          "published": "2026-07-14",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-14"
    },
    {
      "value": "193.37.32.179",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-281",
          "title": "CISA KEV: CVE-2026-15409 \u2014 SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-07-14",
          "sev": "crit"
        },
        {
          "id": "art-282",
          "title": "CISA KEV: CVE-2026-15410 \u2014 SonicWall SMA1000 Appliances Code Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-07-14",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-14"
    },
    {
      "value": "193.37.32.214",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-281",
          "title": "CISA KEV: CVE-2026-15409 \u2014 SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-07-14",
          "sev": "crit"
        },
        {
          "id": "art-282",
          "title": "CISA KEV: CVE-2026-15410 \u2014 SonicWall SMA1000 Appliances Code Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-07-14",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-14"
    },
    {
      "value": "216.73.163.151",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-281",
          "title": "CISA KEV: CVE-2026-15409 \u2014 SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-07-14",
          "sev": "crit"
        },
        {
          "id": "art-282",
          "title": "CISA KEV: CVE-2026-15410 \u2014 SonicWall SMA1000 Appliances Code Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-07-14",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-14"
    },
    {
      "value": "216.73.163.158",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-281",
          "title": "CISA KEV: CVE-2026-15409 \u2014 SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-07-14",
          "sev": "crit"
        },
        {
          "id": "art-282",
          "title": "CISA KEV: CVE-2026-15410 \u2014 SonicWall SMA1000 Appliances Code Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-07-14",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-14"
    },
    {
      "value": "ipfs.io",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "Aikido"
      ],
      "articles": [
        {
          "id": "art-276",
          "title": "AsyncAPI npm packages backdoored via GitHub Actions",
          "link": "https://www.aikido.dev/blog/asyncapi-npm-packages-backdoored-via-github-actions",
          "published": "2026-07-14",
          "sev": "high"
        }
      ],
      "first_seen": "2026-07-14"
    },
    {
      "value": "22bf76fe317ea6769bd38619bd440e42d119bd6b",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "Aikido"
      ],
      "articles": [
        {
          "id": "art-276",
          "title": "AsyncAPI npm packages backdoored via GitHub Actions",
          "link": "https://www.aikido.dev/blog/asyncapi-npm-packages-backdoored-via-github-actions",
          "published": "2026-07-14",
          "sev": "high"
        }
      ],
      "first_seen": "2026-07-14"
    },
    {
      "value": "9890950adcbc2478e7a080234f053214adbad44e",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "Aikido"
      ],
      "articles": [
        {
          "id": "art-276",
          "title": "AsyncAPI npm packages backdoored via GitHub Actions",
          "link": "https://www.aikido.dev/blog/asyncapi-npm-packages-backdoored-via-github-actions",
          "published": "2026-07-14",
          "sev": "high"
        }
      ],
      "first_seen": "2026-07-14"
    },
    {
      "value": "a7e18d96efd3cdb127ef4cdcad9e3ad26c482bf2",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "Aikido"
      ],
      "articles": [
        {
          "id": "art-276",
          "title": "AsyncAPI npm packages backdoored via GitHub Actions",
          "link": "https://www.aikido.dev/blog/asyncapi-npm-packages-backdoored-via-github-actions",
          "published": "2026-07-14",
          "sev": "high"
        }
      ],
      "first_seen": "2026-07-14"
    },
    {
      "value": "c70e105e212ff3c1daa04bb2a62507717f296b0b",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "Aikido"
      ],
      "articles": [
        {
          "id": "art-276",
          "title": "AsyncAPI npm packages backdoored via GitHub Actions",
          "link": "https://www.aikido.dev/blog/asyncapi-npm-packages-backdoored-via-github-actions",
          "published": "2026-07-14",
          "sev": "high"
        }
      ],
      "first_seen": "2026-07-14"
    },
    {
      "value": "c8cb3f6d5b90c46686d2bf531dc1a5786e27edc5",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "Aikido"
      ],
      "articles": [
        {
          "id": "art-276",
          "title": "AsyncAPI npm packages backdoored via GitHub Actions",
          "link": "https://www.aikido.dev/blog/asyncapi-npm-packages-backdoored-via-github-actions",
          "published": "2026-07-14",
          "sev": "high"
        }
      ],
      "first_seen": "2026-07-14"
    },
    {
      "value": "082d733db0687dcd768104972b065d4b58cb1e6043688c6c20fa3702337f36ab",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "Aikido"
      ],
      "articles": [
        {
          "id": "art-276",
          "title": "AsyncAPI npm packages backdoored via GitHub Actions",
          "link": "https://www.aikido.dev/blog/asyncapi-npm-packages-backdoored-via-github-actions",
          "published": "2026-07-14",
          "sev": "high"
        }
      ],
      "first_seen": "2026-07-14"
    },
    {
      "value": "34014776d3d3ff11bc4439b02fd7ac0f02a887eb3a052eeaffd236e2f6db8ad1",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "Aikido"
      ],
      "articles": [
        {
          "id": "art-276",
          "title": "AsyncAPI npm packages backdoored via GitHub Actions",
          "link": "https://www.aikido.dev/blog/asyncapi-npm-packages-backdoored-via-github-actions",
          "published": "2026-07-14",
          "sev": "high"
        }
      ],
      "first_seen": "2026-07-14"
    },
    {
      "value": "9b2e65db653ca8575c9b10eefb9a80c6006404812c2ec212bf5675e3c690233b",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "Aikido"
      ],
      "articles": [
        {
          "id": "art-276",
          "title": "AsyncAPI npm packages backdoored via GitHub Actions",
          "link": "https://www.aikido.dev/blog/asyncapi-npm-packages-backdoored-via-github-actions",
          "published": "2026-07-14",
          "sev": "high"
        }
      ],
      "first_seen": "2026-07-14"
    },
    {
      "value": "9e214f38537e69bf51c7fa1ddd35ae495e9cb897231ec010baf9e4f29407ee9a",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "Aikido"
      ],
      "articles": [
        {
          "id": "art-276",
          "title": "AsyncAPI npm packages backdoored via GitHub Actions",
          "link": "https://www.aikido.dev/blog/asyncapi-npm-packages-backdoored-via-github-actions",
          "published": "2026-07-14",
          "sev": "high"
        }
      ],
      "first_seen": "2026-07-14"
    },
    {
      "value": "bfaeb987faa6de2b5a5eb63b1233d055215b09b0349a9394f2175fd7cdf385e4",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "Aikido"
      ],
      "articles": [
        {
          "id": "art-276",
          "title": "AsyncAPI npm packages backdoored via GitHub Actions",
          "link": "https://www.aikido.dev/blog/asyncapi-npm-packages-backdoored-via-github-actions",
          "published": "2026-07-14",
          "sev": "high"
        }
      ],
      "first_seen": "2026-07-14"
    },
    {
      "value": "f873941d1907a97dc6c718fdecf59fd7d91f3f8212da2f7e5314b878b88bdc0b",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "Aikido"
      ],
      "articles": [
        {
          "id": "art-276",
          "title": "AsyncAPI npm packages backdoored via GitHub Actions",
          "link": "https://www.aikido.dev/blog/asyncapi-npm-packages-backdoored-via-github-actions",
          "published": "2026-07-14",
          "sev": "high"
        }
      ],
      "first_seen": "2026-07-14"
    },
    {
      "value": "CVE-2026-10797",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "med",
      "sources": [
        "ESET WeLiveSecurity"
      ],
      "articles": [
        {
          "id": "art-277",
          "title": "Forgotten UEFI shims undermining Secure Boot",
          "link": "https://www.welivesecurity.com/en/eset-research/forgotten-uefi-shims-undermining-secure-boot/",
          "published": "2026-07-14",
          "sev": "med"
        }
      ],
      "first_seen": "2026-07-14"
    },
    {
      "value": "CVE-2026-8863",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "med",
      "sources": [
        "ESET WeLiveSecurity"
      ],
      "articles": [
        {
          "id": "art-277",
          "title": "Forgotten UEFI shims undermining Secure Boot",
          "link": "https://www.welivesecurity.com/en/eset-research/forgotten-uefi-shims-undermining-secure-boot/",
          "published": "2026-07-14",
          "sev": "med"
        }
      ],
      "first_seen": "2026-07-14"
    },
    {
      "value": "236A9CB0D71951C36398A32EB660CE2CD4A52CCFA7CF751CC6A35D9DE549E19B",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "med",
      "sources": [
        "ESET WeLiveSecurity"
      ],
      "articles": [
        {
          "id": "art-277",
          "title": "Forgotten UEFI shims undermining Secure Boot",
          "link": "https://www.welivesecurity.com/en/eset-research/forgotten-uefi-shims-undermining-secure-boot/",
          "published": "2026-07-14",
          "sev": "med"
        }
      ],
      "first_seen": "2026-07-14"
    },
    {
      "value": "410260B1B6F5AF5FBEEB9EA3220658435E876CB3247126EE907A437F312DB373",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "med",
      "sources": [
        "ESET WeLiveSecurity"
      ],
      "articles": [
        {
          "id": "art-277",
          "title": "Forgotten UEFI shims undermining Secure Boot",
          "link": "https://www.welivesecurity.com/en/eset-research/forgotten-uefi-shims-undermining-secure-boot/",
          "published": "2026-07-14",
          "sev": "med"
        }
      ],
      "first_seen": "2026-07-14"
    },
    {
      "value": "5E594C448760A3135B1A3A83E07A4F2E6FBE49414EF2C7CAB1CBA77F284FA63B",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "med",
      "sources": [
        "ESET WeLiveSecurity"
      ],
      "articles": [
        {
          "id": "art-277",
          "title": "Forgotten UEFI shims undermining Secure Boot",
          "link": "https://www.welivesecurity.com/en/eset-research/forgotten-uefi-shims-undermining-secure-boot/",
          "published": "2026-07-14",
          "sev": "med"
        }
      ],
      "first_seen": "2026-07-14"
    },
    {
      "value": "7B2A3F5C96F95BD8086CE54B0825E300F9C8F11FE3401BB631B3215C8DE9EB10",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "med",
      "sources": [
        "ESET WeLiveSecurity"
      ],
      "articles": [
        {
          "id": "art-277",
          "title": "Forgotten UEFI shims undermining Secure Boot",
          "link": "https://www.welivesecurity.com/en/eset-research/forgotten-uefi-shims-undermining-secure-boot/",
          "published": "2026-07-14",
          "sev": "med"
        }
      ],
      "first_seen": "2026-07-14"
    },
    {
      "value": "8A964D5F8373948D20A1D4296FB92E545DAD4617A0C810F3B934B53D98AE8963",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "med",
      "sources": [
        "ESET WeLiveSecurity"
      ],
      "articles": [
        {
          "id": "art-277",
          "title": "Forgotten UEFI shims undermining Secure Boot",
          "link": "https://www.welivesecurity.com/en/eset-research/forgotten-uefi-shims-undermining-secure-boot/",
          "published": "2026-07-14",
          "sev": "med"
        }
      ],
      "first_seen": "2026-07-14"
    },
    {
      "value": "95B6D71FC0C0F8C5E1533A37AEF92CF6B0C961E2CC612A97117FA6759CE5FC06",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "med",
      "sources": [
        "ESET WeLiveSecurity"
      ],
      "articles": [
        {
          "id": "art-277",
          "title": "Forgotten UEFI shims undermining Secure Boot",
          "link": "https://www.welivesecurity.com/en/eset-research/forgotten-uefi-shims-undermining-secure-boot/",
          "published": "2026-07-14",
          "sev": "med"
        }
      ],
      "first_seen": "2026-07-14"
    },
    {
      "value": "96275DFD6282A522B011177EE049296952AC794832091F937FBBF92869028629",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "med",
      "sources": [
        "ESET WeLiveSecurity"
      ],
      "articles": [
        {
          "id": "art-277",
          "title": "Forgotten UEFI shims undermining Secure Boot",
          "link": "https://www.welivesecurity.com/en/eset-research/forgotten-uefi-shims-undermining-secure-boot/",
          "published": "2026-07-14",
          "sev": "med"
        }
      ],
      "first_seen": "2026-07-14"
    },
    {
      "value": "A0DE9333442C1BF9349A460141AE5E80F911955C6506040FA3D021BF6C1AE3E4",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "med",
      "sources": [
        "ESET WeLiveSecurity"
      ],
      "articles": [
        {
          "id": "art-277",
          "title": "Forgotten UEFI shims undermining Secure Boot",
          "link": "https://www.welivesecurity.com/en/eset-research/forgotten-uefi-shims-undermining-secure-boot/",
          "published": "2026-07-14",
          "sev": "med"
        }
      ],
      "first_seen": "2026-07-14"
    },
    {
      "value": "AE75F0D82BA3DF824FBFC69340CC3B4D66C598373B1AB54CDB6C8BFD83A6B961",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "med",
      "sources": [
        "ESET WeLiveSecurity"
      ],
      "articles": [
        {
          "id": "art-277",
          "title": "Forgotten UEFI shims undermining Secure Boot",
          "link": "https://www.welivesecurity.com/en/eset-research/forgotten-uefi-shims-undermining-secure-boot/",
          "published": "2026-07-14",
          "sev": "med"
        }
      ],
      "first_seen": "2026-07-14"
    },
    {
      "value": "EB86FA1386FE6E4533B8B938DCC1250616D2F1C14C15E2FCF80834A161018A0A",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "med",
      "sources": [
        "ESET WeLiveSecurity"
      ],
      "articles": [
        {
          "id": "art-277",
          "title": "Forgotten UEFI shims undermining Secure Boot",
          "link": "https://www.welivesecurity.com/en/eset-research/forgotten-uefi-shims-undermining-secure-boot/",
          "published": "2026-07-14",
          "sev": "med"
        }
      ],
      "first_seen": "2026-07-14"
    },
    {
      "value": "FD23D6E57DE6F4E1F9D7118DA1C5F31A8AF6BE5E5D9E8170F9493447268D50C5",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "med",
      "sources": [
        "ESET WeLiveSecurity"
      ],
      "articles": [
        {
          "id": "art-277",
          "title": "Forgotten UEFI shims undermining Secure Boot",
          "link": "https://www.welivesecurity.com/en/eset-research/forgotten-uefi-shims-undermining-secure-boot/",
          "published": "2026-07-14",
          "sev": "med"
        }
      ],
      "first_seen": "2026-07-14"
    },
    {
      "value": "CVE-2008-4128",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-289",
          "title": "CISA KEV: CVE-2008-4128 \u2014 Cisco IOS Cross-Site Request Forgery Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-07-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-13"
    },
    {
      "value": "CVE-2026-45579",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "GitHub Security Advisories"
      ],
      "articles": [
        {
          "id": "art-286",
          "title": "[GHSA / CRITICAL] CVE-2026-45579: DIRAC is vulnerable to RCE in RequestManager due to eval on untrusted input",
          "link": "https://github.com/advisories/GHSA-9jpv-c7p4-997x",
          "published": "2026-07-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-13"
    },
    {
      "value": "CVE-2026-47677",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "GitHub Security Advisories"
      ],
      "articles": [
        {
          "id": "art-283",
          "title": "[GHSA / CRITICAL] CVE-2026-47677: FacturaScripts: Account takeover of any 2FA-enabled user",
          "link": "https://github.com/advisories/GHSA-c67f-gmxw-mj93",
          "published": "2026-07-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-13"
    },
    {
      "value": "CVE-2026-61667",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "GitHub Security Advisories"
      ],
      "articles": [
        {
          "id": "art-285",
          "title": "[GHSA / CRITICAL] CVE-2026-61667: DIRAC is vulnerable to RCE in FileCatalog DatasetManager via SQL injection + eval",
          "link": "https://github.com/advisories/GHSA-m4m7-4cw8-62j6",
          "published": "2026-07-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-13"
    },
    {
      "value": "giftshop.club",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "Aikido",
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-287",
          "title": "What is a dependency firewall?",
          "link": "https://www.aikido.dev/blog/what-is-a-dependency-firewall",
          "published": "2026-07-13",
          "sev": "crit"
        },
        {
          "id": "art-390",
          "title": "Code is being written everywhere, and the device is the only constant",
          "link": "https://www.aikido.dev/blog/code-is-written-everywhere",
          "published": "2026-06-10",
          "sev": "high"
        },
        {
          "id": "art-432",
          "title": "What MDM can't protect on developer machines (and what to do about it)",
          "link": "https://www.aikido.dev/blog/what-mdm-cant-protect",
          "published": "2026-05-28",
          "sev": "high"
        },
        {
          "id": "art-867",
          "title": "Malicious MCP Server on npm postmark-mcp Harvests Emails",
          "link": "https://snyk.io/blog/malicious-mcp-server-on-npm-postmark-mcp-harvests-emails/",
          "published": "2025-09-25",
          "sev": "high"
        }
      ],
      "first_seen": "2026-07-13"
    },
    {
      "value": "webhook.site",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "Aikido",
        "StepSecurity",
        "Snyk",
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-284",
          "title": "How Aikido Intel detects malware and vulnerabilities first",
          "link": "https://www.aikido.dev/blog/aikido-intel-detects-malware-vulnerabilities-first",
          "published": "2026-07-13",
          "sev": "high"
        },
        {
          "id": "art-385",
          "title": "npm v12 delivers one of the biggest security improvements in years",
          "link": "https://www.aikido.dev/blog/npm-v12-block-postinstall",
          "published": "2026-06-11",
          "sev": "high"
        },
        {
          "id": "art-627",
          "title": "kubernetes-el Compromised: How a Pwn Request Exploited a Popular Emacs Package",
          "link": "https://www.stepsecurity.io/blog/kubernetes-el-compromised-how-a-pwn-request-exploited-a-popular-emacs-package",
          "published": "2026-03-11",
          "sev": "high"
        },
        {
          "id": "art-796",
          "title": "SHA1-Hulud, npm supply chain incident",
          "link": "https://snyk.io/blog/sha1-hulud-npm-supply-chain-incident/",
          "published": "2025-11-24",
          "sev": "high"
        },
        {
          "id": "art-875",
          "title": "Zero-day Extensive NPM Package Compromise - Shai Hulud Supply Chain Attack",
          "link": "https://snyk.io/blog/embedded-malicious-code-in-tinycolor-and-ngx-bootstrap-releases-on-npm/",
          "published": "2025-09-15",
          "sev": "high"
        },
        {
          "id": "art-927",
          "title": "CISA KEV: CVE-2025-47812 \u2014 Wing FTP Server Improper Neutralization of Null Byte or NUL Character Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-07-14",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-13"
    },
    {
      "value": "46faab8ab153fae6e80e7cca38eab363075bb524edd79e42269217a083628f09",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "Aikido",
        "StepSecurity",
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-284",
          "title": "How Aikido Intel detects malware and vulnerabilities first",
          "link": "https://www.aikido.dev/blog/aikido-intel-detects-malware-vulnerabilities-first",
          "published": "2026-07-13",
          "sev": "high"
        },
        {
          "id": "art-385",
          "title": "npm v12 delivers one of the biggest security improvements in years",
          "link": "https://www.aikido.dev/blog/npm-v12-block-postinstall",
          "published": "2026-06-11",
          "sev": "high"
        },
        {
          "id": "art-562",
          "title": "Securing Vibe Coding and AI Coding Agents: An End-to-End Approach with StepSecurity",
          "link": "https://www.stepsecurity.io/blog/securing-vibe-coding-and-ai-coding-agents-an-end-to-end-approach-with-stepsecurity",
          "published": "2026-04-12",
          "sev": "high"
        },
        {
          "id": "art-796",
          "title": "SHA1-Hulud, npm supply chain incident",
          "link": "https://snyk.io/blog/sha1-hulud-npm-supply-chain-incident/",
          "published": "2025-11-24",
          "sev": "high"
        },
        {
          "id": "art-875",
          "title": "Zero-day Extensive NPM Package Compromise - Shai Hulud Supply Chain Attack",
          "link": "https://snyk.io/blog/embedded-malicious-code-in-tinycolor-and-ngx-bootstrap-releases-on-npm/",
          "published": "2025-09-15",
          "sev": "high"
        }
      ],
      "first_seen": "2026-07-13"
    },
    {
      "value": "62ee164b9b306250c1172583f138c9614139264f889fa99614903c12755468d0",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "Aikido",
        "StepSecurity",
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-284",
          "title": "How Aikido Intel detects malware and vulnerabilities first",
          "link": "https://www.aikido.dev/blog/aikido-intel-detects-malware-vulnerabilities-first",
          "published": "2026-07-13",
          "sev": "high"
        },
        {
          "id": "art-385",
          "title": "npm v12 delivers one of the biggest security improvements in years",
          "link": "https://www.aikido.dev/blog/npm-v12-block-postinstall",
          "published": "2026-06-11",
          "sev": "high"
        },
        {
          "id": "art-562",
          "title": "Securing Vibe Coding and AI Coding Agents: An End-to-End Approach with StepSecurity",
          "link": "https://www.stepsecurity.io/blog/securing-vibe-coding-and-ai-coding-agents-an-end-to-end-approach-with-stepsecurity",
          "published": "2026-04-12",
          "sev": "high"
        },
        {
          "id": "art-796",
          "title": "SHA1-Hulud, npm supply chain incident",
          "link": "https://snyk.io/blog/sha1-hulud-npm-supply-chain-incident/",
          "published": "2025-11-24",
          "sev": "high"
        }
      ],
      "first_seen": "2026-07-13"
    },
    {
      "value": "a3894003ad1d293ba96d77881ccd2071446dc3f65f434669b49b3da92421901a",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "Aikido",
        "StepSecurity",
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-284",
          "title": "How Aikido Intel detects malware and vulnerabilities first",
          "link": "https://www.aikido.dev/blog/aikido-intel-detects-malware-vulnerabilities-first",
          "published": "2026-07-13",
          "sev": "high"
        },
        {
          "id": "art-385",
          "title": "npm v12 delivers one of the biggest security improvements in years",
          "link": "https://www.aikido.dev/blog/npm-v12-block-postinstall",
          "published": "2026-06-11",
          "sev": "high"
        },
        {
          "id": "art-562",
          "title": "Securing Vibe Coding and AI Coding Agents: An End-to-End Approach with StepSecurity",
          "link": "https://www.stepsecurity.io/blog/securing-vibe-coding-and-ai-coding-agents-an-end-to-end-approach-with-stepsecurity",
          "published": "2026-04-12",
          "sev": "high"
        },
        {
          "id": "art-796",
          "title": "SHA1-Hulud, npm supply chain incident",
          "link": "https://snyk.io/blog/sha1-hulud-npm-supply-chain-incident/",
          "published": "2025-11-24",
          "sev": "high"
        }
      ],
      "first_seen": "2026-07-13"
    },
    {
      "value": "cbb9bc5a8496243e02f3cc080efbe3e4a1430ba0671f2e43a202bf45b05479cd",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "Aikido",
        "StepSecurity",
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-284",
          "title": "How Aikido Intel detects malware and vulnerabilities first",
          "link": "https://www.aikido.dev/blog/aikido-intel-detects-malware-vulnerabilities-first",
          "published": "2026-07-13",
          "sev": "high"
        },
        {
          "id": "art-385",
          "title": "npm v12 delivers one of the biggest security improvements in years",
          "link": "https://www.aikido.dev/blog/npm-v12-block-postinstall",
          "published": "2026-06-11",
          "sev": "high"
        },
        {
          "id": "art-562",
          "title": "Securing Vibe Coding and AI Coding Agents: An End-to-End Approach with StepSecurity",
          "link": "https://www.stepsecurity.io/blog/securing-vibe-coding-and-ai-coding-agents-an-end-to-end-approach-with-stepsecurity",
          "published": "2026-04-12",
          "sev": "high"
        },
        {
          "id": "art-796",
          "title": "SHA1-Hulud, npm supply chain incident",
          "link": "https://snyk.io/blog/sha1-hulud-npm-supply-chain-incident/",
          "published": "2025-11-24",
          "sev": "high"
        }
      ],
      "first_seen": "2026-07-13"
    },
    {
      "value": "f099c5d9ec417d4445a0328ac0ada9cde79fc37410914103ae9c609cbc0ee068",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "Aikido",
        "StepSecurity",
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-284",
          "title": "How Aikido Intel detects malware and vulnerabilities first",
          "link": "https://www.aikido.dev/blog/aikido-intel-detects-malware-vulnerabilities-first",
          "published": "2026-07-13",
          "sev": "high"
        },
        {
          "id": "art-385",
          "title": "npm v12 delivers one of the biggest security improvements in years",
          "link": "https://www.aikido.dev/blog/npm-v12-block-postinstall",
          "published": "2026-06-11",
          "sev": "high"
        },
        {
          "id": "art-562",
          "title": "Securing Vibe Coding and AI Coding Agents: An End-to-End Approach with StepSecurity",
          "link": "https://www.stepsecurity.io/blog/securing-vibe-coding-and-ai-coding-agents-an-end-to-end-approach-with-stepsecurity",
          "published": "2026-04-12",
          "sev": "high"
        },
        {
          "id": "art-796",
          "title": "SHA1-Hulud, npm supply chain incident",
          "link": "https://snyk.io/blog/sha1-hulud-npm-supply-chain-incident/",
          "published": "2025-11-24",
          "sev": "high"
        }
      ],
      "first_seen": "2026-07-13"
    },
    {
      "value": "CVE-2025-30066",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "StepSecurity",
        "CISA KEV",
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-292",
          "title": "GitHub Secret Scanning Public Monitoring for Enterprises: Coverage and Gaps",
          "link": "https://www.stepsecurity.io/blog/github-secret-scanning-public-monitoring-for-enterprises-coverage-and-gaps",
          "published": "2026-07-12",
          "sev": "high"
        },
        {
          "id": "art-323",
          "title": "StepSecurity Maintained Actions Are Now Free for Public Repos",
          "link": "https://www.stepsecurity.io/blog/stepsecurity-maintained-actions-are-now-free-for-public-repos",
          "published": "2026-07-02",
          "sev": "high"
        },
        {
          "id": "art-689",
          "title": "Harden-Runner detection: tj-actions/changed-files action is compromised",
          "link": "https://www.stepsecurity.io/blog/harden-runner-detection-tj-actions-changed-files-action-is-compromised",
          "published": "2026-02-11",
          "sev": "high"
        },
        {
          "id": "art-1033",
          "title": "CISA KEV: CVE-2025-30154 \u2014 reviewdog/action-setup GitHub Action Embedded Malicious Code Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-03-24",
          "sev": "crit"
        },
        {
          "id": "art-1041",
          "title": "CISA KEV: CVE-2025-30066 \u2014 tj-actions/changed-files GitHub Action Embedded Malicious Code Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-03-18",
          "sev": "crit"
        },
        {
          "id": "art-1043",
          "title": "Reconstructing the TJ Actions Changed Files GitHub Actions Compromise",
          "link": "https://snyk.io/blog/reconstructing-tj-actions-changed-files-github-actions-compromise/",
          "published": "2025-03-17",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-12"
    },
    {
      "value": "testnet.archival.chain.grpc-web.injective.network",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "StepSecurity",
        "Aikido"
      ],
      "articles": [
        {
          "id": "art-291",
          "title": "Injective npm Supply Chain Attack: 18 Packages Backdoored to Steal Crypto Wallet Keys",
          "link": "https://www.stepsecurity.io/blog/injective-npm-supply-chain-attack-18-packages-backdoored-to-steal-crypto-wallet-keys",
          "published": "2026-07-12",
          "sev": "high"
        },
        {
          "id": "art-308",
          "title": "Compromised @injectivelabs/sdk-ts exfiltrates wallet keys through fake telemetry",
          "link": "https://www.aikido.dev/blog/compromised-injectivelabs-exfiltrates-keys",
          "published": "2026-07-09",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-12"
    },
    {
      "value": "37.27.122.124",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "StepSecurity"
      ],
      "articles": [
        {
          "id": "art-290",
          "title": "jscrambler npm package publishes malicious preinstall binary",
          "link": "https://www.stepsecurity.io/blog/jscrambler-npm-package-publishes-malicious-preinstall-binary",
          "published": "2026-07-12",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-12"
    },
    {
      "value": "57.128.246.79",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "StepSecurity"
      ],
      "articles": [
        {
          "id": "art-290",
          "title": "jscrambler npm package publishes malicious preinstall binary",
          "link": "https://www.stepsecurity.io/blog/jscrambler-npm-package-publishes-malicious-preinstall-binary",
          "published": "2026-07-12",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-12"
    },
    {
      "value": "103c4e6181151c1bcfedc41506cd1815458c38375d08a8fcd9981dbe0b965ce0",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "StepSecurity",
        "Aikido"
      ],
      "articles": [
        {
          "id": "art-291",
          "title": "Injective npm Supply Chain Attack: 18 Packages Backdoored to Steal Crypto Wallet Keys",
          "link": "https://www.stepsecurity.io/blog/injective-npm-supply-chain-attack-18-packages-backdoored-to-steal-crypto-wallet-keys",
          "published": "2026-07-12",
          "sev": "high"
        },
        {
          "id": "art-308",
          "title": "Compromised @injectivelabs/sdk-ts exfiltrates wallet keys through fake telemetry",
          "link": "https://www.aikido.dev/blog/compromised-injectivelabs-exfiltrates-keys",
          "published": "2026-07-09",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-12"
    },
    {
      "value": "9a59eb454f3ca3fe91214136ee5edd417cc47a80e6f169b52099d6561944baf9",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "StepSecurity",
        "Aikido"
      ],
      "articles": [
        {
          "id": "art-291",
          "title": "Injective npm Supply Chain Attack: 18 Packages Backdoored to Steal Crypto Wallet Keys",
          "link": "https://www.stepsecurity.io/blog/injective-npm-supply-chain-attack-18-packages-backdoored-to-steal-crypto-wallet-keys",
          "published": "2026-07-12",
          "sev": "high"
        },
        {
          "id": "art-308",
          "title": "Compromised @injectivelabs/sdk-ts exfiltrates wallet keys through fake telemetry",
          "link": "https://www.aikido.dev/blog/compromised-injectivelabs-exfiltrates-keys",
          "published": "2026-07-09",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-12"
    },
    {
      "value": "b7ca95d1b23c8e67416a25cedf741de0917c2096bbc9d24649eea7853d054903",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "StepSecurity"
      ],
      "articles": [
        {
          "id": "art-290",
          "title": "jscrambler npm package publishes malicious preinstall binary",
          "link": "https://www.stepsecurity.io/blog/jscrambler-npm-package-publishes-malicious-preinstall-binary",
          "published": "2026-07-12",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-12"
    },
    {
      "value": "c8fd47d36bdf7c825378593ab82ed8c24d1dc52e26b507812393e24e1d5201fd",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "StepSecurity"
      ],
      "articles": [
        {
          "id": "art-290",
          "title": "jscrambler npm package publishes malicious preinstall binary",
          "link": "https://www.stepsecurity.io/blog/jscrambler-npm-package-publishes-malicious-preinstall-binary",
          "published": "2026-07-12",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-12"
    },
    {
      "value": "fbbcf4d8f98168f78f5c0c47a9ae56d59ec8ac84a7c9ca6b797fedfb8d62d2bd",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "StepSecurity"
      ],
      "articles": [
        {
          "id": "art-290",
          "title": "jscrambler npm package publishes malicious preinstall binary",
          "link": "https://www.stepsecurity.io/blog/jscrambler-npm-package-publishes-malicious-preinstall-binary",
          "published": "2026-07-12",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-12"
    },
    {
      "value": "CVE-2026-48939",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-304",
          "title": "CISA KEV: CVE-2026-48939 \u2014 iCagenda Unrestricted Upload of File with Dangerous Type Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-07-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-10"
    },
    {
      "value": "CVE-2026-50551",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "GitHub Security Advisories"
      ],
      "articles": [
        {
          "id": "art-295",
          "title": "[GHSA / CRITICAL] CVE-2026-50551: SiYuan: Stored XSS to RCE via Unsanitized Attribute View Asset Cell Content",
          "link": "https://github.com/advisories/GHSA-56mp-4f3v-fgj2",
          "published": "2026-07-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-10"
    },
    {
      "value": "CVE-2026-54067",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "GitHub Security Advisories"
      ],
      "articles": [
        {
          "id": "art-302",
          "title": "[GHSA / CRITICAL] CVE-2026-54067: SiYuan: Stored XSS to RCE via CSS-snippet <style> breakout in renderSnippet()",
          "link": "https://github.com/advisories/GHSA-mvjr-vv3c-w4qv",
          "published": "2026-07-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-10"
    },
    {
      "value": "CVE-2026-54069",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "GitHub Security Advisories"
      ],
      "articles": [
        {
          "id": "art-300",
          "title": "[GHSA / CRITICAL] CVE-2026-54069: SiYuan: Unauthenticated Admin API Access via Blanket chrome-extension:// Origin Allowlist",
          "link": "https://github.com/advisories/GHSA-hvr9-72v2-fff3",
          "published": "2026-07-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-10"
    },
    {
      "value": "CVE-2026-54072",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "GitHub Security Advisories"
      ],
      "articles": [
        {
          "id": "art-301",
          "title": "[GHSA / CRITICAL] CVE-2026-54072: Authorizer: Unvalidated redirect_uri in /authorize leaks OAuth2 tokens to attacker-controlled URL",
          "link": "https://github.com/advisories/GHSA-h29v-hj44-q8cv",
          "published": "2026-07-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-10"
    },
    {
      "value": "CVE-2026-54088",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "GitHub Security Advisories"
      ],
      "articles": [
        {
          "id": "art-297",
          "title": "[GHSA / CRITICAL] CVE-2026-54088: File Browser: Command Injection via Authentication Hook Shell Substitution (Pre-Authentication RCE)",
          "link": "https://github.com/advisories/GHSA-m93h-4hw7-5qcm",
          "published": "2026-07-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-10"
    },
    {
      "value": "CVE-2026-54089",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "GitHub Security Advisories"
      ],
      "articles": [
        {
          "id": "art-299",
          "title": "[GHSA / CRITICAL] CVE-2026-54089: File Browser: Authentication Bypass via Proxy Auth Header Forgery",
          "link": "https://github.com/advisories/GHSA-xqp3-jq6g-x3qm",
          "published": "2026-07-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-10"
    },
    {
      "value": "CVE-2026-54158",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "GitHub Security Advisories"
      ],
      "articles": [
        {
          "id": "art-295",
          "title": "[GHSA / CRITICAL] CVE-2026-50551: SiYuan: Stored XSS to RCE via Unsanitized Attribute View Asset Cell Content",
          "link": "https://github.com/advisories/GHSA-56mp-4f3v-fgj2",
          "published": "2026-07-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-10"
    },
    {
      "value": "CVE-2026-56291",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-303",
          "title": "CISA KEV: CVE-2026-56291 \u2014 Balbooa Forms Unrestricted Upload of File with Dangerous Type Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-07-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-10"
    },
    {
      "value": "CVE-2026-61459",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "GitHub Security Advisories"
      ],
      "articles": [
        {
          "id": "art-294",
          "title": "[GHSA / CRITICAL] CVE-2026-61459: mcp-server-kubernetes argument injection can expose Kubernetes cluster credentials",
          "link": "https://github.com/advisories/GHSA-wmg3-h8mf-wgvr",
          "published": "2026-07-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-10"
    },
    {
      "value": "CVE-2021-32803",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-311",
          "title": "Symlinks Are Still Scary (And Yes, You Can Commit Them to Git)",
          "link": "https://snyk.io/blog/symlinks-are-still-scary/",
          "published": "2026-07-09",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-09"
    },
    {
      "value": "CVE-2024-21626",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-311",
          "title": "Symlinks Are Still Scary (And Yes, You Can Commit Them to Git)",
          "link": "https://snyk.io/blog/symlinks-are-still-scary/",
          "published": "2026-07-09",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-09"
    },
    {
      "value": "CVE-2024-32002",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-311",
          "title": "Symlinks Are Still Scary (And Yes, You Can Commit Them to Git)",
          "link": "https://snyk.io/blog/symlinks-are-still-scary/",
          "published": "2026-07-09",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-09"
    },
    {
      "value": "CVE-2026-12958",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-311",
          "title": "Symlinks Are Still Scary (And Yes, You Can Commit Them to Git)",
          "link": "https://snyk.io/blog/symlinks-are-still-scary/",
          "published": "2026-07-09",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-09"
    },
    {
      "value": "CVE-2026-50549",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-311",
          "title": "Symlinks Are Still Scary (And Yes, You Can Commit Them to Git)",
          "link": "https://snyk.io/blog/symlinks-are-still-scary/",
          "published": "2026-07-09",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-09"
    },
    {
      "value": "CVE-2026-52766",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "GitHub Security Advisories"
      ],
      "articles": [
        {
          "id": "art-307",
          "title": "[GHSA / CRITICAL] CVE-2026-52766: YesWiki vulnerable to unauthenticated arbitrary page deletion via `{{erasespamedcomments}}` action",
          "link": "https://github.com/advisories/GHSA-6x7x-gcmf-7r8x",
          "published": "2026-07-09",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-09"
    },
    {
      "value": "CVE-2026-52777",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "GitHub Security Advisories"
      ],
      "articles": [
        {
          "id": "art-306",
          "title": "[GHSA / CRITICAL] CVE-2026-52777: YesWiki Vulnerable to Authenticated PHP Object Injection in BazarImportAction via unserialize",
          "link": "https://github.com/advisories/GHSA-9369-69wj-7m2f",
          "published": "2026-07-09",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-09"
    },
    {
      "value": "CVE-2026-52778",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "GitHub Security Advisories"
      ],
      "articles": [
        {
          "id": "art-305",
          "title": "[GHSA / CRITICAL] CVE-2026-52778: YesWiki has Unsafe eval() in its Formula Calculato, Leading to Remote Code Execution & Denial of Service",
          "link": "https://github.com/advisories/GHSA-px5m-h76g-p7p8",
          "published": "2026-07-09",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-09"
    },
    {
      "value": "142.171.183.8",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "SentinelLabs"
      ],
      "articles": [
        {
          "id": "art-309",
          "title": "One Target, Two Flags | Rival Espionage Actors Converge On Pakistani Law Enforcement",
          "link": "https://www.sentinelone.com/labs/one-target-china-india-espionage-converge-on-pakistani-law-enforcement/",
          "published": "2026-07-09",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-09"
    },
    {
      "value": "172.111.233.105",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "SentinelLabs"
      ],
      "articles": [
        {
          "id": "art-309",
          "title": "One Target, Two Flags | Rival Espionage Actors Converge On Pakistani Law Enforcement",
          "link": "https://www.sentinelone.com/labs/one-target-china-india-espionage-converge-on-pakistani-law-enforcement/",
          "published": "2026-07-09",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-09"
    },
    {
      "value": "172.111.233.12",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "SentinelLabs"
      ],
      "articles": [
        {
          "id": "art-309",
          "title": "One Target, Two Flags | Rival Espionage Actors Converge On Pakistani Law Enforcement",
          "link": "https://www.sentinelone.com/labs/one-target-china-india-espionage-converge-on-pakistani-law-enforcement/",
          "published": "2026-07-09",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-09"
    },
    {
      "value": "172.111.233.26",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "SentinelLabs"
      ],
      "articles": [
        {
          "id": "art-309",
          "title": "One Target, Two Flags | Rival Espionage Actors Converge On Pakistani Law Enforcement",
          "link": "https://www.sentinelone.com/labs/one-target-china-india-espionage-converge-on-pakistani-law-enforcement/",
          "published": "2026-07-09",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-09"
    },
    {
      "value": "172.111.233.36",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "SentinelLabs"
      ],
      "articles": [
        {
          "id": "art-309",
          "title": "One Target, Two Flags | Rival Espionage Actors Converge On Pakistani Law Enforcement",
          "link": "https://www.sentinelone.com/labs/one-target-china-india-espionage-converge-on-pakistani-law-enforcement/",
          "published": "2026-07-09",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-09"
    },
    {
      "value": "172.111.233.96",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "SentinelLabs"
      ],
      "articles": [
        {
          "id": "art-309",
          "title": "One Target, Two Flags | Rival Espionage Actors Converge On Pakistani Law Enforcement",
          "link": "https://www.sentinelone.com/labs/one-target-china-india-espionage-converge-on-pakistani-law-enforcement/",
          "published": "2026-07-09",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-09"
    },
    {
      "value": "172.94.9.19",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "SentinelLabs"
      ],
      "articles": [
        {
          "id": "art-309",
          "title": "One Target, Two Flags | Rival Espionage Actors Converge On Pakistani Law Enforcement",
          "link": "https://www.sentinelone.com/labs/one-target-china-india-espionage-converge-on-pakistani-law-enforcement/",
          "published": "2026-07-09",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-09"
    },
    {
      "value": "172.94.9.43",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "SentinelLabs"
      ],
      "articles": [
        {
          "id": "art-309",
          "title": "One Target, Two Flags | Rival Espionage Actors Converge On Pakistani Law Enforcement",
          "link": "https://www.sentinelone.com/labs/one-target-china-india-espionage-converge-on-pakistani-law-enforcement/",
          "published": "2026-07-09",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-09"
    },
    {
      "value": "172.94.9.49",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "SentinelLabs"
      ],
      "articles": [
        {
          "id": "art-309",
          "title": "One Target, Two Flags | Rival Espionage Actors Converge On Pakistani Law Enforcement",
          "link": "https://www.sentinelone.com/labs/one-target-china-india-espionage-converge-on-pakistani-law-enforcement/",
          "published": "2026-07-09",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-09"
    },
    {
      "value": "193.42.25.65",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "SentinelLabs"
      ],
      "articles": [
        {
          "id": "art-309",
          "title": "One Target, Two Flags | Rival Espionage Actors Converge On Pakistani Law Enforcement",
          "link": "https://www.sentinelone.com/labs/one-target-china-india-espionage-converge-on-pakistani-law-enforcement/",
          "published": "2026-07-09",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-09"
    },
    {
      "value": "45.125.32.218",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "SentinelLabs"
      ],
      "articles": [
        {
          "id": "art-309",
          "title": "One Target, Two Flags | Rival Espionage Actors Converge On Pakistani Law Enforcement",
          "link": "https://www.sentinelone.com/labs/one-target-china-india-espionage-converge-on-pakistani-law-enforcement/",
          "published": "2026-07-09",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-09"
    },
    {
      "value": "45.74.6.17",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "SentinelLabs"
      ],
      "articles": [
        {
          "id": "art-309",
          "title": "One Target, Two Flags | Rival Espionage Actors Converge On Pakistani Law Enforcement",
          "link": "https://www.sentinelone.com/labs/one-target-china-india-espionage-converge-on-pakistani-law-enforcement/",
          "published": "2026-07-09",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-09"
    },
    {
      "value": "89.31.121.220",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "SentinelLabs"
      ],
      "articles": [
        {
          "id": "art-309",
          "title": "One Target, Two Flags | Rival Espionage Actors Converge On Pakistani Law Enforcement",
          "link": "https://www.sentinelone.com/labs/one-target-china-india-espionage-converge-on-pakistani-law-enforcement/",
          "published": "2026-07-09",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-09"
    },
    {
      "value": "m-mgarg.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "ESET WeLiveSecurity"
      ],
      "articles": [
        {
          "id": "art-312",
          "title": "ESET Threat Report H1 2026",
          "link": "https://www.welivesecurity.com/en/eset-research/eset-threat-report-h1-2026/",
          "published": "2026-07-08",
          "sev": "crit"
        },
        {
          "id": "art-322",
          "title": "Cyber readiness for SMBs: Getting the basics right",
          "link": "https://www.welivesecurity.com/en/business-security/cyber-readiness-smbs-getting-basics-right/",
          "published": "2026-07-03",
          "sev": "high"
        }
      ],
      "first_seen": "2026-07-08"
    },
    {
      "value": "mgardownload.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "ESET WeLiveSecurity"
      ],
      "articles": [
        {
          "id": "art-312",
          "title": "ESET Threat Report H1 2026",
          "link": "https://www.welivesecurity.com/en/eset-research/eset-threat-report-h1-2026/",
          "published": "2026-07-08",
          "sev": "crit"
        },
        {
          "id": "art-322",
          "title": "Cyber readiness for SMBs: Getting the basics right",
          "link": "https://www.welivesecurity.com/en/business-security/cyber-readiness-smbs-getting-basics-right/",
          "published": "2026-07-03",
          "sev": "high"
        }
      ],
      "first_seen": "2026-07-08"
    },
    {
      "value": "104.21.91.170",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "ESET WeLiveSecurity"
      ],
      "articles": [
        {
          "id": "art-312",
          "title": "ESET Threat Report H1 2026",
          "link": "https://www.welivesecurity.com/en/eset-research/eset-threat-report-h1-2026/",
          "published": "2026-07-08",
          "sev": "crit"
        },
        {
          "id": "art-322",
          "title": "Cyber readiness for SMBs: Getting the basics right",
          "link": "https://www.welivesecurity.com/en/business-security/cyber-readiness-smbs-getting-basics-right/",
          "published": "2026-07-03",
          "sev": "high"
        }
      ],
      "first_seen": "2026-07-08"
    },
    {
      "value": "52.222.205.45",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "ESET WeLiveSecurity"
      ],
      "articles": [
        {
          "id": "art-312",
          "title": "ESET Threat Report H1 2026",
          "link": "https://www.welivesecurity.com/en/eset-research/eset-threat-report-h1-2026/",
          "published": "2026-07-08",
          "sev": "crit"
        },
        {
          "id": "art-322",
          "title": "Cyber readiness for SMBs: Getting the basics right",
          "link": "https://www.welivesecurity.com/en/business-security/cyber-readiness-smbs-getting-basics-right/",
          "published": "2026-07-03",
          "sev": "high"
        }
      ],
      "first_seen": "2026-07-08"
    },
    {
      "value": "54.67.2.84",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "ESET WeLiveSecurity"
      ],
      "articles": [
        {
          "id": "art-312",
          "title": "ESET Threat Report H1 2026",
          "link": "https://www.welivesecurity.com/en/eset-research/eset-threat-report-h1-2026/",
          "published": "2026-07-08",
          "sev": "crit"
        },
        {
          "id": "art-322",
          "title": "Cyber readiness for SMBs: Getting the basics right",
          "link": "https://www.welivesecurity.com/en/business-security/cyber-readiness-smbs-getting-basics-right/",
          "published": "2026-07-03",
          "sev": "high"
        }
      ],
      "first_seen": "2026-07-08"
    },
    {
      "value": "076801bd9c6eb78fc0331a4c7a22c73199cc3824",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "ESET WeLiveSecurity"
      ],
      "articles": [
        {
          "id": "art-312",
          "title": "ESET Threat Report H1 2026",
          "link": "https://www.welivesecurity.com/en/eset-research/eset-threat-report-h1-2026/",
          "published": "2026-07-08",
          "sev": "crit"
        },
        {
          "id": "art-322",
          "title": "Cyber readiness for SMBs: Getting the basics right",
          "link": "https://www.welivesecurity.com/en/business-security/cyber-readiness-smbs-getting-basics-right/",
          "published": "2026-07-03",
          "sev": "high"
        }
      ],
      "first_seen": "2026-07-08"
    },
    {
      "value": "375d7423e63c8f5f2cc814e8cfe697ba25168afa",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "ESET WeLiveSecurity"
      ],
      "articles": [
        {
          "id": "art-312",
          "title": "ESET Threat Report H1 2026",
          "link": "https://www.welivesecurity.com/en/eset-research/eset-threat-report-h1-2026/",
          "published": "2026-07-08",
          "sev": "crit"
        },
        {
          "id": "art-322",
          "title": "Cyber readiness for SMBs: Getting the basics right",
          "link": "https://www.welivesecurity.com/en/business-security/cyber-readiness-smbs-getting-basics-right/",
          "published": "2026-07-03",
          "sev": "high"
        }
      ],
      "first_seen": "2026-07-08"
    },
    {
      "value": "3978ac5cd14e357320e127d6c87f10cb70a1dcc2",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "ESET WeLiveSecurity"
      ],
      "articles": [
        {
          "id": "art-312",
          "title": "ESET Threat Report H1 2026",
          "link": "https://www.welivesecurity.com/en/eset-research/eset-threat-report-h1-2026/",
          "published": "2026-07-08",
          "sev": "crit"
        },
        {
          "id": "art-322",
          "title": "Cyber readiness for SMBs: Getting the basics right",
          "link": "https://www.welivesecurity.com/en/business-security/cyber-readiness-smbs-getting-basics-right/",
          "published": "2026-07-03",
          "sev": "high"
        }
      ],
      "first_seen": "2026-07-08"
    },
    {
      "value": "6bbc9ab132ba066f63676e05da13d108598bc29b",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "ESET WeLiveSecurity"
      ],
      "articles": [
        {
          "id": "art-312",
          "title": "ESET Threat Report H1 2026",
          "link": "https://www.welivesecurity.com/en/eset-research/eset-threat-report-h1-2026/",
          "published": "2026-07-08",
          "sev": "crit"
        },
        {
          "id": "art-322",
          "title": "Cyber readiness for SMBs: Getting the basics right",
          "link": "https://www.welivesecurity.com/en/business-security/cyber-readiness-smbs-getting-basics-right/",
          "published": "2026-07-03",
          "sev": "high"
        }
      ],
      "first_seen": "2026-07-08"
    },
    {
      "value": "8364730e9bb2cf3a4b016de1b34f38341c0ee2fa",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "ESET WeLiveSecurity"
      ],
      "articles": [
        {
          "id": "art-312",
          "title": "ESET Threat Report H1 2026",
          "link": "https://www.welivesecurity.com/en/eset-research/eset-threat-report-h1-2026/",
          "published": "2026-07-08",
          "sev": "crit"
        },
        {
          "id": "art-322",
          "title": "Cyber readiness for SMBs: Getting the basics right",
          "link": "https://www.welivesecurity.com/en/business-security/cyber-readiness-smbs-getting-basics-right/",
          "published": "2026-07-03",
          "sev": "high"
        }
      ],
      "first_seen": "2026-07-08"
    },
    {
      "value": "9b1723284e311794987997cb7e8814eb6014713f",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "ESET WeLiveSecurity"
      ],
      "articles": [
        {
          "id": "art-312",
          "title": "ESET Threat Report H1 2026",
          "link": "https://www.welivesecurity.com/en/eset-research/eset-threat-report-h1-2026/",
          "published": "2026-07-08",
          "sev": "crit"
        },
        {
          "id": "art-322",
          "title": "Cyber readiness for SMBs: Getting the basics right",
          "link": "https://www.welivesecurity.com/en/business-security/cyber-readiness-smbs-getting-basics-right/",
          "published": "2026-07-03",
          "sev": "high"
        }
      ],
      "first_seen": "2026-07-08"
    },
    {
      "value": "c14e9b062ed28115ede096788f62b47a6ed841ac",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "ESET WeLiveSecurity"
      ],
      "articles": [
        {
          "id": "art-312",
          "title": "ESET Threat Report H1 2026",
          "link": "https://www.welivesecurity.com/en/eset-research/eset-threat-report-h1-2026/",
          "published": "2026-07-08",
          "sev": "crit"
        },
        {
          "id": "art-322",
          "title": "Cyber readiness for SMBs: Getting the basics right",
          "link": "https://www.welivesecurity.com/en/business-security/cyber-readiness-smbs-getting-basics-right/",
          "published": "2026-07-03",
          "sev": "high"
        }
      ],
      "first_seen": "2026-07-08"
    },
    {
      "value": "e60d12017d2da579df87368f5596a0244621ae86",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "ESET WeLiveSecurity"
      ],
      "articles": [
        {
          "id": "art-312",
          "title": "ESET Threat Report H1 2026",
          "link": "https://www.welivesecurity.com/en/eset-research/eset-threat-report-h1-2026/",
          "published": "2026-07-08",
          "sev": "crit"
        },
        {
          "id": "art-322",
          "title": "Cyber readiness for SMBs: Getting the basics right",
          "link": "https://www.welivesecurity.com/en/business-security/cyber-readiness-smbs-getting-basics-right/",
          "published": "2026-07-03",
          "sev": "high"
        }
      ],
      "first_seen": "2026-07-08"
    },
    {
      "value": "f8f4c5bc498bcce907dc975dd88be8d594629909",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "ESET WeLiveSecurity"
      ],
      "articles": [
        {
          "id": "art-312",
          "title": "ESET Threat Report H1 2026",
          "link": "https://www.welivesecurity.com/en/eset-research/eset-threat-report-h1-2026/",
          "published": "2026-07-08",
          "sev": "crit"
        },
        {
          "id": "art-322",
          "title": "Cyber readiness for SMBs: Getting the basics right",
          "link": "https://www.welivesecurity.com/en/business-security/cyber-readiness-smbs-getting-basics-right/",
          "published": "2026-07-03",
          "sev": "high"
        }
      ],
      "first_seen": "2026-07-08"
    },
    {
      "value": "CVE-2026-48282",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-318",
          "title": "CISA KEV: CVE-2026-48282 \u2014 Adobe ColdFusion Path Traversal Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-07-07",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-07"
    },
    {
      "value": "CVE-2026-48908",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-315",
          "title": "CISA KEV: CVE-2026-48908 \u2014 JoomShaper SP Page Builder Unrestricted Upload of File with Dangerous Type Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-07-07",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-07"
    },
    {
      "value": "CVE-2026-55255",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-316",
          "title": "CISA KEV: CVE-2026-55255 \u2014 Langflow Authorization Bypass Through User-Controlled Key Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-07-07",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-07"
    },
    {
      "value": "CVE-2026-56290",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-317",
          "title": "CISA KEV: CVE-2026-56290 \u2014 Joomlack Page Builder Improper Access Control Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-07-07",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-07"
    },
    {
      "value": "secure.local",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-315",
          "title": "CISA KEV: CVE-2026-48908 \u2014 JoomShaper SP Page Builder Unrestricted Upload of File with Dangerous Type Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-07-07",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-07"
    },
    {
      "value": "103.207.14.220",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-318",
          "title": "CISA KEV: CVE-2026-48282 \u2014 Adobe ColdFusion Path Traversal Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-07-07",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-07"
    },
    {
      "value": "45.207.216.55",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-316",
          "title": "CISA KEV: CVE-2026-55255 \u2014 Langflow Authorization Bypass Through User-Controlled Key Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-07-07",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-07"
    },
    {
      "value": "CVE-2026-48611",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "Aikido"
      ],
      "articles": [
        {
          "id": "art-320",
          "title": "Authentication Bypass in the default configuration phpBB",
          "link": "https://www.aikido.dev/blog/authentication-bypass-phpbb-technical-writeup",
          "published": "2026-07-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-03"
    },
    {
      "value": "161cdcdb46fb8a348aec609a86ff5823752065d2",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "ESET WeLiveSecurity"
      ],
      "articles": [
        {
          "id": "art-322",
          "title": "Cyber readiness for SMBs: Getting the basics right",
          "link": "https://www.welivesecurity.com/en/business-security/cyber-readiness-smbs-getting-basics-right/",
          "published": "2026-07-03",
          "sev": "high"
        }
      ],
      "first_seen": "2026-07-03"
    },
    {
      "value": "24bf7b72f54aa5b93c6681b4f69e579a47d7c102",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "ESET WeLiveSecurity"
      ],
      "articles": [
        {
          "id": "art-322",
          "title": "Cyber readiness for SMBs: Getting the basics right",
          "link": "https://www.welivesecurity.com/en/business-security/cyber-readiness-smbs-getting-basics-right/",
          "published": "2026-07-03",
          "sev": "high"
        }
      ],
      "first_seen": "2026-07-03"
    },
    {
      "value": "639dbc9b365096d6347142fcae64725bd9f73270",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "ESET WeLiveSecurity"
      ],
      "articles": [
        {
          "id": "art-322",
          "title": "Cyber readiness for SMBs: Getting the basics right",
          "link": "https://www.welivesecurity.com/en/business-security/cyber-readiness-smbs-getting-basics-right/",
          "published": "2026-07-03",
          "sev": "high"
        }
      ],
      "first_seen": "2026-07-03"
    },
    {
      "value": "8c7bcafce90f5fb121131ecb27346ecfc6e961c5",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "ESET WeLiveSecurity"
      ],
      "articles": [
        {
          "id": "art-322",
          "title": "Cyber readiness for SMBs: Getting the basics right",
          "link": "https://www.welivesecurity.com/en/business-security/cyber-readiness-smbs-getting-basics-right/",
          "published": "2026-07-03",
          "sev": "high"
        }
      ],
      "first_seen": "2026-07-03"
    },
    {
      "value": "ad223fe2bb4563446aee5227357bbfdc8ada3797",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "ESET WeLiveSecurity"
      ],
      "articles": [
        {
          "id": "art-322",
          "title": "Cyber readiness for SMBs: Getting the basics right",
          "link": "https://www.welivesecurity.com/en/business-security/cyber-readiness-smbs-getting-basics-right/",
          "published": "2026-07-03",
          "sev": "high"
        }
      ],
      "first_seen": "2026-07-03"
    },
    {
      "value": "bb8fb75285bcd151132a3287f2786d4d91da58b8",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "ESET WeLiveSecurity"
      ],
      "articles": [
        {
          "id": "art-322",
          "title": "Cyber readiness for SMBs: Getting the basics right",
          "link": "https://www.welivesecurity.com/en/business-security/cyber-readiness-smbs-getting-basics-right/",
          "published": "2026-07-03",
          "sev": "high"
        }
      ],
      "first_seen": "2026-07-03"
    },
    {
      "value": "f3f4c40c344695388e10cbf29ddb18ef3b61f7ef",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "ESET WeLiveSecurity"
      ],
      "articles": [
        {
          "id": "art-322",
          "title": "Cyber readiness for SMBs: Getting the basics right",
          "link": "https://www.welivesecurity.com/en/business-security/cyber-readiness-smbs-getting-basics-right/",
          "published": "2026-07-03",
          "sev": "high"
        }
      ],
      "first_seen": "2026-07-03"
    },
    {
      "value": "scan.aquasecurtiy.org",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "StepSecurity"
      ],
      "articles": [
        {
          "id": "art-324",
          "title": "10 Layers Deep: How StepSecurity Stops TeamPCP's Trivy Supply Chain Attack on GitHub Actions",
          "link": "https://www.stepsecurity.io/blog/10-layers-deep-how-stepsecurity-stops-teampcps-trivy-supply-chain-attack-on-github-actions",
          "published": "2026-07-02",
          "sev": "crit"
        },
        {
          "id": "art-592",
          "title": "CanisterWorm: How a Self-Propagating npm Worm Is Spreading Backdoors Across the Ecosystem",
          "link": "https://www.stepsecurity.io/blog/canisterworm-how-a-self-propagating-npm-worm-is-spreading-backdoors-across-the-ecosystem",
          "published": "2026-03-26",
          "sev": "high"
        },
        {
          "id": "art-593",
          "title": "Trivy Compromised a Second Time - Malicious v0.69.4 Release, aquasecurity/setup-trivy, aquasecurity/trivy-action GitHub Actions Compromised",
          "link": "https://www.stepsecurity.io/blog/trivy-compromised-a-second-time---malicious-v0-69-4-release",
          "published": "2026-03-26",
          "sev": "high"
        }
      ],
      "first_seen": "2026-07-02"
    },
    {
      "value": "tdtqy-oyaaa-aaaae-af2dq-cai.raw.icp0.io",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "StepSecurity",
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-324",
          "title": "10 Layers Deep: How StepSecurity Stops TeamPCP's Trivy Supply Chain Attack on GitHub Actions",
          "link": "https://www.stepsecurity.io/blog/10-layers-deep-how-stepsecurity-stops-teampcps-trivy-supply-chain-attack-on-github-actions",
          "published": "2026-07-02",
          "sev": "crit"
        },
        {
          "id": "art-579",
          "title": "You Patched LiteLLM, But Do You Know Your AI Blast Radius?",
          "link": "https://snyk.io/blog/litellm-ai-blast-radius/",
          "published": "2026-04-02",
          "sev": "high"
        },
        {
          "id": "art-592",
          "title": "CanisterWorm: How a Self-Propagating npm Worm Is Spreading Backdoors Across the Ecosystem",
          "link": "https://www.stepsecurity.io/blog/canisterworm-how-a-self-propagating-npm-worm-is-spreading-backdoors-across-the-ecosystem",
          "published": "2026-03-26",
          "sev": "high"
        }
      ],
      "first_seen": "2026-07-02"
    },
    {
      "value": "45.148.10.212",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "StepSecurity"
      ],
      "articles": [
        {
          "id": "art-324",
          "title": "10 Layers Deep: How StepSecurity Stops TeamPCP's Trivy Supply Chain Attack on GitHub Actions",
          "link": "https://www.stepsecurity.io/blog/10-layers-deep-how-stepsecurity-stops-teampcps-trivy-supply-chain-attack-on-github-actions",
          "published": "2026-07-02",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-02"
    },
    {
      "value": "0e58ed8671d6b60d0890c21b07f8835ace038e67",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "StepSecurity",
        "CISA KEV",
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-323",
          "title": "StepSecurity Maintained Actions Are Now Free for Public Repos",
          "link": "https://www.stepsecurity.io/blog/stepsecurity-maintained-actions-are-now-free-for-public-repos",
          "published": "2026-07-02",
          "sev": "high"
        },
        {
          "id": "art-689",
          "title": "Harden-Runner detection: tj-actions/changed-files action is compromised",
          "link": "https://www.stepsecurity.io/blog/harden-runner-detection-tj-actions-changed-files-action-is-compromised",
          "published": "2026-02-11",
          "sev": "high"
        },
        {
          "id": "art-1033",
          "title": "CISA KEV: CVE-2025-30154 \u2014 reviewdog/action-setup GitHub Action Embedded Malicious Code Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-03-24",
          "sev": "crit"
        },
        {
          "id": "art-1041",
          "title": "CISA KEV: CVE-2025-30066 \u2014 tj-actions/changed-files GitHub Action Embedded Malicious Code Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-03-18",
          "sev": "crit"
        },
        {
          "id": "art-1043",
          "title": "Reconstructing the TJ Actions Changed Files GitHub Actions Compromise",
          "link": "https://snyk.io/blog/reconstructing-tj-actions-changed-files-github-actions-compromise/",
          "published": "2025-03-17",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-02"
    },
    {
      "value": "CVE-2026-45659",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-334",
          "title": "CISA KEV: CVE-2026-45659 \u2014 Microsoft SharePoint Server Deserialization of Untrusted Data Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-07-01",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-01"
    },
    {
      "value": "maskasd.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "StepSecurity"
      ],
      "articles": [
        {
          "id": "art-326",
          "title": "Secure Registry now tells you which machine pulled a compromised package",
          "link": "https://www.stepsecurity.io/blog/secure-registry-now-tells-you-which-machine-pulled-a-compromised-package",
          "published": "2026-07-01",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-01"
    },
    {
      "value": "teams.onweblive.org",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "StepSecurity"
      ],
      "articles": [
        {
          "id": "art-326",
          "title": "Secure Registry now tells you which machine pulled a compromised package",
          "link": "https://www.stepsecurity.io/blog/secure-registry-now-tells-you-which-machine-pulled-a-compromised-package",
          "published": "2026-07-01",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-01"
    },
    {
      "value": "23.254.164.123",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "StepSecurity",
        "Aikido",
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-326",
          "title": "Secure Registry now tells you which machine pulled a compromised package",
          "link": "https://www.stepsecurity.io/blog/secure-registry-now-tells-you-which-machine-pulled-a-compromised-package",
          "published": "2026-07-01",
          "sev": "crit"
        },
        {
          "id": "art-340",
          "title": "npm now freezes high-impact accounts after risky account changes",
          "link": "https://www.aikido.dev/blog/npm-cooldown-account-changes-announcement",
          "published": "2026-06-26",
          "sev": "high"
        },
        {
          "id": "art-345",
          "title": "Everybody's shipping code they can't read",
          "link": "https://www.aikido.dev/blog/shipping-code-they-cant-read",
          "published": "2026-06-25",
          "sev": "high"
        },
        {
          "id": "art-362",
          "title": "Mastra npm Supply Chain Attack: 140+ Packages Backdoored via easy-day-js Typosquat",
          "link": "https://www.stepsecurity.io/blog/mastra-npm-packages-compromised-using-easy-day-js",
          "published": "2026-06-18",
          "sev": "high"
        },
        {
          "id": "art-370",
          "title": "Over 140 popular Mastra npm Packages Hit by Supply Chain Attack",
          "link": "https://www.aikido.dev/blog/over-140-popular-mastra-npm-packages-hit-by-supply-chain-attack",
          "published": "2026-06-17",
          "sev": "high"
        },
        {
          "id": "art-373",
          "title": "A Forgotten Contributor Account Compromised the Entire Mastra npm Package Scope",
          "link": "https://snyk.io/blog/a-forgotten-contributor-account-compromised-the-entire-mastra-npm-package-scope/",
          "published": "2026-06-16",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-01"
    },
    {
      "value": "23.254.164.92",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "StepSecurity",
        "Aikido",
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-326",
          "title": "Secure Registry now tells you which machine pulled a compromised package",
          "link": "https://www.stepsecurity.io/blog/secure-registry-now-tells-you-which-machine-pulled-a-compromised-package",
          "published": "2026-07-01",
          "sev": "crit"
        },
        {
          "id": "art-340",
          "title": "npm now freezes high-impact accounts after risky account changes",
          "link": "https://www.aikido.dev/blog/npm-cooldown-account-changes-announcement",
          "published": "2026-06-26",
          "sev": "high"
        },
        {
          "id": "art-345",
          "title": "Everybody's shipping code they can't read",
          "link": "https://www.aikido.dev/blog/shipping-code-they-cant-read",
          "published": "2026-06-25",
          "sev": "high"
        },
        {
          "id": "art-362",
          "title": "Mastra npm Supply Chain Attack: 140+ Packages Backdoored via easy-day-js Typosquat",
          "link": "https://www.stepsecurity.io/blog/mastra-npm-packages-compromised-using-easy-day-js",
          "published": "2026-06-18",
          "sev": "high"
        },
        {
          "id": "art-370",
          "title": "Over 140 popular Mastra npm Packages Hit by Supply Chain Attack",
          "link": "https://www.aikido.dev/blog/over-140-popular-mastra-npm-packages-hit-by-supply-chain-attack",
          "published": "2026-06-17",
          "sev": "high"
        },
        {
          "id": "art-373",
          "title": "A Forgotten Contributor Account Compromised the Entire Mastra npm Package Scope",
          "link": "https://snyk.io/blog/a-forgotten-contributor-account-compromised-the-entire-mastra-npm-package-scope/",
          "published": "2026-06-16",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-01"
    },
    {
      "value": "6b9501e1889cc45c91726729610cf69c2442b8c5",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "StepSecurity"
      ],
      "articles": [
        {
          "id": "art-326",
          "title": "Secure Registry now tells you which machine pulled a compromised package",
          "link": "https://www.stepsecurity.io/blog/secure-registry-now-tells-you-which-machine-pulled-a-compromised-package",
          "published": "2026-07-01",
          "sev": "crit"
        },
        {
          "id": "art-331",
          "title": "codfish/semantic-release-action GitHub Action has been compromised",
          "link": "https://www.stepsecurity.io/blog/supply-chain-compromise-codfish-semantic-release-action",
          "published": "2026-07-01",
          "sev": "high"
        }
      ],
      "first_seen": "2026-07-01"
    },
    {
      "value": "221c45a790dec2a296af57969e1165a16f8f49733aeab64c0bbd768d9943badf",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "StepSecurity",
        "Aikido",
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-326",
          "title": "Secure Registry now tells you which machine pulled a compromised package",
          "link": "https://www.stepsecurity.io/blog/secure-registry-now-tells-you-which-machine-pulled-a-compromised-package",
          "published": "2026-07-01",
          "sev": "crit"
        },
        {
          "id": "art-340",
          "title": "npm now freezes high-impact accounts after risky account changes",
          "link": "https://www.aikido.dev/blog/npm-cooldown-account-changes-announcement",
          "published": "2026-06-26",
          "sev": "high"
        },
        {
          "id": "art-345",
          "title": "Everybody's shipping code they can't read",
          "link": "https://www.aikido.dev/blog/shipping-code-they-cant-read",
          "published": "2026-06-25",
          "sev": "high"
        },
        {
          "id": "art-373",
          "title": "A Forgotten Contributor Account Compromised the Entire Mastra npm Package Scope",
          "link": "https://snyk.io/blog/a-forgotten-contributor-account-compromised-the-entire-mastra-npm-package-scope/",
          "published": "2026-06-16",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-01"
    },
    {
      "value": "4a8860240e4231c3a74c81949be655a28e096a7d72f38fbe84e5b37636b98417",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "StepSecurity",
        "Aikido"
      ],
      "articles": [
        {
          "id": "art-326",
          "title": "Secure Registry now tells you which machine pulled a compromised package",
          "link": "https://www.stepsecurity.io/blog/secure-registry-now-tells-you-which-machine-pulled-a-compromised-package",
          "published": "2026-07-01",
          "sev": "crit"
        },
        {
          "id": "art-340",
          "title": "npm now freezes high-impact accounts after risky account changes",
          "link": "https://www.aikido.dev/blog/npm-cooldown-account-changes-announcement",
          "published": "2026-06-26",
          "sev": "high"
        }
      ],
      "first_seen": "2026-07-01"
    },
    {
      "value": "ae70dd4f6bc0d1c8c2848e4e6b51934626c4818dcb5af99d080ddbd7dc337185",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "StepSecurity",
        "Aikido"
      ],
      "articles": [
        {
          "id": "art-326",
          "title": "Secure Registry now tells you which machine pulled a compromised package",
          "link": "https://www.stepsecurity.io/blog/secure-registry-now-tells-you-which-machine-pulled-a-compromised-package",
          "published": "2026-07-01",
          "sev": "crit"
        },
        {
          "id": "art-340",
          "title": "npm now freezes high-impact accounts after risky account changes",
          "link": "https://www.aikido.dev/blog/npm-cooldown-account-changes-announcement",
          "published": "2026-06-26",
          "sev": "high"
        }
      ],
      "first_seen": "2026-07-01"
    },
    {
      "value": "b122a9873bedf145ae2a7fd024b5f309007dbb025149f4dc4ac3f7e4f32a36a4",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "StepSecurity",
        "Aikido",
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-326",
          "title": "Secure Registry now tells you which machine pulled a compromised package",
          "link": "https://www.stepsecurity.io/blog/secure-registry-now-tells-you-which-machine-pulled-a-compromised-package",
          "published": "2026-07-01",
          "sev": "crit"
        },
        {
          "id": "art-345",
          "title": "Everybody's shipping code they can't read",
          "link": "https://www.aikido.dev/blog/shipping-code-they-cant-read",
          "published": "2026-06-25",
          "sev": "high"
        },
        {
          "id": "art-373",
          "title": "A Forgotten Contributor Account Compromised the Entire Mastra npm Package Scope",
          "link": "https://snyk.io/blog/a-forgotten-contributor-account-compromised-the-entire-mastra-npm-package-scope/",
          "published": "2026-06-16",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-01"
    },
    {
      "value": "b73de25c053c3225a077738a1fcbd9ca6966d7b3cd6f5494a30f0aa0eae55c7e",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "StepSecurity"
      ],
      "articles": [
        {
          "id": "art-326",
          "title": "Secure Registry now tells you which machine pulled a compromised package",
          "link": "https://www.stepsecurity.io/blog/secure-registry-now-tells-you-which-machine-pulled-a-compromised-package",
          "published": "2026-07-01",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-07-01"
    },
    {
      "value": "ceff7c51d70832c3ec8dd2744b606a23b3c924ef664ae23439b9b742ea154108",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "StepSecurity",
        "Aikido",
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-327",
          "title": "Multiple @immobiliarelabs Backstage Plugins Compromised on npm",
          "link": "https://www.stepsecurity.io/blog/immobiliarelabs-npm-packages-compromised",
          "published": "2026-07-01",
          "sev": "high"
        },
        {
          "id": "art-398",
          "title": "Wait, binding.gyp Can Do What? Exploring npm's Weirdest Build System",
          "link": "https://www.aikido.dev/blog/exploring-binding-gyp-npm-build-system",
          "published": "2026-06-09",
          "sev": "crit"
        },
        {
          "id": "art-408",
          "title": "Node-gyp Supply Chain Compromise: A Self-Propagating npm Worm That Hides in binding.gyp",
          "link": "https://snyk.io/blog/node-gyp-supply-chain-compromise-self-propagating-npm-worm-binding-gyp/",
          "published": "2026-06-04",
          "sev": "high"
        }
      ],
      "first_seen": "2026-07-01"
    },
    {
      "value": "ef641e956f91d501b748085996303c96a64d67f63bfeef0dda175e5aa19cca90",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "StepSecurity",
        "Aikido",
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-327",
          "title": "Multiple @immobiliarelabs Backstage Plugins Compromised on npm",
          "link": "https://www.stepsecurity.io/blog/immobiliarelabs-npm-packages-compromised",
          "published": "2026-07-01",
          "sev": "high"
        },
        {
          "id": "art-397",
          "title": "Miasma Worm Hits Microsoft Again: Azure Functions Action and 72 Other Repositories Disabled After Supply Chain Attack Targeting AI Coding Agents",
          "link": "https://www.stepsecurity.io/blog/miasma-worm-hits-microsoft-again-azure-functions-action-and-72-other-repositories-disabled-after-supply-chain-attack-targeting-ai-coding-agents",
          "published": "2026-06-09",
          "sev": "high"
        },
        {
          "id": "art-398",
          "title": "Wait, binding.gyp Can Do What? Exploring npm's Weirdest Build System",
          "link": "https://www.aikido.dev/blog/exploring-binding-gyp-npm-build-system",
          "published": "2026-06-09",
          "sev": "crit"
        },
        {
          "id": "art-408",
          "title": "Node-gyp Supply Chain Compromise: A Self-Propagating npm Worm That Hides in binding.gyp",
          "link": "https://snyk.io/blog/node-gyp-supply-chain-compromise-self-propagating-npm-worm-binding-gyp/",
          "published": "2026-06-04",
          "sev": "high"
        }
      ],
      "first_seen": "2026-07-01"
    },
    {
      "value": "fasterxml.org",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "StepSecurity"
      ],
      "articles": [
        {
          "id": "art-328",
          "title": "Maven Support Comes to GitHub Checks and OSS Package Search",
          "link": "https://www.stepsecurity.io/blog/maven-support-comes-to-github-checks-and-oss-package-search",
          "published": "2026-07-01",
          "sev": "high"
        }
      ],
      "first_seen": "2026-07-01"
    },
    {
      "value": "https://github.com/oven-sh/bun/releases/download/bun-v1.3.13/bun-<os>-<arch>.zip",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "StepSecurity"
      ],
      "articles": [
        {
          "id": "art-327",
          "title": "Multiple @immobiliarelabs Backstage Plugins Compromised on npm",
          "link": "https://www.stepsecurity.io/blog/immobiliarelabs-npm-packages-compromised",
          "published": "2026-07-01",
          "sev": "high"
        }
      ],
      "first_seen": "2026-07-01"
    },
    {
      "value": "m.fasterxml.org",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "StepSecurity"
      ],
      "articles": [
        {
          "id": "art-328",
          "title": "Maven Support Comes to GitHub Checks and OSS Package Search",
          "link": "https://www.stepsecurity.io/blog/maven-support-comes-to-github-checks-and-oss-package-search",
          "published": "2026-07-01",
          "sev": "high"
        }
      ],
      "first_seen": "2026-07-01"
    },
    {
      "value": "103.127.243.82",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "StepSecurity"
      ],
      "articles": [
        {
          "id": "art-328",
          "title": "Maven Support Comes to GitHub Checks and OSS Package Search",
          "link": "https://www.stepsecurity.io/blog/maven-support-comes-to-github-checks-and-oss-package-search",
          "published": "2026-07-01",
          "sev": "high"
        }
      ],
      "first_seen": "2026-07-01"
    },
    {
      "value": "39.107.60.51",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "StepSecurity",
        "Aikido"
      ],
      "articles": [
        {
          "id": "art-332",
          "title": "15 Malicious JetBrains Plugins Stole AI API Keys from 70,000 Developers",
          "link": "https://www.stepsecurity.io/blog/jetbrains-malicious-plugins-ai-api-key-theft",
          "published": "2026-07-01",
          "sev": "high"
        },
        {
          "id": "art-374",
          "title": "Multiple JetBrains IDE plugins caught stealing AI keys",
          "link": "https://www.aikido.dev/blog/multiple-jetbrains-ide-plugins-caught-stealing-ai-keys",
          "published": "2026-06-16",
          "sev": "high"
        }
      ],
      "first_seen": "2026-07-01"
    },
    {
      "value": "54089e0f368fa9a7e2050de9b0db121a",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "StepSecurity"
      ],
      "articles": [
        {
          "id": "art-329",
          "title": "Mass npm Supply Chain Attack: 20 Leo Platform Packages Compromised",
          "link": "https://www.stepsecurity.io/blog/mass-npm-supply-chain-attack-20-leo-platform-packages-compromised",
          "published": "2026-07-01",
          "sev": "high"
        }
      ],
      "first_seen": "2026-07-01"
    },
    {
      "value": "ad9f0ecdbf6075f8cc4ca8bdd62bd27c",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "StepSecurity"
      ],
      "articles": [
        {
          "id": "art-329",
          "title": "Mass npm Supply Chain Attack: 20 Leo Platform Packages Compromised",
          "link": "https://www.stepsecurity.io/blog/mass-npm-supply-chain-attack-20-leo-platform-packages-compromised",
          "published": "2026-07-01",
          "sev": "high"
        }
      ],
      "first_seen": "2026-07-01"
    },
    {
      "value": "1a5a1445fcd73133f22a0e7895993ac0a42b56da",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "StepSecurity"
      ],
      "articles": [
        {
          "id": "art-329",
          "title": "Mass npm Supply Chain Attack: 20 Leo Platform Packages Compromised",
          "link": "https://www.stepsecurity.io/blog/mass-npm-supply-chain-attack-20-leo-platform-packages-compromised",
          "published": "2026-07-01",
          "sev": "high"
        }
      ],
      "first_seen": "2026-07-01"
    },
    {
      "value": "1dcc0a39e1cd7293a9058cfc41e1afe8b397c943",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "StepSecurity"
      ],
      "articles": [
        {
          "id": "art-329",
          "title": "Mass npm Supply Chain Attack: 20 Leo Platform Packages Compromised",
          "link": "https://www.stepsecurity.io/blog/mass-npm-supply-chain-attack-20-leo-platform-packages-compromised",
          "published": "2026-07-01",
          "sev": "high"
        }
      ],
      "first_seen": "2026-07-01"
    },
    {
      "value": "24a0d9e496ec07ca978fab602d5f5e0b39fa03a0",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "StepSecurity"
      ],
      "articles": [
        {
          "id": "art-329",
          "title": "Mass npm Supply Chain Attack: 20 Leo Platform Packages Compromised",
          "link": "https://www.stepsecurity.io/blog/mass-npm-supply-chain-attack-20-leo-platform-packages-compromised",
          "published": "2026-07-01",
          "sev": "high"
        }
      ],
      "first_seen": "2026-07-01"
    },
    {
      "value": "47d73156df1c767bb168c4309fd17b92324d587d",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "StepSecurity"
      ],
      "articles": [
        {
          "id": "art-329",
          "title": "Mass npm Supply Chain Attack: 20 Leo Platform Packages Compromised",
          "link": "https://www.stepsecurity.io/blog/mass-npm-supply-chain-attack-20-leo-platform-packages-compromised",
          "published": "2026-07-01",
          "sev": "high"
        }
      ],
      "first_seen": "2026-07-01"
    },
    {
      "value": "5792aba0e2180b9b80b77644370a6889d5817456",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "StepSecurity",
        "Aikido"
      ],
      "articles": [
        {
          "id": "art-330",
          "title": "simonecorsi/mawesome GitHub Action has been compromised",
          "link": "https://www.stepsecurity.io/blog/simonecorsi-mawesome-github-action-has-been-compromised",
          "published": "2026-07-01",
          "sev": "high"
        },
        {
          "id": "art-331",
          "title": "codfish/semantic-release-action GitHub Action has been compromised",
          "link": "https://www.stepsecurity.io/blog/supply-chain-compromise-codfish-semantic-release-action",
          "published": "2026-07-01",
          "sev": "high"
        },
        {
          "id": "art-349",
          "title": "Compromised GitHub action codfish/semantic-release-action steals CI/CD secrets",
          "link": "https://www.aikido.dev/blog/compromised-github-action-codfish-steals-secrets",
          "published": "2026-06-24",
          "sev": "high"
        }
      ],
      "first_seen": "2026-07-01"
    },
    {
      "value": "5e75c14b8acd5752819ab7a10874ddd6389f5238",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "StepSecurity"
      ],
      "articles": [
        {
          "id": "art-329",
          "title": "Mass npm Supply Chain Attack: 20 Leo Platform Packages Compromised",
          "link": "https://www.stepsecurity.io/blog/mass-npm-supply-chain-attack-20-leo-platform-packages-compromised",
          "published": "2026-07-01",
          "sev": "high"
        }
      ],
      "first_seen": "2026-07-01"
    },
    {
      "value": "68a1cd589b2ce322f5f03fe7f85dc3f176a759d4",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "StepSecurity"
      ],
      "articles": [
        {
          "id": "art-329",
          "title": "Mass npm Supply Chain Attack: 20 Leo Platform Packages Compromised",
          "link": "https://www.stepsecurity.io/blog/mass-npm-supply-chain-attack-20-leo-platform-packages-compromised",
          "published": "2026-07-01",
          "sev": "high"
        }
      ],
      "first_seen": "2026-07-01"
    },
    {
      "value": "809ce3680adfdb8f0746189b68b6b5a6888a960f",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "StepSecurity"
      ],
      "articles": [
        {
          "id": "art-329",
          "title": "Mass npm Supply Chain Attack: 20 Leo Platform Packages Compromised",
          "link": "https://www.stepsecurity.io/blog/mass-npm-supply-chain-attack-20-leo-platform-packages-compromised",
          "published": "2026-07-01",
          "sev": "high"
        }
      ],
      "first_seen": "2026-07-01"
    },
    {
      "value": "888094a9b842cfe98e8e24c8f729be1fb6384563",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "StepSecurity"
      ],
      "articles": [
        {
          "id": "art-329",
          "title": "Mass npm Supply Chain Attack: 20 Leo Platform Packages Compromised",
          "link": "https://www.stepsecurity.io/blog/mass-npm-supply-chain-attack-20-leo-platform-packages-compromised",
          "published": "2026-07-01",
          "sev": "high"
        }
      ],
      "first_seen": "2026-07-01"
    },
    {
      "value": "92221eb202e9f2ac577e5c33658c8a05c6d67556",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "StepSecurity"
      ],
      "articles": [
        {
          "id": "art-329",
          "title": "Mass npm Supply Chain Attack: 20 Leo Platform Packages Compromised",
          "link": "https://www.stepsecurity.io/blog/mass-npm-supply-chain-attack-20-leo-platform-packages-compromised",
          "published": "2026-07-01",
          "sev": "high"
        }
      ],
      "first_seen": "2026-07-01"
    },
    {
      "value": "9be49287057cd6a54ef4a70a8d541a7259efbd2d",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "StepSecurity"
      ],
      "articles": [
        {
          "id": "art-329",
          "title": "Mass npm Supply Chain Attack: 20 Leo Platform Packages Compromised",
          "link": "https://www.stepsecurity.io/blog/mass-npm-supply-chain-attack-20-leo-platform-packages-compromised",
          "published": "2026-07-01",
          "sev": "high"
        }
      ],
      "first_seen": "2026-07-01"
    },
    {
      "value": "a8cb86b78ca56befe90dc466642cb04b98079909",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "StepSecurity"
      ],
      "articles": [
        {
          "id": "art-329",
          "title": "Mass npm Supply Chain Attack: 20 Leo Platform Packages Compromised",
          "link": "https://www.stepsecurity.io/blog/mass-npm-supply-chain-attack-20-leo-platform-packages-compromised",
          "published": "2026-07-01",
          "sev": "high"
        }
      ],
      "first_seen": "2026-07-01"
    },
    {
      "value": "bcb6b1d409144318e8fad2171d6fe06d02299d1a",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "StepSecurity",
        "Aikido"
      ],
      "articles": [
        {
          "id": "art-330",
          "title": "simonecorsi/mawesome GitHub Action has been compromised",
          "link": "https://www.stepsecurity.io/blog/simonecorsi-mawesome-github-action-has-been-compromised",
          "published": "2026-07-01",
          "sev": "high"
        },
        {
          "id": "art-331",
          "title": "codfish/semantic-release-action GitHub Action has been compromised",
          "link": "https://www.stepsecurity.io/blog/supply-chain-compromise-codfish-semantic-release-action",
          "published": "2026-07-01",
          "sev": "high"
        },
        {
          "id": "art-349",
          "title": "Compromised GitHub action codfish/semantic-release-action steals CI/CD secrets",
          "link": "https://www.aikido.dev/blog/compromised-github-action-codfish-steals-secrets",
          "published": "2026-06-24",
          "sev": "high"
        }
      ],
      "first_seen": "2026-07-01"
    },
    {
      "value": "be3b1f7f1b50f5d53b164a72fb3a9845f4734325",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "StepSecurity"
      ],
      "articles": [
        {
          "id": "art-329",
          "title": "Mass npm Supply Chain Attack: 20 Leo Platform Packages Compromised",
          "link": "https://www.stepsecurity.io/blog/mass-npm-supply-chain-attack-20-leo-platform-packages-compromised",
          "published": "2026-07-01",
          "sev": "high"
        }
      ],
      "first_seen": "2026-07-01"
    },
    {
      "value": "be6bb1cf88c46e9e4a6f1a68ed001b77769d58de",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "StepSecurity"
      ],
      "articles": [
        {
          "id": "art-329",
          "title": "Mass npm Supply Chain Attack: 20 Leo Platform Packages Compromised",
          "link": "https://www.stepsecurity.io/blog/mass-npm-supply-chain-attack-20-leo-platform-packages-compromised",
          "published": "2026-07-01",
          "sev": "high"
        }
      ],
      "first_seen": "2026-07-01"
    },
    {
      "value": "d45ad3cffbcc7c4b354ebe9d71d002fa585379ec",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "StepSecurity"
      ],
      "articles": [
        {
          "id": "art-329",
          "title": "Mass npm Supply Chain Attack: 20 Leo Platform Packages Compromised",
          "link": "https://www.stepsecurity.io/blog/mass-npm-supply-chain-attack-20-leo-platform-packages-compromised",
          "published": "2026-07-01",
          "sev": "high"
        }
      ],
      "first_seen": "2026-07-01"
    },
    {
      "value": "d7224b6b1f5d2f9403f1cebc8f82518c20b4d0f7",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "StepSecurity"
      ],
      "articles": [
        {
          "id": "art-329",
          "title": "Mass npm Supply Chain Attack: 20 Leo Platform Packages Compromised",
          "link": "https://www.stepsecurity.io/blog/mass-npm-supply-chain-attack-20-leo-platform-packages-compromised",
          "published": "2026-07-01",
          "sev": "high"
        }
      ],
      "first_seen": "2026-07-01"
    },
    {
      "value": "e973173fb757d2dab9c6424b440dd9f7cbe4f14a",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "StepSecurity"
      ],
      "articles": [
        {
          "id": "art-329",
          "title": "Mass npm Supply Chain Attack: 20 Leo Platform Packages Compromised",
          "link": "https://www.stepsecurity.io/blog/mass-npm-supply-chain-attack-20-leo-platform-packages-compromised",
          "published": "2026-07-01",
          "sev": "high"
        }
      ],
      "first_seen": "2026-07-01"
    },
    {
      "value": "ed9a17d6567101fa4f9f552a4a52cfcca88fa662",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "StepSecurity"
      ],
      "articles": [
        {
          "id": "art-329",
          "title": "Mass npm Supply Chain Attack: 20 Leo Platform Packages Compromised",
          "link": "https://www.stepsecurity.io/blog/mass-npm-supply-chain-attack-20-leo-platform-packages-compromised",
          "published": "2026-07-01",
          "sev": "high"
        }
      ],
      "first_seen": "2026-07-01"
    },
    {
      "value": "ef8bf6dd92cbc29ef8d23f3f0fa786ed20a856b1",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "StepSecurity"
      ],
      "articles": [
        {
          "id": "art-329",
          "title": "Mass npm Supply Chain Attack: 20 Leo Platform Packages Compromised",
          "link": "https://www.stepsecurity.io/blog/mass-npm-supply-chain-attack-20-leo-platform-packages-compromised",
          "published": "2026-07-01",
          "sev": "high"
        }
      ],
      "first_seen": "2026-07-01"
    },
    {
      "value": "effa8576594fdd59907b5c5c07293ce28a9a3393",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "StepSecurity"
      ],
      "articles": [
        {
          "id": "art-329",
          "title": "Mass npm Supply Chain Attack: 20 Leo Platform Packages Compromised",
          "link": "https://www.stepsecurity.io/blog/mass-npm-supply-chain-attack-20-leo-platform-packages-compromised",
          "published": "2026-07-01",
          "sev": "high"
        }
      ],
      "first_seen": "2026-07-01"
    },
    {
      "value": "f03a3e0dca9ef402352ce61cad59e5d850744960",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "StepSecurity"
      ],
      "articles": [
        {
          "id": "art-329",
          "title": "Mass npm Supply Chain Attack: 20 Leo Platform Packages Compromised",
          "link": "https://www.stepsecurity.io/blog/mass-npm-supply-chain-attack-20-leo-platform-packages-compromised",
          "published": "2026-07-01",
          "sev": "high"
        }
      ],
      "first_seen": "2026-07-01"
    },
    {
      "value": "702161756dfd150ad3c214fbf97ce98fdc960ea7b3970b5300702ed8c953cafd",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "StepSecurity"
      ],
      "articles": [
        {
          "id": "art-328",
          "title": "Maven Support Comes to GitHub Checks and OSS Package Search",
          "link": "https://www.stepsecurity.io/blog/maven-support-comes-to-github-checks-and-oss-package-search",
          "published": "2026-07-01",
          "sev": "high"
        }
      ],
      "first_seen": "2026-07-01"
    },
    {
      "value": "8bce95ebfb895537fec243e069d7193980361de9d916339906b11a14ffded94f",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "StepSecurity"
      ],
      "articles": [
        {
          "id": "art-328",
          "title": "Maven Support Comes to GitHub Checks and OSS Package Search",
          "link": "https://www.stepsecurity.io/blog/maven-support-comes-to-github-checks-and-oss-package-search",
          "published": "2026-07-01",
          "sev": "high"
        }
      ],
      "first_seen": "2026-07-01"
    },
    {
      "value": "9f93d77d32833a515bc406c46da477142bb1ac2babeecb6aa42f98669a6db015",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "StepSecurity",
        "Aikido"
      ],
      "articles": [
        {
          "id": "art-330",
          "title": "simonecorsi/mawesome GitHub Action has been compromised",
          "link": "https://www.stepsecurity.io/blog/simonecorsi-mawesome-github-action-has-been-compromised",
          "published": "2026-07-01",
          "sev": "high"
        },
        {
          "id": "art-331",
          "title": "codfish/semantic-release-action GitHub Action has been compromised",
          "link": "https://www.stepsecurity.io/blog/supply-chain-compromise-codfish-semantic-release-action",
          "published": "2026-07-01",
          "sev": "high"
        },
        {
          "id": "art-349",
          "title": "Compromised GitHub action codfish/semantic-release-action steals CI/CD secrets",
          "link": "https://www.aikido.dev/blog/compromised-github-action-codfish-steals-secrets",
          "published": "2026-06-24",
          "sev": "high"
        }
      ],
      "first_seen": "2026-07-01"
    },
    {
      "value": "da39146ef451d1b174a24d00b1e2a45cd38d54e849737f8f35333dcb22175707",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "StepSecurity",
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-327",
          "title": "Multiple @immobiliarelabs Backstage Plugins Compromised on npm",
          "link": "https://www.stepsecurity.io/blog/immobiliarelabs-npm-packages-compromised",
          "published": "2026-07-01",
          "sev": "high"
        },
        {
          "id": "art-408",
          "title": "Node-gyp Supply Chain Compromise: A Self-Propagating npm Worm That Hides in binding.gyp",
          "link": "https://snyk.io/blog/node-gyp-supply-chain-compromise-self-propagating-npm-worm-binding-gyp/",
          "published": "2026-06-04",
          "sev": "high"
        }
      ],
      "first_seen": "2026-07-01"
    },
    {
      "value": "CVE-2026-48558",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-339",
          "title": "CISA KEV: CVE-2026-48558 \u2014 SimpleHelp Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-06-29",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-06-29"
    },
    {
      "value": "flipboxstudio.info",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "Aikido",
        "StepSecurity",
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-343",
          "title": "Packagist is now protected by Aikido Intel and other updates to the PHP registry",
          "link": "https://www.aikido.dev/blog/composer-protected-aikido-packagist",
          "published": "2026-06-26",
          "sev": "med"
        },
        {
          "id": "art-417",
          "title": "Laravel-Lang Supply Chain Attack: Every Tag Across Multiple Composer Packages Rewritten to Steal CI Secrets",
          "link": "https://www.stepsecurity.io/blog/laravel-lang-supply-chain-attack",
          "published": "2026-06-02",
          "sev": "high"
        },
        {
          "id": "art-445",
          "title": "Laravel Lang Supply Chain Advisory",
          "link": "https://snyk.io/blog/laravel-lang-supply-chain-advisory/",
          "published": "2026-05-23",
          "sev": "crit"
        },
        {
          "id": "art-446",
          "title": "Supply Chain Attack Targets Laravel-Lang Packages with Credential Stealer",
          "link": "https://www.aikido.dev/blog/supply-chain-attack-targets-laravel-lang-packages-with-credential-stealer",
          "published": "2026-05-23",
          "sev": "high"
        }
      ],
      "first_seen": "2026-06-26"
    },
    {
      "value": "hwsrv-1327785.hostwindsdns.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "Aikido",
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-340",
          "title": "npm now freezes high-impact accounts after risky account changes",
          "link": "https://www.aikido.dev/blog/npm-cooldown-account-changes-announcement",
          "published": "2026-06-26",
          "sev": "high"
        },
        {
          "id": "art-345",
          "title": "Everybody's shipping code they can't read",
          "link": "https://www.aikido.dev/blog/shipping-code-they-cant-read",
          "published": "2026-06-25",
          "sev": "high"
        },
        {
          "id": "art-373",
          "title": "A Forgotten Contributor Account Compromised the Entire Mastra npm Package Scope",
          "link": "https://snyk.io/blog/a-forgotten-contributor-account-compromised-the-entire-mastra-npm-package-scope/",
          "published": "2026-06-16",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-06-26"
    },
    {
      "value": "sfrclak.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "Aikido",
        "Snyk",
        "StepSecurity"
      ],
      "articles": [
        {
          "id": "art-340",
          "title": "npm now freezes high-impact accounts after risky account changes",
          "link": "https://www.aikido.dev/blog/npm-cooldown-account-changes-announcement",
          "published": "2026-06-26",
          "sev": "high"
        },
        {
          "id": "art-367",
          "title": "The full Snyk AI Security Platform, free for open source maintainers",
          "link": "https://snyk.io/blog/secure-developer-program/",
          "published": "2026-06-18",
          "sev": "high"
        },
        {
          "id": "art-385",
          "title": "npm v12 delivers one of the biggest security improvements in years",
          "link": "https://www.aikido.dev/blog/npm-v12-block-postinstall",
          "published": "2026-06-11",
          "sev": "high"
        },
        {
          "id": "art-390",
          "title": "Code is being written everywhere, and the device is the only constant",
          "link": "https://www.aikido.dev/blog/code-is-written-everywhere",
          "published": "2026-06-10",
          "sev": "high"
        },
        {
          "id": "art-415",
          "title": "Why EDR and proxy won\u2019t save you from supply chain malware",
          "link": "https://www.aikido.dev/blog/edr-proxy-wont-protect-supply-chain-malware",
          "published": "2026-06-02",
          "sev": "high"
        },
        {
          "id": "art-568",
          "title": "axios Compromised on npm - Malicious Versions Drop Remote Access Trojan",
          "link": "https://www.stepsecurity.io/blog/axios-compromised-on-npm-malicious-versions-drop-remote-access-trojan",
          "published": "2026-04-09",
          "sev": "crit"
        },
        {
          "id": "art-585",
          "title": "Axios npm Package Compromised: Supply Chain Attack Delivers Cross-Platform RAT",
          "link": "https://snyk.io/blog/axios-npm-package-compromised-supply-chain-attack-delivers-cross-platform/",
          "published": "2026-03-30",
          "sev": "high"
        }
      ],
      "first_seen": "2026-06-26"
    },
    {
      "value": "142.11.206.73",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "Aikido",
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-340",
          "title": "npm now freezes high-impact accounts after risky account changes",
          "link": "https://www.aikido.dev/blog/npm-cooldown-account-changes-announcement",
          "published": "2026-06-26",
          "sev": "high"
        },
        {
          "id": "art-367",
          "title": "The full Snyk AI Security Platform, free for open source maintainers",
          "link": "https://snyk.io/blog/secure-developer-program/",
          "published": "2026-06-18",
          "sev": "high"
        },
        {
          "id": "art-385",
          "title": "npm v12 delivers one of the biggest security improvements in years",
          "link": "https://www.aikido.dev/blog/npm-v12-block-postinstall",
          "published": "2026-06-11",
          "sev": "high"
        },
        {
          "id": "art-390",
          "title": "Code is being written everywhere, and the device is the only constant",
          "link": "https://www.aikido.dev/blog/code-is-written-everywhere",
          "published": "2026-06-10",
          "sev": "high"
        },
        {
          "id": "art-415",
          "title": "Why EDR and proxy won\u2019t save you from supply chain malware",
          "link": "https://www.aikido.dev/blog/edr-proxy-wont-protect-supply-chain-malware",
          "published": "2026-06-02",
          "sev": "high"
        },
        {
          "id": "art-585",
          "title": "Axios npm Package Compromised: Supply Chain Attack Delivers Cross-Platform RAT",
          "link": "https://snyk.io/blog/axios-npm-package-compromised-supply-chain-attack-delivers-cross-platform/",
          "published": "2026-03-30",
          "sev": "high"
        }
      ],
      "first_seen": "2026-06-26"
    },
    {
      "value": "07d889e2dadce6f3910dcbc253317d28ca61c766",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "Aikido",
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-340",
          "title": "npm now freezes high-impact accounts after risky account changes",
          "link": "https://www.aikido.dev/blog/npm-cooldown-account-changes-announcement",
          "published": "2026-06-26",
          "sev": "high"
        },
        {
          "id": "art-367",
          "title": "The full Snyk AI Security Platform, free for open source maintainers",
          "link": "https://snyk.io/blog/secure-developer-program/",
          "published": "2026-06-18",
          "sev": "high"
        },
        {
          "id": "art-385",
          "title": "npm v12 delivers one of the biggest security improvements in years",
          "link": "https://www.aikido.dev/blog/npm-v12-block-postinstall",
          "published": "2026-06-11",
          "sev": "high"
        },
        {
          "id": "art-390",
          "title": "Code is being written everywhere, and the device is the only constant",
          "link": "https://www.aikido.dev/blog/code-is-written-everywhere",
          "published": "2026-06-10",
          "sev": "high"
        },
        {
          "id": "art-415",
          "title": "Why EDR and proxy won\u2019t save you from supply chain malware",
          "link": "https://www.aikido.dev/blog/edr-proxy-wont-protect-supply-chain-malware",
          "published": "2026-06-02",
          "sev": "high"
        },
        {
          "id": "art-585",
          "title": "Axios npm Package Compromised: Supply Chain Attack Delivers Cross-Platform RAT",
          "link": "https://snyk.io/blog/axios-npm-package-compromised-supply-chain-attack-delivers-cross-platform/",
          "published": "2026-03-30",
          "sev": "high"
        }
      ],
      "first_seen": "2026-06-26"
    },
    {
      "value": "2553649f2322049666871cea80a5d0d6adc700ca",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "Aikido",
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-340",
          "title": "npm now freezes high-impact accounts after risky account changes",
          "link": "https://www.aikido.dev/blog/npm-cooldown-account-changes-announcement",
          "published": "2026-06-26",
          "sev": "high"
        },
        {
          "id": "art-385",
          "title": "npm v12 delivers one of the biggest security improvements in years",
          "link": "https://www.aikido.dev/blog/npm-v12-block-postinstall",
          "published": "2026-06-11",
          "sev": "high"
        },
        {
          "id": "art-390",
          "title": "Code is being written everywhere, and the device is the only constant",
          "link": "https://www.aikido.dev/blog/code-is-written-everywhere",
          "published": "2026-06-10",
          "sev": "high"
        },
        {
          "id": "art-415",
          "title": "Why EDR and proxy won\u2019t save you from supply chain malware",
          "link": "https://www.aikido.dev/blog/edr-proxy-wont-protect-supply-chain-malware",
          "published": "2026-06-02",
          "sev": "high"
        },
        {
          "id": "art-585",
          "title": "Axios npm Package Compromised: Supply Chain Attack Delivers Cross-Platform RAT",
          "link": "https://snyk.io/blog/axios-npm-package-compromised-supply-chain-attack-delivers-cross-platform/",
          "published": "2026-03-30",
          "sev": "high"
        }
      ],
      "first_seen": "2026-06-26"
    },
    {
      "value": "d6f3f62fd3b9f5432f5782b62d8cfd5247d5ee71",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "Aikido",
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-340",
          "title": "npm now freezes high-impact accounts after risky account changes",
          "link": "https://www.aikido.dev/blog/npm-cooldown-account-changes-announcement",
          "published": "2026-06-26",
          "sev": "high"
        },
        {
          "id": "art-367",
          "title": "The full Snyk AI Security Platform, free for open source maintainers",
          "link": "https://snyk.io/blog/secure-developer-program/",
          "published": "2026-06-18",
          "sev": "high"
        },
        {
          "id": "art-385",
          "title": "npm v12 delivers one of the biggest security improvements in years",
          "link": "https://www.aikido.dev/blog/npm-v12-block-postinstall",
          "published": "2026-06-11",
          "sev": "high"
        },
        {
          "id": "art-390",
          "title": "Code is being written everywhere, and the device is the only constant",
          "link": "https://www.aikido.dev/blog/code-is-written-everywhere",
          "published": "2026-06-10",
          "sev": "high"
        },
        {
          "id": "art-415",
          "title": "Why EDR and proxy won\u2019t save you from supply chain malware",
          "link": "https://www.aikido.dev/blog/edr-proxy-wont-protect-supply-chain-malware",
          "published": "2026-06-02",
          "sev": "high"
        },
        {
          "id": "art-585",
          "title": "Axios npm Package Compromised: Supply Chain Attack Delivers Cross-Platform RAT",
          "link": "https://snyk.io/blog/axios-npm-package-compromised-supply-chain-attack-delivers-cross-platform/",
          "published": "2026-03-30",
          "sev": "high"
        }
      ],
      "first_seen": "2026-06-26"
    },
    {
      "value": "CVE-2025-8088",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "ESET WeLiveSecurity",
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-344",
          "title": "Gamaredon in 2025: Leveraging tunnels, workers, dead drops, and new alliances",
          "link": "https://www.welivesecurity.com/en/eset-research/gamaredon-2025-leveraging-tunnels-workers-dead-drops-new-alliances/",
          "published": "2026-06-25",
          "sev": "high"
        },
        {
          "id": "art-900",
          "title": "CISA KEV: CVE-2025-8088 \u2014 RARLAB WinRAR Path Traversal Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-08-12",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-06-25"
    },
    {
      "value": "CVE-2026-20230",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-348",
          "title": "CISA KEV: CVE-2026-20230 \u2014 Cisco Unified Communications Manager Server-Side Request Forgery (SSRF) Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-06-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-06-25"
    },
    {
      "value": "CVE-2026-4681",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-347",
          "title": "CISA KEV: CVE-2026-12569 \u2014 PTC Windchill and FlexPLM Improper Input Validation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-06-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-06-25"
    },
    {
      "value": "hwsrv-1327786.hostwindsdns.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "Aikido",
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-345",
          "title": "Everybody's shipping code they can't read",
          "link": "https://www.aikido.dev/blog/shipping-code-they-cant-read",
          "published": "2026-06-25",
          "sev": "high"
        },
        {
          "id": "art-373",
          "title": "A Forgotten Contributor Account Compromised the Entire Mastra npm Package Scope",
          "link": "https://snyk.io/blog/a-forgotten-contributor-account-compromised-the-entire-mastra-npm-package-scope/",
          "published": "2026-06-16",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-06-25"
    },
    {
      "value": "104.194.9.14",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-347",
          "title": "CISA KEV: CVE-2026-12569 \u2014 PTC Windchill and FlexPLM Improper Input Validation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-06-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-06-25"
    },
    {
      "value": "104.243.35.131",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-347",
          "title": "CISA KEV: CVE-2026-12569 \u2014 PTC Windchill and FlexPLM Improper Input Validation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-06-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-06-25"
    },
    {
      "value": "172.111.38.31",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-347",
          "title": "CISA KEV: CVE-2026-12569 \u2014 PTC Windchill and FlexPLM Improper Input Validation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-06-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-06-25"
    },
    {
      "value": "185.227.83.236",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-347",
          "title": "CISA KEV: CVE-2026-12569 \u2014 PTC Windchill and FlexPLM Improper Input Validation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-06-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-06-25"
    },
    {
      "value": "209.222.98.44",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-347",
          "title": "CISA KEV: CVE-2026-12569 \u2014 PTC Windchill and FlexPLM Improper Input Validation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-06-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-06-25"
    },
    {
      "value": "38.60.157.212",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-347",
          "title": "CISA KEV: CVE-2026-12569 \u2014 PTC Windchill and FlexPLM Improper Input Validation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-06-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-06-25"
    },
    {
      "value": "74.50.76.146",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-347",
          "title": "CISA KEV: CVE-2026-12569 \u2014 PTC Windchill and FlexPLM Improper Input Validation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-06-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-06-25"
    },
    {
      "value": "78.128.113.10",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-347",
          "title": "CISA KEV: CVE-2026-12569 \u2014 PTC Windchill and FlexPLM Improper Input Validation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-06-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-06-25"
    },
    {
      "value": "9570f77a5e1511869f4e554e7166df9fde081f2583e293c2569621792ed7d9c9",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "Aikido",
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-345",
          "title": "Everybody's shipping code they can't read",
          "link": "https://www.aikido.dev/blog/shipping-code-they-cant-read",
          "published": "2026-06-25",
          "sev": "high"
        },
        {
          "id": "art-373",
          "title": "A Forgotten Contributor Account Compromised the Entire Mastra npm Package Scope",
          "link": "https://snyk.io/blog/a-forgotten-contributor-account-compromised-the-entire-mastra-npm-package-scope/",
          "published": "2026-06-16",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-06-25"
    },
    {
      "value": "c38954e85bf5433e61e7c8f4230336695624ae88b6953afabf7bf817aa91b638",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "Aikido",
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-345",
          "title": "Everybody's shipping code they can't read",
          "link": "https://www.aikido.dev/blog/shipping-code-they-cant-read",
          "published": "2026-06-25",
          "sev": "high"
        },
        {
          "id": "art-373",
          "title": "A Forgotten Contributor Account Compromised the Entire Mastra npm Package Scope",
          "link": "https://snyk.io/blog/a-forgotten-contributor-account-compromised-the-entire-mastra-npm-package-scope/",
          "published": "2026-06-16",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-06-25"
    },
    {
      "value": "cdec8b20338beb708b5be8d3d7a3041a35a8b0fb92f9186262f312d55ff82066",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "Aikido",
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-345",
          "title": "Everybody's shipping code they can't read",
          "link": "https://www.aikido.dev/blog/shipping-code-they-cant-read",
          "published": "2026-06-25",
          "sev": "high"
        },
        {
          "id": "art-373",
          "title": "A Forgotten Contributor Account Compromised the Entire Mastra npm Package Scope",
          "link": "https://snyk.io/blog/a-forgotten-contributor-account-compromised-the-entire-mastra-npm-package-scope/",
          "published": "2026-06-16",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-06-25"
    },
    {
      "value": "wbound.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "ESET WeLiveSecurity"
      ],
      "articles": [
        {
          "id": "art-351",
          "title": "ESET takes part in Operation Endgame to disrupt Amadey and Stealc",
          "link": "https://www.welivesecurity.com/en/eset-research/eset-takes-part-operation-endgame-disrupt-amadey-stealc/",
          "published": "2026-06-24",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-06-24"
    },
    {
      "value": "176.111.174.140",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "ESET WeLiveSecurity"
      ],
      "articles": [
        {
          "id": "art-351",
          "title": "ESET takes part in Operation Endgame to disrupt Amadey and Stealc",
          "link": "https://www.welivesecurity.com/en/eset-research/eset-takes-part-operation-endgame-disrupt-amadey-stealc/",
          "published": "2026-06-24",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-06-24"
    },
    {
      "value": "176.124.199.207",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "ESET WeLiveSecurity"
      ],
      "articles": [
        {
          "id": "art-351",
          "title": "ESET takes part in Operation Endgame to disrupt Amadey and Stealc",
          "link": "https://www.welivesecurity.com/en/eset-research/eset-takes-part-operation-endgame-disrupt-amadey-stealc/",
          "published": "2026-06-24",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-06-24"
    },
    {
      "value": "188.114.96.1",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "ESET WeLiveSecurity"
      ],
      "articles": [
        {
          "id": "art-351",
          "title": "ESET takes part in Operation Endgame to disrupt Amadey and Stealc",
          "link": "https://www.welivesecurity.com/en/eset-research/eset-takes-part-operation-endgame-disrupt-amadey-stealc/",
          "published": "2026-06-24",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-06-24"
    },
    {
      "value": "193.156.1.16",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "ESET WeLiveSecurity"
      ],
      "articles": [
        {
          "id": "art-351",
          "title": "ESET takes part in Operation Endgame to disrupt Amadey and Stealc",
          "link": "https://www.welivesecurity.com/en/eset-research/eset-takes-part-operation-endgame-disrupt-amadey-stealc/",
          "published": "2026-06-24",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-06-24"
    },
    {
      "value": "194.26.192.191",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "ESET WeLiveSecurity"
      ],
      "articles": [
        {
          "id": "art-351",
          "title": "ESET takes part in Operation Endgame to disrupt Amadey and Stealc",
          "link": "https://www.welivesecurity.com/en/eset-research/eset-takes-part-operation-endgame-disrupt-amadey-stealc/",
          "published": "2026-06-24",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-06-24"
    },
    {
      "value": "196.251.107.130",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "ESET WeLiveSecurity"
      ],
      "articles": [
        {
          "id": "art-351",
          "title": "ESET takes part in Operation Endgame to disrupt Amadey and Stealc",
          "link": "https://www.welivesecurity.com/en/eset-research/eset-takes-part-operation-endgame-disrupt-amadey-stealc/",
          "published": "2026-06-24",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-06-24"
    },
    {
      "value": "62.60.226.159",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "ESET WeLiveSecurity"
      ],
      "articles": [
        {
          "id": "art-351",
          "title": "ESET takes part in Operation Endgame to disrupt Amadey and Stealc",
          "link": "https://www.welivesecurity.com/en/eset-research/eset-takes-part-operation-endgame-disrupt-amadey-stealc/",
          "published": "2026-06-24",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-06-24"
    },
    {
      "value": "64.188.91.237",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "ESET WeLiveSecurity"
      ],
      "articles": [
        {
          "id": "art-351",
          "title": "ESET takes part in Operation Endgame to disrupt Amadey and Stealc",
          "link": "https://www.welivesecurity.com/en/eset-research/eset-takes-part-operation-endgame-disrupt-amadey-stealc/",
          "published": "2026-06-24",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-06-24"
    },
    {
      "value": "94.154.35.25",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "ESET WeLiveSecurity"
      ],
      "articles": [
        {
          "id": "art-351",
          "title": "ESET takes part in Operation Endgame to disrupt Amadey and Stealc",
          "link": "https://www.welivesecurity.com/en/eset-research/eset-takes-part-operation-endgame-disrupt-amadey-stealc/",
          "published": "2026-06-24",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-06-24"
    },
    {
      "value": "95.85.238.4",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "ESET WeLiveSecurity"
      ],
      "articles": [
        {
          "id": "art-351",
          "title": "ESET takes part in Operation Endgame to disrupt Amadey and Stealc",
          "link": "https://www.welivesecurity.com/en/eset-research/eset-takes-part-operation-endgame-disrupt-amadey-stealc/",
          "published": "2026-06-24",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-06-24"
    },
    {
      "value": "CVE-2025-67038",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-357",
          "title": "CISA KEV: CVE-2025-67038 \u2014 Lantronix EDS5000 Code Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-06-23",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-06-23"
    },
    {
      "value": "CVE-2026-34908",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-358",
          "title": "CISA KEV: CVE-2026-34910 \u2014 Ubiquiti UniFi OS Improper Input Validation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-06-23",
          "sev": "crit"
        },
        {
          "id": "art-359",
          "title": "CISA KEV: CVE-2026-34909 \u2014 Ubiquiti UniFi OS Path Traversal Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-06-23",
          "sev": "crit"
        },
        {
          "id": "art-360",
          "title": "CISA KEV: CVE-2026-34908 \u2014 Ubiquiti UniFi OS Improper Access Control Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-06-23",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-06-23"
    },
    {
      "value": "CVE-2026-34909",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-358",
          "title": "CISA KEV: CVE-2026-34910 \u2014 Ubiquiti UniFi OS Improper Input Validation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-06-23",
          "sev": "crit"
        },
        {
          "id": "art-359",
          "title": "CISA KEV: CVE-2026-34909 \u2014 Ubiquiti UniFi OS Path Traversal Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-06-23",
          "sev": "crit"
        },
        {
          "id": "art-360",
          "title": "CISA KEV: CVE-2026-34908 \u2014 Ubiquiti UniFi OS Improper Access Control Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-06-23",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-06-23"
    },
    {
      "value": "CVE-2026-34910",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-358",
          "title": "CISA KEV: CVE-2026-34910 \u2014 Ubiquiti UniFi OS Improper Input Validation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-06-23",
          "sev": "crit"
        },
        {
          "id": "art-359",
          "title": "CISA KEV: CVE-2026-34909 \u2014 Ubiquiti UniFi OS Path Traversal Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-06-23",
          "sev": "crit"
        },
        {
          "id": "art-360",
          "title": "CISA KEV: CVE-2026-34908 \u2014 Ubiquiti UniFi OS Improper Access Control Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-06-23",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-06-23"
    },
    {
      "value": "154.219.113.56",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-357",
          "title": "CISA KEV: CVE-2025-67038 \u2014 Lantronix EDS5000 Code Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-06-23",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-06-23"
    },
    {
      "value": "160.238.37.28",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-357",
          "title": "CISA KEV: CVE-2025-67038 \u2014 Lantronix EDS5000 Code Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-06-23",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-06-23"
    },
    {
      "value": "218.13.42.36",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-357",
          "title": "CISA KEV: CVE-2025-67038 \u2014 Lantronix EDS5000 Code Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-06-23",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-06-23"
    },
    {
      "value": "38.180.201.49",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-357",
          "title": "CISA KEV: CVE-2025-67038 \u2014 Lantronix EDS5000 Code Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-06-23",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-06-23"
    },
    {
      "value": "38.207.136.2",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-357",
          "title": "CISA KEV: CVE-2025-67038 \u2014 Lantronix EDS5000 Code Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-06-23",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-06-23"
    },
    {
      "value": "59.124.166.52",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-357",
          "title": "CISA KEV: CVE-2025-67038 \u2014 Lantronix EDS5000 Code Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-06-23",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-06-23"
    },
    {
      "value": "6328567511d88fdc2ae0939c5ef17b7a63d2a833881900de018a4f12f4982525",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "SentinelLabs"
      ],
      "articles": [
        {
          "id": "art-352",
          "title": "macOS.Gaslight | Rust Backdoor Turns Prompt Injection on the Analyst, Not the Sandbox",
          "link": "https://www.sentinelone.com/labs/macos-gaslight-rust-backdoor-turns-prompt-injection-on-the-analyst-not-the-sandbox/",
          "published": "2026-06-23",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-06-23"
    },
    {
      "value": "77b4fd46994992f0e57302cfe76ed23c0d90101381d2b89fc2ddf5c4536e77ca",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "SentinelLabs"
      ],
      "articles": [
        {
          "id": "art-352",
          "title": "macOS.Gaslight | Rust Backdoor Turns Prompt Injection on the Analyst, Not the Sandbox",
          "link": "https://www.sentinelone.com/labs/macos-gaslight-rust-backdoor-turns-prompt-injection-on-the-analyst-not-the-sandbox/",
          "published": "2026-06-23",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-06-23"
    },
    {
      "value": "b3c56d689414343589f38394d19ba2fe9a518133281200faa0556ba4e4136394",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "SentinelLabs"
      ],
      "articles": [
        {
          "id": "art-352",
          "title": "macOS.Gaslight | Rust Backdoor Turns Prompt Injection on the Analyst, Not the Sandbox",
          "link": "https://www.sentinelone.com/labs/macos-gaslight-rust-backdoor-turns-prompt-injection-on-the-analyst-not-the-sandbox/",
          "published": "2026-06-23",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-06-23"
    },
    {
      "value": "baabf249c77bc54c54ab0e66e15af798bd28aa5b4683554456a8b73ab8741239",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "SentinelLabs"
      ],
      "articles": [
        {
          "id": "art-352",
          "title": "macOS.Gaslight | Rust Backdoor Turns Prompt Injection on the Analyst, Not the Sandbox",
          "link": "https://www.sentinelone.com/labs/macos-gaslight-rust-backdoor-turns-prompt-injection-on-the-analyst-not-the-sandbox/",
          "published": "2026-06-23",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-06-23"
    },
    {
      "value": "138.226.246.94",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-356",
          "title": "When a vendor's breach becomes yours: lessons from the Klue incident",
          "link": "https://snyk.io/blog/when-a-vendors-breach-becomes-yours-lessons-from-the-klue-incident/",
          "published": "2026-06-23",
          "sev": "high"
        }
      ],
      "first_seen": "2026-06-23"
    },
    {
      "value": "212.86.125.24",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-356",
          "title": "When a vendor's breach becomes yours: lessons from the Klue incident",
          "link": "https://snyk.io/blog/when-a-vendors-breach-becomes-yours-lessons-from-the-klue-incident/",
          "published": "2026-06-23",
          "sev": "high"
        }
      ],
      "first_seen": "2026-06-23"
    },
    {
      "value": "213.111.148.90",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-356",
          "title": "When a vendor's breach becomes yours: lessons from the Klue incident",
          "link": "https://snyk.io/blog/when-a-vendors-breach-becomes-yours-lessons-from-the-klue-incident/",
          "published": "2026-06-23",
          "sev": "high"
        }
      ],
      "first_seen": "2026-06-23"
    },
    {
      "value": "94.154.32.160",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-356",
          "title": "When a vendor's breach becomes yours: lessons from the Klue incident",
          "link": "https://snyk.io/blog/when-a-vendors-breach-becomes-yours-lessons-from-the-klue-incident/",
          "published": "2026-06-23",
          "sev": "high"
        }
      ],
      "first_seen": "2026-06-23"
    },
    {
      "value": "CVE-2026-20253",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-368",
          "title": "CISA KEV: CVE-2026-20253 \u2014 Splunk Enterprise Missing Authentication for Critical Function Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-06-18",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-06-18"
    },
    {
      "value": "github.com/fardewoak/nodejs-argo",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "StepSecurity"
      ],
      "articles": [
        {
          "id": "art-364",
          "title": "400+ AUR Packages Hijacked: What the \u201cAtomic Arch\u201d Campaign Means for Supply-Chain Security",
          "link": "https://www.stepsecurity.io/blog/400-aur-packages-hijacked-atomic-arch-campaign",
          "published": "2026-06-18",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-06-18"
    },
    {
      "value": "temp.sh",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "StepSecurity"
      ],
      "articles": [
        {
          "id": "art-364",
          "title": "400+ AUR Packages Hijacked: What the \u201cAtomic Arch\u201d Campaign Means for Supply-Chain Security",
          "link": "https://www.stepsecurity.io/blog/400-aur-packages-hijacked-atomic-arch-campaign",
          "published": "2026-06-18",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-06-18"
    },
    {
      "value": "7069e28a5806db4ab0273639667d203f5e31b401d403af7e36d9f360c1f6d655",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "StepSecurity",
        "Aikido"
      ],
      "articles": [
        {
          "id": "art-365",
          "title": "Miasma and Hades Are Spreading Now: Detect Them on Developer Machines with Suspicious Files",
          "link": "https://www.stepsecurity.io/blog/miasma-and-hades-are-spreading-now-detect-them-on-developer-machines-with-suspicious-files",
          "published": "2026-06-18",
          "sev": "high"
        },
        {
          "id": "art-425",
          "title": "Red Hat npm Packages Compromised to Spread a Credential-Stealing Worm",
          "link": "https://www.aikido.dev/blog/red-hat-npm-packages-compromised-credential-stealing-worm",
          "published": "2026-06-01",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-06-18"
    },
    {
      "value": "b86c5ae9e95bd841a595440faa3eb6317441e746f241ae8fd641ab59ed1d1966",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "StepSecurity",
        "Aikido"
      ],
      "articles": [
        {
          "id": "art-365",
          "title": "Miasma and Hades Are Spreading Now: Detect Them on Developer Machines with Suspicious Files",
          "link": "https://www.stepsecurity.io/blog/miasma-and-hades-are-spreading-now-detect-them-on-developer-machines-with-suspicious-files",
          "published": "2026-06-18",
          "sev": "high"
        },
        {
          "id": "art-425",
          "title": "Red Hat npm Packages Compromised to Spread a Credential-Stealing Worm",
          "link": "https://www.aikido.dev/blog/red-hat-npm-packages-compromised-credential-stealing-worm",
          "published": "2026-06-01",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-06-18"
    },
    {
      "value": "c539766062555d47716f8432e73adbe3a0c0c954a0b6c4005017a668975e275c",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "StepSecurity"
      ],
      "articles": [
        {
          "id": "art-365",
          "title": "Miasma and Hades Are Spreading Now: Detect Them on Developer Machines with Suspicious Files",
          "link": "https://www.stepsecurity.io/blog/miasma-and-hades-are-spreading-now-detect-them-on-developer-machines-with-suspicious-files",
          "published": "2026-06-18",
          "sev": "high"
        }
      ],
      "first_seen": "2026-06-18"
    },
    {
      "value": "dc48b09b2a5954f7ff79ab8a2fd80202bd3b59c08c7cdbc6025aa923cb4c0efe",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "StepSecurity"
      ],
      "articles": [
        {
          "id": "art-365",
          "title": "Miasma and Hades Are Spreading Now: Detect Them on Developer Machines with Suspicious Files",
          "link": "https://www.stepsecurity.io/blog/miasma-and-hades-are-spreading-now-detect-them-on-developer-machines-with-suspicious-files",
          "published": "2026-06-18",
          "sev": "high"
        }
      ],
      "first_seen": "2026-06-18"
    },
    {
      "value": "e1342a80d4b5e83d2c7c22e1e0aaa95f2d88e3dbf0d853a4994b180c93a4b17d",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "StepSecurity"
      ],
      "articles": [
        {
          "id": "art-365",
          "title": "Miasma and Hades Are Spreading Now: Detect Them on Developer Machines with Suspicious Files",
          "link": "https://www.stepsecurity.io/blog/miasma-and-hades-are-spreading-now-detect-them-on-developer-machines-with-suspicious-files",
          "published": "2026-06-18",
          "sev": "high"
        }
      ],
      "first_seen": "2026-06-18"
    },
    {
      "value": "f7d335205b8d7b20208fb3ef93ee6dc817905dc3ae0c10a0b164f4e7d07121cd",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-367",
          "title": "The full Snyk AI Security Platform, free for open source maintainers",
          "link": "https://snyk.io/blog/secure-developer-program/",
          "published": "2026-06-18",
          "sev": "high"
        }
      ],
      "first_seen": "2026-06-18"
    },
    {
      "value": "CVE-2026-48907",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-376",
          "title": "CISA KEV: CVE-2026-48907 \u2014 Widget Factory Joomla Content Editor Improper Access Control Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-06-16",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-06-16"
    },
    {
      "value": "107.149.130.5",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-376",
          "title": "CISA KEV: CVE-2026-48907 \u2014 Widget Factory Joomla Content Editor Improper Access Control Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-06-16",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-06-16"
    },
    {
      "value": "45.153.129.241",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-376",
          "title": "CISA KEV: CVE-2026-48907 \u2014 Widget Factory Joomla Content Editor Improper Access Control Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-06-16",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-06-16"
    },
    {
      "value": "92.38.150.143",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-376",
          "title": "CISA KEV: CVE-2026-48907 \u2014 Widget Factory Joomla Content Editor Improper Access Control Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-06-16",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-06-16"
    },
    {
      "value": "CVE-2023-24932",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "med",
      "sources": [
        "ESET WeLiveSecurity"
      ],
      "articles": [
        {
          "id": "art-375",
          "title": "FishMonger\u2019s arsenal upgraded: SprySOCKS for Windows",
          "link": "https://www.welivesecurity.com/en/eset-research/fishmongers-arsenal-upgraded-sprysocks-windows/",
          "published": "2026-06-16",
          "sev": "med"
        }
      ],
      "first_seen": "2026-06-16"
    },
    {
      "value": "207.148.75.122",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "med",
      "sources": [
        "ESET WeLiveSecurity"
      ],
      "articles": [
        {
          "id": "art-375",
          "title": "FishMonger\u2019s arsenal upgraded: SprySOCKS for Windows",
          "link": "https://www.welivesecurity.com/en/eset-research/fishmongers-arsenal-upgraded-sprysocks-windows/",
          "published": "2026-06-16",
          "sev": "med"
        }
      ],
      "first_seen": "2026-06-16"
    },
    {
      "value": "207.148.78.36",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "med",
      "sources": [
        "ESET WeLiveSecurity"
      ],
      "articles": [
        {
          "id": "art-375",
          "title": "FishMonger\u2019s arsenal upgraded: SprySOCKS for Windows",
          "link": "https://www.welivesecurity.com/en/eset-research/fishmongers-arsenal-upgraded-sprysocks-windows/",
          "published": "2026-06-16",
          "sev": "med"
        }
      ],
      "first_seen": "2026-06-16"
    },
    {
      "value": "037DB2445F3D72388CB2CF8510563148E5A184BE",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "med",
      "sources": [
        "ESET WeLiveSecurity"
      ],
      "articles": [
        {
          "id": "art-375",
          "title": "FishMonger\u2019s arsenal upgraded: SprySOCKS for Windows",
          "link": "https://www.welivesecurity.com/en/eset-research/fishmongers-arsenal-upgraded-sprysocks-windows/",
          "published": "2026-06-16",
          "sev": "med"
        }
      ],
      "first_seen": "2026-06-16"
    },
    {
      "value": "2457EED2AB28E37741F10914EF929DAD2C8079D4",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "med",
      "sources": [
        "ESET WeLiveSecurity"
      ],
      "articles": [
        {
          "id": "art-375",
          "title": "FishMonger\u2019s arsenal upgraded: SprySOCKS for Windows",
          "link": "https://www.welivesecurity.com/en/eset-research/fishmongers-arsenal-upgraded-sprysocks-windows/",
          "published": "2026-06-16",
          "sev": "med"
        }
      ],
      "first_seen": "2026-06-16"
    },
    {
      "value": "44DC4A08C5EB0972C8E18B0E01284E06F09006BB",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "med",
      "sources": [
        "ESET WeLiveSecurity"
      ],
      "articles": [
        {
          "id": "art-375",
          "title": "FishMonger\u2019s arsenal upgraded: SprySOCKS for Windows",
          "link": "https://www.welivesecurity.com/en/eset-research/fishmongers-arsenal-upgraded-sprysocks-windows/",
          "published": "2026-06-16",
          "sev": "med"
        }
      ],
      "first_seen": "2026-06-16"
    },
    {
      "value": "5F3B87CEF56683D9A9E19186E0FD0D8019B559C4",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "med",
      "sources": [
        "ESET WeLiveSecurity"
      ],
      "articles": [
        {
          "id": "art-375",
          "title": "FishMonger\u2019s arsenal upgraded: SprySOCKS for Windows",
          "link": "https://www.welivesecurity.com/en/eset-research/fishmongers-arsenal-upgraded-sprysocks-windows/",
          "published": "2026-06-16",
          "sev": "med"
        }
      ],
      "first_seen": "2026-06-16"
    },
    {
      "value": "621D1952839BE4B0A1B0E66E87BCE5062CA368ED",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "med",
      "sources": [
        "ESET WeLiveSecurity"
      ],
      "articles": [
        {
          "id": "art-375",
          "title": "FishMonger\u2019s arsenal upgraded: SprySOCKS for Windows",
          "link": "https://www.welivesecurity.com/en/eset-research/fishmongers-arsenal-upgraded-sprysocks-windows/",
          "published": "2026-06-16",
          "sev": "med"
        }
      ],
      "first_seen": "2026-06-16"
    },
    {
      "value": "6490B8E4AADE25A3EE2DA9A47F312DB2122470BC",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "med",
      "sources": [
        "ESET WeLiveSecurity"
      ],
      "articles": [
        {
          "id": "art-375",
          "title": "FishMonger\u2019s arsenal upgraded: SprySOCKS for Windows",
          "link": "https://www.welivesecurity.com/en/eset-research/fishmongers-arsenal-upgraded-sprysocks-windows/",
          "published": "2026-06-16",
          "sev": "med"
        }
      ],
      "first_seen": "2026-06-16"
    },
    {
      "value": "955BFC3DCC867256F9F46A606DEB0779FA3416D8",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "med",
      "sources": [
        "ESET WeLiveSecurity"
      ],
      "articles": [
        {
          "id": "art-375",
          "title": "FishMonger\u2019s arsenal upgraded: SprySOCKS for Windows",
          "link": "https://www.welivesecurity.com/en/eset-research/fishmongers-arsenal-upgraded-sprysocks-windows/",
          "published": "2026-06-16",
          "sev": "med"
        }
      ],
      "first_seen": "2026-06-16"
    },
    {
      "value": "AB87B29B6F79487C75CA08D102E79001E536F083",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "med",
      "sources": [
        "ESET WeLiveSecurity"
      ],
      "articles": [
        {
          "id": "art-375",
          "title": "FishMonger\u2019s arsenal upgraded: SprySOCKS for Windows",
          "link": "https://www.welivesecurity.com/en/eset-research/fishmongers-arsenal-upgraded-sprysocks-windows/",
          "published": "2026-06-16",
          "sev": "med"
        }
      ],
      "first_seen": "2026-06-16"
    },
    {
      "value": "C793CA31E3F6628B5C8986146953BF66232E9A30",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "med",
      "sources": [
        "ESET WeLiveSecurity"
      ],
      "articles": [
        {
          "id": "art-375",
          "title": "FishMonger\u2019s arsenal upgraded: SprySOCKS for Windows",
          "link": "https://www.welivesecurity.com/en/eset-research/fishmongers-arsenal-upgraded-sprysocks-windows/",
          "published": "2026-06-16",
          "sev": "med"
        }
      ],
      "first_seen": "2026-06-16"
    },
    {
      "value": "D2C706B1EAF662BF0CE124B5032F73ED84BDA24A",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "med",
      "sources": [
        "ESET WeLiveSecurity"
      ],
      "articles": [
        {
          "id": "art-375",
          "title": "FishMonger\u2019s arsenal upgraded: SprySOCKS for Windows",
          "link": "https://www.welivesecurity.com/en/eset-research/fishmongers-arsenal-upgraded-sprysocks-windows/",
          "published": "2026-06-16",
          "sev": "med"
        }
      ],
      "first_seen": "2026-06-16"
    },
    {
      "value": "E7484C24B88A1A2407A8F09D734F9A993670285B",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "med",
      "sources": [
        "ESET WeLiveSecurity"
      ],
      "articles": [
        {
          "id": "art-375",
          "title": "FishMonger\u2019s arsenal upgraded: SprySOCKS for Windows",
          "link": "https://www.welivesecurity.com/en/eset-research/fishmongers-arsenal-upgraded-sprysocks-windows/",
          "published": "2026-06-16",
          "sev": "med"
        }
      ],
      "first_seen": "2026-06-16"
    },
    {
      "value": "CVE-2026-20262",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-380",
          "title": "CISA KEV: CVE-2026-20262 \u2014 Cisco Catalyst SD-WAN Manager Directory or Path Traversal Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-06-15",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-06-15"
    },
    {
      "value": "CVE-2026-54420",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-379",
          "title": "CISA KEV: CVE-2026-54420 \u2014 LiteSpeed cPanel Plugin UNIX Symbolic Link (Symlink) Following Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-06-15",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-06-15"
    },
    {
      "value": "authdocspro.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "ESET WeLiveSecurity"
      ],
      "articles": [
        {
          "id": "art-377",
          "title": "EvilTokens: A phishing attack that doesn\u2019t steal your password",
          "link": "https://www.welivesecurity.com/en/cybercrime/eviltokens-phishing-doesnt-steal-password/",
          "published": "2026-06-15",
          "sev": "high"
        }
      ],
      "first_seen": "2026-06-15"
    },
    {
      "value": "backdoor-hub.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "ESET WeLiveSecurity"
      ],
      "articles": [
        {
          "id": "art-377",
          "title": "EvilTokens: A phishing attack that doesn\u2019t steal your password",
          "link": "https://www.welivesecurity.com/en/cybercrime/eviltokens-phishing-doesnt-steal-password/",
          "published": "2026-06-15",
          "sev": "high"
        }
      ],
      "first_seen": "2026-06-15"
    },
    {
      "value": "bumpgames.net",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "ESET WeLiveSecurity"
      ],
      "articles": [
        {
          "id": "art-377",
          "title": "EvilTokens: A phishing attack that doesn\u2019t steal your password",
          "link": "https://www.welivesecurity.com/en/cybercrime/eviltokens-phishing-doesnt-steal-password/",
          "published": "2026-06-15",
          "sev": "high"
        }
      ],
      "first_seen": "2026-06-15"
    },
    {
      "value": "carbatterygurgaon.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "ESET WeLiveSecurity"
      ],
      "articles": [
        {
          "id": "art-377",
          "title": "EvilTokens: A phishing attack that doesn\u2019t steal your password",
          "link": "https://www.welivesecurity.com/en/cybercrime/eviltokens-phishing-doesnt-steal-password/",
          "published": "2026-06-15",
          "sev": "high"
        }
      ],
      "first_seen": "2026-06-15"
    },
    {
      "value": "careldutoit-el.co.za",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "ESET WeLiveSecurity"
      ],
      "articles": [
        {
          "id": "art-377",
          "title": "EvilTokens: A phishing attack that doesn\u2019t steal your password",
          "link": "https://www.welivesecurity.com/en/cybercrime/eviltokens-phishing-doesnt-steal-password/",
          "published": "2026-06-15",
          "sev": "high"
        }
      ],
      "first_seen": "2026-06-15"
    },
    {
      "value": "dao.com.au",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "ESET WeLiveSecurity"
      ],
      "articles": [
        {
          "id": "art-377",
          "title": "EvilTokens: A phishing attack that doesn\u2019t steal your password",
          "link": "https://www.welivesecurity.com/en/cybercrime/eviltokens-phishing-doesnt-steal-password/",
          "published": "2026-06-15",
          "sev": "high"
        }
      ],
      "first_seen": "2026-06-15"
    },
    {
      "value": "docusend.networkssolutionmail.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "ESET WeLiveSecurity"
      ],
      "articles": [
        {
          "id": "art-377",
          "title": "EvilTokens: A phishing attack that doesn\u2019t steal your password",
          "link": "https://www.welivesecurity.com/en/cybercrime/eviltokens-phishing-doesnt-steal-password/",
          "published": "2026-06-15",
          "sev": "high"
        }
      ],
      "first_seen": "2026-06-15"
    },
    {
      "value": "eqfit.co.za",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "ESET WeLiveSecurity"
      ],
      "articles": [
        {
          "id": "art-377",
          "title": "EvilTokens: A phishing attack that doesn\u2019t steal your password",
          "link": "https://www.welivesecurity.com/en/cybercrime/eviltokens-phishing-doesnt-steal-password/",
          "published": "2026-06-15",
          "sev": "high"
        }
      ],
      "first_seen": "2026-06-15"
    },
    {
      "value": "eventcalender-schedule.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "ESET WeLiveSecurity"
      ],
      "articles": [
        {
          "id": "art-377",
          "title": "EvilTokens: A phishing attack that doesn\u2019t steal your password",
          "link": "https://www.welivesecurity.com/en/cybercrime/eviltokens-phishing-doesnt-steal-password/",
          "published": "2026-06-15",
          "sev": "high"
        }
      ],
      "first_seen": "2026-06-15"
    },
    {
      "value": "evobothub.org",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "ESET WeLiveSecurity"
      ],
      "articles": [
        {
          "id": "art-377",
          "title": "EvilTokens: A phishing attack that doesn\u2019t steal your password",
          "link": "https://www.welivesecurity.com/en/cybercrime/eviltokens-phishing-doesnt-steal-password/",
          "published": "2026-06-15",
          "sev": "high"
        }
      ],
      "first_seen": "2026-06-15"
    },
    {
      "value": "framebound.cloud",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "ESET WeLiveSecurity"
      ],
      "articles": [
        {
          "id": "art-377",
          "title": "EvilTokens: A phishing attack that doesn\u2019t steal your password",
          "link": "https://www.welivesecurity.com/en/cybercrime/eviltokens-phishing-doesnt-steal-password/",
          "published": "2026-06-15",
          "sev": "high"
        }
      ],
      "first_seen": "2026-06-15"
    },
    {
      "value": "infinitechai.org",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "ESET WeLiveSecurity"
      ],
      "articles": [
        {
          "id": "art-377",
          "title": "EvilTokens: A phishing attack that doesn\u2019t steal your password",
          "link": "https://www.welivesecurity.com/en/cybercrime/eviltokens-phishing-doesnt-steal-password/",
          "published": "2026-06-15",
          "sev": "high"
        }
      ],
      "first_seen": "2026-06-15"
    },
    {
      "value": "internalmemorecord.bxwancheng.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "ESET WeLiveSecurity"
      ],
      "articles": [
        {
          "id": "art-377",
          "title": "EvilTokens: A phishing attack that doesn\u2019t steal your password",
          "link": "https://www.welivesecurity.com/en/cybercrime/eviltokens-phishing-doesnt-steal-password/",
          "published": "2026-06-15",
          "sev": "high"
        }
      ],
      "first_seen": "2026-06-15"
    },
    {
      "value": "macmamo.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "ESET WeLiveSecurity"
      ],
      "articles": [
        {
          "id": "art-377",
          "title": "EvilTokens: A phishing attack that doesn\u2019t steal your password",
          "link": "https://www.welivesecurity.com/en/cybercrime/eviltokens-phishing-doesnt-steal-password/",
          "published": "2026-06-15",
          "sev": "high"
        }
      ],
      "first_seen": "2026-06-15"
    },
    {
      "value": "mirsanotolastik.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "ESET WeLiveSecurity"
      ],
      "articles": [
        {
          "id": "art-377",
          "title": "EvilTokens: A phishing attack that doesn\u2019t steal your password",
          "link": "https://www.welivesecurity.com/en/cybercrime/eviltokens-phishing-doesnt-steal-password/",
          "published": "2026-06-15",
          "sev": "high"
        }
      ],
      "first_seen": "2026-06-15"
    },
    {
      "value": "mirzanyapi.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "ESET WeLiveSecurity"
      ],
      "articles": [
        {
          "id": "art-377",
          "title": "EvilTokens: A phishing attack that doesn\u2019t steal your password",
          "link": "https://www.welivesecurity.com/en/cybercrime/eviltokens-phishing-doesnt-steal-password/",
          "published": "2026-06-15",
          "sev": "high"
        }
      ],
      "first_seen": "2026-06-15"
    },
    {
      "value": "newmobilepolojean.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "ESET WeLiveSecurity"
      ],
      "articles": [
        {
          "id": "art-377",
          "title": "EvilTokens: A phishing attack that doesn\u2019t steal your password",
          "link": "https://www.welivesecurity.com/en/cybercrime/eviltokens-phishing-doesnt-steal-password/",
          "published": "2026-06-15",
          "sev": "high"
        }
      ],
      "first_seen": "2026-06-15"
    },
    {
      "value": "notificationsmanagersec.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "ESET WeLiveSecurity"
      ],
      "articles": [
        {
          "id": "art-377",
          "title": "EvilTokens: A phishing attack that doesn\u2019t steal your password",
          "link": "https://www.welivesecurity.com/en/cybercrime/eviltokens-phishing-doesnt-steal-password/",
          "published": "2026-06-15",
          "sev": "high"
        }
      ],
      "first_seen": "2026-06-15"
    },
    {
      "value": "pelangiservice.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "ESET WeLiveSecurity"
      ],
      "articles": [
        {
          "id": "art-377",
          "title": "EvilTokens: A phishing attack that doesn\u2019t steal your password",
          "link": "https://www.welivesecurity.com/en/cybercrime/eviltokens-phishing-doesnt-steal-password/",
          "published": "2026-06-15",
          "sev": "high"
        }
      ],
      "first_seen": "2026-06-15"
    },
    {
      "value": "prcservis.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "ESET WeLiveSecurity"
      ],
      "articles": [
        {
          "id": "art-377",
          "title": "EvilTokens: A phishing attack that doesn\u2019t steal your password",
          "link": "https://www.welivesecurity.com/en/cybercrime/eviltokens-phishing-doesnt-steal-password/",
          "published": "2026-06-15",
          "sev": "high"
        }
      ],
      "first_seen": "2026-06-15"
    },
    {
      "value": "promanager.outboundciwidey.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "ESET WeLiveSecurity"
      ],
      "articles": [
        {
          "id": "art-377",
          "title": "EvilTokens: A phishing attack that doesn\u2019t steal your password",
          "link": "https://www.welivesecurity.com/en/cybercrime/eviltokens-phishing-doesnt-steal-password/",
          "published": "2026-06-15",
          "sev": "high"
        }
      ],
      "first_seen": "2026-06-15"
    },
    {
      "value": "serenitygovsupplys.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "ESET WeLiveSecurity"
      ],
      "articles": [
        {
          "id": "art-377",
          "title": "EvilTokens: A phishing attack that doesn\u2019t steal your password",
          "link": "https://www.welivesecurity.com/en/cybercrime/eviltokens-phishing-doesnt-steal-password/",
          "published": "2026-06-15",
          "sev": "high"
        }
      ],
      "first_seen": "2026-06-15"
    },
    {
      "value": "signaturerequired.thecoolcactus.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "ESET WeLiveSecurity"
      ],
      "articles": [
        {
          "id": "art-377",
          "title": "EvilTokens: A phishing attack that doesn\u2019t steal your password",
          "link": "https://www.welivesecurity.com/en/cybercrime/eviltokens-phishing-doesnt-steal-password/",
          "published": "2026-06-15",
          "sev": "high"
        }
      ],
      "first_seen": "2026-06-15"
    },
    {
      "value": "smstltle.net",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "ESET WeLiveSecurity"
      ],
      "articles": [
        {
          "id": "art-377",
          "title": "EvilTokens: A phishing attack that doesn\u2019t steal your password",
          "link": "https://www.welivesecurity.com/en/cybercrime/eviltokens-phishing-doesnt-steal-password/",
          "published": "2026-06-15",
          "sev": "high"
        }
      ],
      "first_seen": "2026-06-15"
    },
    {
      "value": "statushelper.aguasomos.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "ESET WeLiveSecurity"
      ],
      "articles": [
        {
          "id": "art-377",
          "title": "EvilTokens: A phishing attack that doesn\u2019t steal your password",
          "link": "https://www.welivesecurity.com/en/cybercrime/eviltokens-phishing-doesnt-steal-password/",
          "published": "2026-06-15",
          "sev": "high"
        }
      ],
      "first_seen": "2026-06-15"
    },
    {
      "value": "suctwocesonesstory.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "ESET WeLiveSecurity"
      ],
      "articles": [
        {
          "id": "art-377",
          "title": "EvilTokens: A phishing attack that doesn\u2019t steal your password",
          "link": "https://www.welivesecurity.com/en/cybercrime/eviltokens-phishing-doesnt-steal-password/",
          "published": "2026-06-15",
          "sev": "high"
        }
      ],
      "first_seen": "2026-06-15"
    },
    {
      "value": "thesafarigarden.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "ESET WeLiveSecurity"
      ],
      "articles": [
        {
          "id": "art-377",
          "title": "EvilTokens: A phishing attack that doesn\u2019t steal your password",
          "link": "https://www.welivesecurity.com/en/cybercrime/eviltokens-phishing-doesnt-steal-password/",
          "published": "2026-06-15",
          "sev": "high"
        }
      ],
      "first_seen": "2026-06-15"
    },
    {
      "value": "topbuysella.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "ESET WeLiveSecurity"
      ],
      "articles": [
        {
          "id": "art-377",
          "title": "EvilTokens: A phishing attack that doesn\u2019t steal your password",
          "link": "https://www.welivesecurity.com/en/cybercrime/eviltokens-phishing-doesnt-steal-password/",
          "published": "2026-06-15",
          "sev": "high"
        }
      ],
      "first_seen": "2026-06-15"
    },
    {
      "value": "totalhomesafe.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "ESET WeLiveSecurity"
      ],
      "articles": [
        {
          "id": "art-377",
          "title": "EvilTokens: A phishing attack that doesn\u2019t steal your password",
          "link": "https://www.welivesecurity.com/en/cybercrime/eviltokens-phishing-doesnt-steal-password/",
          "published": "2026-06-15",
          "sev": "high"
        }
      ],
      "first_seen": "2026-06-15"
    },
    {
      "value": "youremplregroup.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "ESET WeLiveSecurity"
      ],
      "articles": [
        {
          "id": "art-377",
          "title": "EvilTokens: A phishing attack that doesn\u2019t steal your password",
          "link": "https://www.welivesecurity.com/en/cybercrime/eviltokens-phishing-doesnt-steal-password/",
          "published": "2026-06-15",
          "sev": "high"
        }
      ],
      "first_seen": "2026-06-15"
    },
    {
      "value": "162.220.232.0",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "ESET WeLiveSecurity"
      ],
      "articles": [
        {
          "id": "art-377",
          "title": "EvilTokens: A phishing attack that doesn\u2019t steal your password",
          "link": "https://www.welivesecurity.com/en/cybercrime/eviltokens-phishing-doesnt-steal-password/",
          "published": "2026-06-15",
          "sev": "high"
        }
      ],
      "first_seen": "2026-06-15"
    },
    {
      "value": "162.220.234.0",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "ESET WeLiveSecurity"
      ],
      "articles": [
        {
          "id": "art-377",
          "title": "EvilTokens: A phishing attack that doesn\u2019t steal your password",
          "link": "https://www.welivesecurity.com/en/cybercrime/eviltokens-phishing-doesnt-steal-password/",
          "published": "2026-06-15",
          "sev": "high"
        }
      ],
      "first_seen": "2026-06-15"
    },
    {
      "value": "185.81.113.0",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "ESET WeLiveSecurity"
      ],
      "articles": [
        {
          "id": "art-377",
          "title": "EvilTokens: A phishing attack that doesn\u2019t steal your password",
          "link": "https://www.welivesecurity.com/en/cybercrime/eviltokens-phishing-doesnt-steal-password/",
          "published": "2026-06-15",
          "sev": "high"
        }
      ],
      "first_seen": "2026-06-15"
    },
    {
      "value": "89.150.45.0",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "ESET WeLiveSecurity"
      ],
      "articles": [
        {
          "id": "art-377",
          "title": "EvilTokens: A phishing attack that doesn\u2019t steal your password",
          "link": "https://www.welivesecurity.com/en/cybercrime/eviltokens-phishing-doesnt-steal-password/",
          "published": "2026-06-15",
          "sev": "high"
        }
      ],
      "first_seen": "2026-06-15"
    },
    {
      "value": "CVE-2026-35273",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-384",
          "title": "CISA KEV: CVE-2026-35273 \u2014 Oracle PeopleSoft Enterprise PeopleTools Missing Authentication for Critical Function Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-06-12",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-06-12"
    },
    {
      "value": "azurenetfiles.net",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-384",
          "title": "CISA KEV: CVE-2026-35273 \u2014 Oracle PeopleSoft Enterprise PeopleTools Missing Authentication for Critical Function Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-06-12",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-06-12"
    },
    {
      "value": "142.11.200.186",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-384",
          "title": "CISA KEV: CVE-2026-35273 \u2014 Oracle PeopleSoft Enterprise PeopleTools Missing Authentication for Critical Function Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-06-12",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-06-12"
    },
    {
      "value": "142.11.200.187",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-384",
          "title": "CISA KEV: CVE-2026-35273 \u2014 Oracle PeopleSoft Enterprise PeopleTools Missing Authentication for Critical Function Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-06-12",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-06-12"
    },
    {
      "value": "142.11.200.188",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-384",
          "title": "CISA KEV: CVE-2026-35273 \u2014 Oracle PeopleSoft Enterprise PeopleTools Missing Authentication for Critical Function Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-06-12",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-06-12"
    },
    {
      "value": "142.11.200.189",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-384",
          "title": "CISA KEV: CVE-2026-35273 \u2014 Oracle PeopleSoft Enterprise PeopleTools Missing Authentication for Critical Function Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-06-12",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-06-12"
    },
    {
      "value": "142.11.200.190",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-384",
          "title": "CISA KEV: CVE-2026-35273 \u2014 Oracle PeopleSoft Enterprise PeopleTools Missing Authentication for Critical Function Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-06-12",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-06-12"
    },
    {
      "value": "176.120.22.24",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-384",
          "title": "CISA KEV: CVE-2026-35273 \u2014 Oracle PeopleSoft Enterprise PeopleTools Missing Authentication for Critical Function Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-06-12",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-06-12"
    },
    {
      "value": "2ab684d93c1553fad87041b4dea97188a97e78589deee2a7bacff905564f3a35",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-384",
          "title": "CISA KEV: CVE-2026-35273 \u2014 Oracle PeopleSoft Enterprise PeopleTools Missing Authentication for Critical Function Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-06-12",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-06-12"
    },
    {
      "value": "68257a6f9ff196179ec03624e849927f26599eb180a7c82e14ef5bc4e93bc309",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-384",
          "title": "CISA KEV: CVE-2026-35273 \u2014 Oracle PeopleSoft Enterprise PeopleTools Missing Authentication for Critical Function Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-06-12",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-06-12"
    },
    {
      "value": "c7e9332731b06644fc73e0046a2a89eaa59b09f54250e9bd622467187351711f",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-384",
          "title": "CISA KEV: CVE-2026-35273 \u2014 Oracle PeopleSoft Enterprise PeopleTools Missing Authentication for Critical Function Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-06-12",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-06-12"
    },
    {
      "value": "d83fdb9e53c5ff03c4cb0451ea1bebd79b53f29eadc1e2fa394c7af13a86ce2f",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-384",
          "title": "CISA KEV: CVE-2026-35273 \u2014 Oracle PeopleSoft Enterprise PeopleTools Missing Authentication for Critical Function Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-06-12",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-06-12"
    },
    {
      "value": "f02a924c9ff92a8780ce812511341182c6b509d45bc59f3f7b522e37225d24fc",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-384",
          "title": "CISA KEV: CVE-2026-35273 \u2014 Oracle PeopleSoft Enterprise PeopleTools Missing Authentication for Critical Function Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-06-12",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-06-12"
    },
    {
      "value": "CVE-2026-10520",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-389",
          "title": "CISA KEV: CVE-2026-10520 \u2014 Ivanti Sentry OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-06-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-06-11"
    },
    {
      "value": "CVE-2026-10523",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-389",
          "title": "CISA KEV: CVE-2026-10520 \u2014 Ivanti Sentry OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-06-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-06-11"
    },
    {
      "value": "coachcybersecurity.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "ESET WeLiveSecurity"
      ],
      "articles": [
        {
          "id": "art-388",
          "title": "OceanLotus: From external espionage to domestic targeting",
          "link": "https://www.welivesecurity.com/en/eset-research/oceanlotus-external-espionage-domestic-targeting/",
          "published": "2026-06-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-06-11"
    },
    {
      "value": "financemachinelearning.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "ESET WeLiveSecurity"
      ],
      "articles": [
        {
          "id": "art-388",
          "title": "OceanLotus: From external espionage to domestic targeting",
          "link": "https://www.welivesecurity.com/en/eset-research/oceanlotus-external-espionage-domestic-targeting/",
          "published": "2026-06-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-06-11"
    },
    {
      "value": "gatewayrvcenter.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "ESET WeLiveSecurity"
      ],
      "articles": [
        {
          "id": "art-388",
          "title": "OceanLotus: From external espionage to domestic targeting",
          "link": "https://www.welivesecurity.com/en/eset-research/oceanlotus-external-espionage-domestic-targeting/",
          "published": "2026-06-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-06-11"
    },
    {
      "value": "leadingfilipinoteams.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "ESET WeLiveSecurity"
      ],
      "articles": [
        {
          "id": "art-388",
          "title": "OceanLotus: From external espionage to domestic targeting",
          "link": "https://www.welivesecurity.com/en/eset-research/oceanlotus-external-espionage-domestic-targeting/",
          "published": "2026-06-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-06-11"
    },
    {
      "value": "mxprodesign.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "ESET WeLiveSecurity"
      ],
      "articles": [
        {
          "id": "art-388",
          "title": "OceanLotus: From external espionage to domestic targeting",
          "link": "https://www.welivesecurity.com/en/eset-research/oceanlotus-external-espionage-domestic-targeting/",
          "published": "2026-06-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-06-11"
    },
    {
      "value": "power-sync-services.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "ESET WeLiveSecurity"
      ],
      "articles": [
        {
          "id": "art-388",
          "title": "OceanLotus: From external espionage to domestic targeting",
          "link": "https://www.welivesecurity.com/en/eset-research/oceanlotus-external-espionage-domestic-targeting/",
          "published": "2026-06-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-06-11"
    },
    {
      "value": "103.119.47.104",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "ESET WeLiveSecurity"
      ],
      "articles": [
        {
          "id": "art-388",
          "title": "OceanLotus: From external espionage to domestic targeting",
          "link": "https://www.welivesecurity.com/en/eset-research/oceanlotus-external-espionage-domestic-targeting/",
          "published": "2026-06-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-06-11"
    },
    {
      "value": "139.162.11.152",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "ESET WeLiveSecurity"
      ],
      "articles": [
        {
          "id": "art-388",
          "title": "OceanLotus: From external espionage to domestic targeting",
          "link": "https://www.welivesecurity.com/en/eset-research/oceanlotus-external-espionage-domestic-targeting/",
          "published": "2026-06-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-06-11"
    },
    {
      "value": "139.180.128.42",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "ESET WeLiveSecurity"
      ],
      "articles": [
        {
          "id": "art-388",
          "title": "OceanLotus: From external espionage to domestic targeting",
          "link": "https://www.welivesecurity.com/en/eset-research/oceanlotus-external-espionage-domestic-targeting/",
          "published": "2026-06-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-06-11"
    },
    {
      "value": "139.99.33.239",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "ESET WeLiveSecurity"
      ],
      "articles": [
        {
          "id": "art-388",
          "title": "OceanLotus: From external espionage to domestic targeting",
          "link": "https://www.welivesecurity.com/en/eset-research/oceanlotus-external-espionage-domestic-targeting/",
          "published": "2026-06-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-06-11"
    },
    {
      "value": "142.91.98.77",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "ESET WeLiveSecurity"
      ],
      "articles": [
        {
          "id": "art-388",
          "title": "OceanLotus: From external espionage to domestic targeting",
          "link": "https://www.welivesecurity.com/en/eset-research/oceanlotus-external-espionage-domestic-targeting/",
          "published": "2026-06-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-06-11"
    },
    {
      "value": "166.88.77.186",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "ESET WeLiveSecurity"
      ],
      "articles": [
        {
          "id": "art-388",
          "title": "OceanLotus: From external espionage to domestic targeting",
          "link": "https://www.welivesecurity.com/en/eset-research/oceanlotus-external-espionage-domestic-targeting/",
          "published": "2026-06-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-06-11"
    },
    {
      "value": "194.68.26.241",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "ESET WeLiveSecurity"
      ],
      "articles": [
        {
          "id": "art-388",
          "title": "OceanLotus: From external espionage to domestic targeting",
          "link": "https://www.welivesecurity.com/en/eset-research/oceanlotus-external-espionage-domestic-targeting/",
          "published": "2026-06-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-06-11"
    },
    {
      "value": "38.60.245.37",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "ESET WeLiveSecurity"
      ],
      "articles": [
        {
          "id": "art-388",
          "title": "OceanLotus: From external espionage to domestic targeting",
          "link": "https://www.welivesecurity.com/en/eset-research/oceanlotus-external-espionage-domestic-targeting/",
          "published": "2026-06-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-06-11"
    },
    {
      "value": "0037DBB0FEA981D02F6F76DE81EBAEFCB68B7D20",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "ESET WeLiveSecurity"
      ],
      "articles": [
        {
          "id": "art-388",
          "title": "OceanLotus: From external espionage to domestic targeting",
          "link": "https://www.welivesecurity.com/en/eset-research/oceanlotus-external-espionage-domestic-targeting/",
          "published": "2026-06-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-06-11"
    },
    {
      "value": "19A69F856EFA811C376F68E4FEB0997B4724F8BD",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "ESET WeLiveSecurity"
      ],
      "articles": [
        {
          "id": "art-388",
          "title": "OceanLotus: From external espionage to domestic targeting",
          "link": "https://www.welivesecurity.com/en/eset-research/oceanlotus-external-espionage-domestic-targeting/",
          "published": "2026-06-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-06-11"
    },
    {
      "value": "41CB8CD78B8DB76563E4F972ABE817CEEE9CF9B0",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "ESET WeLiveSecurity"
      ],
      "articles": [
        {
          "id": "art-388",
          "title": "OceanLotus: From external espionage to domestic targeting",
          "link": "https://www.welivesecurity.com/en/eset-research/oceanlotus-external-espionage-domestic-targeting/",
          "published": "2026-06-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-06-11"
    },
    {
      "value": "490194E9BB5128ECA8693AD9E610891C2ED185AF",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "ESET WeLiveSecurity"
      ],
      "articles": [
        {
          "id": "art-388",
          "title": "OceanLotus: From external espionage to domestic targeting",
          "link": "https://www.welivesecurity.com/en/eset-research/oceanlotus-external-espionage-domestic-targeting/",
          "published": "2026-06-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-06-11"
    },
    {
      "value": "4AD36AD6C165B5174967020CB1A3358F78D7A283",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "ESET WeLiveSecurity"
      ],
      "articles": [
        {
          "id": "art-388",
          "title": "OceanLotus: From external espionage to domestic targeting",
          "link": "https://www.welivesecurity.com/en/eset-research/oceanlotus-external-espionage-domestic-targeting/",
          "published": "2026-06-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-06-11"
    },
    {
      "value": "51176139B0B2220B802C1578A4994DF68DF5BCD1",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "ESET WeLiveSecurity"
      ],
      "articles": [
        {
          "id": "art-388",
          "title": "OceanLotus: From external espionage to domestic targeting",
          "link": "https://www.welivesecurity.com/en/eset-research/oceanlotus-external-espionage-domestic-targeting/",
          "published": "2026-06-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-06-11"
    },
    {
      "value": "57352B3CEEE32216E5AA20BAA848483D7AB5A6FB",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "ESET WeLiveSecurity"
      ],
      "articles": [
        {
          "id": "art-388",
          "title": "OceanLotus: From external espionage to domestic targeting",
          "link": "https://www.welivesecurity.com/en/eset-research/oceanlotus-external-espionage-domestic-targeting/",
          "published": "2026-06-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-06-11"
    },
    {
      "value": "59A8553A4F8130F576AB234E0B220BE4D4DA0E98",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "ESET WeLiveSecurity"
      ],
      "articles": [
        {
          "id": "art-388",
          "title": "OceanLotus: From external espionage to domestic targeting",
          "link": "https://www.welivesecurity.com/en/eset-research/oceanlotus-external-espionage-domestic-targeting/",
          "published": "2026-06-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-06-11"
    },
    {
      "value": "5D6194BB48FEBB91A10D1462461A012FAFC0918B",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "ESET WeLiveSecurity"
      ],
      "articles": [
        {
          "id": "art-388",
          "title": "OceanLotus: From external espionage to domestic targeting",
          "link": "https://www.welivesecurity.com/en/eset-research/oceanlotus-external-espionage-domestic-targeting/",
          "published": "2026-06-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-06-11"
    },
    {
      "value": "865A1739337D3303B3AB02C5E694C22B79C42B7D",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "ESET WeLiveSecurity"
      ],
      "articles": [
        {
          "id": "art-388",
          "title": "OceanLotus: From external espionage to domestic targeting",
          "link": "https://www.welivesecurity.com/en/eset-research/oceanlotus-external-espionage-domestic-targeting/",
          "published": "2026-06-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-06-11"
    },
    {
      "value": "91F042F59BE4BDCB6E5EA21B91DECD731C175B54",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "ESET WeLiveSecurity"
      ],
      "articles": [
        {
          "id": "art-388",
          "title": "OceanLotus: From external espionage to domestic targeting",
          "link": "https://www.welivesecurity.com/en/eset-research/oceanlotus-external-espionage-domestic-targeting/",
          "published": "2026-06-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-06-11"
    },
    {
      "value": "9BC06DF9F932746A05EE728C8B103BD3BA6BF395",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "ESET WeLiveSecurity"
      ],
      "articles": [
        {
          "id": "art-388",
          "title": "OceanLotus: From external espionage to domestic targeting",
          "link": "https://www.welivesecurity.com/en/eset-research/oceanlotus-external-espionage-domestic-targeting/",
          "published": "2026-06-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-06-11"
    },
    {
      "value": "9CA1A5C7F79882DB913534C1E62B26BCDCB9F6DD",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "ESET WeLiveSecurity"
      ],
      "articles": [
        {
          "id": "art-388",
          "title": "OceanLotus: From external espionage to domestic targeting",
          "link": "https://www.welivesecurity.com/en/eset-research/oceanlotus-external-espionage-domestic-targeting/",
          "published": "2026-06-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-06-11"
    },
    {
      "value": "A177ED0BFFEB1EFE1D9D31D72A82EF2625AE646D",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "ESET WeLiveSecurity"
      ],
      "articles": [
        {
          "id": "art-388",
          "title": "OceanLotus: From external espionage to domestic targeting",
          "link": "https://www.welivesecurity.com/en/eset-research/oceanlotus-external-espionage-domestic-targeting/",
          "published": "2026-06-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-06-11"
    },
    {
      "value": "A8E2BBBFCB86500322D2367744FA12755AB0C165",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "ESET WeLiveSecurity"
      ],
      "articles": [
        {
          "id": "art-388",
          "title": "OceanLotus: From external espionage to domestic targeting",
          "link": "https://www.welivesecurity.com/en/eset-research/oceanlotus-external-espionage-domestic-targeting/",
          "published": "2026-06-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-06-11"
    },
    {
      "value": "B028E947150764A71DEEF498DE6F8C95ECCCB445",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "ESET WeLiveSecurity"
      ],
      "articles": [
        {
          "id": "art-388",
          "title": "OceanLotus: From external espionage to domestic targeting",
          "link": "https://www.welivesecurity.com/en/eset-research/oceanlotus-external-espionage-domestic-targeting/",
          "published": "2026-06-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-06-11"
    },
    {
      "value": "B7B2D2DB544F9EEA74453CDF2B8BEEA58CF07C48",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "ESET WeLiveSecurity"
      ],
      "articles": [
        {
          "id": "art-388",
          "title": "OceanLotus: From external espionage to domestic targeting",
          "link": "https://www.welivesecurity.com/en/eset-research/oceanlotus-external-espionage-domestic-targeting/",
          "published": "2026-06-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-06-11"
    },
    {
      "value": "D511B77459673EC42163F19E300FF1D233B6C39F",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "ESET WeLiveSecurity"
      ],
      "articles": [
        {
          "id": "art-388",
          "title": "OceanLotus: From external espionage to domestic targeting",
          "link": "https://www.welivesecurity.com/en/eset-research/oceanlotus-external-espionage-domestic-targeting/",
          "published": "2026-06-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-06-11"
    },
    {
      "value": "F74F1FEB62B662CDA489FDB2453727824E55ACB9",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "ESET WeLiveSecurity"
      ],
      "articles": [
        {
          "id": "art-388",
          "title": "OceanLotus: From external espionage to domestic targeting",
          "link": "https://www.welivesecurity.com/en/eset-research/oceanlotus-external-espionage-domestic-targeting/",
          "published": "2026-06-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-06-11"
    },
    {
      "value": "F8F8209987CA7F139DE6A62F9E6EE21BD2AE93A9",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "ESET WeLiveSecurity"
      ],
      "articles": [
        {
          "id": "art-388",
          "title": "OceanLotus: From external espionage to domestic targeting",
          "link": "https://www.welivesecurity.com/en/eset-research/oceanlotus-external-espionage-domestic-targeting/",
          "published": "2026-06-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-06-11"
    },
    {
      "value": "4b2399646573bb737c4969563303d8ee2e9ddbd1b271f1ca9e35ea78062538db",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "Aikido",
        "StepSecurity",
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-385",
          "title": "npm v12 delivers one of the biggest security improvements in years",
          "link": "https://www.aikido.dev/blog/npm-v12-block-postinstall",
          "published": "2026-06-11",
          "sev": "high"
        },
        {
          "id": "art-562",
          "title": "Securing Vibe Coding and AI Coding Agents: An End-to-End Approach with StepSecurity",
          "link": "https://www.stepsecurity.io/blog/securing-vibe-coding-and-ai-coding-agents-an-end-to-end-approach-with-stepsecurity",
          "published": "2026-04-12",
          "sev": "high"
        },
        {
          "id": "art-796",
          "title": "SHA1-Hulud, npm supply chain incident",
          "link": "https://snyk.io/blog/sha1-hulud-npm-supply-chain-incident/",
          "published": "2025-11-24",
          "sev": "high"
        }
      ],
      "first_seen": "2026-06-11"
    },
    {
      "value": "b74caeaa75e077c99f7d44f46daaf9796a3be43ecf24f2a1fd381844669da777",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "Aikido",
        "StepSecurity",
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-385",
          "title": "npm v12 delivers one of the biggest security improvements in years",
          "link": "https://www.aikido.dev/blog/npm-v12-block-postinstall",
          "published": "2026-06-11",
          "sev": "high"
        },
        {
          "id": "art-562",
          "title": "Securing Vibe Coding and AI Coding Agents: An End-to-End Approach with StepSecurity",
          "link": "https://www.stepsecurity.io/blog/securing-vibe-coding-and-ai-coding-agents-an-end-to-end-approach-with-stepsecurity",
          "published": "2026-04-12",
          "sev": "high"
        },
        {
          "id": "art-796",
          "title": "SHA1-Hulud, npm supply chain incident",
          "link": "https://snyk.io/blog/sha1-hulud-npm-supply-chain-incident/",
          "published": "2025-11-24",
          "sev": "high"
        }
      ],
      "first_seen": "2026-06-11"
    },
    {
      "value": "dc67467a39b70d1cd4c1f7f7a459b35058163592f4a9e8fb4dffcbba98ef210c",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "Aikido",
        "StepSecurity",
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-385",
          "title": "npm v12 delivers one of the biggest security improvements in years",
          "link": "https://www.aikido.dev/blog/npm-v12-block-postinstall",
          "published": "2026-06-11",
          "sev": "high"
        },
        {
          "id": "art-562",
          "title": "Securing Vibe Coding and AI Coding Agents: An End-to-End Approach with StepSecurity",
          "link": "https://www.stepsecurity.io/blog/securing-vibe-coding-and-ai-coding-agents-an-end-to-end-approach-with-stepsecurity",
          "published": "2026-04-12",
          "sev": "high"
        },
        {
          "id": "art-796",
          "title": "SHA1-Hulud, npm supply chain incident",
          "link": "https://snyk.io/blog/sha1-hulud-npm-supply-chain-incident/",
          "published": "2025-11-24",
          "sev": "high"
        }
      ],
      "first_seen": "2026-06-11"
    },
    {
      "value": "o4511539639222272.ingest.de.sentry.io",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "Aikido"
      ],
      "articles": [
        {
          "id": "art-392",
          "title": "Compromised Rust crate onering performs code exfiltration",
          "link": "https://www.aikido.dev/blog/compromised-rust-crate-onering-performs-code-exfiltration",
          "published": "2026-06-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-06-10"
    },
    {
      "value": "CVE-2026-29199",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "Aikido"
      ],
      "articles": [
        {
          "id": "art-394",
          "title": "10 year old critical vulnerability in phpBB affecting tens of millions of users across thousands of forums",
          "link": "https://www.aikido.dev/blog/phpbb-authentication-bypass-rce",
          "published": "2026-06-10",
          "sev": "high"
        }
      ],
      "first_seen": "2026-06-10"
    },
    {
      "value": "45.32.150.251",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "Aikido"
      ],
      "articles": [
        {
          "id": "art-390",
          "title": "Code is being written everywhere, and the device is the only constant",
          "link": "https://www.aikido.dev/blog/code-is-written-everywhere",
          "published": "2026-06-10",
          "sev": "high"
        }
      ],
      "first_seen": "2026-06-10"
    },
    {
      "value": "45.32.151.157",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "Aikido"
      ],
      "articles": [
        {
          "id": "art-390",
          "title": "Code is being written everywhere, and the device is the only constant",
          "link": "https://www.aikido.dev/blog/code-is-written-everywhere",
          "published": "2026-06-10",
          "sev": "high"
        }
      ],
      "first_seen": "2026-06-10"
    },
    {
      "value": "70.34.242.255",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "Aikido"
      ],
      "articles": [
        {
          "id": "art-390",
          "title": "Code is being written everywhere, and the device is the only constant",
          "link": "https://www.aikido.dev/blog/code-is-written-everywhere",
          "published": "2026-06-10",
          "sev": "high"
        }
      ],
      "first_seen": "2026-06-10"
    },
    {
      "value": "CVE-2026-11645",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-400",
          "title": "CISA KEV: CVE-2026-11645 \u2014 Google Chromium V8 Out-of-Bounds Read and Write Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-06-09",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-06-09"
    },
    {
      "value": "CVE-2026-20122",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-402",
          "title": "CISA KEV: CVE-2026-20245 \u2014 Cisco Catalyst SD-WAN Manager Improper Encoding or Escaping of Output Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-06-09",
          "sev": "crit"
        },
        {
          "id": "art-538",
          "title": "CISA KEV: CVE-2026-20122 \u2014 Cisco Catalyst SD-WAN Manager Incorrect Use of Privileged APIs Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-04-20",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-06-09"
    },
    {
      "value": "CVE-2026-20127",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-402",
          "title": "CISA KEV: CVE-2026-20245 \u2014 Cisco Catalyst SD-WAN Manager Improper Encoding or Escaping of Output Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-06-09",
          "sev": "crit"
        },
        {
          "id": "art-650",
          "title": "CISA KEV: CVE-2026-20127 \u2014 Cisco Catalyst SD-WAN Controller and Manager Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-02-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-06-09"
    },
    {
      "value": "CVE-2026-20128",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-402",
          "title": "CISA KEV: CVE-2026-20245 \u2014 Cisco Catalyst SD-WAN Manager Improper Encoding or Escaping of Output Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-06-09",
          "sev": "crit"
        },
        {
          "id": "art-543",
          "title": "CISA KEV: CVE-2026-20128 \u2014 Cisco Catalyst SD-WAN Manager Storing Passwords in a Recoverable Format Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-04-20",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-06-09"
    },
    {
      "value": "CVE-2026-20133",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-402",
          "title": "CISA KEV: CVE-2026-20245 \u2014 Cisco Catalyst SD-WAN Manager Improper Encoding or Escaping of Output Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-06-09",
          "sev": "crit"
        },
        {
          "id": "art-539",
          "title": "CISA KEV: CVE-2026-20133 \u2014 Cisco Catalyst SD-WAN Manager Exposure of Sensitive Information to an Unauthorized Actor Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-04-20",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-06-09"
    },
    {
      "value": "CVE-2026-20182",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-402",
          "title": "CISA KEV: CVE-2026-20245 \u2014 Cisco Catalyst SD-WAN Manager Improper Encoding or Escaping of Output Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-06-09",
          "sev": "crit"
        },
        {
          "id": "art-482",
          "title": "CISA KEV: CVE-2026-20182 \u2014 Cisco Catalyst SD-WAN Controller Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-05-14",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-06-09"
    },
    {
      "value": "CVE-2026-20245",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-402",
          "title": "CISA KEV: CVE-2026-20245 \u2014 Cisco Catalyst SD-WAN Manager Improper Encoding or Escaping of Output Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-06-09",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-06-09"
    },
    {
      "value": "CVE-2026-7473",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-401",
          "title": "CISA KEV: CVE-2026-7473 \u2014 Arista Extensible Operating System Incomplete Comparison with Missing Factors Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-06-09",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-06-09"
    },
    {
      "value": "t.m-kosche.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "StepSecurity",
        "Aikido",
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-397",
          "title": "Miasma Worm Hits Microsoft Again: Azure Functions Action and 72 Other Repositories Disabled After Supply Chain Attack Targeting AI Coding Agents",
          "link": "https://www.stepsecurity.io/blog/miasma-worm-hits-microsoft-again-azure-functions-action-and-72-other-repositories-disabled-after-supply-chain-attack-targeting-ai-coding-agents",
          "published": "2026-06-09",
          "sev": "high"
        },
        {
          "id": "art-415",
          "title": "Why EDR and proxy won\u2019t save you from supply chain malware",
          "link": "https://www.aikido.dev/blog/edr-proxy-wont-protect-supply-chain-malware",
          "published": "2026-06-02",
          "sev": "high"
        },
        {
          "id": "art-452",
          "title": "5 Supply Chain Attacks in 48 Hours: Why Securing One Layer Is Not Enough",
          "link": "https://www.stepsecurity.io/blog/5-supply-chain-attacks-in-48-hours-why-securing-one-layer-is-not-enough",
          "published": "2026-05-21",
          "sev": "crit"
        },
        {
          "id": "art-468",
          "title": "The AntV Supply Chain Campaign Expands: Microsoft's `durabletask` PyPI Package Compromised",
          "link": "https://snyk.io/blog/durabletask-pypi-supply-chain-attack/",
          "published": "2026-05-19",
          "sev": "high"
        },
        {
          "id": "art-469",
          "title": "Microsoft's durabletask package on PyPi Compromised. Mini Shai Hulud attacks again... again!",
          "link": "https://www.aikido.dev/blog/durabletask-package-compromised-mini-shai-hulud",
          "published": "2026-05-19",
          "sev": "high"
        },
        {
          "id": "art-471",
          "title": "Mini Shai-Hulud strikes again: npm worm compromises hundreds of @antv packages",
          "link": "https://www.aikido.dev/blog/mini-shai-hulud-antv-npm-supply-chain-attack",
          "published": "2026-05-19",
          "sev": "crit"
        },
        {
          "id": "art-472",
          "title": "actions-cool/issues-helper GitHub Action Compromised: All Tags Point to Imposter Commit That Exfiltrates CI/CD Credentials",
          "link": "https://www.stepsecurity.io/blog/actions-cool-issues-helper-github-action-compromised-all-tags-point-to-imposter-commit-that-exfiltrates-ci-cd-credentials",
          "published": "2026-05-19",
          "sev": "med"
        },
        {
          "id": "art-474",
          "title": "Mini Shai-Hulud Hits AntV: 300+ Malicious npm Packages Published via Compromised Maintainer Account",
          "link": "https://snyk.io/blog/mini-shai-hulud-antv-npm-supply-chain-attack/",
          "published": "2026-05-18",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-06-09"
    },
    {
      "value": "185.95.159.32",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "StepSecurity",
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-397",
          "title": "Miasma Worm Hits Microsoft Again: Azure Functions Action and 72 Other Repositories Disabled After Supply Chain Attack Targeting AI Coding Agents",
          "link": "https://www.stepsecurity.io/blog/miasma-worm-hits-microsoft-again-azure-functions-action-and-72-other-repositories-disabled-after-supply-chain-attack-targeting-ai-coding-agents",
          "published": "2026-06-09",
          "sev": "high"
        },
        {
          "id": "art-468",
          "title": "The AntV Supply Chain Campaign Expands: Microsoft's `durabletask` PyPI Package Compromised",
          "link": "https://snyk.io/blog/durabletask-pypi-supply-chain-attack/",
          "published": "2026-05-19",
          "sev": "high"
        },
        {
          "id": "art-474",
          "title": "Mini Shai-Hulud Hits AntV: 300+ Malicious npm Packages Published via Compromised Maintainer Account",
          "link": "https://snyk.io/blog/mini-shai-hulud-antv-npm-supply-chain-attack/",
          "published": "2026-05-18",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-06-09"
    },
    {
      "value": "069ac1dc7f7649b76bc72a11ac700f373804bfd81dab7e561157b703999f44ce",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "StepSecurity",
        "Aikido",
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-397",
          "title": "Miasma Worm Hits Microsoft Again: Azure Functions Action and 72 Other Repositories Disabled After Supply Chain Attack Targeting AI Coding Agents",
          "link": "https://www.stepsecurity.io/blog/miasma-worm-hits-microsoft-again-azure-functions-action-and-72-other-repositories-disabled-after-supply-chain-attack-targeting-ai-coding-agents",
          "published": "2026-06-09",
          "sev": "high"
        },
        {
          "id": "art-415",
          "title": "Why EDR and proxy won\u2019t save you from supply chain malware",
          "link": "https://www.aikido.dev/blog/edr-proxy-wont-protect-supply-chain-malware",
          "published": "2026-06-02",
          "sev": "high"
        },
        {
          "id": "art-452",
          "title": "5 Supply Chain Attacks in 48 Hours: Why Securing One Layer Is Not Enough",
          "link": "https://www.stepsecurity.io/blog/5-supply-chain-attacks-in-48-hours-why-securing-one-layer-is-not-enough",
          "published": "2026-05-21",
          "sev": "crit"
        },
        {
          "id": "art-468",
          "title": "The AntV Supply Chain Campaign Expands: Microsoft's `durabletask` PyPI Package Compromised",
          "link": "https://snyk.io/blog/durabletask-pypi-supply-chain-attack/",
          "published": "2026-05-19",
          "sev": "high"
        },
        {
          "id": "art-469",
          "title": "Microsoft's durabletask package on PyPi Compromised. Mini Shai Hulud attacks again... again!",
          "link": "https://www.aikido.dev/blog/durabletask-package-compromised-mini-shai-hulud",
          "published": "2026-05-19",
          "sev": "high"
        }
      ],
      "first_seen": "2026-06-09"
    },
    {
      "value": "288f26c2eadcb1a7923fe376d16f5404216cce15d9fc162a4a78574dc7df399a",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "Aikido",
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-398",
          "title": "Wait, binding.gyp Can Do What? Exploring npm's Weirdest Build System",
          "link": "https://www.aikido.dev/blog/exploring-binding-gyp-npm-build-system",
          "published": "2026-06-09",
          "sev": "crit"
        },
        {
          "id": "art-408",
          "title": "Node-gyp Supply Chain Compromise: A Self-Propagating npm Worm That Hides in binding.gyp",
          "link": "https://snyk.io/blog/node-gyp-supply-chain-compromise-self-propagating-npm-worm-binding-gyp/",
          "published": "2026-06-04",
          "sev": "high"
        }
      ],
      "first_seen": "2026-06-09"
    },
    {
      "value": "e3dbe63aded45278f49c4746ab938ed9472b36def79b43e2dd2d7eff014481d1",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "Aikido",
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-398",
          "title": "Wait, binding.gyp Can Do What? Exploring npm's Weirdest Build System",
          "link": "https://www.aikido.dev/blog/exploring-binding-gyp-npm-build-system",
          "published": "2026-06-09",
          "sev": "crit"
        },
        {
          "id": "art-408",
          "title": "Node-gyp Supply Chain Compromise: A Self-Propagating npm Worm That Hides in binding.gyp",
          "link": "https://snyk.io/blog/node-gyp-supply-chain-compromise-self-propagating-npm-worm-binding-gyp/",
          "published": "2026-06-04",
          "sev": "high"
        }
      ],
      "first_seen": "2026-06-09"
    },
    {
      "value": "dnsowl.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "StepSecurity"
      ],
      "articles": [
        {
          "id": "art-397",
          "title": "Miasma Worm Hits Microsoft Again: Azure Functions Action and 72 Other Repositories Disabled After Supply Chain Attack Targeting AI Coding Agents",
          "link": "https://www.stepsecurity.io/blog/miasma-worm-hits-microsoft-again-azure-functions-action-and-72-other-repositories-disabled-after-supply-chain-attack-targeting-ai-coding-agents",
          "published": "2026-06-09",
          "sev": "high"
        }
      ],
      "first_seen": "2026-06-09"
    },
    {
      "value": "160.119.64.3",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "StepSecurity",
        "Aikido",
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-397",
          "title": "Miasma Worm Hits Microsoft Again: Azure Functions Action and 72 Other Repositories Disabled After Supply Chain Attack Targeting AI Coding Agents",
          "link": "https://www.stepsecurity.io/blog/miasma-worm-hits-microsoft-again-azure-functions-action-and-72-other-repositories-disabled-after-supply-chain-attack-targeting-ai-coding-agents",
          "published": "2026-06-09",
          "sev": "high"
        },
        {
          "id": "art-415",
          "title": "Why EDR and proxy won\u2019t save you from supply chain malware",
          "link": "https://www.aikido.dev/blog/edr-proxy-wont-protect-supply-chain-malware",
          "published": "2026-06-02",
          "sev": "high"
        },
        {
          "id": "art-468",
          "title": "The AntV Supply Chain Campaign Expands: Microsoft's `durabletask` PyPI Package Compromised",
          "link": "https://snyk.io/blog/durabletask-pypi-supply-chain-attack/",
          "published": "2026-05-19",
          "sev": "high"
        }
      ],
      "first_seen": "2026-06-09"
    },
    {
      "value": "3a9db5ba0c8cd4c91e91717df6b1a141fc1e0fbc0558b5a78d7f5c23f5b2a150",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "StepSecurity"
      ],
      "articles": [
        {
          "id": "art-397",
          "title": "Miasma Worm Hits Microsoft Again: Azure Functions Action and 72 Other Repositories Disabled After Supply Chain Attack Targeting AI Coding Agents",
          "link": "https://www.stepsecurity.io/blog/miasma-worm-hits-microsoft-again-azure-functions-action-and-72-other-repositories-disabled-after-supply-chain-attack-targeting-ai-coding-agents",
          "published": "2026-06-09",
          "sev": "high"
        }
      ],
      "first_seen": "2026-06-09"
    },
    {
      "value": "3de04fe2a76262743ed089efa7115f4508619838e77d60b9a1aab8b20d2cc8bf",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "StepSecurity",
        "Aikido",
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-397",
          "title": "Miasma Worm Hits Microsoft Again: Azure Functions Action and 72 Other Repositories Disabled After Supply Chain Attack Targeting AI Coding Agents",
          "link": "https://www.stepsecurity.io/blog/miasma-worm-hits-microsoft-again-azure-functions-action-and-72-other-repositories-disabled-after-supply-chain-attack-targeting-ai-coding-agents",
          "published": "2026-06-09",
          "sev": "high"
        },
        {
          "id": "art-415",
          "title": "Why EDR and proxy won\u2019t save you from supply chain malware",
          "link": "https://www.aikido.dev/blog/edr-proxy-wont-protect-supply-chain-malware",
          "published": "2026-06-02",
          "sev": "high"
        },
        {
          "id": "art-468",
          "title": "The AntV Supply Chain Campaign Expands: Microsoft's `durabletask` PyPI Package Compromised",
          "link": "https://snyk.io/blog/durabletask-pypi-supply-chain-attack/",
          "published": "2026-05-19",
          "sev": "high"
        },
        {
          "id": "art-469",
          "title": "Microsoft's durabletask package on PyPi Compromised. Mini Shai Hulud attacks again... again!",
          "link": "https://www.aikido.dev/blog/durabletask-package-compromised-mini-shai-hulud",
          "published": "2026-05-19",
          "sev": "high"
        }
      ],
      "first_seen": "2026-06-09"
    },
    {
      "value": "633c8410ee0413ca4b090a19c30b20c03f31598c25247c484846fa34c1df5b64",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "StepSecurity"
      ],
      "articles": [
        {
          "id": "art-397",
          "title": "Miasma Worm Hits Microsoft Again: Azure Functions Action and 72 Other Repositories Disabled After Supply Chain Attack Targeting AI Coding Agents",
          "link": "https://www.stepsecurity.io/blog/miasma-worm-hits-microsoft-again-azure-functions-action-and-72-other-repositories-disabled-after-supply-chain-attack-targeting-ai-coding-agents",
          "published": "2026-06-09",
          "sev": "high"
        }
      ],
      "first_seen": "2026-06-09"
    },
    {
      "value": "85f54c089d78ebfb101454ec934c767065a342a43c9ee1beac8430cdd3b2086f",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "StepSecurity",
        "Aikido",
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-397",
          "title": "Miasma Worm Hits Microsoft Again: Azure Functions Action and 72 Other Repositories Disabled After Supply Chain Attack Targeting AI Coding Agents",
          "link": "https://www.stepsecurity.io/blog/miasma-worm-hits-microsoft-again-azure-functions-action-and-72-other-repositories-disabled-after-supply-chain-attack-targeting-ai-coding-agents",
          "published": "2026-06-09",
          "sev": "high"
        },
        {
          "id": "art-415",
          "title": "Why EDR and proxy won\u2019t save you from supply chain malware",
          "link": "https://www.aikido.dev/blog/edr-proxy-wont-protect-supply-chain-malware",
          "published": "2026-06-02",
          "sev": "high"
        },
        {
          "id": "art-468",
          "title": "The AntV Supply Chain Campaign Expands: Microsoft's `durabletask` PyPI Package Compromised",
          "link": "https://snyk.io/blog/durabletask-pypi-supply-chain-attack/",
          "published": "2026-05-19",
          "sev": "high"
        },
        {
          "id": "art-469",
          "title": "Microsoft's durabletask package on PyPi Compromised. Mini Shai Hulud attacks again... again!",
          "link": "https://www.aikido.dev/blog/durabletask-package-compromised-mini-shai-hulud",
          "published": "2026-05-19",
          "sev": "high"
        }
      ],
      "first_seen": "2026-06-09"
    },
    {
      "value": "c0b094e46842260936d4b97ce63e4539b99a3eae48b736798c700217c52569dc",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "StepSecurity",
        "Aikido",
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-397",
          "title": "Miasma Worm Hits Microsoft Again: Azure Functions Action and 72 Other Repositories Disabled After Supply Chain Attack Targeting AI Coding Agents",
          "link": "https://www.stepsecurity.io/blog/miasma-worm-hits-microsoft-again-azure-functions-action-and-72-other-repositories-disabled-after-supply-chain-attack-targeting-ai-coding-agents",
          "published": "2026-06-09",
          "sev": "high"
        },
        {
          "id": "art-415",
          "title": "Why EDR and proxy won\u2019t save you from supply chain malware",
          "link": "https://www.aikido.dev/blog/edr-proxy-wont-protect-supply-chain-malware",
          "published": "2026-06-02",
          "sev": "high"
        },
        {
          "id": "art-468",
          "title": "The AntV Supply Chain Campaign Expands: Microsoft's `durabletask` PyPI Package Compromised",
          "link": "https://snyk.io/blog/durabletask-pypi-supply-chain-attack/",
          "published": "2026-05-19",
          "sev": "high"
        },
        {
          "id": "art-469",
          "title": "Microsoft's durabletask package on PyPi Compromised. Mini Shai Hulud attacks again... again!",
          "link": "https://www.aikido.dev/blog/durabletask-package-compromised-mini-shai-hulud",
          "published": "2026-05-19",
          "sev": "high"
        }
      ],
      "first_seen": "2026-06-09"
    },
    {
      "value": "d630397de8b01af0f6f5cf4463da91b17f28195a2c50c8f3f38ad9f7873fdb8e",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "StepSecurity"
      ],
      "articles": [
        {
          "id": "art-397",
          "title": "Miasma Worm Hits Microsoft Again: Azure Functions Action and 72 Other Repositories Disabled After Supply Chain Attack Targeting AI Coding Agents",
          "link": "https://www.stepsecurity.io/blog/miasma-worm-hits-microsoft-again-azure-functions-action-and-72-other-repositories-disabled-after-supply-chain-attack-targeting-ai-coding-agents",
          "published": "2026-06-09",
          "sev": "high"
        }
      ],
      "first_seen": "2026-06-09"
    },
    {
      "value": "CVE-2026-42271",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-403",
          "title": "CISA KEV: CVE-2026-42271 \u2014 BerriAI LiteLLM Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-06-08",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-06-08"
    },
    {
      "value": "CVE-2026-48710",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-403",
          "title": "CISA KEV: CVE-2026-42271 \u2014 BerriAI LiteLLM Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-06-08",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-06-08"
    },
    {
      "value": "144.208.127.155",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-404",
          "title": "CISA KEV: CVE-2026-50751 \u2014 Check Point Security Gateway Improper Authentication Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-06-08",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-06-08"
    },
    {
      "value": "162.33.177.101",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-404",
          "title": "CISA KEV: CVE-2026-50751 \u2014 Check Point Security Gateway Improper Authentication Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-06-08",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-06-08"
    },
    {
      "value": "209.182.225.136",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-404",
          "title": "CISA KEV: CVE-2026-50751 \u2014 Check Point Security Gateway Improper Authentication Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-06-08",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-06-08"
    },
    {
      "value": "38.54.107.167",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-404",
          "title": "CISA KEV: CVE-2026-50751 \u2014 Check Point Security Gateway Improper Authentication Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-06-08",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-06-08"
    },
    {
      "value": "38.54.88.201",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-404",
          "title": "CISA KEV: CVE-2026-50751 \u2014 Check Point Security Gateway Improper Authentication Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-06-08",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-06-08"
    },
    {
      "value": "38.60.157.139",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-404",
          "title": "CISA KEV: CVE-2026-50751 \u2014 Check Point Security Gateway Improper Authentication Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-06-08",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-06-08"
    },
    {
      "value": "45.61.136.173",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-404",
          "title": "CISA KEV: CVE-2026-50751 \u2014 Check Point Security Gateway Improper Authentication Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-06-08",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-06-08"
    },
    {
      "value": "45.63.104.106",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-404",
          "title": "CISA KEV: CVE-2026-50751 \u2014 Check Point Security Gateway Improper Authentication Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-06-08",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-06-08"
    },
    {
      "value": "45.76.26.42",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-404",
          "title": "CISA KEV: CVE-2026-50751 \u2014 Check Point Security Gateway Improper Authentication Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-06-08",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-06-08"
    },
    {
      "value": "45.77.149.152",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-404",
          "title": "CISA KEV: CVE-2026-50751 \u2014 Check Point Security Gateway Improper Authentication Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-06-08",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-06-08"
    },
    {
      "value": "66.42.99.200",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-404",
          "title": "CISA KEV: CVE-2026-50751 \u2014 Check Point Security Gateway Improper Authentication Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-06-08",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-06-08"
    },
    {
      "value": "51d39aa39478beeac94f2d12f682ecce",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-404",
          "title": "CISA KEV: CVE-2026-50751 \u2014 Check Point Security Gateway Improper Authentication Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-06-08",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-06-08"
    },
    {
      "value": "52fda5c1b9704544f32ee98d9060e689",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-404",
          "title": "CISA KEV: CVE-2026-50751 \u2014 Check Point Security Gateway Improper Authentication Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-06-08",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-06-08"
    },
    {
      "value": "CVE-2026-28318",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-406",
          "title": "CISA KEV: CVE-2026-28318 \u2014 SolarWinds Serv-U Uncontrolled Resource Consumption Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-06-05",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-06-05"
    },
    {
      "value": "CVE-2025-6514",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-410",
          "title": "So You Have an AI Security Budget. Now what?",
          "link": "https://snyk.io/blog/ai-security-budget/",
          "published": "2026-06-04",
          "sev": "high"
        }
      ],
      "first_seen": "2026-06-04"
    },
    {
      "value": "608d01124cd6b5b8c55888e984b4c4d9b06fa686",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-408",
          "title": "Node-gyp Supply Chain Compromise: A Self-Propagating npm Worm That Hides in binding.gyp",
          "link": "https://snyk.io/blog/node-gyp-supply-chain-compromise-self-propagating-npm-worm-binding-gyp/",
          "published": "2026-06-04",
          "sev": "high"
        }
      ],
      "first_seen": "2026-06-04"
    },
    {
      "value": "8bf051251ec3b973e39a313547e53421a2f8d2f6",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-408",
          "title": "Node-gyp Supply Chain Compromise: A Self-Propagating npm Worm That Hides in binding.gyp",
          "link": "https://snyk.io/blog/node-gyp-supply-chain-compromise-self-propagating-npm-worm-binding-gyp/",
          "published": "2026-06-04",
          "sev": "high"
        }
      ],
      "first_seen": "2026-06-04"
    },
    {
      "value": "ab9903d9edc720d1e11ea7d3d3e7a1c456f44ff7",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-408",
          "title": "Node-gyp Supply Chain Compromise: A Self-Propagating npm Worm That Hides in binding.gyp",
          "link": "https://snyk.io/blog/node-gyp-supply-chain-compromise-self-propagating-npm-worm-binding-gyp/",
          "published": "2026-06-04",
          "sev": "high"
        }
      ],
      "first_seen": "2026-06-04"
    },
    {
      "value": "5926b86b642e00672252953eb30d8f75cfb7797fe3118bd6fa2cfbee92905d61",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-408",
          "title": "Node-gyp Supply Chain Compromise: A Self-Propagating npm Worm That Hides in binding.gyp",
          "link": "https://snyk.io/blog/node-gyp-supply-chain-compromise-self-propagating-npm-worm-binding-gyp/",
          "published": "2026-06-04",
          "sev": "high"
        }
      ],
      "first_seen": "2026-06-04"
    },
    {
      "value": "82d83274680df928fdda296a348e01802f595e412308c399565c320df444052a",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-408",
          "title": "Node-gyp Supply Chain Compromise: A Self-Propagating npm Worm That Hides in binding.gyp",
          "link": "https://snyk.io/blog/node-gyp-supply-chain-compromise-self-propagating-npm-worm-binding-gyp/",
          "published": "2026-06-04",
          "sev": "high"
        }
      ],
      "first_seen": "2026-06-04"
    },
    {
      "value": "CVE-2026-45247",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-414",
          "title": "CISA KEV: CVE-2026-45247 \u2014 Mirasvit Full Page Cache Warmer Deserialization of Untrusted Data Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-06-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-06-03"
    },
    {
      "value": "CVE-2022-0492",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-422",
          "title": "CISA KEV: CVE-2022-0492 \u2014 Linux Kernel Improper Authentication Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-06-02",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-06-02"
    },
    {
      "value": "CVE-2025-48595",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-423",
          "title": "CISA KEV: CVE-2025-48595 \u2014 Android Framework Integer Overflow Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-06-02",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-06-02"
    },
    {
      "value": "556d2b335d4d6d92139822017ee461b668afe375",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "StepSecurity",
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-417",
          "title": "Laravel-Lang Supply Chain Attack: Every Tag Across Multiple Composer Packages Rewritten to Steal CI Secrets",
          "link": "https://www.stepsecurity.io/blog/laravel-lang-supply-chain-attack",
          "published": "2026-06-02",
          "sev": "high"
        },
        {
          "id": "art-445",
          "title": "Laravel Lang Supply Chain Advisory",
          "link": "https://snyk.io/blog/laravel-lang-supply-chain-advisory/",
          "published": "2026-05-23",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-06-02"
    },
    {
      "value": "a5ea2e8fa92ccf29cdb1d2dadbeb27722b2bff37",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "StepSecurity",
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-417",
          "title": "Laravel-Lang Supply Chain Attack: Every Tag Across Multiple Composer Packages Rewritten to Steal CI Secrets",
          "link": "https://www.stepsecurity.io/blog/laravel-lang-supply-chain-attack",
          "published": "2026-06-02",
          "sev": "high"
        },
        {
          "id": "art-445",
          "title": "Laravel Lang Supply Chain Advisory",
          "link": "https://snyk.io/blog/laravel-lang-supply-chain-advisory/",
          "published": "2026-05-23",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-06-02"
    },
    {
      "value": "bba2e443dc7ff1f8704f52a5375383e3f4f643b8",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "StepSecurity",
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-417",
          "title": "Laravel-Lang Supply Chain Attack: Every Tag Across Multiple Composer Packages Rewritten to Steal CI Secrets",
          "link": "https://www.stepsecurity.io/blog/laravel-lang-supply-chain-attack",
          "published": "2026-06-02",
          "sev": "high"
        },
        {
          "id": "art-445",
          "title": "Laravel Lang Supply Chain Advisory",
          "link": "https://snyk.io/blog/laravel-lang-supply-chain-advisory/",
          "published": "2026-05-23",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-06-02"
    },
    {
      "value": "1a4afce34918bdc74ae3f31edaffffaa0ee074d83618f53edfd88137927340b8",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "StepSecurity",
        "Aikido"
      ],
      "articles": [
        {
          "id": "art-419",
          "title": "Nx Console VS Code Extension Compromised",
          "link": "https://www.stepsecurity.io/blog/nx-console-vs-code-extension-compromised",
          "published": "2026-06-02",
          "sev": "high"
        },
        {
          "id": "art-432",
          "title": "What MDM can't protect on developer machines (and what to do about it)",
          "link": "https://www.aikido.dev/blog/what-mdm-cant-protect",
          "published": "2026-05-28",
          "sev": "high"
        },
        {
          "id": "art-452",
          "title": "5 Supply Chain Attacks in 48 Hours: Why Securing One Layer Is Not Enough",
          "link": "https://www.stepsecurity.io/blog/5-supply-chain-attacks-in-48-hours-why-securing-one-layer-is-not-enough",
          "published": "2026-05-21",
          "sev": "crit"
        },
        {
          "id": "art-457",
          "title": "The Wild West of VS Code extensions and how a poisoned extension breached GitHub",
          "link": "https://www.aikido.dev/blog/vs-code-extension-github-breach",
          "published": "2026-05-20",
          "sev": "crit"
        },
        {
          "id": "art-458",
          "title": "GitHub breached via a malicious VS Code extension: why developer devices are the real target",
          "link": "https://www.aikido.dev/blog/github-breached-vs-code-extension",
          "published": "2026-05-20",
          "sev": "high"
        }
      ],
      "first_seen": "2026-06-02"
    },
    {
      "value": "7d80b3ef74ad7992b93c31966962612e4e2ceb93e7727cdbd1d2a9af47d44ba8",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "Aikido",
        "StepSecurity",
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-415",
          "title": "Why EDR and proxy won\u2019t save you from supply chain malware",
          "link": "https://www.aikido.dev/blog/edr-proxy-wont-protect-supply-chain-malware",
          "published": "2026-06-02",
          "sev": "high"
        },
        {
          "id": "art-452",
          "title": "5 Supply Chain Attacks in 48 Hours: Why Securing One Layer Is Not Enough",
          "link": "https://www.stepsecurity.io/blog/5-supply-chain-attacks-in-48-hours-why-securing-one-layer-is-not-enough",
          "published": "2026-05-21",
          "sev": "crit"
        },
        {
          "id": "art-468",
          "title": "The AntV Supply Chain Campaign Expands: Microsoft's `durabletask` PyPI Package Compromised",
          "link": "https://snyk.io/blog/durabletask-pypi-supply-chain-attack/",
          "published": "2026-05-19",
          "sev": "high"
        }
      ],
      "first_seen": "2026-06-02"
    },
    {
      "value": "aeaf583e20347bf850e2fabdcd6f4982996ba023f8c2cd56bbd299cfd56516f5",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "Aikido",
        "StepSecurity",
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-415",
          "title": "Why EDR and proxy won\u2019t save you from supply chain malware",
          "link": "https://www.aikido.dev/blog/edr-proxy-wont-protect-supply-chain-malware",
          "published": "2026-06-02",
          "sev": "high"
        },
        {
          "id": "art-452",
          "title": "5 Supply Chain Attacks in 48 Hours: Why Securing One Layer Is Not Enough",
          "link": "https://www.stepsecurity.io/blog/5-supply-chain-attacks-in-48-hours-why-securing-one-layer-is-not-enough",
          "published": "2026-05-21",
          "sev": "crit"
        },
        {
          "id": "art-468",
          "title": "The AntV Supply Chain Campaign Expands: Microsoft's `durabletask` PyPI Package Compromised",
          "link": "https://snyk.io/blog/durabletask-pypi-supply-chain-attack/",
          "published": "2026-05-19",
          "sev": "high"
        }
      ],
      "first_seen": "2026-06-02"
    },
    {
      "value": "b0cefb66b953e5184b6adb3035e9e267335ac5eabfe1848e07834777b9397b74",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "StepSecurity",
        "Aikido"
      ],
      "articles": [
        {
          "id": "art-419",
          "title": "Nx Console VS Code Extension Compromised",
          "link": "https://www.stepsecurity.io/blog/nx-console-vs-code-extension-compromised",
          "published": "2026-06-02",
          "sev": "high"
        },
        {
          "id": "art-432",
          "title": "What MDM can't protect on developer machines (and what to do about it)",
          "link": "https://www.aikido.dev/blog/what-mdm-cant-protect",
          "published": "2026-05-28",
          "sev": "high"
        },
        {
          "id": "art-452",
          "title": "5 Supply Chain Attacks in 48 Hours: Why Securing One Layer Is Not Enough",
          "link": "https://www.stepsecurity.io/blog/5-supply-chain-attacks-in-48-hours-why-securing-one-layer-is-not-enough",
          "published": "2026-05-21",
          "sev": "crit"
        },
        {
          "id": "art-457",
          "title": "The Wild West of VS Code extensions and how a poisoned extension breached GitHub",
          "link": "https://www.aikido.dev/blog/vs-code-extension-github-breach",
          "published": "2026-05-20",
          "sev": "crit"
        },
        {
          "id": "art-458",
          "title": "GitHub breached via a malicious VS Code extension: why developer devices are the real target",
          "link": "https://www.aikido.dev/blog/github-breached-vs-code-extension",
          "published": "2026-05-20",
          "sev": "high"
        }
      ],
      "first_seen": "2026-06-02"
    },
    {
      "value": "e7347d90653efc565f03733a95e9209d78f9cfa81e31ff2b2dd9d48d75a4b8b1",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "StepSecurity",
        "Aikido"
      ],
      "articles": [
        {
          "id": "art-419",
          "title": "Nx Console VS Code Extension Compromised",
          "link": "https://www.stepsecurity.io/blog/nx-console-vs-code-extension-compromised",
          "published": "2026-06-02",
          "sev": "high"
        },
        {
          "id": "art-432",
          "title": "What MDM can't protect on developer machines (and what to do about it)",
          "link": "https://www.aikido.dev/blog/what-mdm-cant-protect",
          "published": "2026-05-28",
          "sev": "high"
        },
        {
          "id": "art-452",
          "title": "5 Supply Chain Attacks in 48 Hours: Why Securing One Layer Is Not Enough",
          "link": "https://www.stepsecurity.io/blog/5-supply-chain-attacks-in-48-hours-why-securing-one-layer-is-not-enough",
          "published": "2026-05-21",
          "sev": "crit"
        },
        {
          "id": "art-457",
          "title": "The Wild West of VS Code extensions and how a poisoned extension breached GitHub",
          "link": "https://www.aikido.dev/blog/vs-code-extension-github-breach",
          "published": "2026-05-20",
          "sev": "crit"
        },
        {
          "id": "art-458",
          "title": "GitHub breached via a malicious VS Code extension: why developer devices are the real target",
          "link": "https://www.aikido.dev/blog/github-breached-vs-code-extension",
          "published": "2026-05-20",
          "sev": "high"
        }
      ],
      "first_seen": "2026-06-02"
    },
    {
      "value": "packages.npm.org",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "Aikido"
      ],
      "articles": [
        {
          "id": "art-415",
          "title": "Why EDR and proxy won\u2019t save you from supply chain malware",
          "link": "https://www.aikido.dev/blog/edr-proxy-wont-protect-supply-chain-malware",
          "published": "2026-06-02",
          "sev": "high"
        }
      ],
      "first_seen": "2026-06-02"
    },
    {
      "value": "1713b19cbf609cb101ff5e216be41f7224269082",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "StepSecurity"
      ],
      "articles": [
        {
          "id": "art-417",
          "title": "Laravel-Lang Supply Chain Attack: Every Tag Across Multiple Composer Packages Rewritten to Steal CI Secrets",
          "link": "https://www.stepsecurity.io/blog/laravel-lang-supply-chain-attack",
          "published": "2026-06-02",
          "sev": "high"
        }
      ],
      "first_seen": "2026-06-02"
    },
    {
      "value": "26c233e1a0d4fd2331e8e0f175e18f8eed904aa3",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "StepSecurity"
      ],
      "articles": [
        {
          "id": "art-417",
          "title": "Laravel-Lang Supply Chain Attack: Every Tag Across Multiple Composer Packages Rewritten to Steal CI Secrets",
          "link": "https://www.stepsecurity.io/blog/laravel-lang-supply-chain-attack",
          "published": "2026-06-02",
          "sev": "high"
        }
      ],
      "first_seen": "2026-06-02"
    },
    {
      "value": "50ac0db454d19234c835716f297bbc5363c0a25c",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "StepSecurity"
      ],
      "articles": [
        {
          "id": "art-417",
          "title": "Laravel-Lang Supply Chain Attack: Every Tag Across Multiple Composer Packages Rewritten to Steal CI Secrets",
          "link": "https://www.stepsecurity.io/blog/laravel-lang-supply-chain-attack",
          "published": "2026-06-02",
          "sev": "high"
        }
      ],
      "first_seen": "2026-06-02"
    },
    {
      "value": "6b1d5782a8c8c199d070857802d39bfe609eb6f2",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "StepSecurity"
      ],
      "articles": [
        {
          "id": "art-417",
          "title": "Laravel-Lang Supply Chain Attack: Every Tag Across Multiple Composer Packages Rewritten to Steal CI Secrets",
          "link": "https://www.stepsecurity.io/blog/laravel-lang-supply-chain-attack",
          "published": "2026-06-02",
          "sev": "high"
        }
      ],
      "first_seen": "2026-06-02"
    },
    {
      "value": "722cee67326d932e7f71ba3438f62a255d779aa9",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "StepSecurity"
      ],
      "articles": [
        {
          "id": "art-417",
          "title": "Laravel-Lang Supply Chain Attack: Every Tag Across Multiple Composer Packages Rewritten to Steal CI Secrets",
          "link": "https://www.stepsecurity.io/blog/laravel-lang-supply-chain-attack",
          "published": "2026-06-02",
          "sev": "high"
        }
      ],
      "first_seen": "2026-06-02"
    },
    {
      "value": "9ee599d248cc322fa26054694a83a1f4558cc716",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "StepSecurity"
      ],
      "articles": [
        {
          "id": "art-417",
          "title": "Laravel-Lang Supply Chain Attack: Every Tag Across Multiple Composer Packages Rewritten to Steal CI Secrets",
          "link": "https://www.stepsecurity.io/blog/laravel-lang-supply-chain-attack",
          "published": "2026-06-02",
          "sev": "high"
        }
      ],
      "first_seen": "2026-06-02"
    },
    {
      "value": "a9f8d88cf98e35988d3d0fd6d79547f980853041",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "StepSecurity"
      ],
      "articles": [
        {
          "id": "art-417",
          "title": "Laravel-Lang Supply Chain Attack: Every Tag Across Multiple Composer Packages Rewritten to Steal CI Secrets",
          "link": "https://www.stepsecurity.io/blog/laravel-lang-supply-chain-attack",
          "published": "2026-06-02",
          "sev": "high"
        }
      ],
      "first_seen": "2026-06-02"
    },
    {
      "value": "ad24b980db8f0dca50ccb3ba6badb3c2331e0ef4",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "StepSecurity"
      ],
      "articles": [
        {
          "id": "art-417",
          "title": "Laravel-Lang Supply Chain Attack: Every Tag Across Multiple Composer Packages Rewritten to Steal CI Secrets",
          "link": "https://www.stepsecurity.io/blog/laravel-lang-supply-chain-attack",
          "published": "2026-06-02",
          "sev": "high"
        }
      ],
      "first_seen": "2026-06-02"
    },
    {
      "value": "c45764e70285146da37025cd8601a921ab8a7eda",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "StepSecurity"
      ],
      "articles": [
        {
          "id": "art-417",
          "title": "Laravel-Lang Supply Chain Attack: Every Tag Across Multiple Composer Packages Rewritten to Steal CI Secrets",
          "link": "https://www.stepsecurity.io/blog/laravel-lang-supply-chain-attack",
          "published": "2026-06-02",
          "sev": "high"
        }
      ],
      "first_seen": "2026-06-02"
    },
    {
      "value": "d59561727927117e65b35f0183cae131baad19fe",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "StepSecurity"
      ],
      "articles": [
        {
          "id": "art-417",
          "title": "Laravel-Lang Supply Chain Attack: Every Tag Across Multiple Composer Packages Rewritten to Steal CI Secrets",
          "link": "https://www.stepsecurity.io/blog/laravel-lang-supply-chain-attack",
          "published": "2026-06-02",
          "sev": "high"
        }
      ],
      "first_seen": "2026-06-02"
    },
    {
      "value": "daa5212264bb73fb39fe7a36618b62717dc564a5",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "StepSecurity"
      ],
      "articles": [
        {
          "id": "art-417",
          "title": "Laravel-Lang Supply Chain Attack: Every Tag Across Multiple Composer Packages Rewritten to Steal CI Secrets",
          "link": "https://www.stepsecurity.io/blog/laravel-lang-supply-chain-attack",
          "published": "2026-06-02",
          "sev": "high"
        }
      ],
      "first_seen": "2026-06-02"
    },
    {
      "value": "db0c3ef246103fd0f6c318e0d48f26b5289044c3",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "StepSecurity"
      ],
      "articles": [
        {
          "id": "art-417",
          "title": "Laravel-Lang Supply Chain Attack: Every Tag Across Multiple Composer Packages Rewritten to Steal CI Secrets",
          "link": "https://www.stepsecurity.io/blog/laravel-lang-supply-chain-attack",
          "published": "2026-06-02",
          "sev": "high"
        }
      ],
      "first_seen": "2026-06-02"
    },
    {
      "value": "877ff2531a63393c4cb9a3c86908b62d9c4fc3db971bc231c48537faae6cb3ec",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "Aikido"
      ],
      "articles": [
        {
          "id": "art-415",
          "title": "Why EDR and proxy won\u2019t save you from supply chain malware",
          "link": "https://www.aikido.dev/blog/edr-proxy-wont-protect-supply-chain-malware",
          "published": "2026-06-02",
          "sev": "high"
        }
      ],
      "first_seen": "2026-06-02"
    },
    {
      "value": "970ba1a06bfabaf7a7f17df75f12a19e48ad4667c938bc7949a6a0502f6160b6",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-421",
          "title": "Protestware by open source maintainer to hinder agentic coding: The jqwik 1.10.0 Prompt Injection",
          "link": "https://snyk.io/blog/protestware-open-source-maintainer-qwik-1-10-0-prompt-injection/",
          "published": "2026-06-02",
          "sev": "high"
        }
      ],
      "first_seen": "2026-06-02"
    },
    {
      "value": "CVE-2024-21182",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-427",
          "title": "CISA KEV: CVE-2024-21182 \u2014 Oracle WebLogic Server Unspecified Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-06-01",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-06-01"
    },
    {
      "value": "CVE-2026-0257",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-431",
          "title": "CISA KEV: CVE-2026-0257 \u2014 Palo Alto Networks PAN-OS Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-05-29",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-05-29"
    },
    {
      "value": "104.207.144.154",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-431",
          "title": "CISA KEV: CVE-2026-0257 \u2014 Palo Alto Networks PAN-OS Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-05-29",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-05-29"
    },
    {
      "value": "146.19.216.119",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-431",
          "title": "CISA KEV: CVE-2026-0257 \u2014 Palo Alto Networks PAN-OS Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-05-29",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-05-29"
    },
    {
      "value": "146.19.216.120",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-431",
          "title": "CISA KEV: CVE-2026-0257 \u2014 Palo Alto Networks PAN-OS Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-05-29",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-05-29"
    },
    {
      "value": "146.19.216.125",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-431",
          "title": "CISA KEV: CVE-2026-0257 \u2014 Palo Alto Networks PAN-OS Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-05-29",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-05-29"
    },
    {
      "value": "179.43.172.213",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-431",
          "title": "CISA KEV: CVE-2026-0257 \u2014 Palo Alto Networks PAN-OS Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-05-29",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-05-29"
    },
    {
      "value": "185.195.232.139",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-431",
          "title": "CISA KEV: CVE-2026-0257 \u2014 Palo Alto Networks PAN-OS Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-05-29",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-05-29"
    },
    {
      "value": "198.12.106.60",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-431",
          "title": "CISA KEV: CVE-2026-0257 \u2014 Palo Alto Networks PAN-OS Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-05-29",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-05-29"
    },
    {
      "value": "202.144.192.47",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-431",
          "title": "CISA KEV: CVE-2026-0257 \u2014 Palo Alto Networks PAN-OS Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-05-29",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-05-29"
    },
    {
      "value": "209.99.191.137",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-431",
          "title": "CISA KEV: CVE-2026-0257 \u2014 Palo Alto Networks PAN-OS Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-05-29",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-05-29"
    },
    {
      "value": "23.128.228.6",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-431",
          "title": "CISA KEV: CVE-2026-0257 \u2014 Palo Alto Networks PAN-OS Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-05-29",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-05-29"
    },
    {
      "value": "79.130.26.202",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-431",
          "title": "CISA KEV: CVE-2026-0257 \u2014 Palo Alto Networks PAN-OS Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-05-29",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-05-29"
    },
    {
      "value": "filev2.getsession.org",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "Aikido",
        "CISA KEV",
        "StepSecurity",
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-432",
          "title": "What MDM can't protect on developer machines (and what to do about it)",
          "link": "https://www.aikido.dev/blog/what-mdm-cant-protect",
          "published": "2026-05-28",
          "sev": "high"
        },
        {
          "id": "art-440",
          "title": "CISA KEV: CVE-2026-45321 \u2014 TanStack Unspecified Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-05-27",
          "sev": "crit"
        },
        {
          "id": "art-442",
          "title": "Why developer machines are now the number one target for supply chain attacks",
          "link": "https://www.aikido.dev/blog/developer-machines-supply-chain-attacks",
          "published": "2026-05-26",
          "sev": "high"
        },
        {
          "id": "art-452",
          "title": "5 Supply Chain Attacks in 48 Hours: Why Securing One Layer Is Not Enough",
          "link": "https://www.stepsecurity.io/blog/5-supply-chain-attacks-in-48-hours-why-securing-one-layer-is-not-enough",
          "published": "2026-05-21",
          "sev": "crit"
        },
        {
          "id": "art-474",
          "title": "Mini Shai-Hulud Hits AntV: 300+ Malicious npm Packages Published via Compromised Maintainer Account",
          "link": "https://snyk.io/blog/mini-shai-hulud-antv-npm-supply-chain-attack/",
          "published": "2026-05-18",
          "sev": "crit"
        },
        {
          "id": "art-483",
          "title": "TeamPCP's Mini Shai-Hulud Is Back: A Self-Spreading Supply Chain Attack Compromises TanStack npm Packages",
          "link": "https://www.stepsecurity.io/blog/mini-shai-hulud-is-back-a-self-spreading-supply-chain-attack-hits-the-npm-ecosystem",
          "published": "2026-05-12",
          "sev": "crit"
        },
        {
          "id": "art-486",
          "title": "Mini Shai-Hulud Is Back: npm Worm Hits over 160 Packages, including Mistral and Tanstack",
          "link": "https://www.aikido.dev/blog/mini-shai-hulud-is-back-tanstack-compromised",
          "published": "2026-05-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-05-28"
    },
    {
      "value": "558b09d7ad0d1660e2a0fb8a06da81a6f42e06d2",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "Aikido",
        "StepSecurity"
      ],
      "articles": [
        {
          "id": "art-432",
          "title": "What MDM can't protect on developer machines (and what to do about it)",
          "link": "https://www.aikido.dev/blog/what-mdm-cant-protect",
          "published": "2026-05-28",
          "sev": "high"
        },
        {
          "id": "art-452",
          "title": "5 Supply Chain Attacks in 48 Hours: Why Securing One Layer Is Not Enough",
          "link": "https://www.stepsecurity.io/blog/5-supply-chain-attacks-in-48-hours-why-securing-one-layer-is-not-enough",
          "published": "2026-05-21",
          "sev": "crit"
        },
        {
          "id": "art-457",
          "title": "The Wild West of VS Code extensions and how a poisoned extension breached GitHub",
          "link": "https://www.aikido.dev/blog/vs-code-extension-github-breach",
          "published": "2026-05-20",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-05-28"
    },
    {
      "value": "ba642fe2c7c65e42dd7f6444b83023dc6827e08c",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "Aikido"
      ],
      "articles": [
        {
          "id": "art-432",
          "title": "What MDM can't protect on developer machines (and what to do about it)",
          "link": "https://www.aikido.dev/blog/what-mdm-cant-protect",
          "published": "2026-05-28",
          "sev": "high"
        },
        {
          "id": "art-457",
          "title": "The Wild West of VS Code extensions and how a poisoned extension breached GitHub",
          "link": "https://www.aikido.dev/blog/vs-code-extension-github-breach",
          "published": "2026-05-20",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-05-28"
    },
    {
      "value": "cyberhavenext.pro",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "Aikido"
      ],
      "articles": [
        {
          "id": "art-432",
          "title": "What MDM can't protect on developer machines (and what to do about it)",
          "link": "https://www.aikido.dev/blog/what-mdm-cant-protect",
          "published": "2026-05-28",
          "sev": "high"
        }
      ],
      "first_seen": "2026-05-28"
    },
    {
      "value": "CVE-2026-8398",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-441",
          "title": "CISA KEV: CVE-2026-8398 \u2014 Daemon Tools Lite Embedded Malicious Code Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-05-27",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-05-27"
    },
    {
      "value": "api.masscan.cloud",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV",
        "Aikido",
        "StepSecurity"
      ],
      "articles": [
        {
          "id": "art-440",
          "title": "CISA KEV: CVE-2026-45321 \u2014 TanStack Unspecified Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-05-27",
          "sev": "crit"
        },
        {
          "id": "art-442",
          "title": "Why developer machines are now the number one target for supply chain attacks",
          "link": "https://www.aikido.dev/blog/developer-machines-supply-chain-attacks",
          "published": "2026-05-26",
          "sev": "high"
        },
        {
          "id": "art-452",
          "title": "5 Supply Chain Attacks in 48 Hours: Why Securing One Layer Is Not Enough",
          "link": "https://www.stepsecurity.io/blog/5-supply-chain-attacks-in-48-hours-why-securing-one-layer-is-not-enough",
          "published": "2026-05-21",
          "sev": "crit"
        },
        {
          "id": "art-483",
          "title": "TeamPCP's Mini Shai-Hulud Is Back: A Self-Spreading Supply Chain Attack Compromises TanStack npm Packages",
          "link": "https://www.stepsecurity.io/blog/mini-shai-hulud-is-back-a-self-spreading-supply-chain-attack-hits-the-npm-ecosystem",
          "published": "2026-05-12",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-05-27"
    },
    {
      "value": "env-check.daemontools.cc",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-441",
          "title": "CISA KEV: CVE-2026-8398 \u2014 Daemon Tools Lite Embedded Malicious Code Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-05-27",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-05-27"
    },
    {
      "value": "litter.catbox.moe",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV",
        "StepSecurity"
      ],
      "articles": [
        {
          "id": "art-440",
          "title": "CISA KEV: CVE-2026-45321 \u2014 TanStack Unspecified Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-05-27",
          "sev": "crit"
        },
        {
          "id": "art-483",
          "title": "TeamPCP's Mini Shai-Hulud Is Back: A Self-Spreading Supply Chain Attack Compromises TanStack npm Packages",
          "link": "https://www.stepsecurity.io/blog/mini-shai-hulud-is-back-a-self-spreading-supply-chain-attack-hits-the-npm-ecosystem",
          "published": "2026-05-12",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-05-27"
    },
    {
      "value": "seed1.getsession.org",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV",
        "Aikido"
      ],
      "articles": [
        {
          "id": "art-440",
          "title": "CISA KEV: CVE-2026-45321 \u2014 TanStack Unspecified Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-05-27",
          "sev": "crit"
        },
        {
          "id": "art-442",
          "title": "Why developer machines are now the number one target for supply chain attacks",
          "link": "https://www.aikido.dev/blog/developer-machines-supply-chain-attacks",
          "published": "2026-05-26",
          "sev": "high"
        }
      ],
      "first_seen": "2026-05-27"
    },
    {
      "value": "seed2.getsession.org",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-440",
          "title": "CISA KEV: CVE-2026-45321 \u2014 TanStack Unspecified Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-05-27",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-05-27"
    },
    {
      "value": "seed3.getsession.org",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-440",
          "title": "CISA KEV: CVE-2026-45321 \u2014 TanStack Unspecified Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-05-27",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-05-27"
    },
    {
      "value": "38.180.107.76",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-441",
          "title": "CISA KEV: CVE-2026-8398 \u2014 Daemon Tools Lite Embedded Malicious Code Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-05-27",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-05-27"
    },
    {
      "value": "00e2df8f42d14072e4385e500d4669ec783aa517",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-441",
          "title": "CISA KEV: CVE-2026-8398 \u2014 Daemon Tools Lite Embedded Malicious Code Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-05-27",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-05-27"
    },
    {
      "value": "0456e2f5f56ec8ed16078941248e7cbba9f1c8eb",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-441",
          "title": "CISA KEV: CVE-2026-8398 \u2014 Daemon Tools Lite Embedded Malicious Code Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-05-27",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-05-27"
    },
    {
      "value": "0c1d3da9c7a651ba40b40e12d48ebd32b3f31820",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-441",
          "title": "CISA KEV: CVE-2026-8398 \u2014 Daemon Tools Lite Embedded Malicious Code Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-05-27",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-05-27"
    },
    {
      "value": "15ed5c3384e12fe4314ad6edbd1dcccf5ac1ee29",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-441",
          "title": "CISA KEV: CVE-2026-8398 \u2014 Daemon Tools Lite Embedded Malicious Code Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-05-27",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-05-27"
    },
    {
      "value": "28b72576d67ae21d9587d782942628ea46dcc870",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-441",
          "title": "CISA KEV: CVE-2026-8398 \u2014 Daemon Tools Lite Embedded Malicious Code Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-05-27",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-05-27"
    },
    {
      "value": "295ce86226b933e7262c2ce4b36bdd6c389aaaef",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-441",
          "title": "CISA KEV: CVE-2026-8398 \u2014 Daemon Tools Lite Embedded Malicious Code Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-05-27",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-05-27"
    },
    {
      "value": "2d4eb55b01f59c62c6de9aacba9b47267d398fe4",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-441",
          "title": "CISA KEV: CVE-2026-8398 \u2014 Daemon Tools Lite Embedded Malicious Code Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-05-27",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-05-27"
    },
    {
      "value": "2ecb292d27c36c1d4e47fb5cafa42af7ffbdda99",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-441",
          "title": "CISA KEV: CVE-2026-8398 \u2014 Daemon Tools Lite Embedded Malicious Code Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-05-27",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-05-27"
    },
    {
      "value": "3ee71d75020b2634b2c23866211a0c91b942c8d4",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-441",
          "title": "CISA KEV: CVE-2026-8398 \u2014 Daemon Tools Lite Embedded Malicious Code Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-05-27",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-05-27"
    },
    {
      "value": "427f1728682ebc7ffe3300fef67d0e3cb6b62948",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-441",
          "title": "CISA KEV: CVE-2026-8398 \u2014 Daemon Tools Lite Embedded Malicious Code Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-05-27",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-05-27"
    },
    {
      "value": "46b90bf370e60d61075d3472828fdc0b85ab0492",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-441",
          "title": "CISA KEV: CVE-2026-8398 \u2014 Daemon Tools Lite Embedded Malicious Code Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-05-27",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-05-27"
    },
    {
      "value": "50d47adb6dd45215c7cb4c68bae28b129ca09645",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-441",
          "title": "CISA KEV: CVE-2026-8398 \u2014 Daemon Tools Lite Embedded Malicious Code Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-05-27",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-05-27"
    },
    {
      "value": "524d2d92909eef80c406e87a0fc37d7bb4dadc14",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-441",
          "title": "CISA KEV: CVE-2026-8398 \u2014 Daemon Tools Lite Embedded Malicious Code Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-05-27",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-05-27"
    },
    {
      "value": "6325179f442e5b1a716580cd70dea644ac9ecd18",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-441",
          "title": "CISA KEV: CVE-2026-8398 \u2014 Daemon Tools Lite Embedded Malicious Code Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-05-27",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-05-27"
    },
    {
      "value": "64462f751788f529c1eb09023b26a47792ecdc54",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-441",
          "title": "CISA KEV: CVE-2026-8398 \u2014 Daemon Tools Lite Embedded Malicious Code Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-05-27",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-05-27"
    },
    {
      "value": "8d435918d304fc38d54b104a13f2e33e8e598c82",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-441",
          "title": "CISA KEV: CVE-2026-8398 \u2014 Daemon Tools Lite Embedded Malicious Code Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-05-27",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-05-27"
    },
    {
      "value": "8e7eb0f5ac60dd3b4a9474d2544348c3bda48045",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-441",
          "title": "CISA KEV: CVE-2026-8398 \u2014 Daemon Tools Lite Embedded Malicious Code Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-05-27",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-05-27"
    },
    {
      "value": "98de8147394b74b27158e02ce9e7b0e25eb6e98a",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-441",
          "title": "CISA KEV: CVE-2026-8398 \u2014 Daemon Tools Lite Embedded Malicious Code Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-05-27",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-05-27"
    },
    {
      "value": "9a09ad7b7e9ff7a465aa1150541e231189911afb",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-441",
          "title": "CISA KEV: CVE-2026-8398 \u2014 Daemon Tools Lite Embedded Malicious Code Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-05-27",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-05-27"
    },
    {
      "value": "9ccd769624de98eeeb12714ff1707ec4f5bf196d",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-441",
          "title": "CISA KEV: CVE-2026-8398 \u2014 Daemon Tools Lite Embedded Malicious Code Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-05-27",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-05-27"
    },
    {
      "value": "9dbfc23ebf36b3c0b56d2f93116abb32656c42e4",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-441",
          "title": "CISA KEV: CVE-2026-8398 \u2014 Daemon Tools Lite Embedded Malicious Code Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-05-27",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-05-27"
    },
    {
      "value": "a3e90653bd0a81ebe2ae387a67a59bb8d07ce7b5",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-441",
          "title": "CISA KEV: CVE-2026-8398 \u2014 Daemon Tools Lite Embedded Malicious Code Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-05-27",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-05-27"
    },
    {
      "value": "aea55e42c4436236278e5692d3dcbcbe5fe6ce0b",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-441",
          "title": "CISA KEV: CVE-2026-8398 \u2014 Daemon Tools Lite Embedded Malicious Code Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-05-27",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-05-27"
    },
    {
      "value": "bd8fbb5e6842df8683163adbd6a36136164eac58",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-441",
          "title": "CISA KEV: CVE-2026-8398 \u2014 Daemon Tools Lite Embedded Malicious Code Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-05-27",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-05-27"
    },
    {
      "value": "7c12d8614c624c70d6dd6fc2ee289332474abaa38f70ebe2cdef064923ca3a9b",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV",
        "Aikido"
      ],
      "articles": [
        {
          "id": "art-440",
          "title": "CISA KEV: CVE-2026-45321 \u2014 TanStack Unspecified Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-05-27",
          "sev": "crit"
        },
        {
          "id": "art-442",
          "title": "Why developer machines are now the number one target for supply chain attacks",
          "link": "https://www.aikido.dev/blog/developer-machines-supply-chain-attacks",
          "published": "2026-05-26",
          "sev": "high"
        }
      ],
      "first_seen": "2026-05-27"
    },
    {
      "value": "anyclaw.store",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "Aikido"
      ],
      "articles": [
        {
          "id": "art-434",
          "title": "Legitimate-Looking Codex Remote UI Secretly Steals Your AI Tokens",
          "link": "https://www.aikido.dev/blog/codex-remote-ui-steals-ai-tokens",
          "published": "2026-05-27",
          "sev": "high"
        }
      ],
      "first_seen": "2026-05-27"
    },
    {
      "value": "gyx.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "Aikido"
      ],
      "articles": [
        {
          "id": "art-434",
          "title": "Legitimate-Looking Codex Remote UI Secretly Steals Your AI Tokens",
          "link": "https://www.aikido.dev/blog/codex-remote-ui-steals-ai-tokens",
          "published": "2026-05-27",
          "sev": "high"
        }
      ],
      "first_seen": "2026-05-27"
    },
    {
      "value": "sentry.anyclaw.store",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "Aikido"
      ],
      "articles": [
        {
          "id": "art-434",
          "title": "Legitimate-Looking Codex Remote UI Secretly Steals Your AI Tokens",
          "link": "https://www.aikido.dev/blog/codex-remote-ui-steals-ai-tokens",
          "published": "2026-05-27",
          "sev": "high"
        }
      ],
      "first_seen": "2026-05-27"
    },
    {
      "value": "CVE-2026-48172",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-444",
          "title": "CISA KEV: CVE-2026-48172 \u2014 LiteSpeed cPanel Plugin Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-05-26",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-05-26"
    },
    {
      "value": "arbsniper.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "ESET WeLiveSecurity"
      ],
      "articles": [
        {
          "id": "art-443",
          "title": "BTMOB: A stealthy RAT burrowing deep into Android devices",
          "link": "https://www.welivesecurity.com/en/malware/btmob-stealthy-rat-burrowing-deep-android-devices/",
          "published": "2026-05-26",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-05-26"
    },
    {
      "value": "104.21.64.137",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "ESET WeLiveSecurity"
      ],
      "articles": [
        {
          "id": "art-443",
          "title": "BTMOB: A stealthy RAT burrowing deep into Android devices",
          "link": "https://www.welivesecurity.com/en/malware/btmob-stealthy-rat-burrowing-deep-android-devices/",
          "published": "2026-05-26",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-05-26"
    },
    {
      "value": "142.251.183.138",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "ESET WeLiveSecurity"
      ],
      "articles": [
        {
          "id": "art-443",
          "title": "BTMOB: A stealthy RAT burrowing deep into Android devices",
          "link": "https://www.welivesecurity.com/en/malware/btmob-stealthy-rat-burrowing-deep-android-devices/",
          "published": "2026-05-26",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-05-26"
    },
    {
      "value": "173.194.193.138",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "ESET WeLiveSecurity"
      ],
      "articles": [
        {
          "id": "art-443",
          "title": "BTMOB: A stealthy RAT burrowing deep into Android devices",
          "link": "https://www.welivesecurity.com/en/malware/btmob-stealthy-rat-burrowing-deep-android-devices/",
          "published": "2026-05-26",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-05-26"
    },
    {
      "value": "173.194.194.94",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "ESET WeLiveSecurity"
      ],
      "articles": [
        {
          "id": "art-443",
          "title": "BTMOB: A stealthy RAT burrowing deep into Android devices",
          "link": "https://www.welivesecurity.com/en/malware/btmob-stealthy-rat-burrowing-deep-android-devices/",
          "published": "2026-05-26",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-05-26"
    },
    {
      "value": "173.194.206.106",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "ESET WeLiveSecurity"
      ],
      "articles": [
        {
          "id": "art-443",
          "title": "BTMOB: A stealthy RAT burrowing deep into Android devices",
          "link": "https://www.welivesecurity.com/en/malware/btmob-stealthy-rat-burrowing-deep-android-devices/",
          "published": "2026-05-26",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-05-26"
    },
    {
      "value": "178.156.177.192",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "ESET WeLiveSecurity"
      ],
      "articles": [
        {
          "id": "art-443",
          "title": "BTMOB: A stealthy RAT burrowing deep into Android devices",
          "link": "https://www.welivesecurity.com/en/malware/btmob-stealthy-rat-burrowing-deep-android-devices/",
          "published": "2026-05-26",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-05-26"
    },
    {
      "value": "191.101.131.250",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "ESET WeLiveSecurity"
      ],
      "articles": [
        {
          "id": "art-443",
          "title": "BTMOB: A stealthy RAT burrowing deep into Android devices",
          "link": "https://www.welivesecurity.com/en/malware/btmob-stealthy-rat-burrowing-deep-android-devices/",
          "published": "2026-05-26",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-05-26"
    },
    {
      "value": "191.96.224.87",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "ESET WeLiveSecurity"
      ],
      "articles": [
        {
          "id": "art-443",
          "title": "BTMOB: A stealthy RAT burrowing deep into Android devices",
          "link": "https://www.welivesecurity.com/en/malware/btmob-stealthy-rat-burrowing-deep-android-devices/",
          "published": "2026-05-26",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-05-26"
    },
    {
      "value": "191.96.225.241",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "ESET WeLiveSecurity"
      ],
      "articles": [
        {
          "id": "art-443",
          "title": "BTMOB: A stealthy RAT burrowing deep into Android devices",
          "link": "https://www.welivesecurity.com/en/malware/btmob-stealthy-rat-burrowing-deep-android-devices/",
          "published": "2026-05-26",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-05-26"
    },
    {
      "value": "191.96.78.172",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "ESET WeLiveSecurity"
      ],
      "articles": [
        {
          "id": "art-443",
          "title": "BTMOB: A stealthy RAT burrowing deep into Android devices",
          "link": "https://www.welivesecurity.com/en/malware/btmob-stealthy-rat-burrowing-deep-android-devices/",
          "published": "2026-05-26",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-05-26"
    },
    {
      "value": "191.96.78.28",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "ESET WeLiveSecurity"
      ],
      "articles": [
        {
          "id": "art-443",
          "title": "BTMOB: A stealthy RAT burrowing deep into Android devices",
          "link": "https://www.welivesecurity.com/en/malware/btmob-stealthy-rat-burrowing-deep-android-devices/",
          "published": "2026-05-26",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-05-26"
    },
    {
      "value": "191.96.79.133",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "ESET WeLiveSecurity"
      ],
      "articles": [
        {
          "id": "art-443",
          "title": "BTMOB: A stealthy RAT burrowing deep into Android devices",
          "link": "https://www.welivesecurity.com/en/malware/btmob-stealthy-rat-burrowing-deep-android-devices/",
          "published": "2026-05-26",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-05-26"
    },
    {
      "value": "191.96.79.179",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "ESET WeLiveSecurity"
      ],
      "articles": [
        {
          "id": "art-443",
          "title": "BTMOB: A stealthy RAT burrowing deep into Android devices",
          "link": "https://www.welivesecurity.com/en/malware/btmob-stealthy-rat-burrowing-deep-android-devices/",
          "published": "2026-05-26",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-05-26"
    },
    {
      "value": "191.96.79.41",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "ESET WeLiveSecurity"
      ],
      "articles": [
        {
          "id": "art-443",
          "title": "BTMOB: A stealthy RAT burrowing deep into Android devices",
          "link": "https://www.welivesecurity.com/en/malware/btmob-stealthy-rat-burrowing-deep-android-devices/",
          "published": "2026-05-26",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-05-26"
    },
    {
      "value": "192.178.209.95",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "ESET WeLiveSecurity"
      ],
      "articles": [
        {
          "id": "art-443",
          "title": "BTMOB: A stealthy RAT burrowing deep into Android devices",
          "link": "https://www.welivesecurity.com/en/malware/btmob-stealthy-rat-burrowing-deep-android-devices/",
          "published": "2026-05-26",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-05-26"
    },
    {
      "value": "195.160.221.203",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "ESET WeLiveSecurity"
      ],
      "articles": [
        {
          "id": "art-443",
          "title": "BTMOB: A stealthy RAT burrowing deep into Android devices",
          "link": "https://www.welivesecurity.com/en/malware/btmob-stealthy-rat-burrowing-deep-android-devices/",
          "published": "2026-05-26",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-05-26"
    },
    {
      "value": "200.9.155.153",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "ESET WeLiveSecurity"
      ],
      "articles": [
        {
          "id": "art-443",
          "title": "BTMOB: A stealthy RAT burrowing deep into Android devices",
          "link": "https://www.welivesecurity.com/en/malware/btmob-stealthy-rat-burrowing-deep-android-devices/",
          "published": "2026-05-26",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-05-26"
    },
    {
      "value": "74.125.132.95",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "ESET WeLiveSecurity"
      ],
      "articles": [
        {
          "id": "art-443",
          "title": "BTMOB: A stealthy RAT burrowing deep into Android devices",
          "link": "https://www.welivesecurity.com/en/malware/btmob-stealthy-rat-burrowing-deep-android-devices/",
          "published": "2026-05-26",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-05-26"
    },
    {
      "value": "74.125.202.103",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "ESET WeLiveSecurity"
      ],
      "articles": [
        {
          "id": "art-443",
          "title": "BTMOB: A stealthy RAT burrowing deep into Android devices",
          "link": "https://www.welivesecurity.com/en/malware/btmob-stealthy-rat-burrowing-deep-android-devices/",
          "published": "2026-05-26",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-05-26"
    },
    {
      "value": "78.135.93.123",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "ESET WeLiveSecurity"
      ],
      "articles": [
        {
          "id": "art-443",
          "title": "BTMOB: A stealthy RAT burrowing deep into Android devices",
          "link": "https://www.welivesecurity.com/en/malware/btmob-stealthy-rat-burrowing-deep-android-devices/",
          "published": "2026-05-26",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-05-26"
    },
    {
      "value": "79.133.57.141",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "ESET WeLiveSecurity"
      ],
      "articles": [
        {
          "id": "art-443",
          "title": "BTMOB: A stealthy RAT burrowing deep into Android devices",
          "link": "https://www.welivesecurity.com/en/malware/btmob-stealthy-rat-burrowing-deep-android-devices/",
          "published": "2026-05-26",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-05-26"
    },
    {
      "value": "02A52C4CC11748D44C9B49D508EE4E46425661981FA1406F30EC0830CB69DDC5",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "ESET WeLiveSecurity"
      ],
      "articles": [
        {
          "id": "art-443",
          "title": "BTMOB: A stealthy RAT burrowing deep into Android devices",
          "link": "https://www.welivesecurity.com/en/malware/btmob-stealthy-rat-burrowing-deep-android-devices/",
          "published": "2026-05-26",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-05-26"
    },
    {
      "value": "0A542751724A432A8448324613E0CE10393E41739A1800CBB7D5A2C648FCDC35",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "ESET WeLiveSecurity"
      ],
      "articles": [
        {
          "id": "art-443",
          "title": "BTMOB: A stealthy RAT burrowing deep into Android devices",
          "link": "https://www.welivesecurity.com/en/malware/btmob-stealthy-rat-burrowing-deep-android-devices/",
          "published": "2026-05-26",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-05-26"
    },
    {
      "value": "140A7F995B0336942691A2E93E2017FD575267C017C7D0728D69169306F91963",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "ESET WeLiveSecurity"
      ],
      "articles": [
        {
          "id": "art-443",
          "title": "BTMOB: A stealthy RAT burrowing deep into Android devices",
          "link": "https://www.welivesecurity.com/en/malware/btmob-stealthy-rat-burrowing-deep-android-devices/",
          "published": "2026-05-26",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-05-26"
    },
    {
      "value": "168F50BF9A87099094EF410E3AC33E676A6A8740A5437CD09E7B63D73DF8431A",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "ESET WeLiveSecurity"
      ],
      "articles": [
        {
          "id": "art-443",
          "title": "BTMOB: A stealthy RAT burrowing deep into Android devices",
          "link": "https://www.welivesecurity.com/en/malware/btmob-stealthy-rat-burrowing-deep-android-devices/",
          "published": "2026-05-26",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-05-26"
    },
    {
      "value": "1A60CB5F7E2FB7C09FC3DC8459108B26AC98EE73131F37A28CFDAD5FC75B7A7D",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "ESET WeLiveSecurity"
      ],
      "articles": [
        {
          "id": "art-443",
          "title": "BTMOB: A stealthy RAT burrowing deep into Android devices",
          "link": "https://www.welivesecurity.com/en/malware/btmob-stealthy-rat-burrowing-deep-android-devices/",
          "published": "2026-05-26",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-05-26"
    },
    {
      "value": "244D81FD9908CD17815501D4EDADEB1BAF1C421AA25D8BD61C7CB481C939540E",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "ESET WeLiveSecurity"
      ],
      "articles": [
        {
          "id": "art-443",
          "title": "BTMOB: A stealthy RAT burrowing deep into Android devices",
          "link": "https://www.welivesecurity.com/en/malware/btmob-stealthy-rat-burrowing-deep-android-devices/",
          "published": "2026-05-26",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-05-26"
    },
    {
      "value": "2525D1E427A9983B0B4CA0906A4B44FFB9814B23D53FD8A2E3AB6512B027C733",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "ESET WeLiveSecurity"
      ],
      "articles": [
        {
          "id": "art-443",
          "title": "BTMOB: A stealthy RAT burrowing deep into Android devices",
          "link": "https://www.welivesecurity.com/en/malware/btmob-stealthy-rat-burrowing-deep-android-devices/",
          "published": "2026-05-26",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-05-26"
    },
    {
      "value": "26A2268281E8043125EF72B92F8980B42912048753D56894BC378FB54C7C188A",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "ESET WeLiveSecurity"
      ],
      "articles": [
        {
          "id": "art-443",
          "title": "BTMOB: A stealthy RAT burrowing deep into Android devices",
          "link": "https://www.welivesecurity.com/en/malware/btmob-stealthy-rat-burrowing-deep-android-devices/",
          "published": "2026-05-26",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-05-26"
    },
    {
      "value": "512EDE9F2FA794907999F3C26165557FDFD383B7AAD71BA022CE2C8BA6C0019D",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "ESET WeLiveSecurity"
      ],
      "articles": [
        {
          "id": "art-443",
          "title": "BTMOB: A stealthy RAT burrowing deep into Android devices",
          "link": "https://www.welivesecurity.com/en/malware/btmob-stealthy-rat-burrowing-deep-android-devices/",
          "published": "2026-05-26",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-05-26"
    },
    {
      "value": "58AC130A8EBB09E37592AC69841483EDC5695D1545B1F04F23D5B760AC17CD94",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "ESET WeLiveSecurity"
      ],
      "articles": [
        {
          "id": "art-443",
          "title": "BTMOB: A stealthy RAT burrowing deep into Android devices",
          "link": "https://www.welivesecurity.com/en/malware/btmob-stealthy-rat-burrowing-deep-android-devices/",
          "published": "2026-05-26",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-05-26"
    },
    {
      "value": "5AAAF972C8BF39A98F2748E526DE3CC0370BA831997D7D9765CDABA599645C0D",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "ESET WeLiveSecurity"
      ],
      "articles": [
        {
          "id": "art-443",
          "title": "BTMOB: A stealthy RAT burrowing deep into Android devices",
          "link": "https://www.welivesecurity.com/en/malware/btmob-stealthy-rat-burrowing-deep-android-devices/",
          "published": "2026-05-26",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-05-26"
    },
    {
      "value": "6101D1E1811DB052F869F7EB3402DAD28DA7E92103D4A44EE43F95846A075012",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "ESET WeLiveSecurity"
      ],
      "articles": [
        {
          "id": "art-443",
          "title": "BTMOB: A stealthy RAT burrowing deep into Android devices",
          "link": "https://www.welivesecurity.com/en/malware/btmob-stealthy-rat-burrowing-deep-android-devices/",
          "published": "2026-05-26",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-05-26"
    },
    {
      "value": "676CB2D0A60403AFC06CEA1B572CB7261F706365FAC65621B5A4907893E7AC0D",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "ESET WeLiveSecurity"
      ],
      "articles": [
        {
          "id": "art-443",
          "title": "BTMOB: A stealthy RAT burrowing deep into Android devices",
          "link": "https://www.welivesecurity.com/en/malware/btmob-stealthy-rat-burrowing-deep-android-devices/",
          "published": "2026-05-26",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-05-26"
    },
    {
      "value": "6AE94CE710016D86ED7457236DEEF2C4C51478587F3609B6E827A348828B3931",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "ESET WeLiveSecurity"
      ],
      "articles": [
        {
          "id": "art-443",
          "title": "BTMOB: A stealthy RAT burrowing deep into Android devices",
          "link": "https://www.welivesecurity.com/en/malware/btmob-stealthy-rat-burrowing-deep-android-devices/",
          "published": "2026-05-26",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-05-26"
    },
    {
      "value": "6BBA64FA9E8A7B11CB2476CD071DE08986DB44B0783EFF211C68FA5594EF8143",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "ESET WeLiveSecurity"
      ],
      "articles": [
        {
          "id": "art-443",
          "title": "BTMOB: A stealthy RAT burrowing deep into Android devices",
          "link": "https://www.welivesecurity.com/en/malware/btmob-stealthy-rat-burrowing-deep-android-devices/",
          "published": "2026-05-26",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-05-26"
    },
    {
      "value": "6F9832EBB4C3054BEE4A6CE5CCB69C00E2020053E1308353343097E6A4041109",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "ESET WeLiveSecurity"
      ],
      "articles": [
        {
          "id": "art-443",
          "title": "BTMOB: A stealthy RAT burrowing deep into Android devices",
          "link": "https://www.welivesecurity.com/en/malware/btmob-stealthy-rat-burrowing-deep-android-devices/",
          "published": "2026-05-26",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-05-26"
    },
    {
      "value": "702261BA38B57ECC3A5407FED28B2F0611A74C2EC0C116AEA4F9E6DEF0899AED",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "ESET WeLiveSecurity"
      ],
      "articles": [
        {
          "id": "art-443",
          "title": "BTMOB: A stealthy RAT burrowing deep into Android devices",
          "link": "https://www.welivesecurity.com/en/malware/btmob-stealthy-rat-burrowing-deep-android-devices/",
          "published": "2026-05-26",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-05-26"
    },
    {
      "value": "75DD4FB011ED598374A46FC0D9C0D1D64A298341C34AFC83A56A6983CFD27764",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "ESET WeLiveSecurity"
      ],
      "articles": [
        {
          "id": "art-443",
          "title": "BTMOB: A stealthy RAT burrowing deep into Android devices",
          "link": "https://www.welivesecurity.com/en/malware/btmob-stealthy-rat-burrowing-deep-android-devices/",
          "published": "2026-05-26",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-05-26"
    },
    {
      "value": "7AC974899E8E05AAACD417577C97E382D5E8C5F7F4A85632CFFB47EC2F6AE4E0",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "ESET WeLiveSecurity"
      ],
      "articles": [
        {
          "id": "art-443",
          "title": "BTMOB: A stealthy RAT burrowing deep into Android devices",
          "link": "https://www.welivesecurity.com/en/malware/btmob-stealthy-rat-burrowing-deep-android-devices/",
          "published": "2026-05-26",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-05-26"
    },
    {
      "value": "8F09274E808E0063D51F34CAC82A5770B3DF30C792E426DA2F6A80657F27AFFC",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "ESET WeLiveSecurity"
      ],
      "articles": [
        {
          "id": "art-443",
          "title": "BTMOB: A stealthy RAT burrowing deep into Android devices",
          "link": "https://www.welivesecurity.com/en/malware/btmob-stealthy-rat-burrowing-deep-android-devices/",
          "published": "2026-05-26",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-05-26"
    },
    {
      "value": "97A0497DE585D3BE6EC75064AB3BD0979CD85561193C1F0669CCF4DB31330687",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "ESET WeLiveSecurity"
      ],
      "articles": [
        {
          "id": "art-443",
          "title": "BTMOB: A stealthy RAT burrowing deep into Android devices",
          "link": "https://www.welivesecurity.com/en/malware/btmob-stealthy-rat-burrowing-deep-android-devices/",
          "published": "2026-05-26",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-05-26"
    },
    {
      "value": "998A7ED1572AD9DC11375BC25294E1954E606B7CFF9FABC5C120713E597CD274",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "ESET WeLiveSecurity"
      ],
      "articles": [
        {
          "id": "art-443",
          "title": "BTMOB: A stealthy RAT burrowing deep into Android devices",
          "link": "https://www.welivesecurity.com/en/malware/btmob-stealthy-rat-burrowing-deep-android-devices/",
          "published": "2026-05-26",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-05-26"
    },
    {
      "value": "A1E457C52EAB430C20D48F2AC476E080386313F16EFB135A0471902CF68CE475",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "ESET WeLiveSecurity"
      ],
      "articles": [
        {
          "id": "art-443",
          "title": "BTMOB: A stealthy RAT burrowing deep into Android devices",
          "link": "https://www.welivesecurity.com/en/malware/btmob-stealthy-rat-burrowing-deep-android-devices/",
          "published": "2026-05-26",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-05-26"
    },
    {
      "value": "A764D73795ABE47AE640BA09999A18C47B5340E5ECC7B897AFEBF34F3F37638F",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "ESET WeLiveSecurity"
      ],
      "articles": [
        {
          "id": "art-443",
          "title": "BTMOB: A stealthy RAT burrowing deep into Android devices",
          "link": "https://www.welivesecurity.com/en/malware/btmob-stealthy-rat-burrowing-deep-android-devices/",
          "published": "2026-05-26",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-05-26"
    },
    {
      "value": "C6199E175FB988CBBEACDF0F5ACDF9ED83F5BDAAE5C95B7A6C27EE72CD11B0B1",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "ESET WeLiveSecurity"
      ],
      "articles": [
        {
          "id": "art-443",
          "title": "BTMOB: A stealthy RAT burrowing deep into Android devices",
          "link": "https://www.welivesecurity.com/en/malware/btmob-stealthy-rat-burrowing-deep-android-devices/",
          "published": "2026-05-26",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-05-26"
    },
    {
      "value": "C99139B0053C4C698EA0246D26D747F2A984C7ABA4613DA818ECD9F97899EF3A",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "ESET WeLiveSecurity"
      ],
      "articles": [
        {
          "id": "art-443",
          "title": "BTMOB: A stealthy RAT burrowing deep into Android devices",
          "link": "https://www.welivesecurity.com/en/malware/btmob-stealthy-rat-burrowing-deep-android-devices/",
          "published": "2026-05-26",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-05-26"
    },
    {
      "value": "D55057CD9110D12A192281356F06B94F342B9FEBB305CF0A5898A7E6AF40758F",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "ESET WeLiveSecurity"
      ],
      "articles": [
        {
          "id": "art-443",
          "title": "BTMOB: A stealthy RAT burrowing deep into Android devices",
          "link": "https://www.welivesecurity.com/en/malware/btmob-stealthy-rat-burrowing-deep-android-devices/",
          "published": "2026-05-26",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-05-26"
    },
    {
      "value": "DDCE0219923D152B8FACD303F058A6286CF1F6924992B9FB9F5BF4D96436CC39",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "ESET WeLiveSecurity"
      ],
      "articles": [
        {
          "id": "art-443",
          "title": "BTMOB: A stealthy RAT burrowing deep into Android devices",
          "link": "https://www.welivesecurity.com/en/malware/btmob-stealthy-rat-burrowing-deep-android-devices/",
          "published": "2026-05-26",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-05-26"
    },
    {
      "value": "E5A9FDFF900DD502E8F3DCE52D2D1B69AA9AFAFB5094A28F9037E8770DB0E63B",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "ESET WeLiveSecurity"
      ],
      "articles": [
        {
          "id": "art-443",
          "title": "BTMOB: A stealthy RAT burrowing deep into Android devices",
          "link": "https://www.welivesecurity.com/en/malware/btmob-stealthy-rat-burrowing-deep-android-devices/",
          "published": "2026-05-26",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-05-26"
    },
    {
      "value": "F76B13040C634F82A8332FF9443D84C89A5BCED51AE9ADAD7FD15C05FADB4324",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "ESET WeLiveSecurity"
      ],
      "articles": [
        {
          "id": "art-443",
          "title": "BTMOB: A stealthy RAT burrowing deep into Android devices",
          "link": "https://www.welivesecurity.com/en/malware/btmob-stealthy-rat-burrowing-deep-android-devices/",
          "published": "2026-05-26",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-05-26"
    },
    {
      "value": "CVE-2026-9082",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-450",
          "title": "CISA KEV: CVE-2026-9082 \u2014 Drupal Core SQL Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-05-22",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-05-22"
    },
    {
      "value": "actions-bot.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "StepSecurity"
      ],
      "articles": [
        {
          "id": "art-447",
          "title": "Megalodon: Mass GitHub Actions Secret Exfiltration Across 5,500+ Public Repositories",
          "link": "https://www.stepsecurity.io/blog/megalodon-mass-github-actions-secret-exfiltration-across-5-500-public-repositories",
          "published": "2026-05-22",
          "sev": "high"
        }
      ],
      "first_seen": "2026-05-22"
    },
    {
      "value": "github-ci.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "StepSecurity"
      ],
      "articles": [
        {
          "id": "art-447",
          "title": "Megalodon: Mass GitHub Actions Secret Exfiltration Across 5,500+ Public Repositories",
          "link": "https://www.stepsecurity.io/blog/megalodon-mass-github-actions-secret-exfiltration-across-5-500-public-repositories",
          "published": "2026-05-22",
          "sev": "high"
        }
      ],
      "first_seen": "2026-05-22"
    },
    {
      "value": "fifa26.shop",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "med",
      "sources": [
        "ESET WeLiveSecurity"
      ],
      "articles": [
        {
          "id": "art-448",
          "title": "Foul play: Fake FIFA websites target soccer fans looking for World Cup tickets, merchandise",
          "link": "https://www.welivesecurity.com/en/cybersecurity/foul-play-fake-fifa-world-cup-websites-tickets/",
          "published": "2026-05-22",
          "sev": "med"
        }
      ],
      "first_seen": "2026-05-22"
    },
    {
      "value": "fifaworldcup26.hospitality.fifa.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "med",
      "sources": [
        "ESET WeLiveSecurity"
      ],
      "articles": [
        {
          "id": "art-448",
          "title": "Foul play: Fake FIFA websites target soccer fans looking for World Cup tickets, merchandise",
          "link": "https://www.welivesecurity.com/en/cybersecurity/foul-play-fake-fifa-world-cup-websites-tickets/",
          "published": "2026-05-22",
          "sev": "med"
        }
      ],
      "first_seen": "2026-05-22"
    },
    {
      "value": "CVE-2025-34291",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-454",
          "title": "CISA KEV: CVE-2025-34291 \u2014 Langflow Origin Validation Error Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-05-21",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-05-21"
    },
    {
      "value": "CVE-2026-34926",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-455",
          "title": "CISA KEV: CVE-2026-34926 \u2014 Trend Micro Apex One (On-Premise) Directory Traversal Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-05-21",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-05-21"
    },
    {
      "value": "1c9e803c80cc7fed000022d4c94f4b5bc2e90062",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "StepSecurity"
      ],
      "articles": [
        {
          "id": "art-452",
          "title": "5 Supply Chain Attacks in 48 Hours: Why Securing One Layer Is Not Enough",
          "link": "https://www.stepsecurity.io/blog/5-supply-chain-attacks-in-48-hours-why-securing-one-layer-is-not-enough",
          "published": "2026-05-21",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-05-21"
    },
    {
      "value": "5c267592a87e92c2b005b338bd0d2724c2f64acb",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "StepSecurity"
      ],
      "articles": [
        {
          "id": "art-452",
          "title": "5 Supply Chain Attacks in 48 Hours: Why Securing One Layer Is Not Enough",
          "link": "https://www.stepsecurity.io/blog/5-supply-chain-attacks-in-48-hours-why-securing-one-layer-is-not-enough",
          "published": "2026-05-21",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-05-21"
    },
    {
      "value": "7f6120bb10c870b9fde146961a18e5bf0b3d4401",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "StepSecurity"
      ],
      "articles": [
        {
          "id": "art-452",
          "title": "5 Supply Chain Attacks in 48 Hours: Why Securing One Layer Is Not Enough",
          "link": "https://www.stepsecurity.io/blog/5-supply-chain-attacks-in-48-hours-why-securing-one-layer-is-not-enough",
          "published": "2026-05-21",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-05-21"
    },
    {
      "value": "99b7f41bf9e14a2a2c7cc524731336543f552178",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "StepSecurity"
      ],
      "articles": [
        {
          "id": "art-452",
          "title": "5 Supply Chain Attacks in 48 Hours: Why Securing One Layer Is Not Enough",
          "link": "https://www.stepsecurity.io/blog/5-supply-chain-attacks-in-48-hours-why-securing-one-layer-is-not-enough",
          "published": "2026-05-21",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-05-21"
    },
    {
      "value": "b9c83f01929e190cda300e76f688bf7ea7e37a7a",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "StepSecurity"
      ],
      "articles": [
        {
          "id": "art-452",
          "title": "5 Supply Chain Attacks in 48 Hours: Why Securing One Layer Is Not Enough",
          "link": "https://www.stepsecurity.io/blog/5-supply-chain-attacks-in-48-hours-why-securing-one-layer-is-not-enough",
          "published": "2026-05-21",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-05-21"
    },
    {
      "value": "f0448c62fc57b8a5ce23d8acd6e795cdd76a3b6c",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "StepSecurity"
      ],
      "articles": [
        {
          "id": "art-452",
          "title": "5 Supply Chain Attacks in 48 Hours: Why Securing One Layer Is Not Enough",
          "link": "https://www.stepsecurity.io/blog/5-supply-chain-attacks-in-48-hours-why-securing-one-layer-is-not-enough",
          "published": "2026-05-21",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-05-21"
    },
    {
      "value": "43f2b001846c4966073ebffa5be8f15e491a1e7d32bbd805d57406ff540e0dd9",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "StepSecurity",
        "Aikido"
      ],
      "articles": [
        {
          "id": "art-452",
          "title": "5 Supply Chain Attacks in 48 Hours: Why Securing One Layer Is Not Enough",
          "link": "https://www.stepsecurity.io/blog/5-supply-chain-attacks-in-48-hours-why-securing-one-layer-is-not-enough",
          "published": "2026-05-21",
          "sev": "crit"
        },
        {
          "id": "art-457",
          "title": "The Wild West of VS Code extensions and how a poisoned extension breached GitHub",
          "link": "https://www.aikido.dev/blog/vs-code-extension-github-breach",
          "published": "2026-05-20",
          "sev": "crit"
        },
        {
          "id": "art-458",
          "title": "GitHub breached via a malicious VS Code extension: why developer devices are the real target",
          "link": "https://www.aikido.dev/blog/github-breached-vs-code-extension",
          "published": "2026-05-20",
          "sev": "high"
        }
      ],
      "first_seen": "2026-05-21"
    },
    {
      "value": "877ff2531a63393c4cb9c3c86908b62d9c4fc3db971bc231c48537faae6cb3ec",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "StepSecurity",
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-452",
          "title": "5 Supply Chain Attacks in 48 Hours: Why Securing One Layer Is Not Enough",
          "link": "https://www.stepsecurity.io/blog/5-supply-chain-attacks-in-48-hours-why-securing-one-layer-is-not-enough",
          "published": "2026-05-21",
          "sev": "crit"
        },
        {
          "id": "art-468",
          "title": "The AntV Supply Chain Campaign Expands: Microsoft's `durabletask` PyPI Package Compromised",
          "link": "https://snyk.io/blog/durabletask-pypi-supply-chain-attack/",
          "published": "2026-05-19",
          "sev": "high"
        }
      ],
      "first_seen": "2026-05-21"
    },
    {
      "value": "cb86f4f223daa54467c7782a0d8607e9c84e2bb633e6f0e51d9a19579e200990",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "StepSecurity"
      ],
      "articles": [
        {
          "id": "art-452",
          "title": "5 Supply Chain Attacks in 48 Hours: Why Securing One Layer Is Not Enough",
          "link": "https://www.stepsecurity.io/blog/5-supply-chain-attacks-in-48-hours-why-securing-one-layer-is-not-enough",
          "published": "2026-05-21",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-05-21"
    },
    {
      "value": "CVE-2008-4250",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-461",
          "title": "CISA KEV: CVE-2008-4250 \u2014 Microsoft Windows Buffer Overflow Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-05-20",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-05-20"
    },
    {
      "value": "CVE-2009-1537",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-462",
          "title": "CISA KEV: CVE-2009-1537 \u2014 Microsoft DirectX NULL Byte Overwrite Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-05-20",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-05-20"
    },
    {
      "value": "CVE-2009-3459",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-463",
          "title": "CISA KEV: CVE-2009-3459 \u2014 Adobe Acrobat and Reader Heap-Based Buffer Overflow Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-05-20",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-05-20"
    },
    {
      "value": "CVE-2010-0249",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-464",
          "title": "CISA KEV: CVE-2010-0249 \u2014 Microsoft Internet Explorer Use-After-Free Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-05-20",
          "sev": "crit"
        },
        {
          "id": "art-465",
          "title": "CISA KEV: CVE-2010-0806 \u2014 Microsoft Internet Explorer Use-After-Free Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-05-20",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-05-20"
    },
    {
      "value": "CVE-2010-0806",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-465",
          "title": "CISA KEV: CVE-2010-0806 \u2014 Microsoft Internet Explorer Use-After-Free Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-05-20",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-05-20"
    },
    {
      "value": "CVE-2017-7692",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "ESET WeLiveSecurity"
      ],
      "articles": [
        {
          "id": "art-459",
          "title": "Webworm: New burrowing techniques",
          "link": "https://www.welivesecurity.com/en/eset-research/webworm-new-burrowing-techniques/",
          "published": "2026-05-20",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-05-20"
    },
    {
      "value": "CVE-2026-41091",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-466",
          "title": "CISA KEV: CVE-2026-41091 \u2014 Microsoft Defender Link Following Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-05-20",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-05-20"
    },
    {
      "value": "CVE-2026-45498",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-467",
          "title": "CISA KEV: CVE-2026-45498 \u2014 Microsoft Defender Denial of Service Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-05-20",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-05-20"
    },
    {
      "value": "360.homeunix.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-464",
          "title": "CISA KEV: CVE-2010-0249 \u2014 Microsoft Internet Explorer Use-After-Free Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-05-20",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-05-20"
    },
    {
      "value": "blog1.servebeer.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-464",
          "title": "CISA KEV: CVE-2010-0249 \u2014 Microsoft Internet Explorer Use-After-Free Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-05-20",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-05-20"
    },
    {
      "value": "filoups.info",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-464",
          "title": "CISA KEV: CVE-2010-0249 \u2014 Microsoft Internet Explorer Use-After-Free Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-05-20",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-05-20"
    },
    {
      "value": "ftp2.homeunix.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-464",
          "title": "CISA KEV: CVE-2010-0249 \u2014 Microsoft Internet Explorer Use-After-Free Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-05-20",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-05-20"
    },
    {
      "value": "github.com/anjsdgasdf/WordPress",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "ESET WeLiveSecurity"
      ],
      "articles": [
        {
          "id": "art-459",
          "title": "Webworm: New burrowing techniques",
          "link": "https://www.welivesecurity.com/en/eset-research/webworm-new-burrowing-techniques/",
          "published": "2026-05-20",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-05-20"
    },
    {
      "value": "google.homeunix.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-464",
          "title": "CISA KEV: CVE-2010-0249 \u2014 Microsoft Internet Explorer Use-After-Free Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-05-20",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-05-20"
    },
    {
      "value": "sl1.homelinux.org",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-464",
          "title": "CISA KEV: CVE-2010-0249 \u2014 Microsoft Internet Explorer Use-After-Free Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-05-20",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-05-20"
    },
    {
      "value": "update.ourhobby.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-464",
          "title": "CISA KEV: CVE-2010-0249 \u2014 Microsoft Internet Explorer Use-After-Free Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-05-20",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-05-20"
    },
    {
      "value": "voanews.ath.cx",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-464",
          "title": "CISA KEV: CVE-2010-0249 \u2014 Microsoft Internet Explorer Use-After-Free Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-05-20",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-05-20"
    },
    {
      "value": "yahoo.blogdns.net",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-464",
          "title": "CISA KEV: CVE-2010-0249 \u2014 Microsoft Internet Explorer Use-After-Free Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-05-20",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-05-20"
    },
    {
      "value": "ymail.ath.cx",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-464",
          "title": "CISA KEV: CVE-2010-0249 \u2014 Microsoft Internet Explorer Use-After-Free Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-05-20",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-05-20"
    },
    {
      "value": "104.243.23.43",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "ESET WeLiveSecurity"
      ],
      "articles": [
        {
          "id": "art-459",
          "title": "Webworm: New burrowing techniques",
          "link": "https://www.welivesecurity.com/en/eset-research/webworm-new-burrowing-techniques/",
          "published": "2026-05-20",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-05-20"
    },
    {
      "value": "108.61.200.151",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "ESET WeLiveSecurity"
      ],
      "articles": [
        {
          "id": "art-459",
          "title": "Webworm: New burrowing techniques",
          "link": "https://www.welivesecurity.com/en/eset-research/webworm-new-burrowing-techniques/",
          "published": "2026-05-20",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-05-20"
    },
    {
      "value": "144.168.60.233",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "ESET WeLiveSecurity"
      ],
      "articles": [
        {
          "id": "art-459",
          "title": "Webworm: New burrowing techniques",
          "link": "https://www.welivesecurity.com/en/eset-research/webworm-new-burrowing-techniques/",
          "published": "2026-05-20",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-05-20"
    },
    {
      "value": "45.77.13.67",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "ESET WeLiveSecurity"
      ],
      "articles": [
        {
          "id": "art-459",
          "title": "Webworm: New burrowing techniques",
          "link": "https://www.welivesecurity.com/en/eset-research/webworm-new-burrowing-techniques/",
          "published": "2026-05-20",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-05-20"
    },
    {
      "value": "64.176.85.158",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "ESET WeLiveSecurity"
      ],
      "articles": [
        {
          "id": "art-459",
          "title": "Webworm: New burrowing techniques",
          "link": "https://www.welivesecurity.com/en/eset-research/webworm-new-burrowing-techniques/",
          "published": "2026-05-20",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-05-20"
    },
    {
      "value": "0f9c5408335833e72fe73e6166b5a01b",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-464",
          "title": "CISA KEV: CVE-2010-0249 \u2014 Microsoft Internet Explorer Use-After-Free Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-05-20",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-05-20"
    },
    {
      "value": "3a33013a47c5dd8d1b92a4cfdcda3765",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-464",
          "title": "CISA KEV: CVE-2010-0249 \u2014 Microsoft Internet Explorer Use-After-Free Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-05-20",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-05-20"
    },
    {
      "value": "467eef090deb3517f05a48310fcfd4ee",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-464",
          "title": "CISA KEV: CVE-2010-0249 \u2014 Microsoft Internet Explorer Use-After-Free Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-05-20",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-05-20"
    },
    {
      "value": "4a47404fc21fff4a1bc492f9cd23139c",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-464",
          "title": "CISA KEV: CVE-2010-0249 \u2014 Microsoft Internet Explorer Use-After-Free Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-05-20",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-05-20"
    },
    {
      "value": "6a89fbe7b0d526e3d97b0da8418bf851",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-464",
          "title": "CISA KEV: CVE-2010-0249 \u2014 Microsoft Internet Explorer Use-After-Free Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-05-20",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-05-20"
    },
    {
      "value": "7a62295f70642fedf0d5a5637feb7986",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-464",
          "title": "CISA KEV: CVE-2010-0249 \u2014 Microsoft Internet Explorer Use-After-Free Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-05-20",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-05-20"
    },
    {
      "value": "9f880ac607cbd7cdfffa609c5883c708",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-464",
          "title": "CISA KEV: CVE-2010-0249 \u2014 Microsoft Internet Explorer Use-After-Free Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-05-20",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-05-20"
    },
    {
      "value": "cd36a3071a315c3be6ac3366d80bb59c",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-464",
          "title": "CISA KEV: CVE-2010-0249 \u2014 Microsoft Internet Explorer Use-After-Free Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-05-20",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-05-20"
    },
    {
      "value": "e3798c71d25816611a4cab031ae3c27a",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-464",
          "title": "CISA KEV: CVE-2010-0249 \u2014 Microsoft Internet Explorer Use-After-Free Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-05-20",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-05-20"
    },
    {
      "value": "1DF40A4A31B30B62EC33DC6FECC2C4408302ADC7",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "ESET WeLiveSecurity"
      ],
      "articles": [
        {
          "id": "art-459",
          "title": "Webworm: New burrowing techniques",
          "link": "https://www.welivesecurity.com/en/eset-research/webworm-new-burrowing-techniques/",
          "published": "2026-05-20",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-05-20"
    },
    {
      "value": "77F1970D620216C5FFF4E14A6CCC13FCCC267217",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "ESET WeLiveSecurity"
      ],
      "articles": [
        {
          "id": "art-459",
          "title": "Webworm: New burrowing techniques",
          "link": "https://www.welivesecurity.com/en/eset-research/webworm-new-burrowing-techniques/",
          "published": "2026-05-20",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-05-20"
    },
    {
      "value": "7DCFE9EE25841DFD58D3D6871BF867FE32141DFB",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "ESET WeLiveSecurity"
      ],
      "articles": [
        {
          "id": "art-459",
          "title": "Webworm: New burrowing techniques",
          "link": "https://www.welivesecurity.com/en/eset-research/webworm-new-burrowing-techniques/",
          "published": "2026-05-20",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-05-20"
    },
    {
      "value": "948159A7FC2E688386864BEA59FD40DFFC4B24D6",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "ESET WeLiveSecurity"
      ],
      "articles": [
        {
          "id": "art-459",
          "title": "Webworm: New burrowing techniques",
          "link": "https://www.welivesecurity.com/en/eset-research/webworm-new-burrowing-techniques/",
          "published": "2026-05-20",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-05-20"
    },
    {
      "value": "9d88f040c44b5f4d5f9db15ff89310776c168e99",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "Aikido"
      ],
      "articles": [
        {
          "id": "art-457",
          "title": "The Wild West of VS Code extensions and how a poisoned extension breached GitHub",
          "link": "https://www.aikido.dev/blog/vs-code-extension-github-breach",
          "published": "2026-05-20",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-05-20"
    },
    {
      "value": "A3C077BDF8898E612CCD65BC82E7960834ADB2A9",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "ESET WeLiveSecurity"
      ],
      "articles": [
        {
          "id": "art-459",
          "title": "Webworm: New burrowing techniques",
          "link": "https://www.welivesecurity.com/en/eset-research/webworm-new-burrowing-techniques/",
          "published": "2026-05-20",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-05-20"
    },
    {
      "value": "acfc3f957a63b4cde93ff645f2b6bf26a8ed1bbf",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "Aikido"
      ],
      "articles": [
        {
          "id": "art-457",
          "title": "The Wild West of VS Code extensions and how a poisoned extension breached GitHub",
          "link": "https://www.aikido.dev/blog/vs-code-extension-github-breach",
          "published": "2026-05-20",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-05-20"
    },
    {
      "value": "CB4E50433336707381429707F59C3CBE8D497D98",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "ESET WeLiveSecurity"
      ],
      "articles": [
        {
          "id": "art-459",
          "title": "Webworm: New burrowing techniques",
          "link": "https://www.welivesecurity.com/en/eset-research/webworm-new-burrowing-techniques/",
          "published": "2026-05-20",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-05-20"
    },
    {
      "value": "sh.azurestaticprovider.net",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "StepSecurity",
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-473",
          "title": "Active Supply Chain Attack: Malicious node-ipc Versions Published to npm",
          "link": "https://www.stepsecurity.io/blog/node-ipc-npm-supply-chain-attack",
          "published": "2026-05-19",
          "sev": "crit"
        },
        {
          "id": "art-477",
          "title": "Malicious node-ipc versions published to npm in suspected maintainer account compromise",
          "link": "https://snyk.io/blog/malicious-node-ipc-versions-published-npm/",
          "published": "2026-05-15",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-05-19"
    },
    {
      "value": "a68dd1e6a6e35ec3771e1f94fe796f55dfe65a2b94560516ff4ac189390dfa1c",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "Aikido",
        "StepSecurity",
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-471",
          "title": "Mini Shai-Hulud strikes again: npm worm compromises hundreds of @antv packages",
          "link": "https://www.aikido.dev/blog/mini-shai-hulud-antv-npm-supply-chain-attack",
          "published": "2026-05-19",
          "sev": "crit"
        },
        {
          "id": "art-474",
          "title": "Mini Shai-Hulud Hits AntV: 300+ Malicious npm Packages Published via Compromised Maintainer Account",
          "link": "https://snyk.io/blog/mini-shai-hulud-antv-npm-supply-chain-attack/",
          "published": "2026-05-18",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-05-19"
    },
    {
      "value": "bf9d8c0c3ed3ceaa831a13de27f1b1c7c7b7f01d2db4103bfdba4191940b0301",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "StepSecurity"
      ],
      "articles": [
        {
          "id": "art-473",
          "title": "Active Supply Chain Attack: Malicious node-ipc Versions Published to npm",
          "link": "https://www.stepsecurity.io/blog/node-ipc-npm-supply-chain-attack",
          "published": "2026-05-19",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-05-19"
    },
    {
      "value": "fb5c97557230a27460fdab01fafcfabeaa49590bafd5b6ef30501aa9e0a51142",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "Aikido",
        "StepSecurity",
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-471",
          "title": "Mini Shai-Hulud strikes again: npm worm compromises hundreds of @antv packages",
          "link": "https://www.aikido.dev/blog/mini-shai-hulud-antv-npm-supply-chain-attack",
          "published": "2026-05-19",
          "sev": "crit"
        },
        {
          "id": "art-474",
          "title": "Mini Shai-Hulud Hits AntV: 300+ Malicious npm Packages Published via Compromised Maintainer Account",
          "link": "https://snyk.io/blog/mini-shai-hulud-antv-npm-supply-chain-attack/",
          "published": "2026-05-18",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-05-19"
    },
    {
      "value": "git-service.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "Aikido"
      ],
      "articles": [
        {
          "id": "art-469",
          "title": "Microsoft's durabletask package on PyPi Compromised. Mini Shai Hulud attacks again... again!",
          "link": "https://www.aikido.dev/blog/durabletask-package-compromised-mini-shai-hulud",
          "published": "2026-05-19",
          "sev": "high"
        }
      ],
      "first_seen": "2026-05-19"
    },
    {
      "value": "m-kosche.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-474",
          "title": "Mini Shai-Hulud Hits AntV: 300+ Malicious npm Packages Published via Compromised Maintainer Account",
          "link": "https://snyk.io/blog/mini-shai-hulud-antv-npm-supply-chain-attack/",
          "published": "2026-05-18",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-05-18"
    },
    {
      "value": "b06b126b9e26af03a7ef2f8b8e90d446",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-474",
          "title": "Mini Shai-Hulud Hits AntV: 300+ Malicious npm Packages Published via Compromised Maintainer Account",
          "link": "https://snyk.io/blog/mini-shai-hulud-antv-npm-supply-chain-attack/",
          "published": "2026-05-18",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-05-18"
    },
    {
      "value": "783b4019fc5b942a29846132d28441c8fc31bed8",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-474",
          "title": "Mini Shai-Hulud Hits AntV: 300+ Malicious npm Packages Published via Compromised Maintainer Account",
          "link": "https://snyk.io/blog/mini-shai-hulud-antv-npm-supply-chain-attack/",
          "published": "2026-05-18",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-05-18"
    },
    {
      "value": "CVE-2026-42897",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-478",
          "title": "CISA KEV: CVE-2026-42897 \u2014 Microsoft Exchange Server Cross-Site Scripting Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-05-15",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-05-15"
    },
    {
      "value": "azurestaticprovider.net",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-477",
          "title": "Malicious node-ipc versions published to npm in suspected maintainer account compromise",
          "link": "https://snyk.io/blog/malicious-node-ipc-versions-published-npm/",
          "published": "2026-05-15",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-05-15"
    },
    {
      "value": "37.16.75.69",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-477",
          "title": "Malicious node-ipc versions published to npm in suspected maintainer account compromise",
          "link": "https://snyk.io/blog/malicious-node-ipc-versions-published-npm/",
          "published": "2026-05-15",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-05-15"
    },
    {
      "value": "CVE-2023-38831",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "ESET WeLiveSecurity",
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-481",
          "title": "FrostyNeighbor: Fresh mischief and digital shenanigans",
          "link": "https://www.welivesecurity.com/en/eset-research/frostyneighbor-fresh-mischief-digital-shenanigans/",
          "published": "2026-05-14",
          "sev": "crit"
        },
        {
          "id": "art-1372",
          "title": "CISA KEV: CVE-2024-29988 \u2014 Microsoft SmartScreen Prompt Security Feature Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-04-30",
          "sev": "crit"
        },
        {
          "id": "art-1621",
          "title": "CISA KEV: CVE-2023-38831 \u2014 RARLAB WinRAR Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-08-24",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-05-14"
    },
    {
      "value": "CVE-2024-42009",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "ESET WeLiveSecurity",
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-481",
          "title": "FrostyNeighbor: Fresh mischief and digital shenanigans",
          "link": "https://www.welivesecurity.com/en/eset-research/frostyneighbor-fresh-mischief-digital-shenanigans/",
          "published": "2026-05-14",
          "sev": "crit"
        },
        {
          "id": "art-956",
          "title": "CISA KEV: CVE-2024-42009 \u2014 RoundCube Webmail Cross-Site Scripting Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-06-09",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-05-14"
    },
    {
      "value": "book-happy.needbinding.icu",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "ESET WeLiveSecurity"
      ],
      "articles": [
        {
          "id": "art-481",
          "title": "FrostyNeighbor: Fresh mischief and digital shenanigans",
          "link": "https://www.welivesecurity.com/en/eset-research/frostyneighbor-fresh-mischief-digital-shenanigans/",
          "published": "2026-05-14",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-05-14"
    },
    {
      "value": "nama-belakang.nebao.icu",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "ESET WeLiveSecurity"
      ],
      "articles": [
        {
          "id": "art-481",
          "title": "FrostyNeighbor: Fresh mischief and digital shenanigans",
          "link": "https://www.welivesecurity.com/en/eset-research/frostyneighbor-fresh-mischief-digital-shenanigans/",
          "published": "2026-05-14",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-05-14"
    },
    {
      "value": "nebao.icu",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "ESET WeLiveSecurity"
      ],
      "articles": [
        {
          "id": "art-481",
          "title": "FrostyNeighbor: Fresh mischief and digital shenanigans",
          "link": "https://www.welivesecurity.com/en/eset-research/frostyneighbor-fresh-mischief-digital-shenanigans/",
          "published": "2026-05-14",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-05-14"
    },
    {
      "value": "needbinding.icu",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "ESET WeLiveSecurity"
      ],
      "articles": [
        {
          "id": "art-481",
          "title": "FrostyNeighbor: Fresh mischief and digital shenanigans",
          "link": "https://www.welivesecurity.com/en/eset-research/frostyneighbor-fresh-mischief-digital-shenanigans/",
          "published": "2026-05-14",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-05-14"
    },
    {
      "value": "43E30BE82D82B24A6496F6943ECB6877E83F88AB",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "ESET WeLiveSecurity"
      ],
      "articles": [
        {
          "id": "art-481",
          "title": "FrostyNeighbor: Fresh mischief and digital shenanigans",
          "link": "https://www.welivesecurity.com/en/eset-research/frostyneighbor-fresh-mischief-digital-shenanigans/",
          "published": "2026-05-14",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-05-14"
    },
    {
      "value": "776A43E46C36A539C916ED426745EE96E2392B39",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "ESET WeLiveSecurity"
      ],
      "articles": [
        {
          "id": "art-481",
          "title": "FrostyNeighbor: Fresh mischief and digital shenanigans",
          "link": "https://www.welivesecurity.com/en/eset-research/frostyneighbor-fresh-mischief-digital-shenanigans/",
          "published": "2026-05-14",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-05-14"
    },
    {
      "value": "8D1F2A6DF51C7783F2EAF1A0FC0FF8D032E5B57F",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "ESET WeLiveSecurity"
      ],
      "articles": [
        {
          "id": "art-481",
          "title": "FrostyNeighbor: Fresh mischief and digital shenanigans",
          "link": "https://www.welivesecurity.com/en/eset-research/frostyneighbor-fresh-mischief-digital-shenanigans/",
          "published": "2026-05-14",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-05-14"
    },
    {
      "value": "B65551D339AECE718EA1465BF3542C794C445EFC",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "ESET WeLiveSecurity"
      ],
      "articles": [
        {
          "id": "art-481",
          "title": "FrostyNeighbor: Fresh mischief and digital shenanigans",
          "link": "https://www.welivesecurity.com/en/eset-research/frostyneighbor-fresh-mischief-digital-shenanigans/",
          "published": "2026-05-14",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-05-14"
    },
    {
      "value": "833fd59ebe66a4449982c6d18db656b4",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "Aikido"
      ],
      "articles": [
        {
          "id": "art-486",
          "title": "Mini Shai-Hulud Is Back: npm Worm Hits over 160 Packages, including Mistral and Tanstack",
          "link": "https://www.aikido.dev/blog/mini-shai-hulud-is-back-tanstack-compromised",
          "published": "2026-05-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-05-11"
    },
    {
      "value": "b82e54923f7e440664d2d75bd31588ca",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "Aikido"
      ],
      "articles": [
        {
          "id": "art-486",
          "title": "Mini Shai-Hulud Is Back: npm Worm Hits over 160 Packages, including Mistral and Tanstack",
          "link": "https://www.aikido.dev/blog/mini-shai-hulud-is-back-tanstack-compromised",
          "published": "2026-05-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-05-11"
    },
    {
      "value": "12ed9a3c1f73617aefdb740480695c04405d7b4b",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "Aikido"
      ],
      "articles": [
        {
          "id": "art-486",
          "title": "Mini Shai-Hulud Is Back: npm Worm Hits over 160 Packages, including Mistral and Tanstack",
          "link": "https://www.aikido.dev/blog/mini-shai-hulud-is-back-tanstack-compromised",
          "published": "2026-05-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-05-11"
    },
    {
      "value": "CVE-2026-42208",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-490",
          "title": "CISA KEV: CVE-2026-42208 \u2014 BerriAI LiteLLM SQL Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-05-08",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-05-08"
    },
    {
      "value": "CVE-2025-29927",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "SentinelLabs",
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-492",
          "title": "PCPJack | Cloud Worm Evicts TeamPCP and Steals Credentials at Scale",
          "link": "https://www.sentinelone.com/labs/cloud-worm-evicts-teampcp-and-steals-credentials-at-scale/",
          "published": "2026-05-07",
          "sev": "crit"
        },
        {
          "id": "art-1034",
          "title": "CVE-2025-29927 Authorization Bypass in Next.js Middleware",
          "link": "https://snyk.io/blog/cve-2025-29927-authorization-bypass-in-next-js-middleware/",
          "published": "2025-03-23",
          "sev": "high"
        }
      ],
      "first_seen": "2026-05-07"
    },
    {
      "value": "CVE-2025-48703",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "SentinelLabs",
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-492",
          "title": "PCPJack | Cloud Worm Evicts TeamPCP and Steals Credentials at Scale",
          "link": "https://www.sentinelone.com/labs/cloud-worm-evicts-teampcp-and-steals-credentials-at-scale/",
          "published": "2026-05-07",
          "sev": "crit"
        },
        {
          "id": "art-821",
          "title": "CISA KEV: CVE-2025-48703 \u2014 CWP Control Web Panel OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-11-04",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-05-07"
    },
    {
      "value": "CVE-2025-55182",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "SentinelLabs",
        "CISA KEV",
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-492",
          "title": "PCPJack | Cloud Worm Evicts TeamPCP and Steals Credentials at Scale",
          "link": "https://www.sentinelone.com/labs/cloud-worm-evicts-teampcp-and-steals-credentials-at-scale/",
          "published": "2026-05-07",
          "sev": "crit"
        },
        {
          "id": "art-780",
          "title": "CISA KEV: CVE-2025-55182 \u2014 Meta React Server Components Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-12-05",
          "sev": "crit"
        },
        {
          "id": "art-782",
          "title": "Security Advisory: Critical RCE Vulnerabilities in React Server Components (CVE-2025-55182)",
          "link": "https://snyk.io/blog/security-advisory-critical-rce-vulnerabilities-react-server-components/",
          "published": "2025-12-03",
          "sev": "high"
        }
      ],
      "first_seen": "2026-05-07"
    },
    {
      "value": "CVE-2025-9501",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "SentinelLabs"
      ],
      "articles": [
        {
          "id": "art-492",
          "title": "PCPJack | Cloud Worm Evicts TeamPCP and Steals Credentials at Scale",
          "link": "https://www.sentinelone.com/labs/cloud-worm-evicts-teampcp-and-steals-credentials-at-scale/",
          "published": "2026-05-07",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-05-07"
    },
    {
      "value": "CVE-2026-1357",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "SentinelLabs"
      ],
      "articles": [
        {
          "id": "art-492",
          "title": "PCPJack | Cloud Worm Evicts TeamPCP and Steals Credentials at Scale",
          "link": "https://www.sentinelone.com/labs/cloud-worm-evicts-teampcp-and-steals-credentials-at-scale/",
          "published": "2026-05-07",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-05-07"
    },
    {
      "value": "CVE-2026-6973",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-495",
          "title": "CISA KEV: CVE-2026-6973 \u2014 Ivanti Endpoint Manager Mobile (EPMM) Improper Input Validation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-05-07",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-05-07"
    },
    {
      "value": "799BB5127CA54239D3D4A14367DB3B712012CF14",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "ESET WeLiveSecurity"
      ],
      "articles": [
        {
          "id": "art-493",
          "title": "Fake call logs, real payments: How CallPhantom tricks Android users",
          "link": "https://www.welivesecurity.com/en/eset-research/fake-call-logs-real-payments-how-callphantom-tricks-android-users/",
          "published": "2026-05-07",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-05-07"
    },
    {
      "value": "CVE-2026-0300",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-498",
          "title": "CISA KEV: CVE-2026-0300 \u2014 Palo Alto Networks PAN-OS Out-of-bounds Write Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-05-06",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-05-06"
    },
    {
      "value": "sqgame.com.cn",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "ESET WeLiveSecurity"
      ],
      "articles": [
        {
          "id": "art-500",
          "title": "A rigged game: ScarCruft compromises gaming platform in a supply-chain attack",
          "link": "https://www.welivesecurity.com/en/eset-research/rigged-game-scarcruft-compromises-gaming-platform-supply-chain-attack/",
          "published": "2026-05-05",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-05-05"
    },
    {
      "value": "sqgame.net",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "ESET WeLiveSecurity"
      ],
      "articles": [
        {
          "id": "art-500",
          "title": "A rigged game: ScarCruft compromises gaming platform in a supply-chain attack",
          "link": "https://www.welivesecurity.com/en/eset-research/rigged-game-scarcruft-compromises-gaming-platform-supply-chain-attack/",
          "published": "2026-05-05",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-05-05"
    },
    {
      "value": "xiazai.sqgame.com.cn",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "ESET WeLiveSecurity"
      ],
      "articles": [
        {
          "id": "art-500",
          "title": "A rigged game: ScarCruft compromises gaming platform in a supply-chain attack",
          "link": "https://www.welivesecurity.com/en/eset-research/rigged-game-scarcruft-compromises-gaming-platform-supply-chain-attack/",
          "published": "2026-05-05",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-05-05"
    },
    {
      "value": "03E3ECE9F48CF4104AAFC535790CA2FB3C6B26CF",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "ESET WeLiveSecurity"
      ],
      "articles": [
        {
          "id": "art-500",
          "title": "A rigged game: ScarCruft compromises gaming platform in a supply-chain attack",
          "link": "https://www.welivesecurity.com/en/eset-research/rigged-game-scarcruft-compromises-gaming-platform-supply-chain-attack/",
          "published": "2026-05-05",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-05-05"
    },
    {
      "value": "FC0C691DB7E2D2BD3B0B4C1E24D18DF72168B7D9",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "ESET WeLiveSecurity"
      ],
      "articles": [
        {
          "id": "art-500",
          "title": "A rigged game: ScarCruft compromises gaming platform in a supply-chain attack",
          "link": "https://www.welivesecurity.com/en/eset-research/rigged-game-scarcruft-compromises-gaming-platform-supply-chain-attack/",
          "published": "2026-05-05",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-05-05"
    },
    {
      "value": "cjn37-uyaaa-aaaac-qgnva-cai.raw.icp0.io",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "StepSecurity"
      ],
      "articles": [
        {
          "id": "art-504",
          "title": "CanisterSprawl: pgserve Compromised on npm: Malicious Versions Harvest Credentials and Exfiltrate to a Decentralized ICP Canister",
          "link": "https://www.stepsecurity.io/blog/pgserve-compromised-on-npm-malicious-versions-harvest-credentials",
          "published": "2026-05-04",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-05-04"
    },
    {
      "value": "telemetry.api-monitor.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "StepSecurity"
      ],
      "articles": [
        {
          "id": "art-504",
          "title": "CanisterSprawl: pgserve Compromised on npm: Malicious Versions Harvest Credentials and Exfiltrate to a Decentralized ICP Canister",
          "link": "https://www.stepsecurity.io/blog/pgserve-compromised-on-npm-malicious-versions-harvest-credentials",
          "published": "2026-05-04",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-05-04"
    },
    {
      "value": "4066781fa830224c8bbcc3aa005a396657f9c8f9016f9a64ad44a9d7f5f45e34",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "StepSecurity",
        "Aikido",
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-501",
          "title": "Shai-Hulud Worm Pivots to Multi-Cloud: intercom-client@7.0.4 Hijacked \u2014 361,000 Weekly Downloads, AWS, GCP, and Azure Credentials Now in Scope",
          "link": "https://www.stepsecurity.io/blog/shai-hulud-worm-pivots-to-multi-cloud-intercom-client-hijacked",
          "published": "2026-05-04",
          "sev": "crit"
        },
        {
          "id": "art-513",
          "title": "Mini Shai-Hulud Targets SAP npm Packages With a Bun-Based Secret Stealer",
          "link": "https://www.aikido.dev/blog/mini-shai-hulud-has-appeared",
          "published": "2026-04-29",
          "sev": "crit"
        },
        {
          "id": "art-515",
          "title": "\"A Mini Shai-Hulud Has Appeared\": Bun-Based Stealer Hits SAP @cap-js and mbt npm Packages",
          "link": "https://snyk.io/blog/bun-based-stealer-hits-sap-cap-js-mbt-npm-packages/",
          "published": "2026-04-29",
          "sev": "high"
        }
      ],
      "first_seen": "2026-05-04"
    },
    {
      "value": "80a3d2877813968ef847ae73b5eeeb70b9435254e74d7f07d8cf4057f0a710ac",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "StepSecurity",
        "Aikido",
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-501",
          "title": "Shai-Hulud Worm Pivots to Multi-Cloud: intercom-client@7.0.4 Hijacked \u2014 361,000 Weekly Downloads, AWS, GCP, and Azure Credentials Now in Scope",
          "link": "https://www.stepsecurity.io/blog/shai-hulud-worm-pivots-to-multi-cloud-intercom-client-hijacked",
          "published": "2026-05-04",
          "sev": "crit"
        },
        {
          "id": "art-513",
          "title": "Mini Shai-Hulud Targets SAP npm Packages With a Bun-Based Secret Stealer",
          "link": "https://www.aikido.dev/blog/mini-shai-hulud-has-appeared",
          "published": "2026-04-29",
          "sev": "crit"
        },
        {
          "id": "art-515",
          "title": "\"A Mini Shai-Hulud Has Appeared\": Bun-Based Stealer Hits SAP @cap-js and mbt npm Packages",
          "link": "https://snyk.io/blog/bun-based-stealer-hits-sap-cap-js-mbt-npm-packages/",
          "published": "2026-04-29",
          "sev": "high"
        }
      ],
      "first_seen": "2026-05-04"
    },
    {
      "value": "igotnofriendsonlineorirl-imgonnakmslmao.skyhanni.cloud",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "StepSecurity",
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-502",
          "title": "elementary-data Compromised on PyPI and GHCR: Forged Release Pushed via GitHub Actions Script Injection",
          "link": "https://www.stepsecurity.io/blog/elementary-data-compromised-on-pypi-and-ghcr-forged-release-pushed-via-github-actions-script-injection",
          "published": "2026-05-04",
          "sev": "high"
        },
        {
          "id": "art-520",
          "title": "Malicious Release of elementary-data PyPI Package Steals Cloud Credentials from Data Engineers",
          "link": "https://snyk.io/blog/malicious-release-of-elementary-data-pypi-package-steals-cloud-credentials-from-data-engineers/",
          "published": "2026-04-27",
          "sev": "high"
        }
      ],
      "first_seen": "2026-05-04"
    },
    {
      "value": "CVE-2026-31431",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-506",
          "title": "CISA KEV: CVE-2026-31431 \u2014 Linux Kernel Incorrect Resource Transfer Between Spheres Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-05-01",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-05-01"
    },
    {
      "value": "CVE-2026-41940",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-512",
          "title": "CISA KEV: CVE-2026-41940 \u2014 WebPros cPanel & WHM and WP2 (WordPress Squared) Missing Authentication for Critical Function Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-04-30",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-04-30"
    },
    {
      "value": "22evxpggnkyrxpluewqsrv5j4jtde6hut2peq3w44d6ase676qlkoead.onion",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-511",
          "title": "lightning PyPI Compromise: A Bun-Based Credential Stealer in Python",
          "link": "https://snyk.io/blog/lightning-pypi-compromise-bun-based-credential-stealer/",
          "published": "2026-04-30",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-04-30"
    },
    {
      "value": "40d0f21b64ec8fb3a7a1959897252e09",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-511",
          "title": "lightning PyPI Compromise: A Bun-Based Credential Stealer in Python",
          "link": "https://snyk.io/blog/lightning-pypi-compromise-bun-based-credential-stealer/",
          "published": "2026-04-30",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-04-30"
    },
    {
      "value": "f1b3e7b3eec3294c4d6b5f87854a52471f03997f",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-511",
          "title": "lightning PyPI Compromise: A Bun-Based Credential Stealer in Python",
          "link": "https://snyk.io/blog/lightning-pypi-compromise-bun-based-credential-stealer/",
          "published": "2026-04-30",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-04-30"
    },
    {
      "value": "56070a9d8de0c0ffb1ec5c309953cf4679432df5a78df9aeb020fbb73d2be9fb",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-511",
          "title": "lightning PyPI Compromise: A Bun-Based Credential Stealer in Python",
          "link": "https://snyk.io/blog/lightning-pypi-compromise-bun-based-credential-stealer/",
          "published": "2026-04-30",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-04-30"
    },
    {
      "value": "5f5852b5f604369945118937b058e49064612ac69826e0adadca39a357dfb5b1",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "Aikido",
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-507",
          "title": "Popular PyTorch Lightning Package Compromised by Mini Shai-Hulud",
          "link": "https://www.aikido.dev/blog/pytorch-lightning-pypi-compromise-mini-shai-hulud",
          "published": "2026-04-30",
          "sev": "high"
        },
        {
          "id": "art-511",
          "title": "lightning PyPI Compromise: A Bun-Based Credential Stealer in Python",
          "link": "https://snyk.io/blog/lightning-pypi-compromise-bun-based-credential-stealer/",
          "published": "2026-04-30",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-04-30"
    },
    {
      "value": "8046a11187c135da6959862ff3846e99ad15462d2ec8a2f77a30ad53ebd5dcf2",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "Aikido",
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-507",
          "title": "Popular PyTorch Lightning Package Compromised by Mini Shai-Hulud",
          "link": "https://www.aikido.dev/blog/pytorch-lightning-pypi-compromise-mini-shai-hulud",
          "published": "2026-04-30",
          "sev": "high"
        },
        {
          "id": "art-511",
          "title": "lightning PyPI Compromise: A Bun-Based Credential Stealer in Python",
          "link": "https://snyk.io/blog/lightning-pypi-compromise-bun-based-credential-stealer/",
          "published": "2026-04-30",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-04-30"
    },
    {
      "value": "0af7415d65753f6aede8c9c0f39be478666b9c12",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "Aikido",
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-513",
          "title": "Mini Shai-Hulud Targets SAP npm Packages With a Bun-Based Secret Stealer",
          "link": "https://www.aikido.dev/blog/mini-shai-hulud-has-appeared",
          "published": "2026-04-29",
          "sev": "crit"
        },
        {
          "id": "art-515",
          "title": "\"A Mini Shai-Hulud Has Appeared\": Bun-Based Stealer Hits SAP @cap-js and mbt npm Packages",
          "link": "https://snyk.io/blog/bun-based-stealer-hits-sap-cap-js-mbt-npm-packages/",
          "published": "2026-04-29",
          "sev": "high"
        }
      ],
      "first_seen": "2026-04-29"
    },
    {
      "value": "4b04304f6d51392e3f43856c94ca95800518a694",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "Aikido",
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-513",
          "title": "Mini Shai-Hulud Targets SAP npm Packages With a Bun-Based Secret Stealer",
          "link": "https://www.aikido.dev/blog/mini-shai-hulud-has-appeared",
          "published": "2026-04-29",
          "sev": "crit"
        },
        {
          "id": "art-515",
          "title": "\"A Mini Shai-Hulud Has Appeared\": Bun-Based Stealer Hits SAP @cap-js and mbt npm Packages",
          "link": "https://snyk.io/blog/bun-based-stealer-hits-sap-cap-js-mbt-npm-packages/",
          "published": "2026-04-29",
          "sev": "high"
        }
      ],
      "first_seen": "2026-04-29"
    },
    {
      "value": "7b6a28e92149637e5d7c7f4a2d3e54acd507c929",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "Aikido",
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-513",
          "title": "Mini Shai-Hulud Targets SAP npm Packages With a Bun-Based Secret Stealer",
          "link": "https://www.aikido.dev/blog/mini-shai-hulud-has-appeared",
          "published": "2026-04-29",
          "sev": "crit"
        },
        {
          "id": "art-515",
          "title": "\"A Mini Shai-Hulud Has Appeared\": Bun-Based Stealer Hits SAP @cap-js and mbt npm Packages",
          "link": "https://snyk.io/blog/bun-based-stealer-hits-sap-cap-js-mbt-npm-packages/",
          "published": "2026-04-29",
          "sev": "high"
        }
      ],
      "first_seen": "2026-04-29"
    },
    {
      "value": "e80824a19f48d778a746571bb15279b5679fd61c",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "Aikido",
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-513",
          "title": "Mini Shai-Hulud Targets SAP npm Packages With a Bun-Based Secret Stealer",
          "link": "https://www.aikido.dev/blog/mini-shai-hulud-has-appeared",
          "published": "2026-04-29",
          "sev": "crit"
        },
        {
          "id": "art-515",
          "title": "\"A Mini Shai-Hulud Has Appeared\": Bun-Based Stealer Hits SAP @cap-js and mbt npm Packages",
          "link": "https://snyk.io/blog/bun-based-stealer-hits-sap-cap-js-mbt-npm-packages/",
          "published": "2026-04-29",
          "sev": "high"
        }
      ],
      "first_seen": "2026-04-29"
    },
    {
      "value": "29ac906c8bd801dfe1cb39596197df49f80fff2270b3e7fbab52278c24e4f1a7",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "Aikido"
      ],
      "articles": [
        {
          "id": "art-513",
          "title": "Mini Shai-Hulud Targets SAP npm Packages With a Bun-Based Secret Stealer",
          "link": "https://www.aikido.dev/blog/mini-shai-hulud-has-appeared",
          "published": "2026-04-29",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-04-29"
    },
    {
      "value": "6f933d00b7d05678eb43c90963a80b8947c4ae6830182f89df31da9f568fea95",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "Aikido",
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-513",
          "title": "Mini Shai-Hulud Targets SAP npm Packages With a Bun-Based Secret Stealer",
          "link": "https://www.aikido.dev/blog/mini-shai-hulud-has-appeared",
          "published": "2026-04-29",
          "sev": "crit"
        },
        {
          "id": "art-515",
          "title": "\"A Mini Shai-Hulud Has Appeared\": Bun-Based Stealer Hits SAP @cap-js and mbt npm Packages",
          "link": "https://snyk.io/blog/bun-based-stealer-hits-sap-cap-js-mbt-npm-packages/",
          "published": "2026-04-29",
          "sev": "high"
        }
      ],
      "first_seen": "2026-04-29"
    },
    {
      "value": "CVE-2026-40478",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-517",
          "title": "Don't Panic: The Thymeleaf Template Injection That Only Hurts If You Let It (CVE-2026-40478)",
          "link": "https://snyk.io/blog/thymeleaf-injection/",
          "published": "2026-04-29",
          "sev": "high"
        }
      ],
      "first_seen": "2026-04-29"
    },
    {
      "value": "api.svix.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "Aikido"
      ],
      "articles": [
        {
          "id": "art-514",
          "title": "Someone published four versions of a fake \"tanstack\" package in 27 minutes to steal your .env files",
          "link": "https://www.aikido.dev/blog/fake-tanstack-packages-steal-env-files",
          "published": "2026-04-29",
          "sev": "high"
        }
      ],
      "first_seen": "2026-04-29"
    },
    {
      "value": "35baf8316645372eea40b91d48acb067",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-515",
          "title": "\"A Mini Shai-Hulud Has Appeared\": Bun-Based Stealer Hits SAP @cap-js and mbt npm Packages",
          "link": "https://snyk.io/blog/bun-based-stealer-hits-sap-cap-js-mbt-npm-packages/",
          "published": "2026-04-29",
          "sev": "high"
        }
      ],
      "first_seen": "2026-04-29"
    },
    {
      "value": "307d0fa7407d40e67d14e9d5a4c61ac5b4f20431",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-515",
          "title": "\"A Mini Shai-Hulud Has Appeared\": Bun-Based Stealer Hits SAP @cap-js and mbt npm Packages",
          "link": "https://snyk.io/blog/bun-based-stealer-hits-sap-cap-js-mbt-npm-packages/",
          "published": "2026-04-29",
          "sev": "high"
        }
      ],
      "first_seen": "2026-04-29"
    },
    {
      "value": "04ee5325c8900c9d644ed81c9012525b6fc19f21c65cef85b6ba98b6a0a23566",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "Aikido"
      ],
      "articles": [
        {
          "id": "art-514",
          "title": "Someone published four versions of a fake \"tanstack\" package in 27 minutes to steal your .env files",
          "link": "https://www.aikido.dev/blog/fake-tanstack-packages-steal-env-files",
          "published": "2026-04-29",
          "sev": "high"
        }
      ],
      "first_seen": "2026-04-29"
    },
    {
      "value": "72ec4571e27c06f1d48737477c2b38a4f90d699950dab8946b48591133dc4f90",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "Aikido"
      ],
      "articles": [
        {
          "id": "art-514",
          "title": "Someone published four versions of a fake \"tanstack\" package in 27 minutes to steal your .env files",
          "link": "https://www.aikido.dev/blog/fake-tanstack-packages-steal-env-files",
          "published": "2026-04-29",
          "sev": "high"
        }
      ],
      "first_seen": "2026-04-29"
    },
    {
      "value": "7bb84e6ba893248814cd3bac70b7bdc115740fba9e13419940c73460cbcd7b6f",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "Aikido"
      ],
      "articles": [
        {
          "id": "art-514",
          "title": "Someone published four versions of a fake \"tanstack\" package in 27 minutes to steal your .env files",
          "link": "https://www.aikido.dev/blog/fake-tanstack-packages-steal-env-files",
          "published": "2026-04-29",
          "sev": "high"
        }
      ],
      "first_seen": "2026-04-29"
    },
    {
      "value": "abc164807947b102164488a08161adb4ee08be6b78a371350a6b156eed0d97d9",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "Aikido"
      ],
      "articles": [
        {
          "id": "art-514",
          "title": "Someone published four versions of a fake \"tanstack\" package in 27 minutes to steal your .env files",
          "link": "https://www.aikido.dev/blog/fake-tanstack-packages-steal-env-files",
          "published": "2026-04-29",
          "sev": "high"
        }
      ],
      "first_seen": "2026-04-29"
    },
    {
      "value": "CVE-2024-1708",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-518",
          "title": "CISA KEV: CVE-2024-1708 \u2014 ConnectWise ScreenConnect Path Traversal Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-04-28",
          "sev": "crit"
        },
        {
          "id": "art-1419",
          "title": "CISA KEV: CVE-2024-1709 \u2014 ConnectWise ScreenConnect Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-02-22",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-04-28"
    },
    {
      "value": "CVE-2026-32202",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-519",
          "title": "CISA KEV: CVE-2026-32202 \u2014 Microsoft Windows Protection Mechanism Failure Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-04-28",
          "sev": "crit"
        },
        {
          "id": "art-700",
          "title": "CISA KEV: CVE-2026-21510 \u2014 Microsoft Windows Shell Protection Mechanism Failure Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-02-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-04-28"
    },
    {
      "value": "CVE-2026-3965",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-521",
          "title": "Qinglong task scheduler RCE vulnerabilities exploited in the wild for cryptomining",
          "link": "https://snyk.io/blog/qinglong-task-scheduler-rce-vulnerabilities/",
          "published": "2026-04-27",
          "sev": "high"
        }
      ],
      "first_seen": "2026-04-27"
    },
    {
      "value": "CVE-2026-4047",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-521",
          "title": "Qinglong task scheduler RCE vulnerabilities exploited in the wild for cryptomining",
          "link": "https://snyk.io/blog/qinglong-task-scheduler-rce-vulnerabilities/",
          "published": "2026-04-27",
          "sev": "high"
        }
      ],
      "first_seen": "2026-04-27"
    },
    {
      "value": "file.551911.xyz",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-521",
          "title": "Qinglong task scheduler RCE vulnerabilities exploited in the wild for cryptomining",
          "link": "https://snyk.io/blog/qinglong-task-scheduler-rce-vulnerabilities/",
          "published": "2026-04-27",
          "sev": "high"
        }
      ],
      "first_seen": "2026-04-27"
    },
    {
      "value": "b1e4b1f3aad0d489ab0e9208031c67402bbb8480",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-520",
          "title": "Malicious Release of elementary-data PyPI Package Steals Cloud Credentials from Data Engineers",
          "link": "https://snyk.io/blog/malicious-release-of-elementary-data-pypi-package-steals-cloud-credentials-from-data-engineers/",
          "published": "2026-04-27",
          "sev": "high"
        }
      ],
      "first_seen": "2026-04-27"
    },
    {
      "value": "31ecc5939de6d24cf60c50d4ca26cf7a8c322db82a8ce4bd122ebd89cf634255",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-520",
          "title": "Malicious Release of elementary-data PyPI Package Steals Cloud Credentials from Data Engineers",
          "link": "https://snyk.io/blog/malicious-release-of-elementary-data-pypi-package-steals-cloud-credentials-from-data-engineers/",
          "published": "2026-04-27",
          "sev": "high"
        }
      ],
      "first_seen": "2026-04-27"
    },
    {
      "value": "CVE-2024-57726",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-527",
          "title": "CISA KEV: CVE-2024-57726 \u2014 SimpleHelp Missing Authorization Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-04-24",
          "sev": "crit"
        },
        {
          "id": "art-1089",
          "title": "CISA KEV: CVE-2024-57727 \u2014 SimpleHelp Path Traversal Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-02-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-04-24"
    },
    {
      "value": "CVE-2024-57728",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-526",
          "title": "CISA KEV: CVE-2024-57728 \u2014 SimpleHelp Path Traversal Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-04-24",
          "sev": "crit"
        },
        {
          "id": "art-1089",
          "title": "CISA KEV: CVE-2024-57727 \u2014 SimpleHelp Path Traversal Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-02-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-04-24"
    },
    {
      "value": "CVE-2024-7399",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-525",
          "title": "CISA KEV: CVE-2024-7399 \u2014 Samsung MagicINFO 9 Server Path Traversal Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-04-24",
          "sev": "crit"
        },
        {
          "id": "art-978",
          "title": "CISA KEV: CVE-2025-4632 \u2014 Samsung MagicINFO 9 Server Path Traversal Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-05-22",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-04-24"
    },
    {
      "value": "CVE-2025-29635",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-524",
          "title": "CISA KEV: CVE-2025-29635 \u2014 D-Link DIR-823X Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-04-24",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-04-24"
    },
    {
      "value": "38.147.173.172",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-532",
          "title": "CISA KEV: CVE-2026-39987 \u2014 Marimo Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-04-23",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-04-23"
    },
    {
      "value": "43.231.113.50",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "ESET WeLiveSecurity"
      ],
      "articles": [
        {
          "id": "art-529",
          "title": "GopherWhisper: A burrow full of malware",
          "link": "https://www.welivesecurity.com/en/eset-research/gopherwhisper-burrow-full-malware/",
          "published": "2026-04-23",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-04-23"
    },
    {
      "value": "039eb329a173fce7efeca18611a8f2c0f7d24609",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "ESET WeLiveSecurity"
      ],
      "articles": [
        {
          "id": "art-529",
          "title": "GopherWhisper: A burrow full of malware",
          "link": "https://www.welivesecurity.com/en/eset-research/gopherwhisper-burrow-full-malware/",
          "published": "2026-04-23",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-04-23"
    },
    {
      "value": "57c2490e4db194d3503ee85635fb1d6f26e8c534",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "ESET WeLiveSecurity"
      ],
      "articles": [
        {
          "id": "art-529",
          "title": "GopherWhisper: A burrow full of malware",
          "link": "https://www.welivesecurity.com/en/eset-research/gopherwhisper-burrow-full-malware/",
          "published": "2026-04-23",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-04-23"
    },
    {
      "value": "5a1bbb40c442b12594a913431f8c6757a3a66e8f",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "ESET WeLiveSecurity"
      ],
      "articles": [
        {
          "id": "art-529",
          "title": "GopherWhisper: A burrow full of malware",
          "link": "https://www.welivesecurity.com/en/eset-research/gopherwhisper-burrow-full-malware/",
          "published": "2026-04-23",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-04-23"
    },
    {
      "value": "716554dc580a82cc17a1035add302c0766590964",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "ESET WeLiveSecurity"
      ],
      "articles": [
        {
          "id": "art-529",
          "title": "GopherWhisper: A burrow full of malware",
          "link": "https://www.welivesecurity.com/en/eset-research/gopherwhisper-burrow-full-malware/",
          "published": "2026-04-23",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-04-23"
    },
    {
      "value": "926974facfd0383c65458d6ef1f31fbb7c769e18",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "ESET WeLiveSecurity"
      ],
      "articles": [
        {
          "id": "art-529",
          "title": "GopherWhisper: A burrow full of malware",
          "link": "https://www.welivesecurity.com/en/eset-research/gopherwhisper-burrow-full-malware/",
          "published": "2026-04-23",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-04-23"
    },
    {
      "value": "ad7e264eb08415871617e45f21d03f7d71e4c36f",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "ESET WeLiveSecurity"
      ],
      "articles": [
        {
          "id": "art-529",
          "title": "GopherWhisper: A burrow full of malware",
          "link": "https://www.welivesecurity.com/en/eset-research/gopherwhisper-burrow-full-malware/",
          "published": "2026-04-23",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-04-23"
    },
    {
      "value": "c72e7540d6f12d74d8e737b02f31568385f575d7",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "ESET WeLiveSecurity"
      ],
      "articles": [
        {
          "id": "art-529",
          "title": "GopherWhisper: A burrow full of malware",
          "link": "https://www.welivesecurity.com/en/eset-research/gopherwhisper-burrow-full-malware/",
          "published": "2026-04-23",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-04-23"
    },
    {
      "value": "fa9e65e58eb8fa41fde0a0a870b7d24b298026d9",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "ESET WeLiveSecurity"
      ],
      "articles": [
        {
          "id": "art-529",
          "title": "GopherWhisper: A burrow full of malware",
          "link": "https://www.welivesecurity.com/en/eset-research/gopherwhisper-burrow-full-malware/",
          "published": "2026-04-23",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-04-23"
    },
    {
      "value": "37f34aa3b86db6898065f3ca886031978580a15251f2576f6d24c3b778907336",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "Aikido"
      ],
      "articles": [
        {
          "id": "art-528",
          "title": "Is Shai-Hulud Back? Compromised Bitwarden CLI Contains a Self-Propagating npm Worm",
          "link": "https://www.aikido.dev/blog/shai-hulud-npm-bitwarden-cli-compromise",
          "published": "2026-04-23",
          "sev": "high"
        }
      ],
      "first_seen": "2026-04-23"
    },
    {
      "value": "sync.geeker.indevs.in",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "Aikido"
      ],
      "articles": [
        {
          "id": "art-534",
          "title": "GPT-Proxy Backdoor in npm and PyPI turns Servers into Chinese LLM Relays",
          "link": "https://www.aikido.dev/blog/gpt-proxy-backdoor-npm-pypi-chinese-llm-relay",
          "published": "2026-04-22",
          "sev": "high"
        }
      ],
      "first_seen": "2026-04-22"
    },
    {
      "value": "3a3d8f8636fa1db21871005a49ecd7fa59688fa763622fa737ce6b899558b300",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "Aikido"
      ],
      "articles": [
        {
          "id": "art-534",
          "title": "GPT-Proxy Backdoor in npm and PyPI turns Servers into Chinese LLM Relays",
          "link": "https://www.aikido.dev/blog/gpt-proxy-backdoor-npm-pypi-chinese-llm-relay",
          "published": "2026-04-22",
          "sev": "high"
        }
      ],
      "first_seen": "2026-04-22"
    },
    {
      "value": "5d58ce3119c37f2bd552f4d883a4f4896dfcb8fb04875f844f999497e4ca846d",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "Aikido"
      ],
      "articles": [
        {
          "id": "art-534",
          "title": "GPT-Proxy Backdoor in npm and PyPI turns Servers into Chinese LLM Relays",
          "link": "https://www.aikido.dev/blog/gpt-proxy-backdoor-npm-pypi-chinese-llm-relay",
          "published": "2026-04-22",
          "sev": "high"
        }
      ],
      "first_seen": "2026-04-22"
    },
    {
      "value": "b3405b8456f4e82f192cdff6fdd5b290a58fafda01fbc08174105b922bd7b3cf",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "Aikido"
      ],
      "articles": [
        {
          "id": "art-534",
          "title": "GPT-Proxy Backdoor in npm and PyPI turns Servers into Chinese LLM Relays",
          "link": "https://www.aikido.dev/blog/gpt-proxy-backdoor-npm-pypi-chinese-llm-relay",
          "published": "2026-04-22",
          "sev": "high"
        }
      ],
      "first_seen": "2026-04-22"
    },
    {
      "value": "fb3ae78d09c119ec335c3b99a95c97d9bb6f92fd2c7c9b0d3e875347e2f25bb2",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "Aikido"
      ],
      "articles": [
        {
          "id": "art-534",
          "title": "GPT-Proxy Backdoor in npm and PyPI turns Servers into Chinese LLM Relays",
          "link": "https://www.aikido.dev/blog/gpt-proxy-backdoor-npm-pypi-chinese-llm-relay",
          "published": "2026-04-22",
          "sev": "high"
        }
      ],
      "first_seen": "2026-04-22"
    },
    {
      "value": "CVE-2023-27351",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-541",
          "title": "CISA KEV: CVE-2023-27351 \u2014 PaperCut NG/MF Improper Authentication Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-04-20",
          "sev": "crit"
        },
        {
          "id": "art-1778",
          "title": "CISA KEV: CVE-2023-27350 \u2014 PaperCut MF/NG Improper Access Control Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-04-21",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-04-20"
    },
    {
      "value": "CVE-2024-27199",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-545",
          "title": "CISA KEV: CVE-2024-27199 \u2014 JetBrains TeamCity Relative Path Traversal Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-04-20",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-04-20"
    },
    {
      "value": "CVE-2025-2749",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-540",
          "title": "CISA KEV: CVE-2025-2749 \u2014 Kentico Xperience Path Traversal Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-04-20",
          "sev": "crit"
        },
        {
          "id": "art-833",
          "title": "CISA KEV: CVE-2025-2746 \u2014 Kentico Xperience CMS Authentication Bypass Using an Alternate Path or Channel Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-10-20",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-04-20"
    },
    {
      "value": "CVE-2025-32975",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-544",
          "title": "CISA KEV: CVE-2025-32975 \u2014 Quest KACE Systems Management Appliance (SMA) Improper Authentication Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-04-20",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-04-20"
    },
    {
      "value": "CVE-2025-48700",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-542",
          "title": "CISA KEV: CVE-2025-48700 \u2014 Synacor Zimbra Collaboration Suite (ZCS) Cross-site Scripting Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-04-20",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-04-20"
    },
    {
      "value": "CVE-2026-34197",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-550",
          "title": "CISA KEV: CVE-2026-34197 \u2014 Apache ActiveMQ Improper Input Validation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-04-16",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-04-16"
    },
    {
      "value": "CVE-2009-0238",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-552",
          "title": "CISA KEV: CVE-2009-0238 \u2014 Microsoft Office Remote Code Execution",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-04-14",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-04-14"
    },
    {
      "value": "CVE-2026-32201",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-553",
          "title": "CISA KEV: CVE-2026-32201 \u2014 Microsoft SharePoint Server Improper Input Validation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-04-14",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-04-14"
    },
    {
      "value": "CVE-2012-1854",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-555",
          "title": "CISA KEV: CVE-2012-1854 \u2014 Microsoft Visual Basic for Applications Insecure Library Loading Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-04-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-04-13"
    },
    {
      "value": "CVE-2020-9715",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-559",
          "title": "CISA KEV: CVE-2020-9715 \u2014 Adobe Acrobat Use-After-Free Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-04-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-04-13"
    },
    {
      "value": "CVE-2023-21529",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-557",
          "title": "CISA KEV: CVE-2023-21529 \u2014 Microsoft Exchange Server Deserialization of Untrusted Data Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-04-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-04-13"
    },
    {
      "value": "CVE-2023-36424",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-558",
          "title": "CISA KEV: CVE-2023-36424 \u2014 Microsoft Windows Out-of-Bounds Read Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-04-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-04-13"
    },
    {
      "value": "CVE-2025-60710",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-556",
          "title": "CISA KEV: CVE-2025-60710 \u2014 Microsoft Windows Link Following Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-04-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-04-13"
    },
    {
      "value": "CVE-2026-21643",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-560",
          "title": "CISA KEV: CVE-2026-21643 \u2014 Fortinet FortiClient EMS SQL Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-04-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-04-13"
    },
    {
      "value": "CVE-2026-34621",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-561",
          "title": "CISA KEV: CVE-2026-34621 \u2014 Adobe Acrobat and Reader Prototype Pollution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-04-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-04-13"
    },
    {
      "value": "api.metrics-trustwallet.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "StepSecurity"
      ],
      "articles": [
        {
          "id": "art-562",
          "title": "Securing Vibe Coding and AI Coding Agents: An End-to-End Approach with StepSecurity",
          "link": "https://www.stepsecurity.io/blog/securing-vibe-coding-and-ai-coding-agents-an-end-to-end-approach-with-stepsecurity",
          "published": "2026-04-12",
          "sev": "high"
        }
      ],
      "first_seen": "2026-04-12"
    },
    {
      "value": "metrics-trustwallet.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "StepSecurity"
      ],
      "articles": [
        {
          "id": "art-562",
          "title": "Securing Vibe Coding and AI Coding Agents: An End-to-End Approach with StepSecurity",
          "link": "https://www.stepsecurity.io/blog/securing-vibe-coding-and-ai-coding-agents-an-end-to-end-approach-with-stepsecurity",
          "published": "2026-04-12",
          "sev": "high"
        }
      ],
      "first_seen": "2026-04-12"
    },
    {
      "value": "CVE-2026-25253",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "StepSecurity"
      ],
      "articles": [
        {
          "id": "art-571",
          "title": "Cline Supply Chain Attack Detected: cline@2.3.0 Silently Installs OpenClaw",
          "link": "https://www.stepsecurity.io/blog/cline-supply-chain-attack-detected-cline-2-3-0-silently-installs-openclaw",
          "published": "2026-04-09",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-04-09"
    },
    {
      "value": "hackmoltrepeat.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "StepSecurity"
      ],
      "articles": [
        {
          "id": "art-570",
          "title": "hackerbot-claw: An AI-Powered Bot Actively Exploiting GitHub Actions - Microsoft, DataDog, and CNCF Projects Hit So Far",
          "link": "https://www.stepsecurity.io/blog/hackerbot-claw-github-actions-exploitation",
          "published": "2026-04-09",
          "sev": "high"
        }
      ],
      "first_seen": "2026-04-09"
    },
    {
      "value": "recv.hackmoltrepeat.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "StepSecurity"
      ],
      "articles": [
        {
          "id": "art-570",
          "title": "hackerbot-claw: An AI-Powered Bot Actively Exploiting GitHub Actions - Microsoft, DataDog, and CNCF Projects Hit So Far",
          "link": "https://www.stepsecurity.io/blog/hackerbot-claw-github-actions-exploitation",
          "published": "2026-04-09",
          "sev": "high"
        }
      ],
      "first_seen": "2026-04-09"
    },
    {
      "value": "CVE-2026-1340",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-573",
          "title": "CISA KEV: CVE-2026-1340 \u2014 Ivanti Endpoint Manager Mobile (EPMM) Code Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-04-08",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-04-08"
    },
    {
      "value": "github.com/ColossusQuailPray/oiegjqde",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "Aikido"
      ],
      "articles": [
        {
          "id": "art-572",
          "title": "GlassWorm goes native: New Zig dropper infects every IDE on your machine",
          "link": "https://www.aikido.dev/blog/glassworm-zig-dropper-infects-every-ide-on-your-machine",
          "published": "2026-04-08",
          "sev": "high"
        }
      ],
      "first_seen": "2026-04-08"
    },
    {
      "value": "112d1b33dd9b0244525f51e59e6a79ac5ae452bf6e98c310e7b4fa7902e4db44",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "Aikido"
      ],
      "articles": [
        {
          "id": "art-572",
          "title": "GlassWorm goes native: New Zig dropper infects every IDE on your machine",
          "link": "https://www.aikido.dev/blog/glassworm-zig-dropper-infects-every-ide-on-your-machine",
          "published": "2026-04-08",
          "sev": "high"
        }
      ],
      "first_seen": "2026-04-08"
    },
    {
      "value": "2819ea44e22b9c47049e86894e544f3fd0de1d8afc7b545314bd3bc718bf2e02",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "Aikido"
      ],
      "articles": [
        {
          "id": "art-572",
          "title": "GlassWorm goes native: New Zig dropper infects every IDE on your machine",
          "link": "https://www.aikido.dev/blog/glassworm-zig-dropper-infects-every-ide-on-your-machine",
          "published": "2026-04-08",
          "sev": "high"
        }
      ],
      "first_seen": "2026-04-08"
    },
    {
      "value": "CVE-2026-35616",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-576",
          "title": "CISA KEV: CVE-2026-35616 \u2014 Fortinet FortiClient EMS Improper Access Control Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-04-06",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-04-06"
    },
    {
      "value": "CVE-2026-3502",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-580",
          "title": "CISA KEV: CVE-2026-3502 \u2014 TrueConf Client Download of Code Without Integrity Check Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-04-02",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-04-02"
    },
    {
      "value": "cdn.rraghh.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "StepSecurity"
      ],
      "articles": [
        {
          "id": "art-577",
          "title": "Malicious IoliteLabs VSCode Extensions Target Solidity Developers on Windows, macOS, and Linux with Backdoor",
          "link": "https://www.stepsecurity.io/blog/malicious-iolitelabs-vscode-extensions-target-solidity-developers-on-windows-macos-and-linux-with-backdoor",
          "published": "2026-04-02",
          "sev": "high"
        }
      ],
      "first_seen": "2026-04-02"
    },
    {
      "value": "championships-peoples-point-cassette.trycloudflare.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-579",
          "title": "You Patched LiteLLM, But Do You Know Your AI Blast Radius?",
          "link": "https://snyk.io/blog/litellm-ai-blast-radius/",
          "published": "2026-04-02",
          "sev": "high"
        }
      ],
      "first_seen": "2026-04-02"
    },
    {
      "value": "investigation-launches-hearings-copying.trycloudflare.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-579",
          "title": "You Patched LiteLLM, But Do You Know Your AI Blast Radius?",
          "link": "https://snyk.io/blog/litellm-ai-blast-radius/",
          "published": "2026-04-02",
          "sev": "high"
        }
      ],
      "first_seen": "2026-04-02"
    },
    {
      "value": "oortt.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "StepSecurity"
      ],
      "articles": [
        {
          "id": "art-577",
          "title": "Malicious IoliteLabs VSCode Extensions Target Solidity Developers on Windows, macOS, and Linux with Backdoor",
          "link": "https://www.stepsecurity.io/blog/malicious-iolitelabs-vscode-extensions-target-solidity-developers-on-windows-macos-and-linux-with-backdoor",
          "published": "2026-04-02",
          "sev": "high"
        }
      ],
      "first_seen": "2026-04-02"
    },
    {
      "value": "rraghh.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "StepSecurity"
      ],
      "articles": [
        {
          "id": "art-577",
          "title": "Malicious IoliteLabs VSCode Extensions Target Solidity Developers on Windows, macOS, and Linux with Backdoor",
          "link": "https://www.stepsecurity.io/blog/malicious-iolitelabs-vscode-extensions-target-solidity-developers-on-windows-macos-and-linux-with-backdoor",
          "published": "2026-04-02",
          "sev": "high"
        }
      ],
      "first_seen": "2026-04-02"
    },
    {
      "value": "souls-entire-defined-routes.trycloudflare.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-579",
          "title": "You Patched LiteLLM, But Do You Know Your AI Blast Radius?",
          "link": "https://snyk.io/blog/litellm-ai-blast-radius/",
          "published": "2026-04-02",
          "sev": "high"
        }
      ],
      "first_seen": "2026-04-02"
    },
    {
      "value": "e903ae267bf7ed1d02b218c1dc7cf6d87257e87de9fbda411a13f9154716bfa3",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "StepSecurity"
      ],
      "articles": [
        {
          "id": "art-577",
          "title": "Malicious IoliteLabs VSCode Extensions Target Solidity Developers on Windows, macOS, and Linux with Backdoor",
          "link": "https://www.stepsecurity.io/blog/malicious-iolitelabs-vscode-extensions-target-solidity-developers-on-windows-macos-and-linux-with-backdoor",
          "published": "2026-04-02",
          "sev": "high"
        }
      ],
      "first_seen": "2026-04-02"
    },
    {
      "value": "fcd398abc51fd16e8bc93ef8d88a23d7dec28081b6dfce4b933020322a610508",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "StepSecurity"
      ],
      "articles": [
        {
          "id": "art-577",
          "title": "Malicious IoliteLabs VSCode Extensions Target Solidity Developers on Windows, macOS, and Linux with Backdoor",
          "link": "https://www.stepsecurity.io/blog/malicious-iolitelabs-vscode-extensions-target-solidity-developers-on-windows-macos-and-linux-with-backdoor",
          "published": "2026-04-02",
          "sev": "high"
        }
      ],
      "first_seen": "2026-04-02"
    },
    {
      "value": "CVE-2026-5281",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-583",
          "title": "CISA KEV: CVE-2026-5281 \u2014 Google Dawn Use-After-Free Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-04-01",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-04-01"
    },
    {
      "value": "617b67a8e1210e4fc87c92d1d1da45a2f311c08d26e89b12307cf583c900d101",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-585",
          "title": "Axios npm Package Compromised: Supply Chain Attack Delivers Cross-Platform RAT",
          "link": "https://snyk.io/blog/axios-npm-package-compromised-supply-chain-attack-delivers-cross-platform/",
          "published": "2026-03-30",
          "sev": "high"
        }
      ],
      "first_seen": "2026-03-30"
    },
    {
      "value": "92ff08773995ebc8d55ec4b8e1a225d0d1e51efa4ef88b8849d0071230c9645a",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-585",
          "title": "Axios npm Package Compromised: Supply Chain Attack Delivers Cross-Platform RAT",
          "link": "https://snyk.io/blog/axios-npm-package-compromised-supply-chain-attack-delivers-cross-platform/",
          "published": "2026-03-30",
          "sev": "high"
        }
      ],
      "first_seen": "2026-03-30"
    },
    {
      "value": "fcb81618bb15edfdedfb638b4c08a2af9cac9ecfa551af135a8402bf980375cf",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-585",
          "title": "Axios npm Package Compromised: Supply Chain Attack Delivers Cross-Platform RAT",
          "link": "https://snyk.io/blog/axios-npm-package-compromised-supply-chain-attack-delivers-cross-platform/",
          "published": "2026-03-30",
          "sev": "high"
        }
      ],
      "first_seen": "2026-03-30"
    },
    {
      "value": "CVE-2025-53521",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-590",
          "title": "CISA KEV: CVE-2025-53521 \u2014 F5 BIG-IP Stack-Based Buffer Overflow Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-03-27",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-03-27"
    },
    {
      "value": "cloudflareguard.vercel.app",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "StepSecurity"
      ],
      "articles": [
        {
          "id": "art-596",
          "title": "Malicious Polymarket Bot Hides in Hijacked dev-protocol GitHub Org and Steals Wallet Keys",
          "link": "https://www.stepsecurity.io/blog/malicious-polymarket-bot-hides-in-hijacked-dev-protocol-github-org-and-steals-wallet-keys",
          "published": "2026-03-26",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-03-26"
    },
    {
      "value": "cloudflareinsights.vercel.app",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "StepSecurity"
      ],
      "articles": [
        {
          "id": "art-596",
          "title": "Malicious Polymarket Bot Hides in Hijacked dev-protocol GitHub Org and Steals Wallet Keys",
          "link": "https://www.stepsecurity.io/blog/malicious-polymarket-bot-hides-in-hijacked-dev-protocol-github-org-and-steals-wallet-keys",
          "published": "2026-03-26",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-03-26"
    },
    {
      "value": "finney.metagraph-stats.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "StepSecurity"
      ],
      "articles": [
        {
          "id": "art-594",
          "title": "bittensor-wallet 4.0.2 Compromised on PyPI - Backdoor Exfiltrates Private Keys",
          "link": "https://www.stepsecurity.io/blog/bittensor-wallet-4-0-2-compromised-on-pypi---backdoor-exfiltrates-private-keys",
          "published": "2026-03-26",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-03-26"
    },
    {
      "value": "finney.opentensor-metrics.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "StepSecurity"
      ],
      "articles": [
        {
          "id": "art-594",
          "title": "bittensor-wallet 4.0.2 Compromised on PyPI - Backdoor Exfiltrates Private Keys",
          "link": "https://www.stepsecurity.io/blog/bittensor-wallet-4-0-2-compromised-on-pypi---backdoor-exfiltrates-private-keys",
          "published": "2026-03-26",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-03-26"
    },
    {
      "value": "finney.subtensor-telemetry.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "StepSecurity"
      ],
      "articles": [
        {
          "id": "art-594",
          "title": "bittensor-wallet 4.0.2 Compromised on PyPI - Backdoor Exfiltrates Private Keys",
          "link": "https://www.stepsecurity.io/blog/bittensor-wallet-4-0-2-compromised-on-pypi---backdoor-exfiltrates-private-keys",
          "published": "2026-03-26",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-03-26"
    },
    {
      "value": "opentensor-cdn.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "StepSecurity"
      ],
      "articles": [
        {
          "id": "art-594",
          "title": "bittensor-wallet 4.0.2 Compromised on PyPI - Backdoor Exfiltrates Private Keys",
          "link": "https://www.stepsecurity.io/blog/bittensor-wallet-4-0-2-compromised-on-pypi---backdoor-exfiltrates-private-keys",
          "published": "2026-03-26",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-03-26"
    },
    {
      "value": "t.opentensor-cdn.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "StepSecurity"
      ],
      "articles": [
        {
          "id": "art-594",
          "title": "bittensor-wallet 4.0.2 Compromised on PyPI - Backdoor Exfiltrates Private Keys",
          "link": "https://www.stepsecurity.io/blog/bittensor-wallet-4-0-2-compromised-on-pypi---backdoor-exfiltrates-private-keys",
          "published": "2026-03-26",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-03-26"
    },
    {
      "value": "tbqcbkpbhy.opentensor-cdn.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "StepSecurity"
      ],
      "articles": [
        {
          "id": "art-594",
          "title": "bittensor-wallet 4.0.2 Compromised on PyPI - Backdoor Exfiltrates Private Keys",
          "link": "https://www.stepsecurity.io/blog/bittensor-wallet-4-0-2-compromised-on-pypi---backdoor-exfiltrates-private-keys",
          "published": "2026-03-26",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-03-26"
    },
    {
      "value": "tuwyqibtvy.opentensor-cdn.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "StepSecurity"
      ],
      "articles": [
        {
          "id": "art-594",
          "title": "bittensor-wallet 4.0.2 Compromised on PyPI - Backdoor Exfiltrates Private Keys",
          "link": "https://www.stepsecurity.io/blog/bittensor-wallet-4-0-2-compromised-on-pypi---backdoor-exfiltrates-private-keys",
          "published": "2026-03-26",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-03-26"
    },
    {
      "value": "yccansiwfr.opentensor-cdn.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "StepSecurity"
      ],
      "articles": [
        {
          "id": "art-594",
          "title": "bittensor-wallet 4.0.2 Compromised on PyPI - Backdoor Exfiltrates Private Keys",
          "link": "https://www.stepsecurity.io/blog/bittensor-wallet-4-0-2-compromised-on-pypi---backdoor-exfiltrates-private-keys",
          "published": "2026-03-26",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-03-26"
    },
    {
      "value": "217.69.0.159",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "StepSecurity"
      ],
      "articles": [
        {
          "id": "art-597",
          "title": "ForceMemo: Hundreds of GitHub Python Repos Compromised via Account Takeover and Force-Push",
          "link": "https://www.stepsecurity.io/blog/forcememo-hundreds-of-github-python-repos-compromised-via-account-takeover-and-force-push",
          "published": "2026-03-26",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-03-26"
    },
    {
      "value": "6a416b72ff24804abc12484a3b41413a8580acedd8a5f8c84224fcf0732c2f8e",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "StepSecurity"
      ],
      "articles": [
        {
          "id": "art-594",
          "title": "bittensor-wallet 4.0.2 Compromised on PyPI - Backdoor Exfiltrates Private Keys",
          "link": "https://www.stepsecurity.io/blog/bittensor-wallet-4-0-2-compromised-on-pypi---backdoor-exfiltrates-private-keys",
          "published": "2026-03-26",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-03-26"
    },
    {
      "value": "security-verify.91.214.78.178.nip.io",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "StepSecurity"
      ],
      "articles": [
        {
          "id": "art-598",
          "title": "xygeni-action Compromised: C2 Reverse Shell Backdoor Injected via Tag Poisoning",
          "link": "https://www.stepsecurity.io/blog/xygeni-action-compromised-c2-reverse-shell-backdoor-injected-via-tag-poisoning",
          "published": "2026-03-26",
          "sev": "high"
        }
      ],
      "first_seen": "2026-03-26"
    },
    {
      "value": "91.214.78.178",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "StepSecurity"
      ],
      "articles": [
        {
          "id": "art-598",
          "title": "xygeni-action Compromised: C2 Reverse Shell Backdoor Injected via Tag Poisoning",
          "link": "https://www.stepsecurity.io/blog/xygeni-action-compromised-c2-reverse-shell-backdoor-injected-via-tag-poisoning",
          "published": "2026-03-26",
          "sev": "high"
        }
      ],
      "first_seen": "2026-03-26"
    },
    {
      "value": "CVE-2025-31277",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-610",
          "title": "CISA KEV: CVE-2025-43510 \u2014 Apple Multiple Products Improper Locking Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-03-20",
          "sev": "crit"
        },
        {
          "id": "art-612",
          "title": "CISA KEV: CVE-2025-31277 \u2014 Apple Multiple Products Buffer Overflow Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-03-20",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-03-20"
    },
    {
      "value": "CVE-2025-32432",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-608",
          "title": "CISA KEV: CVE-2025-32432 \u2014 Craft CMS Code Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-03-20",
          "sev": "crit"
        },
        {
          "id": "art-969",
          "title": "CISA KEV: CVE-2025-35939 \u2014 Craft CMS External Control of Assumed-Immutable Web Parameter Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-06-02",
          "sev": "crit"
        },
        {
          "id": "art-1003",
          "title": "CISA KEV: CVE-2024-58136 \u2014 Yiiframework Yii Improper Protection of Alternate Path Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-05-02",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-03-20"
    },
    {
      "value": "CVE-2025-43510",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-610",
          "title": "CISA KEV: CVE-2025-43510 \u2014 Apple Multiple Products Improper Locking Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-03-20",
          "sev": "crit"
        },
        {
          "id": "art-612",
          "title": "CISA KEV: CVE-2025-31277 \u2014 Apple Multiple Products Buffer Overflow Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-03-20",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-03-20"
    },
    {
      "value": "CVE-2025-43520",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-610",
          "title": "CISA KEV: CVE-2025-43510 \u2014 Apple Multiple Products Improper Locking Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-03-20",
          "sev": "crit"
        },
        {
          "id": "art-611",
          "title": "CISA KEV: CVE-2025-43520 \u2014 Apple Multiple Products Classic Buffer Overflow Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-03-20",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-03-20"
    },
    {
      "value": "CVE-2025-54068",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-609",
          "title": "CISA KEV: CVE-2025-54068 \u2014 Laravel Livewire Code Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-03-20",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-03-20"
    },
    {
      "value": "CVE-2026-20131",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-615",
          "title": "CISA KEV: CVE-2026-20131 \u2014 Cisco Secure Firewall Management Center (FMC) Software and Cisco Security Cloud Control (SCC) Firewall Management Deserialization of Untrusted Data Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-03-19",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-03-19"
    },
    {
      "value": "CVE-2026-20963",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-618",
          "title": "CISA KEV: CVE-2026-20963 \u2014 Microsoft SharePoint Deserialization of Untrusted Data Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-03-18",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-03-18"
    },
    {
      "value": "CVE-2025-47813",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-621",
          "title": "CISA KEV: CVE-2025-47813 \u2014 Wing FTP Server Information Disclosure Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-03-16",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-03-16"
    },
    {
      "value": "CVE-2026-3909",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-625",
          "title": "CISA KEV: CVE-2026-3909 \u2014 Google Skia Out-of-Bounds Write Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-03-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-03-13"
    },
    {
      "value": "CVE-2026-3910",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-624",
          "title": "CISA KEV: CVE-2026-3910 \u2014 Google Chromium V8 Improper Restriction of Operations Within the Bounds of a Memory Buffer Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-03-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-03-13"
    },
    {
      "value": "iili.io",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "Lab52"
      ],
      "articles": [
        {
          "id": "art-623",
          "title": "DRILLAPP: new backdoor targeting Ukrainian entities with possible links to Laundry Bear",
          "link": "https://lab52.io/blog/drillapp-new-backdoor-targeting-ukrainian-entities-with-possible-links-to-laundry-bear/",
          "published": "2026-03-13",
          "sev": "high"
        }
      ],
      "first_seen": "2026-03-13"
    },
    {
      "value": "pastefy.app",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "Lab52"
      ],
      "articles": [
        {
          "id": "art-623",
          "title": "DRILLAPP: new backdoor targeting Ukrainian entities with possible links to Laundry Bear",
          "link": "https://lab52.io/blog/drillapp-new-backdoor-targeting-ukrainian-entities-with-possible-links-to-laundry-bear/",
          "published": "2026-03-13",
          "sev": "high"
        }
      ],
      "first_seen": "2026-03-13"
    },
    {
      "value": "short-link.net",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "Lab52"
      ],
      "articles": [
        {
          "id": "art-623",
          "title": "DRILLAPP: new backdoor targeting Ukrainian entities with possible links to Laundry Bear",
          "link": "https://lab52.io/blog/drillapp-new-backdoor-targeting-ukrainian-entities-with-possible-links-to-laundry-bear/",
          "published": "2026-03-13",
          "sev": "high"
        }
      ],
      "first_seen": "2026-03-13"
    },
    {
      "value": "188.137.228.162",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "Lab52"
      ],
      "articles": [
        {
          "id": "art-623",
          "title": "DRILLAPP: new backdoor targeting Ukrainian entities with possible links to Laundry Bear",
          "link": "https://lab52.io/blog/drillapp-new-backdoor-targeting-ukrainian-entities-with-possible-links-to-laundry-bear/",
          "published": "2026-03-13",
          "sev": "high"
        }
      ],
      "first_seen": "2026-03-13"
    },
    {
      "value": "80.89.224.13",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "Lab52"
      ],
      "articles": [
        {
          "id": "art-623",
          "title": "DRILLAPP: new backdoor targeting Ukrainian entities with possible links to Laundry Bear",
          "link": "https://lab52.io/blog/drillapp-new-backdoor-targeting-ukrainian-entities-with-possible-links-to-laundry-bear/",
          "published": "2026-03-13",
          "sev": "high"
        }
      ],
      "first_seen": "2026-03-13"
    },
    {
      "value": "107b2badfc93fcdd3ffda7d3999477ced3f39f43f458dd0f6a424c9ab52681c3",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "Lab52"
      ],
      "articles": [
        {
          "id": "art-623",
          "title": "DRILLAPP: new backdoor targeting Ukrainian entities with possible links to Laundry Bear",
          "link": "https://lab52.io/blog/drillapp-new-backdoor-targeting-ukrainian-entities-with-possible-links-to-laundry-bear/",
          "published": "2026-03-13",
          "sev": "high"
        }
      ],
      "first_seen": "2026-03-13"
    },
    {
      "value": "21fefc3913d3d2dfde7f0dff54800ca7512eb5df9513b1a457a2af25fdd51b26",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "Lab52"
      ],
      "articles": [
        {
          "id": "art-623",
          "title": "DRILLAPP: new backdoor targeting Ukrainian entities with possible links to Laundry Bear",
          "link": "https://lab52.io/blog/drillapp-new-backdoor-targeting-ukrainian-entities-with-possible-links-to-laundry-bear/",
          "published": "2026-03-13",
          "sev": "high"
        }
      ],
      "first_seen": "2026-03-13"
    },
    {
      "value": "2b5d8f8db5fd38ae1c34807dcba35b057cffa61eb14ba3b558f82eb630480c3f",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "Lab52"
      ],
      "articles": [
        {
          "id": "art-623",
          "title": "DRILLAPP: new backdoor targeting Ukrainian entities with possible links to Laundry Bear",
          "link": "https://lab52.io/blog/drillapp-new-backdoor-targeting-ukrainian-entities-with-possible-links-to-laundry-bear/",
          "published": "2026-03-13",
          "sev": "high"
        }
      ],
      "first_seen": "2026-03-13"
    },
    {
      "value": "32973ef02e10a585a4a0196b013265e29fc57d8e1c50752f7b39e43b9f388715",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "Lab52"
      ],
      "articles": [
        {
          "id": "art-623",
          "title": "DRILLAPP: new backdoor targeting Ukrainian entities with possible links to Laundry Bear",
          "link": "https://lab52.io/blog/drillapp-new-backdoor-targeting-ukrainian-entities-with-possible-links-to-laundry-bear/",
          "published": "2026-03-13",
          "sev": "high"
        }
      ],
      "first_seen": "2026-03-13"
    },
    {
      "value": "352f34ea5cc40e2b3ec056ae60fa19a368dbd42503ef225cb1ca57956eb05e81",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "Lab52"
      ],
      "articles": [
        {
          "id": "art-623",
          "title": "DRILLAPP: new backdoor targeting Ukrainian entities with possible links to Laundry Bear",
          "link": "https://lab52.io/blog/drillapp-new-backdoor-targeting-ukrainian-entities-with-possible-links-to-laundry-bear/",
          "published": "2026-03-13",
          "sev": "high"
        }
      ],
      "first_seen": "2026-03-13"
    },
    {
      "value": "51e86408904c0ca3778361cde746783a0f2b9fd2a6782aa7e062aa597151876e",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "Lab52"
      ],
      "articles": [
        {
          "id": "art-623",
          "title": "DRILLAPP: new backdoor targeting Ukrainian entities with possible links to Laundry Bear",
          "link": "https://lab52.io/blog/drillapp-new-backdoor-targeting-ukrainian-entities-with-possible-links-to-laundry-bear/",
          "published": "2026-03-13",
          "sev": "high"
        }
      ],
      "first_seen": "2026-03-13"
    },
    {
      "value": "5b978cdc46afa28d83e532cd19622d9097bebedf87efc4c87bd35d8ffad9e672",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "Lab52"
      ],
      "articles": [
        {
          "id": "art-623",
          "title": "DRILLAPP: new backdoor targeting Ukrainian entities with possible links to Laundry Bear",
          "link": "https://lab52.io/blog/drillapp-new-backdoor-targeting-ukrainian-entities-with-possible-links-to-laundry-bear/",
          "published": "2026-03-13",
          "sev": "high"
        }
      ],
      "first_seen": "2026-03-13"
    },
    {
      "value": "6178b1af51057c0bac75a842afff500a8fa3ed957d79a712a6ef089bec7e7a8b",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "Lab52"
      ],
      "articles": [
        {
          "id": "art-623",
          "title": "DRILLAPP: new backdoor targeting Ukrainian entities with possible links to Laundry Bear",
          "link": "https://lab52.io/blog/drillapp-new-backdoor-targeting-ukrainian-entities-with-possible-links-to-laundry-bear/",
          "published": "2026-03-13",
          "sev": "high"
        }
      ],
      "first_seen": "2026-03-13"
    },
    {
      "value": "66a7828bc8c6c783b2ffa3c906d53f6dae1bbddc019283cc369d7d73247c5181",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "Lab52"
      ],
      "articles": [
        {
          "id": "art-623",
          "title": "DRILLAPP: new backdoor targeting Ukrainian entities with possible links to Laundry Bear",
          "link": "https://lab52.io/blog/drillapp-new-backdoor-targeting-ukrainian-entities-with-possible-links-to-laundry-bear/",
          "published": "2026-03-13",
          "sev": "high"
        }
      ],
      "first_seen": "2026-03-13"
    },
    {
      "value": "6fea579685d2433cedb1c32ef704575dcbc1d0a623769e824023ffccd0dedaae",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "Lab52"
      ],
      "articles": [
        {
          "id": "art-623",
          "title": "DRILLAPP: new backdoor targeting Ukrainian entities with possible links to Laundry Bear",
          "link": "https://lab52.io/blog/drillapp-new-backdoor-targeting-ukrainian-entities-with-possible-links-to-laundry-bear/",
          "published": "2026-03-13",
          "sev": "high"
        }
      ],
      "first_seen": "2026-03-13"
    },
    {
      "value": "76eb713e38f145ee68b89f2febd8f9a28bbb2b464da61cb029d84433a0b2c746",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "Lab52"
      ],
      "articles": [
        {
          "id": "art-623",
          "title": "DRILLAPP: new backdoor targeting Ukrainian entities with possible links to Laundry Bear",
          "link": "https://lab52.io/blog/drillapp-new-backdoor-targeting-ukrainian-entities-with-possible-links-to-laundry-bear/",
          "published": "2026-03-13",
          "sev": "high"
        }
      ],
      "first_seen": "2026-03-13"
    },
    {
      "value": "801c47550799831bfb1ac6c5c3fd698be95da19fc85bd65f5d8639f26244d2a9",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "Lab52"
      ],
      "articles": [
        {
          "id": "art-623",
          "title": "DRILLAPP: new backdoor targeting Ukrainian entities with possible links to Laundry Bear",
          "link": "https://lab52.io/blog/drillapp-new-backdoor-targeting-ukrainian-entities-with-possible-links-to-laundry-bear/",
          "published": "2026-03-13",
          "sev": "high"
        }
      ],
      "first_seen": "2026-03-13"
    },
    {
      "value": "886df55794cbca146de96dcc626471b3c097a5c20ba488033b24f4347aa20a14",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "Lab52"
      ],
      "articles": [
        {
          "id": "art-623",
          "title": "DRILLAPP: new backdoor targeting Ukrainian entities with possible links to Laundry Bear",
          "link": "https://lab52.io/blog/drillapp-new-backdoor-targeting-ukrainian-entities-with-possible-links-to-laundry-bear/",
          "published": "2026-03-13",
          "sev": "high"
        }
      ],
      "first_seen": "2026-03-13"
    },
    {
      "value": "8c6ea44ce7f4ed4e4e7e19e11b3b345d58785c93b33aa795ddd1b0d753236b05",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "Lab52"
      ],
      "articles": [
        {
          "id": "art-623",
          "title": "DRILLAPP: new backdoor targeting Ukrainian entities with possible links to Laundry Bear",
          "link": "https://lab52.io/blog/drillapp-new-backdoor-targeting-ukrainian-entities-with-possible-links-to-laundry-bear/",
          "published": "2026-03-13",
          "sev": "high"
        }
      ],
      "first_seen": "2026-03-13"
    },
    {
      "value": "9367f4b4d2775ff47279d143dd9a0ef544ddff81946aab33da9350a49f14e1e1",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "Lab52"
      ],
      "articles": [
        {
          "id": "art-623",
          "title": "DRILLAPP: new backdoor targeting Ukrainian entities with possible links to Laundry Bear",
          "link": "https://lab52.io/blog/drillapp-new-backdoor-targeting-ukrainian-entities-with-possible-links-to-laundry-bear/",
          "published": "2026-03-13",
          "sev": "high"
        }
      ],
      "first_seen": "2026-03-13"
    },
    {
      "value": "993d55f60414bf2092f421c3d0ac6af1897a21cc4ea260ae8e610a402bf4c81c",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "Lab52"
      ],
      "articles": [
        {
          "id": "art-623",
          "title": "DRILLAPP: new backdoor targeting Ukrainian entities with possible links to Laundry Bear",
          "link": "https://lab52.io/blog/drillapp-new-backdoor-targeting-ukrainian-entities-with-possible-links-to-laundry-bear/",
          "published": "2026-03-13",
          "sev": "high"
        }
      ],
      "first_seen": "2026-03-13"
    },
    {
      "value": "a545908c931ec47884b5ccfb1f112435f5d0cdac140e664673672c9df9016672",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "Lab52"
      ],
      "articles": [
        {
          "id": "art-623",
          "title": "DRILLAPP: new backdoor targeting Ukrainian entities with possible links to Laundry Bear",
          "link": "https://lab52.io/blog/drillapp-new-backdoor-targeting-ukrainian-entities-with-possible-links-to-laundry-bear/",
          "published": "2026-03-13",
          "sev": "high"
        }
      ],
      "first_seen": "2026-03-13"
    },
    {
      "value": "ac60eefc2607216f8126c0b22b6243f3862ef2bb265c585deee0d00a20a436b3",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "Lab52"
      ],
      "articles": [
        {
          "id": "art-623",
          "title": "DRILLAPP: new backdoor targeting Ukrainian entities with possible links to Laundry Bear",
          "link": "https://lab52.io/blog/drillapp-new-backdoor-targeting-ukrainian-entities-with-possible-links-to-laundry-bear/",
          "published": "2026-03-13",
          "sev": "high"
        }
      ],
      "first_seen": "2026-03-13"
    },
    {
      "value": "b891fa118db5190f07b18be46eb9bc10677f9afab1406a7d52ce587522ab3d28",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "Lab52"
      ],
      "articles": [
        {
          "id": "art-623",
          "title": "DRILLAPP: new backdoor targeting Ukrainian entities with possible links to Laundry Bear",
          "link": "https://lab52.io/blog/drillapp-new-backdoor-targeting-ukrainian-entities-with-possible-links-to-laundry-bear/",
          "published": "2026-03-13",
          "sev": "high"
        }
      ],
      "first_seen": "2026-03-13"
    },
    {
      "value": "bad7c6f6ca25363a02eaceb3ed1e378218dc4a246a63d723cfcc5feee3af5056",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "Lab52"
      ],
      "articles": [
        {
          "id": "art-623",
          "title": "DRILLAPP: new backdoor targeting Ukrainian entities with possible links to Laundry Bear",
          "link": "https://lab52.io/blog/drillapp-new-backdoor-targeting-ukrainian-entities-with-possible-links-to-laundry-bear/",
          "published": "2026-03-13",
          "sev": "high"
        }
      ],
      "first_seen": "2026-03-13"
    },
    {
      "value": "c6905bae088982a2b234451b45db742098f2e2ab4fd6ca62c8f4e801160552aa",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "Lab52"
      ],
      "articles": [
        {
          "id": "art-623",
          "title": "DRILLAPP: new backdoor targeting Ukrainian entities with possible links to Laundry Bear",
          "link": "https://lab52.io/blog/drillapp-new-backdoor-targeting-ukrainian-entities-with-possible-links-to-laundry-bear/",
          "published": "2026-03-13",
          "sev": "high"
        }
      ],
      "first_seen": "2026-03-13"
    },
    {
      "value": "ccb7d999ee4d979e175b8c87e09ccda0cbc93b6140471283e3a1f1f9da33759d",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "Lab52"
      ],
      "articles": [
        {
          "id": "art-623",
          "title": "DRILLAPP: new backdoor targeting Ukrainian entities with possible links to Laundry Bear",
          "link": "https://lab52.io/blog/drillapp-new-backdoor-targeting-ukrainian-entities-with-possible-links-to-laundry-bear/",
          "published": "2026-03-13",
          "sev": "high"
        }
      ],
      "first_seen": "2026-03-13"
    },
    {
      "value": "e20831cecd763d0dc91fb39f3bd61d17002608c5a40a6cf0bd16111f4e50d341",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "Lab52"
      ],
      "articles": [
        {
          "id": "art-623",
          "title": "DRILLAPP: new backdoor targeting Ukrainian entities with possible links to Laundry Bear",
          "link": "https://lab52.io/blog/drillapp-new-backdoor-targeting-ukrainian-entities-with-possible-links-to-laundry-bear/",
          "published": "2026-03-13",
          "sev": "high"
        }
      ],
      "first_seen": "2026-03-13"
    },
    {
      "value": "eb9c1649e01db6a9a94d5d50373e54865d672b14ad6f221c98047c562d3cc0f3",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "Lab52"
      ],
      "articles": [
        {
          "id": "art-623",
          "title": "DRILLAPP: new backdoor targeting Ukrainian entities with possible links to Laundry Bear",
          "link": "https://lab52.io/blog/drillapp-new-backdoor-targeting-ukrainian-entities-with-possible-links-to-laundry-bear/",
          "published": "2026-03-13",
          "sev": "high"
        }
      ],
      "first_seen": "2026-03-13"
    },
    {
      "value": "ee90b01b16099e0bb23d4653607a3a559590fc8d0c43120b8456fb1860d2e630",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "Lab52"
      ],
      "articles": [
        {
          "id": "art-623",
          "title": "DRILLAPP: new backdoor targeting Ukrainian entities with possible links to Laundry Bear",
          "link": "https://lab52.io/blog/drillapp-new-backdoor-targeting-ukrainian-entities-with-possible-links-to-laundry-bear/",
          "published": "2026-03-13",
          "sev": "high"
        }
      ],
      "first_seen": "2026-03-13"
    },
    {
      "value": "fb16933b09a4fcca5beff93da05566e924017fb534a2f45caf57b57a633f43a6",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "Lab52"
      ],
      "articles": [
        {
          "id": "art-623",
          "title": "DRILLAPP: new backdoor targeting Ukrainian entities with possible links to Laundry Bear",
          "link": "https://lab52.io/blog/drillapp-new-backdoor-targeting-ukrainian-entities-with-possible-links-to-laundry-bear/",
          "published": "2026-03-13",
          "sev": "high"
        }
      ],
      "first_seen": "2026-03-13"
    },
    {
      "value": "929c6399c4fde4fe236bd6712b2c53f750d9ad3a",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "StepSecurity"
      ],
      "articles": [
        {
          "id": "art-627",
          "title": "kubernetes-el Compromised: How a Pwn Request Exploited a Popular Emacs Package",
          "link": "https://www.stepsecurity.io/blog/kubernetes-el-compromised-how-a-pwn-request-exploited-a-popular-emacs-package",
          "published": "2026-03-11",
          "sev": "high"
        }
      ],
      "first_seen": "2026-03-11"
    },
    {
      "value": "99B454262DC26B081600E844371982A49D334E5E",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "ESET WeLiveSecurity"
      ],
      "articles": [
        {
          "id": "art-629",
          "title": "Sednit reloaded: Back in the trenches",
          "link": "https://www.welivesecurity.com/en/eset-research/sednit-reloaded-back-trenches/",
          "published": "2026-03-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-03-10"
    },
    {
      "value": "D0DB619A7A160949528D46D20FC0151BF9775C32",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "ESET WeLiveSecurity"
      ],
      "articles": [
        {
          "id": "art-629",
          "title": "Sednit reloaded: Back in the trenches",
          "link": "https://www.welivesecurity.com/en/eset-research/sednit-reloaded-back-trenches/",
          "published": "2026-03-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-03-10"
    },
    {
      "value": "CVE-2021-22054",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-630",
          "title": "CISA KEV: CVE-2021-22054 \u2014 Omnissa Workspace ONE Server-Side Request Forgery",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-03-09",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-03-09"
    },
    {
      "value": "CVE-2025-26399",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-631",
          "title": "CISA KEV: CVE-2025-26399 \u2014 SolarWinds Web Help Desk Deserialization of Untrusted Data Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-03-09",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-03-09"
    },
    {
      "value": "CVE-2025-40536",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-631",
          "title": "CISA KEV: CVE-2025-26399 \u2014 SolarWinds Web Help Desk Deserialization of Untrusted Data Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-03-09",
          "sev": "crit"
        },
        {
          "id": "art-685",
          "title": "CISA KEV: CVE-2025-40536 \u2014 SolarWinds Web Help Desk Security Control Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-02-12",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-03-09"
    },
    {
      "value": "CVE-2025-40551",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-631",
          "title": "CISA KEV: CVE-2025-26399 \u2014 SolarWinds Web Help Desk Deserialization of Untrusted Data Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-03-09",
          "sev": "crit"
        },
        {
          "id": "art-713",
          "title": "CISA KEV: CVE-2025-40551 \u2014 SolarWinds Web Help Desk Deserialization of Untrusted Data Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-02-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-03-09"
    },
    {
      "value": "CVE-2026-1603",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-632",
          "title": "CISA KEV: CVE-2026-1603 \u2014 Ivanti Endpoint Manager (EPM) Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-03-09",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-03-09"
    },
    {
      "value": "auth.qgtxtebl.workers.dev",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-631",
          "title": "CISA KEV: CVE-2025-26399 \u2014 SolarWinds Web Help Desk Deserialization of Untrusted Data Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-03-09",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-03-09"
    },
    {
      "value": "files.catbox.moe",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-631",
          "title": "CISA KEV: CVE-2025-26399 \u2014 SolarWinds Web Help Desk Deserialization of Untrusted Data Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-03-09",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-03-09"
    },
    {
      "value": "v2-api.mooo.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-631",
          "title": "CISA KEV: CVE-2025-26399 \u2014 SolarWinds Web Help Desk Deserialization of Untrusted Data Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-03-09",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-03-09"
    },
    {
      "value": "vdfccjpnedujhrzscjtq.supabase.co",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-631",
          "title": "CISA KEV: CVE-2025-26399 \u2014 SolarWinds Web Help Desk Deserialization of Untrusted Data Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-03-09",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-03-09"
    },
    {
      "value": "34b2a6c334813adb2cc70f5bd666c4afbdc4a6d8a58cc1c7a902b13bbd2381f4",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-631",
          "title": "CISA KEV: CVE-2025-26399 \u2014 SolarWinds Web Help Desk Deserialization of Untrusted Data Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-03-09",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-03-09"
    },
    {
      "value": "46831be6e577e3120084ee992168cca5af2047d4a08e3fd67ecd90396393b751",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-631",
          "title": "CISA KEV: CVE-2025-26399 \u2014 SolarWinds Web Help Desk Deserialization of Untrusted Data Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-03-09",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-03-09"
    },
    {
      "value": "897eae49e6c32de3f4bfa229ad4f2d6e56bcf7a39c6c962d02e5c85cd538a189",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-631",
          "title": "CISA KEV: CVE-2025-26399 \u2014 SolarWinds Web Help Desk Deserialization of Untrusted Data Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-03-09",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-03-09"
    },
    {
      "value": "bbd6e120bf55309141f75c85cc94455b1337a1a4333f6868b245b2edfa97ef44",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-631",
          "title": "CISA KEV: CVE-2025-26399 \u2014 SolarWinds Web Help Desk Deserialization of Untrusted Data Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-03-09",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-03-09"
    },
    {
      "value": "CVE-2017-7921",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-635",
          "title": "CISA KEV: CVE-2017-7921 \u2014 Hikvision Multiple Products Improper Authentication Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-03-05",
          "sev": "crit"
        },
        {
          "id": "art-908",
          "title": "CISA KEV: CVE-2020-25078 \u2014 D-Link DCS-2530L and DCS-2670L Devices Unspecified Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-08-05",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-03-05"
    },
    {
      "value": "CVE-2021-22681",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-636",
          "title": "CISA KEV: CVE-2021-22681 \u2014 Rockwell Multiple Products Insufficient Protected Credentials Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-03-05",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-03-05"
    },
    {
      "value": "CVE-2021-30952",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-638",
          "title": "CISA KEV: CVE-2021-30952 \u2014 Apple Multiple Products Integer Overflow or Wraparound Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-03-05",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-03-05"
    },
    {
      "value": "CVE-2023-41974",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-639",
          "title": "CISA KEV: CVE-2023-41974 \u2014 Apple iOS and iPadOS Use-After-Free Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-03-05",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-03-05"
    },
    {
      "value": "CVE-2023-43000",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-637",
          "title": "CISA KEV: CVE-2023-43000 \u2014 Apple Multiple products Use-After-Free Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-03-05",
          "sev": "crit"
        },
        {
          "id": "art-639",
          "title": "CISA KEV: CVE-2023-41974 \u2014 Apple iOS and iPadOS Use-After-Free Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-03-05",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-03-05"
    },
    {
      "value": "CVE-2024-23222",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-639",
          "title": "CISA KEV: CVE-2023-41974 \u2014 Apple iOS and iPadOS Use-After-Free Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-03-05",
          "sev": "crit"
        },
        {
          "id": "art-1441",
          "title": "CISA KEV: CVE-2024-23222 \u2014 Apple Multiple Products WebKit Type Confusion Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-01-23",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-03-05"
    },
    {
      "value": "CVE-2026-21385",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-643",
          "title": "CISA KEV: CVE-2026-21385 \u2014 Qualcomm Multiple Chipsets Memory Corruption Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-03-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-03-03"
    },
    {
      "value": "CVE-2026-22719",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-642",
          "title": "CISA KEV: CVE-2026-22719 \u2014 Broadcom VMware Aria Operations Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-03-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-03-03"
    },
    {
      "value": "decoorat.net",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "Lab52"
      ],
      "articles": [
        {
          "id": "art-648",
          "title": "PlugX Meeting Invitation via MSBuild and GDATA",
          "link": "https://lab52.io/blog/plugx-meeting-invitation-via-msbuild-and-gdata/",
          "published": "2026-02-26",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-02-26"
    },
    {
      "value": "decoraat.net",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "Lab52"
      ],
      "articles": [
        {
          "id": "art-648",
          "title": "PlugX Meeting Invitation via MSBuild and GDATA",
          "link": "https://lab52.io/blog/plugx-meeting-invitation-via-msbuild-and-gdata/",
          "published": "2026-02-26",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-02-26"
    },
    {
      "value": "gesecole.net",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "Lab52"
      ],
      "articles": [
        {
          "id": "art-648",
          "title": "PlugX Meeting Invitation via MSBuild and GDATA",
          "link": "https://lab52.io/blog/plugx-meeting-invitation-via-msbuild-and-gdata/",
          "published": "2026-02-26",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-02-26"
    },
    {
      "value": "onedow.gesecole.net",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "Lab52"
      ],
      "articles": [
        {
          "id": "art-648",
          "title": "PlugX Meeting Invitation via MSBuild and GDATA",
          "link": "https://lab52.io/blog/plugx-meeting-invitation-via-msbuild-and-gdata/",
          "published": "2026-02-26",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-02-26"
    },
    {
      "value": "onedown.gesecole.net",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "Lab52"
      ],
      "articles": [
        {
          "id": "art-648",
          "title": "PlugX Meeting Invitation via MSBuild and GDATA",
          "link": "https://lab52.io/blog/plugx-meeting-invitation-via-msbuild-and-gdata/",
          "published": "2026-02-26",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-02-26"
    },
    {
      "value": "381247c1d4c68a406237d7d3aa030930",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "Lab52"
      ],
      "articles": [
        {
          "id": "art-648",
          "title": "PlugX Meeting Invitation via MSBuild and GDATA",
          "link": "https://lab52.io/blog/plugx-meeting-invitation-via-msbuild-and-gdata/",
          "published": "2026-02-26",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-02-26"
    },
    {
      "value": "769687f93869a70511aac1ef7c752455",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "Lab52"
      ],
      "articles": [
        {
          "id": "art-648",
          "title": "PlugX Meeting Invitation via MSBuild and GDATA",
          "link": "https://lab52.io/blog/plugx-meeting-invitation-via-msbuild-and-gdata/",
          "published": "2026-02-26",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-02-26"
    },
    {
      "value": "7a75e713db41c28378e823322fdea0fd",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "Lab52"
      ],
      "articles": [
        {
          "id": "art-648",
          "title": "PlugX Meeting Invitation via MSBuild and GDATA",
          "link": "https://lab52.io/blog/plugx-meeting-invitation-via-msbuild-and-gdata/",
          "published": "2026-02-26",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-02-26"
    },
    {
      "value": "9f331a11a054f33664fe86543fc34cf0",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "Lab52"
      ],
      "articles": [
        {
          "id": "art-648",
          "title": "PlugX Meeting Invitation via MSBuild and GDATA",
          "link": "https://lab52.io/blog/plugx-meeting-invitation-via-msbuild-and-gdata/",
          "published": "2026-02-26",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-02-26"
    },
    {
      "value": "e7cb954f4bbdbadbd2c0206577621683",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "Lab52"
      ],
      "articles": [
        {
          "id": "art-648",
          "title": "PlugX Meeting Invitation via MSBuild and GDATA",
          "link": "https://lab52.io/blog/plugx-meeting-invitation-via-msbuild-and-gdata/",
          "published": "2026-02-26",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-02-26"
    },
    {
      "value": "1151100a0aa1ed88f7897709444fd3b3b1044c10",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "Lab52"
      ],
      "articles": [
        {
          "id": "art-648",
          "title": "PlugX Meeting Invitation via MSBuild and GDATA",
          "link": "https://lab52.io/blog/plugx-meeting-invitation-via-msbuild-and-gdata/",
          "published": "2026-02-26",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-02-26"
    },
    {
      "value": "2336c9a20ecd53ec1be468282bae94c8160eb93a",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "Lab52"
      ],
      "articles": [
        {
          "id": "art-648",
          "title": "PlugX Meeting Invitation via MSBuild and GDATA",
          "link": "https://lab52.io/blog/plugx-meeting-invitation-via-msbuild-and-gdata/",
          "published": "2026-02-26",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-02-26"
    },
    {
      "value": "ad833604d230b241e180950980ea462b3812f82a",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "Lab52"
      ],
      "articles": [
        {
          "id": "art-648",
          "title": "PlugX Meeting Invitation via MSBuild and GDATA",
          "link": "https://lab52.io/blog/plugx-meeting-invitation-via-msbuild-and-gdata/",
          "published": "2026-02-26",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-02-26"
    },
    {
      "value": "d1a86ed06b18efef5ce724d2129cf1583b779b44",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "Lab52"
      ],
      "articles": [
        {
          "id": "art-648",
          "title": "PlugX Meeting Invitation via MSBuild and GDATA",
          "link": "https://lab52.io/blog/plugx-meeting-invitation-via-msbuild-and-gdata/",
          "published": "2026-02-26",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-02-26"
    },
    {
      "value": "f06da8e29c3f0fafabfc3a524ae8b21730b57ed3",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "Lab52"
      ],
      "articles": [
        {
          "id": "art-648",
          "title": "PlugX Meeting Invitation via MSBuild and GDATA",
          "link": "https://lab52.io/blog/plugx-meeting-invitation-via-msbuild-and-gdata/",
          "published": "2026-02-26",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-02-26"
    },
    {
      "value": "29cd44aa2a51a200d82cca578d97dc13241bc906ea6a33b132c6ca567dc8f3ad",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "Lab52"
      ],
      "articles": [
        {
          "id": "art-648",
          "title": "PlugX Meeting Invitation via MSBuild and GDATA",
          "link": "https://lab52.io/blog/plugx-meeting-invitation-via-msbuild-and-gdata/",
          "published": "2026-02-26",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-02-26"
    },
    {
      "value": "46314092c8d00ab93cbbdc824b9fc39dec9303169163b9625bae3b1717d70ebc",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "Lab52"
      ],
      "articles": [
        {
          "id": "art-648",
          "title": "PlugX Meeting Invitation via MSBuild and GDATA",
          "link": "https://lab52.io/blog/plugx-meeting-invitation-via-msbuild-and-gdata/",
          "published": "2026-02-26",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-02-26"
    },
    {
      "value": "5f9af68db10b029453264cfc9b8eee4265549a2855bb79668ccfc571fb11f5fc",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "Lab52"
      ],
      "articles": [
        {
          "id": "art-648",
          "title": "PlugX Meeting Invitation via MSBuild and GDATA",
          "link": "https://lab52.io/blog/plugx-meeting-invitation-via-msbuild-and-gdata/",
          "published": "2026-02-26",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-02-26"
    },
    {
      "value": "6df8649bf4e233ee86a896ee8e5a3b3179c168ef927ac9283b945186f8629ee7",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "Lab52"
      ],
      "articles": [
        {
          "id": "art-648",
          "title": "PlugX Meeting Invitation via MSBuild and GDATA",
          "link": "https://lab52.io/blog/plugx-meeting-invitation-via-msbuild-and-gdata/",
          "published": "2026-02-26",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-02-26"
    },
    {
      "value": "8421e7995778faf1f2a902fb2c51d85ae39481f443b7b3186068d5c33c472d99",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "Lab52"
      ],
      "articles": [
        {
          "id": "art-648",
          "title": "PlugX Meeting Invitation via MSBuild and GDATA",
          "link": "https://lab52.io/blog/plugx-meeting-invitation-via-msbuild-and-gdata/",
          "published": "2026-02-26",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-02-26"
    },
    {
      "value": "d293ded5a63679b81556d2c622c78be6253f500b6751d4eeb271e6500a23b21e",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "Lab52"
      ],
      "articles": [
        {
          "id": "art-648",
          "title": "PlugX Meeting Invitation via MSBuild and GDATA",
          "link": "https://lab52.io/blog/plugx-meeting-invitation-via-msbuild-and-gdata/",
          "published": "2026-02-26",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-02-26"
    },
    {
      "value": "de8ddc2451fb1305d76ab20661725d11c77625aeeaa1447faf3fbf56706c87f1",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "Lab52"
      ],
      "articles": [
        {
          "id": "art-648",
          "title": "PlugX Meeting Invitation via MSBuild and GDATA",
          "link": "https://lab52.io/blog/plugx-meeting-invitation-via-msbuild-and-gdata/",
          "published": "2026-02-26",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-02-26"
    },
    {
      "value": "e7ed0cd4115f3ff35c38d36cc50c6a13eba2d845554439a36108789cd1e05b17",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "Lab52"
      ],
      "articles": [
        {
          "id": "art-648",
          "title": "PlugX Meeting Invitation via MSBuild and GDATA",
          "link": "https://lab52.io/blog/plugx-meeting-invitation-via-msbuild-and-gdata/",
          "published": "2026-02-26",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-02-26"
    },
    {
      "value": "CVE-2022-20775",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-649",
          "title": "CISA KEV: CVE-2022-20775 \u2014 Cisco SD-WAN Path Traversal Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-02-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-02-25"
    },
    {
      "value": "CVE-2026-25108",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-653",
          "title": "CISA KEV: CVE-2026-25108 \u2014 Soliton Systems K.K FileZen OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-02-24",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-02-24"
    },
    {
      "value": "CVE-2025-68461",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-658",
          "title": "CISA KEV: CVE-2025-68461 \u2014 RoundCube Webmail Cross-site Scripting Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-02-20",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-02-20"
    },
    {
      "value": "attacker.oastify.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-661",
          "title": "How \u201cClinejection\u201d Turned an AI Bot into a Supply Chain Attack",
          "link": "https://snyk.io/blog/cline-supply-chain-attack-prompt-injection-github-actions/",
          "published": "2026-02-19",
          "sev": "high"
        }
      ],
      "first_seen": "2026-02-19"
    },
    {
      "value": "CVE-2021-22175",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-663",
          "title": "CISA KEV: CVE-2021-22175 \u2014 GitLab Server-Side Request Forgery (SSRF) Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-02-18",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-02-18"
    },
    {
      "value": "CVE-2026-22769",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-664",
          "title": "CISA KEV: CVE-2026-22769 \u2014 Dell RecoverPoint for Virtual Machines (RP4VMs) Use of Hard-coded Credentials Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-02-18",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-02-18"
    },
    {
      "value": "CVE-2008-0015",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-670",
          "title": "CISA KEV: CVE-2008-0015 \u2014  Microsoft Windows Video ActiveX Control Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-02-17",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-02-17"
    },
    {
      "value": "CVE-2020-7796",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-668",
          "title": "CISA KEV: CVE-2020-7796 \u2014 Synacor Zimbra Collaboration Suite (ZCS) Server-Side Request Forgery Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-02-17",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-02-17"
    },
    {
      "value": "CVE-2024-7694",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-669",
          "title": "CISA KEV: CVE-2024-7694 \u2014 TeamT5 ThreatSonar Anti-Ransomware Unrestricted Upload of File with Dangerous Type Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-02-17",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-02-17"
    },
    {
      "value": "CVE-2026-2441",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-671",
          "title": "CISA KEV: CVE-2026-2441 \u2014 Google Chromium CSS Use-After-Free Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-02-17",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-02-17"
    },
    {
      "value": "CVE-2024-3094",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "StepSecurity",
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-674",
          "title": "2024 in Review: The Evolution of CI/CD Security & What's Next",
          "link": "https://www.stepsecurity.io/blog/2024-in-review-the-evolution-of-ci-cd-security-whats-next",
          "published": "2026-02-15",
          "sev": "high"
        },
        {
          "id": "art-1392",
          "title": "The XZ backdoor CVE-2024-3094",
          "link": "https://snyk.io/blog/the-xz-backdoor-cve-2024-3094/",
          "published": "2024-03-31",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-02-15"
    },
    {
      "value": "319feb5a9cddd81955d915b5632b4a5f8f9080281fb46e2f6d69d53f693c23ae",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "StepSecurity",
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-674",
          "title": "2024 in Review: The Evolution of CI/CD Security & What's Next",
          "link": "https://www.stepsecurity.io/blog/2024-in-review-the-evolution-of-ci-cd-security-whats-next",
          "published": "2026-02-15",
          "sev": "high"
        },
        {
          "id": "art-1392",
          "title": "The XZ backdoor CVE-2024-3094",
          "link": "https://snyk.io/blog/the-xz-backdoor-cve-2024-3094/",
          "published": "2024-03-31",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-02-15"
    },
    {
      "value": "5448850cdc3a7ae41ff53b433c2adbd0ff492515012412ee63a40d2685db3049",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "StepSecurity",
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-674",
          "title": "2024 in Review: The Evolution of CI/CD Security & What's Next",
          "link": "https://www.stepsecurity.io/blog/2024-in-review-the-evolution-of-ci-cd-security-whats-next",
          "published": "2026-02-15",
          "sev": "high"
        },
        {
          "id": "art-1392",
          "title": "The XZ backdoor CVE-2024-3094",
          "link": "https://snyk.io/blog/the-xz-backdoor-cve-2024-3094/",
          "published": "2024-03-31",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-02-15"
    },
    {
      "value": "605861f833fc181c7cdcabd5577ddb8989bea332648a8f498b4eef89b8f85ad4",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "StepSecurity",
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-674",
          "title": "2024 in Review: The Evolution of CI/CD Security & What's Next",
          "link": "https://www.stepsecurity.io/blog/2024-in-review-the-evolution-of-ci-cd-security-whats-next",
          "published": "2026-02-15",
          "sev": "high"
        },
        {
          "id": "art-1392",
          "title": "The XZ backdoor CVE-2024-3094",
          "link": "https://snyk.io/blog/the-xz-backdoor-cve-2024-3094/",
          "published": "2024-03-31",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-02-15"
    },
    {
      "value": "8fa641c454c3e0f76de73b7cc3446096b9c8b9d33d406d38b8ac76090b0344fd",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "StepSecurity",
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-674",
          "title": "2024 in Review: The Evolution of CI/CD Security & What's Next",
          "link": "https://www.stepsecurity.io/blog/2024-in-review-the-evolution-of-ci-cd-security-whats-next",
          "published": "2026-02-15",
          "sev": "high"
        },
        {
          "id": "art-1392",
          "title": "The XZ backdoor CVE-2024-3094",
          "link": "https://snyk.io/blog/the-xz-backdoor-cve-2024-3094/",
          "published": "2024-03-31",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-02-15"
    },
    {
      "value": "b418bfd34aa246b2e7b5cb5d263a640e5d080810f767370c4d2c24662a274963",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "StepSecurity",
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-674",
          "title": "2024 in Review: The Evolution of CI/CD Security & What's Next",
          "link": "https://www.stepsecurity.io/blog/2024-in-review-the-evolution-of-ci-cd-security-whats-next",
          "published": "2026-02-15",
          "sev": "high"
        },
        {
          "id": "art-1392",
          "title": "The XZ backdoor CVE-2024-3094",
          "link": "https://snyk.io/blog/the-xz-backdoor-cve-2024-3094/",
          "published": "2024-03-31",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-02-15"
    },
    {
      "value": "cbeef92e67bf41ca9c015557d81f39adaba67ca9fb3574139754999030b83537",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "StepSecurity",
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-674",
          "title": "2024 in Review: The Evolution of CI/CD Security & What's Next",
          "link": "https://www.stepsecurity.io/blog/2024-in-review-the-evolution-of-ci-cd-security-whats-next",
          "published": "2026-02-15",
          "sev": "high"
        },
        {
          "id": "art-1392",
          "title": "The XZ backdoor CVE-2024-3094",
          "link": "https://snyk.io/blog/the-xz-backdoor-cve-2024-3094/",
          "published": "2024-03-31",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-02-15"
    },
    {
      "value": "CVE-2026-1731",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-677",
          "title": "CISA KEV: CVE-2026-1731 \u2014 BeyondTrust Remote Support (RS) and Privileged Remote Access (PRA) OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-02-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-02-13"
    },
    {
      "value": "CVE-2024-43468",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-683",
          "title": "CISA KEV: CVE-2024-43468 \u2014 Microsoft Configuration Manager SQL Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-02-12",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-02-12"
    },
    {
      "value": "CVE-2025-15556",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-684",
          "title": "CISA KEV: CVE-2025-15556 \u2014 Notepad++ Download of Code Without Integrity Check Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-02-12",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-02-12"
    },
    {
      "value": "CVE-2026-20700",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-682",
          "title": "CISA KEV: CVE-2026-20700 \u2014 Apple Multiple Buffer Overflow Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-02-12",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-02-12"
    },
    {
      "value": "CVE-2026-21510",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-700",
          "title": "CISA KEV: CVE-2026-21510 \u2014 Microsoft Windows Shell Protection Mechanism Failure Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-02-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-02-10"
    },
    {
      "value": "CVE-2026-21513",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-698",
          "title": "CISA KEV: CVE-2026-21513 \u2014 Microsoft MSHTML Framework Protection Mechanism Failure Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-02-10",
          "sev": "crit"
        },
        {
          "id": "art-700",
          "title": "CISA KEV: CVE-2026-21510 \u2014 Microsoft Windows Shell Protection Mechanism Failure Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-02-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-02-10"
    },
    {
      "value": "CVE-2026-21514",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-703",
          "title": "CISA KEV: CVE-2026-21514 \u2014 Microsoft Office Word Reliance on Untrusted Inputs in a Security Decision Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-02-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-02-10"
    },
    {
      "value": "CVE-2026-21519",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-702",
          "title": "CISA KEV: CVE-2026-21519 \u2014 Microsoft Windows Type Confusion Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-02-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-02-10"
    },
    {
      "value": "CVE-2026-21525",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-699",
          "title": "CISA KEV: CVE-2026-21525 \u2014 Microsoft Windows NULL Pointer Dereference Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-02-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-02-10"
    },
    {
      "value": "CVE-2026-21533",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-701",
          "title": "CISA KEV: CVE-2026-21533 \u2014 Microsoft Windows Improper Privilege Management Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-02-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-02-10"
    },
    {
      "value": "github.com/aztr0nutz/NET_NINJA.v1.2",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-697",
          "title": "How a Malicious Google Skill on ClawHub Tricks Users Into Installing Malware",
          "link": "https://snyk.io/blog/clawhub-malicious-google-skill-openclaw-malware/",
          "published": "2026-02-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-02-10"
    },
    {
      "value": "github.com/denboss99/openclaw-core",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-697",
          "title": "How a Malicious Google Skill on ClawHub Tricks Users Into Installing Malware",
          "link": "https://snyk.io/blog/clawhub-malicious-google-skill-openclaw-malware/",
          "published": "2026-02-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-02-10"
    },
    {
      "value": "rentry.co/openclaw-core",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-697",
          "title": "How a Malicious Google Skill on ClawHub Tricks Users Into Installing Malware",
          "link": "https://snyk.io/blog/clawhub-malicious-google-skill-openclaw-malware/",
          "published": "2026-02-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-02-10"
    },
    {
      "value": "setup-service.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-697",
          "title": "How a Malicious Google Skill on ClawHub Tricks Users Into Installing Malware",
          "link": "https://snyk.io/blog/clawhub-malicious-google-skill-openclaw-malware/",
          "published": "2026-02-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-02-10"
    },
    {
      "value": "CVE-2025-11953",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-706",
          "title": "CISA KEV: CVE-2025-11953 \u2014 React Native Community CLI OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-02-05",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-02-05"
    },
    {
      "value": "CVE-2026-24423",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-707",
          "title": "CISA KEV: CVE-2026-24423 \u2014 SmarterTools SmarterMail Missing Authentication for Critical Function Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-02-05",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-02-05"
    },
    {
      "value": "CVE-2019-19006",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-712",
          "title": "CISA KEV: CVE-2019-19006 \u2014  Sangoma FreePBX Improper Authentication Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-02-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-02-03"
    },
    {
      "value": "CVE-2021-39935",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-710",
          "title": "CISA KEV: CVE-2021-39935 \u2014 GitLab Community and Enterprise Editions Server-Side Request Forgery (SSRF) Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-02-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-02-03"
    },
    {
      "value": "CVE-2025-64328",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-711",
          "title": "CISA KEV: CVE-2025-64328 \u2014 Sangoma FreePBX OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-02-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-02-03"
    },
    {
      "value": "progamevl.ru",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "ESET WeLiveSecurity"
      ],
      "articles": [
        {
          "id": "art-717",
          "title": "DynoWiper update: Technical analysis and attribution",
          "link": "https://www.welivesecurity.com/en/eset-research/dynowiper-update-technical-analysis-attribution/",
          "published": "2026-01-30",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-01-30"
    },
    {
      "value": "31.172.71.5",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "ESET WeLiveSecurity"
      ],
      "articles": [
        {
          "id": "art-717",
          "title": "DynoWiper update: Technical analysis and attribution",
          "link": "https://www.welivesecurity.com/en/eset-research/dynowiper-update-technical-analysis-attribution/",
          "published": "2026-01-30",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-01-30"
    },
    {
      "value": "CVE-2026-1281",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-718",
          "title": "CISA KEV: CVE-2026-1281 \u2014 Ivanti Endpoint Manager Mobile (EPMM) Code Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-01-29",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-01-29"
    },
    {
      "value": "CVE-2026-24858",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-722",
          "title": "CISA KEV: CVE-2026-24858 \u2014 Fortinet Multiple Products Authentication Bypass Using an Alternate Path or Channel Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-01-27",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-01-27"
    },
    {
      "value": "CVE-2018-14634",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-723",
          "title": "CISA KEV: CVE-2018-14634 \u2014 Linux Kernel Integer Overflow Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-01-26",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-01-26"
    },
    {
      "value": "CVE-2025-52691",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-724",
          "title": "CISA KEV: CVE-2025-52691 \u2014 SmarterTools SmarterMail Unrestricted Upload of File with Dangerous Type Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-01-26",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-01-26"
    },
    {
      "value": "CVE-2026-21509",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-727",
          "title": "CISA KEV: CVE-2026-21509 \u2014 Microsoft Office Security Feature Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-01-26",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-01-26"
    },
    {
      "value": "CVE-2026-23760",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-725",
          "title": "CISA KEV: CVE-2026-23760 \u2014 SmarterTools SmarterMail Authentication Bypass Using an Alternate Path or Channel Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-01-26",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-01-26"
    },
    {
      "value": "CVE-2026-24061",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-726",
          "title": "CISA KEV: CVE-2026-24061 \u2014 GNU InetUtils Argument Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-01-26",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-01-26"
    },
    {
      "value": "CVE-2024-37079",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-730",
          "title": "CISA KEV: CVE-2024-37079 \u2014 Broadcom VMware vCenter Server Out-of-bounds Write Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-01-23",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-01-23"
    },
    {
      "value": "4ec3c90846af6b79ee1a5188eefa3fd21f6d4cf6",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "ESET WeLiveSecurity"
      ],
      "articles": [
        {
          "id": "art-728",
          "title": "ESET Research: Sandworm behind cyberattack on Poland\u2019s power grid in late 2025",
          "link": "https://www.welivesecurity.com/en/eset-research/eset-research-sandworm-cyberattack-poland-power-grid-late-2025/",
          "published": "2026-01-23",
          "sev": "high"
        }
      ],
      "first_seen": "2026-01-23"
    },
    {
      "value": "CVE-2025-31125",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-734",
          "title": "CISA KEV: CVE-2025-31125 \u2014 Vite Vitejs Improper Access Control Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-01-22",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-01-22"
    },
    {
      "value": "CVE-2025-34026",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-733",
          "title": "CISA KEV: CVE-2025-34026 \u2014 Versa Concerto Improper Authentication Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-01-22",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-01-22"
    },
    {
      "value": "CVE-2025-54313",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV",
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-735",
          "title": "CISA KEV: CVE-2025-54313 \u2014 Prettier eslint-config-prettier Embedded Malicious Code Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-01-22",
          "sev": "crit"
        },
        {
          "id": "art-917",
          "title": "Maintainers of ESLint Prettier Plugin Attacked via npm Supply Chain Malware",
          "link": "https://snyk.io/blog/maintainers-of-eslint-prettier-plugin-attacked-via-npm-supply-chain-malware/",
          "published": "2025-07-22",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-01-22"
    },
    {
      "value": "CVE-2025-68645",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-732",
          "title": "CISA KEV: CVE-2025-68645 \u2014 Synacor Zimbra Collaboration Suite (ZCS) PHP Remote File Inclusion Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-01-22",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-01-22"
    },
    {
      "value": "CVE-2026-20045",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-736",
          "title": "CISA KEV: CVE-2026-20045 \u2014 Cisco Unified Communications Products Code Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-01-21",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-01-21"
    },
    {
      "value": "CVE-2026-20805",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-743",
          "title": "CISA KEV: CVE-2026-20805 \u2014 Microsoft Windows Information Disclosure Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-01-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-01-13"
    },
    {
      "value": "CVE-2025-8110",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-744",
          "title": "CISA KEV: CVE-2025-8110 \u2014 Gogs Path Traversal Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-01-12",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-01-12"
    },
    {
      "value": "CVE-2009-0556",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-748",
          "title": "CISA KEV: CVE-2009-0556 \u2014 Microsoft Office PowerPoint Code Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-01-07",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-01-07"
    },
    {
      "value": "CVE-2025-37164",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-749",
          "title": "CISA KEV: CVE-2025-37164 \u2014 Hewlett Packard Enterprise (HPE) OneView Code Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2026-01-07",
          "sev": "crit"
        }
      ],
      "first_seen": "2026-01-07"
    },
    {
      "value": "CVE-2025-14847",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-752",
          "title": "CISA KEV: CVE-2025-14847 \u2014 MongoDB and MongoDB Server Improper Handling of Length Parameter Inconsistency Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-12-29",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-12-29"
    },
    {
      "value": "CVE-2023-52163",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-755",
          "title": "CISA KEV: CVE-2023-52163 \u2014 Digiever DS-2105 Pro Missing Authorization Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-12-22",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-12-22"
    },
    {
      "value": "CVE-2025-50165",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "ESET WeLiveSecurity"
      ],
      "articles": [
        {
          "id": "art-754",
          "title": "Revisiting CVE-2025-50165: A critical flaw in Windows Imaging Component",
          "link": "https://www.welivesecurity.com/en/eset-research/revisiting-cve-2025-50165-critical-flaw-windows-imaging-component/",
          "published": "2025-12-22",
          "sev": "high"
        }
      ],
      "first_seen": "2025-12-22"
    },
    {
      "value": "CVE-2025-14733",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-757",
          "title": "CISA KEV: CVE-2025-14733 \u2014 WatchGuard Firebox Out of Bounds Write Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-12-19",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-12-19"
    },
    {
      "value": "CVE-2025-20393",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-761",
          "title": "CISA KEV: CVE-2025-20393 \u2014 Cisco Multiple Products Improper Input Validation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-12-17",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-12-17"
    },
    {
      "value": "CVE-2025-40602",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-760",
          "title": "CISA KEV: CVE-2025-40602 \u2014 SonicWall SMA1000 Missing Authorization Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-12-17",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-12-17"
    },
    {
      "value": "CVE-2025-59374",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-759",
          "title": "CISA KEV: CVE-2025-59374 \u2014 ASUS Live Update Embedded Malicious Code Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-12-17",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-12-17"
    },
    {
      "value": "CVE-2025-59718",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-764",
          "title": "CISA KEV: CVE-2025-59718 \u2014 Fortinet Multiple Products Improper Verification of Cryptographic Signature Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-12-16",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-12-16"
    },
    {
      "value": "CVE-2025-59719",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-764",
          "title": "CISA KEV: CVE-2025-59718 \u2014 Fortinet Multiple Products Improper Verification of Cryptographic Signature Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-12-16",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-12-16"
    },
    {
      "value": "CVE-2025-14611",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-765",
          "title": "CISA KEV: CVE-2025-14611 \u2014 Gladinet CentreStack and Triofox Hard Coded Cryptographic Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-12-15",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-12-15"
    },
    {
      "value": "CVE-2025-43529",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-766",
          "title": "CISA KEV: CVE-2025-43529 \u2014 Apple Multiple Products Use-After-Free WebKit Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-12-15",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-12-15"
    },
    {
      "value": "CVE-2018-4063",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-768",
          "title": "CISA KEV: CVE-2018-4063 \u2014 Sierra Wireless AirLink ALEOS Unrestricted Upload of File with Dangerous Type Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-12-12",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-12-12"
    },
    {
      "value": "CVE-2025-14174",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-769",
          "title": "CISA KEV: CVE-2025-14174 \u2014 Google Chromium Out of Bounds Memory Access Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-12-12",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-12-12"
    },
    {
      "value": "CVE-2025-58360",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-772",
          "title": "CISA KEV: CVE-2025-58360 \u2014 OSGeo GeoServer Improper Restriction of XML External Entity Reference Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-12-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-12-11"
    },
    {
      "value": "CVE-2025-6218",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-776",
          "title": "CISA KEV: CVE-2025-6218 \u2014 RARLAB WinRAR Path Traversal Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-12-09",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-12-09"
    },
    {
      "value": "CVE-2025-62221",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-777",
          "title": "CISA KEV: CVE-2025-62221 \u2014 Microsoft Windows Use After Free Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-12-09",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-12-09"
    },
    {
      "value": "CVE-2025-66644",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-779",
          "title": "CISA KEV: CVE-2025-66644 \u2014 Array Networks ArrayOS AG OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-12-08",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-12-08"
    },
    {
      "value": "CVE-2021-26828",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-785",
          "title": "CISA KEV: CVE-2021-26828 \u2014 OpenPLC ScadaBR Unrestricted Upload of File with Dangerous Type Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-12-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-12-03"
    },
    {
      "value": "CVE-2025-66478",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-782",
          "title": "Security Advisory: Critical RCE Vulnerabilities in React Server Components (CVE-2025-55182)",
          "link": "https://snyk.io/blog/security-advisory-critical-rce-vulnerabilities-react-server-components/",
          "published": "2025-12-03",
          "sev": "high"
        }
      ],
      "first_seen": "2025-12-03"
    },
    {
      "value": "anywherehost.site",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-782",
          "title": "Security Advisory: Critical RCE Vulnerabilities in React Server Components (CVE-2025-55182)",
          "link": "https://snyk.io/blog/security-advisory-critical-rce-vulnerabilities-react-server-components/",
          "published": "2025-12-03",
          "sev": "high"
        }
      ],
      "first_seen": "2025-12-03"
    },
    {
      "value": "donaldjtrmp.anondns.net",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-782",
          "title": "Security Advisory: Critical RCE Vulnerabilities in React Server Components (CVE-2025-55182)",
          "link": "https://snyk.io/blog/security-advisory-critical-rce-vulnerabilities-react-server-components/",
          "published": "2025-12-03",
          "sev": "high"
        }
      ],
      "first_seen": "2025-12-03"
    },
    {
      "value": "ghostbin.axel.org",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-782",
          "title": "Security Advisory: Critical RCE Vulnerabilities in React Server Components (CVE-2025-55182)",
          "link": "https://snyk.io/blog/security-advisory-critical-rce-vulnerabilities-react-server-components/",
          "published": "2025-12-03",
          "sev": "high"
        }
      ],
      "first_seen": "2025-12-03"
    },
    {
      "value": "help.093214.xyz",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-782",
          "title": "Security Advisory: Critical RCE Vulnerabilities in React Server Components (CVE-2025-55182)",
          "link": "https://snyk.io/blog/security-advisory-critical-rce-vulnerabilities-react-server-components/",
          "published": "2025-12-03",
          "sev": "high"
        }
      ],
      "first_seen": "2025-12-03"
    },
    {
      "value": "keep.camdvr.org",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-782",
          "title": "Security Advisory: Critical RCE Vulnerabilities in React Server Components (CVE-2025-55182)",
          "link": "https://snyk.io/blog/security-advisory-critical-rce-vulnerabilities-react-server-components/",
          "published": "2025-12-03",
          "sev": "high"
        }
      ],
      "first_seen": "2025-12-03"
    },
    {
      "value": "krebsec.anondns.net",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-782",
          "title": "Security Advisory: Critical RCE Vulnerabilities in React Server Components (CVE-2025-55182)",
          "link": "https://snyk.io/blog/security-advisory-critical-rce-vulnerabilities-react-server-components/",
          "published": "2025-12-03",
          "sev": "high"
        }
      ],
      "first_seen": "2025-12-03"
    },
    {
      "value": "labubu.anondns.net",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-782",
          "title": "Security Advisory: Critical RCE Vulnerabilities in React Server Components (CVE-2025-55182)",
          "link": "https://snyk.io/blog/security-advisory-critical-rce-vulnerabilities-react-server-components/",
          "published": "2025-12-03",
          "sev": "high"
        }
      ],
      "first_seen": "2025-12-03"
    },
    {
      "value": "overcome-pmc-conferencing-books.trycloudflare.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-782",
          "title": "Security Advisory: Critical RCE Vulnerabilities in React Server Components (CVE-2025-55182)",
          "link": "https://snyk.io/blog/security-advisory-critical-rce-vulnerabilities-react-server-components/",
          "published": "2025-12-03",
          "sev": "high"
        }
      ],
      "first_seen": "2025-12-03"
    },
    {
      "value": "reactcdn.windowserrorapis.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-782",
          "title": "Security Advisory: Critical RCE Vulnerabilities in React Server Components (CVE-2025-55182)",
          "link": "https://snyk.io/blog/security-advisory-critical-rce-vulnerabilities-react-server-components/",
          "published": "2025-12-03",
          "sev": "high"
        }
      ],
      "first_seen": "2025-12-03"
    },
    {
      "value": "res.qiqigece.top",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-782",
          "title": "Security Advisory: Critical RCE Vulnerabilities in React Server Components (CVE-2025-55182)",
          "link": "https://snyk.io/blog/security-advisory-critical-rce-vulnerabilities-react-server-components/",
          "published": "2025-12-03",
          "sev": "high"
        }
      ],
      "first_seen": "2025-12-03"
    },
    {
      "value": "superminecraft.net.br",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-782",
          "title": "Security Advisory: Critical RCE Vulnerabilities in React Server Components (CVE-2025-55182)",
          "link": "https://snyk.io/blog/security-advisory-critical-rce-vulnerabilities-react-server-components/",
          "published": "2025-12-03",
          "sev": "high"
        }
      ],
      "first_seen": "2025-12-03"
    },
    {
      "value": "vip.kof97.lol",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-782",
          "title": "Security Advisory: Critical RCE Vulnerabilities in React Server Components (CVE-2025-55182)",
          "link": "https://snyk.io/blog/security-advisory-critical-rce-vulnerabilities-react-server-components/",
          "published": "2025-12-03",
          "sev": "high"
        }
      ],
      "first_seen": "2025-12-03"
    },
    {
      "value": "vps-zap812595-1.zap-srv.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-782",
          "title": "Security Advisory: Critical RCE Vulnerabilities in React Server Components (CVE-2025-55182)",
          "link": "https://snyk.io/blog/security-advisory-critical-rce-vulnerabilities-react-server-components/",
          "published": "2025-12-03",
          "sev": "high"
        }
      ],
      "first_seen": "2025-12-03"
    },
    {
      "value": "xpertclient.net",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-782",
          "title": "Security Advisory: Critical RCE Vulnerabilities in React Server Components (CVE-2025-55182)",
          "link": "https://snyk.io/blog/security-advisory-critical-rce-vulnerabilities-react-server-components/",
          "published": "2025-12-03",
          "sev": "high"
        }
      ],
      "first_seen": "2025-12-03"
    },
    {
      "value": "115.42.60.223",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-782",
          "title": "Security Advisory: Critical RCE Vulnerabilities in React Server Components (CVE-2025-55182)",
          "link": "https://snyk.io/blog/security-advisory-critical-rce-vulnerabilities-react-server-components/",
          "published": "2025-12-03",
          "sev": "high"
        }
      ],
      "first_seen": "2025-12-03"
    },
    {
      "value": "140.99.223.178",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-782",
          "title": "Security Advisory: Critical RCE Vulnerabilities in React Server Components (CVE-2025-55182)",
          "link": "https://snyk.io/blog/security-advisory-critical-rce-vulnerabilities-react-server-components/",
          "published": "2025-12-03",
          "sev": "high"
        }
      ],
      "first_seen": "2025-12-03"
    },
    {
      "value": "146.88.129.138",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-782",
          "title": "Security Advisory: Critical RCE Vulnerabilities in React Server Components (CVE-2025-55182)",
          "link": "https://snyk.io/blog/security-advisory-critical-rce-vulnerabilities-react-server-components/",
          "published": "2025-12-03",
          "sev": "high"
        }
      ],
      "first_seen": "2025-12-03"
    },
    {
      "value": "156.234.209.103",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-782",
          "title": "Security Advisory: Critical RCE Vulnerabilities in React Server Components (CVE-2025-55182)",
          "link": "https://snyk.io/blog/security-advisory-critical-rce-vulnerabilities-react-server-components/",
          "published": "2025-12-03",
          "sev": "high"
        }
      ],
      "first_seen": "2025-12-03"
    },
    {
      "value": "162.215.170.26",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-782",
          "title": "Security Advisory: Critical RCE Vulnerabilities in React Server Components (CVE-2025-55182)",
          "link": "https://snyk.io/blog/security-advisory-critical-rce-vulnerabilities-react-server-components/",
          "published": "2025-12-03",
          "sev": "high"
        }
      ],
      "first_seen": "2025-12-03"
    },
    {
      "value": "192.238.202.17",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-782",
          "title": "Security Advisory: Critical RCE Vulnerabilities in React Server Components (CVE-2025-55182)",
          "link": "https://snyk.io/blog/security-advisory-critical-rce-vulnerabilities-react-server-components/",
          "published": "2025-12-03",
          "sev": "high"
        }
      ],
      "first_seen": "2025-12-03"
    },
    {
      "value": "193.24.123.68",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-782",
          "title": "Security Advisory: Critical RCE Vulnerabilities in React Server Components (CVE-2025-55182)",
          "link": "https://snyk.io/blog/security-advisory-critical-rce-vulnerabilities-react-server-components/",
          "published": "2025-12-03",
          "sev": "high"
        }
      ],
      "first_seen": "2025-12-03"
    },
    {
      "value": "193.34.213.150",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-782",
          "title": "Security Advisory: Critical RCE Vulnerabilities in React Server Components (CVE-2025-55182)",
          "link": "https://snyk.io/blog/security-advisory-critical-rce-vulnerabilities-react-server-components/",
          "published": "2025-12-03",
          "sev": "high"
        }
      ],
      "first_seen": "2025-12-03"
    },
    {
      "value": "194.69.203.32",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-782",
          "title": "Security Advisory: Critical RCE Vulnerabilities in React Server Components (CVE-2025-55182)",
          "link": "https://snyk.io/blog/security-advisory-critical-rce-vulnerabilities-react-server-components/",
          "published": "2025-12-03",
          "sev": "high"
        }
      ],
      "first_seen": "2025-12-03"
    },
    {
      "value": "196.251.100.191",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-782",
          "title": "Security Advisory: Critical RCE Vulnerabilities in React Server Components (CVE-2025-55182)",
          "link": "https://snyk.io/blog/security-advisory-critical-rce-vulnerabilities-react-server-components/",
          "published": "2025-12-03",
          "sev": "high"
        }
      ],
      "first_seen": "2025-12-03"
    },
    {
      "value": "216.158.232.43",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-782",
          "title": "Security Advisory: Critical RCE Vulnerabilities in React Server Components (CVE-2025-55182)",
          "link": "https://snyk.io/blog/security-advisory-critical-rce-vulnerabilities-react-server-components/",
          "published": "2025-12-03",
          "sev": "high"
        }
      ],
      "first_seen": "2025-12-03"
    },
    {
      "value": "31.56.27.76",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-782",
          "title": "Security Advisory: Critical RCE Vulnerabilities in React Server Components (CVE-2025-55182)",
          "link": "https://snyk.io/blog/security-advisory-critical-rce-vulnerabilities-react-server-components/",
          "published": "2025-12-03",
          "sev": "high"
        }
      ],
      "first_seen": "2025-12-03"
    },
    {
      "value": "31.57.46.28",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-782",
          "title": "Security Advisory: Critical RCE Vulnerabilities in React Server Components (CVE-2025-55182)",
          "link": "https://snyk.io/blog/security-advisory-critical-rce-vulnerabilities-react-server-components/",
          "published": "2025-12-03",
          "sev": "high"
        }
      ],
      "first_seen": "2025-12-03"
    },
    {
      "value": "38.162.112.141",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-782",
          "title": "Security Advisory: Critical RCE Vulnerabilities in React Server Components (CVE-2025-55182)",
          "link": "https://snyk.io/blog/security-advisory-critical-rce-vulnerabilities-react-server-components/",
          "published": "2025-12-03",
          "sev": "high"
        }
      ],
      "first_seen": "2025-12-03"
    },
    {
      "value": "45.32.158.54",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-782",
          "title": "Security Advisory: Critical RCE Vulnerabilities in React Server Components (CVE-2025-55182)",
          "link": "https://snyk.io/blog/security-advisory-critical-rce-vulnerabilities-react-server-components/",
          "published": "2025-12-03",
          "sev": "high"
        }
      ],
      "first_seen": "2025-12-03"
    },
    {
      "value": "46.36.37.85",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-782",
          "title": "Security Advisory: Critical RCE Vulnerabilities in React Server Components (CVE-2025-55182)",
          "link": "https://snyk.io/blog/security-advisory-critical-rce-vulnerabilities-react-server-components/",
          "published": "2025-12-03",
          "sev": "high"
        }
      ],
      "first_seen": "2025-12-03"
    },
    {
      "value": "47.84.57.207",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-782",
          "title": "Security Advisory: Critical RCE Vulnerabilities in React Server Components (CVE-2025-55182)",
          "link": "https://snyk.io/blog/security-advisory-critical-rce-vulnerabilities-react-server-components/",
          "published": "2025-12-03",
          "sev": "high"
        }
      ],
      "first_seen": "2025-12-03"
    },
    {
      "value": "47.84.79.46",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-782",
          "title": "Security Advisory: Critical RCE Vulnerabilities in React Server Components (CVE-2025-55182)",
          "link": "https://snyk.io/blog/security-advisory-critical-rce-vulnerabilities-react-server-components/",
          "published": "2025-12-03",
          "sev": "high"
        }
      ],
      "first_seen": "2025-12-03"
    },
    {
      "value": "72.62.67.33",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-782",
          "title": "Security Advisory: Critical RCE Vulnerabilities in React Server Components (CVE-2025-55182)",
          "link": "https://snyk.io/blog/security-advisory-critical-rce-vulnerabilities-react-server-components/",
          "published": "2025-12-03",
          "sev": "high"
        }
      ],
      "first_seen": "2025-12-03"
    },
    {
      "value": "92.246.87.48",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-782",
          "title": "Security Advisory: Critical RCE Vulnerabilities in React Server Components (CVE-2025-55182)",
          "link": "https://snyk.io/blog/security-advisory-critical-rce-vulnerabilities-react-server-components/",
          "published": "2025-12-03",
          "sev": "high"
        }
      ],
      "first_seen": "2025-12-03"
    },
    {
      "value": "95.169.180.135",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-782",
          "title": "Security Advisory: Critical RCE Vulnerabilities in React Server Components (CVE-2025-55182)",
          "link": "https://snyk.io/blog/security-advisory-critical-rce-vulnerabilities-react-server-components/",
          "published": "2025-12-03",
          "sev": "high"
        }
      ],
      "first_seen": "2025-12-03"
    },
    {
      "value": "1663d98c259001f1b03f82d0c5bee7cfd3c7623ccb83759c994f9ab845939665",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-782",
          "title": "Security Advisory: Critical RCE Vulnerabilities in React Server Components (CVE-2025-55182)",
          "link": "https://snyk.io/blog/security-advisory-critical-rce-vulnerabilities-react-server-components/",
          "published": "2025-12-03",
          "sev": "high"
        }
      ],
      "first_seen": "2025-12-03"
    },
    {
      "value": "18c68a982f91f665effe769f663c51cb0567ea2bfc7fab6a1a40d4fe50fc382b",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-782",
          "title": "Security Advisory: Critical RCE Vulnerabilities in React Server Components (CVE-2025-55182)",
          "link": "https://snyk.io/blog/security-advisory-critical-rce-vulnerabilities-react-server-components/",
          "published": "2025-12-03",
          "sev": "high"
        }
      ],
      "first_seen": "2025-12-03"
    },
    {
      "value": "1a3e7b4ee2b2858dbac2d73dd1c52b1ea1d69c6ebb24cc434d1e15e43325b74e",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-782",
          "title": "Security Advisory: Critical RCE Vulnerabilities in React Server Components (CVE-2025-55182)",
          "link": "https://snyk.io/blog/security-advisory-critical-rce-vulnerabilities-react-server-components/",
          "published": "2025-12-03",
          "sev": "high"
        }
      ],
      "first_seen": "2025-12-03"
    },
    {
      "value": "1cdd9b0434eb5b06173c7516f99a832dc4614ac10dda171c8eed3272a5e63d20",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-782",
          "title": "Security Advisory: Critical RCE Vulnerabilities in React Server Components (CVE-2025-55182)",
          "link": "https://snyk.io/blog/security-advisory-critical-rce-vulnerabilities-react-server-components/",
          "published": "2025-12-03",
          "sev": "high"
        }
      ],
      "first_seen": "2025-12-03"
    },
    {
      "value": "1e31dc074a4ea7f400cb969ea80e8855b5e7486660aab415da17591bc284ac5b",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-782",
          "title": "Security Advisory: Critical RCE Vulnerabilities in React Server Components (CVE-2025-55182)",
          "link": "https://snyk.io/blog/security-advisory-critical-rce-vulnerabilities-react-server-components/",
          "published": "2025-12-03",
          "sev": "high"
        }
      ],
      "first_seen": "2025-12-03"
    },
    {
      "value": "1f3f0695c7ec63723b2b8e9d50b1838df304821fcb22c7902db1f8248a812035",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-782",
          "title": "Security Advisory: Critical RCE Vulnerabilities in React Server Components (CVE-2025-55182)",
          "link": "https://snyk.io/blog/security-advisory-critical-rce-vulnerabilities-react-server-components/",
          "published": "2025-12-03",
          "sev": "high"
        }
      ],
      "first_seen": "2025-12-03"
    },
    {
      "value": "2b0dc27f035ba1417990a21dafb361e083e4ed94a75a1c49dc45690ecf463de4",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-782",
          "title": "Security Advisory: Critical RCE Vulnerabilities in React Server Components (CVE-2025-55182)",
          "link": "https://snyk.io/blog/security-advisory-critical-rce-vulnerabilities-react-server-components/",
          "published": "2025-12-03",
          "sev": "high"
        }
      ],
      "first_seen": "2025-12-03"
    },
    {
      "value": "2ca913556efd6c45109fd8358edb18d22a10fb6a36c1ab7b2df7594cd5b0adbc",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-782",
          "title": "Security Advisory: Critical RCE Vulnerabilities in React Server Components (CVE-2025-55182)",
          "link": "https://snyk.io/blog/security-advisory-critical-rce-vulnerabilities-react-server-components/",
          "published": "2025-12-03",
          "sev": "high"
        }
      ],
      "first_seen": "2025-12-03"
    },
    {
      "value": "33641bfbbdd5a9cd2320c61f65fe446a2226d8a48e3bd3c29e8f916f0592575f",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-782",
          "title": "Security Advisory: Critical RCE Vulnerabilities in React Server Components (CVE-2025-55182)",
          "link": "https://snyk.io/blog/security-advisory-critical-rce-vulnerabilities-react-server-components/",
          "published": "2025-12-03",
          "sev": "high"
        }
      ],
      "first_seen": "2025-12-03"
    },
    {
      "value": "4745703f395282a0687def2c7dcf82ed1683f3128bef1686bd74c966273ce1c5",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-782",
          "title": "Security Advisory: Critical RCE Vulnerabilities in React Server Components (CVE-2025-55182)",
          "link": "https://snyk.io/blog/security-advisory-critical-rce-vulnerabilities-react-server-components/",
          "published": "2025-12-03",
          "sev": "high"
        }
      ],
      "first_seen": "2025-12-03"
    },
    {
      "value": "4a759cbc219bcb3a1f8380a959307b39873fb36a9afd0d57ba0736ad7a02763b",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-782",
          "title": "Security Advisory: Critical RCE Vulnerabilities in React Server Components (CVE-2025-55182)",
          "link": "https://snyk.io/blog/security-advisory-critical-rce-vulnerabilities-react-server-components/",
          "published": "2025-12-03",
          "sev": "high"
        }
      ],
      "first_seen": "2025-12-03"
    },
    {
      "value": "4ff096fbea443778fec6f960bf2b9c84da121e6d63e189aebaaa6397d9aac948",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-782",
          "title": "Security Advisory: Critical RCE Vulnerabilities in React Server Components (CVE-2025-55182)",
          "link": "https://snyk.io/blog/security-advisory-critical-rce-vulnerabilities-react-server-components/",
          "published": "2025-12-03",
          "sev": "high"
        }
      ],
      "first_seen": "2025-12-03"
    },
    {
      "value": "55ae00bc8482afd085fd128965b108cca4adb5a3a8a0ee2957d76f33edd5a864",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-782",
          "title": "Security Advisory: Critical RCE Vulnerabilities in React Server Components (CVE-2025-55182)",
          "link": "https://snyk.io/blog/security-advisory-critical-rce-vulnerabilities-react-server-components/",
          "published": "2025-12-03",
          "sev": "high"
        }
      ],
      "first_seen": "2025-12-03"
    },
    {
      "value": "62e9a01307bcf85cdaeecafd6efb5be72a622c43a10f06d6d6d3b566b072228d",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-782",
          "title": "Security Advisory: Critical RCE Vulnerabilities in React Server Components (CVE-2025-55182)",
          "link": "https://snyk.io/blog/security-advisory-critical-rce-vulnerabilities-react-server-components/",
          "published": "2025-12-03",
          "sev": "high"
        }
      ],
      "first_seen": "2025-12-03"
    },
    {
      "value": "7d25a97be42b357adcc6d7f56ab01111378a3190134aa788b1f04336eb924b53",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-782",
          "title": "Security Advisory: Critical RCE Vulnerabilities in React Server Components (CVE-2025-55182)",
          "link": "https://snyk.io/blog/security-advisory-critical-rce-vulnerabilities-react-server-components/",
          "published": "2025-12-03",
          "sev": "high"
        }
      ],
      "first_seen": "2025-12-03"
    },
    {
      "value": "7f05bad031d22c2bb4352bf0b6b9ee2ca064a4c0e11a317e6fedc694de37737a",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-782",
          "title": "Security Advisory: Critical RCE Vulnerabilities in React Server Components (CVE-2025-55182)",
          "link": "https://snyk.io/blog/security-advisory-critical-rce-vulnerabilities-react-server-components/",
          "published": "2025-12-03",
          "sev": "high"
        }
      ],
      "first_seen": "2025-12-03"
    },
    {
      "value": "9c931f7f7d511108263b0a75f7b9fcbbf9fd67ebcc7cd2e5dcd1266b75053624",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-782",
          "title": "Security Advisory: Critical RCE Vulnerabilities in React Server Components (CVE-2025-55182)",
          "link": "https://snyk.io/blog/security-advisory-critical-rce-vulnerabilities-react-server-components/",
          "published": "2025-12-03",
          "sev": "high"
        }
      ],
      "first_seen": "2025-12-03"
    },
    {
      "value": "a455731133c00fdd2a141bdfba4def34ae58195126f762cdf951056b0ef161d4",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-782",
          "title": "Security Advisory: Critical RCE Vulnerabilities in React Server Components (CVE-2025-55182)",
          "link": "https://snyk.io/blog/security-advisory-critical-rce-vulnerabilities-react-server-components/",
          "published": "2025-12-03",
          "sev": "high"
        }
      ],
      "first_seen": "2025-12-03"
    },
    {
      "value": "ac2182dfbf56d58b4d63cde3ad6e7a52fed54e52959e4c82d6fc999f20f8d693",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-782",
          "title": "Security Advisory: Critical RCE Vulnerabilities in React Server Components (CVE-2025-55182)",
          "link": "https://snyk.io/blog/security-advisory-critical-rce-vulnerabilities-react-server-components/",
          "published": "2025-12-03",
          "sev": "high"
        }
      ],
      "first_seen": "2025-12-03"
    },
    {
      "value": "ac7027f30514d0c00d9e8b379b5ad8150c9827c827dc7ee54d906fc2585b6bf6",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-782",
          "title": "Security Advisory: Critical RCE Vulnerabilities in React Server Components (CVE-2025-55182)",
          "link": "https://snyk.io/blog/security-advisory-critical-rce-vulnerabilities-react-server-components/",
          "published": "2025-12-03",
          "sev": "high"
        }
      ],
      "first_seen": "2025-12-03"
    },
    {
      "value": "b38ec4c803a2d84277d9c598bfa5434fb8561ddad0ec38da6f9b8ece8104d787",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-782",
          "title": "Security Advisory: Critical RCE Vulnerabilities in React Server Components (CVE-2025-55182)",
          "link": "https://snyk.io/blog/security-advisory-critical-rce-vulnerabilities-react-server-components/",
          "published": "2025-12-03",
          "sev": "high"
        }
      ],
      "first_seen": "2025-12-03"
    },
    {
      "value": "bc31561c44a36e1305692d0af673bc5406f4a5bb2c3f2ffdb613c09b4e80fa9f",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-782",
          "title": "Security Advisory: Critical RCE Vulnerabilities in React Server Components (CVE-2025-55182)",
          "link": "https://snyk.io/blog/security-advisory-critical-rce-vulnerabilities-react-server-components/",
          "published": "2025-12-03",
          "sev": "high"
        }
      ],
      "first_seen": "2025-12-03"
    },
    {
      "value": "bf602b11d99e815e26c88a3a47eb63997d43db8b8c60db06d6fbddf386fd8c4a",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-782",
          "title": "Security Advisory: Critical RCE Vulnerabilities in React Server Components (CVE-2025-55182)",
          "link": "https://snyk.io/blog/security-advisory-critical-rce-vulnerabilities-react-server-components/",
          "published": "2025-12-03",
          "sev": "high"
        }
      ],
      "first_seen": "2025-12-03"
    },
    {
      "value": "c2867570f3bbb71102373a94c7153239599478af84b9c81f2a0368de36f14a7c",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-782",
          "title": "Security Advisory: Critical RCE Vulnerabilities in React Server Components (CVE-2025-55182)",
          "link": "https://snyk.io/blog/security-advisory-critical-rce-vulnerabilities-react-server-components/",
          "published": "2025-12-03",
          "sev": "high"
        }
      ],
      "first_seen": "2025-12-03"
    },
    {
      "value": "d704541cde64a3eef5c4f80d0d7f96dc96bae8083804c930111024b274557b16",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-782",
          "title": "Security Advisory: Critical RCE Vulnerabilities in React Server Components (CVE-2025-55182)",
          "link": "https://snyk.io/blog/security-advisory-critical-rce-vulnerabilities-react-server-components/",
          "published": "2025-12-03",
          "sev": "high"
        }
      ],
      "first_seen": "2025-12-03"
    },
    {
      "value": "d9313f949af339ed9fafb12374600e66b870961eeb9b2b0d4a3172fd1aa34ed0",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-782",
          "title": "Security Advisory: Critical RCE Vulnerabilities in React Server Components (CVE-2025-55182)",
          "link": "https://snyk.io/blog/security-advisory-critical-rce-vulnerabilities-react-server-components/",
          "published": "2025-12-03",
          "sev": "high"
        }
      ],
      "first_seen": "2025-12-03"
    },
    {
      "value": "e2d7c8491436411474cef5d3b51116ddecfee68bab1e15081752a54772559879",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-782",
          "title": "Security Advisory: Critical RCE Vulnerabilities in React Server Components (CVE-2025-55182)",
          "link": "https://snyk.io/blog/security-advisory-critical-rce-vulnerabilities-react-server-components/",
          "published": "2025-12-03",
          "sev": "high"
        }
      ],
      "first_seen": "2025-12-03"
    },
    {
      "value": "ebdb85704b2e7ced3673b12c6f3687bc0177a7b1b3caef110213cc93a75da837",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-782",
          "title": "Security Advisory: Critical RCE Vulnerabilities in React Server Components (CVE-2025-55182)",
          "link": "https://snyk.io/blog/security-advisory-critical-rce-vulnerabilities-react-server-components/",
          "published": "2025-12-03",
          "sev": "high"
        }
      ],
      "first_seen": "2025-12-03"
    },
    {
      "value": "f88ce150345787dd1bcfbc301350033404e32273c9a140f22da80810e3a3f6ea",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-782",
          "title": "Security Advisory: Critical RCE Vulnerabilities in React Server Components (CVE-2025-55182)",
          "link": "https://snyk.io/blog/security-advisory-critical-rce-vulnerabilities-react-server-components/",
          "published": "2025-12-03",
          "sev": "high"
        }
      ],
      "first_seen": "2025-12-03"
    },
    {
      "value": "fc9e53675e315edeea2292069c3fbc91337c972c936ca0f535da01760814b125",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-782",
          "title": "Security Advisory: Critical RCE Vulnerabilities in React Server Components (CVE-2025-55182)",
          "link": "https://snyk.io/blog/security-advisory-critical-rce-vulnerabilities-react-server-components/",
          "published": "2025-12-03",
          "sev": "high"
        }
      ],
      "first_seen": "2025-12-03"
    },
    {
      "value": "CVE-2025-48572",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-788",
          "title": "CISA KEV: CVE-2025-48572 \u2014 Android Framework Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-12-02",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-12-02"
    },
    {
      "value": "CVE-2025-48633",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-787",
          "title": "CISA KEV: CVE-2025-48633 \u2014 Android Framework Information Disclosure Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-12-02",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-12-02"
    },
    {
      "value": "CVE-2021-26829",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-792",
          "title": "CISA KEV: CVE-2021-26829 \u2014 OpenPLC ScadaBR Cross-site Scripting Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-11-28",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-11-28"
    },
    {
      "value": "3d7570d14d34b0ba137d502f042b27b0f37a59fa",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-796",
          "title": "SHA1-Hulud, npm supply chain incident",
          "link": "https://snyk.io/blog/sha1-hulud-npm-supply-chain-incident/",
          "published": "2025-11-24",
          "sev": "high"
        }
      ],
      "first_seen": "2025-11-24"
    },
    {
      "value": "d1829b4708126dcc7bea7437c04d1f10eacd4a16",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-796",
          "title": "SHA1-Hulud, npm supply chain incident",
          "link": "https://snyk.io/blog/sha1-hulud-npm-supply-chain-incident/",
          "published": "2025-11-24",
          "sev": "high"
        }
      ],
      "first_seen": "2025-11-24"
    },
    {
      "value": "d60ec97eea19fffb4809bc35b91033b52490ca11",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-796",
          "title": "SHA1-Hulud, npm supply chain incident",
          "link": "https://snyk.io/blog/sha1-hulud-npm-supply-chain-incident/",
          "published": "2025-11-24",
          "sev": "high"
        }
      ],
      "first_seen": "2025-11-24"
    },
    {
      "value": "CVE-2025-61757",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-800",
          "title": "CISA KEV: CVE-2025-61757 \u2014 Oracle Fusion Middleware Missing Authentication for Critical Function Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-11-21",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-11-21"
    },
    {
      "value": "CVE-2025-13223",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-806",
          "title": "CISA KEV: CVE-2025-13223 \u2014 Google Chromium V8 Type Confusion Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-11-19",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-11-19"
    },
    {
      "value": "ds20221202.dsc.wcsset.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "ESET WeLiveSecurity"
      ],
      "articles": [
        {
          "id": "art-803",
          "title": "PlushDaemon compromises network devices for adversary-in-the-middle attacks",
          "link": "https://www.welivesecurity.com/en/eset-research/plushdaemon-compromises-network-devices-for-adversary-in-the-middle-attacks/",
          "published": "2025-11-19",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-11-19"
    },
    {
      "value": "test.dsc.wcsset.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "ESET WeLiveSecurity"
      ],
      "articles": [
        {
          "id": "art-803",
          "title": "PlushDaemon compromises network devices for adversary-in-the-middle attacks",
          "link": "https://www.welivesecurity.com/en/eset-research/plushdaemon-compromises-network-devices-for-adversary-in-the-middle-attacks/",
          "published": "2025-11-19",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-11-19"
    },
    {
      "value": "119.136.153.0",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "ESET WeLiveSecurity"
      ],
      "articles": [
        {
          "id": "art-803",
          "title": "PlushDaemon compromises network devices for adversary-in-the-middle attacks",
          "link": "https://www.welivesecurity.com/en/eset-research/plushdaemon-compromises-network-devices-for-adversary-in-the-middle-attacks/",
          "published": "2025-11-19",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-11-19"
    },
    {
      "value": "47.242.198.250",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "ESET WeLiveSecurity"
      ],
      "articles": [
        {
          "id": "art-803",
          "title": "PlushDaemon compromises network devices for adversary-in-the-middle attacks",
          "link": "https://www.welivesecurity.com/en/eset-research/plushdaemon-compromises-network-devices-for-adversary-in-the-middle-attacks/",
          "published": "2025-11-19",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-11-19"
    },
    {
      "value": "CVE-2025-58034",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-808",
          "title": "CISA KEV: CVE-2025-58034 \u2014 Fortinet FortiWeb OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-11-18",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-11-18"
    },
    {
      "value": "CVE-2025-64446",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-809",
          "title": "CISA KEV: CVE-2025-64446 \u2014 Fortinet FortiWeb Path Traversal Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-11-14",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-11-14"
    },
    {
      "value": "CVE-2025-12480",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-812",
          "title": "CISA KEV: CVE-2025-12480 \u2014 Gladinet Triofox Improper Access Control Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-11-12",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-11-12"
    },
    {
      "value": "CVE-2025-62215",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-813",
          "title": "CISA KEV: CVE-2025-62215 \u2014 Microsoft Windows Race Condition Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-11-12",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-11-12"
    },
    {
      "value": "CVE-2025-9242",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-814",
          "title": "CISA KEV: CVE-2025-9242 \u2014 WatchGuard Firebox Out-of-Bounds Write Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-11-12",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-11-12"
    },
    {
      "value": "CVE-2025-21042",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-817",
          "title": "CISA KEV: CVE-2025-21042 \u2014 Samsung Mobile Devices Out-of-Bounds Write Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-11-10",
          "sev": "crit"
        },
        {
          "id": "art-859",
          "title": "CISA KEV: CVE-2025-21043 \u2014 Samsung Mobile Devices Out-of-Bounds Write Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-10-02",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-11-10"
    },
    {
      "value": "CVE-2025-21043",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-817",
          "title": "CISA KEV: CVE-2025-21042 \u2014 Samsung Mobile Devices Out-of-Bounds Write Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-11-10",
          "sev": "crit"
        },
        {
          "id": "art-859",
          "title": "CISA KEV: CVE-2025-21043 \u2014 Samsung Mobile Devices Out-of-Bounds Write Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-10-02",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-11-10"
    },
    {
      "value": "CVE-2025-43300",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-817",
          "title": "CISA KEV: CVE-2025-21042 \u2014 Samsung Mobile Devices Out-of-Bounds Write Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-11-10",
          "sev": "crit"
        },
        {
          "id": "art-886",
          "title": "CISA KEV: CVE-2025-55177 \u2014 Meta Platforms WhatsApp Incorrect Authorization Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-09-02",
          "sev": "crit"
        },
        {
          "id": "art-893",
          "title": "CISA KEV: CVE-2025-43300 \u2014 Apple iOS, iPadOS, and macOS Out-of-Bounds Write Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-08-21",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-11-10"
    },
    {
      "value": "CVE-2025-55177",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-817",
          "title": "CISA KEV: CVE-2025-21042 \u2014 Samsung Mobile Devices Out-of-Bounds Write Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-11-10",
          "sev": "crit"
        },
        {
          "id": "art-886",
          "title": "CISA KEV: CVE-2025-55177 \u2014 Meta Platforms WhatsApp Incorrect Authorization Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-09-02",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-11-10"
    },
    {
      "value": "brightvideodesigns.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-817",
          "title": "CISA KEV: CVE-2025-21042 \u2014 Samsung Mobile Devices Out-of-Bounds Write Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-11-10",
          "sev": "crit"
        },
        {
          "id": "art-859",
          "title": "CISA KEV: CVE-2025-21043 \u2014 Samsung Mobile Devices Out-of-Bounds Write Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-10-02",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-11-10"
    },
    {
      "value": "healthyeatingontherun.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-817",
          "title": "CISA KEV: CVE-2025-21042 \u2014 Samsung Mobile Devices Out-of-Bounds Write Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-11-10",
          "sev": "crit"
        },
        {
          "id": "art-859",
          "title": "CISA KEV: CVE-2025-21043 \u2014 Samsung Mobile Devices Out-of-Bounds Write Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-10-02",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-11-10"
    },
    {
      "value": "hotelsitereview.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-817",
          "title": "CISA KEV: CVE-2025-21042 \u2014 Samsung Mobile Devices Out-of-Bounds Write Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-11-10",
          "sev": "crit"
        },
        {
          "id": "art-859",
          "title": "CISA KEV: CVE-2025-21043 \u2014 Samsung Mobile Devices Out-of-Bounds Write Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-10-02",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-11-10"
    },
    {
      "value": "projectmanagerskills.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-817",
          "title": "CISA KEV: CVE-2025-21042 \u2014 Samsung Mobile Devices Out-of-Bounds Write Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-11-10",
          "sev": "crit"
        },
        {
          "id": "art-859",
          "title": "CISA KEV: CVE-2025-21043 \u2014 Samsung Mobile Devices Out-of-Bounds Write Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-10-02",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-11-10"
    },
    {
      "value": "192.36.57.56",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-817",
          "title": "CISA KEV: CVE-2025-21042 \u2014 Samsung Mobile Devices Out-of-Bounds Write Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-11-10",
          "sev": "crit"
        },
        {
          "id": "art-859",
          "title": "CISA KEV: CVE-2025-21043 \u2014 Samsung Mobile Devices Out-of-Bounds Write Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-10-02",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-11-10"
    },
    {
      "value": "194.76.224.127",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-817",
          "title": "CISA KEV: CVE-2025-21042 \u2014 Samsung Mobile Devices Out-of-Bounds Write Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-11-10",
          "sev": "crit"
        },
        {
          "id": "art-859",
          "title": "CISA KEV: CVE-2025-21043 \u2014 Samsung Mobile Devices Out-of-Bounds Write Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-10-02",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-11-10"
    },
    {
      "value": "45.155.250.158",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-817",
          "title": "CISA KEV: CVE-2025-21042 \u2014 Samsung Mobile Devices Out-of-Bounds Write Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-11-10",
          "sev": "crit"
        },
        {
          "id": "art-859",
          "title": "CISA KEV: CVE-2025-21043 \u2014 Samsung Mobile Devices Out-of-Bounds Write Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-10-02",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-11-10"
    },
    {
      "value": "46.246.28.75",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-817",
          "title": "CISA KEV: CVE-2025-21042 \u2014 Samsung Mobile Devices Out-of-Bounds Write Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-11-10",
          "sev": "crit"
        },
        {
          "id": "art-859",
          "title": "CISA KEV: CVE-2025-21043 \u2014 Samsung Mobile Devices Out-of-Bounds Write Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-10-02",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-11-10"
    },
    {
      "value": "91.132.92.35",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-817",
          "title": "CISA KEV: CVE-2025-21042 \u2014 Samsung Mobile Devices Out-of-Bounds Write Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-11-10",
          "sev": "crit"
        },
        {
          "id": "art-859",
          "title": "CISA KEV: CVE-2025-21043 \u2014 Samsung Mobile Devices Out-of-Bounds Write Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-10-02",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-11-10"
    },
    {
      "value": "92.243.65.240",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-817",
          "title": "CISA KEV: CVE-2025-21042 \u2014 Samsung Mobile Devices Out-of-Bounds Write Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-11-10",
          "sev": "crit"
        },
        {
          "id": "art-859",
          "title": "CISA KEV: CVE-2025-21043 \u2014 Samsung Mobile Devices Out-of-Bounds Write Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-10-02",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-11-10"
    },
    {
      "value": "211311468f3673f005031d5f77d4d716e80cbf3c1f0bb1f148f2200920513261",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-817",
          "title": "CISA KEV: CVE-2025-21042 \u2014 Samsung Mobile Devices Out-of-Bounds Write Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-11-10",
          "sev": "crit"
        },
        {
          "id": "art-859",
          "title": "CISA KEV: CVE-2025-21043 \u2014 Samsung Mobile Devices Out-of-Bounds Write Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-10-02",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-11-10"
    },
    {
      "value": "2425f15eb542fca82892fd107ac19d63d4d112ddbfe698650f0c25acf6f8d78a",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-817",
          "title": "CISA KEV: CVE-2025-21042 \u2014 Samsung Mobile Devices Out-of-Bounds Write Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-11-10",
          "sev": "crit"
        },
        {
          "id": "art-859",
          "title": "CISA KEV: CVE-2025-21043 \u2014 Samsung Mobile Devices Out-of-Bounds Write Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-10-02",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-11-10"
    },
    {
      "value": "29882a3c426273a7302e852aa77662e168b6d44dcebfca53757e29a9cdf02483",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-817",
          "title": "CISA KEV: CVE-2025-21042 \u2014 Samsung Mobile Devices Out-of-Bounds Write Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-11-10",
          "sev": "crit"
        },
        {
          "id": "art-859",
          "title": "CISA KEV: CVE-2025-21043 \u2014 Samsung Mobile Devices Out-of-Bounds Write Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-10-02",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-11-10"
    },
    {
      "value": "384f073d3d51e0f2e1586b6050af62de886ff448735d963dfc026580096d81bd",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-817",
          "title": "CISA KEV: CVE-2025-21042 \u2014 Samsung Mobile Devices Out-of-Bounds Write Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-11-10",
          "sev": "crit"
        },
        {
          "id": "art-859",
          "title": "CISA KEV: CVE-2025-21043 \u2014 Samsung Mobile Devices Out-of-Bounds Write Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-10-02",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-11-10"
    },
    {
      "value": "69cf56ac6f3888efa7a1306977f431fd1edb369a5fd4591ce37b72b7e01955ee",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-817",
          "title": "CISA KEV: CVE-2025-21042 \u2014 Samsung Mobile Devices Out-of-Bounds Write Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-11-10",
          "sev": "crit"
        },
        {
          "id": "art-859",
          "title": "CISA KEV: CVE-2025-21043 \u2014 Samsung Mobile Devices Out-of-Bounds Write Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-10-02",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-11-10"
    },
    {
      "value": "9297888746158e38d320b05b27b0032b2cc29231be8990d87bc46f1e06456f93",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-817",
          "title": "CISA KEV: CVE-2025-21042 \u2014 Samsung Mobile Devices Out-of-Bounds Write Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-11-10",
          "sev": "crit"
        },
        {
          "id": "art-859",
          "title": "CISA KEV: CVE-2025-21043 \u2014 Samsung Mobile Devices Out-of-Bounds Write Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-10-02",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-11-10"
    },
    {
      "value": "a62a2400bf93ed84ebadf22b441924f904d3fcda7d1507ba309a4b1801d44495",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-817",
          "title": "CISA KEV: CVE-2025-21042 \u2014 Samsung Mobile Devices Out-of-Bounds Write Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-11-10",
          "sev": "crit"
        },
        {
          "id": "art-859",
          "title": "CISA KEV: CVE-2025-21043 \u2014 Samsung Mobile Devices Out-of-Bounds Write Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-10-02",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-11-10"
    },
    {
      "value": "b06dec10e8ad0005ebb9da24204c96cb2e297bd8d418bc1c8983d066c0997756",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-817",
          "title": "CISA KEV: CVE-2025-21042 \u2014 Samsung Mobile Devices Out-of-Bounds Write Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-11-10",
          "sev": "crit"
        },
        {
          "id": "art-859",
          "title": "CISA KEV: CVE-2025-21043 \u2014 Samsung Mobile Devices Out-of-Bounds Write Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-10-02",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-11-10"
    },
    {
      "value": "b45817ffb0355badcc89f2d7d48eecf00ebdf2b966ac986514f9d971f6c57d18",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-817",
          "title": "CISA KEV: CVE-2025-21042 \u2014 Samsung Mobile Devices Out-of-Bounds Write Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-11-10",
          "sev": "crit"
        },
        {
          "id": "art-859",
          "title": "CISA KEV: CVE-2025-21043 \u2014 Samsung Mobile Devices Out-of-Bounds Write Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-10-02",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-11-10"
    },
    {
      "value": "b975b499baa3119ac5c2b3379306d4e50b9610e9bba3e56de7dfd3927a96032d",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-817",
          "title": "CISA KEV: CVE-2025-21042 \u2014 Samsung Mobile Devices Out-of-Bounds Write Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-11-10",
          "sev": "crit"
        },
        {
          "id": "art-859",
          "title": "CISA KEV: CVE-2025-21043 \u2014 Samsung Mobile Devices Out-of-Bounds Write Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-10-02",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-11-10"
    },
    {
      "value": "c0f30c2a2d6f95b57128e78dc0b7180e69315057e62809de1926b75f86516b2e",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-817",
          "title": "CISA KEV: CVE-2025-21042 \u2014 Samsung Mobile Devices Out-of-Bounds Write Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-11-10",
          "sev": "crit"
        },
        {
          "id": "art-859",
          "title": "CISA KEV: CVE-2025-21043 \u2014 Samsung Mobile Devices Out-of-Bounds Write Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-10-02",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-11-10"
    },
    {
      "value": "d2fafc7100f33a11089e98b660a85bd479eab761b137cca83b1f6d19629dd3b0",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-817",
          "title": "CISA KEV: CVE-2025-21042 \u2014 Samsung Mobile Devices Out-of-Bounds Write Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-11-10",
          "sev": "crit"
        },
        {
          "id": "art-859",
          "title": "CISA KEV: CVE-2025-21043 \u2014 Samsung Mobile Devices Out-of-Bounds Write Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-10-02",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-11-10"
    },
    {
      "value": "ffeeb0356abb56c5084756a5ab0a39002832403bca5290bb6d794d14b642ffe2",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-817",
          "title": "CISA KEV: CVE-2025-21042 \u2014 Samsung Mobile Devices Out-of-Bounds Write Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-11-10",
          "sev": "crit"
        },
        {
          "id": "art-859",
          "title": "CISA KEV: CVE-2025-21043 \u2014 Samsung Mobile Devices Out-of-Bounds Write Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-10-02",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-11-10"
    },
    {
      "value": "CVE-2025-11371",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-822",
          "title": "CISA KEV: CVE-2025-11371 \u2014 Gladinet CentreStack and Triofox Files or Directories Accessible to External Parties Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-11-04",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-11-04"
    },
    {
      "value": "CVE-2025-30406",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-822",
          "title": "CISA KEV: CVE-2025-11371 \u2014 Gladinet CentreStack and Triofox Files or Directories Accessible to External Parties Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-11-04",
          "sev": "crit"
        },
        {
          "id": "art-1022",
          "title": "CISA KEV: CVE-2025-30406 \u2014 Gladinet CentreStack and Triofox Use of Hard-coded Cryptographic Key Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-04-08",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-11-04"
    },
    {
      "value": "146.70.134.50",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-822",
          "title": "CISA KEV: CVE-2025-11371 \u2014 Gladinet CentreStack and Triofox Files or Directories Accessible to External Parties Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-11-04",
          "sev": "crit"
        },
        {
          "id": "art-1022",
          "title": "CISA KEV: CVE-2025-30406 \u2014 Gladinet CentreStack and Triofox Use of Hard-coded Cryptographic Key Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-04-08",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-11-04"
    },
    {
      "value": "147.124.216.205",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-822",
          "title": "CISA KEV: CVE-2025-11371 \u2014 Gladinet CentreStack and Triofox Files or Directories Accessible to External Parties Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-11-04",
          "sev": "crit"
        },
        {
          "id": "art-1022",
          "title": "CISA KEV: CVE-2025-30406 \u2014 Gladinet CentreStack and Triofox Use of Hard-coded Cryptographic Key Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-04-08",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-11-04"
    },
    {
      "value": "CVE-2025-24893",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-824",
          "title": "CISA KEV: CVE-2025-24893 \u2014 XWiki Platform Eval Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-10-30",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-10-30"
    },
    {
      "value": "CVE-2025-41244",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-823",
          "title": "CISA KEV: CVE-2025-41244 \u2014 Broadcom VMware Aria Operations and VMware Tools Privilege Defined with Unsafe Actions Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-10-30",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-10-30"
    },
    {
      "value": "c3pool.org",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-824",
          "title": "CISA KEV: CVE-2025-24893 \u2014 XWiki Platform Eval Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-10-30",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-10-30"
    },
    {
      "value": "123.25.249.88",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-824",
          "title": "CISA KEV: CVE-2025-24893 \u2014 XWiki Platform Eval Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-10-30",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-10-30"
    },
    {
      "value": "193.32.208.24",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-824",
          "title": "CISA KEV: CVE-2025-24893 \u2014 XWiki Platform Eval Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-10-30",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-10-30"
    },
    {
      "value": "0b907eee9a85d39f8f0d7c503cc1f84a71c4de10",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-824",
          "title": "CISA KEV: CVE-2025-24893 \u2014 XWiki Platform Eval Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-10-30",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-10-30"
    },
    {
      "value": "2abd6f68a24b0a5df5809276016e6b85c77e5f7f",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-824",
          "title": "CISA KEV: CVE-2025-24893 \u2014 XWiki Platform Eval Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-10-30",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-10-30"
    },
    {
      "value": "5abc337dbc04fee7206956dad1e0b6d43921a868",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-824",
          "title": "CISA KEV: CVE-2025-24893 \u2014 XWiki Platform Eval Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-10-30",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-10-30"
    },
    {
      "value": "90d274c7600fbdca5fe035250d0baff20889ec2b",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-824",
          "title": "CISA KEV: CVE-2025-24893 \u2014 XWiki Platform Eval Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-10-30",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-10-30"
    },
    {
      "value": "de082aeb01d41dd81cfb79bc5bfa33453b0022ed",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-824",
          "title": "CISA KEV: CVE-2025-24893 \u2014 XWiki Platform Eval Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-10-30",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-10-30"
    },
    {
      "value": "CVE-2025-6204",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-825",
          "title": "CISA KEV: CVE-2025-6204 \u2014 Dassault Syst\u00e8mes DELMIA Apriso Code Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-10-28",
          "sev": "crit"
        },
        {
          "id": "art-826",
          "title": "CISA KEV: CVE-2025-6205 \u2014 Dassault Syst\u00e8mes DELMIA Apriso Missing Authorization Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-10-28",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-10-28"
    },
    {
      "value": "CVE-2025-6205",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-825",
          "title": "CISA KEV: CVE-2025-6204 \u2014 Dassault Syst\u00e8mes DELMIA Apriso Code Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-10-28",
          "sev": "crit"
        },
        {
          "id": "art-826",
          "title": "CISA KEV: CVE-2025-6205 \u2014 Dassault Syst\u00e8mes DELMIA Apriso Missing Authorization Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-10-28",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-10-28"
    },
    {
      "value": "CVE-2025-54236",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-827",
          "title": "CISA KEV: CVE-2025-54236 \u2014 Adobe Commerce and\u202fMagento Improper Input Validation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-10-24",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-10-24"
    },
    {
      "value": "CVE-2025-59287",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-828",
          "title": "CISA KEV: CVE-2025-59287 \u2014 Microsoft Windows Server Update Service (WSUS) Deserialization of Untrusted Data Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-10-24",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-10-24"
    },
    {
      "value": "sagecrafft.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-827",
          "title": "CISA KEV: CVE-2025-54236 \u2014 Adobe Commerce and\u202fMagento Improper Input Validation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-10-24",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-10-24"
    },
    {
      "value": "tecnokauf.ru",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-827",
          "title": "CISA KEV: CVE-2025-54236 \u2014 Adobe Commerce and\u202fMagento Improper Input Validation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-10-24",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-10-24"
    },
    {
      "value": "webhook.site/22b6b8c8-2e07-4878-a681-b772e569aa6a",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-828",
          "title": "CISA KEV: CVE-2025-59287 \u2014 Microsoft Windows Server Update Service (WSUS) Deserialization of Untrusted Data Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-10-24",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-10-24"
    },
    {
      "value": "worcksbot.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-827",
          "title": "CISA KEV: CVE-2025-54236 \u2014 Adobe Commerce and\u202fMagento Improper Input Validation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-10-24",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-10-24"
    },
    {
      "value": "103.215.237.26",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-827",
          "title": "CISA KEV: CVE-2025-54236 \u2014 Adobe Commerce and\u202fMagento Improper Input Validation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-10-24",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-10-24"
    },
    {
      "value": "141.11.62.221",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-827",
          "title": "CISA KEV: CVE-2025-54236 \u2014 Adobe Commerce and\u202fMagento Improper Input Validation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-10-24",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-10-24"
    },
    {
      "value": "143.244.44.172",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-827",
          "title": "CISA KEV: CVE-2025-54236 \u2014 Adobe Commerce and\u202fMagento Improper Input Validation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-10-24",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-10-24"
    },
    {
      "value": "149.28.33.250",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-827",
          "title": "CISA KEV: CVE-2025-54236 \u2014 Adobe Commerce and\u202fMagento Improper Input Validation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-10-24",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-10-24"
    },
    {
      "value": "155.117.84.134",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-827",
          "title": "CISA KEV: CVE-2025-54236 \u2014 Adobe Commerce and\u202fMagento Improper Input Validation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-10-24",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-10-24"
    },
    {
      "value": "155.138.226.245",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-827",
          "title": "CISA KEV: CVE-2025-54236 \u2014 Adobe Commerce and\u202fMagento Improper Input Validation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-10-24",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-10-24"
    },
    {
      "value": "156.244.16.170",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-827",
          "title": "CISA KEV: CVE-2025-54236 \u2014 Adobe Commerce and\u202fMagento Improper Input Validation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-10-24",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-10-24"
    },
    {
      "value": "157.245.52.111",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-827",
          "title": "CISA KEV: CVE-2025-54236 \u2014 Adobe Commerce and\u202fMagento Improper Input Validation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-10-24",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-10-24"
    },
    {
      "value": "159.89.12.166",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-827",
          "title": "CISA KEV: CVE-2025-54236 \u2014 Adobe Commerce and\u202fMagento Improper Input Validation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-10-24",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-10-24"
    },
    {
      "value": "198.144.182.13",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-827",
          "title": "CISA KEV: CVE-2025-54236 \u2014 Adobe Commerce and\u202fMagento Improper Input Validation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-10-24",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-10-24"
    },
    {
      "value": "212.8.248.191",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-827",
          "title": "CISA KEV: CVE-2025-54236 \u2014 Adobe Commerce and\u202fMagento Improper Input Validation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-10-24",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-10-24"
    },
    {
      "value": "23.146.184.93",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-827",
          "title": "CISA KEV: CVE-2025-54236 \u2014 Adobe Commerce and\u202fMagento Improper Input Validation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-10-24",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-10-24"
    },
    {
      "value": "23.249.27.221",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-827",
          "title": "CISA KEV: CVE-2025-54236 \u2014 Adobe Commerce and\u202fMagento Improper Input Validation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-10-24",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-10-24"
    },
    {
      "value": "34.227.25.4",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-827",
          "title": "CISA KEV: CVE-2025-54236 \u2014 Adobe Commerce and\u202fMagento Improper Input Validation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-10-24",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-10-24"
    },
    {
      "value": "44.212.43.34",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-827",
          "title": "CISA KEV: CVE-2025-54236 \u2014 Adobe Commerce and\u202fMagento Improper Input Validation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-10-24",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-10-24"
    },
    {
      "value": "45.143.20.147",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-827",
          "title": "CISA KEV: CVE-2025-54236 \u2014 Adobe Commerce and\u202fMagento Improper Input Validation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-10-24",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-10-24"
    },
    {
      "value": "45.32.66.51",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-827",
          "title": "CISA KEV: CVE-2025-54236 \u2014 Adobe Commerce and\u202fMagento Improper Input Validation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-10-24",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-10-24"
    },
    {
      "value": "46.39.230.243",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-827",
          "title": "CISA KEV: CVE-2025-54236 \u2014 Adobe Commerce and\u202fMagento Improper Input Validation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-10-24",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-10-24"
    },
    {
      "value": "54.205.171.35",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-827",
          "title": "CISA KEV: CVE-2025-54236 \u2014 Adobe Commerce and\u202fMagento Improper Input Validation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-10-24",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-10-24"
    },
    {
      "value": "54.226.181.219",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-827",
          "title": "CISA KEV: CVE-2025-54236 \u2014 Adobe Commerce and\u202fMagento Improper Input Validation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-10-24",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-10-24"
    },
    {
      "value": "80.78.25.213",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-827",
          "title": "CISA KEV: CVE-2025-54236 \u2014 Adobe Commerce and\u202fMagento Improper Input Validation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-10-24",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-10-24"
    },
    {
      "value": "86.203.185.51",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-827",
          "title": "CISA KEV: CVE-2025-54236 \u2014 Adobe Commerce and\u202fMagento Improper Input Validation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-10-24",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-10-24"
    },
    {
      "value": "99.246.176.115",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-827",
          "title": "CISA KEV: CVE-2025-54236 \u2014 Adobe Commerce and\u202fMagento Improper Input Validation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-10-24",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-10-24"
    },
    {
      "value": "CVE-2025-61932",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-831",
          "title": "CISA KEV: CVE-2025-61932 \u2014 Motex LANSCOPE Endpoint Manager Improper Verification of Source of a Communication Channel Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-10-22",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-10-22"
    },
    {
      "value": "108.61.161.118",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-831",
          "title": "CISA KEV: CVE-2025-61932 \u2014 Motex LANSCOPE Endpoint Manager Improper Verification of Source of a Communication Channel Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-10-22",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-10-22"
    },
    {
      "value": "38.54.56.10",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-831",
          "title": "CISA KEV: CVE-2025-61932 \u2014 Motex LANSCOPE Endpoint Manager Improper Verification of Source of a Communication Channel Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-10-22",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-10-22"
    },
    {
      "value": "38.54.56.57",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-831",
          "title": "CISA KEV: CVE-2025-61932 \u2014 Motex LANSCOPE Endpoint Manager Improper Verification of Source of a Communication Channel Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-10-22",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-10-22"
    },
    {
      "value": "38.54.88.172",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-831",
          "title": "CISA KEV: CVE-2025-61932 \u2014 Motex LANSCOPE Endpoint Manager Improper Verification of Source of a Communication Channel Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-10-22",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-10-22"
    },
    {
      "value": "4946b0de3b705878c514e2eead096e1e",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-831",
          "title": "CISA KEV: CVE-2025-61932 \u2014 Motex LANSCOPE Endpoint Manager Improper Verification of Source of a Communication Channel Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-10-22",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-10-22"
    },
    {
      "value": "932c91020b74aaa7ffc687e21da0119c",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-831",
          "title": "CISA KEV: CVE-2025-61932 \u2014 Motex LANSCOPE Endpoint Manager Improper Verification of Source of a Communication Channel Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-10-22",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-10-22"
    },
    {
      "value": "1406b4e905c65ba1599eb9c619c196fa5e1c3bf7",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-831",
          "title": "CISA KEV: CVE-2025-61932 \u2014 Motex LANSCOPE Endpoint Manager Improper Verification of Source of a Communication Channel Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-10-22",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-10-22"
    },
    {
      "value": "8124940a41d4b7608eada0d2b546b73c010e30b1",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-831",
          "title": "CISA KEV: CVE-2025-61932 \u2014 Motex LANSCOPE Endpoint Manager Improper Verification of Source of a Communication Channel Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-10-22",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-10-22"
    },
    {
      "value": "be75458b489468e0acdea6ebbb424bc898b3db29",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-831",
          "title": "CISA KEV: CVE-2025-61932 \u2014 Motex LANSCOPE Endpoint Manager Improper Verification of Source of a Communication Channel Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-10-22",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-10-22"
    },
    {
      "value": "3c96c1a9b3751339390be9d7a5c3694df46212fb97ebddc074547c2338a4c7ba",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-831",
          "title": "CISA KEV: CVE-2025-61932 \u2014 Motex LANSCOPE Endpoint Manager Improper Verification of Source of a Communication Channel Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-10-22",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-10-22"
    },
    {
      "value": "704e697441c0af67423458a99f30318c57f1a81c4146beb4dd1a88a88a8c97c3",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-831",
          "title": "CISA KEV: CVE-2025-61932 \u2014 Motex LANSCOPE Endpoint Manager Improper Verification of Source of a Communication Channel Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-10-22",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-10-22"
    },
    {
      "value": "9e581d0506d2f6ec39226f052a58bc5a020ebc81ae539fa3a6b7fc0db1b94946",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-831",
          "title": "CISA KEV: CVE-2025-61932 \u2014 Motex LANSCOPE Endpoint Manager Improper Verification of Source of a Communication Channel Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-10-22",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-10-22"
    },
    {
      "value": "CVE-2022-48503",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-832",
          "title": "CISA KEV: CVE-2022-48503 \u2014 Apple Multiple Products Unspecified Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-10-20",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-10-20"
    },
    {
      "value": "CVE-2025-2746",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-833",
          "title": "CISA KEV: CVE-2025-2746 \u2014 Kentico Xperience CMS Authentication Bypass Using an Alternate Path or Channel Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-10-20",
          "sev": "crit"
        },
        {
          "id": "art-834",
          "title": "CISA KEV: CVE-2025-2747 \u2014 Kentico Xperience CMS Authentication Bypass Using an Alternate Path or Channel Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-10-20",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-10-20"
    },
    {
      "value": "CVE-2025-2747",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-833",
          "title": "CISA KEV: CVE-2025-2746 \u2014 Kentico Xperience CMS Authentication Bypass Using an Alternate Path or Channel Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-10-20",
          "sev": "crit"
        },
        {
          "id": "art-834",
          "title": "CISA KEV: CVE-2025-2747 \u2014 Kentico Xperience CMS Authentication Bypass Using an Alternate Path or Channel Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-10-20",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-10-20"
    },
    {
      "value": "CVE-2025-33073",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-835",
          "title": "CISA KEV: CVE-2025-33073 \u2014 Microsoft Windows SMB Client Improper Access Control Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-10-20",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-10-20"
    },
    {
      "value": "CVE-2025-61882",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-836",
          "title": "CISA KEV: CVE-2025-61884 \u2014 Oracle E-Business Suite Server-Side Request Forgery (SSRF) Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-10-20",
          "sev": "crit"
        },
        {
          "id": "art-855",
          "title": "CISA KEV: CVE-2025-61882 \u2014 Oracle E-Business Suite Unspecified Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-10-06",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-10-20"
    },
    {
      "value": "CVE-2025-61884",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-836",
          "title": "CISA KEV: CVE-2025-61884 \u2014 Oracle E-Business Suite Server-Side Request Forgery (SSRF) Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-10-20",
          "sev": "crit"
        },
        {
          "id": "art-855",
          "title": "CISA KEV: CVE-2025-61882 \u2014 Oracle E-Business Suite Unspecified Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-10-06",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-10-20"
    },
    {
      "value": "pubstorm.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-836",
          "title": "CISA KEV: CVE-2025-61884 \u2014 Oracle E-Business Suite Server-Side Request Forgery (SSRF) Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-10-20",
          "sev": "crit"
        },
        {
          "id": "art-855",
          "title": "CISA KEV: CVE-2025-61882 \u2014 Oracle E-Business Suite Unspecified Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-10-06",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-10-20"
    },
    {
      "value": "pubstorm.net",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-836",
          "title": "CISA KEV: CVE-2025-61884 \u2014 Oracle E-Business Suite Server-Side Request Forgery (SSRF) Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-10-20",
          "sev": "crit"
        },
        {
          "id": "art-855",
          "title": "CISA KEV: CVE-2025-61882 \u2014 Oracle E-Business Suite Unspecified Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-10-06",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-10-20"
    },
    {
      "value": "104.194.11.200",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-836",
          "title": "CISA KEV: CVE-2025-61884 \u2014 Oracle E-Business Suite Server-Side Request Forgery (SSRF) Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-10-20",
          "sev": "crit"
        },
        {
          "id": "art-855",
          "title": "CISA KEV: CVE-2025-61882 \u2014 Oracle E-Business Suite Unspecified Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-10-06",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-10-20"
    },
    {
      "value": "161.97.99.49",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-836",
          "title": "CISA KEV: CVE-2025-61884 \u2014 Oracle E-Business Suite Server-Side Request Forgery (SSRF) Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-10-20",
          "sev": "crit"
        },
        {
          "id": "art-855",
          "title": "CISA KEV: CVE-2025-61882 \u2014 Oracle E-Business Suite Unspecified Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-10-06",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-10-20"
    },
    {
      "value": "162.55.17.215",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-836",
          "title": "CISA KEV: CVE-2025-61884 \u2014 Oracle E-Business Suite Server-Side Request Forgery (SSRF) Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-10-20",
          "sev": "crit"
        },
        {
          "id": "art-855",
          "title": "CISA KEV: CVE-2025-61882 \u2014 Oracle E-Business Suite Unspecified Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-10-06",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-10-20"
    },
    {
      "value": "200.107.207.26",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-836",
          "title": "CISA KEV: CVE-2025-61884 \u2014 Oracle E-Business Suite Server-Side Request Forgery (SSRF) Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-10-20",
          "sev": "crit"
        },
        {
          "id": "art-855",
          "title": "CISA KEV: CVE-2025-61882 \u2014 Oracle E-Business Suite Unspecified Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-10-06",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-10-20"
    },
    {
      "value": "CVE-2025-54253",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-839",
          "title": "CISA KEV: CVE-2025-54253 \u2014 Adobe Experience Manager Forms Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-10-15",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-10-15"
    },
    {
      "value": "CVE-2025-54254",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-839",
          "title": "CISA KEV: CVE-2025-54253 \u2014 Adobe Experience Manager Forms Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-10-15",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-10-15"
    },
    {
      "value": "CVE-2016-7836",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-845",
          "title": "CISA KEV: CVE-2016-7836 \u2014 SKYSEA Client View Improper Authentication Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-10-14",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-10-14"
    },
    {
      "value": "CVE-2025-24990",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-843",
          "title": "CISA KEV: CVE-2025-24990 \u2014 Microsoft Windows Untrusted Pointer Dereference Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-10-14",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-10-14"
    },
    {
      "value": "CVE-2025-47827",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-842",
          "title": "CISA KEV: CVE-2025-47827 \u2014 IGEL OS Use of a Key Past its Expiration Date Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-10-14",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-10-14"
    },
    {
      "value": "CVE-2025-59230",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-844",
          "title": "CISA KEV: CVE-2025-59230 \u2014 Microsoft Windows Improper Access Control Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-10-14",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-10-14"
    },
    {
      "value": "CVE-2021-43798",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-847",
          "title": "CISA KEV: CVE-2021-43798 \u2014 Grafana Path Traversal Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-10-09",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-10-09"
    },
    {
      "value": "cfn.fejyhy.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-846",
          "title": "Phishing Campaign Leveraging the NPM Ecosystem",
          "link": "https://snyk.io/blog/phishing-campaign-leveraging-the-npm-ecosystem/",
          "published": "2025-10-09",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-10-09"
    },
    {
      "value": "cfn.fenamu.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-846",
          "title": "Phishing Campaign Leveraging the NPM Ecosystem",
          "link": "https://snyk.io/blog/phishing-campaign-leveraging-the-npm-ecosystem/",
          "published": "2025-10-09",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-10-09"
    },
    {
      "value": "cfn.jackpotmastersdanske.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-846",
          "title": "Phishing Campaign Leveraging the NPM Ecosystem",
          "link": "https://snyk.io/blog/phishing-campaign-leveraging-the-npm-ecosystem/",
          "published": "2025-10-09",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-10-09"
    },
    {
      "value": "cfn.notwinningbutpartici.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-846",
          "title": "Phishing Campaign Leveraging the NPM Ecosystem",
          "link": "https://snyk.io/blog/phishing-campaign-leveraging-the-npm-ecosystem/",
          "published": "2025-10-09",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-10-09"
    },
    {
      "value": "elkendinsc.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-846",
          "title": "Phishing Campaign Leveraging the NPM Ecosystem",
          "link": "https://snyk.io/blog/phishing-campaign-leveraging-the-npm-ecosystem/",
          "published": "2025-10-09",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-10-09"
    },
    {
      "value": "musicboxcr.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-846",
          "title": "Phishing Campaign Leveraging the NPM Ecosystem",
          "link": "https://snyk.io/blog/phishing-campaign-leveraging-the-npm-ecosystem/",
          "published": "2025-10-09",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-10-09"
    },
    {
      "value": "villasmbuva.co.mz",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-846",
          "title": "Phishing Campaign Leveraging the NPM Ecosystem",
          "link": "https://snyk.io/blog/phishing-campaign-leveraging-the-npm-ecosystem/",
          "published": "2025-10-09",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-10-09"
    },
    {
      "value": "CVE-2025-27915",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-848",
          "title": "CISA KEV: CVE-2025-27915 \u2014 Synacor Zimbra Collaboration Suite (ZCS) Cross-site Scripting Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-10-07",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-10-07"
    },
    {
      "value": "ffrk.net",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-848",
          "title": "CISA KEV: CVE-2025-27915 \u2014 Synacor Zimbra Collaboration Suite (ZCS) Cross-site Scripting Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-10-07",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-10-07"
    },
    {
      "value": "193.29.58.37",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-848",
          "title": "CISA KEV: CVE-2025-27915 \u2014 Synacor Zimbra Collaboration Suite (ZCS) Cross-site Scripting Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-10-07",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-10-07"
    },
    {
      "value": "CVE-2010-3765",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-854",
          "title": "CISA KEV: CVE-2010-3765 \u2014 Mozilla Multiple Products Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-10-06",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-10-06"
    },
    {
      "value": "CVE-2010-3962",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-850",
          "title": "CISA KEV: CVE-2010-3962 \u2014 Microsoft Internet Explorer Uninitialized Memory Corruption Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-10-06",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-10-06"
    },
    {
      "value": "CVE-2011-3402",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-853",
          "title": "CISA KEV: CVE-2011-3402 \u2014 Microsoft Windows Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-10-06",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-10-06"
    },
    {
      "value": "CVE-2013-3918",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-852",
          "title": "CISA KEV: CVE-2013-3918 \u2014 Microsoft Windows Out-of-Bounds Write Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-10-06",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-10-06"
    },
    {
      "value": "CVE-2021-22555",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-849",
          "title": "CISA KEV: CVE-2021-22555 \u2014 Linux Kernel Heap Out-of-Bounds Write Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-10-06",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-10-06"
    },
    {
      "value": "CVE-2021-43226",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-851",
          "title": "CISA KEV: CVE-2021-43226 \u2014 Microsoft Windows Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-10-06",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-10-06"
    },
    {
      "value": "dxcdfghg.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-850",
          "title": "CISA KEV: CVE-2010-3962 \u2014 Microsoft Internet Explorer Uninitialized Memory Corruption Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-10-06",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-10-06"
    },
    {
      "value": "l-3com.dyndns-work.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-854",
          "title": "CISA KEV: CVE-2010-3765 \u2014 Mozilla Multiple Products Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-10-06",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-10-06"
    },
    {
      "value": "l-3com.dyndns.tv",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-854",
          "title": "CISA KEV: CVE-2010-3765 \u2014 Mozilla Multiple Products Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-10-06",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-10-06"
    },
    {
      "value": "185.181.60.11",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-855",
          "title": "CISA KEV: CVE-2025-61882 \u2014 Oracle E-Business Suite Unspecified Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-10-06",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-10-06"
    },
    {
      "value": "76b6d36e04e367a2334c445b51e1ecce97e4c614e88dfb4f72b104ca0f31235d",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-855",
          "title": "CISA KEV: CVE-2025-61882 \u2014 Oracle E-Business Suite Unspecified Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-10-06",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-10-06"
    },
    {
      "value": "CVE-2014-6271",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-856",
          "title": "CISA KEV: CVE-2014-6278 \u2014 GNU Bash OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-10-02",
          "sev": "crit"
        },
        {
          "id": "art-2684",
          "title": "CISA KEV: CVE-2014-6271 \u2014 GNU Bourne-Again Shell (Bash) Arbitrary Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-01-28",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-10-02"
    },
    {
      "value": "CVE-2014-6277",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-856",
          "title": "CISA KEV: CVE-2014-6278 \u2014 GNU Bash OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-10-02",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-10-02"
    },
    {
      "value": "CVE-2014-6278",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-856",
          "title": "CISA KEV: CVE-2014-6278 \u2014 GNU Bash OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-10-02",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-10-02"
    },
    {
      "value": "CVE-2014-7169",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-856",
          "title": "CISA KEV: CVE-2014-6278 \u2014 GNU Bash OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-10-02",
          "sev": "crit"
        },
        {
          "id": "art-2684",
          "title": "CISA KEV: CVE-2014-6271 \u2014 GNU Bourne-Again Shell (Bash) Arbitrary Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-01-28",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-10-02"
    },
    {
      "value": "CVE-2014-7186",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-856",
          "title": "CISA KEV: CVE-2014-6278 \u2014 GNU Bash OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-10-02",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-10-02"
    },
    {
      "value": "CVE-2014-7187",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-856",
          "title": "CISA KEV: CVE-2014-6278 \u2014 GNU Bash OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-10-02",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-10-02"
    },
    {
      "value": "CVE-2015-7755",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-858",
          "title": "CISA KEV: CVE-2015-7755 \u2014 Juniper ScreenOS Improper Authentication Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-10-02",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-10-02"
    },
    {
      "value": "CVE-2015-7756",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-858",
          "title": "CISA KEV: CVE-2015-7755 \u2014 Juniper ScreenOS Improper Authentication Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-10-02",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-10-02"
    },
    {
      "value": "CVE-2017-1000353",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-857",
          "title": "CISA KEV: CVE-2017-1000353 \u2014 Jenkins Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-10-02",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-10-02"
    },
    {
      "value": "CVE-2025-4008",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-860",
          "title": "CISA KEV: CVE-2025-4008 \u2014 Smartbedded Meteobridge Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-10-02",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-10-02"
    },
    {
      "value": "CVE-2017-3881",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-865",
          "title": "CISA KEV: CVE-2025-20352 \u2014 Cisco IOS and IOS XE Software SNMP Denial of Service and Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-09-29",
          "sev": "crit"
        },
        {
          "id": "art-2444",
          "title": "CISA KEV: CVE-2017-3881 \u2014 Cisco IOS and IOS XE Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-09-29"
    },
    {
      "value": "CVE-2021-21311",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-866",
          "title": "CISA KEV: CVE-2021-21311 \u2014 Adminer Server-Side Request Forgery Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-09-29",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-09-29"
    },
    {
      "value": "CVE-2025-10035",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-864",
          "title": "CISA KEV: CVE-2025-10035 \u2014 Fortra GoAnywhere MFT Deserialization of Untrusted Data Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-09-29",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-09-29"
    },
    {
      "value": "CVE-2025-20352",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-865",
          "title": "CISA KEV: CVE-2025-20352 \u2014 Cisco IOS and IOS XE Software SNMP Denial of Service and Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-09-29",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-09-29"
    },
    {
      "value": "CVE-2025-32463",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-862",
          "title": "CISA KEV: CVE-2025-32463 \u2014 Sudo Inclusion of Functionality from Untrusted Control Sphere Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-09-29",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-09-29"
    },
    {
      "value": "CVE-2025-59689",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-863",
          "title": "CISA KEV: CVE-2025-59689 \u2014 Libraesva Email Security Gateway Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-09-29",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-09-29"
    },
    {
      "value": "213.183.63.41",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-864",
          "title": "CISA KEV: CVE-2025-10035 \u2014 Fortra GoAnywhere MFT Deserialization of Untrusted Data Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-09-29",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-09-29"
    },
    {
      "value": "31.220.45.120",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-864",
          "title": "CISA KEV: CVE-2025-10035 \u2014 Fortra GoAnywhere MFT Deserialization of Untrusted Data Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-09-29",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-09-29"
    },
    {
      "value": "45.11.183.123",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-864",
          "title": "CISA KEV: CVE-2025-10035 \u2014 Fortra GoAnywhere MFT Deserialization of Untrusted Data Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-09-29",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-09-29"
    },
    {
      "value": "235dc2d8c92661e5e2797a03bccd2653272ca1ac93401d194d7784930ca17a5a",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-865",
          "title": "CISA KEV: CVE-2025-20352 \u2014 Cisco IOS and IOS XE Software SNMP Denial of Service and Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-09-29",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-09-29"
    },
    {
      "value": "2abc874435c16aa5cfd431b0d9c26095ef4b9429bd82306f054c367e96df49b2",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-865",
          "title": "CISA KEV: CVE-2025-20352 \u2014 Cisco IOS and IOS XE Software SNMP Denial of Service and Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-09-29",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-09-29"
    },
    {
      "value": "3a524bc40ca7c11b68283504f0119caeefd7589edea621d43d5d0cd973354675",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-865",
          "title": "CISA KEV: CVE-2025-20352 \u2014 Cisco IOS and IOS XE Software SNMP Denial of Service and Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-09-29",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-09-29"
    },
    {
      "value": "4106c35ff46bb6f2f4a42d63a2b8a619f1e1df72414122ddf6fd1b1a644b3220",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-864",
          "title": "CISA KEV: CVE-2025-10035 \u2014 Fortra GoAnywhere MFT Deserialization of Untrusted Data Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-09-29",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-09-29"
    },
    {
      "value": "5ba7de7d5115789b952d9b1c6cff440c9128f438de933ff9044a68fff8496d19",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-864",
          "title": "CISA KEV: CVE-2025-10035 \u2014 Fortra GoAnywhere MFT Deserialization of Untrusted Data Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-09-29",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-09-29"
    },
    {
      "value": "69d761bdde73ea8e33384cf986d7e9c2d9011f7aad8933e8af64e60a77091e11",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-865",
          "title": "CISA KEV: CVE-2025-20352 \u2014 Cisco IOS and IOS XE Software SNMP Denial of Service and Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-09-29",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-09-29"
    },
    {
      "value": "7cc7aed51adb426e55d82fd74c55b78f6ecbb895a315be721ef149a17f4b3a9b",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-865",
          "title": "CISA KEV: CVE-2025-20352 \u2014 Cisco IOS and IOS XE Software SNMP Denial of Service and Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-09-29",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-09-29"
    },
    {
      "value": "81b35152768f28a479ba9f7e27d66042b0d7edcd79355481aa401f3f47a7733b",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-865",
          "title": "CISA KEV: CVE-2025-20352 \u2014 Cisco IOS and IOS XE Software SNMP Denial of Service and Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-09-29",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-09-29"
    },
    {
      "value": "9b8a896aa2057f46e17b18bbe091d85fb816b1d3232a3178d6aba94df3a92f6a",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-865",
          "title": "CISA KEV: CVE-2025-20352 \u2014 Cisco IOS and IOS XE Software SNMP Denial of Service and Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-09-29",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-09-29"
    },
    {
      "value": "b08877f6f1c6c097240a6a8aa4a23243e3b14a1432170bc3fa5fa9886a2b19b4",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-865",
          "title": "CISA KEV: CVE-2025-20352 \u2014 Cisco IOS and IOS XE Software SNMP Denial of Service and Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-09-29",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-09-29"
    },
    {
      "value": "c7e2632702d0e22598b90ea226d3cde4830455d9232bd8b33ebcb13827e99bc3",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-864",
          "title": "CISA KEV: CVE-2025-10035 \u2014 Fortra GoAnywhere MFT Deserialization of Untrusted Data Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-09-29",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-09-29"
    },
    {
      "value": "cd5aa589873d777c6e919c4438afe8bceccad6bbe57739e2ccb70b39aee1e8b3",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-864",
          "title": "CISA KEV: CVE-2025-10035 \u2014 Fortra GoAnywhere MFT Deserialization of Untrusted Data Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-09-29",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-09-29"
    },
    {
      "value": "e303d0c6c59b4dc55edc0212a9319702e9db7fa03185ae9177777b874c02d4c1",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-865",
          "title": "CISA KEV: CVE-2025-20352 \u2014 Cisco IOS and IOS XE Software SNMP Denial of Service and Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-09-29",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-09-29"
    },
    {
      "value": "CVE-2025-20333",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-868",
          "title": "CISA KEV: CVE-2025-20362 \u2014 Cisco Secure Firewall Adaptive Security (ASA) Appliance and Secure Firewall Threat Defense (FTD) Missing Authorization Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-09-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-09-25"
    },
    {
      "value": "CVE-2025-20362",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-868",
          "title": "CISA KEV: CVE-2025-20362 \u2014 Cisco Secure Firewall Adaptive Security (ASA) Appliance and Secure Firewall Threat Defense (FTD) Missing Authorization Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-09-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-09-25"
    },
    {
      "value": "CVE-2025-20363",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-868",
          "title": "CISA KEV: CVE-2025-20362 \u2014 Cisco Secure Firewall Adaptive Security (ASA) Appliance and Secure Firewall Threat Defense (FTD) Missing Authorization Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-09-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-09-25"
    },
    {
      "value": "CVE-2025-10585",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-870",
          "title": "CISA KEV: CVE-2025-10585 \u2014 Google Chromium V8 Type Confusion Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-09-23",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-09-23"
    },
    {
      "value": "CVE-2025-5086",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-876",
          "title": "CISA KEV: CVE-2025-5086 \u2014 Dassault Syst\u00e8mes DELMIA Apriso Deserialization of Untrusted Data Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-09-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-09-11"
    },
    {
      "value": "156.244.33.162",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-876",
          "title": "CISA KEV: CVE-2025-5086 \u2014 Dassault Syst\u00e8mes DELMIA Apriso Deserialization of Untrusted Data Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-09-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-09-11"
    },
    {
      "value": "292ea9dbc5a1d15b769edb5df1602418931122455223081064ad7ea4e8ab6821",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-876",
          "title": "CISA KEV: CVE-2025-5086 \u2014 Dassault Syst\u00e8mes DELMIA Apriso Deserialization of Untrusted Data Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-09-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-09-11"
    },
    {
      "value": "websocket-api2.publicvm.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-878",
          "title": "npm Supply Chain Attack via Open Source maintainer compromise",
          "link": "https://snyk.io/blog/npm-supply-chain-attack-via-open-source-maintainer-compromise/",
          "published": "2025-09-08",
          "sev": "high"
        }
      ],
      "first_seen": "2025-09-08"
    },
    {
      "value": "CVE-2025-38352",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-880",
          "title": "CISA KEV: CVE-2025-38352 \u2014 Linux Kernel Time-of-Check Time-of-Use (TOCTOU) Race Condition Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-09-04",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-09-04"
    },
    {
      "value": "CVE-2025-48543",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-881",
          "title": "CISA KEV: CVE-2025-48543 \u2014 Android Runtime Use-After-Free Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-09-04",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-09-04"
    },
    {
      "value": "CVE-2025-53690",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-882",
          "title": "CISA KEV: CVE-2025-53690 \u2014 Sitecore Multiple Products Deserialization of Untrusted Data Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-09-04",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-09-04"
    },
    {
      "value": "103.235.46.102",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-882",
          "title": "CISA KEV: CVE-2025-53690 \u2014 Sitecore Multiple Products Deserialization of Untrusted Data Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-09-04",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-09-04"
    },
    {
      "value": "130.33.156.194",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-882",
          "title": "CISA KEV: CVE-2025-53690 \u2014 Sitecore Multiple Products Deserialization of Untrusted Data Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-09-04",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-09-04"
    },
    {
      "value": "117305c6c8222162d7246f842c4bb014",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-882",
          "title": "CISA KEV: CVE-2025-53690 \u2014 Sitecore Multiple Products Deserialization of Untrusted Data Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-09-04",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-09-04"
    },
    {
      "value": "62483e732553c8ba051b792949f3c6d0",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-882",
          "title": "CISA KEV: CVE-2025-53690 \u2014 Sitecore Multiple Products Deserialization of Untrusted Data Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-09-04",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-09-04"
    },
    {
      "value": "63d22ae0568b760b5e3aabb915313e44",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-882",
          "title": "CISA KEV: CVE-2025-53690 \u2014 Sitecore Multiple Products Deserialization of Untrusted Data Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-09-04",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-09-04"
    },
    {
      "value": "a39696e95a34a017be1435db7ff139d5",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-882",
          "title": "CISA KEV: CVE-2025-53690 \u2014 Sitecore Multiple Products Deserialization of Untrusted Data Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-09-04",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-09-04"
    },
    {
      "value": "be7e2c6a9a4654b51a16f8b10a2be175",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-882",
          "title": "CISA KEV: CVE-2025-53690 \u2014 Sitecore Multiple Products Deserialization of Untrusted Data Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-09-04",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-09-04"
    },
    {
      "value": "f410d88429b93786b224e489c960bf5c",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-882",
          "title": "CISA KEV: CVE-2025-53690 \u2014 Sitecore Multiple Products Deserialization of Untrusted Data Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-09-04",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-09-04"
    },
    {
      "value": "223b873c50380fe9a39f1a22b6abf8d46db506e1c08d08312902f6f3cd1f7ac3",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-882",
          "title": "CISA KEV: CVE-2025-53690 \u2014 Sitecore Multiple Products Deserialization of Untrusted Data Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-09-04",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-09-04"
    },
    {
      "value": "61f897ed69646e0509f6802fb2d7c5e88c3e3b93c4ca86942e24d203aa878863",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-882",
          "title": "CISA KEV: CVE-2025-53690 \u2014 Sitecore Multiple Products Deserialization of Untrusted Data Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-09-04",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-09-04"
    },
    {
      "value": "a566cceaf9a66332470a978a234a8a8e2bbdd4d6aa43c2c75c25a80b3b744307",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-882",
          "title": "CISA KEV: CVE-2025-53690 \u2014 Sitecore Multiple Products Deserialization of Untrusted Data Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-09-04",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-09-04"
    },
    {
      "value": "b3f83721f24f7ee5eb19f24747b7668ff96da7dfd9be947e6e24a688ecc0a52b",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-882",
          "title": "CISA KEV: CVE-2025-53690 \u2014 Sitecore Multiple Products Deserialization of Untrusted Data Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-09-04",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-09-04"
    },
    {
      "value": "CVE-2023-50224",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-883",
          "title": "CISA KEV: CVE-2023-50224 \u2014 TP-Link TL-WR841N Authentication Bypass by Spoofing Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-09-03",
          "sev": "crit"
        },
        {
          "id": "art-884",
          "title": "CISA KEV: CVE-2025-9377 \u2014 TP-Link Archer C7(EU) and TL-WR841N/ND(MS) OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-09-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-09-03"
    },
    {
      "value": "CVE-2025-9377",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-883",
          "title": "CISA KEV: CVE-2023-50224 \u2014 TP-Link TL-WR841N Authentication Bypass by Spoofing Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-09-03",
          "sev": "crit"
        },
        {
          "id": "art-884",
          "title": "CISA KEV: CVE-2025-9377 \u2014 TP-Link Archer C7(EU) and TL-WR841N/ND(MS) OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-09-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-09-03"
    },
    {
      "value": "CVE-2020-24363",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-885",
          "title": "CISA KEV: CVE-2020-24363 \u2014 TP-link TL-WA855RE Missing Authentication for Critical Function Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-09-02",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-09-02"
    },
    {
      "value": "CVE-2025-57819",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-887",
          "title": "CISA KEV: CVE-2025-57819 \u2014 Sangoma FreePBX Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-08-29",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-08-29"
    },
    {
      "value": "CVE-2025-7775",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-889",
          "title": "CISA KEV: CVE-2025-7775 \u2014 Citrix NetScaler Memory Overflow Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-08-26",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-08-26"
    },
    {
      "value": "CVE-2025-7776",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-889",
          "title": "CISA KEV: CVE-2025-7775 \u2014 Citrix NetScaler Memory Overflow Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-08-26",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-08-26"
    },
    {
      "value": "CVE-2025-8424",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-889",
          "title": "CISA KEV: CVE-2025-7775 \u2014 Citrix NetScaler Memory Overflow Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-08-26",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-08-26"
    },
    {
      "value": "CVE-2024-8068",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-891",
          "title": "CISA KEV: CVE-2024-8068 \u2014 Citrix Session Recording Improper Privilege Management Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-08-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-08-25"
    },
    {
      "value": "CVE-2024-8069",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-891",
          "title": "CISA KEV: CVE-2024-8068 \u2014 Citrix Session Recording Improper Privilege Management Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-08-25",
          "sev": "crit"
        },
        {
          "id": "art-892",
          "title": "CISA KEV: CVE-2024-8069 \u2014 Citrix Session Recording Deserialization of Untrusted Data Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-08-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-08-25"
    },
    {
      "value": "CVE-2025-48384",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-890",
          "title": "CISA KEV: CVE-2025-48384 \u2014 Git Link Following Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-08-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-08-25"
    },
    {
      "value": "CVE-2025-54948",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-895",
          "title": "CISA KEV: CVE-2025-54948 \u2014 Trend Micro Apex One OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-08-18",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-08-18"
    },
    {
      "value": "CVE-2025-54987",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-895",
          "title": "CISA KEV: CVE-2025-54948 \u2014 Trend Micro Apex One OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-08-18",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-08-18"
    },
    {
      "value": "CVE-2025-8875",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-899",
          "title": "CISA KEV: CVE-2025-8875 \u2014 N-able N-Central Insecure Deserialization Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-08-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-08-13"
    },
    {
      "value": "CVE-2025-8876",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-898",
          "title": "CISA KEV: CVE-2025-8876 \u2014 N-able N-Central Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-08-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-08-13"
    },
    {
      "value": "CVE-2007-0671",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-901",
          "title": "CISA KEV: CVE-2007-0671 \u2014 Microsoft Office Excel Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-08-12",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-08-12"
    },
    {
      "value": "CVE-2013-3893",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-902",
          "title": "CISA KEV: CVE-2013-3893 \u2014 Microsoft Internet Explorer Resource Management Errors Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-08-12",
          "sev": "crit"
        },
        {
          "id": "art-2593",
          "title": "CISA KEV: CVE-2013-3897 \u2014 Microsoft Internet Explorer Use-After-Free Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-08-12"
    },
    {
      "value": "ali.blankchair.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-902",
          "title": "CISA KEV: CVE-2013-3893 \u2014 Microsoft Internet Explorer Resource Management Errors Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-08-12",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-08-12"
    },
    {
      "value": "blankchair.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-902",
          "title": "CISA KEV: CVE-2013-3893 \u2014 Microsoft Internet Explorer Resource Management Errors Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-08-12",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-08-12"
    },
    {
      "value": "dll.freshdns.org",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-902",
          "title": "CISA KEV: CVE-2013-3893 \u2014 Microsoft Internet Explorer Resource Management Errors Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-08-12",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-08-12"
    },
    {
      "value": "downloadmp3server.servemp3.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-902",
          "title": "CISA KEV: CVE-2013-3893 \u2014 Microsoft Internet Explorer Resource Management Errors Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-08-12",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-08-12"
    },
    {
      "value": "ea.blankchair.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-902",
          "title": "CISA KEV: CVE-2013-3893 \u2014 Microsoft Internet Explorer Resource Management Errors Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-08-12",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-08-12"
    },
    {
      "value": "rt.blankchair.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-902",
          "title": "CISA KEV: CVE-2013-3893 \u2014 Microsoft Internet Explorer Resource Management Errors Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-08-12",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-08-12"
    },
    {
      "value": "yahooeast.net",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-902",
          "title": "CISA KEV: CVE-2013-3893 \u2014 Microsoft Internet Explorer Resource Management Errors Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-08-12",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-08-12"
    },
    {
      "value": "103.17.117.90",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-902",
          "title": "CISA KEV: CVE-2013-3893 \u2014 Microsoft Internet Explorer Resource Management Errors Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-08-12",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-08-12"
    },
    {
      "value": "110.45.158.5",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-902",
          "title": "CISA KEV: CVE-2013-3893 \u2014 Microsoft Internet Explorer Resource Management Errors Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-08-12",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-08-12"
    },
    {
      "value": "180.150.228.102",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-902",
          "title": "CISA KEV: CVE-2013-3893 \u2014 Microsoft Internet Explorer Resource Management Errors Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-08-12",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-08-12"
    },
    {
      "value": "192.192.91.6",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-902",
          "title": "CISA KEV: CVE-2013-3893 \u2014 Microsoft Internet Explorer Resource Management Errors Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-08-12",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-08-12"
    },
    {
      "value": "210.176.3.130",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-902",
          "title": "CISA KEV: CVE-2013-3893 \u2014 Microsoft Internet Explorer Resource Management Errors Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-08-12",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-08-12"
    },
    {
      "value": "210.177.74.45",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-902",
          "title": "CISA KEV: CVE-2013-3893 \u2014 Microsoft Internet Explorer Resource Management Errors Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-08-12",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-08-12"
    },
    {
      "value": "211.23.103.221",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-902",
          "title": "CISA KEV: CVE-2013-3893 \u2014 Microsoft Internet Explorer Resource Management Errors Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-08-12",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-08-12"
    },
    {
      "value": "61.63.47.27",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-902",
          "title": "CISA KEV: CVE-2013-3893 \u2014 Microsoft Internet Explorer Resource Management Errors Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-08-12",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-08-12"
    },
    {
      "value": "66.153.86.14",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-902",
          "title": "CISA KEV: CVE-2013-3893 \u2014 Microsoft Internet Explorer Resource Management Errors Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-08-12",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-08-12"
    },
    {
      "value": "1b03e3de1ef3e7135fbf9d5ce7e7ccf6",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-902",
          "title": "CISA KEV: CVE-2013-3893 \u2014 Microsoft Internet Explorer Resource Management Errors Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-08-12",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-08-12"
    },
    {
      "value": "4d257e569539973ab0bbafee8fb87582",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-902",
          "title": "CISA KEV: CVE-2013-3893 \u2014 Microsoft Internet Explorer Resource Management Errors Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-08-12",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-08-12"
    },
    {
      "value": "58dc05118ef8b11dcb5f5c596ab772fd",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-902",
          "title": "CISA KEV: CVE-2013-3893 \u2014 Microsoft Internet Explorer Resource Management Errors Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-08-12",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-08-12"
    },
    {
      "value": "645e29b7c6319295ae8b13ce8575dc1d",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-902",
          "title": "CISA KEV: CVE-2013-3893 \u2014 Microsoft Internet Explorer Resource Management Errors Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-08-12",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-08-12"
    },
    {
      "value": "bf891c72e4c29cfbe533756ea5685314",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-902",
          "title": "CISA KEV: CVE-2013-3893 \u2014 Microsoft Internet Explorer Resource Management Errors Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-08-12",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-08-12"
    },
    {
      "value": "dbdb1032d7bb4757d6011fb1d077856c",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-902",
          "title": "CISA KEV: CVE-2013-3893 \u2014 Microsoft Internet Explorer Resource Management Errors Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-08-12",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-08-12"
    },
    {
      "value": "e9c73997694a897d3c6aadb26ed34797",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-902",
          "title": "CISA KEV: CVE-2013-3893 \u2014 Microsoft Internet Explorer Resource Management Errors Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-08-12",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-08-12"
    },
    {
      "value": "CVE-2018-9995",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-908",
          "title": "CISA KEV: CVE-2020-25078 \u2014 D-Link DCS-2530L and DCS-2670L Devices Unspecified Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-08-05",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-08-05"
    },
    {
      "value": "CVE-2020-25078",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-908",
          "title": "CISA KEV: CVE-2020-25078 \u2014 D-Link DCS-2530L and DCS-2670L Devices Unspecified Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-08-05",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-08-05"
    },
    {
      "value": "CVE-2020-25079",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-909",
          "title": "CISA KEV: CVE-2020-25079 \u2014 D-Link DCS-2530L and DCS-2670L Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-08-05",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-08-05"
    },
    {
      "value": "CVE-2021-33044",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-908",
          "title": "CISA KEV: CVE-2020-25078 \u2014 D-Link DCS-2530L and DCS-2670L Devices Unspecified Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-08-05",
          "sev": "crit"
        },
        {
          "id": "art-1276",
          "title": "CISA KEV: CVE-2021-33044 \u2014 Dahua IP Camera Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-08-21",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-08-05"
    },
    {
      "value": "CVE-2022-40799",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-910",
          "title": "CISA KEV: CVE-2022-40799 \u2014 D-Link DNR-322L Download of Code Without Integrity Check Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-08-05",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-08-05"
    },
    {
      "value": "CVE-2023-2533",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-914",
          "title": "CISA KEV: CVE-2023-2533 \u2014 PaperCut NG/MF Cross-Site Request Forgery (CSRF) Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-07-28",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-07-28"
    },
    {
      "value": "CVE-2025-20281",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-915",
          "title": "CISA KEV: CVE-2025-20337 \u2014 Cisco Identity Services Engine Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-07-28",
          "sev": "crit"
        },
        {
          "id": "art-916",
          "title": "CISA KEV: CVE-2025-20281 \u2014 Cisco Identity Services Engine Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-07-28",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-07-28"
    },
    {
      "value": "CVE-2025-20282",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-915",
          "title": "CISA KEV: CVE-2025-20337 \u2014 Cisco Identity Services Engine Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-07-28",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-07-28"
    },
    {
      "value": "CVE-2025-20337",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-915",
          "title": "CISA KEV: CVE-2025-20337 \u2014 Cisco Identity Services Engine Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-07-28",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-07-28"
    },
    {
      "value": "CVE-2025-5777",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-915",
          "title": "CISA KEV: CVE-2025-20337 \u2014 Cisco Identity Services Engine Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-07-28",
          "sev": "crit"
        },
        {
          "id": "art-928",
          "title": "CISA KEV: CVE-2025-5777 \u2014 Citrix NetScaler ADC and Gateway Out-of-Bounds Read Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-07-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-07-28"
    },
    {
      "value": "CVE-2024-36394",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-918",
          "title": "CISA KEV: CVE-2025-2775 \u2014 SysAid On-Prem Improper Restriction of XML External Entity Reference Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-07-22",
          "sev": "crit"
        },
        {
          "id": "art-919",
          "title": "CISA KEV: CVE-2025-2776 \u2014 SysAid On-Prem Improper Restriction of XML External Entity Reference Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-07-22",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-07-22"
    },
    {
      "value": "CVE-2025-2775",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-918",
          "title": "CISA KEV: CVE-2025-2775 \u2014 SysAid On-Prem Improper Restriction of XML External Entity Reference Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-07-22",
          "sev": "crit"
        },
        {
          "id": "art-919",
          "title": "CISA KEV: CVE-2025-2776 \u2014 SysAid On-Prem Improper Restriction of XML External Entity Reference Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-07-22",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-07-22"
    },
    {
      "value": "CVE-2025-2776",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-918",
          "title": "CISA KEV: CVE-2025-2775 \u2014 SysAid On-Prem Improper Restriction of XML External Entity Reference Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-07-22",
          "sev": "crit"
        },
        {
          "id": "art-919",
          "title": "CISA KEV: CVE-2025-2776 \u2014 SysAid On-Prem Improper Restriction of XML External Entity Reference Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-07-22",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-07-22"
    },
    {
      "value": "CVE-2025-2777",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-918",
          "title": "CISA KEV: CVE-2025-2775 \u2014 SysAid On-Prem Improper Restriction of XML External Entity Reference Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-07-22",
          "sev": "crit"
        },
        {
          "id": "art-919",
          "title": "CISA KEV: CVE-2025-2776 \u2014 SysAid On-Prem Improper Restriction of XML External Entity Reference Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-07-22",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-07-22"
    },
    {
      "value": "CVE-2025-49704",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-922",
          "title": "CISA KEV: CVE-2025-49704 \u2014 Microsoft SharePoint Code Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-07-22",
          "sev": "crit"
        },
        {
          "id": "art-925",
          "title": "CISA KEV: CVE-2025-53770 \u2014 Microsoft SharePoint Deserialization of Untrusted Data Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-07-20",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-07-22"
    },
    {
      "value": "CVE-2025-49706",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-922",
          "title": "CISA KEV: CVE-2025-49704 \u2014 Microsoft SharePoint Code Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-07-22",
          "sev": "crit"
        },
        {
          "id": "art-925",
          "title": "CISA KEV: CVE-2025-53770 \u2014 Microsoft SharePoint Deserialization of Untrusted Data Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-07-20",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-07-22"
    },
    {
      "value": "CVE-2025-53770",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-922",
          "title": "CISA KEV: CVE-2025-49704 \u2014 Microsoft SharePoint Code Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-07-22",
          "sev": "crit"
        },
        {
          "id": "art-925",
          "title": "CISA KEV: CVE-2025-53770 \u2014 Microsoft SharePoint Deserialization of Untrusted Data Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-07-20",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-07-22"
    },
    {
      "value": "CVE-2025-53771",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-922",
          "title": "CISA KEV: CVE-2025-49704 \u2014 Microsoft SharePoint Code Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-07-22",
          "sev": "crit"
        },
        {
          "id": "art-925",
          "title": "CISA KEV: CVE-2025-53770 \u2014 Microsoft SharePoint Deserialization of Untrusted Data Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-07-20",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-07-22"
    },
    {
      "value": "CVE-2025-54309",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-921",
          "title": "CISA KEV: CVE-2025-54309 \u2014  CrushFTP Unprotected Alternate Channel Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-07-22",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-07-22"
    },
    {
      "value": "CVE-2025-6558",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-920",
          "title": "CISA KEV: CVE-2025-6558 \u2014 Google Chromium ANGLE and GPU Improper Input Validation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-07-22",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-07-22"
    },
    {
      "value": "bpp.theinnovationfactory.it",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-922",
          "title": "CISA KEV: CVE-2025-49704 \u2014 Microsoft SharePoint Code Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-07-22",
          "sev": "crit"
        },
        {
          "id": "art-925",
          "title": "CISA KEV: CVE-2025-53770 \u2014 Microsoft SharePoint Deserialization of Untrusted Data Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-07-20",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-07-22"
    },
    {
      "value": "c34718cbb4c6.ngrok-free.app",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-922",
          "title": "CISA KEV: CVE-2025-49704 \u2014 Microsoft SharePoint Code Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-07-22",
          "sev": "crit"
        },
        {
          "id": "art-925",
          "title": "CISA KEV: CVE-2025-53770 \u2014 Microsoft SharePoint Deserialization of Untrusted Data Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-07-20",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-07-22"
    },
    {
      "value": "ice.theinnovationfactory.it",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-922",
          "title": "CISA KEV: CVE-2025-49704 \u2014 Microsoft SharePoint Code Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-07-22",
          "sev": "crit"
        },
        {
          "id": "art-925",
          "title": "CISA KEV: CVE-2025-53770 \u2014 Microsoft SharePoint Deserialization of Untrusted Data Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-07-20",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-07-22"
    },
    {
      "value": "msupdate.updatemicfosoft.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-922",
          "title": "CISA KEV: CVE-2025-49704 \u2014 Microsoft SharePoint Code Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-07-22",
          "sev": "crit"
        },
        {
          "id": "art-925",
          "title": "CISA KEV: CVE-2025-53770 \u2014 Microsoft SharePoint Deserialization of Untrusted Data Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-07-20",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-07-22"
    },
    {
      "value": "npnjs.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-917",
          "title": "Maintainers of ESLint Prettier Plugin Attacked via npm Supply Chain Malware",
          "link": "https://snyk.io/blog/maintainers-of-eslint-prettier-plugin-attacked-via-npm-supply-chain-malware/",
          "published": "2025-07-22",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-07-22"
    },
    {
      "value": "update.updatemicfosoft.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-922",
          "title": "CISA KEV: CVE-2025-49704 \u2014 Microsoft SharePoint Code Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-07-22",
          "sev": "crit"
        },
        {
          "id": "art-925",
          "title": "CISA KEV: CVE-2025-53770 \u2014 Microsoft SharePoint Deserialization of Untrusted Data Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-07-20",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-07-22"
    },
    {
      "value": "104.238.159.149",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-922",
          "title": "CISA KEV: CVE-2025-49704 \u2014 Microsoft SharePoint Code Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-07-22",
          "sev": "crit"
        },
        {
          "id": "art-925",
          "title": "CISA KEV: CVE-2025-53770 \u2014 Microsoft SharePoint Deserialization of Untrusted Data Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-07-20",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-07-22"
    },
    {
      "value": "107.191.58.76",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-922",
          "title": "CISA KEV: CVE-2025-49704 \u2014 Microsoft SharePoint Code Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-07-22",
          "sev": "crit"
        },
        {
          "id": "art-925",
          "title": "CISA KEV: CVE-2025-53770 \u2014 Microsoft SharePoint Deserialization of Untrusted Data Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-07-20",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-07-22"
    },
    {
      "value": "128.199.240.182",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-922",
          "title": "CISA KEV: CVE-2025-49704 \u2014 Microsoft SharePoint Code Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-07-22",
          "sev": "crit"
        },
        {
          "id": "art-925",
          "title": "CISA KEV: CVE-2025-53770 \u2014 Microsoft SharePoint Deserialization of Untrusted Data Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-07-20",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-07-22"
    },
    {
      "value": "131.226.2.6",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-922",
          "title": "CISA KEV: CVE-2025-49704 \u2014 Microsoft SharePoint Code Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-07-22",
          "sev": "crit"
        },
        {
          "id": "art-925",
          "title": "CISA KEV: CVE-2025-53770 \u2014 Microsoft SharePoint Deserialization of Untrusted Data Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-07-20",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-07-22"
    },
    {
      "value": "134.199.202.205",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-922",
          "title": "CISA KEV: CVE-2025-49704 \u2014 Microsoft SharePoint Code Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-07-22",
          "sev": "crit"
        },
        {
          "id": "art-925",
          "title": "CISA KEV: CVE-2025-53770 \u2014 Microsoft SharePoint Deserialization of Untrusted Data Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-07-20",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-07-22"
    },
    {
      "value": "139.144.199.41",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-922",
          "title": "CISA KEV: CVE-2025-49704 \u2014 Microsoft SharePoint Code Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-07-22",
          "sev": "crit"
        },
        {
          "id": "art-925",
          "title": "CISA KEV: CVE-2025-53770 \u2014 Microsoft SharePoint Deserialization of Untrusted Data Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-07-20",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-07-22"
    },
    {
      "value": "145.239.97.206",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-922",
          "title": "CISA KEV: CVE-2025-49704 \u2014 Microsoft SharePoint Code Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-07-22",
          "sev": "crit"
        },
        {
          "id": "art-925",
          "title": "CISA KEV: CVE-2025-53770 \u2014 Microsoft SharePoint Deserialization of Untrusted Data Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-07-20",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-07-22"
    },
    {
      "value": "149.28.124.70",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-922",
          "title": "CISA KEV: CVE-2025-49704 \u2014 Microsoft SharePoint Code Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-07-22",
          "sev": "crit"
        },
        {
          "id": "art-925",
          "title": "CISA KEV: CVE-2025-53770 \u2014 Microsoft SharePoint Deserialization of Untrusted Data Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-07-20",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-07-22"
    },
    {
      "value": "149.40.50.15",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-922",
          "title": "CISA KEV: CVE-2025-49704 \u2014 Microsoft SharePoint Code Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-07-22",
          "sev": "crit"
        },
        {
          "id": "art-925",
          "title": "CISA KEV: CVE-2025-53770 \u2014 Microsoft SharePoint Deserialization of Untrusted Data Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-07-20",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-07-22"
    },
    {
      "value": "154.223.19.106",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-922",
          "title": "CISA KEV: CVE-2025-49704 \u2014 Microsoft SharePoint Code Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-07-22",
          "sev": "crit"
        },
        {
          "id": "art-925",
          "title": "CISA KEV: CVE-2025-53770 \u2014 Microsoft SharePoint Deserialization of Untrusted Data Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-07-20",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-07-22"
    },
    {
      "value": "185.197.248.131",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-922",
          "title": "CISA KEV: CVE-2025-49704 \u2014 Microsoft SharePoint Code Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-07-22",
          "sev": "crit"
        },
        {
          "id": "art-925",
          "title": "CISA KEV: CVE-2025-53770 \u2014 Microsoft SharePoint Deserialization of Untrusted Data Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-07-20",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-07-22"
    },
    {
      "value": "188.130.206.168",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-922",
          "title": "CISA KEV: CVE-2025-49704 \u2014 Microsoft SharePoint Code Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-07-22",
          "sev": "crit"
        },
        {
          "id": "art-925",
          "title": "CISA KEV: CVE-2025-53770 \u2014 Microsoft SharePoint Deserialization of Untrusted Data Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-07-20",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-07-22"
    },
    {
      "value": "206.166.251.228",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-922",
          "title": "CISA KEV: CVE-2025-49704 \u2014 Microsoft SharePoint Code Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-07-22",
          "sev": "crit"
        },
        {
          "id": "art-925",
          "title": "CISA KEV: CVE-2025-53770 \u2014 Microsoft SharePoint Deserialization of Untrusted Data Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-07-20",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-07-22"
    },
    {
      "value": "212.125.27.102",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-922",
          "title": "CISA KEV: CVE-2025-49704 \u2014 Microsoft SharePoint Code Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-07-22",
          "sev": "crit"
        },
        {
          "id": "art-925",
          "title": "CISA KEV: CVE-2025-53770 \u2014 Microsoft SharePoint Deserialization of Untrusted Data Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-07-20",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-07-22"
    },
    {
      "value": "45.77.155.170",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-922",
          "title": "CISA KEV: CVE-2025-49704 \u2014 Microsoft SharePoint Code Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-07-22",
          "sev": "crit"
        },
        {
          "id": "art-925",
          "title": "CISA KEV: CVE-2025-53770 \u2014 Microsoft SharePoint Deserialization of Untrusted Data Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-07-20",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-07-22"
    },
    {
      "value": "45.86.231.241",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-922",
          "title": "CISA KEV: CVE-2025-49704 \u2014 Microsoft SharePoint Code Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-07-22",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-07-22"
    },
    {
      "value": "51.161.152.26",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-922",
          "title": "CISA KEV: CVE-2025-49704 \u2014 Microsoft SharePoint Code Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-07-22",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-07-22"
    },
    {
      "value": "64.176.50.109",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-922",
          "title": "CISA KEV: CVE-2025-49704 \u2014 Microsoft SharePoint Code Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-07-22",
          "sev": "crit"
        },
        {
          "id": "art-925",
          "title": "CISA KEV: CVE-2025-53770 \u2014 Microsoft SharePoint Deserialization of Untrusted Data Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-07-20",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-07-22"
    },
    {
      "value": "65.38.121.198",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-922",
          "title": "CISA KEV: CVE-2025-49704 \u2014 Microsoft SharePoint Code Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-07-22",
          "sev": "crit"
        },
        {
          "id": "art-925",
          "title": "CISA KEV: CVE-2025-53770 \u2014 Microsoft SharePoint Deserialization of Untrusted Data Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-07-20",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-07-22"
    },
    {
      "value": "86.48.9.38",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-922",
          "title": "CISA KEV: CVE-2025-49704 \u2014 Microsoft SharePoint Code Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-07-22",
          "sev": "crit"
        },
        {
          "id": "art-925",
          "title": "CISA KEV: CVE-2025-53770 \u2014 Microsoft SharePoint Deserialization of Untrusted Data Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-07-20",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-07-22"
    },
    {
      "value": "89.46.223.88",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-922",
          "title": "CISA KEV: CVE-2025-49704 \u2014 Microsoft SharePoint Code Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-07-22",
          "sev": "crit"
        },
        {
          "id": "art-925",
          "title": "CISA KEV: CVE-2025-53770 \u2014 Microsoft SharePoint Deserialization of Untrusted Data Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-07-20",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-07-22"
    },
    {
      "value": "91.132.95.60",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-922",
          "title": "CISA KEV: CVE-2025-49704 \u2014 Microsoft SharePoint Code Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-07-22",
          "sev": "crit"
        },
        {
          "id": "art-925",
          "title": "CISA KEV: CVE-2025-53770 \u2014 Microsoft SharePoint Deserialization of Untrusted Data Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-07-20",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-07-22"
    },
    {
      "value": "91.236.230.76",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-922",
          "title": "CISA KEV: CVE-2025-49704 \u2014 Microsoft SharePoint Code Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-07-22",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-07-22"
    },
    {
      "value": "92.222.167.88",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-922",
          "title": "CISA KEV: CVE-2025-49704 \u2014 Microsoft SharePoint Code Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-07-22",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-07-22"
    },
    {
      "value": "95.179.158.42",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-922",
          "title": "CISA KEV: CVE-2025-49704 \u2014 Microsoft SharePoint Code Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-07-22",
          "sev": "crit"
        },
        {
          "id": "art-925",
          "title": "CISA KEV: CVE-2025-53770 \u2014 Microsoft SharePoint Deserialization of Untrusted Data Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-07-20",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-07-22"
    },
    {
      "value": "96.9.125.147",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-922",
          "title": "CISA KEV: CVE-2025-49704 \u2014 Microsoft SharePoint Code Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-07-22",
          "sev": "crit"
        },
        {
          "id": "art-925",
          "title": "CISA KEV: CVE-2025-53770 \u2014 Microsoft SharePoint Deserialization of Untrusted Data Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-07-20",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-07-22"
    },
    {
      "value": "1eb914c09c873f0a7bcf81475ab0f6bdfaccc6b63bf7e5f2dbf19295106af192",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-922",
          "title": "CISA KEV: CVE-2025-49704 \u2014 Microsoft SharePoint Code Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-07-22",
          "sev": "crit"
        },
        {
          "id": "art-925",
          "title": "CISA KEV: CVE-2025-53770 \u2014 Microsoft SharePoint Deserialization of Untrusted Data Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-07-20",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-07-22"
    },
    {
      "value": "24480dbe306597da1ba393b6e30d542673066f98826cc07ac4b9033137f37dbf",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-922",
          "title": "CISA KEV: CVE-2025-49704 \u2014 Microsoft SharePoint Code Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-07-22",
          "sev": "crit"
        },
        {
          "id": "art-925",
          "title": "CISA KEV: CVE-2025-53770 \u2014 Microsoft SharePoint Deserialization of Untrusted Data Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-07-20",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-07-22"
    },
    {
      "value": "33067028e35982c7b9fdcfe25eb4029463542451fdff454007832cf953feaf1e",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-922",
          "title": "CISA KEV: CVE-2025-49704 \u2014 Microsoft SharePoint Code Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-07-22",
          "sev": "crit"
        },
        {
          "id": "art-925",
          "title": "CISA KEV: CVE-2025-53770 \u2014 Microsoft SharePoint Deserialization of Untrusted Data Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-07-20",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-07-22"
    },
    {
      "value": "390665bdd93a656f48c463bb6c11a4d45b7d5444bdd1d1f7a5879b0f6f9aac7e",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-922",
          "title": "CISA KEV: CVE-2025-49704 \u2014 Microsoft SharePoint Code Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-07-22",
          "sev": "crit"
        },
        {
          "id": "art-925",
          "title": "CISA KEV: CVE-2025-53770 \u2014 Microsoft SharePoint Deserialization of Untrusted Data Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-07-20",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-07-22"
    },
    {
      "value": "445a37279d3a229ed18513e85f0c8d861c6f560e0f914a5869df14a74b679b86",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-922",
          "title": "CISA KEV: CVE-2025-49704 \u2014 Microsoft SharePoint Code Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-07-22",
          "sev": "crit"
        },
        {
          "id": "art-925",
          "title": "CISA KEV: CVE-2025-53770 \u2014 Microsoft SharePoint Deserialization of Untrusted Data Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-07-20",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-07-22"
    },
    {
      "value": "4a02a72aedc3356d8cb38f01f0e0b9f26ddc5ccb7c0f04a561337cf24aa84030",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-922",
          "title": "CISA KEV: CVE-2025-49704 \u2014 Microsoft SharePoint Code Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-07-22",
          "sev": "crit"
        },
        {
          "id": "art-925",
          "title": "CISA KEV: CVE-2025-53770 \u2014 Microsoft SharePoint Deserialization of Untrusted Data Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-07-20",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-07-22"
    },
    {
      "value": "4c1750a14915bf2c0b093c2cb59063912dfa039a2adfe6d26d6914804e2ae928",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-922",
          "title": "CISA KEV: CVE-2025-49704 \u2014 Microsoft SharePoint Code Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-07-22",
          "sev": "crit"
        },
        {
          "id": "art-925",
          "title": "CISA KEV: CVE-2025-53770 \u2014 Microsoft SharePoint Deserialization of Untrusted Data Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-07-20",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-07-22"
    },
    {
      "value": "567cb8e8c8bd0d909870c656b292b57bcb24eb55a8582b884e0a228e298e7443",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-922",
          "title": "CISA KEV: CVE-2025-49704 \u2014 Microsoft SharePoint Code Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-07-22",
          "sev": "crit"
        },
        {
          "id": "art-925",
          "title": "CISA KEV: CVE-2025-53770 \u2014 Microsoft SharePoint Deserialization of Untrusted Data Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-07-20",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-07-22"
    },
    {
      "value": "62881359e75c9e8899c4bc9f452ef9743e68ce467f8b3e4398bebacde9550dea",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-922",
          "title": "CISA KEV: CVE-2025-49704 \u2014 Microsoft SharePoint Code Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-07-22",
          "sev": "crit"
        },
        {
          "id": "art-925",
          "title": "CISA KEV: CVE-2025-53770 \u2014 Microsoft SharePoint Deserialization of Untrusted Data Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-07-20",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-07-22"
    },
    {
      "value": "66af332ce5f93ce21d2fe408dffd49d4ae31e364d6802fff97d95ed593ff3082",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-922",
          "title": "CISA KEV: CVE-2025-49704 \u2014 Microsoft SharePoint Code Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-07-22",
          "sev": "crit"
        },
        {
          "id": "art-925",
          "title": "CISA KEV: CVE-2025-53770 \u2014 Microsoft SharePoint Deserialization of Untrusted Data Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-07-20",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-07-22"
    },
    {
      "value": "6753b840cec65dfba0d7d326ec768bff2495784c60db6a139f51c5e83349ac4d",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-922",
          "title": "CISA KEV: CVE-2025-49704 \u2014 Microsoft SharePoint Code Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-07-22",
          "sev": "crit"
        },
        {
          "id": "art-925",
          "title": "CISA KEV: CVE-2025-53770 \u2014 Microsoft SharePoint Deserialization of Untrusted Data Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-07-20",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-07-22"
    },
    {
      "value": "6b273c2179518dacb1218201fd37ee2492a5e1713be907e69bf7ea56ceca53a5",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-922",
          "title": "CISA KEV: CVE-2025-49704 \u2014 Microsoft SharePoint Code Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-07-22",
          "sev": "crit"
        },
        {
          "id": "art-925",
          "title": "CISA KEV: CVE-2025-53770 \u2014 Microsoft SharePoint Deserialization of Untrusted Data Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-07-20",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-07-22"
    },
    {
      "value": "6f6db63ece791c6dc1054f1e1231b5bbcf6c051a49bad0784569271753e24619",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-922",
          "title": "CISA KEV: CVE-2025-49704 \u2014 Microsoft SharePoint Code Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-07-22",
          "sev": "crit"
        },
        {
          "id": "art-925",
          "title": "CISA KEV: CVE-2025-53770 \u2014 Microsoft SharePoint Deserialization of Untrusted Data Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-07-20",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-07-22"
    },
    {
      "value": "7ae971e40528d364fa52f3bb5e0660ac25ef63e082e3bbd54f153e27b31eae68",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-922",
          "title": "CISA KEV: CVE-2025-49704 \u2014 Microsoft SharePoint Code Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-07-22",
          "sev": "crit"
        },
        {
          "id": "art-925",
          "title": "CISA KEV: CVE-2025-53770 \u2014 Microsoft SharePoint Deserialization of Untrusted Data Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-07-20",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-07-22"
    },
    {
      "value": "7baf220eb89f2a216fcb2d0e9aa021b2a10324f0641caf8b7a9088e4e45bec95",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-922",
          "title": "CISA KEV: CVE-2025-49704 \u2014 Microsoft SharePoint Code Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-07-22",
          "sev": "crit"
        },
        {
          "id": "art-925",
          "title": "CISA KEV: CVE-2025-53770 \u2014 Microsoft SharePoint Deserialization of Untrusted Data Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-07-20",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-07-22"
    },
    {
      "value": "83705c75731e1d590b08f9357bc3b0f04741e92a033618736387512b40dab060",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-922",
          "title": "CISA KEV: CVE-2025-49704 \u2014 Microsoft SharePoint Code Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-07-22",
          "sev": "crit"
        },
        {
          "id": "art-925",
          "title": "CISA KEV: CVE-2025-53770 \u2014 Microsoft SharePoint Deserialization of Untrusted Data Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-07-20",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-07-22"
    },
    {
      "value": "92bb4ddb98eeaf11fc15bb32e71d0a63256a0ed826a03ba293ce3a8bf057a514",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-922",
          "title": "CISA KEV: CVE-2025-49704 \u2014 Microsoft SharePoint Code Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-07-22",
          "sev": "crit"
        },
        {
          "id": "art-925",
          "title": "CISA KEV: CVE-2025-53770 \u2014 Microsoft SharePoint Deserialization of Untrusted Data Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-07-20",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-07-22"
    },
    {
      "value": "b180ab0a5845ed619939154f67526d2b04d28713fcc1904fbd666275538f431d",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-922",
          "title": "CISA KEV: CVE-2025-49704 \u2014 Microsoft SharePoint Code Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-07-22",
          "sev": "crit"
        },
        {
          "id": "art-925",
          "title": "CISA KEV: CVE-2025-53770 \u2014 Microsoft SharePoint Deserialization of Untrusted Data Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-07-20",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-07-22"
    },
    {
      "value": "b39c14becb62aeb55df7fd55c814afbb0d659687d947d917512fe67973100b70",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-922",
          "title": "CISA KEV: CVE-2025-49704 \u2014 Microsoft SharePoint Code Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-07-22",
          "sev": "crit"
        },
        {
          "id": "art-925",
          "title": "CISA KEV: CVE-2025-53770 \u2014 Microsoft SharePoint Deserialization of Untrusted Data Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-07-20",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-07-22"
    },
    {
      "value": "b5a78616f709859a0d9f830d28ff2f9dbbb2387df1753739407917e96dadf6b0",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-922",
          "title": "CISA KEV: CVE-2025-49704 \u2014 Microsoft SharePoint Code Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-07-22",
          "sev": "crit"
        },
        {
          "id": "art-925",
          "title": "CISA KEV: CVE-2025-53770 \u2014 Microsoft SharePoint Deserialization of Untrusted Data Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-07-20",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-07-22"
    },
    {
      "value": "c27b725ff66fdfb11dd6487a3815d1d1eba89d61b0e919e4d06ed3ac6a74fe94",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-922",
          "title": "CISA KEV: CVE-2025-49704 \u2014 Microsoft SharePoint Code Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-07-22",
          "sev": "crit"
        },
        {
          "id": "art-925",
          "title": "CISA KEV: CVE-2025-53770 \u2014 Microsoft SharePoint Deserialization of Untrusted Data Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-07-20",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-07-22"
    },
    {
      "value": "c2c1fec7856e8d49f5d49267e69993837575dbbec99cd702c5be134a85b2c139",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-922",
          "title": "CISA KEV: CVE-2025-49704 \u2014 Microsoft SharePoint Code Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-07-22",
          "sev": "crit"
        },
        {
          "id": "art-925",
          "title": "CISA KEV: CVE-2025-53770 \u2014 Microsoft SharePoint Deserialization of Untrusted Data Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-07-20",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-07-22"
    },
    {
      "value": "c68e42f416f482d43653f36cd14384270b54b68d6496a8e34ce887687de5b441",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-917",
          "title": "Maintainers of ESLint Prettier Plugin Attacked via npm Supply Chain Malware",
          "link": "https://snyk.io/blog/maintainers-of-eslint-prettier-plugin-attacked-via-npm-supply-chain-malware/",
          "published": "2025-07-22",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-07-22"
    },
    {
      "value": "d6da885c90a5d1fb88d0a3f0b5d9817a82d5772d5510a0773c80ca581ce2486d",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-922",
          "title": "CISA KEV: CVE-2025-49704 \u2014 Microsoft SharePoint Code Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-07-22",
          "sev": "crit"
        },
        {
          "id": "art-925",
          "title": "CISA KEV: CVE-2025-53770 \u2014 Microsoft SharePoint Deserialization of Untrusted Data Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-07-20",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-07-22"
    },
    {
      "value": "f54ae00a9bae73da001c4d3d690d26ddf5e8e006b5562f936df472ec5e299441",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-922",
          "title": "CISA KEV: CVE-2025-49704 \u2014 Microsoft SharePoint Code Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-07-22",
          "sev": "crit"
        },
        {
          "id": "art-925",
          "title": "CISA KEV: CVE-2025-53770 \u2014 Microsoft SharePoint Deserialization of Untrusted Data Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-07-20",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-07-22"
    },
    {
      "value": "fa3a74a6c015c801f5341c02be2cbdfb301c6ed60633d49fc0bc723617741af7",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-922",
          "title": "CISA KEV: CVE-2025-49704 \u2014 Microsoft SharePoint Code Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-07-22",
          "sev": "crit"
        },
        {
          "id": "art-925",
          "title": "CISA KEV: CVE-2025-53770 \u2014 Microsoft SharePoint Deserialization of Untrusted Data Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-07-20",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-07-22"
    },
    {
      "value": "ffbc9dfc284b147e07a430fe9471e66c716a84a1f18976474a54bee82605fa9a",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-922",
          "title": "CISA KEV: CVE-2025-49704 \u2014 Microsoft SharePoint Code Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-07-22",
          "sev": "crit"
        },
        {
          "id": "art-925",
          "title": "CISA KEV: CVE-2025-53770 \u2014 Microsoft SharePoint Deserialization of Untrusted Data Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-07-20",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-07-22"
    },
    {
      "value": "angelic.su",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-924",
          "title": "Cursor IDE Malware Extension Compromise in $500k Crypto Heist",
          "link": "https://snyk.io/blog/cursor-ide-malware-extension-compromise-in-usd500k-crypto-heist/",
          "published": "2025-07-21",
          "sev": "high"
        }
      ],
      "first_seen": "2025-07-21"
    },
    {
      "value": "begalinokotobananinotrippitroppacrocofanclub.su",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-924",
          "title": "Cursor IDE Malware Extension Compromise in $500k Crypto Heist",
          "link": "https://snyk.io/blog/cursor-ide-malware-extension-compromise-in-usd500k-crypto-heist/",
          "published": "2025-07-21",
          "sev": "high"
        }
      ],
      "first_seen": "2025-07-21"
    },
    {
      "value": "lmfao.su",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-924",
          "title": "Cursor IDE Malware Extension Compromise in $500k Crypto Heist",
          "link": "https://snyk.io/blog/cursor-ide-malware-extension-compromise-in-usd500k-crypto-heist/",
          "published": "2025-07-21",
          "sev": "high"
        }
      ],
      "first_seen": "2025-07-21"
    },
    {
      "value": "m-vn.ws",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-924",
          "title": "Cursor IDE Malware Extension Compromise in $500k Crypto Heist",
          "link": "https://snyk.io/blog/cursor-ide-malware-extension-compromise-in-usd500k-crypto-heist/",
          "published": "2025-07-21",
          "sev": "high"
        }
      ],
      "first_seen": "2025-07-21"
    },
    {
      "value": "myaunet.su",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-924",
          "title": "Cursor IDE Malware Extension Compromise in $500k Crypto Heist",
          "link": "https://snyk.io/blog/cursor-ide-malware-extension-compromise-in-usd500k-crypto-heist/",
          "published": "2025-07-21",
          "sev": "high"
        }
      ],
      "first_seen": "2025-07-21"
    },
    {
      "value": "relay.lmfao.su",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-924",
          "title": "Cursor IDE Malware Extension Compromise in $500k Crypto Heist",
          "link": "https://snyk.io/blog/cursor-ide-malware-extension-compromise-in-usd500k-crypto-heist/",
          "published": "2025-07-21",
          "sev": "high"
        }
      ],
      "first_seen": "2025-07-21"
    },
    {
      "value": "solidity.bot",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-924",
          "title": "Cursor IDE Malware Extension Compromise in $500k Crypto Heist",
          "link": "https://snyk.io/blog/cursor-ide-malware-extension-compromise-in-usd500k-crypto-heist/",
          "published": "2025-07-21",
          "sev": "high"
        }
      ],
      "first_seen": "2025-07-21"
    },
    {
      "value": "staketree.net",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-924",
          "title": "Cursor IDE Malware Extension Compromise in $500k Crypto Heist",
          "link": "https://snyk.io/blog/cursor-ide-malware-extension-compromise-in-usd500k-crypto-heist/",
          "published": "2025-07-21",
          "sev": "high"
        }
      ],
      "first_seen": "2025-07-21"
    },
    {
      "value": "144.172.112.84",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-924",
          "title": "Cursor IDE Malware Extension Compromise in $500k Crypto Heist",
          "link": "https://snyk.io/blog/cursor-ide-malware-extension-compromise-in-usd500k-crypto-heist/",
          "published": "2025-07-21",
          "sev": "high"
        }
      ],
      "first_seen": "2025-07-21"
    },
    {
      "value": "209fb5bb2440ffe1a631dfe3b574229105a33c5153eded023cc77d8e8f81d1de",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-924",
          "title": "Cursor IDE Malware Extension Compromise in $500k Crypto Heist",
          "link": "https://snyk.io/blog/cursor-ide-malware-extension-compromise-in-usd500k-crypto-heist/",
          "published": "2025-07-21",
          "sev": "high"
        }
      ],
      "first_seen": "2025-07-21"
    },
    {
      "value": "2c471e265409763024cdc33579c84d88d5aaf9aea1911266b875d3b7604a0eeb",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-924",
          "title": "Cursor IDE Malware Extension Compromise in $500k Crypto Heist",
          "link": "https://snyk.io/blog/cursor-ide-malware-extension-compromise-in-usd500k-crypto-heist/",
          "published": "2025-07-21",
          "sev": "high"
        }
      ],
      "first_seen": "2025-07-21"
    },
    {
      "value": "404dd413f10ccfeea23bfb00b0e403532fa8651bfb456d84b6a16953355a800a",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-924",
          "title": "Cursor IDE Malware Extension Compromise in $500k Crypto Heist",
          "link": "https://snyk.io/blog/cursor-ide-malware-extension-compromise-in-usd500k-crypto-heist/",
          "published": "2025-07-21",
          "sev": "high"
        }
      ],
      "first_seen": "2025-07-21"
    },
    {
      "value": "70309bf3d2aed946bba51fc3eedb2daa3e8044b60151f0b5c1550831fbc6df17",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-924",
          "title": "Cursor IDE Malware Extension Compromise in $500k Crypto Heist",
          "link": "https://snyk.io/blog/cursor-ide-malware-extension-compromise-in-usd500k-crypto-heist/",
          "published": "2025-07-21",
          "sev": "high"
        }
      ],
      "first_seen": "2025-07-21"
    },
    {
      "value": "84d4a4c6d7e55e201b20327ca2068992180d9ec08a6827faa4ff3534b96c3d6f",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-924",
          "title": "Cursor IDE Malware Extension Compromise in $500k Crypto Heist",
          "link": "https://snyk.io/blog/cursor-ide-malware-extension-compromise-in-usd500k-crypto-heist/",
          "published": "2025-07-21",
          "sev": "high"
        }
      ],
      "first_seen": "2025-07-21"
    },
    {
      "value": "a1eadd41327bd8736e275627d3953944fe7089c032d72a3e429ff18ad0958ada",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-924",
          "title": "Cursor IDE Malware Extension Compromise in $500k Crypto Heist",
          "link": "https://snyk.io/blog/cursor-ide-malware-extension-compromise-in-usd500k-crypto-heist/",
          "published": "2025-07-21",
          "sev": "high"
        }
      ],
      "first_seen": "2025-07-21"
    },
    {
      "value": "c3684164933c3f54d5b0b242a8a906a85d633de479079a820bb804c0f73c0f58",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-924",
          "title": "Cursor IDE Malware Extension Compromise in $500k Crypto Heist",
          "link": "https://snyk.io/blog/cursor-ide-malware-extension-compromise-in-usd500k-crypto-heist/",
          "published": "2025-07-21",
          "sev": "high"
        }
      ],
      "first_seen": "2025-07-21"
    },
    {
      "value": "c5c0228a1e0ba2bb748219325f66acf17078a26165b45728d8e98150377aa068",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-924",
          "title": "Cursor IDE Malware Extension Compromise in $500k Crypto Heist",
          "link": "https://snyk.io/blog/cursor-ide-malware-extension-compromise-in-usd500k-crypto-heist/",
          "published": "2025-07-21",
          "sev": "high"
        }
      ],
      "first_seen": "2025-07-21"
    },
    {
      "value": "ce72b79e324371134db762fe70b8b1789af899d7217461bc3658a6bd84743eb6",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-924",
          "title": "Cursor IDE Malware Extension Compromise in $500k Crypto Heist",
          "link": "https://snyk.io/blog/cursor-ide-malware-extension-compromise-in-usd500k-crypto-heist/",
          "published": "2025-07-21",
          "sev": "high"
        }
      ],
      "first_seen": "2025-07-21"
    },
    {
      "value": "e0ca66c1a9a68b319b24a7c6b8fdca219dffd802dd4de2d59f602c4d90f40d6c",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-924",
          "title": "Cursor IDE Malware Extension Compromise in $500k Crypto Heist",
          "link": "https://snyk.io/blog/cursor-ide-malware-extension-compromise-in-usd500k-crypto-heist/",
          "published": "2025-07-21",
          "sev": "high"
        }
      ],
      "first_seen": "2025-07-21"
    },
    {
      "value": "e19d5d8f941b9a98fbb3b65e1e6077fa00d97529e351e455297b0204ec07e9ed",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-924",
          "title": "Cursor IDE Malware Extension Compromise in $500k Crypto Heist",
          "link": "https://snyk.io/blog/cursor-ide-malware-extension-compromise-in-usd500k-crypto-heist/",
          "published": "2025-07-21",
          "sev": "high"
        }
      ],
      "first_seen": "2025-07-21"
    },
    {
      "value": "eb5b35057dedb235940b2c41da9e3ae0553969f1c89a16e3f66ba6f6005c6fa8",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-924",
          "title": "Cursor IDE Malware Extension Compromise in $500k Crypto Heist",
          "link": "https://snyk.io/blog/cursor-ide-malware-extension-compromise-in-usd500k-crypto-heist/",
          "published": "2025-07-21",
          "sev": "high"
        }
      ],
      "first_seen": "2025-07-21"
    },
    {
      "value": "f4721f32b8d6eb856364327c21ea3c703f1787cfb4c043f87435a8876d903b2c",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-924",
          "title": "Cursor IDE Malware Extension Compromise in $500k Crypto Heist",
          "link": "https://snyk.io/blog/cursor-ide-malware-extension-compromise-in-usd500k-crypto-heist/",
          "published": "2025-07-21",
          "sev": "high"
        }
      ],
      "first_seen": "2025-07-21"
    },
    {
      "value": "141.164.60.10",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-925",
          "title": "CISA KEV: CVE-2025-53770 \u2014 Microsoft SharePoint Deserialization of Untrusted Data Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-07-20",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-07-20"
    },
    {
      "value": "CVE-2025-25257",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-926",
          "title": "CISA KEV: CVE-2025-25257 \u2014 Fortinet FortiWeb SQL Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-07-18",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-07-18"
    },
    {
      "value": "CVE-2025-47812",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-927",
          "title": "CISA KEV: CVE-2025-47812 \u2014 Wing FTP Server Improper Neutralization of Null Byte or NUL Character Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-07-14",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-07-14"
    },
    {
      "value": "instance-y9tbyl-relay.screenconnect.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-927",
          "title": "CISA KEV: CVE-2025-47812 \u2014 Wing FTP Server Improper Neutralization of Null Byte or NUL Character Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-07-14",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-07-14"
    },
    {
      "value": "oooooooo11.screenconnect.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-927",
          "title": "CISA KEV: CVE-2025-47812 \u2014 Wing FTP Server Improper Neutralization of Null Byte or NUL Character Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-07-14",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-07-14"
    },
    {
      "value": "103.88.141.42",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-927",
          "title": "CISA KEV: CVE-2025-47812 \u2014 Wing FTP Server Improper Neutralization of Null Byte or NUL Character Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-07-14",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-07-14"
    },
    {
      "value": "146.70.11.39",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-927",
          "title": "CISA KEV: CVE-2025-47812 \u2014 Wing FTP Server Improper Neutralization of Null Byte or NUL Character Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-07-14",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-07-14"
    },
    {
      "value": "149.248.44.88",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-927",
          "title": "CISA KEV: CVE-2025-47812 \u2014 Wing FTP Server Improper Neutralization of Null Byte or NUL Character Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-07-14",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-07-14"
    },
    {
      "value": "185.196.9.225",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-927",
          "title": "CISA KEV: CVE-2025-47812 \u2014 Wing FTP Server Improper Neutralization of Null Byte or NUL Character Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-07-14",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-07-14"
    },
    {
      "value": "223.160.131.104",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-927",
          "title": "CISA KEV: CVE-2025-47812 \u2014 Wing FTP Server Improper Neutralization of Null Byte or NUL Character Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-07-14",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-07-14"
    },
    {
      "value": "c637ec00bd22da4539ec6def89cd9f7196a303d17632b1131a89d65e4f5698f4",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-927",
          "title": "CISA KEV: CVE-2025-47812 \u2014 Wing FTP Server Improper Neutralization of Null Byte or NUL Character Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-07-14",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-07-14"
    },
    {
      "value": "f0fcc638cd93bdd6fb4745d75b491395a7a1b2cb08e0153a2eb417cb2f58d8ac",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-927",
          "title": "CISA KEV: CVE-2025-47812 \u2014 Wing FTP Server Improper Neutralization of Null Byte or NUL Character Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-07-14",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-07-14"
    },
    {
      "value": "CVE-2014-3931",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-932",
          "title": "CISA KEV: CVE-2014-3931 \u2014 Multi-Router Looking Glass (MRLG) Buffer Overflow Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-07-07",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-07-07"
    },
    {
      "value": "CVE-2016-10033",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-931",
          "title": "CISA KEV: CVE-2016-10033 \u2014 PHPMailer Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-07-07",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-07-07"
    },
    {
      "value": "CVE-2016-10045",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-931",
          "title": "CISA KEV: CVE-2016-10033 \u2014 PHPMailer Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-07-07",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-07-07"
    },
    {
      "value": "CVE-2019-5418",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-930",
          "title": "CISA KEV: CVE-2019-5418 \u2014 Rails Ruby on Rails Path Traversal Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-07-07",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-07-07"
    },
    {
      "value": "CVE-2019-9621",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-929",
          "title": "CISA KEV: CVE-2019-9621 \u2014 Synacor Zimbra Collaboration Suite (ZCS) Server-Side Request Forgery (SSRF) Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-07-07",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-07-07"
    },
    {
      "value": "CVE-2019-9670",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-929",
          "title": "CISA KEV: CVE-2019-9621 \u2014 Synacor Zimbra Collaboration Suite (ZCS) Server-Side Request Forgery (SSRF) Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-07-07",
          "sev": "crit"
        },
        {
          "id": "art-2723",
          "title": "CISA KEV: CVE-2019-9670 \u2014 Synacor Zimbra Collaboration Suite (ZCS) Improper Restriction of XML External Entity Reference",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-01-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-07-07"
    },
    {
      "value": "CVE-2025-6554",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-933",
          "title": "CISA KEV: CVE-2025-6554 \u2014 Google Chromium V8 Type Confusion Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-07-02",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-07-02"
    },
    {
      "value": "CVE-2025-48927",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-935",
          "title": "CISA KEV: CVE-2025-48928 \u2014 TeleMessage TM SGNL Exposure of Core Dump File to an Unauthorized Control Sphere Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-07-01",
          "sev": "crit"
        },
        {
          "id": "art-936",
          "title": "CISA KEV: CVE-2025-48927 \u2014 TeleMessage TM SGNL Initialization of a Resource with an Insecure Default Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-07-01",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-07-01"
    },
    {
      "value": "CVE-2025-48928",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-935",
          "title": "CISA KEV: CVE-2025-48928 \u2014 TeleMessage TM SGNL Exposure of Core Dump File to an Unauthorized Control Sphere Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-07-01",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-07-01"
    },
    {
      "value": "CVE-2025-6543",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-938",
          "title": "CISA KEV: CVE-2025-6543 \u2014 Citrix NetScaler ADC and Gateway Buffer Overflow Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-06-30",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-06-30"
    },
    {
      "value": "CVE-2019-6693",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-940",
          "title": "CISA KEV: CVE-2019-6693 \u2014 Fortinet FortiOS Use of Hard-Coded Credentials Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-06-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-06-25"
    },
    {
      "value": "CVE-2022-26872",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-942",
          "title": "CISA KEV: CVE-2024-54085 \u2014 AMI MegaRAC SPx Authentication Bypass by Spoofing Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-06-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-06-25"
    },
    {
      "value": "CVE-2022-2827",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-942",
          "title": "CISA KEV: CVE-2024-54085 \u2014 AMI MegaRAC SPx Authentication Bypass by Spoofing Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-06-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-06-25"
    },
    {
      "value": "CVE-2022-40242",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-942",
          "title": "CISA KEV: CVE-2024-54085 \u2014 AMI MegaRAC SPx Authentication Bypass by Spoofing Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-06-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-06-25"
    },
    {
      "value": "CVE-2022-40258",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-942",
          "title": "CISA KEV: CVE-2024-54085 \u2014 AMI MegaRAC SPx Authentication Bypass by Spoofing Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-06-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-06-25"
    },
    {
      "value": "CVE-2022-40259",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-942",
          "title": "CISA KEV: CVE-2024-54085 \u2014 AMI MegaRAC SPx Authentication Bypass by Spoofing Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-06-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-06-25"
    },
    {
      "value": "CVE-2023-34329",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-942",
          "title": "CISA KEV: CVE-2024-54085 \u2014 AMI MegaRAC SPx Authentication Bypass by Spoofing Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-06-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-06-25"
    },
    {
      "value": "CVE-2023-34330",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-942",
          "title": "CISA KEV: CVE-2024-54085 \u2014 AMI MegaRAC SPx Authentication Bypass by Spoofing Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-06-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-06-25"
    },
    {
      "value": "CVE-2024-0769",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-941",
          "title": "CISA KEV: CVE-2024-0769 \u2014  D-Link DIR-859 Router Path Traversal Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-06-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-06-25"
    },
    {
      "value": "CVE-2024-54085",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-942",
          "title": "CISA KEV: CVE-2024-54085 \u2014 AMI MegaRAC SPx Authentication Bypass by Spoofing Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-06-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-06-25"
    },
    {
      "value": "CVE-2023-0386",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-947",
          "title": "CISA KEV: CVE-2023-0386 \u2014 Linux Kernel Improper Ownership Management Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-06-17",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-06-17"
    },
    {
      "value": "CVE-2023-33538",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-948",
          "title": "CISA KEV: CVE-2023-33538 \u2014 TP-Link Multiple Routers Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-06-16",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-06-16"
    },
    {
      "value": "CVE-2025-43200",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-949",
          "title": "CISA KEV: CVE-2025-43200 \u2014 Apple Multiple Products Unspecified Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-06-16",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-06-16"
    },
    {
      "value": "bot.ddosvps.cc",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-948",
          "title": "CISA KEV: CVE-2023-33538 \u2014 TP-Link Multiple Routers Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-06-16",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-06-16"
    },
    {
      "value": "cnc.vietdediserver.shop",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-948",
          "title": "CISA KEV: CVE-2023-33538 \u2014 TP-Link Multiple Routers Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-06-16",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-06-16"
    },
    {
      "value": "51.38.137.113",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-948",
          "title": "CISA KEV: CVE-2023-33538 \u2014 TP-Link Multiple Routers Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-06-16",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-06-16"
    },
    {
      "value": "00078aeeaca54b5d3c1237e964e9f956690b782e4ea160d81edc3c6b44e7f620",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-948",
          "title": "CISA KEV: CVE-2023-33538 \u2014 TP-Link Multiple Routers Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-06-16",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-06-16"
    },
    {
      "value": "3fbd2a2e82ceb5e91eadbad02cb45ac618324da9b1895d81ebe7de765dca30e7",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-948",
          "title": "CISA KEV: CVE-2023-33538 \u2014 TP-Link Multiple Routers Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-06-16",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-06-16"
    },
    {
      "value": "4caaa18982cd4056fead54b98d57f9a2a1ddd654cf19a7ba2366dfadbd6033da",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-948",
          "title": "CISA KEV: CVE-2023-33538 \u2014 TP-Link Multiple Routers Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-06-16",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-06-16"
    },
    {
      "value": "534b654531a6a540a144da9545ee343e1046f843d7de4c1091b46c3ee66a508b",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-948",
          "title": "CISA KEV: CVE-2023-33538 \u2014 TP-Link Multiple Routers Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-06-16",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-06-16"
    },
    {
      "value": "56f21f412e898ad9e3ee05d5f44c44d9d7bcb9ecbfbdb9de11b8fa5a637aeef6",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-948",
          "title": "CISA KEV: CVE-2023-33538 \u2014 TP-Link Multiple Routers Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-06-16",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-06-16"
    },
    {
      "value": "7bbb21fec19512d932b7a92652ed0c8f0fedea89f34b9d6f267cf39de0eb9b20",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-948",
          "title": "CISA KEV: CVE-2023-33538 \u2014 TP-Link Multiple Routers Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-06-16",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-06-16"
    },
    {
      "value": "919f292a07a37f163f88527e725406187c8ecc637387ad24853fe49ce4e6ddf4",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-948",
          "title": "CISA KEV: CVE-2023-33538 \u2014 TP-Link Multiple Routers Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-06-16",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-06-16"
    },
    {
      "value": "9df711c3aef2bba17b622ddfd955452f8d8eb55899528fbc13d9540c52f13402",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-948",
          "title": "CISA KEV: CVE-2023-33538 \u2014 TP-Link Multiple Routers Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-06-16",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-06-16"
    },
    {
      "value": "c321933e4e5970ba7299fe21778dab9398994c22ca0ba0422c6cbc3fbb95ea26",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-948",
          "title": "CISA KEV: CVE-2023-33538 \u2014 TP-Link Multiple Routers Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-06-16",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-06-16"
    },
    {
      "value": "CVE-2014-8361",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-955",
          "title": "CISA KEV: CVE-2025-24016 \u2014 Wazuh Server Deserialization of Untrusted Data Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-06-10",
          "sev": "crit"
        },
        {
          "id": "art-1595",
          "title": "CISA KEV: CVE-2014-8361 \u2014 Realtek SDK Improper Input Validation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-09-18",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-06-10"
    },
    {
      "value": "CVE-2017-17215",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-955",
          "title": "CISA KEV: CVE-2025-24016 \u2014 Wazuh Server Deserialization of Untrusted Data Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-06-10",
          "sev": "crit"
        },
        {
          "id": "art-2363",
          "title": "CISA KEV: CVE-2021-45382 \u2014 D-Link Multiple Routers Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-04-04",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-06-10"
    },
    {
      "value": "CVE-2017-18368",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-955",
          "title": "CISA KEV: CVE-2025-24016 \u2014 Wazuh Server Deserialization of Untrusted Data Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-06-10",
          "sev": "crit"
        },
        {
          "id": "art-1640",
          "title": "CISA KEV: CVE-2017-18368 \u2014 Zyxel P660HN-T1A Routers Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-08-07",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-06-10"
    },
    {
      "value": "CVE-2024-3721",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-955",
          "title": "CISA KEV: CVE-2025-24016 \u2014 Wazuh Server Deserialization of Untrusted Data Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-06-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-06-10"
    },
    {
      "value": "CVE-2025-24016",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-955",
          "title": "CISA KEV: CVE-2025-24016 \u2014 Wazuh Server Deserialization of Untrusted Data Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-06-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-06-10"
    },
    {
      "value": "CVE-2025-33053",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-954",
          "title": "CISA KEV: CVE-2025-33053 \u2014  Microsoft Windows External Control of File Name or Path Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-06-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-06-10"
    },
    {
      "value": "cbot.galaxias.cc",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-955",
          "title": "CISA KEV: CVE-2025-24016 \u2014 Wazuh Server Deserialization of Untrusted Data Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-06-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-06-10"
    },
    {
      "value": "cyclingonlineshop.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-954",
          "title": "CISA KEV: CVE-2025-33053 \u2014  Microsoft Windows External Control of File Name or Path Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-06-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-06-10"
    },
    {
      "value": "downloadessays.net",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-954",
          "title": "CISA KEV: CVE-2025-33053 \u2014  Microsoft Windows External Control of File Name or Path Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-06-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-06-10"
    },
    {
      "value": "fastfilebackup.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-954",
          "title": "CISA KEV: CVE-2025-33053 \u2014  Microsoft Windows External Control of File Name or Path Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-06-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-06-10"
    },
    {
      "value": "galaxias.cc",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-955",
          "title": "CISA KEV: CVE-2025-24016 \u2014 Wazuh Server Deserialization of Untrusted Data Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-06-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-06-10"
    },
    {
      "value": "gestisciweb.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-955",
          "title": "CISA KEV: CVE-2025-24016 \u2014 Wazuh Server Deserialization of Untrusted Data Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-06-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-06-10"
    },
    {
      "value": "healthherofit.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-954",
          "title": "CISA KEV: CVE-2025-33053 \u2014  Microsoft Windows External Control of File Name or Path Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-06-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-06-10"
    },
    {
      "value": "joinushealth.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-954",
          "title": "CISA KEV: CVE-2025-33053 \u2014  Microsoft Windows External Control of File Name or Path Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-06-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-06-10"
    },
    {
      "value": "luxuryfitnesslabs.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-954",
          "title": "CISA KEV: CVE-2025-33053 \u2014  Microsoft Windows External Control of File Name or Path Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-06-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-06-10"
    },
    {
      "value": "mystartupblog.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-954",
          "title": "CISA KEV: CVE-2025-33053 \u2014  Microsoft Windows External Control of File Name or Path Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-06-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-06-10"
    },
    {
      "value": "nuklearcnc.duckdns.org",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-955",
          "title": "CISA KEV: CVE-2025-24016 \u2014 Wazuh Server Deserialization of Untrusted Data Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-06-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-06-10"
    },
    {
      "value": "purvoyage.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-954",
          "title": "CISA KEV: CVE-2025-33053 \u2014  Microsoft Windows External Control of File Name or Path Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-06-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-06-10"
    },
    {
      "value": "radiotimesignal.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-954",
          "title": "CISA KEV: CVE-2025-33053 \u2014  Microsoft Windows External Control of File Name or Path Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-06-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-06-10"
    },
    {
      "value": "roundedbullets.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-954",
          "title": "CISA KEV: CVE-2025-33053 \u2014  Microsoft Windows External Control of File Name or Path Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-06-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-06-10"
    },
    {
      "value": "summerartcamp.net",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-954",
          "title": "CISA KEV: CVE-2025-33053 \u2014  Microsoft Windows External Control of File Name or Path Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-06-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-06-10"
    },
    {
      "value": "worryfreetransport.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-954",
          "title": "CISA KEV: CVE-2025-33053 \u2014  Microsoft Windows External Control of File Name or Path Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-06-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-06-10"
    },
    {
      "value": "104.168.101.27",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-955",
          "title": "CISA KEV: CVE-2025-24016 \u2014 Wazuh Server Deserialization of Untrusted Data Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-06-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-06-10"
    },
    {
      "value": "176.65.134.62",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-955",
          "title": "CISA KEV: CVE-2025-24016 \u2014 Wazuh Server Deserialization of Untrusted Data Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-06-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-06-10"
    },
    {
      "value": "176.65.142.137",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-955",
          "title": "CISA KEV: CVE-2025-24016 \u2014 Wazuh Server Deserialization of Untrusted Data Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-06-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-06-10"
    },
    {
      "value": "196.251.86.49",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-955",
          "title": "CISA KEV: CVE-2025-24016 \u2014 Wazuh Server Deserialization of Untrusted Data Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-06-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-06-10"
    },
    {
      "value": "209.141.34.106",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-955",
          "title": "CISA KEV: CVE-2025-24016 \u2014 Wazuh Server Deserialization of Untrusted Data Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-06-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-06-10"
    },
    {
      "value": "42.112.26.36",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-955",
          "title": "CISA KEV: CVE-2025-24016 \u2014 Wazuh Server Deserialization of Untrusted Data Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-06-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-06-10"
    },
    {
      "value": "65.222.202.53",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-955",
          "title": "CISA KEV: CVE-2025-24016 \u2014 Wazuh Server Deserialization of Untrusted Data Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-06-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-06-10"
    },
    {
      "value": "1d95a44f341435da50878eea1ec0a1aab6ae0ee91644c497378266290a6ef1d8",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-954",
          "title": "CISA KEV: CVE-2025-33053 \u2014  Microsoft Windows External Control of File Name or Path Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-06-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-06-10"
    },
    {
      "value": "257c63a9e21b829bb4b9f8b0e352379444b0e573176530107a3e6c279d1919da",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-954",
          "title": "CISA KEV: CVE-2025-33053 \u2014  Microsoft Windows External Control of File Name or Path Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-06-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-06-10"
    },
    {
      "value": "66a893728a0ac1a7fae39ee134ad4182d674e719219fbf5d9b7cd4fd4f07f535",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-954",
          "title": "CISA KEV: CVE-2025-33053 \u2014  Microsoft Windows External Control of File Name or Path Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-06-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-06-10"
    },
    {
      "value": "700b422556f070325b327325e31ddf597f98cc319f29ef8638c7b0508c632cee",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-954",
          "title": "CISA KEV: CVE-2025-33053 \u2014  Microsoft Windows External Control of File Name or Path Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-06-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-06-10"
    },
    {
      "value": "da3bb6e38b3f4d83e69d31783f00c10ce062abd008e81e983a9bd4317a9482aa",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-954",
          "title": "CISA KEV: CVE-2025-33053 \u2014  Microsoft Windows External Control of File Name or Path Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-06-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-06-10"
    },
    {
      "value": "ddce79afe9f67b78e83f6e530c3e03265533eb3f4530e7c89fdc357f7093a80b",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-954",
          "title": "CISA KEV: CVE-2025-33053 \u2014  Microsoft Windows External Control of File Name or Path Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-06-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-06-10"
    },
    {
      "value": "CVE-2025-32433",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-957",
          "title": "CISA KEV: CVE-2025-32433 \u2014 Erlang Erlang/OTP SSH Server Missing Authentication for Critical Function Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-06-09",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-06-09"
    },
    {
      "value": "a.mpk-krakow.pl",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-956",
          "title": "CISA KEV: CVE-2024-42009 \u2014 RoundCube Webmail Cross-Site Scripting Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-06-09",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-06-09"
    },
    {
      "value": "dns.outbound.watchtowr.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-957",
          "title": "CISA KEV: CVE-2025-32433 \u2014 Erlang Erlang/OTP SSH Server Missing Authentication for Critical Function Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-06-09",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-06-09"
    },
    {
      "value": "146.103.40.203",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-957",
          "title": "CISA KEV: CVE-2025-32433 \u2014 Erlang Erlang/OTP SSH Server Missing Authentication for Critical Function Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-06-09",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-06-09"
    },
    {
      "value": "194.165.16.71",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-957",
          "title": "CISA KEV: CVE-2025-32433 \u2014 Erlang Erlang/OTP SSH Server Missing Authentication for Critical Function Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-06-09",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-06-09"
    },
    {
      "value": "70cea07c972a30597cda7a1d3cd4cd8f75acad75940ca311a5a2033e6a1dd149",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-956",
          "title": "CISA KEV: CVE-2024-42009 \u2014 RoundCube Webmail Cross-Site Scripting Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-06-09",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-06-09"
    },
    {
      "value": "CVE-2025-5419",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-960",
          "title": "CISA KEV: CVE-2025-5419 \u2014 Google Chromium V8 Out-of-Bounds Read and Write Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-06-05",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-06-05"
    },
    {
      "value": "CVE-2025-21479",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-963",
          "title": "CISA KEV: CVE-2025-21479 \u2014 Qualcomm Multiple Chipsets Incorrect Authorization Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-06-03",
          "sev": "crit"
        },
        {
          "id": "art-964",
          "title": "CISA KEV: CVE-2025-21480 \u2014 Qualcomm Multiple Chipsets Incorrect Authorization Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-06-03",
          "sev": "crit"
        },
        {
          "id": "art-965",
          "title": "CISA KEV: CVE-2025-27038 \u2014 Qualcomm Multiple Chipsets Use-After-Free Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-06-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-06-03"
    },
    {
      "value": "CVE-2025-21480",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-963",
          "title": "CISA KEV: CVE-2025-21479 \u2014 Qualcomm Multiple Chipsets Incorrect Authorization Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-06-03",
          "sev": "crit"
        },
        {
          "id": "art-964",
          "title": "CISA KEV: CVE-2025-21480 \u2014 Qualcomm Multiple Chipsets Incorrect Authorization Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-06-03",
          "sev": "crit"
        },
        {
          "id": "art-965",
          "title": "CISA KEV: CVE-2025-27038 \u2014 Qualcomm Multiple Chipsets Use-After-Free Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-06-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-06-03"
    },
    {
      "value": "CVE-2025-27038",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-963",
          "title": "CISA KEV: CVE-2025-21479 \u2014 Qualcomm Multiple Chipsets Incorrect Authorization Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-06-03",
          "sev": "crit"
        },
        {
          "id": "art-964",
          "title": "CISA KEV: CVE-2025-21480 \u2014 Qualcomm Multiple Chipsets Incorrect Authorization Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-06-03",
          "sev": "crit"
        },
        {
          "id": "art-965",
          "title": "CISA KEV: CVE-2025-27038 \u2014 Qualcomm Multiple Chipsets Use-After-Free Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-06-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-06-03"
    },
    {
      "value": "CVE-2021-32030",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-967",
          "title": "CISA KEV: CVE-2021-32030 \u2014 ASUS Routers Improper Authentication Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-06-02",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-06-02"
    },
    {
      "value": "CVE-2023-39780",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-967",
          "title": "CISA KEV: CVE-2021-32030 \u2014 ASUS Routers Improper Authentication Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-06-02",
          "sev": "crit"
        },
        {
          "id": "art-971",
          "title": "CISA KEV: CVE-2023-39780 \u2014 ASUS RT-AX55 Routers OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-06-02",
          "sev": "crit"
        },
        {
          "id": "art-1074",
          "title": "CISA KEV: CVE-2023-20118 \u2014 Cisco Small Business RV Series Routers Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-03-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-06-02"
    },
    {
      "value": "CVE-2024-56145",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-970",
          "title": "CISA KEV: CVE-2024-56145 \u2014 Craft CMS Code Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-06-02",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-06-02"
    },
    {
      "value": "CVE-2024-58136",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-969",
          "title": "CISA KEV: CVE-2025-35939 \u2014 Craft CMS External Control of Assumed-Immutable Web Parameter Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-06-02",
          "sev": "crit"
        },
        {
          "id": "art-1003",
          "title": "CISA KEV: CVE-2024-58136 \u2014 Yiiframework Yii Improper Protection of Alternate Path Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-05-02",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-06-02"
    },
    {
      "value": "CVE-2025-35939",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-969",
          "title": "CISA KEV: CVE-2025-35939 \u2014 Craft CMS External Control of Assumed-Immutable Web Parameter Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-06-02",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-06-02"
    },
    {
      "value": "CVE-2025-3935",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-968",
          "title": "CISA KEV: CVE-2025-3935 \u2014 ConnectWise ScreenConnect Improper Authentication Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-06-02",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-06-02"
    },
    {
      "value": "101.99.91.151",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-967",
          "title": "CISA KEV: CVE-2021-32030 \u2014 ASUS Routers Improper Authentication Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-06-02",
          "sev": "crit"
        },
        {
          "id": "art-971",
          "title": "CISA KEV: CVE-2023-39780 \u2014 ASUS RT-AX55 Routers OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-06-02",
          "sev": "crit"
        },
        {
          "id": "art-1074",
          "title": "CISA KEV: CVE-2023-20118 \u2014 Cisco Small Business RV Series Routers Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-03-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-06-02"
    },
    {
      "value": "101.99.94.173",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-967",
          "title": "CISA KEV: CVE-2021-32030 \u2014 ASUS Routers Improper Authentication Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-06-02",
          "sev": "crit"
        },
        {
          "id": "art-971",
          "title": "CISA KEV: CVE-2023-39780 \u2014 ASUS RT-AX55 Routers OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-06-02",
          "sev": "crit"
        },
        {
          "id": "art-1074",
          "title": "CISA KEV: CVE-2023-20118 \u2014 Cisco Small Business RV Series Routers Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-03-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-06-02"
    },
    {
      "value": "103.106.66.123",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-969",
          "title": "CISA KEV: CVE-2025-35939 \u2014 Craft CMS External Control of Assumed-Immutable Web Parameter Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-06-02",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-06-02"
    },
    {
      "value": "104.161.32.11",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-969",
          "title": "CISA KEV: CVE-2025-35939 \u2014 Craft CMS External Control of Assumed-Immutable Web Parameter Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-06-02",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-06-02"
    },
    {
      "value": "111.90.146.237",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-967",
          "title": "CISA KEV: CVE-2021-32030 \u2014 ASUS Routers Improper Authentication Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-06-02",
          "sev": "crit"
        },
        {
          "id": "art-971",
          "title": "CISA KEV: CVE-2023-39780 \u2014 ASUS RT-AX55 Routers OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-06-02",
          "sev": "crit"
        },
        {
          "id": "art-1074",
          "title": "CISA KEV: CVE-2023-20118 \u2014 Cisco Small Business RV Series Routers Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-03-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-06-02"
    },
    {
      "value": "154.211.22.213",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-969",
          "title": "CISA KEV: CVE-2025-35939 \u2014 Craft CMS External Control of Assumed-Immutable Web Parameter Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-06-02",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-06-02"
    },
    {
      "value": "172.86.113.137",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-969",
          "title": "CISA KEV: CVE-2025-35939 \u2014 Craft CMS External Control of Assumed-Immutable Web Parameter Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-06-02",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-06-02"
    },
    {
      "value": "38.145.208.231",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-969",
          "title": "CISA KEV: CVE-2025-35939 \u2014 Craft CMS External Control of Assumed-Immutable Web Parameter Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-06-02",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-06-02"
    },
    {
      "value": "79.141.163.179",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-967",
          "title": "CISA KEV: CVE-2021-32030 \u2014 ASUS Routers Improper Authentication Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-06-02",
          "sev": "crit"
        },
        {
          "id": "art-971",
          "title": "CISA KEV: CVE-2023-39780 \u2014 ASUS RT-AX55 Routers OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-06-02",
          "sev": "crit"
        },
        {
          "id": "art-1074",
          "title": "CISA KEV: CVE-2023-20118 \u2014 Cisco Small Business RV Series Routers Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-03-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-06-02"
    },
    {
      "value": "d8fddbd85e6af76c91bfa17118dbecc6",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-969",
          "title": "CISA KEV: CVE-2025-35939 \u2014 Craft CMS External Control of Assumed-Immutable Web Parameter Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-06-02",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-06-02"
    },
    {
      "value": "e6c3e12f6712719f69f40fb6f06e2b60facd8e61",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-969",
          "title": "CISA KEV: CVE-2025-35939 \u2014 Craft CMS External Control of Assumed-Immutable Web Parameter Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-06-02",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-06-02"
    },
    {
      "value": "dce988346f98d55b97f7ca7a4c49cef2883b80855a0ecb6371df4063e7ecc40d",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-969",
          "title": "CISA KEV: CVE-2025-35939 \u2014 Craft CMS External Control of Assumed-Immutable Web Parameter Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-06-02",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-06-02"
    },
    {
      "value": "CVE-2025-4632",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-978",
          "title": "CISA KEV: CVE-2025-4632 \u2014 Samsung MagicINFO 9 Server Path Traversal Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-05-22",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-05-22"
    },
    {
      "value": "CVE-2020-12641",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-983",
          "title": "CISA KEV: CVE-2024-11182 \u2014 MDaemon Email Server Cross-Site Scripting (XSS) Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-05-19",
          "sev": "crit"
        },
        {
          "id": "art-1699",
          "title": "CISA KEV: CVE-2020-12641 \u2014 Roundcube Webmail Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-06-22",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-05-19"
    },
    {
      "value": "CVE-2020-35730",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-981",
          "title": "CISA KEV: CVE-2024-27443 \u2014 Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting (XSS) Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-05-19",
          "sev": "crit"
        },
        {
          "id": "art-983",
          "title": "CISA KEV: CVE-2024-11182 \u2014 MDaemon Email Server Cross-Site Scripting (XSS) Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-05-19",
          "sev": "crit"
        },
        {
          "id": "art-1544",
          "title": "CISA KEV: CVE-2023-5631 \u2014 Roundcube Webmail Persistent Cross-Site Scripting (XSS) Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-10-26",
          "sev": "crit"
        },
        {
          "id": "art-1698",
          "title": "CISA KEV: CVE-2020-35730 \u2014 Roundcube Webmail Cross-Site Scripting (XSS) Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-06-22",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-05-19"
    },
    {
      "value": "CVE-2021-44026",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-983",
          "title": "CISA KEV: CVE-2024-11182 \u2014 MDaemon Email Server Cross-Site Scripting (XSS) Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-05-19",
          "sev": "crit"
        },
        {
          "id": "art-1700",
          "title": "CISA KEV: CVE-2021-44026 \u2014 Roundcube Webmail SQL Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-06-22",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-05-19"
    },
    {
      "value": "CVE-2023-38950",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-980",
          "title": "CISA KEV: CVE-2023-38950 \u2014 ZKTeco BioTime Path Traversal Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-05-19",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-05-19"
    },
    {
      "value": "CVE-2023-43770",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-981",
          "title": "CISA KEV: CVE-2024-27443 \u2014 Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting (XSS) Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-05-19",
          "sev": "crit"
        },
        {
          "id": "art-983",
          "title": "CISA KEV: CVE-2024-11182 \u2014 MDaemon Email Server Cross-Site Scripting (XSS) Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-05-19",
          "sev": "crit"
        },
        {
          "id": "art-1431",
          "title": "CISA KEV: CVE-2023-43770 \u2014 Roundcube Webmail Persistent Cross-Site Scripting (XSS) Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-02-12",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-05-19"
    },
    {
      "value": "CVE-2024-11182",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-981",
          "title": "CISA KEV: CVE-2024-27443 \u2014 Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting (XSS) Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-05-19",
          "sev": "crit"
        },
        {
          "id": "art-983",
          "title": "CISA KEV: CVE-2024-11182 \u2014 MDaemon Email Server Cross-Site Scripting (XSS) Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-05-19",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-05-19"
    },
    {
      "value": "CVE-2024-27443",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-981",
          "title": "CISA KEV: CVE-2024-27443 \u2014 Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting (XSS) Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-05-19",
          "sev": "crit"
        },
        {
          "id": "art-983",
          "title": "CISA KEV: CVE-2024-11182 \u2014 MDaemon Email Server Cross-Site Scripting (XSS) Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-05-19",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-05-19"
    },
    {
      "value": "CVE-2025-27920",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-982",
          "title": "CISA KEV: CVE-2025-27920 \u2014 Srimax Output Messenger Directory Traversal Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-05-19",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-05-19"
    },
    {
      "value": "CVE-2025-35036",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-984",
          "title": "CISA KEV: CVE-2025-4428 \u2014 Ivanti Endpoint Manager Mobile (EPMM) Code Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-05-19",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-05-19"
    },
    {
      "value": "CVE-2025-4427",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-984",
          "title": "CISA KEV: CVE-2025-4428 \u2014 Ivanti Endpoint Manager Mobile (EPMM) Code Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-05-19",
          "sev": "crit"
        },
        {
          "id": "art-985",
          "title": "CISA KEV: CVE-2025-4427 \u2014 Ivanti Endpoint Manager Mobile (EPMM) Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-05-19",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-05-19"
    },
    {
      "value": "CVE-2025-4428",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-984",
          "title": "CISA KEV: CVE-2025-4428 \u2014 Ivanti Endpoint Manager Mobile (EPMM) Code Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-05-19",
          "sev": "crit"
        },
        {
          "id": "art-985",
          "title": "CISA KEV: CVE-2025-4427 \u2014 Ivanti Endpoint Manager Mobile (EPMM) Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-05-19",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-05-19"
    },
    {
      "value": "api.wordinfos.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-982",
          "title": "CISA KEV: CVE-2025-27920 \u2014 Srimax Output Messenger Directory Traversal Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-05-19",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-05-19"
    },
    {
      "value": "censysinspect.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-984",
          "title": "CISA KEV: CVE-2025-4428 \u2014 Ivanti Endpoint Manager Mobile (EPMM) Code Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-05-19",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-05-19"
    },
    {
      "value": "craft-dev.greenenaftaligallery.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-984",
          "title": "CISA KEV: CVE-2025-4428 \u2014 Ivanti Endpoint Manager Mobile (EPMM) Code Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-05-19",
          "sev": "crit"
        },
        {
          "id": "art-985",
          "title": "CISA KEV: CVE-2025-4427 \u2014 Ivanti Endpoint Manager Mobile (EPMM) Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-05-19",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-05-19"
    },
    {
      "value": "e-wago.pl",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-984",
          "title": "CISA KEV: CVE-2025-4428 \u2014 Ivanti Endpoint Manager Mobile (EPMM) Code Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-05-19",
          "sev": "crit"
        },
        {
          "id": "art-985",
          "title": "CISA KEV: CVE-2025-4427 \u2014 Ivanti Endpoint Manager Mobile (EPMM) Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-05-19",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-05-19"
    },
    {
      "value": "elektrobohater.pl",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-984",
          "title": "CISA KEV: CVE-2025-4428 \u2014 Ivanti Endpoint Manager Mobile (EPMM) Code Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-05-19",
          "sev": "crit"
        },
        {
          "id": "art-985",
          "title": "CISA KEV: CVE-2025-4427 \u2014 Ivanti Endpoint Manager Mobile (EPMM) Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-05-19",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-05-19"
    },
    {
      "value": "hfuu.de",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-981",
          "title": "CISA KEV: CVE-2024-27443 \u2014 Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting (XSS) Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-05-19",
          "sev": "crit"
        },
        {
          "id": "art-983",
          "title": "CISA KEV: CVE-2024-11182 \u2014 MDaemon Email Server Cross-Site Scripting (XSS) Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-05-19",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-05-19"
    },
    {
      "value": "hijx.xyz",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-981",
          "title": "CISA KEV: CVE-2024-27443 \u2014 Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting (XSS) Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-05-19",
          "sev": "crit"
        },
        {
          "id": "art-983",
          "title": "CISA KEV: CVE-2024-11182 \u2014 MDaemon Email Server Cross-Site Scripting (XSS) Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-05-19",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-05-19"
    },
    {
      "value": "ikses.net",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-981",
          "title": "CISA KEV: CVE-2024-27443 \u2014 Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting (XSS) Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-05-19",
          "sev": "crit"
        },
        {
          "id": "art-983",
          "title": "CISA KEV: CVE-2024-11182 \u2014 MDaemon Email Server Cross-Site Scripting (XSS) Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-05-19",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-05-19"
    },
    {
      "value": "jiaw.shop",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-981",
          "title": "CISA KEV: CVE-2024-27443 \u2014 Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting (XSS) Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-05-19",
          "sev": "crit"
        },
        {
          "id": "art-983",
          "title": "CISA KEV: CVE-2024-11182 \u2014 MDaemon Email Server Cross-Site Scripting (XSS) Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-05-19",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-05-19"
    },
    {
      "value": "lsjb.digital",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-981",
          "title": "CISA KEV: CVE-2024-27443 \u2014 Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting (XSS) Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-05-19",
          "sev": "crit"
        },
        {
          "id": "art-983",
          "title": "CISA KEV: CVE-2024-11182 \u2014 MDaemon Email Server Cross-Site Scripting (XSS) Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-05-19",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-05-19"
    },
    {
      "value": "ns1.cybertunnel.run",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-984",
          "title": "CISA KEV: CVE-2025-4428 \u2014 Ivanti Endpoint Manager Mobile (EPMM) Code Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-05-19",
          "sev": "crit"
        },
        {
          "id": "art-985",
          "title": "CISA KEV: CVE-2025-4427 \u2014 Ivanti Endpoint Manager Mobile (EPMM) Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-05-19",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-05-19"
    },
    {
      "value": "raxia.top",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-981",
          "title": "CISA KEV: CVE-2024-27443 \u2014 Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting (XSS) Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-05-19",
          "sev": "crit"
        },
        {
          "id": "art-983",
          "title": "CISA KEV: CVE-2024-11182 \u2014 MDaemon Email Server Cross-Site Scripting (XSS) Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-05-19",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-05-19"
    },
    {
      "value": "rnl.world",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-981",
          "title": "CISA KEV: CVE-2024-27443 \u2014 Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting (XSS) Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-05-19",
          "sev": "crit"
        },
        {
          "id": "art-983",
          "title": "CISA KEV: CVE-2024-11182 \u2014 MDaemon Email Server Cross-Site Scripting (XSS) Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-05-19",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-05-19"
    },
    {
      "value": "sqj.fr",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-981",
          "title": "CISA KEV: CVE-2024-27443 \u2014 Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting (XSS) Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-05-19",
          "sev": "crit"
        },
        {
          "id": "art-983",
          "title": "CISA KEV: CVE-2024-11182 \u2014 MDaemon Email Server Cross-Site Scripting (XSS) Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-05-19",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-05-19"
    },
    {
      "value": "tgh24.xyz",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-981",
          "title": "CISA KEV: CVE-2024-27443 \u2014 Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting (XSS) Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-05-19",
          "sev": "crit"
        },
        {
          "id": "art-983",
          "title": "CISA KEV: CVE-2024-11182 \u2014 MDaemon Email Server Cross-Site Scripting (XSS) Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-05-19",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-05-19"
    },
    {
      "value": "tuo.world",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-981",
          "title": "CISA KEV: CVE-2024-27443 \u2014 Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting (XSS) Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-05-19",
          "sev": "crit"
        },
        {
          "id": "art-983",
          "title": "CISA KEV: CVE-2024-11182 \u2014 MDaemon Email Server Cross-Site Scripting (XSS) Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-05-19",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-05-19"
    },
    {
      "value": "wagodirect.pl",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-984",
          "title": "CISA KEV: CVE-2025-4428 \u2014 Ivanti Endpoint Manager Mobile (EPMM) Code Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-05-19",
          "sev": "crit"
        },
        {
          "id": "art-985",
          "title": "CISA KEV: CVE-2025-4427 \u2014 Ivanti Endpoint Manager Mobile (EPMM) Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-05-19",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-05-19"
    },
    {
      "value": "100.26.51.59",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-984",
          "title": "CISA KEV: CVE-2025-4428 \u2014 Ivanti Endpoint Manager Mobile (EPMM) Code Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-05-19",
          "sev": "crit"
        },
        {
          "id": "art-985",
          "title": "CISA KEV: CVE-2025-4427 \u2014 Ivanti Endpoint Manager Mobile (EPMM) Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-05-19",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-05-19"
    },
    {
      "value": "103.244.88.125",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-984",
          "title": "CISA KEV: CVE-2025-4428 \u2014 Ivanti Endpoint Manager Mobile (EPMM) Code Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-05-19",
          "sev": "crit"
        },
        {
          "id": "art-985",
          "title": "CISA KEV: CVE-2025-4427 \u2014 Ivanti Endpoint Manager Mobile (EPMM) Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-05-19",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-05-19"
    },
    {
      "value": "111.90.151.167",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-981",
          "title": "CISA KEV: CVE-2024-27443 \u2014 Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting (XSS) Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-05-19",
          "sev": "crit"
        },
        {
          "id": "art-983",
          "title": "CISA KEV: CVE-2024-11182 \u2014 MDaemon Email Server Cross-Site Scripting (XSS) Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-05-19",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-05-19"
    },
    {
      "value": "124.223.202.90",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-984",
          "title": "CISA KEV: CVE-2025-4428 \u2014 Ivanti Endpoint Manager Mobile (EPMM) Code Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-05-19",
          "sev": "crit"
        },
        {
          "id": "art-985",
          "title": "CISA KEV: CVE-2025-4427 \u2014 Ivanti Endpoint Manager Mobile (EPMM) Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-05-19",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-05-19"
    },
    {
      "value": "146.70.125.79",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-981",
          "title": "CISA KEV: CVE-2024-27443 \u2014 Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting (XSS) Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-05-19",
          "sev": "crit"
        },
        {
          "id": "art-983",
          "title": "CISA KEV: CVE-2024-11182 \u2014 MDaemon Email Server Cross-Site Scripting (XSS) Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-05-19",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-05-19"
    },
    {
      "value": "146.70.87.67",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-984",
          "title": "CISA KEV: CVE-2025-4428 \u2014 Ivanti Endpoint Manager Mobile (EPMM) Code Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-05-19",
          "sev": "crit"
        },
        {
          "id": "art-985",
          "title": "CISA KEV: CVE-2025-4427 \u2014 Ivanti Endpoint Manager Mobile (EPMM) Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-05-19",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-05-19"
    },
    {
      "value": "150.241.71.231",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-984",
          "title": "CISA KEV: CVE-2025-4428 \u2014 Ivanti Endpoint Manager Mobile (EPMM) Code Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-05-19",
          "sev": "crit"
        },
        {
          "id": "art-985",
          "title": "CISA KEV: CVE-2025-4427 \u2014 Ivanti Endpoint Manager Mobile (EPMM) Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-05-19",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-05-19"
    },
    {
      "value": "150.241.97.83",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-984",
          "title": "CISA KEV: CVE-2025-4428 \u2014 Ivanti Endpoint Manager Mobile (EPMM) Code Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-05-19",
          "sev": "crit"
        },
        {
          "id": "art-985",
          "title": "CISA KEV: CVE-2025-4427 \u2014 Ivanti Endpoint Manager Mobile (EPMM) Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-05-19",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-05-19"
    },
    {
      "value": "185.193.125.65",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-984",
          "title": "CISA KEV: CVE-2025-4428 \u2014 Ivanti Endpoint Manager Mobile (EPMM) Code Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-05-19",
          "sev": "crit"
        },
        {
          "id": "art-985",
          "title": "CISA KEV: CVE-2025-4427 \u2014 Ivanti Endpoint Manager Mobile (EPMM) Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-05-19",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-05-19"
    },
    {
      "value": "185.195.237.106",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-981",
          "title": "CISA KEV: CVE-2024-27443 \u2014 Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting (XSS) Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-05-19",
          "sev": "crit"
        },
        {
          "id": "art-983",
          "title": "CISA KEV: CVE-2024-11182 \u2014 MDaemon Email Server Cross-Site Scripting (XSS) Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-05-19",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-05-19"
    },
    {
      "value": "185.225.69.223",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-981",
          "title": "CISA KEV: CVE-2024-27443 \u2014 Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting (XSS) Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-05-19",
          "sev": "crit"
        },
        {
          "id": "art-983",
          "title": "CISA KEV: CVE-2024-11182 \u2014 MDaemon Email Server Cross-Site Scripting (XSS) Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-05-19",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-05-19"
    },
    {
      "value": "193.29.104.152",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-981",
          "title": "CISA KEV: CVE-2024-27443 \u2014 Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting (XSS) Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-05-19",
          "sev": "crit"
        },
        {
          "id": "art-983",
          "title": "CISA KEV: CVE-2024-11182 \u2014 MDaemon Email Server Cross-Site Scripting (XSS) Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-05-19",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-05-19"
    },
    {
      "value": "27.25.148.183",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-984",
          "title": "CISA KEV: CVE-2025-4428 \u2014 Ivanti Endpoint Manager Mobile (EPMM) Code Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-05-19",
          "sev": "crit"
        },
        {
          "id": "art-985",
          "title": "CISA KEV: CVE-2025-4427 \u2014 Ivanti Endpoint Manager Mobile (EPMM) Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-05-19",
          "sev": "crit"
        },
        {
          "id": "art-1007",
          "title": "CISA KEV: CVE-2025-31324 \u2014 SAP NetWeaver Unrestricted File Upload Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-04-29",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-05-19"
    },
    {
      "value": "37.219.84.22",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-984",
          "title": "CISA KEV: CVE-2025-4428 \u2014 Ivanti Endpoint Manager Mobile (EPMM) Code Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-05-19",
          "sev": "crit"
        },
        {
          "id": "art-985",
          "title": "CISA KEV: CVE-2025-4427 \u2014 Ivanti Endpoint Manager Mobile (EPMM) Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-05-19",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-05-19"
    },
    {
      "value": "45.137.222.24",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-981",
          "title": "CISA KEV: CVE-2024-27443 \u2014 Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting (XSS) Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-05-19",
          "sev": "crit"
        },
        {
          "id": "art-983",
          "title": "CISA KEV: CVE-2024-11182 \u2014 MDaemon Email Server Cross-Site Scripting (XSS) Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-05-19",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-05-19"
    },
    {
      "value": "45.38.17.43",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-984",
          "title": "CISA KEV: CVE-2025-4428 \u2014 Ivanti Endpoint Manager Mobile (EPMM) Code Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-05-19",
          "sev": "crit"
        },
        {
          "id": "art-985",
          "title": "CISA KEV: CVE-2025-4427 \u2014 Ivanti Endpoint Manager Mobile (EPMM) Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-05-19",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-05-19"
    },
    {
      "value": "47.120.74.19",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-984",
          "title": "CISA KEV: CVE-2025-4428 \u2014 Ivanti Endpoint Manager Mobile (EPMM) Code Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-05-19",
          "sev": "crit"
        },
        {
          "id": "art-985",
          "title": "CISA KEV: CVE-2025-4427 \u2014 Ivanti Endpoint Manager Mobile (EPMM) Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-05-19",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-05-19"
    },
    {
      "value": "5.181.159.149",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-984",
          "title": "CISA KEV: CVE-2025-4428 \u2014 Ivanti Endpoint Manager Mobile (EPMM) Code Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-05-19",
          "sev": "crit"
        },
        {
          "id": "art-985",
          "title": "CISA KEV: CVE-2025-4427 \u2014 Ivanti Endpoint Manager Mobile (EPMM) Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-05-19",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-05-19"
    },
    {
      "value": "75.170.92.132",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-984",
          "title": "CISA KEV: CVE-2025-4428 \u2014 Ivanti Endpoint Manager Mobile (EPMM) Code Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-05-19",
          "sev": "crit"
        },
        {
          "id": "art-985",
          "title": "CISA KEV: CVE-2025-4427 \u2014 Ivanti Endpoint Manager Mobile (EPMM) Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-05-19",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-05-19"
    },
    {
      "value": "77.221.158.154",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-984",
          "title": "CISA KEV: CVE-2025-4428 \u2014 Ivanti Endpoint Manager Mobile (EPMM) Code Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-05-19",
          "sev": "crit"
        },
        {
          "id": "art-985",
          "title": "CISA KEV: CVE-2025-4427 \u2014 Ivanti Endpoint Manager Mobile (EPMM) Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-05-19",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-05-19"
    },
    {
      "value": "82.132.235.212",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-984",
          "title": "CISA KEV: CVE-2025-4428 \u2014 Ivanti Endpoint Manager Mobile (EPMM) Code Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-05-19",
          "sev": "crit"
        },
        {
          "id": "art-985",
          "title": "CISA KEV: CVE-2025-4427 \u2014 Ivanti Endpoint Manager Mobile (EPMM) Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-05-19",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-05-19"
    },
    {
      "value": "83.229.126.234",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-984",
          "title": "CISA KEV: CVE-2025-4428 \u2014 Ivanti Endpoint Manager Mobile (EPMM) Code Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-05-19",
          "sev": "crit"
        },
        {
          "id": "art-985",
          "title": "CISA KEV: CVE-2025-4427 \u2014 Ivanti Endpoint Manager Mobile (EPMM) Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-05-19",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-05-19"
    },
    {
      "value": "88.194.29.21",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-984",
          "title": "CISA KEV: CVE-2025-4428 \u2014 Ivanti Endpoint Manager Mobile (EPMM) Code Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-05-19",
          "sev": "crit"
        },
        {
          "id": "art-985",
          "title": "CISA KEV: CVE-2025-4427 \u2014 Ivanti Endpoint Manager Mobile (EPMM) Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-05-19",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-05-19"
    },
    {
      "value": "89.44.9.74",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-981",
          "title": "CISA KEV: CVE-2024-27443 \u2014 Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting (XSS) Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-05-19",
          "sev": "crit"
        },
        {
          "id": "art-983",
          "title": "CISA KEV: CVE-2024-11182 \u2014 MDaemon Email Server Cross-Site Scripting (XSS) Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-05-19",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-05-19"
    },
    {
      "value": "91.193.19.109",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-984",
          "title": "CISA KEV: CVE-2025-4428 \u2014 Ivanti Endpoint Manager Mobile (EPMM) Code Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-05-19",
          "sev": "crit"
        },
        {
          "id": "art-985",
          "title": "CISA KEV: CVE-2025-4427 \u2014 Ivanti Endpoint Manager Mobile (EPMM) Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-05-19",
          "sev": "crit"
        },
        {
          "id": "art-1118",
          "title": "CISA KEV: CVE-2024-50603 \u2014 Aviatrix Controllers OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-01-16",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-05-19"
    },
    {
      "value": "91.237.124.153",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-981",
          "title": "CISA KEV: CVE-2024-27443 \u2014 Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting (XSS) Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-05-19",
          "sev": "crit"
        },
        {
          "id": "art-983",
          "title": "CISA KEV: CVE-2024-11182 \u2014 MDaemon Email Server Cross-Site Scripting (XSS) Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-05-19",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-05-19"
    },
    {
      "value": "91.237.124.164",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-981",
          "title": "CISA KEV: CVE-2024-27443 \u2014 Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting (XSS) Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-05-19",
          "sev": "crit"
        },
        {
          "id": "art-983",
          "title": "CISA KEV: CVE-2024-11182 \u2014 MDaemon Email Server Cross-Site Scripting (XSS) Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-05-19",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-05-19"
    },
    {
      "value": "1078C587FE2B246D618AF74D157F941078477579",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-981",
          "title": "CISA KEV: CVE-2024-27443 \u2014 Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting (XSS) Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-05-19",
          "sev": "crit"
        },
        {
          "id": "art-983",
          "title": "CISA KEV: CVE-2024-11182 \u2014 MDaemon Email Server Cross-Site Scripting (XSS) Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-05-19",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-05-19"
    },
    {
      "value": "19b4df629f5b15e5ff742c70d2c7dc4dac29a7ce",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-984",
          "title": "CISA KEV: CVE-2025-4428 \u2014 Ivanti Endpoint Manager Mobile (EPMM) Code Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-05-19",
          "sev": "crit"
        },
        {
          "id": "art-985",
          "title": "CISA KEV: CVE-2025-4427 \u2014 Ivanti Endpoint Manager Mobile (EPMM) Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-05-19",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-05-19"
    },
    {
      "value": "1b1dda5e8e26da568559e0577769697c624df30e",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-984",
          "title": "CISA KEV: CVE-2025-4428 \u2014 Ivanti Endpoint Manager Mobile (EPMM) Code Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-05-19",
          "sev": "crit"
        },
        {
          "id": "art-985",
          "title": "CISA KEV: CVE-2025-4427 \u2014 Ivanti Endpoint Manager Mobile (EPMM) Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-05-19",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-05-19"
    },
    {
      "value": "2664593E2F5DCFDA9AAA1A2DF7C4CE7EEB1EDBB6",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-981",
          "title": "CISA KEV: CVE-2024-27443 \u2014 Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting (XSS) Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-05-19",
          "sev": "crit"
        },
        {
          "id": "art-983",
          "title": "CISA KEV: CVE-2024-11182 \u2014 MDaemon Email Server Cross-Site Scripting (XSS) Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-05-19",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-05-19"
    },
    {
      "value": "2bd61ce5bdd258c7dcbef53aedb1b018b8e0ae26",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-984",
          "title": "CISA KEV: CVE-2025-4428 \u2014 Ivanti Endpoint Manager Mobile (EPMM) Code Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-05-19",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-05-19"
    },
    {
      "value": "2bd61ce5bdf258c7dcbef53aedb1b018b8e0ae26",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-985",
          "title": "CISA KEV: CVE-2025-4427 \u2014 Ivanti Endpoint Manager Mobile (EPMM) Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-05-19",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-05-19"
    },
    {
      "value": "41FE2EFB38E0C7DD10E6009A68BD26687D6DBF4C",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-981",
          "title": "CISA KEV: CVE-2024-27443 \u2014 Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting (XSS) Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-05-19",
          "sev": "crit"
        },
        {
          "id": "art-983",
          "title": "CISA KEV: CVE-2024-11182 \u2014 MDaemon Email Server Cross-Site Scripting (XSS) Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-05-19",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-05-19"
    },
    {
      "value": "60D592765B0F4E08078D42B2F3DE4F5767F88773",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-981",
          "title": "CISA KEV: CVE-2024-27443 \u2014 Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting (XSS) Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-05-19",
          "sev": "crit"
        },
        {
          "id": "art-983",
          "title": "CISA KEV: CVE-2024-11182 \u2014 MDaemon Email Server Cross-Site Scripting (XSS) Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-05-19",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-05-19"
    },
    {
      "value": "65A8D221B9ECED76B9C17A3E1992DF9B085CECD7",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-981",
          "title": "CISA KEV: CVE-2024-27443 \u2014 Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting (XSS) Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-05-19",
          "sev": "crit"
        },
        {
          "id": "art-983",
          "title": "CISA KEV: CVE-2024-11182 \u2014 MDaemon Email Server Cross-Site Scripting (XSS) Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-05-19",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-05-19"
    },
    {
      "value": "6EF845938F064DE39F4BF6450119A0CDBB61378C",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-981",
          "title": "CISA KEV: CVE-2024-27443 \u2014 Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting (XSS) Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-05-19",
          "sev": "crit"
        },
        {
          "id": "art-983",
          "title": "CISA KEV: CVE-2024-11182 \u2014 MDaemon Email Server Cross-Site Scripting (XSS) Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-05-19",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-05-19"
    },
    {
      "value": "8E6C07F38EF920B5154FD081BA252B9295E8184D",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-981",
          "title": "CISA KEV: CVE-2024-27443 \u2014 Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting (XSS) Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-05-19",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-05-19"
    },
    {
      "value": "8EBBBC9EB54E216EFFB437A28B9F2C7C9DA3A0FA",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-981",
          "title": "CISA KEV: CVE-2024-27443 \u2014 Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting (XSS) Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-05-19",
          "sev": "crit"
        },
        {
          "id": "art-983",
          "title": "CISA KEV: CVE-2024-11182 \u2014 MDaemon Email Server Cross-Site Scripting (XSS) Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-05-19",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-05-19"
    },
    {
      "value": "A5948E1E45D50A8DB063D7DFA5B6F6E249F61652",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-981",
          "title": "CISA KEV: CVE-2024-27443 \u2014 Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting (XSS) Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-05-19",
          "sev": "crit"
        },
        {
          "id": "art-983",
          "title": "CISA KEV: CVE-2024-11182 \u2014 MDaemon Email Server Cross-Site Scripting (XSS) Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-05-19",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-05-19"
    },
    {
      "value": "aa2cfeeca6c8e7743ad1a5996fe5ccc3d52e901d",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-984",
          "title": "CISA KEV: CVE-2025-4428 \u2014 Ivanti Endpoint Manager Mobile (EPMM) Code Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-05-19",
          "sev": "crit"
        },
        {
          "id": "art-985",
          "title": "CISA KEV: CVE-2025-4427 \u2014 Ivanti Endpoint Manager Mobile (EPMM) Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-05-19",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-05-19"
    },
    {
      "value": "ac389c8b7f3d2fcf4fd73891f881b12b8343665b",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-984",
          "title": "CISA KEV: CVE-2025-4428 \u2014 Ivanti Endpoint Manager Mobile (EPMM) Code Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-05-19",
          "sev": "crit"
        },
        {
          "id": "art-985",
          "title": "CISA KEV: CVE-2025-4427 \u2014 Ivanti Endpoint Manager Mobile (EPMM) Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-05-19",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-05-19"
    },
    {
      "value": "AD3C590D1C0963D62702445E8108DB025EEBEC70",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-981",
          "title": "CISA KEV: CVE-2024-27443 \u2014 Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting (XSS) Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-05-19",
          "sev": "crit"
        },
        {
          "id": "art-983",
          "title": "CISA KEV: CVE-2024-11182 \u2014 MDaemon Email Server Cross-Site Scripting (XSS) Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-05-19",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-05-19"
    },
    {
      "value": "B6C340549700470C651031865C2772D3A4C81310",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-981",
          "title": "CISA KEV: CVE-2024-27443 \u2014 Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting (XSS) Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-05-19",
          "sev": "crit"
        },
        {
          "id": "art-983",
          "title": "CISA KEV: CVE-2024-11182 \u2014 MDaemon Email Server Cross-Site Scripting (XSS) Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-05-19",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-05-19"
    },
    {
      "value": "dce8faf5fcf5998b6802995914caa988ee1ebd92",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-984",
          "title": "CISA KEV: CVE-2025-4428 \u2014 Ivanti Endpoint Manager Mobile (EPMM) Code Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-05-19",
          "sev": "crit"
        },
        {
          "id": "art-985",
          "title": "CISA KEV: CVE-2025-4427 \u2014 Ivanti Endpoint Manager Mobile (EPMM) Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-05-19",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-05-19"
    },
    {
      "value": "EBF794E421BE60C9532091EB432C1977517D1BE5",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-983",
          "title": "CISA KEV: CVE-2024-11182 \u2014 MDaemon Email Server Cross-Site Scripting (XSS) Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-05-19",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-05-19"
    },
    {
      "value": "EBF794E421BE60C9532091EB432D1977517D1BE5",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-981",
          "title": "CISA KEV: CVE-2024-27443 \u2014 Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting (XSS) Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-05-19",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-05-19"
    },
    {
      "value": "f780151c151b6cec853a278b4e847ef2af3dbc5d",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-984",
          "title": "CISA KEV: CVE-2025-4428 \u2014 Ivanti Endpoint Manager Mobile (EPMM) Code Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-05-19",
          "sev": "crit"
        },
        {
          "id": "art-985",
          "title": "CISA KEV: CVE-2025-4427 \u2014 Ivanti Endpoint Manager Mobile (EPMM) Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-05-19",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-05-19"
    },
    {
      "value": "F81DE9584F0BF3E55C6CF1B465F00B2671DAA230",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-981",
          "title": "CISA KEV: CVE-2024-27443 \u2014 Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting (XSS) Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-05-19",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-05-19"
    },
    {
      "value": "F95F26F1C097D4CA38304ECC692DBAC7424A5E8D",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-981",
          "title": "CISA KEV: CVE-2024-27443 \u2014 Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting (XSS) Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-05-19",
          "sev": "crit"
        },
        {
          "id": "art-983",
          "title": "CISA KEV: CVE-2024-11182 \u2014 MDaemon Email Server Cross-Site Scripting (XSS) Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-05-19",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-05-19"
    },
    {
      "value": "150ccd3b24a1b40630e46300100a3f810aa7a6badeb6806b59ed6ba7bafb7b21",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-984",
          "title": "CISA KEV: CVE-2025-4428 \u2014 Ivanti Endpoint Manager Mobile (EPMM) Code Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-05-19",
          "sev": "crit"
        },
        {
          "id": "art-985",
          "title": "CISA KEV: CVE-2025-4427 \u2014 Ivanti Endpoint Manager Mobile (EPMM) Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-05-19",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-05-19"
    },
    {
      "value": "1df959e4d2f48c4066fddcb5b3fd00b0b25ae44f350f5f35a86571abb2852e39",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-982",
          "title": "CISA KEV: CVE-2025-27920 \u2014 Srimax Output Messenger Directory Traversal Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-05-19",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-05-19"
    },
    {
      "value": "29ae4fa86329bf6d0955020319b618d4c183d433830187b80979d392bf159768",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-984",
          "title": "CISA KEV: CVE-2025-4428 \u2014 Ivanti Endpoint Manager Mobile (EPMM) Code Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-05-19",
          "sev": "crit"
        },
        {
          "id": "art-985",
          "title": "CISA KEV: CVE-2025-4427 \u2014 Ivanti Endpoint Manager Mobile (EPMM) Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-05-19",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-05-19"
    },
    {
      "value": "2b7b65d6f8815dbe18cabaa20c01be655d8475fc429388a4541eff193596ae63",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-982",
          "title": "CISA KEV: CVE-2025-27920 \u2014 Srimax Output Messenger Directory Traversal Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-05-19",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-05-19"
    },
    {
      "value": "44c4a0d1826369993d1a2c4fcc00a86bf45723342cfd9f3a8b44b673eee6733a",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-984",
          "title": "CISA KEV: CVE-2025-4428 \u2014 Ivanti Endpoint Manager Mobile (EPMM) Code Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-05-19",
          "sev": "crit"
        },
        {
          "id": "art-985",
          "title": "CISA KEV: CVE-2025-4427 \u2014 Ivanti Endpoint Manager Mobile (EPMM) Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-05-19",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-05-19"
    },
    {
      "value": "64764ffe4b1e4fc5b9fe27b513e02f0392f659c4e033d23a4ba7a3b7f20c6d30",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-984",
          "title": "CISA KEV: CVE-2025-4428 \u2014 Ivanti Endpoint Manager Mobile (EPMM) Code Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-05-19",
          "sev": "crit"
        },
        {
          "id": "art-985",
          "title": "CISA KEV: CVE-2025-4427 \u2014 Ivanti Endpoint Manager Mobile (EPMM) Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-05-19",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-05-19"
    },
    {
      "value": "7a4e0eb5fbab9709c8f42beb322a5dfefbc4ec5f914938a8862f8e26a31d30a5",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-984",
          "title": "CISA KEV: CVE-2025-4428 \u2014 Ivanti Endpoint Manager Mobile (EPMM) Code Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-05-19",
          "sev": "crit"
        },
        {
          "id": "art-985",
          "title": "CISA KEV: CVE-2025-4427 \u2014 Ivanti Endpoint Manager Mobile (EPMM) Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-05-19",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-05-19"
    },
    {
      "value": "b422645db18e95aa0b4daaf5277417b73322bed306f42385ecfd6d49be26bfab",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-984",
          "title": "CISA KEV: CVE-2025-4428 \u2014 Ivanti Endpoint Manager Mobile (EPMM) Code Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-05-19",
          "sev": "crit"
        },
        {
          "id": "art-985",
          "title": "CISA KEV: CVE-2025-4427 \u2014 Ivanti Endpoint Manager Mobile (EPMM) Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-05-19",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-05-19"
    },
    {
      "value": "f34db4ea8ec3c2cbe53fde3d73229ccaa2a9e7168cd96d9a49bf89adef5ab47c",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-984",
          "title": "CISA KEV: CVE-2025-4428 \u2014 Ivanti Endpoint Manager Mobile (EPMM) Code Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-05-19",
          "sev": "crit"
        },
        {
          "id": "art-985",
          "title": "CISA KEV: CVE-2025-4427 \u2014 Ivanti Endpoint Manager Mobile (EPMM) Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-05-19",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-05-19"
    },
    {
      "value": "CVE-2024-12987",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-987",
          "title": "CISA KEV: CVE-2024-12987 \u2014 DrayTek Vigor Routers OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-05-15",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-05-15"
    },
    {
      "value": "CVE-2025-42999",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-986",
          "title": "CISA KEV: CVE-2025-42999 \u2014 SAP NetWeaver Deserialization Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-05-15",
          "sev": "crit"
        },
        {
          "id": "art-1007",
          "title": "CISA KEV: CVE-2025-31324 \u2014 SAP NetWeaver Unrestricted File Upload Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-04-29",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-05-15"
    },
    {
      "value": "dvrhelper.anondns.net",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-987",
          "title": "CISA KEV: CVE-2024-12987 \u2014 DrayTek Vigor Routers OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-05-15",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-05-15"
    },
    {
      "value": "miraisucks.anondns.net",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-987",
          "title": "CISA KEV: CVE-2024-12987 \u2014 DrayTek Vigor Routers OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-05-15",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-05-15"
    },
    {
      "value": "rustbot.anondns.net",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-987",
          "title": "CISA KEV: CVE-2024-12987 \u2014 DrayTek Vigor Routers OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-05-15",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-05-15"
    },
    {
      "value": "techsupport.anondns.net",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-987",
          "title": "CISA KEV: CVE-2024-12987 \u2014 DrayTek Vigor Routers OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-05-15",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-05-15"
    },
    {
      "value": "5.255.125.150",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-987",
          "title": "CISA KEV: CVE-2024-12987 \u2014 DrayTek Vigor Routers OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-05-15",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-05-15"
    },
    {
      "value": "66.63.187.69",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-987",
          "title": "CISA KEV: CVE-2024-12987 \u2014 DrayTek Vigor Routers OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-05-15",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-05-15"
    },
    {
      "value": "114b460012412411363c9a3ab0246e48a584ce86fc6c0b7855495ec531dd05a1",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-987",
          "title": "CISA KEV: CVE-2024-12987 \u2014 DrayTek Vigor Routers OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-05-15",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-05-15"
    },
    {
      "value": "15c9d7a63fa419305d7f2710b63f71cc38178973c0ccf6d437ce8b6feeca4ee1",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-987",
          "title": "CISA KEV: CVE-2024-12987 \u2014 DrayTek Vigor Routers OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-05-15",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-05-15"
    },
    {
      "value": "1697fd5230f7f09a7b43fee1a1693013ed98beeb7a182cd3f0393d93dd1b7576",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-987",
          "title": "CISA KEV: CVE-2024-12987 \u2014 DrayTek Vigor Routers OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-05-15",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-05-15"
    },
    {
      "value": "427399864232c6c099f183704b23bff241c7e0de642e9eec66cc56890e8a6304",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-987",
          "title": "CISA KEV: CVE-2024-12987 \u2014 DrayTek Vigor Routers OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-05-15",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-05-15"
    },
    {
      "value": "44a526f20c592fd95b4f7d61974c6f87701e33776b68a5d0b44ccd2fa3f48c5d",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-987",
          "title": "CISA KEV: CVE-2024-12987 \u2014 DrayTek Vigor Routers OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-05-15",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-05-15"
    },
    {
      "value": "4f0ba25183ecb79a0721037a0ff9452fa8c19448f82943deca01b36555f2cc99",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-987",
          "title": "CISA KEV: CVE-2024-12987 \u2014 DrayTek Vigor Routers OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-05-15",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-05-15"
    },
    {
      "value": "5dc90cbb0f69f283ccf52a2a79b3dfe94ee8b3474cf6474cfcbe9f66f245a55d",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-987",
          "title": "CISA KEV: CVE-2024-12987 \u2014 DrayTek Vigor Routers OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-05-15",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-05-15"
    },
    {
      "value": "9a9b5bdeb1f23736ceffba623c8950d627a791a0b40c4d44ae2f80e02a43955d",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-987",
          "title": "CISA KEV: CVE-2024-12987 \u2014 DrayTek Vigor Routers OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-05-15",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-05-15"
    },
    {
      "value": "9e660ce74e1bdb0a75293758200b03efd5f807e7896665addb684e0ffb53afd2",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-987",
          "title": "CISA KEV: CVE-2024-12987 \u2014 DrayTek Vigor Routers OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-05-15",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-05-15"
    },
    {
      "value": "9f098920613bd0390d6485936256a67ae310b633124cfbf503936904e69a81bf",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-987",
          "title": "CISA KEV: CVE-2024-12987 \u2014 DrayTek Vigor Routers OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-05-15",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-05-15"
    },
    {
      "value": "b68e2d852ad157fc01da34e11aa24a5ab30845b706d7827b8119a3e648ce2cf1",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-987",
          "title": "CISA KEV: CVE-2024-12987 \u2014 DrayTek Vigor Routers OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-05-15",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-05-15"
    },
    {
      "value": "b910e77ee686d7d6769fab8cb8f9b17a4609c4e164bb4ed80d9717d9ddad364f",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-987",
          "title": "CISA KEV: CVE-2024-12987 \u2014 DrayTek Vigor Routers OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-05-15",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-05-15"
    },
    {
      "value": "c0abb19b3a72bd2785e8b567e82300423da672a463eefdeda6dd60872ff0e072",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-987",
          "title": "CISA KEV: CVE-2024-12987 \u2014 DrayTek Vigor Routers OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-05-15",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-05-15"
    },
    {
      "value": "dae8dae748be54ba0d5785ab27b1fdf42b7e66c48ab19177d4981bcc032cfb1c",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-987",
          "title": "CISA KEV: CVE-2024-12987 \u2014 DrayTek Vigor Routers OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-05-15",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-05-15"
    },
    {
      "value": "e547306d6dee4b5b2b6ce3e989b9713a5c21ebe3fefa0f5c1a1ea37cec37e20f",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-987",
          "title": "CISA KEV: CVE-2024-12987 \u2014 DrayTek Vigor Routers OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-05-15",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-05-15"
    },
    {
      "value": "ec9e77f1185f644462305184cf8afcf5d12c7eb524a2d3f4090a658a198c20ce",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-987",
          "title": "CISA KEV: CVE-2024-12987 \u2014 DrayTek Vigor Routers OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-05-15",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-05-15"
    },
    {
      "value": "efb0153047b08aa1876e1e4e97a082f6cb05af75479e1e9069b77d98473a11f4",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-987",
          "title": "CISA KEV: CVE-2024-12987 \u2014 DrayTek Vigor Routers OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-05-15",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-05-15"
    },
    {
      "value": "CVE-2025-32756",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-988",
          "title": "CISA KEV: CVE-2025-32756 \u2014 Fortinet Multiple Products Stack-Based Buffer Overflow Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-05-14",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-05-14"
    },
    {
      "value": "156.236.76.90",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-988",
          "title": "CISA KEV: CVE-2025-32756 \u2014 Fortinet Multiple Products Stack-Based Buffer Overflow Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-05-14",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-05-14"
    },
    {
      "value": "198.105.127.124",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-988",
          "title": "CISA KEV: CVE-2025-32756 \u2014 Fortinet Multiple Products Stack-Based Buffer Overflow Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-05-14",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-05-14"
    },
    {
      "value": "218.187.69.244",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-988",
          "title": "CISA KEV: CVE-2025-32756 \u2014 Fortinet Multiple Products Stack-Based Buffer Overflow Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-05-14",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-05-14"
    },
    {
      "value": "218.187.69.59",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-988",
          "title": "CISA KEV: CVE-2025-32756 \u2014 Fortinet Multiple Products Stack-Based Buffer Overflow Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-05-14",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-05-14"
    },
    {
      "value": "43.228.217.173",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-988",
          "title": "CISA KEV: CVE-2025-32756 \u2014 Fortinet Multiple Products Stack-Based Buffer Overflow Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-05-14",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-05-14"
    },
    {
      "value": "43.228.217.82",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-988",
          "title": "CISA KEV: CVE-2025-32756 \u2014 Fortinet Multiple Products Stack-Based Buffer Overflow Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-05-14",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-05-14"
    },
    {
      "value": "2c8834a52faee8d87cff7cd09c4fb946",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-988",
          "title": "CISA KEV: CVE-2025-32756 \u2014 Fortinet Multiple Products Stack-Based Buffer Overflow Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-05-14",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-05-14"
    },
    {
      "value": "364929c45703a84347064e2d5de45bcd",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-988",
          "title": "CISA KEV: CVE-2025-32756 \u2014 Fortinet Multiple Products Stack-Based Buffer Overflow Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-05-14",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-05-14"
    },
    {
      "value": "4410352e110f82eabc0bf160bec41d21",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-988",
          "title": "CISA KEV: CVE-2025-32756 \u2014 Fortinet Multiple Products Stack-Based Buffer Overflow Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-05-14",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-05-14"
    },
    {
      "value": "489821c38f429a21e1ea821f8460e590",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-988",
          "title": "CISA KEV: CVE-2025-32756 \u2014 Fortinet Multiple Products Stack-Based Buffer Overflow Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-05-14",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-05-14"
    },
    {
      "value": "ebce43017d2cb316ea45e08374de7315",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-988",
          "title": "CISA KEV: CVE-2025-32756 \u2014 Fortinet Multiple Products Stack-Based Buffer Overflow Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-05-14",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-05-14"
    },
    {
      "value": "CVE-2025-30397",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-990",
          "title": "CISA KEV: CVE-2025-30397 \u2014 Microsoft Windows Scripting Engine Type Confusion Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-05-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-05-13"
    },
    {
      "value": "CVE-2025-30400",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-993",
          "title": "CISA KEV: CVE-2025-30400 \u2014 Microsoft Windows DWM Core Library Use-After-Free Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-05-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-05-13"
    },
    {
      "value": "CVE-2025-32701",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-992",
          "title": "CISA KEV: CVE-2025-32701 \u2014 Microsoft Windows Common Log File System (CLFS) Driver Use-After-Free Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-05-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-05-13"
    },
    {
      "value": "CVE-2025-32706",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-991",
          "title": "CISA KEV: CVE-2025-32706 \u2014 Microsoft Windows Common Log File System (CLFS) Driver Heap-Based Buffer Overflow Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-05-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-05-13"
    },
    {
      "value": "CVE-2025-32709",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-989",
          "title": "CISA KEV: CVE-2025-32709 \u2014 Microsoft Windows Ancillary Function Driver for WinSock Use-After-Free Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-05-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-05-13"
    },
    {
      "value": "CVE-2025-47729",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-995",
          "title": "CISA KEV: CVE-2025-47729 \u2014 TeleMessage TM SGNL Hidden Functionality Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-05-12",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-05-12"
    },
    {
      "value": "CVE-2018-10561",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-998",
          "title": "CISA KEV: CVE-2024-6047 \u2014 GeoVision Devices OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-05-07",
          "sev": "crit"
        },
        {
          "id": "art-1092",
          "title": "CISA KEV: CVE-2024-41710 \u2014 Mitel SIP Phones Argument Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-02-12",
          "sev": "crit"
        },
        {
          "id": "art-2374",
          "title": "CISA KEV: CVE-2018-10562 \u2014 Dasan GPON Routers Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-31",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-05-07"
    },
    {
      "value": "CVE-2024-11120",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-997",
          "title": "CISA KEV: CVE-2024-11120 \u2014 GeoVision Devices OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-05-07",
          "sev": "crit"
        },
        {
          "id": "art-998",
          "title": "CISA KEV: CVE-2024-6047 \u2014 GeoVision Devices OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-05-07",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-05-07"
    },
    {
      "value": "CVE-2024-6047",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-997",
          "title": "CISA KEV: CVE-2024-11120 \u2014 GeoVision Devices OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-05-07",
          "sev": "crit"
        },
        {
          "id": "art-998",
          "title": "CISA KEV: CVE-2024-6047 \u2014 GeoVision Devices OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-05-07",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-05-07"
    },
    {
      "value": "connect.antiwifi.dev",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-997",
          "title": "CISA KEV: CVE-2024-11120 \u2014 GeoVision Devices OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-05-07",
          "sev": "crit"
        },
        {
          "id": "art-998",
          "title": "CISA KEV: CVE-2024-6047 \u2014 GeoVision Devices OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-05-07",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-05-07"
    },
    {
      "value": "176.65.144.232",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-997",
          "title": "CISA KEV: CVE-2024-11120 \u2014 GeoVision Devices OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-05-07",
          "sev": "crit"
        },
        {
          "id": "art-998",
          "title": "CISA KEV: CVE-2024-6047 \u2014 GeoVision Devices OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-05-07",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-05-07"
    },
    {
      "value": "176.65.144.253",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-997",
          "title": "CISA KEV: CVE-2024-11120 \u2014 GeoVision Devices OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-05-07",
          "sev": "crit"
        },
        {
          "id": "art-998",
          "title": "CISA KEV: CVE-2024-6047 \u2014 GeoVision Devices OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-05-07",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-05-07"
    },
    {
      "value": "198.23.212.246",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-997",
          "title": "CISA KEV: CVE-2024-11120 \u2014 GeoVision Devices OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-05-07",
          "sev": "crit"
        },
        {
          "id": "art-998",
          "title": "CISA KEV: CVE-2024-6047 \u2014 GeoVision Devices OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-05-07",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-05-07"
    },
    {
      "value": "209.141.44.28",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-997",
          "title": "CISA KEV: CVE-2024-11120 \u2014 GeoVision Devices OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-05-07",
          "sev": "crit"
        },
        {
          "id": "art-998",
          "title": "CISA KEV: CVE-2024-6047 \u2014 GeoVision Devices OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-05-07",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-05-07"
    },
    {
      "value": "51.38.137.114",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-997",
          "title": "CISA KEV: CVE-2024-11120 \u2014 GeoVision Devices OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-05-07",
          "sev": "crit"
        },
        {
          "id": "art-998",
          "title": "CISA KEV: CVE-2024-6047 \u2014 GeoVision Devices OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-05-07",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-05-07"
    },
    {
      "value": "11c0447f524d0fcb3be2cd0fbd23eb2cc2045f374b70c9c029708a9f2f4a4114",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-997",
          "title": "CISA KEV: CVE-2024-11120 \u2014 GeoVision Devices OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-05-07",
          "sev": "crit"
        },
        {
          "id": "art-998",
          "title": "CISA KEV: CVE-2024-6047 \u2014 GeoVision Devices OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-05-07",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-05-07"
    },
    {
      "value": "8df660bd1722a09c45fb213e591d1dab73f24d240c456865fe0e2dc85573d85e",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-998",
          "title": "CISA KEV: CVE-2024-6047 \u2014 GeoVision Devices OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-05-07",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-05-07"
    },
    {
      "value": "f05247a2322e212513ee08b2e8513f4c764bde7b30831736dfc927097baf6714",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-997",
          "title": "CISA KEV: CVE-2024-11120 \u2014 GeoVision Devices OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-05-07",
          "sev": "crit"
        },
        {
          "id": "art-998",
          "title": "CISA KEV: CVE-2024-6047 \u2014 GeoVision Devices OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-05-07",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-05-07"
    },
    {
      "value": "CVE-2025-27363",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-999",
          "title": "CISA KEV: CVE-2025-27363 \u2014 FreeType Out-of-Bounds Write Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-05-06",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-05-06"
    },
    {
      "value": "CVE-2025-3248",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1001",
          "title": "CISA KEV: CVE-2025-3248 \u2014 Langflow Missing Authentication Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-05-05",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-05-05"
    },
    {
      "value": "80.66.75.121",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1001",
          "title": "CISA KEV: CVE-2025-3248 \u2014 Langflow Missing Authentication Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-05-05",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-05-05"
    },
    {
      "value": "CVE-2024-4990",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1003",
          "title": "CISA KEV: CVE-2024-58136 \u2014 Yiiframework Yii Improper Protection of Alternate Path Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-05-02",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-05-02"
    },
    {
      "value": "CVE-2025-34028",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1002",
          "title": "CISA KEV: CVE-2025-34028 \u2014 Commvault Command Center Path Traversal Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-05-02",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-05-02"
    },
    {
      "value": "CVE-2023-44221",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1005",
          "title": "CISA KEV: CVE-2024-38475 \u2014 Apache HTTP Server Improper Escaping of Output Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-05-01",
          "sev": "crit"
        },
        {
          "id": "art-1006",
          "title": "CISA KEV: CVE-2023-44221 \u2014 SonicWall SMA100 Appliances OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-05-01",
          "sev": "crit"
        },
        {
          "id": "art-1017",
          "title": "CISA KEV: CVE-2021-20035 \u2014 SonicWall SMA100 Appliances OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-04-16",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-05-01"
    },
    {
      "value": "CVE-2024-38475",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1005",
          "title": "CISA KEV: CVE-2024-38475 \u2014 Apache HTTP Server Improper Escaping of Output Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-05-01",
          "sev": "crit"
        },
        {
          "id": "art-1006",
          "title": "CISA KEV: CVE-2023-44221 \u2014 SonicWall SMA100 Appliances OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-05-01",
          "sev": "crit"
        },
        {
          "id": "art-1017",
          "title": "CISA KEV: CVE-2021-20035 \u2014 SonicWall SMA100 Appliances OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-04-16",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-05-01"
    },
    {
      "value": "CVE-2024-40766",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1006",
          "title": "CISA KEV: CVE-2023-44221 \u2014 SonicWall SMA100 Appliances OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-05-01",
          "sev": "crit"
        },
        {
          "id": "art-1255",
          "title": "CISA KEV: CVE-2024-40766 \u2014 SonicWall SonicOS Improper Access Control Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-09-09",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-05-01"
    },
    {
      "value": "CVE-2025-31324",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1007",
          "title": "CISA KEV: CVE-2025-31324 \u2014 SAP NetWeaver Unrestricted File Upload Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-04-29",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-04-29"
    },
    {
      "value": "aaa.ki6zmfw3ps8q14rfbfczfq5qkhq8e12q.oastify.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1007",
          "title": "CISA KEV: CVE-2025-31324 \u2014 SAP NetWeaver Unrestricted File Upload Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-04-29",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-04-29"
    },
    {
      "value": "d-69b.pages.dev",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1007",
          "title": "CISA KEV: CVE-2025-31324 \u2014 SAP NetWeaver Unrestricted File Upload Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-04-29",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-04-29"
    },
    {
      "value": "data.hs285.top",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1007",
          "title": "CISA KEV: CVE-2025-31324 \u2014 SAP NetWeaver Unrestricted File Upload Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-04-29",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-04-29"
    },
    {
      "value": "ocr-freespace.oss-cn-beijing.aliyuncs.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1007",
          "title": "CISA KEV: CVE-2025-31324 \u2014 SAP NetWeaver Unrestricted File Upload Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-04-29",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-04-29"
    },
    {
      "value": "overseas-recognized-athens-oakland.trycloudflare.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1007",
          "title": "CISA KEV: CVE-2025-31324 \u2014 SAP NetWeaver Unrestricted File Upload Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-04-29",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-04-29"
    },
    {
      "value": "sentinelones.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1007",
          "title": "CISA KEV: CVE-2025-31324 \u2014 SAP NetWeaver Unrestricted File Upload Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-04-29",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-04-29"
    },
    {
      "value": "101.99.91.107",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1007",
          "title": "CISA KEV: CVE-2025-31324 \u2014 SAP NetWeaver Unrestricted File Upload Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-04-29",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-04-29"
    },
    {
      "value": "103.207.14.195",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1007",
          "title": "CISA KEV: CVE-2025-31324 \u2014 SAP NetWeaver Unrestricted File Upload Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-04-29",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-04-29"
    },
    {
      "value": "103.30.76.206",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1007",
          "title": "CISA KEV: CVE-2025-31324 \u2014 SAP NetWeaver Unrestricted File Upload Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-04-29",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-04-29"
    },
    {
      "value": "107.173.135.116",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1007",
          "title": "CISA KEV: CVE-2025-31324 \u2014 SAP NetWeaver Unrestricted File Upload Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-04-29",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-04-29"
    },
    {
      "value": "107.175.77.118",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1007",
          "title": "CISA KEV: CVE-2025-31324 \u2014 SAP NetWeaver Unrestricted File Upload Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-04-29",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-04-29"
    },
    {
      "value": "108.171.195.163",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1007",
          "title": "CISA KEV: CVE-2025-31324 \u2014 SAP NetWeaver Unrestricted File Upload Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-04-29",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-04-29"
    },
    {
      "value": "13.232.191.219",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1007",
          "title": "CISA KEV: CVE-2025-31324 \u2014 SAP NetWeaver Unrestricted File Upload Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-04-29",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-04-29"
    },
    {
      "value": "138.197.40.133",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1007",
          "title": "CISA KEV: CVE-2025-31324 \u2014 SAP NetWeaver Unrestricted File Upload Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-04-29",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-04-29"
    },
    {
      "value": "138.68.61.82",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1007",
          "title": "CISA KEV: CVE-2025-31324 \u2014 SAP NetWeaver Unrestricted File Upload Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-04-29",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-04-29"
    },
    {
      "value": "15.188.246.198",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1007",
          "title": "CISA KEV: CVE-2025-31324 \u2014 SAP NetWeaver Unrestricted File Upload Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-04-29",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-04-29"
    },
    {
      "value": "15.204.56.106",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1007",
          "title": "CISA KEV: CVE-2025-31324 \u2014 SAP NetWeaver Unrestricted File Upload Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-04-29",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-04-29"
    },
    {
      "value": "158.247.224.100",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1007",
          "title": "CISA KEV: CVE-2025-31324 \u2014 SAP NetWeaver Unrestricted File Upload Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-04-29",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-04-29"
    },
    {
      "value": "159.65.34.242",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1007",
          "title": "CISA KEV: CVE-2025-31324 \u2014 SAP NetWeaver Unrestricted File Upload Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-04-29",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-04-29"
    },
    {
      "value": "188.166.87.88",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1007",
          "title": "CISA KEV: CVE-2025-31324 \u2014 SAP NetWeaver Unrestricted File Upload Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-04-29",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-04-29"
    },
    {
      "value": "192.243.115.175",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1007",
          "title": "CISA KEV: CVE-2025-31324 \u2014 SAP NetWeaver Unrestricted File Upload Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-04-29",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-04-29"
    },
    {
      "value": "192.3.153.18",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1007",
          "title": "CISA KEV: CVE-2025-31324 \u2014 SAP NetWeaver Unrestricted File Upload Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-04-29",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-04-29"
    },
    {
      "value": "205.169.39.55",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1007",
          "title": "CISA KEV: CVE-2025-31324 \u2014 SAP NetWeaver Unrestricted File Upload Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-04-29",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-04-29"
    },
    {
      "value": "206.188.197.52",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1007",
          "title": "CISA KEV: CVE-2025-31324 \u2014 SAP NetWeaver Unrestricted File Upload Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-04-29",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-04-29"
    },
    {
      "value": "223.184.254.150",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1007",
          "title": "CISA KEV: CVE-2025-31324 \u2014 SAP NetWeaver Unrestricted File Upload Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-04-29",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-04-29"
    },
    {
      "value": "23.95.123.5",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1007",
          "title": "CISA KEV: CVE-2025-31324 \u2014 SAP NetWeaver Unrestricted File Upload Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-04-29",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-04-29"
    },
    {
      "value": "3.125.102.39",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1007",
          "title": "CISA KEV: CVE-2025-31324 \u2014 SAP NetWeaver Unrestricted File Upload Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-04-29",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-04-29"
    },
    {
      "value": "31.192.107.157",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1007",
          "title": "CISA KEV: CVE-2025-31324 \u2014 SAP NetWeaver Unrestricted File Upload Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-04-29",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-04-29"
    },
    {
      "value": "43.247.135.53",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1007",
          "title": "CISA KEV: CVE-2025-31324 \u2014 SAP NetWeaver Unrestricted File Upload Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-04-29",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-04-29"
    },
    {
      "value": "45.155.222.14",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1007",
          "title": "CISA KEV: CVE-2025-31324 \u2014 SAP NetWeaver Unrestricted File Upload Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-04-29",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-04-29"
    },
    {
      "value": "45.76.93.60",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1007",
          "title": "CISA KEV: CVE-2025-31324 \u2014 SAP NetWeaver Unrestricted File Upload Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-04-29",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-04-29"
    },
    {
      "value": "47.97.42.177",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1007",
          "title": "CISA KEV: CVE-2025-31324 \u2014 SAP NetWeaver Unrestricted File Upload Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-04-29",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-04-29"
    },
    {
      "value": "51.79.66.183",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1007",
          "title": "CISA KEV: CVE-2025-31324 \u2014 SAP NetWeaver Unrestricted File Upload Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-04-29",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-04-29"
    },
    {
      "value": "65.49.235.210",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1007",
          "title": "CISA KEV: CVE-2025-31324 \u2014 SAP NetWeaver Unrestricted File Upload Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-04-29",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-04-29"
    },
    {
      "value": "85.106.113.168",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1007",
          "title": "CISA KEV: CVE-2025-31324 \u2014 SAP NetWeaver Unrestricted File Upload Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-04-29",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-04-29"
    },
    {
      "value": "00920e109f16fe61092e70fca68a5219ade6d42b427e895202f628b467a3d22e",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1007",
          "title": "CISA KEV: CVE-2025-31324 \u2014 SAP NetWeaver Unrestricted File Upload Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-04-29",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-04-29"
    },
    {
      "value": "0c2c8280701706e0772cb9be83502096e94ad4d9c21d576db0bc627e1e84b579",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1007",
          "title": "CISA KEV: CVE-2025-31324 \u2014 SAP NetWeaver Unrestricted File Upload Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-04-29",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-04-29"
    },
    {
      "value": "1abf922a8228fd439a72cfddf1ed08ea09b59eaa4ae5eeba1d322d5f3e3c97e8",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1007",
          "title": "CISA KEV: CVE-2025-31324 \u2014 SAP NetWeaver Unrestricted File Upload Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-04-29",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-04-29"
    },
    {
      "value": "2dcbb4138f836bb5d7bc7d8101d3004848c541df6af997246d4b2a252f29d51a",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1007",
          "title": "CISA KEV: CVE-2025-31324 \u2014 SAP NetWeaver Unrestricted File Upload Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-04-29",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-04-29"
    },
    {
      "value": "2e6f348f8296f4e062c397d2f3708ca6fdeab2c71edfd130b2ca4c935e53c0d3",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1007",
          "title": "CISA KEV: CVE-2025-31324 \u2014 SAP NetWeaver Unrestricted File Upload Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-04-29",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-04-29"
    },
    {
      "value": "3f14dc65cc9e35989857dc1ec4bb1179ab05457f2238e917b698edb4c57ae7ce",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1007",
          "title": "CISA KEV: CVE-2025-31324 \u2014 SAP NetWeaver Unrestricted File Upload Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-04-29",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-04-29"
    },
    {
      "value": "3f5fd4b23126cb21d1007b479954af619a16b0963a51f45cc32a8611e8e845b5",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1007",
          "title": "CISA KEV: CVE-2025-31324 \u2014 SAP NetWeaver Unrestricted File Upload Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-04-29",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-04-29"
    },
    {
      "value": "427877aadd89f427e1815007998d9bb88309c548951a92a6e4064df001e327c2",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1007",
          "title": "CISA KEV: CVE-2025-31324 \u2014 SAP NetWeaver Unrestricted File Upload Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-04-29",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-04-29"
    },
    {
      "value": "47ff0ae9220a09bfad2a2fb1e2fa2c8ffe5e9cb0466646e2a940ac2e0cf55d04",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1007",
          "title": "CISA KEV: CVE-2025-31324 \u2014 SAP NetWeaver Unrestricted File Upload Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-04-29",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-04-29"
    },
    {
      "value": "4b17beee8c2d94cf8e40efc100651d70d046f5c14a027cf97d845dc839e423f9",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1007",
          "title": "CISA KEV: CVE-2025-31324 \u2014 SAP NetWeaver Unrestricted File Upload Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-04-29",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-04-29"
    },
    {
      "value": "4c9e60cc73e87da4cadc51523690d67549de4902e880974bfacf7f1a8dc40d7d",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1007",
          "title": "CISA KEV: CVE-2025-31324 \u2014 SAP NetWeaver Unrestricted File Upload Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-04-29",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-04-29"
    },
    {
      "value": "5919f2eab8a826d7ba84e6c413626f5d11ed412d7df0d3ab864f31d3a8db3763",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1007",
          "title": "CISA KEV: CVE-2025-31324 \u2014 SAP NetWeaver Unrestricted File Upload Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-04-29",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-04-29"
    },
    {
      "value": "598b38f44564565e0e76aa604f915ad88a20a8d5b5827151e681c8866b7ea8b0",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1007",
          "title": "CISA KEV: CVE-2025-31324 \u2014 SAP NetWeaver Unrestricted File Upload Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-04-29",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-04-29"
    },
    {
      "value": "5a8ddc779dcf124fe5692d15be44346fb6d742322acb0eb3c6b4e90f581c5f9e",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1007",
          "title": "CISA KEV: CVE-2025-31324 \u2014 SAP NetWeaver Unrestricted File Upload Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-04-29",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-04-29"
    },
    {
      "value": "5e24b41a0bd076ec2b4e49e66daac94396c6180d00a45bcd7f4342a385fa1eed",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1007",
          "title": "CISA KEV: CVE-2025-31324 \u2014 SAP NetWeaver Unrestricted File Upload Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-04-29",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-04-29"
    },
    {
      "value": "5f3d1f17033d85b85f3bd5ae55cb720e53b31f1679d52986c8d635fd1ce0c08a",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1007",
          "title": "CISA KEV: CVE-2025-31324 \u2014 SAP NetWeaver Unrestricted File Upload Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-04-29",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-04-29"
    },
    {
      "value": "63aa0c6890ec5c16b872fb6d070556447cd707dfba185d32a2c10c008dbdbcdd",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1007",
          "title": "CISA KEV: CVE-2025-31324 \u2014 SAP NetWeaver Unrestricted File Upload Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-04-29",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-04-29"
    },
    {
      "value": "69bb809b3fee09ed3ec9138f7566cc867bd6f1e8949b5e3daff21d451c533d75",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1007",
          "title": "CISA KEV: CVE-2025-31324 \u2014 SAP NetWeaver Unrestricted File Upload Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-04-29",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-04-29"
    },
    {
      "value": "6c6c984727dc53af110ed08ec8b15092facb924c8ad62e86ec76b52a00a41a40",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1007",
          "title": "CISA KEV: CVE-2025-31324 \u2014 SAP NetWeaver Unrestricted File Upload Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-04-29",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-04-29"
    },
    {
      "value": "888e953538ff668104f838120bc4d801c41adb07027db16281402a62f6ec29ef",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1007",
          "title": "CISA KEV: CVE-2025-31324 \u2014 SAP NetWeaver Unrestricted File Upload Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-04-29",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-04-29"
    },
    {
      "value": "91f66ba1ad49d3062afdcc80e54da0807207d80a1b539edcdbd6e1bf99e7a2ca",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1007",
          "title": "CISA KEV: CVE-2025-31324 \u2014 SAP NetWeaver Unrestricted File Upload Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-04-29",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-04-29"
    },
    {
      "value": "9fb57a4c6576a98003de6bf441e4306f72c83f783630286758f5b468abaa105d",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1007",
          "title": "CISA KEV: CVE-2025-31324 \u2014 SAP NetWeaver Unrestricted File Upload Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-04-29",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-04-29"
    },
    {
      "value": "a114b52c146bd11558cc7c48c3ee679ca5ca55cf2c9cc33616956a6e6229f110",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1007",
          "title": "CISA KEV: CVE-2025-31324 \u2014 SAP NetWeaver Unrestricted File Upload Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-04-29",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-04-29"
    },
    {
      "value": "b8e56de3792dbd0f4239b54cfaad7ece3bd42affa4fbbdd7668492de548b5df8",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1007",
          "title": "CISA KEV: CVE-2025-31324 \u2014 SAP NetWeaver Unrestricted File Upload Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-04-29",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-04-29"
    },
    {
      "value": "b9533ce8e428f16f3d0e1946f19a6f756ff11a532d0b7e61ae402837f46c678e",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1007",
          "title": "CISA KEV: CVE-2025-31324 \u2014 SAP NetWeaver Unrestricted File Upload Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-04-29",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-04-29"
    },
    {
      "value": "b9ef95ca541d3e05a6285411005f5fee15495251041f78e715234b09d019b92c",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1007",
          "title": "CISA KEV: CVE-2025-31324 \u2014 SAP NetWeaver Unrestricted File Upload Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-04-29",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-04-29"
    },
    {
      "value": "c71da1dfea145798f881afd73b597336d87f18f8fd8f9a7f524c6749a5c664e4",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1007",
          "title": "CISA KEV: CVE-2025-31324 \u2014 SAP NetWeaver Unrestricted File Upload Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-04-29",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-04-29"
    },
    {
      "value": "c7b9ae61046eed01651a72afe7a31de088056f1c1430b368b1acda0b58299e28",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1007",
          "title": "CISA KEV: CVE-2025-31324 \u2014 SAP NetWeaver Unrestricted File Upload Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-04-29",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-04-29"
    },
    {
      "value": "df492597eb412c94155a7f437f593aed89cfec2f1f149eb65174c6201be69049",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1007",
          "title": "CISA KEV: CVE-2025-31324 \u2014 SAP NetWeaver Unrestricted File Upload Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-04-29",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-04-29"
    },
    {
      "value": "f92d0cf4d577c68aa615797d1704f40b14810d98b48834b241dd5c9963e113ec",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1007",
          "title": "CISA KEV: CVE-2025-31324 \u2014 SAP NetWeaver Unrestricted File Upload Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-04-29",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-04-29"
    },
    {
      "value": "CVE-2025-1976",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1009",
          "title": "CISA KEV: CVE-2025-1976 \u2014 Broadcom Brocade Fabric OS Code Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-04-28",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-04-28"
    },
    {
      "value": "CVE-2025-3928",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1011",
          "title": "CISA KEV: CVE-2025-3928 \u2014 Commvault Web Server Unspecified Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-04-28",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-04-28"
    },
    {
      "value": "CVE-2025-42599",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1010",
          "title": "CISA KEV: CVE-2025-42599 \u2014 Qualitia Active! Mail Stack-Based Buffer Overflow Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-04-28",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-04-28"
    },
    {
      "value": "108.6.189.53",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1011",
          "title": "CISA KEV: CVE-2025-3928 \u2014 Commvault Web Server Unspecified Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-04-28",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-04-28"
    },
    {
      "value": "108.69.148.100",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1011",
          "title": "CISA KEV: CVE-2025-3928 \u2014 Commvault Web Server Unspecified Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-04-28",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-04-28"
    },
    {
      "value": "128.92.80.210",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1011",
          "title": "CISA KEV: CVE-2025-3928 \u2014 Commvault Web Server Unspecified Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-04-28",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-04-28"
    },
    {
      "value": "159.242.42.20",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1011",
          "title": "CISA KEV: CVE-2025-3928 \u2014 Commvault Web Server Unspecified Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-04-28",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-04-28"
    },
    {
      "value": "184.153.42.129",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1011",
          "title": "CISA KEV: CVE-2025-3928 \u2014 Commvault Web Server Unspecified Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-04-28",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-04-28"
    },
    {
      "value": "CVE-2024-43451",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1013",
          "title": "CISA KEV: CVE-2025-24054 \u2014 Microsoft Windows NTLM Hash Disclosure Spoofing Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-04-17",
          "sev": "crit"
        },
        {
          "id": "art-1183",
          "title": "CISA KEV: CVE-2024-43451 \u2014 Microsoft Windows NTLMv2 Hash Disclosure Spoofing Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-11-12",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-04-17"
    },
    {
      "value": "CVE-2025-24054",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1013",
          "title": "CISA KEV: CVE-2025-24054 \u2014 Microsoft Windows NTLM Hash Disclosure Spoofing Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-04-17",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-04-17"
    },
    {
      "value": "CVE-2025-31200",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1014",
          "title": "CISA KEV: CVE-2025-31201 \u2014 Apple Multiple Products Arbitrary Read and Write Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-04-17",
          "sev": "crit"
        },
        {
          "id": "art-1015",
          "title": "CISA KEV: CVE-2025-31200 \u2014 Apple Multiple Products Memory Corruption Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-04-17",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-04-17"
    },
    {
      "value": "CVE-2025-31201",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1014",
          "title": "CISA KEV: CVE-2025-31201 \u2014 Apple Multiple Products Arbitrary Read and Write Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-04-17",
          "sev": "crit"
        },
        {
          "id": "art-1015",
          "title": "CISA KEV: CVE-2025-31200 \u2014 Apple Multiple Products Memory Corruption Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-04-17",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-04-17"
    },
    {
      "value": "159.196.128.120",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1013",
          "title": "CISA KEV: CVE-2025-24054 \u2014 Microsoft Windows NTLM Hash Disclosure Spoofing Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-04-17",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-04-17"
    },
    {
      "value": "194.127.179.157",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1013",
          "title": "CISA KEV: CVE-2025-24054 \u2014 Microsoft Windows NTLM Hash Disclosure Spoofing Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-04-17",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-04-17"
    },
    {
      "value": "054784f1a398a35e0c5242cbfa164df0c277da73",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1013",
          "title": "CISA KEV: CVE-2025-24054 \u2014 Microsoft Windows NTLM Hash Disclosure Spoofing Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-04-17",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-04-17"
    },
    {
      "value": "5e42c6d12f6b51364b6bfb170f4306c5ce608b4f",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1013",
          "title": "CISA KEV: CVE-2025-24054 \u2014 Microsoft Windows NTLM Hash Disclosure Spoofing Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-04-17",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-04-17"
    },
    {
      "value": "76e93c97ffdb5adb509c966bca22e12c4508dcaa",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1013",
          "title": "CISA KEV: CVE-2025-24054 \u2014 Microsoft Windows NTLM Hash Disclosure Spoofing Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-04-17",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-04-17"
    },
    {
      "value": "7a43c177a582c777e258246f0ba818f9e73a69ab",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1013",
          "title": "CISA KEV: CVE-2025-24054 \u2014 Microsoft Windows NTLM Hash Disclosure Spoofing Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-04-17",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-04-17"
    },
    {
      "value": "7dd0131dd4660be562bc869675772e58a1e3ac8e",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1013",
          "title": "CISA KEV: CVE-2025-24054 \u2014 Microsoft Windows NTLM Hash Disclosure Spoofing Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-04-17",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-04-17"
    },
    {
      "value": "84132ae00239e15b50c1a20126000eed29388100",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1013",
          "title": "CISA KEV: CVE-2025-24054 \u2014 Microsoft Windows NTLM Hash Disclosure Spoofing Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-04-17",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-04-17"
    },
    {
      "value": "9ca72d969d7c5494a30e996324c6c0fcb72ae1ae",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1013",
          "title": "CISA KEV: CVE-2025-24054 \u2014 Microsoft Windows NTLM Hash Disclosure Spoofing Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-04-17",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-04-17"
    },
    {
      "value": "CVE-2021-20035",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1017",
          "title": "CISA KEV: CVE-2021-20035 \u2014 SonicWall SMA100 Appliances OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-04-16",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-04-16"
    },
    {
      "value": "CVE-2021-20038",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1017",
          "title": "CISA KEV: CVE-2021-20035 \u2014 SonicWall SMA100 Appliances OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-04-16",
          "sev": "crit"
        },
        {
          "id": "art-2679",
          "title": "CISA KEV: CVE-2021-20038 \u2014 SonicWall SMA 100 Appliances Stack-Based Buffer Overflow Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-01-28",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-04-16"
    },
    {
      "value": "CVE-2021-20039",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1017",
          "title": "CISA KEV: CVE-2021-20035 \u2014 SonicWall SMA100 Appliances OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-04-16",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-04-16"
    },
    {
      "value": "CVE-2025-32819",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1017",
          "title": "CISA KEV: CVE-2021-20035 \u2014 SonicWall SMA100 Appliances OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-04-16",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-04-16"
    },
    {
      "value": "193.149.176.230",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1017",
          "title": "CISA KEV: CVE-2021-20035 \u2014 SonicWall SMA100 Appliances OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-04-16",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-04-16"
    },
    {
      "value": "193.149.180.50",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1017",
          "title": "CISA KEV: CVE-2021-20035 \u2014 SonicWall SMA100 Appliances OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-04-16",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-04-16"
    },
    {
      "value": "64.52.80.80",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1017",
          "title": "CISA KEV: CVE-2021-20035 \u2014 SonicWall SMA100 Appliances OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-04-16",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-04-16"
    },
    {
      "value": "6de26d211966262e59359d0e2a67d473",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1017",
          "title": "CISA KEV: CVE-2021-20035 \u2014 SonicWall SMA100 Appliances OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-04-16",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-04-16"
    },
    {
      "value": "b28d57269fe4cd90d1650bde5e905611",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1017",
          "title": "CISA KEV: CVE-2021-20035 \u2014 SonicWall SMA100 Appliances OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-04-16",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-04-16"
    },
    {
      "value": "d5a070acac1debaf0889d0d48c10e149",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1017",
          "title": "CISA KEV: CVE-2021-20035 \u2014 SonicWall SMA100 Appliances OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-04-16",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-04-16"
    },
    {
      "value": "f0e0db06ca665907770e2202957d3ecc",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1017",
          "title": "CISA KEV: CVE-2021-20035 \u2014 SonicWall SMA100 Appliances OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-04-16",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-04-16"
    },
    {
      "value": "CVE-2024-50302",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1020",
          "title": "CISA KEV: CVE-2024-53197 \u2014 Linux Kernel Out-of-Bounds Access Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-04-09",
          "sev": "crit"
        },
        {
          "id": "art-1069",
          "title": "CISA KEV: CVE-2024-50302 \u2014 Linux Kernel Use of Uninitialized Resource Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-03-04",
          "sev": "crit"
        },
        {
          "id": "art-1105",
          "title": "CISA KEV: CVE-2024-53104 \u2014 Linux Kernel Out-of-Bounds Write Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-02-05",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-04-09"
    },
    {
      "value": "CVE-2024-53104",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1020",
          "title": "CISA KEV: CVE-2024-53197 \u2014 Linux Kernel Out-of-Bounds Access Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-04-09",
          "sev": "crit"
        },
        {
          "id": "art-1105",
          "title": "CISA KEV: CVE-2024-53104 \u2014 Linux Kernel Out-of-Bounds Write Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-02-05",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-04-09"
    },
    {
      "value": "CVE-2024-53150",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1019",
          "title": "CISA KEV: CVE-2024-53150 \u2014 Linux Kernel Out-of-Bounds Read Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-04-09",
          "sev": "crit"
        },
        {
          "id": "art-1020",
          "title": "CISA KEV: CVE-2024-53197 \u2014 Linux Kernel Out-of-Bounds Access Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-04-09",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-04-09"
    },
    {
      "value": "CVE-2024-53197",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1020",
          "title": "CISA KEV: CVE-2024-53197 \u2014 Linux Kernel Out-of-Bounds Access Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-04-09",
          "sev": "crit"
        },
        {
          "id": "art-1105",
          "title": "CISA KEV: CVE-2024-53104 \u2014 Linux Kernel Out-of-Bounds Write Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-02-05",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-04-09"
    },
    {
      "value": "CVE-2025-29824",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1021",
          "title": "CISA KEV: CVE-2025-29824 \u2014 Microsoft Windows Common Log File System (CLFS) Driver Use-After-Free Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-04-08",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-04-08"
    },
    {
      "value": "jbdg4buq6jd7ed3rd6cynqtq5abttuekjnxqrqyvk4xam5i7ld33jvqd.onion",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1021",
          "title": "CISA KEV: CVE-2025-29824 \u2014 Microsoft Windows Common Log File System (CLFS) Driver Use-After-Free Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-04-08",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-04-08"
    },
    {
      "value": "rtb.mftadsrvr.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1022",
          "title": "CISA KEV: CVE-2025-30406 \u2014 Gladinet CentreStack and Triofox Use of Hard-coded Cryptographic Key Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-04-08",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-04-08"
    },
    {
      "value": "uyhi3ypdkfeymyf5v35pbk3pz7st3zamsbjzf47jiqbcm3zmikpwf3qd.onion",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1021",
          "title": "CISA KEV: CVE-2025-29824 \u2014 Microsoft Windows Common Log File System (CLFS) Driver Use-After-Free Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-04-08",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-04-08"
    },
    {
      "value": "104.21.16.1",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1022",
          "title": "CISA KEV: CVE-2025-30406 \u2014 Gladinet CentreStack and Triofox Use of Hard-coded Cryptographic Key Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-04-08",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-04-08"
    },
    {
      "value": "104.21.48.1",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1022",
          "title": "CISA KEV: CVE-2025-30406 \u2014 Gladinet CentreStack and Triofox Use of Hard-coded Cryptographic Key Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-04-08",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-04-08"
    },
    {
      "value": "165.227.7.206",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1022",
          "title": "CISA KEV: CVE-2025-30406 \u2014 Gladinet CentreStack and Triofox Use of Hard-coded Cryptographic Key Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-04-08",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-04-08"
    },
    {
      "value": "2.58.56.16",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1022",
          "title": "CISA KEV: CVE-2025-30406 \u2014 Gladinet CentreStack and Triofox Use of Hard-coded Cryptographic Key Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-04-08",
          "sev": "crit"
        },
        {
          "id": "art-1023",
          "title": "CISA KEV: CVE-2025-31161 \u2014 CrushFTP Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-04-07",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-04-08"
    },
    {
      "value": "45.84.107.76",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1022",
          "title": "CISA KEV: CVE-2025-30406 \u2014 Gladinet CentreStack and Triofox Use of Hard-coded Cryptographic Key Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-04-08",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-04-08"
    },
    {
      "value": "293b455b5b7e1c2063a8781f3c169cf8ef2b1d06e6b7a086b7b44f37f55729bd",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1021",
          "title": "CISA KEV: CVE-2025-29824 \u2014 Microsoft Windows Common Log File System (CLFS) Driver Use-After-Free Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-04-08",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-04-08"
    },
    {
      "value": "30981d4082b58704d12a376c3cbb12fecb8a36c2bce64666315e26aef21e75c2",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1022",
          "title": "CISA KEV: CVE-2025-30406 \u2014 Gladinet CentreStack and Triofox Use of Hard-coded Cryptographic Key Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-04-08",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-04-08"
    },
    {
      "value": "430d1364d0d0a60facd9b73e674faddf63a8f77649cd10ba855df7e49189980b",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1021",
          "title": "CISA KEV: CVE-2025-29824 \u2014 Microsoft Windows Common Log File System (CLFS) Driver Use-After-Free Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-04-08",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-04-08"
    },
    {
      "value": "48b006cb17e75ecdb707dc40dd654f449b94abe49f97a808b35cabca1c5fabbf",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1022",
          "title": "CISA KEV: CVE-2025-30406 \u2014 Gladinet CentreStack and Triofox Use of Hard-coded Cryptographic Key Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-04-08",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-04-08"
    },
    {
      "value": "6030c4381b8b5d5c5734341292316723a89f1bdbd2d10bb67c4d06b1242afd05",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1021",
          "title": "CISA KEV: CVE-2025-29824 \u2014 Microsoft Windows Common Log File System (CLFS) Driver Use-After-Free Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-04-08",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-04-08"
    },
    {
      "value": "6d7374b4f977f689389c7155192b5db70ee44a7645625ecf8163c00da8828388",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1021",
          "title": "CISA KEV: CVE-2025-29824 \u2014 Microsoft Windows Common Log File System (CLFS) Driver Use-After-Free Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-04-08",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-04-08"
    },
    {
      "value": "858efe4f9037e5efebadaaa70aa8ad096f7244c4c4aeade72c51ddad23d05bfe",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1021",
          "title": "CISA KEV: CVE-2025-29824 \u2014 Microsoft Windows Common Log File System (CLFS) Driver Use-After-Free Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-04-08",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-04-08"
    },
    {
      "value": "9c21adbcb2888daf14ef55c4fa1f41eaa6cbfbe20d85c3e1da61a96a53ba18f9",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1021",
          "title": "CISA KEV: CVE-2025-29824 \u2014 Microsoft Windows Common Log File System (CLFS) Driver Use-After-Free Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-04-08",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-04-08"
    },
    {
      "value": "af260c172baffd0e8b2671fd0c84e607ac9b2c8beb57df43cf5df6e103cbb7ad",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1021",
          "title": "CISA KEV: CVE-2025-29824 \u2014 Microsoft Windows Common Log File System (CLFS) Driver Use-After-Free Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-04-08",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-04-08"
    },
    {
      "value": "b2cba01ae6707ce694073018d948f82340b9c41fb2b2bc49769f9a0be37071e1",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1021",
          "title": "CISA KEV: CVE-2025-29824 \u2014 Microsoft Windows Common Log File System (CLFS) Driver Use-After-Free Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-04-08",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-04-08"
    },
    {
      "value": "b3ee068bf282575ac7eb715dd779254889e0b8a55aba2b7a1700fc8aa4dcb1da",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1021",
          "title": "CISA KEV: CVE-2025-29824 \u2014 Microsoft Windows Common Log File System (CLFS) Driver Use-After-Free Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-04-08",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-04-08"
    },
    {
      "value": "CVE-2024-4040",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1023",
          "title": "CISA KEV: CVE-2025-31161 \u2014 CrushFTP Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-04-07",
          "sev": "crit"
        },
        {
          "id": "art-1374",
          "title": "CISA KEV: CVE-2024-4040 \u2014 CrushFTP VFS Sandbox Escape Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-04-24",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-04-07"
    },
    {
      "value": "CVE-2025-2825",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1023",
          "title": "CISA KEV: CVE-2025-31161 \u2014 CrushFTP Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-04-07",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-04-07"
    },
    {
      "value": "CVE-2025-31161",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1023",
          "title": "CISA KEV: CVE-2025-31161 \u2014 CrushFTP Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-04-07",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-04-07"
    },
    {
      "value": "143.244.47.67",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1023",
          "title": "CISA KEV: CVE-2025-31161 \u2014 CrushFTP Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-04-07",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-04-07"
    },
    {
      "value": "146.70.166.201",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1023",
          "title": "CISA KEV: CVE-2025-31161 \u2014 CrushFTP Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-04-07",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-04-07"
    },
    {
      "value": "172.235.144.67",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1023",
          "title": "CISA KEV: CVE-2025-31161 \u2014 CrushFTP Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-04-07",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-04-07"
    },
    {
      "value": "0b8e76eb315bc522af3cec74749a85e8f55cfed720976892d6610cfc89d84f69",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1023",
          "title": "CISA KEV: CVE-2025-31161 \u2014 CrushFTP Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-04-07",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-04-07"
    },
    {
      "value": "85a1bfebf2a5973ebecd6e5a58c8fab18edfead2c1680ec1e9cce902924c347e",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1023",
          "title": "CISA KEV: CVE-2025-31161 \u2014 CrushFTP Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-04-07",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-04-07"
    },
    {
      "value": "9036c92c3ca73cb6ec2da25035322554319288fd2f6db906413011873ad7e281",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1023",
          "title": "CISA KEV: CVE-2025-31161 \u2014 CrushFTP Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-04-07",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-04-07"
    },
    {
      "value": "be6cb5f80b33b9e97622d278a86a99e67b78ccab0b3e554b8430ae5969bcfc0e",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1023",
          "title": "CISA KEV: CVE-2025-31161 \u2014 CrushFTP Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-04-07",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-04-07"
    },
    {
      "value": "ee6d24410a8cf31d672d2a47466b76ad287c7ba016d3711490f0f607b1dc0be3",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1023",
          "title": "CISA KEV: CVE-2025-31161 \u2014 CrushFTP Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-04-07",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-04-07"
    },
    {
      "value": "f7c8be827f3bd98b30c5a8d23c1af77f3d0324a9ebcd90104134fc1971751ff7",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1023",
          "title": "CISA KEV: CVE-2025-31161 \u2014 CrushFTP Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-04-07",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-04-07"
    },
    {
      "value": "CVE-2025-22457",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1024",
          "title": "CISA KEV: CVE-2025-22457 \u2014 Ivanti Connect Secure, Policy Secure, and ZTA Gateways Stack-Based Buffer Overflow Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-04-04",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-04-04"
    },
    {
      "value": "10659b392e7f5b30b375b94cae4fdca0",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1024",
          "title": "CISA KEV: CVE-2025-22457 \u2014 Ivanti Connect Secure, Policy Secure, and ZTA Gateways Stack-Based Buffer Overflow Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-04-04",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-04-04"
    },
    {
      "value": "4628a501088c31f53b5c9ddf6788e835",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1024",
          "title": "CISA KEV: CVE-2025-22457 \u2014 Ivanti Connect Secure, Policy Secure, and ZTA Gateways Stack-Based Buffer Overflow Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-04-04",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-04-04"
    },
    {
      "value": "6e01ef1367ea81994578526b3bd331d6",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1024",
          "title": "CISA KEV: CVE-2025-22457 \u2014 Ivanti Connect Secure, Policy Secure, and ZTA Gateways Stack-Based Buffer Overflow Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-04-04",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-04-04"
    },
    {
      "value": "ce2b6a554ae46b5eb7d79ca5e7f440da",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1024",
          "title": "CISA KEV: CVE-2025-22457 \u2014 Ivanti Connect Secure, Policy Secure, and ZTA Gateways Stack-Based Buffer Overflow Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-04-04",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-04-04"
    },
    {
      "value": "e5192258c27e712c7acf80303e68980b",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1024",
          "title": "CISA KEV: CVE-2025-22457 \u2014 Ivanti Connect Secure, Policy Secure, and ZTA Gateways Stack-Based Buffer Overflow Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-04-04",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-04-04"
    },
    {
      "value": "CVE-2024-0305",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1028",
          "title": "CISA KEV: CVE-2024-20439 \u2014 Cisco Smart Licensing Utility Static Credential Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-03-31",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-03-31"
    },
    {
      "value": "CVE-2024-20439",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1028",
          "title": "CISA KEV: CVE-2024-20439 \u2014 Cisco Smart Licensing Utility Static Credential Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-03-31",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-03-31"
    },
    {
      "value": "CVE-2024-20440",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1028",
          "title": "CISA KEV: CVE-2024-20439 \u2014 Cisco Smart Licensing Utility Static Credential Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-03-31",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-03-31"
    },
    {
      "value": "CVE-2024-6473",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1030",
          "title": "CISA KEV: CVE-2025-2783 \u2014 Google Chromium Mojo Sandbox Escape Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-03-27",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-03-27"
    },
    {
      "value": "CVE-2025-2783",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1030",
          "title": "CISA KEV: CVE-2025-2783 \u2014 Google Chromium Mojo Sandbox Escape Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-03-27",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-03-27"
    },
    {
      "value": "CVE-2025-2857",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1030",
          "title": "CISA KEV: CVE-2025-2783 \u2014 Google Chromium Mojo Sandbox Escape Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-03-27",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-03-27"
    },
    {
      "value": "bus-pod-tenant.global.ssl.fastly.net",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1030",
          "title": "CISA KEV: CVE-2025-2783 \u2014 Google Chromium Mojo Sandbox Escape Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-03-27",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-03-27"
    },
    {
      "value": "e-library.wiki",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1030",
          "title": "CISA KEV: CVE-2025-2783 \u2014 Google Chromium Mojo Sandbox Escape Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-03-27",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-03-27"
    },
    {
      "value": "perf-service-clients2.global.ssl.fastly.net",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1030",
          "title": "CISA KEV: CVE-2025-2783 \u2014 Google Chromium Mojo Sandbox Escape Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-03-27",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-03-27"
    },
    {
      "value": "status-portal-api.global.ssl.fastly.net",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1030",
          "title": "CISA KEV: CVE-2025-2783 \u2014 Google Chromium Mojo Sandbox Escape Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-03-27",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-03-27"
    },
    {
      "value": "33bb0678af6011481845d7ce9643cedc",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1030",
          "title": "CISA KEV: CVE-2025-2783 \u2014 Google Chromium Mojo Sandbox Escape Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-03-27",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-03-27"
    },
    {
      "value": "35869e8760928407d2789c7f115b7f83",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1030",
          "title": "CISA KEV: CVE-2025-2783 \u2014 Google Chromium Mojo Sandbox Escape Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-03-27",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-03-27"
    },
    {
      "value": "7d3a30dbf4fd3edaf4dde35ccb5cf926",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1030",
          "title": "CISA KEV: CVE-2025-2783 \u2014 Google Chromium Mojo Sandbox Escape Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-03-27",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-03-27"
    },
    {
      "value": "3650c1ac97bd5674e1e3bfa9b26008644edacfed",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1030",
          "title": "CISA KEV: CVE-2025-2783 \u2014 Google Chromium Mojo Sandbox Escape Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-03-27",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-03-27"
    },
    {
      "value": "8390e2ebdd0db5d1a950b2c9984a5f429805d48c",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1030",
          "title": "CISA KEV: CVE-2025-2783 \u2014 Google Chromium Mojo Sandbox Escape Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-03-27",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-03-27"
    },
    {
      "value": "c25275228c6da54cf578fa72c9f49697e5309694",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1030",
          "title": "CISA KEV: CVE-2025-2783 \u2014 Google Chromium Mojo Sandbox Escape Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-03-27",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-03-27"
    },
    {
      "value": "07d272b607f082305ce7b1987bfa17dc967ab45c8cd89699bcdced34ea94e126",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1030",
          "title": "CISA KEV: CVE-2025-2783 \u2014 Google Chromium Mojo Sandbox Escape Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-03-27",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-03-27"
    },
    {
      "value": "2e39800df1cafbebfa22b437744d80f1b38111b471fa3eb42f2214a5ac7e1f13",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1030",
          "title": "CISA KEV: CVE-2025-2783 \u2014 Google Chromium Mojo Sandbox Escape Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-03-27",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-03-27"
    },
    {
      "value": "388a8af43039f5f16a0673a6e342fa6ae2402e63ba7569d20d9ba4894dc0ba59",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1030",
          "title": "CISA KEV: CVE-2025-2783 \u2014 Google Chromium Mojo Sandbox Escape Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-03-27",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-03-27"
    },
    {
      "value": "CVE-2019-9874",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1031",
          "title": "CISA KEV: CVE-2019-9875 \u2014 Sitecore CMS and Experience Platform (XP) Deserialization Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-03-26",
          "sev": "crit"
        },
        {
          "id": "art-1032",
          "title": "CISA KEV: CVE-2019-9874 \u2014 Sitecore CMS and Experience Platform (XP) Deserialization Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-03-26",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-03-26"
    },
    {
      "value": "CVE-2019-9875",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1031",
          "title": "CISA KEV: CVE-2019-9875 \u2014 Sitecore CMS and Experience Platform (XP) Deserialization Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-03-26",
          "sev": "crit"
        },
        {
          "id": "art-1032",
          "title": "CISA KEV: CVE-2019-9874 \u2014 Sitecore CMS and Experience Platform (XP) Deserialization Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-03-26",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-03-26"
    },
    {
      "value": "CVE-2025-30154",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1033",
          "title": "CISA KEV: CVE-2025-30154 \u2014 reviewdog/action-setup GitHub Action Embedded Malicious Code Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-03-24",
          "sev": "crit"
        },
        {
          "id": "art-1041",
          "title": "CISA KEV: CVE-2025-30066 \u2014 tj-actions/changed-files GitHub Action Embedded Malicious Code Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-03-18",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-03-24"
    },
    {
      "value": "3c6d5c14e71ff37a0a341c6fdc3e71cefbc85ba0",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1033",
          "title": "CISA KEV: CVE-2025-30154 \u2014 reviewdog/action-setup GitHub Action Embedded Malicious Code Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-03-24",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-03-24"
    },
    {
      "value": "6e6023c01918b353229af0881232f601a4cc8365",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1033",
          "title": "CISA KEV: CVE-2025-30154 \u2014 reviewdog/action-setup GitHub Action Embedded Malicious Code Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-03-24",
          "sev": "crit"
        },
        {
          "id": "art-1041",
          "title": "CISA KEV: CVE-2025-30066 \u2014 tj-actions/changed-files GitHub Action Embedded Malicious Code Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-03-18",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-03-24"
    },
    {
      "value": "f5434e31b6259b4e08684618a305bae127b6d784",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1033",
          "title": "CISA KEV: CVE-2025-30154 \u2014 reviewdog/action-setup GitHub Action Embedded Malicious Code Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-03-24",
          "sev": "crit"
        },
        {
          "id": "art-1041",
          "title": "CISA KEV: CVE-2025-30066 \u2014 tj-actions/changed-files GitHub Action Embedded Malicious Code Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-03-18",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-03-24"
    },
    {
      "value": "CVE-2017-12637",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1036",
          "title": "CISA KEV: CVE-2017-12637 \u2014 SAP NetWeaver Directory Traversal Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-03-19",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-03-19"
    },
    {
      "value": "CVE-2024-48248",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1037",
          "title": "CISA KEV: CVE-2024-48248 \u2014 NAKIVO Backup and Replication Absolute Path Traversal Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-03-19",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-03-19"
    },
    {
      "value": "CVE-2025-1316",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1038",
          "title": "CISA KEV: CVE-2025-1316 \u2014 Edimax IC-7100 IP Camera OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-03-19",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-03-19"
    },
    {
      "value": "CVE-2024-55591",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1042",
          "title": "CISA KEV: CVE-2025-24472 \u2014 Fortinet FortiOS and FortiProxy Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-03-18",
          "sev": "crit"
        },
        {
          "id": "art-1125",
          "title": "CISA KEV: CVE-2024-55591 \u2014 Fortinet FortiOS and FortiProxy Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-01-14",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-03-18"
    },
    {
      "value": "CVE-2025-24472",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1042",
          "title": "CISA KEV: CVE-2025-24472 \u2014 Fortinet FortiOS and FortiProxy Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-03-18",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-03-18"
    },
    {
      "value": "109.248.160.118",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1042",
          "title": "CISA KEV: CVE-2025-24472 \u2014 Fortinet FortiOS and FortiProxy Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-03-18",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-03-18"
    },
    {
      "value": "149.22.94.37",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1042",
          "title": "CISA KEV: CVE-2025-24472 \u2014 Fortinet FortiOS and FortiProxy Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-03-18",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-03-18"
    },
    {
      "value": "155.133.4.175",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1042",
          "title": "CISA KEV: CVE-2025-24472 \u2014 Fortinet FortiOS and FortiProxy Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-03-18",
          "sev": "crit"
        },
        {
          "id": "art-1125",
          "title": "CISA KEV: CVE-2024-55591 \u2014 Fortinet FortiOS and FortiProxy Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-01-14",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-03-18"
    },
    {
      "value": "158.255.215.126",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1042",
          "title": "CISA KEV: CVE-2025-24472 \u2014 Fortinet FortiOS and FortiProxy Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-03-18",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-03-18"
    },
    {
      "value": "170.130.55.164",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1042",
          "title": "CISA KEV: CVE-2025-24472 \u2014 Fortinet FortiOS and FortiProxy Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-03-18",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-03-18"
    },
    {
      "value": "176.53.147.5",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1042",
          "title": "CISA KEV: CVE-2025-24472 \u2014 Fortinet FortiOS and FortiProxy Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-03-18",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-03-18"
    },
    {
      "value": "185.147.124.10",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1042",
          "title": "CISA KEV: CVE-2025-24472 \u2014 Fortinet FortiOS and FortiProxy Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-03-18",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-03-18"
    },
    {
      "value": "185.147.124.31",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1042",
          "title": "CISA KEV: CVE-2025-24472 \u2014 Fortinet FortiOS and FortiProxy Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-03-18",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-03-18"
    },
    {
      "value": "185.147.124.34",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1042",
          "title": "CISA KEV: CVE-2025-24472 \u2014 Fortinet FortiOS and FortiProxy Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-03-18",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-03-18"
    },
    {
      "value": "185.147.124.55",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1042",
          "title": "CISA KEV: CVE-2025-24472 \u2014 Fortinet FortiOS and FortiProxy Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-03-18",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-03-18"
    },
    {
      "value": "185.224.0.201",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1042",
          "title": "CISA KEV: CVE-2025-24472 \u2014 Fortinet FortiOS and FortiProxy Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-03-18",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-03-18"
    },
    {
      "value": "185.95.159.43",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1042",
          "title": "CISA KEV: CVE-2025-24472 \u2014 Fortinet FortiOS and FortiProxy Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-03-18",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-03-18"
    },
    {
      "value": "192.248.155.218",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1042",
          "title": "CISA KEV: CVE-2025-24472 \u2014 Fortinet FortiOS and FortiProxy Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-03-18",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-03-18"
    },
    {
      "value": "193.143.1.65",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1042",
          "title": "CISA KEV: CVE-2025-24472 \u2014 Fortinet FortiOS and FortiProxy Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-03-18",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-03-18"
    },
    {
      "value": "213.176.64.114",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1042",
          "title": "CISA KEV: CVE-2025-24472 \u2014 Fortinet FortiOS and FortiProxy Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-03-18",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-03-18"
    },
    {
      "value": "217.144.189.35",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1042",
          "title": "CISA KEV: CVE-2025-24472 \u2014 Fortinet FortiOS and FortiProxy Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-03-18",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-03-18"
    },
    {
      "value": "45.15.17.67",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1042",
          "title": "CISA KEV: CVE-2025-24472 \u2014 Fortinet FortiOS and FortiProxy Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-03-18",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-03-18"
    },
    {
      "value": "45.55.158.47",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1042",
          "title": "CISA KEV: CVE-2025-24472 \u2014 Fortinet FortiOS and FortiProxy Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-03-18",
          "sev": "crit"
        },
        {
          "id": "art-1125",
          "title": "CISA KEV: CVE-2024-55591 \u2014 Fortinet FortiOS and FortiProxy Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-01-14",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-03-18"
    },
    {
      "value": "5.181.171.133",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1042",
          "title": "CISA KEV: CVE-2025-24472 \u2014 Fortinet FortiOS and FortiProxy Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-03-18",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-03-18"
    },
    {
      "value": "57.69.19.70",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1042",
          "title": "CISA KEV: CVE-2025-24472 \u2014 Fortinet FortiOS and FortiProxy Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-03-18",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-03-18"
    },
    {
      "value": "80.64.30.237",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1042",
          "title": "CISA KEV: CVE-2025-24472 \u2014 Fortinet FortiOS and FortiProxy Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-03-18",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-03-18"
    },
    {
      "value": "80.66.88.90",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1042",
          "title": "CISA KEV: CVE-2025-24472 \u2014 Fortinet FortiOS and FortiProxy Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-03-18",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-03-18"
    },
    {
      "value": "87.249.138.47",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1042",
          "title": "CISA KEV: CVE-2025-24472 \u2014 Fortinet FortiOS and FortiProxy Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-03-18",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-03-18"
    },
    {
      "value": "89.248.192.55",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1042",
          "title": "CISA KEV: CVE-2025-24472 \u2014 Fortinet FortiOS and FortiProxy Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-03-18",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-03-18"
    },
    {
      "value": "94.154.35.208",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1042",
          "title": "CISA KEV: CVE-2025-24472 \u2014 Fortinet FortiOS and FortiProxy Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-03-18",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-03-18"
    },
    {
      "value": "94.156.177.187",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1042",
          "title": "CISA KEV: CVE-2025-24472 \u2014 Fortinet FortiOS and FortiProxy Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-03-18",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-03-18"
    },
    {
      "value": "94.156.227.208",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1042",
          "title": "CISA KEV: CVE-2025-24472 \u2014 Fortinet FortiOS and FortiProxy Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-03-18",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-03-18"
    },
    {
      "value": "95.179.234.4",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1042",
          "title": "CISA KEV: CVE-2025-24472 \u2014 Fortinet FortiOS and FortiProxy Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-03-18",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-03-18"
    },
    {
      "value": "95.217.78.122",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1042",
          "title": "CISA KEV: CVE-2025-24472 \u2014 Fortinet FortiOS and FortiProxy Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-03-18",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-03-18"
    },
    {
      "value": "96.31.67.39",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1042",
          "title": "CISA KEV: CVE-2025-24472 \u2014 Fortinet FortiOS and FortiProxy Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-03-18",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-03-18"
    },
    {
      "value": "782c3c463809cd818dadad736f076c36cdea01d8c4efed094d78661ba0a57045",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1042",
          "title": "CISA KEV: CVE-2025-24472 \u2014 Fortinet FortiOS and FortiProxy Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-03-18",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-03-18"
    },
    {
      "value": "813ad8caa4dcbd814c1ee9ea28040d74338e79e76beae92bedc8a47b402dedc2",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1042",
          "title": "CISA KEV: CVE-2025-24472 \u2014 Fortinet FortiOS and FortiProxy Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-03-18",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-03-18"
    },
    {
      "value": "917e115cc403e29b4388e0d175cbfac3e7e40ca1742299fbdb353847db2de7c2",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1042",
          "title": "CISA KEV: CVE-2025-24472 \u2014 Fortinet FortiOS and FortiProxy Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-03-18",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-03-18"
    },
    {
      "value": "c994b132b2a264b8cf1d47b2f432fe6bda631b994ec7dcddf5650113f4a5a404",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1042",
          "title": "CISA KEV: CVE-2025-24472 \u2014 Fortinet FortiOS and FortiProxy Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-03-18",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-03-18"
    },
    {
      "value": "d9938ac4346d03a07f8ce8b57436e75ba5e936372b9bfd0386f18f6d56902c88",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1042",
          "title": "CISA KEV: CVE-2025-24472 \u2014 Fortinet FortiOS and FortiProxy Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-03-18",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-03-18"
    },
    {
      "value": "f383bca7e763b9a76e64489f1e2e54c44e1fd24094e9f3a28d4b45b5ec88b513",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1042",
          "title": "CISA KEV: CVE-2025-24472 \u2014 Fortinet FortiOS and FortiProxy Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-03-18",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-03-18"
    },
    {
      "value": "CVE-2025-21590",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1046",
          "title": "CISA KEV: CVE-2025-21590 \u2014 Juniper Junos OS Improper Isolation or Compartmentalization Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-03-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-03-13"
    },
    {
      "value": "CVE-2025-24201",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1047",
          "title": "CISA KEV: CVE-2025-24201 \u2014 Apple Multiple Products WebKit Out-of-Bounds Write Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-03-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-03-13"
    },
    {
      "value": "101.100.182.122",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1046",
          "title": "CISA KEV: CVE-2025-21590 \u2014 Juniper Junos OS Improper Isolation or Compartmentalization Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-03-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-03-13"
    },
    {
      "value": "116.88.34.184",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1046",
          "title": "CISA KEV: CVE-2025-21590 \u2014 Juniper Junos OS Improper Isolation or Compartmentalization Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-03-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-03-13"
    },
    {
      "value": "118.189.188.122",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1046",
          "title": "CISA KEV: CVE-2025-21590 \u2014 Juniper Junos OS Improper Isolation or Compartmentalization Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-03-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-03-13"
    },
    {
      "value": "129.126.109.50",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1046",
          "title": "CISA KEV: CVE-2025-21590 \u2014 Juniper Junos OS Improper Isolation or Compartmentalization Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-03-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-03-13"
    },
    {
      "value": "158.140.135.244",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1046",
          "title": "CISA KEV: CVE-2025-21590 \u2014 Juniper Junos OS Improper Isolation or Compartmentalization Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-03-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-03-13"
    },
    {
      "value": "223.25.78.136",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1046",
          "title": "CISA KEV: CVE-2025-21590 \u2014 Juniper Junos OS Improper Isolation or Compartmentalization Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-03-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-03-13"
    },
    {
      "value": "45.77.39.28",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1046",
          "title": "CISA KEV: CVE-2025-21590 \u2014 Juniper Junos OS Improper Isolation or Compartmentalization Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-03-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-03-13"
    },
    {
      "value": "8.222.225.8",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1046",
          "title": "CISA KEV: CVE-2025-21590 \u2014 Juniper Junos OS Improper Isolation or Compartmentalization Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-03-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-03-13"
    },
    {
      "value": "2c89a18944d3a895bd6432415546635e",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1046",
          "title": "CISA KEV: CVE-2025-21590 \u2014 Juniper Junos OS Improper Isolation or Compartmentalization Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-03-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-03-13"
    },
    {
      "value": "3243e04afe18cc5e1230d49011e19899",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1046",
          "title": "CISA KEV: CVE-2025-21590 \u2014 Juniper Junos OS Improper Isolation or Compartmentalization Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-03-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-03-13"
    },
    {
      "value": "5724d76f832ce8061f74b0e9f1dcad90",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1046",
          "title": "CISA KEV: CVE-2025-21590 \u2014 Juniper Junos OS Improper Isolation or Compartmentalization Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-03-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-03-13"
    },
    {
      "value": "8023d01ffb7a38b582f0d598afb974ee",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1046",
          "title": "CISA KEV: CVE-2025-21590 \u2014 Juniper Junos OS Improper Isolation or Compartmentalization Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-03-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-03-13"
    },
    {
      "value": "aac5d83d296df81c9259c9a533a8423a",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1046",
          "title": "CISA KEV: CVE-2025-21590 \u2014 Juniper Junos OS Improper Isolation or Compartmentalization Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-03-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-03-13"
    },
    {
      "value": "b9e4784fa0e6283ce6e2094426a02fce",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1046",
          "title": "CISA KEV: CVE-2025-21590 \u2014 Juniper Junos OS Improper Isolation or Compartmentalization Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-03-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-03-13"
    },
    {
      "value": "bf80c96089d37b8571b5de7cab14dd9f",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1046",
          "title": "CISA KEV: CVE-2025-21590 \u2014 Juniper Junos OS Improper Isolation or Compartmentalization Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-03-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-03-13"
    },
    {
      "value": "e7622d983d22e749b3658600df00296d",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1046",
          "title": "CISA KEV: CVE-2025-21590 \u2014 Juniper Junos OS Improper Isolation or Compartmentalization Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-03-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-03-13"
    },
    {
      "value": "01735bb47a933ae9ec470e6be737d8f646a8ec66",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1046",
          "title": "CISA KEV: CVE-2025-21590 \u2014 Juniper Junos OS Improper Isolation or Compartmentalization Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-03-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-03-13"
    },
    {
      "value": "06a1f879da398c00522649171526dc968f769093",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1046",
          "title": "CISA KEV: CVE-2025-21590 \u2014 Juniper Junos OS Improper Isolation or Compartmentalization Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-03-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-03-13"
    },
    {
      "value": "1a6d07da7e77a5706dd8af899ebe4daa74bbbe91",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1046",
          "title": "CISA KEV: CVE-2025-21590 \u2014 Juniper Junos OS Improper Isolation or Compartmentalization Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-03-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-03-13"
    },
    {
      "value": "2e9215a203e908483d04dfc0328651d79d35b54f",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1046",
          "title": "CISA KEV: CVE-2025-21590 \u2014 Juniper Junos OS Improper Isolation or Compartmentalization Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-03-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-03-13"
    },
    {
      "value": "50520639cf77df0c15cc95076fac901e3d04b708",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1046",
          "title": "CISA KEV: CVE-2025-21590 \u2014 Juniper Junos OS Improper Isolation or Compartmentalization Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-03-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-03-13"
    },
    {
      "value": "cec327e51b79cf11b3eeffebf1be8ac0d66e9529",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1046",
          "title": "CISA KEV: CVE-2025-21590 \u2014 Juniper Junos OS Improper Isolation or Compartmentalization Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-03-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-03-13"
    },
    {
      "value": "cf7af504ef0796d91207e41815187a793d430d85",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1046",
          "title": "CISA KEV: CVE-2025-21590 \u2014 Juniper Junos OS Improper Isolation or Compartmentalization Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-03-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-03-13"
    },
    {
      "value": "f8697b400059d4d5082eee2d269735aa8ea2df9a",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1046",
          "title": "CISA KEV: CVE-2025-21590 \u2014 Juniper Junos OS Improper Isolation or Compartmentalization Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-03-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-03-13"
    },
    {
      "value": "3751997cfcb038e6b658e9180bc7cce28a3c25dbb892b661bcd1065723f11f7e",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1046",
          "title": "CISA KEV: CVE-2025-21590 \u2014 Juniper Junos OS Improper Isolation or Compartmentalization Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-03-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-03-13"
    },
    {
      "value": "5995aaff5a047565c0d7fe3c80fa354c40e7e8c3e7d4df292316c8472d4ac67a",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1046",
          "title": "CISA KEV: CVE-2025-21590 \u2014 Juniper Junos OS Improper Isolation or Compartmentalization Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-03-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-03-13"
    },
    {
      "value": "5bef7608d66112315eefff354dae42f49178b7498f994a728ae6203a8a59f5a2",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1046",
          "title": "CISA KEV: CVE-2025-21590 \u2014 Juniper Junos OS Improper Isolation or Compartmentalization Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-03-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-03-13"
    },
    {
      "value": "905b18d5df58bd6c16930e318d9574a2ad793ec993ad2f68bca813574e3d854b",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1046",
          "title": "CISA KEV: CVE-2025-21590 \u2014 Juniper Junos OS Improper Isolation or Compartmentalization Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-03-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-03-13"
    },
    {
      "value": "98380ec6bf4e03d3ff490cdc6c48c37714450930e4adf82e6e14d244d8373888",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1046",
          "title": "CISA KEV: CVE-2025-21590 \u2014 Juniper Junos OS Improper Isolation or Compartmentalization Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-03-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-03-13"
    },
    {
      "value": "c0ec15e08b4fb3730c5695fb7b4a6b85f7fe341282ad469e4e141c40ead310c3",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1046",
          "title": "CISA KEV: CVE-2025-21590 \u2014 Juniper Junos OS Improper Isolation or Compartmentalization Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-03-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-03-13"
    },
    {
      "value": "e1de05a2832437ab70d36c4c05b43c4a57f856289224bbd41182deea978400ed",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1046",
          "title": "CISA KEV: CVE-2025-21590 \u2014 Juniper Junos OS Improper Isolation or Compartmentalization Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-03-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-03-13"
    },
    {
      "value": "CVE-2025-22869",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-1048",
          "title": "Snyk Helps Secure the Golang Bento Project",
          "link": "https://snyk.io/blog/snyk-helps-secure-the-golang-bento-project/",
          "published": "2025-03-12",
          "sev": "high"
        }
      ],
      "first_seen": "2025-03-12"
    },
    {
      "value": "CVE-2025-24983",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1056",
          "title": "CISA KEV: CVE-2025-24983 \u2014 Microsoft Windows Win32k Use-After-Free Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-03-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-03-11"
    },
    {
      "value": "CVE-2025-24984",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1055",
          "title": "CISA KEV: CVE-2025-24984 \u2014 Microsoft Windows NTFS Information Disclosure Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-03-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-03-11"
    },
    {
      "value": "CVE-2025-24985",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1054",
          "title": "CISA KEV: CVE-2025-24985 \u2014 Microsoft Windows Fast FAT File System Driver Integer Overflow Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-03-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-03-11"
    },
    {
      "value": "CVE-2025-24991",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1053",
          "title": "CISA KEV: CVE-2025-24991 \u2014 Microsoft Windows NTFS Out-Of-Bounds Read Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-03-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-03-11"
    },
    {
      "value": "CVE-2025-24993",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1052",
          "title": "CISA KEV: CVE-2025-24993 \u2014 Microsoft Windows NTFS Heap-Based Buffer Overflow Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-03-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-03-11"
    },
    {
      "value": "CVE-2025-26633",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1057",
          "title": "CISA KEV: CVE-2025-26633 \u2014 Microsoft Windows Management Console (MMC) Improper Neutralization Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-03-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-03-11"
    },
    {
      "value": "belaysolutions.link",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1057",
          "title": "CISA KEV: CVE-2025-26633 \u2014 Microsoft Windows Management Console (MMC) Improper Neutralization Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-03-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-03-11"
    },
    {
      "value": "103.246.147.17",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1057",
          "title": "CISA KEV: CVE-2025-26633 \u2014 Microsoft Windows Management Console (MMC) Improper Neutralization Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-03-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-03-11"
    },
    {
      "value": "82.115.223.182",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1057",
          "title": "CISA KEV: CVE-2025-26633 \u2014 Microsoft Windows Management Console (MMC) Improper Neutralization Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-03-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-03-11"
    },
    {
      "value": "bad43a1c8ba1dacf3daf82bc30a0673f9bc2675ea6cdedd34624ffc933b959f4",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1057",
          "title": "CISA KEV: CVE-2025-26633 \u2014 Microsoft Windows Management Console (MMC) Improper Neutralization Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-03-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-03-11"
    },
    {
      "value": "CVE-2017-9248",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1062",
          "title": "CISA KEV: CVE-2025-25181 \u2014  Advantive VeraCore SQL Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-03-10",
          "sev": "crit"
        },
        {
          "id": "art-2350",
          "title": "CISA KEV: CVE-2017-11317 \u2014 Telerik UI for ASP.NET AJAX Unrestricted File Upload Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-04-11",
          "sev": "crit"
        },
        {
          "id": "art-3012",
          "title": "CISA KEV: CVE-2019-18935 \u2014 Progress Telerik UI for ASP.NET AJAX Deserialization of Untrusted Data Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        },
        {
          "id": "art-3047",
          "title": "CISA KEV: CVE-2017-9248 \u2014 Progress Telerik UI for ASP.NET AJAX and Sitefinity Cryptographic Weakness Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-03-10"
    },
    {
      "value": "CVE-2019-18935",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1062",
          "title": "CISA KEV: CVE-2025-25181 \u2014  Advantive VeraCore SQL Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-03-10",
          "sev": "crit"
        },
        {
          "id": "art-1882",
          "title": "CISA KEV: CVE-2017-11357 \u2014 Telerik UI for ASP.NET AJAX Insecure Direct Object Reference Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-01-26",
          "sev": "crit"
        },
        {
          "id": "art-2350",
          "title": "CISA KEV: CVE-2017-11317 \u2014 Telerik UI for ASP.NET AJAX Unrestricted File Upload Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-04-11",
          "sev": "crit"
        },
        {
          "id": "art-3012",
          "title": "CISA KEV: CVE-2019-18935 \u2014 Progress Telerik UI for ASP.NET AJAX Deserialization of Untrusted Data Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        },
        {
          "id": "art-3047",
          "title": "CISA KEV: CVE-2017-9248 \u2014 Progress Telerik UI for ASP.NET AJAX and Sitefinity Cryptographic Weakness Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-03-10"
    },
    {
      "value": "CVE-2024-10811",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1060",
          "title": "CISA KEV: CVE-2024-13159 \u2014 Ivanti Endpoint Manager (EPM) Absolute Path Traversal Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-03-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-03-10"
    },
    {
      "value": "CVE-2024-13159",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1060",
          "title": "CISA KEV: CVE-2024-13159 \u2014 Ivanti Endpoint Manager (EPM) Absolute Path Traversal Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-03-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-03-10"
    },
    {
      "value": "CVE-2024-13160",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1059",
          "title": "CISA KEV: CVE-2024-13160 \u2014 Ivanti Endpoint Manager (EPM) Absolute Path Traversal Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-03-10",
          "sev": "crit"
        },
        {
          "id": "art-1060",
          "title": "CISA KEV: CVE-2024-13159 \u2014 Ivanti Endpoint Manager (EPM) Absolute Path Traversal Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-03-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-03-10"
    },
    {
      "value": "CVE-2024-13161",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1058",
          "title": "CISA KEV: CVE-2024-13161 \u2014 Ivanti Endpoint Manager (EPM) Absolute Path Traversal Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-03-10",
          "sev": "crit"
        },
        {
          "id": "art-1060",
          "title": "CISA KEV: CVE-2024-13159 \u2014 Ivanti Endpoint Manager (EPM) Absolute Path Traversal Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-03-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-03-10"
    },
    {
      "value": "CVE-2024-57968",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1061",
          "title": "CISA KEV: CVE-2024-57968 \u2014 Advantive VeraCore Unrestricted File Upload Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-03-10",
          "sev": "crit"
        },
        {
          "id": "art-1062",
          "title": "CISA KEV: CVE-2025-25181 \u2014  Advantive VeraCore SQL Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-03-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-03-10"
    },
    {
      "value": "CVE-2025-25181",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1061",
          "title": "CISA KEV: CVE-2024-57968 \u2014 Advantive VeraCore Unrestricted File Upload Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-03-10",
          "sev": "crit"
        },
        {
          "id": "art-1062",
          "title": "CISA KEV: CVE-2025-25181 \u2014  Advantive VeraCore SQL Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-03-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-03-10"
    },
    {
      "value": "hivnd.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1061",
          "title": "CISA KEV: CVE-2024-57968 \u2014 Advantive VeraCore Unrestricted File Upload Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-03-10",
          "sev": "crit"
        },
        {
          "id": "art-1062",
          "title": "CISA KEV: CVE-2025-25181 \u2014  Advantive VeraCore SQL Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-03-10",
          "sev": "crit"
        },
        {
          "id": "art-2350",
          "title": "CISA KEV: CVE-2017-11317 \u2014 Telerik UI for ASP.NET AJAX Unrestricted File Upload Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-04-11",
          "sev": "crit"
        },
        {
          "id": "art-3012",
          "title": "CISA KEV: CVE-2019-18935 \u2014 Progress Telerik UI for ASP.NET AJAX Deserialization of Untrusted Data Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        },
        {
          "id": "art-3047",
          "title": "CISA KEV: CVE-2017-9248 \u2014 Progress Telerik UI for ASP.NET AJAX and Sitefinity Cryptographic Weakness Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-03-10"
    },
    {
      "value": "object.fm",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1061",
          "title": "CISA KEV: CVE-2024-57968 \u2014 Advantive VeraCore Unrestricted File Upload Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-03-10",
          "sev": "crit"
        },
        {
          "id": "art-1062",
          "title": "CISA KEV: CVE-2025-25181 \u2014  Advantive VeraCore SQL Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-03-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-03-10"
    },
    {
      "value": "paycashs.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1061",
          "title": "CISA KEV: CVE-2024-57968 \u2014 Advantive VeraCore Unrestricted File Upload Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-03-10",
          "sev": "crit"
        },
        {
          "id": "art-1062",
          "title": "CISA KEV: CVE-2025-25181 \u2014  Advantive VeraCore SQL Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-03-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-03-10"
    },
    {
      "value": "sexadult.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1061",
          "title": "CISA KEV: CVE-2024-57968 \u2014 Advantive VeraCore Unrestricted File Upload Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-03-10",
          "sev": "crit"
        },
        {
          "id": "art-1062",
          "title": "CISA KEV: CVE-2025-25181 \u2014  Advantive VeraCore SQL Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-03-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-03-10"
    },
    {
      "value": "xegroups.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1061",
          "title": "CISA KEV: CVE-2024-57968 \u2014 Advantive VeraCore Unrestricted File Upload Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-03-10",
          "sev": "crit"
        },
        {
          "id": "art-1062",
          "title": "CISA KEV: CVE-2025-25181 \u2014  Advantive VeraCore SQL Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-03-10",
          "sev": "crit"
        },
        {
          "id": "art-2350",
          "title": "CISA KEV: CVE-2017-11317 \u2014 Telerik UI for ASP.NET AJAX Unrestricted File Upload Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-04-11",
          "sev": "crit"
        },
        {
          "id": "art-3012",
          "title": "CISA KEV: CVE-2019-18935 \u2014 Progress Telerik UI for ASP.NET AJAX Deserialization of Untrusted Data Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        },
        {
          "id": "art-3047",
          "title": "CISA KEV: CVE-2017-9248 \u2014 Progress Telerik UI for ASP.NET AJAX and Sitefinity Cryptographic Weakness Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-03-10"
    },
    {
      "value": "xework.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1061",
          "title": "CISA KEV: CVE-2024-57968 \u2014 Advantive VeraCore Unrestricted File Upload Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-03-10",
          "sev": "crit"
        },
        {
          "id": "art-1062",
          "title": "CISA KEV: CVE-2025-25181 \u2014  Advantive VeraCore SQL Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-03-10",
          "sev": "crit"
        },
        {
          "id": "art-2350",
          "title": "CISA KEV: CVE-2017-11317 \u2014 Telerik UI for ASP.NET AJAX Unrestricted File Upload Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-04-11",
          "sev": "crit"
        },
        {
          "id": "art-3012",
          "title": "CISA KEV: CVE-2019-18935 \u2014 Progress Telerik UI for ASP.NET AJAX Deserialization of Untrusted Data Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        },
        {
          "id": "art-3047",
          "title": "CISA KEV: CVE-2017-9248 \u2014 Progress Telerik UI for ASP.NET AJAX and Sitefinity Cryptographic Weakness Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-03-10"
    },
    {
      "value": "123.20.29.193",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1061",
          "title": "CISA KEV: CVE-2024-57968 \u2014 Advantive VeraCore Unrestricted File Upload Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-03-10",
          "sev": "crit"
        },
        {
          "id": "art-1062",
          "title": "CISA KEV: CVE-2025-25181 \u2014  Advantive VeraCore SQL Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-03-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-03-10"
    },
    {
      "value": "171.227.250.249",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1061",
          "title": "CISA KEV: CVE-2024-57968 \u2014 Advantive VeraCore Unrestricted File Upload Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-03-10",
          "sev": "crit"
        },
        {
          "id": "art-1062",
          "title": "CISA KEV: CVE-2025-25181 \u2014  Advantive VeraCore SQL Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-03-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-03-10"
    },
    {
      "value": "222.253.102.94",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1061",
          "title": "CISA KEV: CVE-2024-57968 \u2014 Advantive VeraCore Unrestricted File Upload Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-03-10",
          "sev": "crit"
        },
        {
          "id": "art-1062",
          "title": "CISA KEV: CVE-2025-25181 \u2014  Advantive VeraCore SQL Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-03-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-03-10"
    },
    {
      "value": "339a79457a8cf3504312d394be3ece98",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1061",
          "title": "CISA KEV: CVE-2024-57968 \u2014 Advantive VeraCore Unrestricted File Upload Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-03-10",
          "sev": "crit"
        },
        {
          "id": "art-1062",
          "title": "CISA KEV: CVE-2025-25181 \u2014  Advantive VeraCore SQL Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-03-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-03-10"
    },
    {
      "value": "457d7e3a708d1b5c6a8d449e52064985",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1061",
          "title": "CISA KEV: CVE-2024-57968 \u2014 Advantive VeraCore Unrestricted File Upload Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-03-10",
          "sev": "crit"
        },
        {
          "id": "art-1062",
          "title": "CISA KEV: CVE-2025-25181 \u2014  Advantive VeraCore SQL Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-03-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-03-10"
    },
    {
      "value": "7a9b5c3bb7dab0857ee2c2d71758eca3",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1061",
          "title": "CISA KEV: CVE-2024-57968 \u2014 Advantive VeraCore Unrestricted File Upload Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-03-10",
          "sev": "crit"
        },
        {
          "id": "art-1062",
          "title": "CISA KEV: CVE-2025-25181 \u2014  Advantive VeraCore SQL Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-03-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-03-10"
    },
    {
      "value": "7abb73b7844f2308d9c62954e6e8b7fc",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1061",
          "title": "CISA KEV: CVE-2024-57968 \u2014 Advantive VeraCore Unrestricted File Upload Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-03-10",
          "sev": "crit"
        },
        {
          "id": "art-1062",
          "title": "CISA KEV: CVE-2025-25181 \u2014  Advantive VeraCore SQL Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-03-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-03-10"
    },
    {
      "value": "7b5b7d96006fec70c2091e90fbf02b99",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1062",
          "title": "CISA KEV: CVE-2025-25181 \u2014  Advantive VeraCore SQL Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-03-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-03-10"
    },
    {
      "value": "032dd95a1299f37aaa76318945e030eb7da94da9",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1061",
          "title": "CISA KEV: CVE-2024-57968 \u2014 Advantive VeraCore Unrestricted File Upload Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-03-10",
          "sev": "crit"
        },
        {
          "id": "art-1062",
          "title": "CISA KEV: CVE-2025-25181 \u2014  Advantive VeraCore SQL Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-03-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-03-10"
    },
    {
      "value": "16db01fe25b0c09e18d13f38c88a4ead5d10e323",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1061",
          "title": "CISA KEV: CVE-2024-57968 \u2014 Advantive VeraCore Unrestricted File Upload Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-03-10",
          "sev": "crit"
        },
        {
          "id": "art-1062",
          "title": "CISA KEV: CVE-2025-25181 \u2014  Advantive VeraCore SQL Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-03-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-03-10"
    },
    {
      "value": "84e7f4ff1f93a4297c2e2c4e54f14edb18396b60",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1061",
          "title": "CISA KEV: CVE-2024-57968 \u2014 Advantive VeraCore Unrestricted File Upload Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-03-10",
          "sev": "crit"
        },
        {
          "id": "art-1062",
          "title": "CISA KEV: CVE-2025-25181 \u2014  Advantive VeraCore SQL Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-03-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-03-10"
    },
    {
      "value": "9e928a26aa3c0e6eb8e709fc55ea12dcf7e02ff9",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1062",
          "title": "CISA KEV: CVE-2025-25181 \u2014  Advantive VeraCore SQL Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-03-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-03-10"
    },
    {
      "value": "ede5ddb97b98d80440553b23dfc19fdb4adc7499",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1061",
          "title": "CISA KEV: CVE-2024-57968 \u2014 Advantive VeraCore Unrestricted File Upload Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-03-10",
          "sev": "crit"
        },
        {
          "id": "art-1062",
          "title": "CISA KEV: CVE-2025-25181 \u2014  Advantive VeraCore SQL Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-03-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-03-10"
    },
    {
      "value": "013ccea1d7fc2aa2d660e900f87a3192f5cb73768710ef2eb9016f81df8e5c70",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1062",
          "title": "CISA KEV: CVE-2025-25181 \u2014  Advantive VeraCore SQL Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-03-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-03-10"
    },
    {
      "value": "322f8cd560d5e10e93af3ea6d3505c8de213f549e6627c3ef4664ed92ba55f56",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1061",
          "title": "CISA KEV: CVE-2024-57968 \u2014 Advantive VeraCore Unrestricted File Upload Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-03-10",
          "sev": "crit"
        },
        {
          "id": "art-1062",
          "title": "CISA KEV: CVE-2025-25181 \u2014  Advantive VeraCore SQL Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-03-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-03-10"
    },
    {
      "value": "38b2d52dc471587fb65ef99c64cb3f69470ddfdaa184a256aecb26edeff3553a",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1061",
          "title": "CISA KEV: CVE-2024-57968 \u2014 Advantive VeraCore Unrestricted File Upload Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-03-10",
          "sev": "crit"
        },
        {
          "id": "art-1062",
          "title": "CISA KEV: CVE-2025-25181 \u2014  Advantive VeraCore SQL Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-03-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-03-10"
    },
    {
      "value": "680b7e8ec8204975c5026bcbaf70f7e9620eacdd7bf72e5476d17266b4a7d316",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1061",
          "title": "CISA KEV: CVE-2024-57968 \u2014 Advantive VeraCore Unrestricted File Upload Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-03-10",
          "sev": "crit"
        },
        {
          "id": "art-1062",
          "title": "CISA KEV: CVE-2025-25181 \u2014  Advantive VeraCore SQL Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-03-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-03-10"
    },
    {
      "value": "884c394c7b3eb757ae57050ac2e6a75385a361555e8e4272de1a3cf24746eec7",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1062",
          "title": "CISA KEV: CVE-2025-25181 \u2014  Advantive VeraCore SQL Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-03-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-03-10"
    },
    {
      "value": "c564acd69efa62a5037931090bf70a6506419fdf59ec52f8d1ab0b15d861cc67",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1061",
          "title": "CISA KEV: CVE-2024-57968 \u2014 Advantive VeraCore Unrestricted File Upload Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-03-10",
          "sev": "crit"
        },
        {
          "id": "art-1062",
          "title": "CISA KEV: CVE-2025-25181 \u2014  Advantive VeraCore SQL Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-03-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-03-10"
    },
    {
      "value": "CVE-2025-22224",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1067",
          "title": "CISA KEV: CVE-2025-22225 \u2014 VMware ESXi Arbitrary Write Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-03-04",
          "sev": "crit"
        },
        {
          "id": "art-1068",
          "title": "CISA KEV: CVE-2025-22224 \u2014 VMware ESXi and Workstation TOCTOU Race Condition Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-03-04",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-03-04"
    },
    {
      "value": "CVE-2025-22225",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1067",
          "title": "CISA KEV: CVE-2025-22225 \u2014 VMware ESXi Arbitrary Write Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-03-04",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-03-04"
    },
    {
      "value": "CVE-2025-22226",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1066",
          "title": "CISA KEV: CVE-2025-22226 \u2014 VMware ESXi, Workstation, and Fusion Information Disclosure Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-03-04",
          "sev": "crit"
        },
        {
          "id": "art-1067",
          "title": "CISA KEV: CVE-2025-22225 \u2014 VMware ESXi Arbitrary Write Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-03-04",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-03-04"
    },
    {
      "value": "2bc5d02774ac1778be22cace51f9e35fe7b53378f8d70143bf646b68d2c0f94c",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1068",
          "title": "CISA KEV: CVE-2025-22224 \u2014 VMware ESXi and Workstation TOCTOU Race Condition Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-03-04",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-03-04"
    },
    {
      "value": "37972a232ac6d8c402ac4531430967c1fd458b74a52d6d1990688d88956791a7",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1068",
          "title": "CISA KEV: CVE-2025-22224 \u2014 VMware ESXi and Workstation TOCTOU Race Condition Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-03-04",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-03-04"
    },
    {
      "value": "4614346fc1ff74f057d189db45aa7dc25d6e7f3d9b68c287a409a53c86dca25e",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1068",
          "title": "CISA KEV: CVE-2025-22224 \u2014 VMware ESXi and Workstation TOCTOU Race Condition Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-03-04",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-03-04"
    },
    {
      "value": "c3f8da7599468c11782c2332497b9e5013d98a1030034243dfed0cf072469c89",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1068",
          "title": "CISA KEV: CVE-2025-22224 \u2014 VMware ESXi and Workstation TOCTOU Race Condition Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-03-04",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-03-04"
    },
    {
      "value": "dc5b8f7c6a8a6764de3309279e3b6412c23e6af1d7a8631c65b80027444d62bb",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1068",
          "title": "CISA KEV: CVE-2025-22224 \u2014 VMware ESXi and Workstation TOCTOU Race Condition Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-03-04",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-03-04"
    },
    {
      "value": "CVE-2018-8639",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1071",
          "title": "CISA KEV: CVE-2018-8639 \u2014 Microsoft Windows Win32k Improper Resource Shutdown or Release Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-03-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-03-03"
    },
    {
      "value": "CVE-2022-43769",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1072",
          "title": "CISA KEV: CVE-2022-43769 \u2014 Hitachi Vantara Pentaho BA Server Special Element Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-03-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-03-03"
    },
    {
      "value": "CVE-2022-43939",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1073",
          "title": "CISA KEV: CVE-2022-43939 \u2014 Hitachi Vantara Pentaho BA Server Authorization Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-03-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-03-03"
    },
    {
      "value": "CVE-2023-20118",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1074",
          "title": "CISA KEV: CVE-2023-20118 \u2014 Cisco Small Business RV Series Routers Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-03-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-03-03"
    },
    {
      "value": "CVE-2024-4885",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1070",
          "title": "CISA KEV: CVE-2024-4885 \u2014 Progress WhatsUp Gold Path Traversal Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-03-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-03-03"
    },
    {
      "value": "aipricadd.top",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1074",
          "title": "CISA KEV: CVE-2023-20118 \u2014 Cisco Small Business RV Series Routers Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-03-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-03-03"
    },
    {
      "value": "asustordownload.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1074",
          "title": "CISA KEV: CVE-2023-20118 \u2014 Cisco Small Business RV Series Routers Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-03-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-03-03"
    },
    {
      "value": "centrequ.cc",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1074",
          "title": "CISA KEV: CVE-2023-20118 \u2014 Cisco Small Business RV Series Routers Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-03-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-03-03"
    },
    {
      "value": "durianlink.cc",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1074",
          "title": "CISA KEV: CVE-2023-20118 \u2014 Cisco Small Business RV Series Routers Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-03-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-03-03"
    },
    {
      "value": "firebasesafer.top",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1074",
          "title": "CISA KEV: CVE-2023-20118 \u2014 Cisco Small Business RV Series Routers Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-03-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-03-03"
    },
    {
      "value": "gardensc.cc",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1074",
          "title": "CISA KEV: CVE-2023-20118 \u2014 Cisco Small Business RV Series Routers Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-03-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-03-03"
    },
    {
      "value": "headached.cc",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1074",
          "title": "CISA KEV: CVE-2023-20118 \u2014 Cisco Small Business RV Series Routers Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-03-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-03-03"
    },
    {
      "value": "hitchil.cc",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1074",
          "title": "CISA KEV: CVE-2023-20118 \u2014 Cisco Small Business RV Series Routers Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-03-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-03-03"
    },
    {
      "value": "icecreand.cc",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1074",
          "title": "CISA KEV: CVE-2023-20118 \u2014 Cisco Small Business RV Series Routers Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-03-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-03-03"
    },
    {
      "value": "landim.cc",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1074",
          "title": "CISA KEV: CVE-2023-20118 \u2014 Cisco Small Business RV Series Routers Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-03-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-03-03"
    },
    {
      "value": "largeroofs.top",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1074",
          "title": "CISA KEV: CVE-2023-20118 \u2014 Cisco Small Business RV Series Routers Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-03-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-03-03"
    },
    {
      "value": "logchim.cc",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1074",
          "title": "CISA KEV: CVE-2023-20118 \u2014 Cisco Small Business RV Series Routers Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-03-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-03-03"
    },
    {
      "value": "longlog.cc",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1074",
          "title": "CISA KEV: CVE-2023-20118 \u2014 Cisco Small Business RV Series Routers Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-03-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-03-03"
    },
    {
      "value": "nternetd.cc",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1074",
          "title": "CISA KEV: CVE-2023-20118 \u2014 Cisco Small Business RV Series Routers Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-03-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-03-03"
    },
    {
      "value": "siotherlentsearsitech.shop",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1074",
          "title": "CISA KEV: CVE-2023-20118 \u2014 Cisco Small Business RV Series Routers Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-03-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-03-03"
    },
    {
      "value": "ssofhoseuegsgrfnu.ru",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1074",
          "title": "CISA KEV: CVE-2023-20118 \u2014 Cisco Small Business RV Series Routers Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-03-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-03-03"
    },
    {
      "value": "suiteiol.cc",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1074",
          "title": "CISA KEV: CVE-2023-20118 \u2014 Cisco Small Business RV Series Routers Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-03-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-03-03"
    },
    {
      "value": "101.99.91.239",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1074",
          "title": "CISA KEV: CVE-2023-20118 \u2014 Cisco Small Business RV Series Routers Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-03-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-03-03"
    },
    {
      "value": "119.8.186.227",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1074",
          "title": "CISA KEV: CVE-2023-20118 \u2014 Cisco Small Business RV Series Routers Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-03-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-03-03"
    },
    {
      "value": "122.8.183.181",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1074",
          "title": "CISA KEV: CVE-2023-20118 \u2014 Cisco Small Business RV Series Routers Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-03-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-03-03"
    },
    {
      "value": "159.138.119.99",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1074",
          "title": "CISA KEV: CVE-2023-20118 \u2014 Cisco Small Business RV Series Routers Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-03-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-03-03"
    },
    {
      "value": "195.123.212.54",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1074",
          "title": "CISA KEV: CVE-2023-20118 \u2014 Cisco Small Business RV Series Routers Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-03-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-03-03"
    },
    {
      "value": "43.129.205.244",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1074",
          "title": "CISA KEV: CVE-2023-20118 \u2014 Cisco Small Business RV Series Routers Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-03-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-03-03"
    },
    {
      "value": "121969d72f8e6f09ad93cf17500c479c452e230e27e7b157d5c9336dff15b6ef",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1074",
          "title": "CISA KEV: CVE-2023-20118 \u2014 Cisco Small Business RV Series Routers Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-03-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-03-03"
    },
    {
      "value": "13cd040a7f488e937b1b234d71a0126b7bc74367bf6538b6961c476f5d620d13",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1074",
          "title": "CISA KEV: CVE-2023-20118 \u2014 Cisco Small Business RV Series Routers Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-03-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-03-03"
    },
    {
      "value": "1ca7262f91d517853a0551b14abb0306c4e3567e41b1e82a018f0aac718e499e",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1074",
          "title": "CISA KEV: CVE-2023-20118 \u2014 Cisco Small Business RV Series Routers Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-03-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-03-03"
    },
    {
      "value": "464f29d5f496b4acffc455330f00adb34ab920c66ca1908eee262339d6946bcd",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1074",
          "title": "CISA KEV: CVE-2023-20118 \u2014 Cisco Small Business RV Series Routers Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-03-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-03-03"
    },
    {
      "value": "932b2545bd6e3ad74b82ca2199944edecf9c92ad3f75fce0d07e04ab084824d5",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1074",
          "title": "CISA KEV: CVE-2023-20118 \u2014 Cisco Small Business RV Series Routers Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-03-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-03-03"
    },
    {
      "value": "eda7cc5e1781c681afe99bf513fcaf5ae86afbf1d84dfd23aa563b1a043cbba8",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1074",
          "title": "CISA KEV: CVE-2023-20118 \u2014 Cisco Small Business RV Series Routers Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-03-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-03-03"
    },
    {
      "value": "CVE-2023-34192",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1079",
          "title": "CISA KEV: CVE-2023-34192 \u2014 Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting (XSS) Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-02-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-02-25"
    },
    {
      "value": "CVE-2024-49035",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1080",
          "title": "CISA KEV: CVE-2024-49035 \u2014 Microsoft Partner Center Improper Access Control Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-02-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-02-25"
    },
    {
      "value": "CVE-2017-3066",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1082",
          "title": "CISA KEV: CVE-2017-3066 \u2014 Adobe ColdFusion Deserialization Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-02-24",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-02-24"
    },
    {
      "value": "CVE-2024-20953",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1081",
          "title": "CISA KEV: CVE-2024-20953 \u2014 Oracle Agile Product Lifecycle Management (PLM) Deserialization Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-02-24",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-02-24"
    },
    {
      "value": "CVE-2025-24989",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1083",
          "title": "CISA KEV: CVE-2025-24989 \u2014 Microsoft Power Pages Improper Access Control Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-02-21",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-02-21"
    },
    {
      "value": "CVE-2022-24439",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-1084",
          "title": "Snyk\u2019s Fetch the Flag CTF is More Than Just a CTF",
          "link": "https://snyk.io/blog/snyks-fetch-the-flag-ctf/",
          "published": "2025-02-20",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-02-20"
    },
    {
      "value": "CVE-2022-33891",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "Snyk",
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1084",
          "title": "Snyk\u2019s Fetch the Flag CTF is More Than Just a CTF",
          "link": "https://snyk.io/blog/snyks-fetch-the-flag-ctf/",
          "published": "2025-02-20",
          "sev": "crit"
        },
        {
          "id": "art-1843",
          "title": "CISA KEV: CVE-2022-33891 \u2014 Apache Spark Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-03-07",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-02-20"
    },
    {
      "value": "CVE-2023-40267",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-1084",
          "title": "Snyk\u2019s Fetch the Flag CTF is More Than Just a CTF",
          "link": "https://snyk.io/blog/snyks-fetch-the-flag-ctf/",
          "published": "2025-02-20",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-02-20"
    },
    {
      "value": "CVE-2024-9474",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1085",
          "title": "CISA KEV: CVE-2025-0111 \u2014 Palo Alto Networks PAN-OS File Read Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-02-20",
          "sev": "crit"
        },
        {
          "id": "art-1087",
          "title": "CISA KEV: CVE-2025-0108 \u2014 Palo Alto Networks PAN-OS Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-02-18",
          "sev": "crit"
        },
        {
          "id": "art-1171",
          "title": "CISA KEV: CVE-2024-9474 \u2014 Palo Alto Networks PAN-OS Management Interface OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-11-18",
          "sev": "crit"
        },
        {
          "id": "art-1172",
          "title": "CISA KEV: CVE-2024-0012 \u2014 Palo Alto Networks PAN-OS Management Interface Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-11-18",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-02-20"
    },
    {
      "value": "CVE-2025-0108",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1085",
          "title": "CISA KEV: CVE-2025-0111 \u2014 Palo Alto Networks PAN-OS File Read Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-02-20",
          "sev": "crit"
        },
        {
          "id": "art-1087",
          "title": "CISA KEV: CVE-2025-0108 \u2014 Palo Alto Networks PAN-OS Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-02-18",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-02-20"
    },
    {
      "value": "CVE-2025-0111",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1085",
          "title": "CISA KEV: CVE-2025-0111 \u2014 Palo Alto Networks PAN-OS File Read Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-02-20",
          "sev": "crit"
        },
        {
          "id": "art-1087",
          "title": "CISA KEV: CVE-2025-0108 \u2014 Palo Alto Networks PAN-OS Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-02-18",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-02-20"
    },
    {
      "value": "CVE-2025-23209",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1086",
          "title": "CISA KEV: CVE-2025-23209 \u2014 Craft CMS Code Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-02-20",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-02-20"
    },
    {
      "value": "CVE-2024-53704",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1088",
          "title": "CISA KEV: CVE-2024-53704 \u2014 SonicWall SonicOS SSLVPN Improper Authentication Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-02-18",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-02-18"
    },
    {
      "value": "CVE-2024-57727",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1089",
          "title": "CISA KEV: CVE-2024-57727 \u2014 SimpleHelp Path Traversal Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-02-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-02-13"
    },
    {
      "value": "CVE-2018-10562",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1092",
          "title": "CISA KEV: CVE-2024-41710 \u2014 Mitel SIP Phones Argument Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-02-12",
          "sev": "crit"
        },
        {
          "id": "art-2374",
          "title": "CISA KEV: CVE-2018-10562 \u2014 Dasan GPON Routers Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-31",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-02-12"
    },
    {
      "value": "CVE-2018-17532",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1092",
          "title": "CISA KEV: CVE-2024-41710 \u2014 Mitel SIP Phones Argument Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-02-12",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-02-12"
    },
    {
      "value": "CVE-2022-31137",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1092",
          "title": "CISA KEV: CVE-2024-41710 \u2014 Mitel SIP Phones Argument Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-02-12",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-02-12"
    },
    {
      "value": "CVE-2023-26801",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1092",
          "title": "CISA KEV: CVE-2024-41710 \u2014 Mitel SIP Phones Argument Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-02-12",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-02-12"
    },
    {
      "value": "CVE-2024-41710",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1092",
          "title": "CISA KEV: CVE-2024-41710 \u2014 Mitel SIP Phones Argument Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-02-12",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-02-12"
    },
    {
      "value": "CVE-2025-24200",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1091",
          "title": "CISA KEV: CVE-2025-24200 \u2014 Apple iOS and iPadOS Incorrect Authorization Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-02-12",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-02-12"
    },
    {
      "value": "GO-2025-3451",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-1090",
          "title": "Do not pass GO - Malicious Package Alert",
          "link": "https://snyk.io/blog/go-malicious-package-alert/",
          "published": "2025-02-12",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-02-12"
    },
    {
      "value": "cardiacpure.ru",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1092",
          "title": "CISA KEV: CVE-2024-41710 \u2014 Mitel SIP Phones Argument Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-02-12",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-02-12"
    },
    {
      "value": "eye-network.ru",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1092",
          "title": "CISA KEV: CVE-2024-41710 \u2014 Mitel SIP Phones Argument Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-02-12",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-02-12"
    },
    {
      "value": "fuerer-net.ru",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1092",
          "title": "CISA KEV: CVE-2024-41710 \u2014 Mitel SIP Phones Argument Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-02-12",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-02-12"
    },
    {
      "value": "github.com/boltdb-go/bolt",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-1090",
          "title": "Do not pass GO - Malicious Package Alert",
          "link": "https://snyk.io/blog/go-malicious-package-alert/",
          "published": "2025-02-12",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-02-12"
    },
    {
      "value": "intenseapi.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1092",
          "title": "CISA KEV: CVE-2024-41710 \u2014 Mitel SIP Phones Argument Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-02-12",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-02-12"
    },
    {
      "value": "49.12.198.231",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-1090",
          "title": "Do not pass GO - Malicious Package Alert",
          "link": "https://snyk.io/blog/go-malicious-package-alert/",
          "published": "2025-02-12",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-02-12"
    },
    {
      "value": "91.92.243.233",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1092",
          "title": "CISA KEV: CVE-2024-41710 \u2014 Mitel SIP Phones Argument Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-02-12",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-02-12"
    },
    {
      "value": "e06c3f5c32aaa422e66056290eb566065afe2ce611fe019f3ba804af939ac1a3",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1092",
          "title": "CISA KEV: CVE-2024-41710 \u2014 Mitel SIP Phones Argument Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-02-12",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-02-12"
    },
    {
      "value": "CVE-2024-40890",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1093",
          "title": "CISA KEV: CVE-2024-40891 \u2014 Zyxel DSL CPE OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-02-11",
          "sev": "crit"
        },
        {
          "id": "art-1094",
          "title": "CISA KEV: CVE-2024-40890 \u2014 Zyxel DSL CPE OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-02-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-02-11"
    },
    {
      "value": "CVE-2024-40891",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1093",
          "title": "CISA KEV: CVE-2024-40891 \u2014 Zyxel DSL CPE OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-02-11",
          "sev": "crit"
        },
        {
          "id": "art-1094",
          "title": "CISA KEV: CVE-2024-40890 \u2014 Zyxel DSL CPE OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-02-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-02-11"
    },
    {
      "value": "CVE-2025-0890",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1093",
          "title": "CISA KEV: CVE-2024-40891 \u2014 Zyxel DSL CPE OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-02-11",
          "sev": "crit"
        },
        {
          "id": "art-1094",
          "title": "CISA KEV: CVE-2024-40890 \u2014 Zyxel DSL CPE OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-02-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-02-11"
    },
    {
      "value": "CVE-2025-21391",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1096",
          "title": "CISA KEV: CVE-2025-21391 \u2014 Microsoft Windows Storage Link Following Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-02-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-02-11"
    },
    {
      "value": "CVE-2025-21418",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1095",
          "title": "CISA KEV: CVE-2025-21418 \u2014 Microsoft Windows Ancillary Function Driver for WinSock Heap-Based Buffer Overflow Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-02-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-02-11"
    },
    {
      "value": "CVE-2025-0994",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1097",
          "title": "CISA KEV: CVE-2025-0994 \u2014 Trimble Cityworks Deserialization Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-02-07",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-02-07"
    },
    {
      "value": "cdn.lgaircon.xyz",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1097",
          "title": "CISA KEV: CVE-2025-0994 \u2014 Trimble Cityworks Deserialization Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-02-07",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-02-07"
    },
    {
      "value": "cdn.phototagx.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1097",
          "title": "CISA KEV: CVE-2025-0994 \u2014 Trimble Cityworks Deserialization Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-02-07",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-02-07"
    },
    {
      "value": "lgaircon.xyz",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1097",
          "title": "CISA KEV: CVE-2025-0994 \u2014 Trimble Cityworks Deserialization Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-02-07",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-02-07"
    },
    {
      "value": "www.roomako.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1097",
          "title": "CISA KEV: CVE-2025-0994 \u2014 Trimble Cityworks Deserialization Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-02-07",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-02-07"
    },
    {
      "value": "192.210.239.172",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1097",
          "title": "CISA KEV: CVE-2025-0994 \u2014 Trimble Cityworks Deserialization Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-02-07",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-02-07"
    },
    {
      "value": "14ed3878b6623c287283a8a80020f68e1cb6bfc37b236f33a95f3a64c4f4611f",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1097",
          "title": "CISA KEV: CVE-2025-0994 \u2014 Trimble Cityworks Deserialization Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-02-07",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-02-07"
    },
    {
      "value": "1c38e3cda8ac6d79d9da40834367697a209c6b07e6b3ab93b3a4f375b161a901",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1097",
          "title": "CISA KEV: CVE-2025-0994 \u2014 Trimble Cityworks Deserialization Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-02-07",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-02-07"
    },
    {
      "value": "1de72c03927bcd2810ce98205ff871ef1ebf4344fba187e126e50caa1e43250b",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1097",
          "title": "CISA KEV: CVE-2025-0994 \u2014 Trimble Cityworks Deserialization Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-02-07",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-02-07"
    },
    {
      "value": "4ffc33bdc8527a2e8cb87e49cdc16c3b1480dfc135e507d552f581a67d1850a9",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1097",
          "title": "CISA KEV: CVE-2025-0994 \u2014 Trimble Cityworks Deserialization Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-02-07",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-02-07"
    },
    {
      "value": "c02d50d0eb3974818091b8dd91a8bbb8cdefd94d4568a4aea8e1dcdd8869f738",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1097",
          "title": "CISA KEV: CVE-2025-0994 \u2014 Trimble Cityworks Deserialization Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-02-07",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-02-07"
    },
    {
      "value": "CVE-2020-15069",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1099",
          "title": "CISA KEV: CVE-2020-15069 \u2014 Sophos XG Firewall Buffer Overflow Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-02-06",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-02-06"
    },
    {
      "value": "CVE-2020-29574",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1100",
          "title": "CISA KEV: CVE-2020-29574 \u2014 CyberoamOS (CROS) SQL Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-02-06",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-02-06"
    },
    {
      "value": "CVE-2022-23748",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1102",
          "title": "CISA KEV: CVE-2022-23748 \u2014 Dante Discovery Process Control Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-02-06",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-02-06"
    },
    {
      "value": "CVE-2024-21413",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1101",
          "title": "CISA KEV: CVE-2024-21413 \u2014 Microsoft Outlook Improper Input Validation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-02-06",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-02-06"
    },
    {
      "value": "CVE-2025-0411",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1103",
          "title": "CISA KEV: CVE-2025-0411 \u2014 7-Zip Mark of the Web Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-02-06",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-02-06"
    },
    {
      "value": "7786501e3666c1a5071c9c5e5a019e2bc86a1f169d469cc4bfef2fe339aaf384",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1103",
          "title": "CISA KEV: CVE-2025-0411 \u2014 7-Zip Mark of the Web Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-02-06",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-02-06"
    },
    {
      "value": "84ab6c3e1f2dc98cf4d5b8b739237570416bb82e2edaf078e9868663553c5412",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1103",
          "title": "CISA KEV: CVE-2025-0411 \u2014 7-Zip Mark of the Web Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-02-06",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-02-06"
    },
    {
      "value": "CVE-2018-19410",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1107",
          "title": "CISA KEV: CVE-2018-19410 \u2014 Paessler PRTG Network Monitor Local File Inclusion Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-02-04",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-02-04"
    },
    {
      "value": "CVE-2018-9276",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1108",
          "title": "CISA KEV: CVE-2018-9276 \u2014 Paessler PRTG Network Monitor OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-02-04",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-02-04"
    },
    {
      "value": "CVE-2024-29059",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1109",
          "title": "CISA KEV: CVE-2024-29059 \u2014 Microsoft .NET Framework Information Disclosure Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-02-04",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-02-04"
    },
    {
      "value": "CVE-2024-45195",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1110",
          "title": "CISA KEV: CVE-2024-45195 \u2014 Apache OFBiz Forced Browsing Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-02-04",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-02-04"
    },
    {
      "value": "CVE-2025-24085",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1111",
          "title": "CISA KEV: CVE-2025-24085 \u2014 Apple Multiple Products Use-After-Free Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-01-29",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-01-29"
    },
    {
      "value": "CVE-2025-23006",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1112",
          "title": "CISA KEV: CVE-2025-23006 \u2014 SonicWall SMA1000 Appliances Deserialization Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-01-24",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-01-24"
    },
    {
      "value": "CVE-2020-11023",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1115",
          "title": "CISA KEV: CVE-2020-11023 \u2014 JQuery Cross-Site Scripting (XSS) Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-01-23",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-01-23"
    },
    {
      "value": "CVE-2024-50603",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1118",
          "title": "CISA KEV: CVE-2024-50603 \u2014 Aviatrix Controllers OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-01-16",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-01-16"
    },
    {
      "value": "107.172.43.186",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1118",
          "title": "CISA KEV: CVE-2024-50603 \u2014 Aviatrix Controllers OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-01-16",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-01-16"
    },
    {
      "value": "172.104.60.176",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1118",
          "title": "CISA KEV: CVE-2024-50603 \u2014 Aviatrix Controllers OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-01-16",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-01-16"
    },
    {
      "value": "83.222.191.91",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1118",
          "title": "CISA KEV: CVE-2024-50603 \u2014 Aviatrix Controllers OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-01-16",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-01-16"
    },
    {
      "value": "91.188.254.21",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1118",
          "title": "CISA KEV: CVE-2024-50603 \u2014 Aviatrix Controllers OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-01-16",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-01-16"
    },
    {
      "value": "1ce0c293f2042b677cd55a393913ec052eded4b9",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1118",
          "title": "CISA KEV: CVE-2024-50603 \u2014 Aviatrix Controllers OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-01-16",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-01-16"
    },
    {
      "value": "41d589a077038048c4b120494719c905e71485ba",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1118",
          "title": "CISA KEV: CVE-2024-50603 \u2014 Aviatrix Controllers OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-01-16",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-01-16"
    },
    {
      "value": "68d88d1918676c87dcd39c7581c3910a9eb94882",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1118",
          "title": "CISA KEV: CVE-2024-50603 \u2014 Aviatrix Controllers OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-01-16",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-01-16"
    },
    {
      "value": "c4f63a3a6cb6b8aae133bd4c5ac6f2fc9020c349",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1118",
          "title": "CISA KEV: CVE-2024-50603 \u2014 Aviatrix Controllers OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-01-16",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-01-16"
    },
    {
      "value": "c63f646edfddb4232afa5618e3fac4eee1b4b115",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1118",
          "title": "CISA KEV: CVE-2024-50603 \u2014 Aviatrix Controllers OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-01-16",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-01-16"
    },
    {
      "value": "e10e750115bf2ae29a8ce8f9fa14e09e66534a15",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1118",
          "title": "CISA KEV: CVE-2024-50603 \u2014 Aviatrix Controllers OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-01-16",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-01-16"
    },
    {
      "value": "CVE-2025-21333",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1122",
          "title": "CISA KEV: CVE-2025-21335 \u2014 Microsoft Windows Hyper-V NT Kernel Integration VSP Use-After-Free Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-01-14",
          "sev": "crit"
        },
        {
          "id": "art-1123",
          "title": "CISA KEV: CVE-2025-21334 \u2014 Microsoft Windows Hyper-V NT Kernel Integration VSP Use-After-Free Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-01-14",
          "sev": "crit"
        },
        {
          "id": "art-1124",
          "title": "CISA KEV: CVE-2025-21333 \u2014 Microsoft Windows Hyper-V NT Kernel Integration VSP Heap-based Buffer Overflow Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-01-14",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-01-14"
    },
    {
      "value": "CVE-2025-21334",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1122",
          "title": "CISA KEV: CVE-2025-21335 \u2014 Microsoft Windows Hyper-V NT Kernel Integration VSP Use-After-Free Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-01-14",
          "sev": "crit"
        },
        {
          "id": "art-1123",
          "title": "CISA KEV: CVE-2025-21334 \u2014 Microsoft Windows Hyper-V NT Kernel Integration VSP Use-After-Free Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-01-14",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-01-14"
    },
    {
      "value": "CVE-2025-21335",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1122",
          "title": "CISA KEV: CVE-2025-21335 \u2014 Microsoft Windows Hyper-V NT Kernel Integration VSP Use-After-Free Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-01-14",
          "sev": "crit"
        },
        {
          "id": "art-1123",
          "title": "CISA KEV: CVE-2025-21334 \u2014 Microsoft Windows Hyper-V NT Kernel Integration VSP Use-After-Free Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-01-14",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-01-14"
    },
    {
      "value": "137.184.65.71",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1125",
          "title": "CISA KEV: CVE-2024-55591 \u2014 Fortinet FortiOS and FortiProxy Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-01-14",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-01-14"
    },
    {
      "value": "157.245.3.251",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1125",
          "title": "CISA KEV: CVE-2024-55591 \u2014 Fortinet FortiOS and FortiProxy Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-01-14",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-01-14"
    },
    {
      "value": "167.71.245.10",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1125",
          "title": "CISA KEV: CVE-2024-55591 \u2014 Fortinet FortiOS and FortiProxy Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-01-14",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-01-14"
    },
    {
      "value": "23.27.140.65",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1125",
          "title": "CISA KEV: CVE-2024-55591 \u2014 Fortinet FortiOS and FortiProxy Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-01-14",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-01-14"
    },
    {
      "value": "31.192.107.165",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1125",
          "title": "CISA KEV: CVE-2024-55591 \u2014 Fortinet FortiOS and FortiProxy Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-01-14",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-01-14"
    },
    {
      "value": "37.19.196.65",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1125",
          "title": "CISA KEV: CVE-2024-55591 \u2014 Fortinet FortiOS and FortiProxy Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-01-14",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-01-14"
    },
    {
      "value": "64.190.113.25",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1125",
          "title": "CISA KEV: CVE-2024-55591 \u2014 Fortinet FortiOS and FortiProxy Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-01-14",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-01-14"
    },
    {
      "value": "66.135.27.178",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1125",
          "title": "CISA KEV: CVE-2024-55591 \u2014 Fortinet FortiOS and FortiProxy Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-01-14",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-01-14"
    },
    {
      "value": "CVE-2023-41265",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1126",
          "title": "CISA KEV: CVE-2023-48365 \u2014 Qlik Sense HTTP Tunneling Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-01-13",
          "sev": "crit"
        },
        {
          "id": "art-1482",
          "title": "CISA KEV: CVE-2023-41266 \u2014 Qlik Sense Path Traversal Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-12-07",
          "sev": "crit"
        },
        {
          "id": "art-1483",
          "title": "CISA KEV: CVE-2023-41265 \u2014 Qlik Sense HTTP Tunneling Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-12-07",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-01-13"
    },
    {
      "value": "CVE-2023-41266",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1126",
          "title": "CISA KEV: CVE-2023-48365 \u2014 Qlik Sense HTTP Tunneling Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-01-13",
          "sev": "crit"
        },
        {
          "id": "art-1482",
          "title": "CISA KEV: CVE-2023-41266 \u2014 Qlik Sense Path Traversal Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-12-07",
          "sev": "crit"
        },
        {
          "id": "art-1483",
          "title": "CISA KEV: CVE-2023-41265 \u2014 Qlik Sense HTTP Tunneling Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-12-07",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-01-13"
    },
    {
      "value": "CVE-2023-48365",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1126",
          "title": "CISA KEV: CVE-2023-48365 \u2014 Qlik Sense HTTP Tunneling Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-01-13",
          "sev": "crit"
        },
        {
          "id": "art-1482",
          "title": "CISA KEV: CVE-2023-41266 \u2014 Qlik Sense Path Traversal Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-12-07",
          "sev": "crit"
        },
        {
          "id": "art-1483",
          "title": "CISA KEV: CVE-2023-41265 \u2014 Qlik Sense HTTP Tunneling Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-12-07",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-01-13"
    },
    {
      "value": "CVE-2024-12356",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1127",
          "title": "CISA KEV: CVE-2024-12686 \u2014 BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-01-13",
          "sev": "crit"
        },
        {
          "id": "art-1138",
          "title": "CISA KEV: CVE-2024-12356 \u2014 BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) Command Injection Vulnerability ",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-12-19",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-01-13"
    },
    {
      "value": "CVE-2024-12686",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1127",
          "title": "CISA KEV: CVE-2024-12686 \u2014 BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-01-13",
          "sev": "crit"
        },
        {
          "id": "art-1138",
          "title": "CISA KEV: CVE-2024-12356 \u2014 BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) Command Injection Vulnerability ",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-12-19",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-01-13"
    },
    {
      "value": "q983.requestcatcher.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1126",
          "title": "CISA KEV: CVE-2023-48365 \u2014 Qlik Sense HTTP Tunneling Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-01-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-01-13"
    },
    {
      "value": "zohoservice.net",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1126",
          "title": "CISA KEV: CVE-2023-48365 \u2014 Qlik Sense HTTP Tunneling Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-01-13",
          "sev": "crit"
        },
        {
          "id": "art-1482",
          "title": "CISA KEV: CVE-2023-41266 \u2014 Qlik Sense Path Traversal Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-12-07",
          "sev": "crit"
        },
        {
          "id": "art-1483",
          "title": "CISA KEV: CVE-2023-41265 \u2014 Qlik Sense HTTP Tunneling Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-12-07",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-01-13"
    },
    {
      "value": "144.172.122.30",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1126",
          "title": "CISA KEV: CVE-2023-48365 \u2014 Qlik Sense HTTP Tunneling Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-01-13",
          "sev": "crit"
        },
        {
          "id": "art-1482",
          "title": "CISA KEV: CVE-2023-41266 \u2014 Qlik Sense Path Traversal Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-12-07",
          "sev": "crit"
        },
        {
          "id": "art-1483",
          "title": "CISA KEV: CVE-2023-41265 \u2014 Qlik Sense HTTP Tunneling Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-12-07",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-01-13"
    },
    {
      "value": "216.107.136.46",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1126",
          "title": "CISA KEV: CVE-2023-48365 \u2014 Qlik Sense HTTP Tunneling Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-01-13",
          "sev": "crit"
        },
        {
          "id": "art-1482",
          "title": "CISA KEV: CVE-2023-41266 \u2014 Qlik Sense Path Traversal Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-12-07",
          "sev": "crit"
        },
        {
          "id": "art-1483",
          "title": "CISA KEV: CVE-2023-41265 \u2014 Qlik Sense HTTP Tunneling Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-12-07",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-01-13"
    },
    {
      "value": "45.61.147.176",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1126",
          "title": "CISA KEV: CVE-2023-48365 \u2014 Qlik Sense HTTP Tunneling Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-01-13",
          "sev": "crit"
        },
        {
          "id": "art-1482",
          "title": "CISA KEV: CVE-2023-41266 \u2014 Qlik Sense Path Traversal Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-12-07",
          "sev": "crit"
        },
        {
          "id": "art-1483",
          "title": "CISA KEV: CVE-2023-41265 \u2014 Qlik Sense HTTP Tunneling Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-12-07",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-01-13"
    },
    {
      "value": "94.156.71.115",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1126",
          "title": "CISA KEV: CVE-2023-48365 \u2014 Qlik Sense HTTP Tunneling Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-01-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-01-13"
    },
    {
      "value": "CVE-2025-0282",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1130",
          "title": "CISA KEV: CVE-2025-0282 \u2014 Ivanti Connect Secure, Policy Secure, and ZTA Gateways Stack-Based Buffer Overflow Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-01-08",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-01-08"
    },
    {
      "value": "CVE-2025-0283",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1130",
          "title": "CISA KEV: CVE-2025-0282 \u2014 Ivanti Connect Secure, Policy Secure, and ZTA Gateways Stack-Based Buffer Overflow Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-01-08",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-01-08"
    },
    {
      "value": "61bb586dc4e047ab081ef6ca65684e48",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1130",
          "title": "CISA KEV: CVE-2025-0282 \u2014 Ivanti Connect Secure, Policy Secure, and ZTA Gateways Stack-Based Buffer Overflow Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-01-08",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-01-08"
    },
    {
      "value": "a638fd203ddb540d0484d8e00490df06",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1130",
          "title": "CISA KEV: CVE-2025-0282 \u2014 Ivanti Connect Secure, Policy Secure, and ZTA Gateways Stack-Based Buffer Overflow Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-01-08",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-01-08"
    },
    {
      "value": "d18e5425ecd9608ecb992606b974e15d",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1130",
          "title": "CISA KEV: CVE-2025-0282 \u2014 Ivanti Connect Secure, Policy Secure, and ZTA Gateways Stack-Based Buffer Overflow Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-01-08",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-01-08"
    },
    {
      "value": "e7d24813535f74187db31d4114f607a1",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1130",
          "title": "CISA KEV: CVE-2025-0282 \u2014 Ivanti Connect Secure, Policy Secure, and ZTA Gateways Stack-Based Buffer Overflow Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-01-08",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-01-08"
    },
    {
      "value": "CVE-2020-2555",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1131",
          "title": "CISA KEV: CVE-2020-2883 \u2014 Oracle WebLogic Server Unspecified Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-01-07",
          "sev": "crit"
        },
        {
          "id": "art-3005",
          "title": "CISA KEV: CVE-2020-2555 \u2014 Oracle Multiple Products Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-01-07"
    },
    {
      "value": "CVE-2020-2883",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1131",
          "title": "CISA KEV: CVE-2020-2883 \u2014 Oracle WebLogic Server Unspecified Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-01-07",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-01-07"
    },
    {
      "value": "CVE-2024-41713",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1132",
          "title": "CISA KEV: CVE-2024-55550 \u2014 Mitel MiCollab Path Traversal Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-01-07",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-01-07"
    },
    {
      "value": "CVE-2024-55550",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1132",
          "title": "CISA KEV: CVE-2024-55550 \u2014 Mitel MiCollab Path Traversal Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2025-01-07",
          "sev": "crit"
        }
      ],
      "first_seen": "2025-01-07"
    },
    {
      "value": "CVE-2024-3393",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1135",
          "title": "CISA KEV: CVE-2024-3393 \u2014 Palo Alto Networks PAN-OS Malicious DNS Packet Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-12-30",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-12-30"
    },
    {
      "value": "CVE-2020-0688",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1137",
          "title": "CISA KEV: CVE-2021-44207 \u2014 Acclaim Systems USAHERDS Use of Hard-Coded Credentials Vulnerability ",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-12-23",
          "sev": "crit"
        },
        {
          "id": "art-2946",
          "title": "CISA KEV: CVE-2020-0688 \u2014 Microsoft Exchange Server Validation Key Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-12-23"
    },
    {
      "value": "CVE-2021-44207",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1137",
          "title": "CISA KEV: CVE-2021-44207 \u2014 Acclaim Systems USAHERDS Use of Hard-Coded Credentials Vulnerability ",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-12-23",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-12-23"
    },
    {
      "value": "CVE-2021-44228",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV",
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-1137",
          "title": "CISA KEV: CVE-2021-44207 \u2014 Acclaim Systems USAHERDS Use of Hard-Coded Credentials Vulnerability ",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-12-23",
          "sev": "crit"
        },
        {
          "id": "art-1264",
          "title": "The persistent threat: Why major vulnerabilities like Log4Shell and Spring4Shell remain significant",
          "link": "https://snyk.io/blog/log4shell-spring4shell-threat/",
          "published": "2024-08-29",
          "sev": "high"
        },
        {
          "id": "art-1770",
          "title": "CISA KEV: CVE-2021-45046 \u2014 Apache Log4j2 Deserialization of Untrusted Data Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-05-01",
          "sev": "crit"
        },
        {
          "id": "art-1907",
          "title": "Snyk in 30: Open source security for Atlassian Bitbucket Cloud",
          "link": "https://snyk.io/blog/snyk-open-source-security-atlassian-bitbucket/",
          "published": "2022-12-15",
          "sev": "high"
        },
        {
          "id": "art-1918",
          "title": "Using Snyk reporting for data-driven security",
          "link": "https://snyk.io/blog/using-snyk-reporting-for-data-driven-security/",
          "published": "2022-12-09",
          "sev": "high"
        },
        {
          "id": "art-1937",
          "title": "How Atlassian used Snyk to solve Log4Shell",
          "link": "https://snyk.io/blog/how-atlassian-used-snyk-to-solve-log4shell/",
          "published": "2022-11-16",
          "sev": "high"
        },
        {
          "id": "art-2099",
          "title": "Controlling your server with a reverse shell attack",
          "link": "https://snyk.io/blog/reverse-shell-attack/",
          "published": "2022-08-10",
          "sev": "crit"
        },
        {
          "id": "art-2121",
          "title": "Improving developer experience with security tools at Pinterest",
          "link": "https://snyk.io/blog/improving-developer-experience-with-security-tools-at-pinterest/",
          "published": "2022-07-14",
          "sev": "high"
        },
        {
          "id": "art-2269",
          "title": "How LiveRamp used Snyk to remediate Log4Shell",
          "link": "https://snyk.io/blog/liveramp-used-snyk-to-remediate-log4shell/",
          "published": "2022-05-19",
          "sev": "high"
        },
        {
          "id": "art-2500",
          "title": "Build a software bill of materials (SBOM) for open source supply chain security",
          "link": "https://snyk.io/blog/building-sbom-open-source-supply-chain-security/",
          "published": "2022-03-14",
          "sev": "high"
        },
        {
          "id": "art-2505",
          "title": "Simplifying container security with Snyk\u2019s security expertise",
          "link": "https://snyk.io/blog/simplifying-container-security-snyk-expertise/",
          "published": "2022-03-08",
          "sev": "high"
        },
        {
          "id": "art-2636",
          "title": "Teaming up with Sysdig to deliver developer and runtime Kubernetes security",
          "link": "https://snyk.io/blog/snyk-teaming-up-with-sysdig/",
          "published": "2022-02-16",
          "sev": "high"
        },
        {
          "id": "art-2672",
          "title": "Log4Shell remediation with Snyk by the numbers",
          "link": "https://snyk.io/blog/log4shell-remediation-with-snyk-by-the-numbers/",
          "published": "2022-02-05",
          "sev": "high"
        },
        {
          "id": "art-2688",
          "title": "Stranger Danger: Live hack of how a Log4Shell exploit works",
          "link": "https://snyk.io/blog/stranger-danger-live-hack-log4shell-exploit/",
          "published": "2022-01-25",
          "sev": "crit"
        },
        {
          "id": "art-2693",
          "title": "CISA KEV: CVE-2021-35247 \u2014 SolarWinds Serv-U Improper Input Validation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-01-21",
          "sev": "crit"
        },
        {
          "id": "art-2714",
          "title": "The Secure Developer: 2021 in review",
          "link": "https://snyk.io/blog/the-secure-developer-2021-in-review/",
          "published": "2022-01-12",
          "sev": "crit"
        },
        {
          "id": "art-2733",
          "title": "FTC highlights the importance of securing Log4j and software supply chain",
          "link": "https://snyk.io/blog/ftc-warning-securing-log4j-software-supply-chain/",
          "published": "2022-01-07",
          "sev": "high"
        },
        {
          "id": "art-2740",
          "title": "It takes a community: Responding to open source criticism post-Log4Shell",
          "link": "https://snyk.io/blog/responding-to-open-source-criticism-post-log4shell/",
          "published": "2021-12-24",
          "sev": "high"
        },
        {
          "id": "art-2745",
          "title": "Snyk makes it easier to fix Log4Shell with extended free scans",
          "link": "https://snyk.io/blog/snyk-fix-log4shell-extended-free-scans/",
          "published": "2021-12-21",
          "sev": "high"
        },
        {
          "id": "art-2747",
          "title": "Log4j 2.16 High Severity Vulnerability (CVE-2021-45105) Discovered",
          "link": "https://snyk.io/blog/log4j-2-16-vulnerability-cve-2021-45105-discovered/",
          "published": "2021-12-18",
          "sev": "high"
        },
        {
          "id": "art-2748",
          "title": "Find Log4Shell vulnerabilities in your unmanaged and shaded jars with the Snyk CLI",
          "link": "https://snyk.io/blog/new-snyk-cli-command-finds-log4shell-in-unmanaged-undeclared-java-code/",
          "published": "2021-12-18",
          "sev": "high"
        },
        {
          "id": "art-2749",
          "title": "Log4j 2.15 vulnerability CVE-2021-45046 upgraded to a critical severity arbitrary code execution",
          "link": "https://snyk.io/blog/log4j-2-15-vulnerability-cve-2021-45046-critical-ace/",
          "published": "2021-12-17",
          "sev": "high"
        },
        {
          "id": "art-2750",
          "title": "Security in context: When is a CVE not a CVE?",
          "link": "https://snyk.io/blog/when-is-a-cve-not-a-cve/",
          "published": "2021-12-17",
          "sev": "high"
        },
        {
          "id": "art-2751",
          "title": "Log4Shell in a nutshell (for non-developers & non-Java developers)",
          "link": "https://snyk.io/blog/log4shell-in-a-nutshell/",
          "published": "2021-12-15",
          "sev": "high"
        },
        {
          "id": "art-2756",
          "title": "The Log4j vulnerability and its impact on software supply chain security",
          "link": "https://snyk.io/blog/log4j-vulnerability-software-supply-chain-security-log4shell/",
          "published": "2021-12-13",
          "sev": "high"
        },
        {
          "id": "art-2757",
          "title": "Find and fix the Log4Shell exploit fast with Snyk",
          "link": "https://snyk.io/blog/find-fix-log4shell-quickly-snyk/",
          "published": "2021-12-13",
          "sev": "high"
        },
        {
          "id": "art-2758",
          "title": "Log4j vulnerability explained: Prevent Log4Shell RCE by updating to version 2.17.1",
          "link": "https://snyk.io/blog/log4j-rce-log4shell-vulnerability-cve-2021-44228/",
          "published": "2021-12-10",
          "sev": "crit"
        },
        {
          "id": "art-2772",
          "title": "CISA KEV: CVE-2021-44228 \u2014 Apache Log4j2 Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-12-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-12-23"
    },
    {
      "value": "afdentry.workstation.eu.org",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1137",
          "title": "CISA KEV: CVE-2021-44207 \u2014 Acclaim Systems USAHERDS Use of Hard-Coded Credentials Vulnerability ",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-12-23",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-12-23"
    },
    {
      "value": "cdn.ns.time12.cf",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1137",
          "title": "CISA KEV: CVE-2021-44207 \u2014 Acclaim Systems USAHERDS Use of Hard-Coded Credentials Vulnerability ",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-12-23",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-12-23"
    },
    {
      "value": "east.winsproxy.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1137",
          "title": "CISA KEV: CVE-2021-44207 \u2014 Acclaim Systems USAHERDS Use of Hard-Coded Credentials Vulnerability ",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-12-23",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-12-23"
    },
    {
      "value": "ns1.entrydns.eu.org",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1137",
          "title": "CISA KEV: CVE-2021-44207 \u2014 Acclaim Systems USAHERDS Use of Hard-Coded Credentials Vulnerability ",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-12-23",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-12-23"
    },
    {
      "value": "subnet.milli-seconds.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1137",
          "title": "CISA KEV: CVE-2021-44207 \u2014 Acclaim Systems USAHERDS Use of Hard-Coded Credentials Vulnerability ",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-12-23",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-12-23"
    },
    {
      "value": "work.queryip.cf",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1137",
          "title": "CISA KEV: CVE-2021-44207 \u2014 Acclaim Systems USAHERDS Use of Hard-Coded Credentials Vulnerability ",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-12-23",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-12-23"
    },
    {
      "value": "work.viewdns.ml",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1137",
          "title": "CISA KEV: CVE-2021-44207 \u2014 Acclaim Systems USAHERDS Use of Hard-Coded Credentials Vulnerability ",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-12-23",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-12-23"
    },
    {
      "value": "107.172.210.69",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1137",
          "title": "CISA KEV: CVE-2021-44207 \u2014 Acclaim Systems USAHERDS Use of Hard-Coded Credentials Vulnerability ",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-12-23",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-12-23"
    },
    {
      "value": "149.28.15.152",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1137",
          "title": "CISA KEV: CVE-2021-44207 \u2014 Acclaim Systems USAHERDS Use of Hard-Coded Credentials Vulnerability ",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-12-23",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-12-23"
    },
    {
      "value": "172.104.206.48",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1137",
          "title": "CISA KEV: CVE-2021-44207 \u2014 Acclaim Systems USAHERDS Use of Hard-Coded Credentials Vulnerability ",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-12-23",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-12-23"
    },
    {
      "value": "18.118.56.237",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1137",
          "title": "CISA KEV: CVE-2021-44207 \u2014 Acclaim Systems USAHERDS Use of Hard-Coded Credentials Vulnerability ",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-12-23",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-12-23"
    },
    {
      "value": "185.118.167.40",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1137",
          "title": "CISA KEV: CVE-2021-44207 \u2014 Acclaim Systems USAHERDS Use of Hard-Coded Credentials Vulnerability ",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-12-23",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-12-23"
    },
    {
      "value": "194.156.98.12",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1137",
          "title": "CISA KEV: CVE-2021-44207 \u2014 Acclaim Systems USAHERDS Use of Hard-Coded Credentials Vulnerability ",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-12-23",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-12-23"
    },
    {
      "value": "194.195.125.121",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1137",
          "title": "CISA KEV: CVE-2021-44207 \u2014 Acclaim Systems USAHERDS Use of Hard-Coded Credentials Vulnerability ",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-12-23",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-12-23"
    },
    {
      "value": "20.121.42.11",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1137",
          "title": "CISA KEV: CVE-2021-44207 \u2014 Acclaim Systems USAHERDS Use of Hard-Coded Credentials Vulnerability ",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-12-23",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-12-23"
    },
    {
      "value": "34.139.13.46",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1137",
          "title": "CISA KEV: CVE-2021-44207 \u2014 Acclaim Systems USAHERDS Use of Hard-Coded Credentials Vulnerability ",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-12-23",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-12-23"
    },
    {
      "value": "45.153.231.31",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1137",
          "title": "CISA KEV: CVE-2021-44207 \u2014 Acclaim Systems USAHERDS Use of Hard-Coded Credentials Vulnerability ",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-12-23",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-12-23"
    },
    {
      "value": "45.84.1.181",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1137",
          "title": "CISA KEV: CVE-2021-44207 \u2014 Acclaim Systems USAHERDS Use of Hard-Coded Credentials Vulnerability ",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-12-23",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-12-23"
    },
    {
      "value": "54.248.110.45",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1137",
          "title": "CISA KEV: CVE-2021-44207 \u2014 Acclaim Systems USAHERDS Use of Hard-Coded Credentials Vulnerability ",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-12-23",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-12-23"
    },
    {
      "value": "54.80.67.241",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1137",
          "title": "CISA KEV: CVE-2021-44207 \u2014 Acclaim Systems USAHERDS Use of Hard-Coded Credentials Vulnerability ",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-12-23",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-12-23"
    },
    {
      "value": "67.205.132.162",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1137",
          "title": "CISA KEV: CVE-2021-44207 \u2014 Acclaim Systems USAHERDS Use of Hard-Coded Credentials Vulnerability ",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-12-23",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-12-23"
    },
    {
      "value": "143278845a3f5276a1dd5860e7488313",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1137",
          "title": "CISA KEV: CVE-2021-44207 \u2014 Acclaim Systems USAHERDS Use of Hard-Coded Credentials Vulnerability ",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-12-23",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-12-23"
    },
    {
      "value": "49f1daea8a115dd6fce51a1328d863cf",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1137",
          "title": "CISA KEV: CVE-2021-44207 \u2014 Acclaim Systems USAHERDS Use of Hard-Coded Credentials Vulnerability ",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-12-23",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-12-23"
    },
    {
      "value": "900ca3ee85dfc109baeed4888ccb5d39",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1137",
          "title": "CISA KEV: CVE-2021-44207 \u2014 Acclaim Systems USAHERDS Use of Hard-Coded Credentials Vulnerability ",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-12-23",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-12-23"
    },
    {
      "value": "b108b28138b93ec4822e165b82e41c7a",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1137",
          "title": "CISA KEV: CVE-2021-44207 \u2014 Acclaim Systems USAHERDS Use of Hard-Coded Credentials Vulnerability ",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-12-23",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-12-23"
    },
    {
      "value": "b82456963d04f44e83442b6393face47",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1137",
          "title": "CISA KEV: CVE-2021-44207 \u2014 Acclaim Systems USAHERDS Use of Hard-Coded Credentials Vulnerability ",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-12-23",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-12-23"
    },
    {
      "value": "355b3ff61db44d18003537be8496eb03536e300f",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1137",
          "title": "CISA KEV: CVE-2021-44207 \u2014 Acclaim Systems USAHERDS Use of Hard-Coded Credentials Vulnerability ",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-12-23",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-12-23"
    },
    {
      "value": "6f6b51e6c88e5252a2a117ca1cfb57934930166b",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1137",
          "title": "CISA KEV: CVE-2021-44207 \u2014 Acclaim Systems USAHERDS Use of Hard-Coded Credentials Vulnerability ",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-12-23",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-12-23"
    },
    {
      "value": "7056b044f97e3e349e3e0183311bb44b0bc3464f",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1137",
          "title": "CISA KEV: CVE-2021-44207 \u2014 Acclaim Systems USAHERDS Use of Hard-Coded Credentials Vulnerability ",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-12-23",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-12-23"
    },
    {
      "value": "996aa691bbc1250b571a2f5423a5d5e2da8317e6",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1137",
          "title": "CISA KEV: CVE-2021-44207 \u2014 Acclaim Systems USAHERDS Use of Hard-Coded Credentials Vulnerability ",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-12-23",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-12-23"
    },
    {
      "value": "e85427af661fe5e853c8c9398dc46ddde50e2241",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1137",
          "title": "CISA KEV: CVE-2021-44207 \u2014 Acclaim Systems USAHERDS Use of Hard-Coded Credentials Vulnerability ",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-12-23",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-12-23"
    },
    {
      "value": "062a7399100454c7a523a938293bef7ddb0bc10636fd402be5f9797d8cc3c57e",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1137",
          "title": "CISA KEV: CVE-2021-44207 \u2014 Acclaim Systems USAHERDS Use of Hard-Coded Credentials Vulnerability ",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-12-23",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-12-23"
    },
    {
      "value": "a4647fcb35c79f26354c34452e4a03a1e4e338a80b2c29db97bba4088a208ad0",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1137",
          "title": "CISA KEV: CVE-2021-44207 \u2014 Acclaim Systems USAHERDS Use of Hard-Coded Credentials Vulnerability ",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-12-23",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-12-23"
    },
    {
      "value": "d7e8cc6c19ceebf0e125c9f18b50167c0ee65294b3fce179fdab560e3e8e0192",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1137",
          "title": "CISA KEV: CVE-2021-44207 \u2014 Acclaim Systems USAHERDS Use of Hard-Coded Credentials Vulnerability ",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-12-23",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-12-23"
    },
    {
      "value": "e024ccc4c72eb5813cc2b6db7975e4750337a1cc619d7339b21fdbb32d93fd85",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1137",
          "title": "CISA KEV: CVE-2021-44207 \u2014 Acclaim Systems USAHERDS Use of Hard-Coded Credentials Vulnerability ",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-12-23",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-12-23"
    },
    {
      "value": "ebf28e56ae5873102b51da2cc49cbbe43192ca2f318c4dfc874448d9b85ebd00",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1137",
          "title": "CISA KEV: CVE-2021-44207 \u2014 Acclaim Systems USAHERDS Use of Hard-Coded Credentials Vulnerability ",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-12-23",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-12-23"
    },
    {
      "value": "CVE-2011-5325",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1142",
          "title": "CISA KEV: CVE-2022-23227 \u2014 NUUO NVRmini2 Devices Missing Authentication Vulnerability ",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-12-18",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-12-18"
    },
    {
      "value": "CVE-2018-14933",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1143",
          "title": "CISA KEV: CVE-2018-14933 \u2014 NUUO NVRmini Devices OS Command Injection Vulnerability ",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-12-18",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-12-18"
    },
    {
      "value": "CVE-2019-11001",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1141",
          "title": "CISA KEV: CVE-2019-11001 \u2014 Reolink Multiple IP Cameras OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-12-18",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-12-18"
    },
    {
      "value": "CVE-2021-40407",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1140",
          "title": "CISA KEV: CVE-2021-40407 \u2014 Reolink RLC-410W IP Camera OS Command Injection Vulnerability ",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-12-18",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-12-18"
    },
    {
      "value": "CVE-2022-23227",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1142",
          "title": "CISA KEV: CVE-2022-23227 \u2014 NUUO NVRmini2 Devices Missing Authentication Vulnerability ",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-12-18",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-12-18"
    },
    {
      "value": "CVE-2024-50623",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1144",
          "title": "CISA KEV: CVE-2024-55956 \u2014 Cleo Multiple Products Unauthenticated File Upload Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-12-17",
          "sev": "crit"
        },
        {
          "id": "art-1147",
          "title": "CISA KEV: CVE-2024-50623 \u2014 Cleo Multiple Products Unrestricted File Upload Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-12-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-12-17"
    },
    {
      "value": "CVE-2024-55956",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1144",
          "title": "CISA KEV: CVE-2024-55956 \u2014 Cleo Multiple Products Unauthenticated File Upload Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-12-17",
          "sev": "crit"
        },
        {
          "id": "art-1147",
          "title": "CISA KEV: CVE-2024-50623 \u2014 Cleo Multiple Products Unrestricted File Upload Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-12-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-12-17"
    },
    {
      "value": "176.123.10.115",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1144",
          "title": "CISA KEV: CVE-2024-55956 \u2014 Cleo Multiple Products Unauthenticated File Upload Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-12-17",
          "sev": "crit"
        },
        {
          "id": "art-1147",
          "title": "CISA KEV: CVE-2024-50623 \u2014 Cleo Multiple Products Unrestricted File Upload Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-12-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-12-17"
    },
    {
      "value": "176.123.5.126",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1144",
          "title": "CISA KEV: CVE-2024-55956 \u2014 Cleo Multiple Products Unauthenticated File Upload Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-12-17",
          "sev": "crit"
        },
        {
          "id": "art-1147",
          "title": "CISA KEV: CVE-2024-50623 \u2014 Cleo Multiple Products Unrestricted File Upload Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-12-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-12-17"
    },
    {
      "value": "181.214.147.164",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1144",
          "title": "CISA KEV: CVE-2024-55956 \u2014 Cleo Multiple Products Unauthenticated File Upload Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-12-17",
          "sev": "crit"
        },
        {
          "id": "art-1147",
          "title": "CISA KEV: CVE-2024-50623 \u2014 Cleo Multiple Products Unrestricted File Upload Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-12-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-12-17"
    },
    {
      "value": "185.162.128.133",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1144",
          "title": "CISA KEV: CVE-2024-55956 \u2014 Cleo Multiple Products Unauthenticated File Upload Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-12-17",
          "sev": "crit"
        },
        {
          "id": "art-1147",
          "title": "CISA KEV: CVE-2024-50623 \u2014 Cleo Multiple Products Unrestricted File Upload Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-12-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-12-17"
    },
    {
      "value": "185.163.204.137",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1144",
          "title": "CISA KEV: CVE-2024-55956 \u2014 Cleo Multiple Products Unauthenticated File Upload Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-12-17",
          "sev": "crit"
        },
        {
          "id": "art-1147",
          "title": "CISA KEV: CVE-2024-50623 \u2014 Cleo Multiple Products Unrestricted File Upload Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-12-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-12-17"
    },
    {
      "value": "185.181.230.103",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1144",
          "title": "CISA KEV: CVE-2024-55956 \u2014 Cleo Multiple Products Unauthenticated File Upload Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-12-17",
          "sev": "crit"
        },
        {
          "id": "art-1147",
          "title": "CISA KEV: CVE-2024-50623 \u2014 Cleo Multiple Products Unrestricted File Upload Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-12-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-12-17"
    },
    {
      "value": "192.119.99.42",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1144",
          "title": "CISA KEV: CVE-2024-55956 \u2014 Cleo Multiple Products Unauthenticated File Upload Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-12-17",
          "sev": "crit"
        },
        {
          "id": "art-1147",
          "title": "CISA KEV: CVE-2024-50623 \u2014 Cleo Multiple Products Unrestricted File Upload Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-12-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-12-17"
    },
    {
      "value": "209.127.12.38",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1144",
          "title": "CISA KEV: CVE-2024-55956 \u2014 Cleo Multiple Products Unauthenticated File Upload Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-12-17",
          "sev": "crit"
        },
        {
          "id": "art-1147",
          "title": "CISA KEV: CVE-2024-50623 \u2014 Cleo Multiple Products Unrestricted File Upload Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-12-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-12-17"
    },
    {
      "value": "45.182.189.102",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1144",
          "title": "CISA KEV: CVE-2024-55956 \u2014 Cleo Multiple Products Unauthenticated File Upload Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-12-17",
          "sev": "crit"
        },
        {
          "id": "art-1147",
          "title": "CISA KEV: CVE-2024-50623 \u2014 Cleo Multiple Products Unrestricted File Upload Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-12-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-12-17"
    },
    {
      "value": "5.149.249.226",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1144",
          "title": "CISA KEV: CVE-2024-55956 \u2014 Cleo Multiple Products Unauthenticated File Upload Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-12-17",
          "sev": "crit"
        },
        {
          "id": "art-1147",
          "title": "CISA KEV: CVE-2024-50623 \u2014 Cleo Multiple Products Unrestricted File Upload Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-12-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-12-17"
    },
    {
      "value": "89.248.172.139",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1144",
          "title": "CISA KEV: CVE-2024-55956 \u2014 Cleo Multiple Products Unauthenticated File Upload Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-12-17",
          "sev": "crit"
        },
        {
          "id": "art-1147",
          "title": "CISA KEV: CVE-2024-50623 \u2014 Cleo Multiple Products Unrestricted File Upload Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-12-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-12-17"
    },
    {
      "value": "CVE-2023-26347",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1146",
          "title": "CISA KEV: CVE-2024-20767 \u2014 Adobe ColdFusion Improper Access Control Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-12-16",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-12-16"
    },
    {
      "value": "CVE-2023-26359",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1146",
          "title": "CISA KEV: CVE-2024-20767 \u2014 Adobe ColdFusion Improper Access Control Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-12-16",
          "sev": "crit"
        },
        {
          "id": "art-1628",
          "title": "CISA KEV: CVE-2023-26359 \u2014 Adobe ColdFusion Deserialization of Untrusted Data Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-08-21",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-12-16"
    },
    {
      "value": "CVE-2023-29298",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1146",
          "title": "CISA KEV: CVE-2024-20767 \u2014 Adobe ColdFusion Improper Access Control Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-12-16",
          "sev": "crit"
        },
        {
          "id": "art-1460",
          "title": "CISA KEV: CVE-2023-29300 \u2014 Adobe ColdFusion Deserialization of Untrusted Data Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-01-08",
          "sev": "crit"
        },
        {
          "id": "art-1461",
          "title": "CISA KEV: CVE-2023-38203 \u2014 Adobe ColdFusion Deserialization of Untrusted Data Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-01-08",
          "sev": "crit"
        },
        {
          "id": "art-1656",
          "title": "CISA KEV: CVE-2023-29298 \u2014 Adobe ColdFusion Improper Access Control Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-07-20",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-12-16"
    },
    {
      "value": "CVE-2023-29300",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1146",
          "title": "CISA KEV: CVE-2024-20767 \u2014 Adobe ColdFusion Improper Access Control Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-12-16",
          "sev": "crit"
        },
        {
          "id": "art-1460",
          "title": "CISA KEV: CVE-2023-29300 \u2014 Adobe ColdFusion Deserialization of Untrusted Data Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-01-08",
          "sev": "crit"
        },
        {
          "id": "art-1461",
          "title": "CISA KEV: CVE-2023-38203 \u2014 Adobe ColdFusion Deserialization of Untrusted Data Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-01-08",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-12-16"
    },
    {
      "value": "CVE-2023-38203",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1146",
          "title": "CISA KEV: CVE-2024-20767 \u2014 Adobe ColdFusion Improper Access Control Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-12-16",
          "sev": "crit"
        },
        {
          "id": "art-1460",
          "title": "CISA KEV: CVE-2023-29300 \u2014 Adobe ColdFusion Deserialization of Untrusted Data Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-01-08",
          "sev": "crit"
        },
        {
          "id": "art-1461",
          "title": "CISA KEV: CVE-2023-38203 \u2014 Adobe ColdFusion Deserialization of Untrusted Data Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-01-08",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-12-16"
    },
    {
      "value": "CVE-2023-38204",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1146",
          "title": "CISA KEV: CVE-2024-20767 \u2014 Adobe ColdFusion Improper Access Control Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-12-16",
          "sev": "crit"
        },
        {
          "id": "art-1461",
          "title": "CISA KEV: CVE-2023-38203 \u2014 Adobe ColdFusion Deserialization of Untrusted Data Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-01-08",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-12-16"
    },
    {
      "value": "CVE-2023-38205",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1146",
          "title": "CISA KEV: CVE-2024-20767 \u2014 Adobe ColdFusion Improper Access Control Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-12-16",
          "sev": "crit"
        },
        {
          "id": "art-1657",
          "title": "CISA KEV: CVE-2023-38205 \u2014 Adobe ColdFusion Improper Access Control Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-07-20",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-12-16"
    },
    {
      "value": "CVE-2023-44352",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1146",
          "title": "CISA KEV: CVE-2024-20767 \u2014 Adobe ColdFusion Improper Access Control Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-12-16",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-12-16"
    },
    {
      "value": "CVE-2023-44353",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1146",
          "title": "CISA KEV: CVE-2024-20767 \u2014 Adobe ColdFusion Improper Access Control Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-12-16",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-12-16"
    },
    {
      "value": "CVE-2024-20767",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1146",
          "title": "CISA KEV: CVE-2024-20767 \u2014 Adobe ColdFusion Improper Access Control Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-12-16",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-12-16"
    },
    {
      "value": "CVE-2024-35250",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1145",
          "title": "CISA KEV: CVE-2024-35250 \u2014 Microsoft Windows Kernel-Mode Driver Untrusted Pointer Dereference Vulnerability ",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-12-16",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-12-16"
    },
    {
      "value": "oast.fun",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1146",
          "title": "CISA KEV: CVE-2024-20767 \u2014 Adobe ColdFusion Improper Access Control Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-12-16",
          "sev": "crit"
        },
        {
          "id": "art-1250",
          "title": "CISA KEV: CVE-2024-8190 \u2014 Ivanti Cloud Services Appliance OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-09-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-12-16"
    },
    {
      "value": "oast.live",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1146",
          "title": "CISA KEV: CVE-2024-20767 \u2014 Adobe ColdFusion Improper Access Control Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-12-16",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-12-16"
    },
    {
      "value": "oast.me",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1146",
          "title": "CISA KEV: CVE-2024-20767 \u2014 Adobe ColdFusion Improper Access Control Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-12-16",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-12-16"
    },
    {
      "value": "oast.online",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1146",
          "title": "CISA KEV: CVE-2024-20767 \u2014 Adobe ColdFusion Improper Access Control Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-12-16",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-12-16"
    },
    {
      "value": "oast.pro",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1146",
          "title": "CISA KEV: CVE-2024-20767 \u2014 Adobe ColdFusion Improper Access Control Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-12-16",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-12-16"
    },
    {
      "value": "oast.site",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1146",
          "title": "CISA KEV: CVE-2024-20767 \u2014 Adobe ColdFusion Improper Access Control Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-12-16",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-12-16"
    },
    {
      "value": "134.122.136.119",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1146",
          "title": "CISA KEV: CVE-2024-20767 \u2014 Adobe ColdFusion Improper Access Control Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-12-16",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-12-16"
    },
    {
      "value": "134.122.136.96",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1146",
          "title": "CISA KEV: CVE-2024-20767 \u2014 Adobe ColdFusion Improper Access Control Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-12-16",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-12-16"
    },
    {
      "value": "172.81.132.99",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1146",
          "title": "CISA KEV: CVE-2024-20767 \u2014 Adobe ColdFusion Improper Access Control Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-12-16",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-12-16"
    },
    {
      "value": "23.234.85.20",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1146",
          "title": "CISA KEV: CVE-2024-20767 \u2014 Adobe ColdFusion Improper Access Control Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-12-16",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-12-16"
    },
    {
      "value": "38.225.206.87",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1146",
          "title": "CISA KEV: CVE-2024-20767 \u2014 Adobe ColdFusion Improper Access Control Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-12-16",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-12-16"
    },
    {
      "value": "38.225.206.88",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1146",
          "title": "CISA KEV: CVE-2024-20767 \u2014 Adobe ColdFusion Improper Access Control Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-12-16",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-12-16"
    },
    {
      "value": "connect.consrensys.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-1149",
          "title": "Ultralytics AI Pwn Request Supply Chain Attack",
          "link": "https://snyk.io/blog/ultralytics-ai-pwn-request-supply-chain-attack/",
          "published": "2024-12-11",
          "sev": "high"
        }
      ],
      "first_seen": "2024-12-11"
    },
    {
      "value": "webhook.site/1e6c12e8-aaeb-4349-98ad-a7196e632c5a",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-1149",
          "title": "Ultralytics AI Pwn Request Supply Chain Attack",
          "link": "https://snyk.io/blog/ultralytics-ai-pwn-request-supply-chain-attack/",
          "published": "2024-12-11",
          "sev": "high"
        }
      ],
      "first_seen": "2024-12-11"
    },
    {
      "value": "webhook.site/ecd706a0-f207-4df2-b639-d326ef3c2fe1",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-1149",
          "title": "Ultralytics AI Pwn Request Supply Chain Attack",
          "link": "https://snyk.io/blog/ultralytics-ai-pwn-request-supply-chain-attack/",
          "published": "2024-12-11",
          "sev": "high"
        }
      ],
      "first_seen": "2024-12-11"
    },
    {
      "value": "059beed5bcdfea16c05b4d45560c97abfd4af3de",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-1149",
          "title": "Ultralytics AI Pwn Request Supply Chain Attack",
          "link": "https://snyk.io/blog/ultralytics-ai-pwn-request-supply-chain-attack/",
          "published": "2024-12-11",
          "sev": "high"
        }
      ],
      "first_seen": "2024-12-11"
    },
    {
      "value": "62b6532384bdd9b96af5ac684d87f52efb48f7de",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-1149",
          "title": "Ultralytics AI Pwn Request Supply Chain Attack",
          "link": "https://snyk.io/blog/ultralytics-ai-pwn-request-supply-chain-attack/",
          "published": "2024-12-11",
          "sev": "high"
        }
      ],
      "first_seen": "2024-12-11"
    },
    {
      "value": "7c6136cf4e857582c2f086673359be94e7e4b702",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-1149",
          "title": "Ultralytics AI Pwn Request Supply Chain Attack",
          "link": "https://snyk.io/blog/ultralytics-ai-pwn-request-supply-chain-attack/",
          "published": "2024-12-11",
          "sev": "high"
        }
      ],
      "first_seen": "2024-12-11"
    },
    {
      "value": "96f496ac5c64f3c884676dd99d6edbe7fa596255",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-1149",
          "title": "Ultralytics AI Pwn Request Supply Chain Attack",
          "link": "https://snyk.io/blog/ultralytics-ai-pwn-request-supply-chain-attack/",
          "published": "2024-12-11",
          "sev": "high"
        }
      ],
      "first_seen": "2024-12-11"
    },
    {
      "value": "a1f1e3ede7c7e6ae650a294630214ce7fa596255",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-1149",
          "title": "Ultralytics AI Pwn Request Supply Chain Attack",
          "link": "https://snyk.io/blog/ultralytics-ai-pwn-request-supply-chain-attack/",
          "published": "2024-12-11",
          "sev": "high"
        }
      ],
      "first_seen": "2024-12-11"
    },
    {
      "value": "bea3060707e6f3fec47aa2af64ea2e774b56e9f5",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-1149",
          "title": "Ultralytics AI Pwn Request Supply Chain Attack",
          "link": "https://snyk.io/blog/ultralytics-ai-pwn-request-supply-chain-attack/",
          "published": "2024-12-11",
          "sev": "high"
        }
      ],
      "first_seen": "2024-12-11"
    },
    {
      "value": "dd0577b10e73792f2b2315af63b872fe4123ec9c",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-1149",
          "title": "Ultralytics AI Pwn Request Supply Chain Attack",
          "link": "https://snyk.io/blog/ultralytics-ai-pwn-request-supply-chain-attack/",
          "published": "2024-12-11",
          "sev": "high"
        }
      ],
      "first_seen": "2024-12-11"
    },
    {
      "value": "ee304a92a9e68e7923d7a37a370c7556ac596250",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-1149",
          "title": "Ultralytics AI Pwn Request Supply Chain Attack",
          "link": "https://snyk.io/blog/ultralytics-ai-pwn-request-supply-chain-attack/",
          "published": "2024-12-11",
          "sev": "high"
        }
      ],
      "first_seen": "2024-12-11"
    },
    {
      "value": "15bcffd83cda47082acb081eaf7270a38c497b3a2bc6e917582bda8a5b0f7bab",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-1149",
          "title": "Ultralytics AI Pwn Request Supply Chain Attack",
          "link": "https://snyk.io/blog/ultralytics-ai-pwn-request-supply-chain-attack/",
          "published": "2024-12-11",
          "sev": "high"
        }
      ],
      "first_seen": "2024-12-11"
    },
    {
      "value": "4347625838a5cb0e9d29f3ec76ed8365b31b281103b716952bf64d37cf309785",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-1149",
          "title": "Ultralytics AI Pwn Request Supply Chain Attack",
          "link": "https://snyk.io/blog/ultralytics-ai-pwn-request-supply-chain-attack/",
          "published": "2024-12-11",
          "sev": "high"
        }
      ],
      "first_seen": "2024-12-11"
    },
    {
      "value": "6a9d121f538cad60cabd9369a951ec4405a081c664311a90537f0a7a61b0f3e5",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-1149",
          "title": "Ultralytics AI Pwn Request Supply Chain Attack",
          "link": "https://snyk.io/blog/ultralytics-ai-pwn-request-supply-chain-attack/",
          "published": "2024-12-11",
          "sev": "high"
        }
      ],
      "first_seen": "2024-12-11"
    },
    {
      "value": "b0e1ae6d73d656b203514f498b59cbcf29f067edf6fbd3803a3de7d21960848d",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-1149",
          "title": "Ultralytics AI Pwn Request Supply Chain Attack",
          "link": "https://snyk.io/blog/ultralytics-ai-pwn-request-supply-chain-attack/",
          "published": "2024-12-11",
          "sev": "high"
        }
      ],
      "first_seen": "2024-12-11"
    },
    {
      "value": "b6ea1681855ec2f73c643ea2acfcf7ae084a9648f888d4bd1e3e119ec15c3495",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-1149",
          "title": "Ultralytics AI Pwn Request Supply Chain Attack",
          "link": "https://snyk.io/blog/ultralytics-ai-pwn-request-supply-chain-attack/",
          "published": "2024-12-11",
          "sev": "high"
        }
      ],
      "first_seen": "2024-12-11"
    },
    {
      "value": "c9c3401536fd9a0b6012aec9169d2c1fc1368b7073503384cfc0b38c47b1d7e1",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-1149",
          "title": "Ultralytics AI Pwn Request Supply Chain Attack",
          "link": "https://snyk.io/blog/ultralytics-ai-pwn-request-supply-chain-attack/",
          "published": "2024-12-11",
          "sev": "high"
        }
      ],
      "first_seen": "2024-12-11"
    },
    {
      "value": "e9d538203ac43e9df11b68803470c116b7bb02881cd06175b0edfc4438d4d1a2",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-1149",
          "title": "Ultralytics AI Pwn Request Supply Chain Attack",
          "link": "https://snyk.io/blog/ultralytics-ai-pwn-request-supply-chain-attack/",
          "published": "2024-12-11",
          "sev": "high"
        }
      ],
      "first_seen": "2024-12-11"
    },
    {
      "value": "ec12cd32729e8abea5258478731e70ccc5a7c6c4847dde78488b8dd0b91b8555",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-1149",
          "title": "Ultralytics AI Pwn Request Supply Chain Attack",
          "link": "https://snyk.io/blog/ultralytics-ai-pwn-request-supply-chain-attack/",
          "published": "2024-12-11",
          "sev": "high"
        }
      ],
      "first_seen": "2024-12-11"
    },
    {
      "value": "f08d47cb3e1e848b5607ac44baedf1754b201b6b90dfc527d6cefab1dd2d2c23",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-1149",
          "title": "Ultralytics AI Pwn Request Supply Chain Attack",
          "link": "https://snyk.io/blog/ultralytics-ai-pwn-request-supply-chain-attack/",
          "published": "2024-12-11",
          "sev": "high"
        }
      ],
      "first_seen": "2024-12-11"
    },
    {
      "value": "CVE-2024-49138",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1151",
          "title": "CISA KEV: CVE-2024-49138 \u2014 Microsoft Windows Common Log File System (CLFS) Driver Heap-Based Buffer Overflow Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-12-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-12-10"
    },
    {
      "value": "CVE-2024-51378",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1153",
          "title": "CISA KEV: CVE-2024-51378 \u2014 CyberPanel Incorrect Default Permissions Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-12-04",
          "sev": "crit"
        },
        {
          "id": "art-1186",
          "title": "CISA KEV: CVE-2024-51567 \u2014 CyberPanel Incorrect Default Permissions Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-11-07",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-12-04"
    },
    {
      "value": "CVE-2023-28461",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1158",
          "title": "CISA KEV: CVE-2023-45727 \u2014 North Grid Proself Improper Restriction of XML External Entity (XXE) Reference Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-12-03",
          "sev": "crit"
        },
        {
          "id": "art-1162",
          "title": "CISA KEV: CVE-2023-28461 \u2014 Array Networks AG and vxAG ArrayOS Missing Authentication for Critical Function Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-11-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-12-03"
    },
    {
      "value": "CVE-2023-45727",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1158",
          "title": "CISA KEV: CVE-2023-45727 \u2014 North Grid Proself Improper Restriction of XML External Entity (XXE) Reference Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-12-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-12-03"
    },
    {
      "value": "CVE-2024-11667",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1156",
          "title": "CISA KEV: CVE-2024-11667 \u2014 Zyxel Multiple Firewalls Path Traversal Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-12-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-12-03"
    },
    {
      "value": "CVE-2024-11680",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1157",
          "title": "CISA KEV: CVE-2024-11680 \u2014 ProjectSend Improper Authentication Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-12-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-12-03"
    },
    {
      "value": "CVE-2024-42057",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1156",
          "title": "CISA KEV: CVE-2024-11667 \u2014 Zyxel Multiple Firewalls Path Traversal Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-12-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-12-03"
    },
    {
      "value": "0bfe25de8c46834e9a7c216f99057d855e272eafafdfef98a6012cecbbdcfabf",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1156",
          "title": "CISA KEV: CVE-2024-11667 \u2014 Zyxel Multiple Firewalls Path Traversal Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-12-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-12-03"
    },
    {
      "value": "2621c5c7e1c12560c6062fdf2eeeb815de4ce3856376022a1a9f8421b4bae8e1",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1156",
          "title": "CISA KEV: CVE-2024-11667 \u2014 Zyxel Multiple Firewalls Path Traversal Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-12-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-12-03"
    },
    {
      "value": "2b15e09b98bc2835a4430c4560d3f5b25011141c9efa4331f66e9a707e2a23c0",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1156",
          "title": "CISA KEV: CVE-2024-11667 \u2014 Zyxel Multiple Firewalls Path Traversal Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-12-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-12-03"
    },
    {
      "value": "3e3fad9888856ce195c9c239ad014074f687ba288c78ef26660be93ddd97289e",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1156",
          "title": "CISA KEV: CVE-2024-11667 \u2014 Zyxel Multiple Firewalls Path Traversal Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-12-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-12-03"
    },
    {
      "value": "47635e2cf9d41cab4b73f2a37e6a59a7de29428b75a7b4481205aee4330d4d19",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1156",
          "title": "CISA KEV: CVE-2024-11667 \u2014 Zyxel Multiple Firewalls Path Traversal Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-12-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-12-03"
    },
    {
      "value": "67aea3de7ab23b72e02347cbf6514f28fb726d313e62934b5de6d154215ee733",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1156",
          "title": "CISA KEV: CVE-2024-11667 \u2014 Zyxel Multiple Firewalls Path Traversal Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-12-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-12-03"
    },
    {
      "value": "6ef9a0b6301d737763f6c59ae6d5b3be4cf38941a69517be0f069d0a35f394dd",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1156",
          "title": "CISA KEV: CVE-2024-11667 \u2014 Zyxel Multiple Firewalls Path Traversal Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-12-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-12-03"
    },
    {
      "value": "7731d73e048a351205615821b90ed4f2507abc65acf4d6fe30ecdb211f0b0872",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1156",
          "title": "CISA KEV: CVE-2024-11667 \u2014 Zyxel Multiple Firewalls Path Traversal Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-12-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-12-03"
    },
    {
      "value": "7cd7c04c62d2a8b4697ceebbe7dd95c910d687e4a6989c1d839117e55c1cafd7",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1156",
          "title": "CISA KEV: CVE-2024-11667 \u2014 Zyxel Multiple Firewalls Path Traversal Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-12-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-12-03"
    },
    {
      "value": "9ab19741ac36e198fb2fd912620bf320aa7fdeeeb8d4a9e956f3eb3d2092c92c",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1156",
          "title": "CISA KEV: CVE-2024-11667 \u2014 Zyxel Multiple Firewalls Path Traversal Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-12-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-12-03"
    },
    {
      "value": "cb48e4298b216ae532cfd3c89c8f2cbd1e32bb402866d2c81682c6671aa4f8ea",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1156",
          "title": "CISA KEV: CVE-2024-11667 \u2014 Zyxel Multiple Firewalls Path Traversal Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-12-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-12-03"
    },
    {
      "value": "ccd78d3eba6c53959835c6407d81262d3094e8d06bf2712fefa4b04baadd4bfe",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1156",
          "title": "CISA KEV: CVE-2024-11667 \u2014 Zyxel Multiple Firewalls Path Traversal Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-12-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-12-03"
    },
    {
      "value": "CVE-2024-21287",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1164",
          "title": "CISA KEV: CVE-2024-21287 \u2014 Oracle Agile Product Lifecycle Management (PLM) Incorrect Authorization Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-11-21",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-11-21"
    },
    {
      "value": "CVE-2024-44308",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1165",
          "title": "CISA KEV: CVE-2024-44309 \u2014 Apple Multiple Products Cross-Site Scripting (XSS) Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-11-21",
          "sev": "crit"
        },
        {
          "id": "art-1166",
          "title": "CISA KEV: CVE-2024-44308 \u2014 Apple Multiple Products Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-11-21",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-11-21"
    },
    {
      "value": "CVE-2024-44309",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1165",
          "title": "CISA KEV: CVE-2024-44309 \u2014 Apple Multiple Products Cross-Site Scripting (XSS) Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-11-21",
          "sev": "crit"
        },
        {
          "id": "art-1166",
          "title": "CISA KEV: CVE-2024-44308 \u2014 Apple Multiple Products Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-11-21",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-11-21"
    },
    {
      "value": "CVE-2024-38812",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1167",
          "title": "CISA KEV: CVE-2024-38813 \u2014 VMware vCenter Server Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-11-20",
          "sev": "crit"
        },
        {
          "id": "art-1168",
          "title": "CISA KEV: CVE-2024-38812 \u2014 VMware vCenter Server Heap-Based Buffer Overflow Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-11-20",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-11-20"
    },
    {
      "value": "CVE-2024-38813",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1167",
          "title": "CISA KEV: CVE-2024-38813 \u2014 VMware vCenter Server Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-11-20",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-11-20"
    },
    {
      "value": "CVE-2024-0012",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1171",
          "title": "CISA KEV: CVE-2024-9474 \u2014 Palo Alto Networks PAN-OS Management Interface OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-11-18",
          "sev": "crit"
        },
        {
          "id": "art-1172",
          "title": "CISA KEV: CVE-2024-0012 \u2014 Palo Alto Networks PAN-OS Management Interface Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-11-18",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-11-18"
    },
    {
      "value": "CVE-2024-1212",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1173",
          "title": "CISA KEV: CVE-2024-1212 \u2014 Progress Kemp LoadMaster OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-11-18",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-11-18"
    },
    {
      "value": "103.112.106.17",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1171",
          "title": "CISA KEV: CVE-2024-9474 \u2014 Palo Alto Networks PAN-OS Management Interface OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-11-18",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-11-18"
    },
    {
      "value": "104.28.208.123",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1171",
          "title": "CISA KEV: CVE-2024-9474 \u2014 Palo Alto Networks PAN-OS Management Interface OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-11-18",
          "sev": "crit"
        },
        {
          "id": "art-1172",
          "title": "CISA KEV: CVE-2024-0012 \u2014 Palo Alto Networks PAN-OS Management Interface Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-11-18",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-11-18"
    },
    {
      "value": "104.28.240.123",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1171",
          "title": "CISA KEV: CVE-2024-9474 \u2014 Palo Alto Networks PAN-OS Management Interface OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-11-18",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-11-18"
    },
    {
      "value": "136.144.17.146",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1171",
          "title": "CISA KEV: CVE-2024-9474 \u2014 Palo Alto Networks PAN-OS Management Interface OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-11-18",
          "sev": "crit"
        },
        {
          "id": "art-1172",
          "title": "CISA KEV: CVE-2024-0012 \u2014 Palo Alto Networks PAN-OS Management Interface Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-11-18",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-11-18"
    },
    {
      "value": "136.144.17.149",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1171",
          "title": "CISA KEV: CVE-2024-9474 \u2014 Palo Alto Networks PAN-OS Management Interface OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-11-18",
          "sev": "crit"
        },
        {
          "id": "art-1172",
          "title": "CISA KEV: CVE-2024-0012 \u2014 Palo Alto Networks PAN-OS Management Interface Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-11-18",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-11-18"
    },
    {
      "value": "136.144.17.154",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1171",
          "title": "CISA KEV: CVE-2024-9474 \u2014 Palo Alto Networks PAN-OS Management Interface OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-11-18",
          "sev": "crit"
        },
        {
          "id": "art-1172",
          "title": "CISA KEV: CVE-2024-0012 \u2014 Palo Alto Networks PAN-OS Management Interface Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-11-18",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-11-18"
    },
    {
      "value": "136.144.17.158",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1171",
          "title": "CISA KEV: CVE-2024-9474 \u2014 Palo Alto Networks PAN-OS Management Interface OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-11-18",
          "sev": "crit"
        },
        {
          "id": "art-1172",
          "title": "CISA KEV: CVE-2024-0012 \u2014 Palo Alto Networks PAN-OS Management Interface Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-11-18",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-11-18"
    },
    {
      "value": "136.144.17.161",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1171",
          "title": "CISA KEV: CVE-2024-9474 \u2014 Palo Alto Networks PAN-OS Management Interface OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-11-18",
          "sev": "crit"
        },
        {
          "id": "art-1172",
          "title": "CISA KEV: CVE-2024-0012 \u2014 Palo Alto Networks PAN-OS Management Interface Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-11-18",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-11-18"
    },
    {
      "value": "136.144.17.164",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1171",
          "title": "CISA KEV: CVE-2024-9474 \u2014 Palo Alto Networks PAN-OS Management Interface OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-11-18",
          "sev": "crit"
        },
        {
          "id": "art-1172",
          "title": "CISA KEV: CVE-2024-0012 \u2014 Palo Alto Networks PAN-OS Management Interface Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-11-18",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-11-18"
    },
    {
      "value": "136.144.17.166",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1171",
          "title": "CISA KEV: CVE-2024-9474 \u2014 Palo Alto Networks PAN-OS Management Interface OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-11-18",
          "sev": "crit"
        },
        {
          "id": "art-1172",
          "title": "CISA KEV: CVE-2024-0012 \u2014 Palo Alto Networks PAN-OS Management Interface Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-11-18",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-11-18"
    },
    {
      "value": "136.144.17.167",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1171",
          "title": "CISA KEV: CVE-2024-9474 \u2014 Palo Alto Networks PAN-OS Management Interface OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-11-18",
          "sev": "crit"
        },
        {
          "id": "art-1172",
          "title": "CISA KEV: CVE-2024-0012 \u2014 Palo Alto Networks PAN-OS Management Interface Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-11-18",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-11-18"
    },
    {
      "value": "136.144.17.170",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1171",
          "title": "CISA KEV: CVE-2024-9474 \u2014 Palo Alto Networks PAN-OS Management Interface OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-11-18",
          "sev": "crit"
        },
        {
          "id": "art-1172",
          "title": "CISA KEV: CVE-2024-0012 \u2014 Palo Alto Networks PAN-OS Management Interface Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-11-18",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-11-18"
    },
    {
      "value": "136.144.17.176",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1171",
          "title": "CISA KEV: CVE-2024-9474 \u2014 Palo Alto Networks PAN-OS Management Interface OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-11-18",
          "sev": "crit"
        },
        {
          "id": "art-1172",
          "title": "CISA KEV: CVE-2024-0012 \u2014 Palo Alto Networks PAN-OS Management Interface Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-11-18",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-11-18"
    },
    {
      "value": "136.144.17.177",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1171",
          "title": "CISA KEV: CVE-2024-9474 \u2014 Palo Alto Networks PAN-OS Management Interface OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-11-18",
          "sev": "crit"
        },
        {
          "id": "art-1172",
          "title": "CISA KEV: CVE-2024-0012 \u2014 Palo Alto Networks PAN-OS Management Interface Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-11-18",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-11-18"
    },
    {
      "value": "136.144.17.178",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1171",
          "title": "CISA KEV: CVE-2024-9474 \u2014 Palo Alto Networks PAN-OS Management Interface OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-11-18",
          "sev": "crit"
        },
        {
          "id": "art-1172",
          "title": "CISA KEV: CVE-2024-0012 \u2014 Palo Alto Networks PAN-OS Management Interface Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-11-18",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-11-18"
    },
    {
      "value": "136.144.17.180",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1171",
          "title": "CISA KEV: CVE-2024-9474 \u2014 Palo Alto Networks PAN-OS Management Interface OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-11-18",
          "sev": "crit"
        },
        {
          "id": "art-1172",
          "title": "CISA KEV: CVE-2024-0012 \u2014 Palo Alto Networks PAN-OS Management Interface Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-11-18",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-11-18"
    },
    {
      "value": "15.235.189.144",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1172",
          "title": "CISA KEV: CVE-2024-0012 \u2014 Palo Alto Networks PAN-OS Management Interface Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-11-18",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-11-18"
    },
    {
      "value": "15.235.189.145",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1172",
          "title": "CISA KEV: CVE-2024-0012 \u2014 Palo Alto Networks PAN-OS Management Interface Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-11-18",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-11-18"
    },
    {
      "value": "15.235.189.146",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1172",
          "title": "CISA KEV: CVE-2024-0012 \u2014 Palo Alto Networks PAN-OS Management Interface Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-11-18",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-11-18"
    },
    {
      "value": "15.235.189.147",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1172",
          "title": "CISA KEV: CVE-2024-0012 \u2014 Palo Alto Networks PAN-OS Management Interface Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-11-18",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-11-18"
    },
    {
      "value": "15.235.189.148",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1172",
          "title": "CISA KEV: CVE-2024-0012 \u2014 Palo Alto Networks PAN-OS Management Interface Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-11-18",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-11-18"
    },
    {
      "value": "15.235.189.149",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1172",
          "title": "CISA KEV: CVE-2024-0012 \u2014 Palo Alto Networks PAN-OS Management Interface Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-11-18",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-11-18"
    },
    {
      "value": "15.235.189.150",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1172",
          "title": "CISA KEV: CVE-2024-0012 \u2014 Palo Alto Networks PAN-OS Management Interface Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-11-18",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-11-18"
    },
    {
      "value": "173.239.218.248",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1171",
          "title": "CISA KEV: CVE-2024-9474 \u2014 Palo Alto Networks PAN-OS Management Interface OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-11-18",
          "sev": "crit"
        },
        {
          "id": "art-1172",
          "title": "CISA KEV: CVE-2024-0012 \u2014 Palo Alto Networks PAN-OS Management Interface Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-11-18",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-11-18"
    },
    {
      "value": "173.239.218.251",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1171",
          "title": "CISA KEV: CVE-2024-9474 \u2014 Palo Alto Networks PAN-OS Management Interface OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-11-18",
          "sev": "crit"
        },
        {
          "id": "art-1172",
          "title": "CISA KEV: CVE-2024-0012 \u2014 Palo Alto Networks PAN-OS Management Interface Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-11-18",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-11-18"
    },
    {
      "value": "182.78.17.137",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1171",
          "title": "CISA KEV: CVE-2024-9474 \u2014 Palo Alto Networks PAN-OS Management Interface OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-11-18",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-11-18"
    },
    {
      "value": "209.200.246.173",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1171",
          "title": "CISA KEV: CVE-2024-9474 \u2014 Palo Alto Networks PAN-OS Management Interface OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-11-18",
          "sev": "crit"
        },
        {
          "id": "art-1172",
          "title": "CISA KEV: CVE-2024-0012 \u2014 Palo Alto Networks PAN-OS Management Interface Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-11-18",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-11-18"
    },
    {
      "value": "209.200.246.184",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1171",
          "title": "CISA KEV: CVE-2024-9474 \u2014 Palo Alto Networks PAN-OS Management Interface OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-11-18",
          "sev": "crit"
        },
        {
          "id": "art-1172",
          "title": "CISA KEV: CVE-2024-0012 \u2014 Palo Alto Networks PAN-OS Management Interface Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-11-18",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-11-18"
    },
    {
      "value": "216.73.160.186",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1171",
          "title": "CISA KEV: CVE-2024-9474 \u2014 Palo Alto Networks PAN-OS Management Interface OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-11-18",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-11-18"
    },
    {
      "value": "216.73.162.69",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1171",
          "title": "CISA KEV: CVE-2024-9474 \u2014 Palo Alto Networks PAN-OS Management Interface OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-11-18",
          "sev": "crit"
        },
        {
          "id": "art-1172",
          "title": "CISA KEV: CVE-2024-0012 \u2014 Palo Alto Networks PAN-OS Management Interface Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-11-18",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-11-18"
    },
    {
      "value": "216.73.162.71",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1171",
          "title": "CISA KEV: CVE-2024-9474 \u2014 Palo Alto Networks PAN-OS Management Interface OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-11-18",
          "sev": "crit"
        },
        {
          "id": "art-1172",
          "title": "CISA KEV: CVE-2024-0012 \u2014 Palo Alto Networks PAN-OS Management Interface Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-11-18",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-11-18"
    },
    {
      "value": "216.73.162.73",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1171",
          "title": "CISA KEV: CVE-2024-9474 \u2014 Palo Alto Networks PAN-OS Management Interface OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-11-18",
          "sev": "crit"
        },
        {
          "id": "art-1172",
          "title": "CISA KEV: CVE-2024-0012 \u2014 Palo Alto Networks PAN-OS Management Interface Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-11-18",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-11-18"
    },
    {
      "value": "216.73.162.74",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1171",
          "title": "CISA KEV: CVE-2024-9474 \u2014 Palo Alto Networks PAN-OS Management Interface OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-11-18",
          "sev": "crit"
        },
        {
          "id": "art-1172",
          "title": "CISA KEV: CVE-2024-0012 \u2014 Palo Alto Networks PAN-OS Management Interface Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-11-18",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-11-18"
    },
    {
      "value": "45.32.110.123",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1171",
          "title": "CISA KEV: CVE-2024-9474 \u2014 Palo Alto Networks PAN-OS Management Interface OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-11-18",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-11-18"
    },
    {
      "value": "91.208.197.167",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1171",
          "title": "CISA KEV: CVE-2024-9474 \u2014 Palo Alto Networks PAN-OS Management Interface OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-11-18",
          "sev": "crit"
        },
        {
          "id": "art-1172",
          "title": "CISA KEV: CVE-2024-0012 \u2014 Palo Alto Networks PAN-OS Management Interface Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-11-18",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-11-18"
    },
    {
      "value": "3c5f9034c86cb1952aa5bb07b4f77ce7d8bb5cc9fe5c029a32c72adc7e814668",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1171",
          "title": "CISA KEV: CVE-2024-9474 \u2014 Palo Alto Networks PAN-OS Management Interface OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-11-18",
          "sev": "crit"
        },
        {
          "id": "art-1172",
          "title": "CISA KEV: CVE-2024-0012 \u2014 Palo Alto Networks PAN-OS Management Interface Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-11-18",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-11-18"
    },
    {
      "value": "CVE-2024-5910",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1175",
          "title": "CISA KEV: CVE-2024-9465 \u2014 Palo Alto Networks Expedition SQL Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-11-14",
          "sev": "crit"
        },
        {
          "id": "art-1188",
          "title": "CISA KEV: CVE-2024-5910 \u2014 Palo Alto Networks Expedition Missing Authentication Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-11-07",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-11-14"
    },
    {
      "value": "CVE-2024-9463",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1175",
          "title": "CISA KEV: CVE-2024-9465 \u2014 Palo Alto Networks Expedition SQL Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-11-14",
          "sev": "crit"
        },
        {
          "id": "art-1176",
          "title": "CISA KEV: CVE-2024-9463 \u2014 Palo Alto Networks Expedition OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-11-14",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-11-14"
    },
    {
      "value": "CVE-2024-9464",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1175",
          "title": "CISA KEV: CVE-2024-9465 \u2014 Palo Alto Networks Expedition SQL Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-11-14",
          "sev": "crit"
        },
        {
          "id": "art-1188",
          "title": "CISA KEV: CVE-2024-5910 \u2014 Palo Alto Networks Expedition Missing Authentication Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-11-07",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-11-14"
    },
    {
      "value": "CVE-2024-9465",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1175",
          "title": "CISA KEV: CVE-2024-9465 \u2014 Palo Alto Networks Expedition SQL Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-11-14",
          "sev": "crit"
        },
        {
          "id": "art-1188",
          "title": "CISA KEV: CVE-2024-5910 \u2014 Palo Alto Networks Expedition Missing Authentication Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-11-07",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-11-14"
    },
    {
      "value": "CVE-2024-9466",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1175",
          "title": "CISA KEV: CVE-2024-9465 \u2014 Palo Alto Networks Expedition SQL Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-11-14",
          "sev": "crit"
        },
        {
          "id": "art-1188",
          "title": "CISA KEV: CVE-2024-5910 \u2014 Palo Alto Networks Expedition Missing Authentication Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-11-07",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-11-14"
    },
    {
      "value": "CVE-2024-9467",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1175",
          "title": "CISA KEV: CVE-2024-9465 \u2014 Palo Alto Networks Expedition SQL Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-11-14",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-11-14"
    },
    {
      "value": "CVE-2014-2120",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1181",
          "title": "CISA KEV: CVE-2014-2120 \u2014 Cisco Adaptive Security Appliance (ASA) Cross-Site Scripting (XSS) Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-11-12",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-11-12"
    },
    {
      "value": "CVE-2021-26086",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1180",
          "title": "CISA KEV: CVE-2021-26086 \u2014 Atlassian Jira Server and Data Center Path Traversal Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-11-12",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-11-12"
    },
    {
      "value": "CVE-2021-41277",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1182",
          "title": "CISA KEV: CVE-2021-41277 \u2014 Metabase GeoJSON API Local File Inclusion Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-11-12",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-11-12"
    },
    {
      "value": "CVE-2024-49039",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1184",
          "title": "CISA KEV: CVE-2024-49039 \u2014 Microsoft Windows Task Scheduler Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-11-12",
          "sev": "crit"
        },
        {
          "id": "art-1209",
          "title": "CISA KEV: CVE-2024-9680 \u2014 Mozilla Firefox Use-After-Free Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-10-15",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-11-12"
    },
    {
      "value": "CVE-2024-9680",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1184",
          "title": "CISA KEV: CVE-2024-49039 \u2014 Microsoft Windows Task Scheduler Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-11-12",
          "sev": "crit"
        },
        {
          "id": "art-1209",
          "title": "CISA KEV: CVE-2024-9680 \u2014 Mozilla Firefox Use-After-Free Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-10-15",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-11-12"
    },
    {
      "value": "1drv.us.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1184",
          "title": "CISA KEV: CVE-2024-49039 \u2014 Microsoft Windows Task Scheduler Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-11-12",
          "sev": "crit"
        },
        {
          "id": "art-1209",
          "title": "CISA KEV: CVE-2024-9680 \u2014 Mozilla Firefox Use-After-Free Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-10-15",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-11-12"
    },
    {
      "value": "correctiv.sbs",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1184",
          "title": "CISA KEV: CVE-2024-49039 \u2014 Microsoft Windows Task Scheduler Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-11-12",
          "sev": "crit"
        },
        {
          "id": "art-1209",
          "title": "CISA KEV: CVE-2024-9680 \u2014 Mozilla Firefox Use-After-Free Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-10-15",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-11-12"
    },
    {
      "value": "cwise.store",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1184",
          "title": "CISA KEV: CVE-2024-49039 \u2014 Microsoft Windows Task Scheduler Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-11-12",
          "sev": "crit"
        },
        {
          "id": "art-1209",
          "title": "CISA KEV: CVE-2024-9680 \u2014 Mozilla Firefox Use-After-Free Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-10-15",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-11-12"
    },
    {
      "value": "devolredir.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1184",
          "title": "CISA KEV: CVE-2024-49039 \u2014 Microsoft Windows Task Scheduler Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-11-12",
          "sev": "crit"
        },
        {
          "id": "art-1209",
          "title": "CISA KEV: CVE-2024-9680 \u2014 Mozilla Firefox Use-After-Free Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-10-15",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-11-12"
    },
    {
      "value": "doc.osvita-kp.gov.ua",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1183",
          "title": "CISA KEV: CVE-2024-43451 \u2014 Microsoft Windows NTLMv2 Hash Disclosure Spoofing Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-11-12",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-11-12"
    },
    {
      "value": "economistjournal.cloud",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1184",
          "title": "CISA KEV: CVE-2024-49039 \u2014 Microsoft Windows Task Scheduler Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-11-12",
          "sev": "crit"
        },
        {
          "id": "art-1209",
          "title": "CISA KEV: CVE-2024-9680 \u2014 Mozilla Firefox Use-After-Free Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-10-15",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-11-12"
    },
    {
      "value": "journalctd.live",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1184",
          "title": "CISA KEV: CVE-2024-49039 \u2014 Microsoft Windows Task Scheduler Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-11-12",
          "sev": "crit"
        },
        {
          "id": "art-1209",
          "title": "CISA KEV: CVE-2024-9680 \u2014 Mozilla Firefox Use-After-Free Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-10-15",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-11-12"
    },
    {
      "value": "osvita-kp.gov.ua",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1183",
          "title": "CISA KEV: CVE-2024-43451 \u2014 Microsoft Windows NTLMv2 Hash Disclosure Spoofing Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-11-12",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-11-12"
    },
    {
      "value": "redirconnectwise.cloud",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1184",
          "title": "CISA KEV: CVE-2024-49039 \u2014 Microsoft Windows Task Scheduler Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-11-12",
          "sev": "crit"
        },
        {
          "id": "art-1209",
          "title": "CISA KEV: CVE-2024-9680 \u2014 Mozilla Firefox Use-After-Free Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-10-15",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-11-12"
    },
    {
      "value": "redircorrectiv.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1184",
          "title": "CISA KEV: CVE-2024-49039 \u2014 Microsoft Windows Task Scheduler Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-11-12",
          "sev": "crit"
        },
        {
          "id": "art-1209",
          "title": "CISA KEV: CVE-2024-9680 \u2014 Mozilla Firefox Use-After-Free Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-10-15",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-11-12"
    },
    {
      "value": "redjournal.cloud",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1184",
          "title": "CISA KEV: CVE-2024-49039 \u2014 Microsoft Windows Task Scheduler Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-11-12",
          "sev": "crit"
        },
        {
          "id": "art-1209",
          "title": "CISA KEV: CVE-2024-9680 \u2014 Mozilla Firefox Use-After-Free Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-10-15",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-11-12"
    },
    {
      "value": "147.45.78.102",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1184",
          "title": "CISA KEV: CVE-2024-49039 \u2014 Microsoft Windows Task Scheduler Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-11-12",
          "sev": "crit"
        },
        {
          "id": "art-1209",
          "title": "CISA KEV: CVE-2024-9680 \u2014 Mozilla Firefox Use-After-Free Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-10-15",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-11-12"
    },
    {
      "value": "176.124.206.88",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1184",
          "title": "CISA KEV: CVE-2024-49039 \u2014 Microsoft Windows Task Scheduler Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-11-12",
          "sev": "crit"
        },
        {
          "id": "art-1209",
          "title": "CISA KEV: CVE-2024-9680 \u2014 Mozilla Firefox Use-After-Free Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-10-15",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-11-12"
    },
    {
      "value": "178.236.246.241",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1184",
          "title": "CISA KEV: CVE-2024-49039 \u2014 Microsoft Windows Task Scheduler Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-11-12",
          "sev": "crit"
        },
        {
          "id": "art-1209",
          "title": "CISA KEV: CVE-2024-9680 \u2014 Mozilla Firefox Use-After-Free Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-10-15",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-11-12"
    },
    {
      "value": "194.87.189.171",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1184",
          "title": "CISA KEV: CVE-2024-49039 \u2014 Microsoft Windows Task Scheduler Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-11-12",
          "sev": "crit"
        },
        {
          "id": "art-1209",
          "title": "CISA KEV: CVE-2024-9680 \u2014 Mozilla Firefox Use-After-Free Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-10-15",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-11-12"
    },
    {
      "value": "194.87.189.19",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1184",
          "title": "CISA KEV: CVE-2024-49039 \u2014 Microsoft Windows Task Scheduler Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-11-12",
          "sev": "crit"
        },
        {
          "id": "art-1209",
          "title": "CISA KEV: CVE-2024-9680 \u2014 Mozilla Firefox Use-After-Free Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-10-15",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-11-12"
    },
    {
      "value": "45.138.74.238",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1184",
          "title": "CISA KEV: CVE-2024-49039 \u2014 Microsoft Windows Task Scheduler Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-11-12",
          "sev": "crit"
        },
        {
          "id": "art-1209",
          "title": "CISA KEV: CVE-2024-9680 \u2014 Mozilla Firefox Use-After-Free Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-10-15",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-11-12"
    },
    {
      "value": "46.226.163.67",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1184",
          "title": "CISA KEV: CVE-2024-49039 \u2014 Microsoft Windows Task Scheduler Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-11-12",
          "sev": "crit"
        },
        {
          "id": "art-1209",
          "title": "CISA KEV: CVE-2024-9680 \u2014 Mozilla Firefox Use-After-Free Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-10-15",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-11-12"
    },
    {
      "value": "62.60.237.116",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1184",
          "title": "CISA KEV: CVE-2024-49039 \u2014 Microsoft Windows Task Scheduler Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-11-12",
          "sev": "crit"
        },
        {
          "id": "art-1209",
          "title": "CISA KEV: CVE-2024-9680 \u2014 Mozilla Firefox Use-After-Free Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-10-15",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-11-12"
    },
    {
      "value": "62.60.237.38",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1184",
          "title": "CISA KEV: CVE-2024-49039 \u2014 Microsoft Windows Task Scheduler Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-11-12",
          "sev": "crit"
        },
        {
          "id": "art-1209",
          "title": "CISA KEV: CVE-2024-9680 \u2014 Mozilla Firefox Use-After-Free Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-10-15",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-11-12"
    },
    {
      "value": "62.60.238.81",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1184",
          "title": "CISA KEV: CVE-2024-49039 \u2014 Microsoft Windows Task Scheduler Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-11-12",
          "sev": "crit"
        },
        {
          "id": "art-1209",
          "title": "CISA KEV: CVE-2024-9680 \u2014 Mozilla Firefox Use-After-Free Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-10-15",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-11-12"
    },
    {
      "value": "92.42.96.30",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1183",
          "title": "CISA KEV: CVE-2024-43451 \u2014 Microsoft Windows NTLMv2 Hash Disclosure Spoofing Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-11-12",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-11-12"
    },
    {
      "value": "21918cfd17b378eb4152910f1246d2446f9b5b11",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1184",
          "title": "CISA KEV: CVE-2024-49039 \u2014 Microsoft Windows Task Scheduler Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-11-12",
          "sev": "crit"
        },
        {
          "id": "art-1209",
          "title": "CISA KEV: CVE-2024-9680 \u2014 Mozilla Firefox Use-After-Free Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-10-15",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-11-12"
    },
    {
      "value": "703a25f053e356eb6ece4d16a048344c55dc89fd",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1184",
          "title": "CISA KEV: CVE-2024-49039 \u2014 Microsoft Windows Task Scheduler Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-11-12",
          "sev": "crit"
        },
        {
          "id": "art-1209",
          "title": "CISA KEV: CVE-2024-9680 \u2014 Mozilla Firefox Use-After-Free Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-10-15",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-11-12"
    },
    {
      "value": "a4aad0e2ac1ee0c8dd25968fa4631805689757b6",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1184",
          "title": "CISA KEV: CVE-2024-49039 \u2014 Microsoft Windows Task Scheduler Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-11-12",
          "sev": "crit"
        },
        {
          "id": "art-1209",
          "title": "CISA KEV: CVE-2024-9680 \u2014 Mozilla Firefox Use-After-Free Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-10-15",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-11-12"
    },
    {
      "value": "a9d445b77f6f4e90c29e385264d4b1b95947add5",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1184",
          "title": "CISA KEV: CVE-2024-49039 \u2014 Microsoft Windows Task Scheduler Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-11-12",
          "sev": "crit"
        },
        {
          "id": "art-1209",
          "title": "CISA KEV: CVE-2024-9680 \u2014 Mozilla Firefox Use-After-Free Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-10-15",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-11-12"
    },
    {
      "value": "abb54c4751f97a9fc1c9598fed1ec9fb9e6b1db6",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1184",
          "title": "CISA KEV: CVE-2024-49039 \u2014 Microsoft Windows Task Scheduler Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-11-12",
          "sev": "crit"
        },
        {
          "id": "art-1209",
          "title": "CISA KEV: CVE-2024-9680 \u2014 Mozilla Firefox Use-After-Free Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-10-15",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-11-12"
    },
    {
      "value": "ca6f8966a3b2640f49b19434ba8c21832e77a031",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1184",
          "title": "CISA KEV: CVE-2024-49039 \u2014 Microsoft Windows Task Scheduler Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-11-12",
          "sev": "crit"
        },
        {
          "id": "art-1209",
          "title": "CISA KEV: CVE-2024-9680 \u2014 Mozilla Firefox Use-After-Free Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-10-15",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-11-12"
    },
    {
      "value": "CVE-2019-16278",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1185",
          "title": "CISA KEV: CVE-2019-16278 \u2014 Nostromo nhttpd Directory Traversal Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-11-07",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-11-07"
    },
    {
      "value": "CVE-2024-43093",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1187",
          "title": "CISA KEV: CVE-2024-43093 \u2014 Android Framework Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-11-07",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-11-07"
    },
    {
      "value": "CVE-2024-51567",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1186",
          "title": "CISA KEV: CVE-2024-51567 \u2014 CyberPanel Incorrect Default Permissions Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-11-07",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-11-07"
    },
    {
      "value": "CVE-2024-51568",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1186",
          "title": "CISA KEV: CVE-2024-51567 \u2014 CyberPanel Incorrect Default Permissions Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-11-07",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-11-07"
    },
    {
      "value": "CVE-2024-8956",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1189",
          "title": "CISA KEV: CVE-2024-8956 \u2014 PTZOptics PT30X-SDI/NDI Cameras Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-11-04",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-11-04"
    },
    {
      "value": "CVE-2024-8957",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1189",
          "title": "CISA KEV: CVE-2024-8956 \u2014 PTZOptics PT30X-SDI/NDI Cameras Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-11-04",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-11-04"
    },
    {
      "value": "209.141.35.56",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1189",
          "title": "CISA KEV: CVE-2024-8956 \u2014 PTZOptics PT30X-SDI/NDI Cameras Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-11-04",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-11-04"
    },
    {
      "value": "45.128.232.229",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1189",
          "title": "CISA KEV: CVE-2024-8956 \u2014 PTZOptics PT30X-SDI/NDI Cameras Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-11-04",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-11-04"
    },
    {
      "value": "CVE-2024-20481",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1196",
          "title": "CISA KEV: CVE-2024-20481 \u2014 Cisco ASA and FTD Denial-of-Service Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-10-24",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-10-24"
    },
    {
      "value": "CVE-2024-37383",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1195",
          "title": "CISA KEV: CVE-2024-37383 \u2014 RoundCube Webmail Cross-Site Scripting (XSS) Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-10-24",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-10-24"
    },
    {
      "value": "libcdn.org",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1195",
          "title": "CISA KEV: CVE-2024-37383 \u2014 RoundCube Webmail Cross-Site Scripting (XSS) Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-10-24",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-10-24"
    },
    {
      "value": "rcm.codes",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1195",
          "title": "CISA KEV: CVE-2024-37383 \u2014 RoundCube Webmail Cross-Site Scripting (XSS) Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-10-24",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-10-24"
    },
    {
      "value": "CVE-2024-47575",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1198",
          "title": "CISA KEV: CVE-2024-47575 \u2014 Fortinet FortiManager Missing Authentication Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-10-23",
          "sev": "crit"
        },
        {
          "id": "art-1216",
          "title": "CISA KEV: CVE-2024-23113 \u2014 Fortinet Multiple Products Format String Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-10-09",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-10-23"
    },
    {
      "value": "104.238.141.143",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1198",
          "title": "CISA KEV: CVE-2024-47575 \u2014 Fortinet FortiManager Missing Authentication Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-10-23",
          "sev": "crit"
        },
        {
          "id": "art-1216",
          "title": "CISA KEV: CVE-2024-23113 \u2014 Fortinet Multiple Products Format String Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-10-09",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-10-23"
    },
    {
      "value": "142.93.177.233",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1198",
          "title": "CISA KEV: CVE-2024-47575 \u2014 Fortinet FortiManager Missing Authentication Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-10-23",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-10-23"
    },
    {
      "value": "158.247.199.37",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1198",
          "title": "CISA KEV: CVE-2024-47575 \u2014 Fortinet FortiManager Missing Authentication Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-10-23",
          "sev": "crit"
        },
        {
          "id": "art-1216",
          "title": "CISA KEV: CVE-2024-23113 \u2014 Fortinet Multiple Products Format String Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-10-09",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-10-23"
    },
    {
      "value": "172.232.167.68",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1198",
          "title": "CISA KEV: CVE-2024-47575 \u2014 Fortinet FortiManager Missing Authentication Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-10-23",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-10-23"
    },
    {
      "value": "195.85.114.78",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1198",
          "title": "CISA KEV: CVE-2024-47575 \u2014 Fortinet FortiManager Missing Authentication Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-10-23",
          "sev": "crit"
        },
        {
          "id": "art-1216",
          "title": "CISA KEV: CVE-2024-23113 \u2014 Fortinet Multiple Products Format String Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-10-09",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-10-23"
    },
    {
      "value": "198.199.122.22",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1198",
          "title": "CISA KEV: CVE-2024-47575 \u2014 Fortinet FortiManager Missing Authentication Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-10-23",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-10-23"
    },
    {
      "value": "45.32.41.202",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1198",
          "title": "CISA KEV: CVE-2024-47575 \u2014 Fortinet FortiManager Missing Authentication Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-10-23",
          "sev": "crit"
        },
        {
          "id": "art-1216",
          "title": "CISA KEV: CVE-2024-23113 \u2014 Fortinet Multiple Products Format String Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-10-09",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-10-23"
    },
    {
      "value": "45.32.63.2",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1198",
          "title": "CISA KEV: CVE-2024-47575 \u2014 Fortinet FortiManager Missing Authentication Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-10-23",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-10-23"
    },
    {
      "value": "80.66.196.199",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1198",
          "title": "CISA KEV: CVE-2024-47575 \u2014 Fortinet FortiManager Missing Authentication Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-10-23",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-10-23"
    },
    {
      "value": "9dcfab171580b52deae8703157012674",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1198",
          "title": "CISA KEV: CVE-2024-47575 \u2014 Fortinet FortiManager Missing Authentication Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-10-23",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-10-23"
    },
    {
      "value": "CVE-2024-38094",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1201",
          "title": "CISA KEV: CVE-2024-38094 \u2014 Microsoft SharePoint Deserialization Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-10-22",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-10-22"
    },
    {
      "value": "18.195.61.200",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1201",
          "title": "CISA KEV: CVE-2024-38094 \u2014 Microsoft SharePoint Deserialization Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-10-22",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-10-22"
    },
    {
      "value": "54.255.89.118",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1201",
          "title": "CISA KEV: CVE-2024-38094 \u2014 Microsoft SharePoint Deserialization Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-10-22",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-10-22"
    },
    {
      "value": "1beec8cecd28fdf9f7e0fc5fb9226b360934086ded84f69e3d542d1362e3fdf3",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1201",
          "title": "CISA KEV: CVE-2024-38094 \u2014 Microsoft SharePoint Deserialization Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-10-22",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-10-22"
    },
    {
      "value": "61c0810a23580cf492a6ba4f7654566108331e7a4134c968c2d6a05261b2d8a1",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1201",
          "title": "CISA KEV: CVE-2024-38094 \u2014 Microsoft SharePoint Deserialization Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-10-22",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-10-22"
    },
    {
      "value": "6ce228240458563d73c1c3cbbd04ef15cb7c5badacc78ce331848f5431b406cc",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1201",
          "title": "CISA KEV: CVE-2024-38094 \u2014 Microsoft SharePoint Deserialization Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-10-22",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-10-22"
    },
    {
      "value": "95cc0b082fcfc366a7de8030a6325c099d8012533a3234edbdf555df082413c7",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1201",
          "title": "CISA KEV: CVE-2024-38094 \u2014 Microsoft SharePoint Deserialization Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-10-22",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-10-22"
    },
    {
      "value": "acb5de5a69c06b7501f86c0522d10fefa9c34776c7535e937e946c6abfc9bbc6",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1201",
          "title": "CISA KEV: CVE-2024-38094 \u2014 Microsoft SharePoint Deserialization Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-10-22",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-10-22"
    },
    {
      "value": "d18aa84b7bf0efde9c6b5db2a38ab1ec9484c59c5284c0bd080f5197bf9388b0",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1201",
          "title": "CISA KEV: CVE-2024-38094 \u2014 Microsoft SharePoint Deserialization Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-10-22",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-10-22"
    },
    {
      "value": "d3a6ed07bd3b52c62411132d060560f9c0c88ce183851f16b632a99b4d4e7581",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1201",
          "title": "CISA KEV: CVE-2024-38094 \u2014 Microsoft SharePoint Deserialization Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-10-22",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-10-22"
    },
    {
      "value": "e451287843b3927c6046eaabd3e22b929bc1f445eec23a73b1398b115d02e4fb",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1201",
          "title": "CISA KEV: CVE-2024-38094 \u2014 Microsoft SharePoint Deserialization Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-10-22",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-10-22"
    },
    {
      "value": "f618b09c0908119399d14f80fc868b002b987006f7c76adbcec1ac11b9208940",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1201",
          "title": "CISA KEV: CVE-2024-38094 \u2014 Microsoft SharePoint Deserialization Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-10-22",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-10-22"
    },
    {
      "value": "CVE-2024-9537",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1202",
          "title": "CISA KEV: CVE-2024-9537 \u2014 ScienceLogic SL1 Unspecified Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-10-21",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-10-21"
    },
    {
      "value": "CVE-2024-40711",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1206",
          "title": "CISA KEV: CVE-2024-40711 \u2014 Veeam Backup and Replication Deserialization Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-10-17",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-10-17"
    },
    {
      "value": "CVE-2021-35232",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1208",
          "title": "CISA KEV: CVE-2024-28987 \u2014 SolarWinds Web Help Desk Hardcoded Credential Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-10-15",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-10-15"
    },
    {
      "value": "CVE-2024-28987",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1208",
          "title": "CISA KEV: CVE-2024-28987 \u2014 SolarWinds Web Help Desk Hardcoded Credential Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-10-15",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-10-15"
    },
    {
      "value": "CVE-2024-30088",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1210",
          "title": "CISA KEV: CVE-2024-30088 \u2014 Microsoft Windows Kernel TOCTOU Race Condition Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-10-15",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-10-15"
    },
    {
      "value": "CVE-2024-23113",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1216",
          "title": "CISA KEV: CVE-2024-23113 \u2014 Fortinet Multiple Products Format String Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-10-09",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-10-09"
    },
    {
      "value": "CVE-2024-29824",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1214",
          "title": "CISA KEV: CVE-2024-9380 \u2014 Ivanti Cloud Services Appliance (CSA) OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-10-09",
          "sev": "crit"
        },
        {
          "id": "art-1225",
          "title": "CISA KEV: CVE-2024-29824 \u2014 Ivanti Endpoint Manager (EPM) SQL Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-10-02",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-10-09"
    },
    {
      "value": "CVE-2024-8190",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1214",
          "title": "CISA KEV: CVE-2024-9380 \u2014 Ivanti Cloud Services Appliance (CSA) OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-10-09",
          "sev": "crit"
        },
        {
          "id": "art-1215",
          "title": "CISA KEV: CVE-2024-9379 \u2014 Ivanti Cloud Services Appliance (CSA) SQL Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-10-09",
          "sev": "crit"
        },
        {
          "id": "art-1236",
          "title": "CISA KEV: CVE-2024-8963 \u2014 Ivanti Cloud Services Appliance (CSA) Path Traversal Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-09-19",
          "sev": "crit"
        },
        {
          "id": "art-1250",
          "title": "CISA KEV: CVE-2024-8190 \u2014 Ivanti Cloud Services Appliance OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-09-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-10-09"
    },
    {
      "value": "CVE-2024-8963",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1214",
          "title": "CISA KEV: CVE-2024-9380 \u2014 Ivanti Cloud Services Appliance (CSA) OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-10-09",
          "sev": "crit"
        },
        {
          "id": "art-1215",
          "title": "CISA KEV: CVE-2024-9379 \u2014 Ivanti Cloud Services Appliance (CSA) SQL Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-10-09",
          "sev": "crit"
        },
        {
          "id": "art-1236",
          "title": "CISA KEV: CVE-2024-8963 \u2014 Ivanti Cloud Services Appliance (CSA) Path Traversal Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-09-19",
          "sev": "crit"
        },
        {
          "id": "art-1250",
          "title": "CISA KEV: CVE-2024-8190 \u2014 Ivanti Cloud Services Appliance OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-09-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-10-09"
    },
    {
      "value": "CVE-2024-9379",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1214",
          "title": "CISA KEV: CVE-2024-9380 \u2014 Ivanti Cloud Services Appliance (CSA) OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-10-09",
          "sev": "crit"
        },
        {
          "id": "art-1215",
          "title": "CISA KEV: CVE-2024-9379 \u2014 Ivanti Cloud Services Appliance (CSA) SQL Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-10-09",
          "sev": "crit"
        },
        {
          "id": "art-1236",
          "title": "CISA KEV: CVE-2024-8963 \u2014 Ivanti Cloud Services Appliance (CSA) Path Traversal Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-09-19",
          "sev": "crit"
        },
        {
          "id": "art-1250",
          "title": "CISA KEV: CVE-2024-8190 \u2014 Ivanti Cloud Services Appliance OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-09-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-10-09"
    },
    {
      "value": "CVE-2024-9380",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1214",
          "title": "CISA KEV: CVE-2024-9380 \u2014 Ivanti Cloud Services Appliance (CSA) OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-10-09",
          "sev": "crit"
        },
        {
          "id": "art-1215",
          "title": "CISA KEV: CVE-2024-9379 \u2014 Ivanti Cloud Services Appliance (CSA) SQL Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-10-09",
          "sev": "crit"
        },
        {
          "id": "art-1236",
          "title": "CISA KEV: CVE-2024-8963 \u2014 Ivanti Cloud Services Appliance (CSA) Path Traversal Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-09-19",
          "sev": "crit"
        },
        {
          "id": "art-1250",
          "title": "CISA KEV: CVE-2024-8190 \u2014 Ivanti Cloud Services Appliance OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-09-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-10-09"
    },
    {
      "value": "189f31ed7d.ipv6.bypass.eu.org",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1214",
          "title": "CISA KEV: CVE-2024-9380 \u2014 Ivanti Cloud Services Appliance (CSA) OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-10-09",
          "sev": "crit"
        },
        {
          "id": "art-1250",
          "title": "CISA KEV: CVE-2024-8190 \u2014 Ivanti Cloud Services Appliance OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-09-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-10-09"
    },
    {
      "value": "apiv5.serverbks.xyz",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1214",
          "title": "CISA KEV: CVE-2024-9380 \u2014 Ivanti Cloud Services Appliance (CSA) OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-10-09",
          "sev": "crit"
        },
        {
          "id": "art-1236",
          "title": "CISA KEV: CVE-2024-8963 \u2014 Ivanti Cloud Services Appliance (CSA) Path Traversal Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-09-19",
          "sev": "crit"
        },
        {
          "id": "art-1250",
          "title": "CISA KEV: CVE-2024-8190 \u2014 Ivanti Cloud Services Appliance OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-09-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-10-09"
    },
    {
      "value": "c67f045c2f.ipv6.1433.eu.org",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1214",
          "title": "CISA KEV: CVE-2024-9380 \u2014 Ivanti Cloud Services Appliance (CSA) OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-10-09",
          "sev": "crit"
        },
        {
          "id": "art-1250",
          "title": "CISA KEV: CVE-2024-8190 \u2014 Ivanti Cloud Services Appliance OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-09-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-10-09"
    },
    {
      "value": "iowxuintgredogzgblrsmr2cx2e471bor.oast.fun",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1214",
          "title": "CISA KEV: CVE-2024-9380 \u2014 Ivanti Cloud Services Appliance (CSA) OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-10-09",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-10-09"
    },
    {
      "value": "156.234.193.18",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1214",
          "title": "CISA KEV: CVE-2024-9380 \u2014 Ivanti Cloud Services Appliance (CSA) OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-10-09",
          "sev": "crit"
        },
        {
          "id": "art-1250",
          "title": "CISA KEV: CVE-2024-8190 \u2014 Ivanti Cloud Services Appliance OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-09-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-10-09"
    },
    {
      "value": "193.189.100.197",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1214",
          "title": "CISA KEV: CVE-2024-9380 \u2014 Ivanti Cloud Services Appliance (CSA) OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-10-09",
          "sev": "crit"
        },
        {
          "id": "art-1236",
          "title": "CISA KEV: CVE-2024-8963 \u2014 Ivanti Cloud Services Appliance (CSA) Path Traversal Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-09-19",
          "sev": "crit"
        },
        {
          "id": "art-1250",
          "title": "CISA KEV: CVE-2024-8190 \u2014 Ivanti Cloud Services Appliance OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-09-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-10-09"
    },
    {
      "value": "206.189.156.69",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1214",
          "title": "CISA KEV: CVE-2024-9380 \u2014 Ivanti Cloud Services Appliance (CSA) OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-10-09",
          "sev": "crit"
        },
        {
          "id": "art-1236",
          "title": "CISA KEV: CVE-2024-8963 \u2014 Ivanti Cloud Services Appliance (CSA) Path Traversal Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-09-19",
          "sev": "crit"
        },
        {
          "id": "art-1250",
          "title": "CISA KEV: CVE-2024-8190 \u2014 Ivanti Cloud Services Appliance OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-09-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-10-09"
    },
    {
      "value": "208.105.190.170",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1214",
          "title": "CISA KEV: CVE-2024-9380 \u2014 Ivanti Cloud Services Appliance (CSA) OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-10-09",
          "sev": "crit"
        },
        {
          "id": "art-1236",
          "title": "CISA KEV: CVE-2024-8963 \u2014 Ivanti Cloud Services Appliance (CSA) Path Traversal Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-09-19",
          "sev": "crit"
        },
        {
          "id": "art-1250",
          "title": "CISA KEV: CVE-2024-8190 \u2014 Ivanti Cloud Services Appliance OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-09-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-10-09"
    },
    {
      "value": "216.131.75.52",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1214",
          "title": "CISA KEV: CVE-2024-9380 \u2014 Ivanti Cloud Services Appliance (CSA) OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-10-09",
          "sev": "crit"
        },
        {
          "id": "art-1236",
          "title": "CISA KEV: CVE-2024-8963 \u2014 Ivanti Cloud Services Appliance (CSA) Path Traversal Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-09-19",
          "sev": "crit"
        },
        {
          "id": "art-1250",
          "title": "CISA KEV: CVE-2024-8190 \u2014 Ivanti Cloud Services Appliance OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-09-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-10-09"
    },
    {
      "value": "23.236.66.97",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1214",
          "title": "CISA KEV: CVE-2024-9380 \u2014 Ivanti Cloud Services Appliance (CSA) OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-10-09",
          "sev": "crit"
        },
        {
          "id": "art-1236",
          "title": "CISA KEV: CVE-2024-8963 \u2014 Ivanti Cloud Services Appliance (CSA) Path Traversal Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-09-19",
          "sev": "crit"
        },
        {
          "id": "art-1250",
          "title": "CISA KEV: CVE-2024-8190 \u2014 Ivanti Cloud Services Appliance OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-09-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-10-09"
    },
    {
      "value": "24.166.100.255",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1214",
          "title": "CISA KEV: CVE-2024-9380 \u2014 Ivanti Cloud Services Appliance (CSA) OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-10-09",
          "sev": "crit"
        },
        {
          "id": "art-1236",
          "title": "CISA KEV: CVE-2024-8963 \u2014 Ivanti Cloud Services Appliance (CSA) Path Traversal Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-09-19",
          "sev": "crit"
        },
        {
          "id": "art-1250",
          "title": "CISA KEV: CVE-2024-8190 \u2014 Ivanti Cloud Services Appliance OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-09-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-10-09"
    },
    {
      "value": "3.248.33.252",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1214",
          "title": "CISA KEV: CVE-2024-9380 \u2014 Ivanti Cloud Services Appliance (CSA) OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-10-09",
          "sev": "crit"
        },
        {
          "id": "art-1236",
          "title": "CISA KEV: CVE-2024-8963 \u2014 Ivanti Cloud Services Appliance (CSA) Path Traversal Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-09-19",
          "sev": "crit"
        },
        {
          "id": "art-1250",
          "title": "CISA KEV: CVE-2024-8190 \u2014 Ivanti Cloud Services Appliance OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-09-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-10-09"
    },
    {
      "value": "38.207.159.76",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1214",
          "title": "CISA KEV: CVE-2024-9380 \u2014 Ivanti Cloud Services Appliance (CSA) OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-10-09",
          "sev": "crit"
        },
        {
          "id": "art-1236",
          "title": "CISA KEV: CVE-2024-8963 \u2014 Ivanti Cloud Services Appliance (CSA) Path Traversal Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-09-19",
          "sev": "crit"
        },
        {
          "id": "art-1250",
          "title": "CISA KEV: CVE-2024-8190 \u2014 Ivanti Cloud Services Appliance OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-09-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-10-09"
    },
    {
      "value": "45.61.136.189",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1214",
          "title": "CISA KEV: CVE-2024-9380 \u2014 Ivanti Cloud Services Appliance (CSA) OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-10-09",
          "sev": "crit"
        },
        {
          "id": "art-1236",
          "title": "CISA KEV: CVE-2024-8963 \u2014 Ivanti Cloud Services Appliance (CSA) Path Traversal Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-09-19",
          "sev": "crit"
        },
        {
          "id": "art-1250",
          "title": "CISA KEV: CVE-2024-8190 \u2014 Ivanti Cloud Services Appliance OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-09-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-10-09"
    },
    {
      "value": "51.91.79.17",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1214",
          "title": "CISA KEV: CVE-2024-9380 \u2014 Ivanti Cloud Services Appliance (CSA) OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-10-09",
          "sev": "crit"
        },
        {
          "id": "art-1250",
          "title": "CISA KEV: CVE-2024-8190 \u2014 Ivanti Cloud Services Appliance OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-09-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-10-09"
    },
    {
      "value": "67.217.228.92",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1214",
          "title": "CISA KEV: CVE-2024-9380 \u2014 Ivanti Cloud Services Appliance (CSA) OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-10-09",
          "sev": "crit"
        },
        {
          "id": "art-1236",
          "title": "CISA KEV: CVE-2024-8963 \u2014 Ivanti Cloud Services Appliance (CSA) Path Traversal Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-09-19",
          "sev": "crit"
        },
        {
          "id": "art-1250",
          "title": "CISA KEV: CVE-2024-8190 \u2014 Ivanti Cloud Services Appliance OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-09-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-10-09"
    },
    {
      "value": "69.49.88.235",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1214",
          "title": "CISA KEV: CVE-2024-9380 \u2014 Ivanti Cloud Services Appliance (CSA) OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-10-09",
          "sev": "crit"
        },
        {
          "id": "art-1236",
          "title": "CISA KEV: CVE-2024-8963 \u2014 Ivanti Cloud Services Appliance (CSA) Path Traversal Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-09-19",
          "sev": "crit"
        },
        {
          "id": "art-1250",
          "title": "CISA KEV: CVE-2024-8190 \u2014 Ivanti Cloud Services Appliance OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-09-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-10-09"
    },
    {
      "value": "74.62.81.162",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1214",
          "title": "CISA KEV: CVE-2024-9380 \u2014 Ivanti Cloud Services Appliance (CSA) OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-10-09",
          "sev": "crit"
        },
        {
          "id": "art-1250",
          "title": "CISA KEV: CVE-2024-8190 \u2014 Ivanti Cloud Services Appliance OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-09-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-10-09"
    },
    {
      "value": "64efc1aad330ea9d98c0c705e16cd4b3af7e74f8",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1214",
          "title": "CISA KEV: CVE-2024-9380 \u2014 Ivanti Cloud Services Appliance (CSA) OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-10-09",
          "sev": "crit"
        },
        {
          "id": "art-1236",
          "title": "CISA KEV: CVE-2024-8963 \u2014 Ivanti Cloud Services Appliance (CSA) Path Traversal Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-09-19",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-10-09"
    },
    {
      "value": "beb723a5f20a1a2c4375f9aa250d968d55155689",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1214",
          "title": "CISA KEV: CVE-2024-9380 \u2014 Ivanti Cloud Services Appliance (CSA) OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-10-09",
          "sev": "crit"
        },
        {
          "id": "art-1236",
          "title": "CISA KEV: CVE-2024-8963 \u2014 Ivanti Cloud Services Appliance (CSA) Path Traversal Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-09-19",
          "sev": "crit"
        },
        {
          "id": "art-1250",
          "title": "CISA KEV: CVE-2024-8190 \u2014 Ivanti Cloud Services Appliance OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-09-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-10-09"
    },
    {
      "value": "6edd7b3123de985846a805931ca8ee5f6f7ed7b160144aa0e066967bc7c0423a",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1214",
          "title": "CISA KEV: CVE-2024-9380 \u2014 Ivanti Cloud Services Appliance (CSA) OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-10-09",
          "sev": "crit"
        },
        {
          "id": "art-1236",
          "title": "CISA KEV: CVE-2024-8963 \u2014 Ivanti Cloud Services Appliance (CSA) Path Traversal Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-09-19",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-10-09"
    },
    {
      "value": "8d016d02f8fbe25dce76481a90dd0b48630ce9e74e8c31ba007cf133e48b8526",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1214",
          "title": "CISA KEV: CVE-2024-9380 \u2014 Ivanti Cloud Services Appliance (CSA) OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-10-09",
          "sev": "crit"
        },
        {
          "id": "art-1236",
          "title": "CISA KEV: CVE-2024-8963 \u2014 Ivanti Cloud Services Appliance (CSA) Path Traversal Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-09-19",
          "sev": "crit"
        },
        {
          "id": "art-1250",
          "title": "CISA KEV: CVE-2024-8190 \u2014 Ivanti Cloud Services Appliance OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-09-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-10-09"
    },
    {
      "value": "d57a2cac394a778e19ce9b926f2e0a71936510798f30d20f207f2a49b49ce7b1",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1214",
          "title": "CISA KEV: CVE-2024-9380 \u2014 Ivanti Cloud Services Appliance (CSA) OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-10-09",
          "sev": "crit"
        },
        {
          "id": "art-1236",
          "title": "CISA KEV: CVE-2024-8963 \u2014 Ivanti Cloud Services Appliance (CSA) Path Traversal Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-09-19",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-10-09"
    },
    {
      "value": "CVE-2024-38112",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1218",
          "title": "CISA KEV: CVE-2024-43573 \u2014 Microsoft Windows MSHTML Platform Spoofing Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-10-08",
          "sev": "crit"
        },
        {
          "id": "art-1249",
          "title": "CISA KEV: CVE-2024-43461 \u2014 Microsoft Windows MSHTML Platform Spoofing Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-09-16",
          "sev": "crit"
        },
        {
          "id": "art-1316",
          "title": "CISA KEV: CVE-2024-38112 \u2014 Microsoft Windows MSHTML Platform Spoofing Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-07-09",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-10-08"
    },
    {
      "value": "CVE-2024-43047",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1220",
          "title": "CISA KEV: CVE-2024-43047 \u2014 Qualcomm Multiple Chipsets Use-After-Free Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-10-08",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-10-08"
    },
    {
      "value": "CVE-2024-43461",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1218",
          "title": "CISA KEV: CVE-2024-43573 \u2014 Microsoft Windows MSHTML Platform Spoofing Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-10-08",
          "sev": "crit"
        },
        {
          "id": "art-1249",
          "title": "CISA KEV: CVE-2024-43461 \u2014 Microsoft Windows MSHTML Platform Spoofing Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-09-16",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-10-08"
    },
    {
      "value": "CVE-2024-43572",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1219",
          "title": "CISA KEV: CVE-2024-43572 \u2014 Microsoft Windows Management Console Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-10-08",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-10-08"
    },
    {
      "value": "CVE-2024-43573",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1218",
          "title": "CISA KEV: CVE-2024-43573 \u2014 Microsoft Windows MSHTML Platform Spoofing Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-10-08",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-10-08"
    },
    {
      "value": "CVE-2024-45519",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1222",
          "title": "CISA KEV: CVE-2024-45519 \u2014 Synacor Zimbra Collaboration Suite (ZCS) Command Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-10-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-10-03"
    },
    {
      "value": "79.124.49.86",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1222",
          "title": "CISA KEV: CVE-2024-45519 \u2014 Synacor Zimbra Collaboration Suite (ZCS) Command Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-10-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-10-03"
    },
    {
      "value": "CVE-2019-0344",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1227",
          "title": "CISA KEV: CVE-2019-0344 \u2014 SAP Commerce Cloud Deserialization of Untrusted Data Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-09-30",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-09-30"
    },
    {
      "value": "CVE-2020-14472",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1228",
          "title": "CISA KEV: CVE-2020-15415 \u2014 DrayTek Multiple Vigor Routers OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-09-30",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-09-30"
    },
    {
      "value": "CVE-2020-14993",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1228",
          "title": "CISA KEV: CVE-2020-15415 \u2014 DrayTek Multiple Vigor Routers OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-09-30",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-09-30"
    },
    {
      "value": "CVE-2020-15415",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1228",
          "title": "CISA KEV: CVE-2020-15415 \u2014 DrayTek Multiple Vigor Routers OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-09-30",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-09-30"
    },
    {
      "value": "CVE-2020-19664",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1228",
          "title": "CISA KEV: CVE-2020-15415 \u2014 DrayTek Multiple Vigor Routers OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-09-30",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-09-30"
    },
    {
      "value": "CVE-2020-8515",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1228",
          "title": "CISA KEV: CVE-2020-15415 \u2014 DrayTek Multiple Vigor Routers OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-09-30",
          "sev": "crit"
        },
        {
          "id": "art-2876",
          "title": "CISA KEV: CVE-2020-8515 \u2014 Multiple DrayTek Vigor Routers Web Management Page Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-09-30"
    },
    {
      "value": "CVE-2021-42911",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1228",
          "title": "CISA KEV: CVE-2020-15415 \u2014 DrayTek Multiple Vigor Routers OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-09-30",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-09-30"
    },
    {
      "value": "CVE-2021-43118",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1228",
          "title": "CISA KEV: CVE-2020-15415 \u2014 DrayTek Multiple Vigor Routers OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-09-30",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-09-30"
    },
    {
      "value": "CVE-2023-1162",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1228",
          "title": "CISA KEV: CVE-2020-15415 \u2014 DrayTek Multiple Vigor Routers OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-09-30",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-09-30"
    },
    {
      "value": "CVE-2023-24229",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1228",
          "title": "CISA KEV: CVE-2020-15415 \u2014 DrayTek Multiple Vigor Routers OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-09-30",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-09-30"
    },
    {
      "value": "CVE-2023-25280",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1229",
          "title": "CISA KEV: CVE-2023-25280 \u2014 D-Link DIR-820 Router OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-09-30",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-09-30"
    },
    {
      "value": "CVE-2024-41592",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1228",
          "title": "CISA KEV: CVE-2020-15415 \u2014 DrayTek Multiple Vigor Routers OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-09-30",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-09-30"
    },
    {
      "value": "zvub.us",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1229",
          "title": "CISA KEV: CVE-2023-25280 \u2014 D-Link DIR-820 Router OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-09-30",
          "sev": "crit"
        },
        {
          "id": "art-1666",
          "title": "CISA KEV: CVE-2022-29303 \u2014 SolarView Compact Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-07-13",
          "sev": "crit"
        },
        {
          "id": "art-1678",
          "title": "CISA KEV: CVE-2019-17621 \u2014 D-Link DIR-859 Router Command Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-06-29",
          "sev": "crit"
        },
        {
          "id": "art-1679",
          "title": "CISA KEV: CVE-2019-20500 \u2014 D-Link DWL-2600AP Access Point Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-06-29",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-09-30"
    },
    {
      "value": "185.225.74.251",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1229",
          "title": "CISA KEV: CVE-2023-25280 \u2014 D-Link DIR-820 Router OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-09-30",
          "sev": "crit"
        },
        {
          "id": "art-1666",
          "title": "CISA KEV: CVE-2022-29303 \u2014 SolarView Compact Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-07-13",
          "sev": "crit"
        },
        {
          "id": "art-1678",
          "title": "CISA KEV: CVE-2019-17621 \u2014 D-Link DIR-859 Router Command Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-06-29",
          "sev": "crit"
        },
        {
          "id": "art-1679",
          "title": "CISA KEV: CVE-2019-20500 \u2014 D-Link DWL-2600AP Access Point Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-06-29",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-09-30"
    },
    {
      "value": "185.44.81.114",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1229",
          "title": "CISA KEV: CVE-2023-25280 \u2014 D-Link DIR-820 Router OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-09-30",
          "sev": "crit"
        },
        {
          "id": "art-1666",
          "title": "CISA KEV: CVE-2022-29303 \u2014 SolarView Compact Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-07-13",
          "sev": "crit"
        },
        {
          "id": "art-1678",
          "title": "CISA KEV: CVE-2019-17621 \u2014 D-Link DIR-859 Router Command Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-06-29",
          "sev": "crit"
        },
        {
          "id": "art-1679",
          "title": "CISA KEV: CVE-2019-20500 \u2014 D-Link DWL-2600AP Access Point Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-06-29",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-09-30"
    },
    {
      "value": "193.32.162.189",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1229",
          "title": "CISA KEV: CVE-2023-25280 \u2014 D-Link DIR-820 Router OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-09-30",
          "sev": "crit"
        },
        {
          "id": "art-1666",
          "title": "CISA KEV: CVE-2022-29303 \u2014 SolarView Compact Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-07-13",
          "sev": "crit"
        },
        {
          "id": "art-1678",
          "title": "CISA KEV: CVE-2019-17621 \u2014 D-Link DIR-859 Router Command Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-06-29",
          "sev": "crit"
        },
        {
          "id": "art-1679",
          "title": "CISA KEV: CVE-2019-20500 \u2014 D-Link DWL-2600AP Access Point Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-06-29",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-09-30"
    },
    {
      "value": "0d404a27c2f511ea7f4adb8aa150f787b2b1ff36c1b67923d6d1c90179033915",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1229",
          "title": "CISA KEV: CVE-2023-25280 \u2014 D-Link DIR-820 Router OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-09-30",
          "sev": "crit"
        },
        {
          "id": "art-1666",
          "title": "CISA KEV: CVE-2022-29303 \u2014 SolarView Compact Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-07-13",
          "sev": "crit"
        },
        {
          "id": "art-1678",
          "title": "CISA KEV: CVE-2019-17621 \u2014 D-Link DIR-859 Router Command Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-06-29",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-09-30"
    },
    {
      "value": "2d0c8ab6c71743af8667c7318a6d8e16c144ace8df59a681a0a7d48affc05599",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1229",
          "title": "CISA KEV: CVE-2023-25280 \u2014 D-Link DIR-820 Router OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-09-30",
          "sev": "crit"
        },
        {
          "id": "art-1666",
          "title": "CISA KEV: CVE-2022-29303 \u2014 SolarView Compact Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-07-13",
          "sev": "crit"
        },
        {
          "id": "art-1678",
          "title": "CISA KEV: CVE-2019-17621 \u2014 D-Link DIR-859 Router Command Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-06-29",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-09-30"
    },
    {
      "value": "366ddbaa36791cdb99cf7104b0914a258f0c373a94f6cf869f946c7799d5e2c6",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1229",
          "title": "CISA KEV: CVE-2023-25280 \u2014 D-Link DIR-820 Router OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-09-30",
          "sev": "crit"
        },
        {
          "id": "art-1666",
          "title": "CISA KEV: CVE-2022-29303 \u2014 SolarView Compact Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-07-13",
          "sev": "crit"
        },
        {
          "id": "art-1678",
          "title": "CISA KEV: CVE-2019-17621 \u2014 D-Link DIR-859 Router Command Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-06-29",
          "sev": "crit"
        },
        {
          "id": "art-1679",
          "title": "CISA KEV: CVE-2019-20500 \u2014 D-Link DWL-2600AP Access Point Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-06-29",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-09-30"
    },
    {
      "value": "3f427eda4d4e18fb192d585fca1490389a1b5f796f88e7ebf3eceec51018ef4d",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1229",
          "title": "CISA KEV: CVE-2023-25280 \u2014 D-Link DIR-820 Router OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-09-30",
          "sev": "crit"
        },
        {
          "id": "art-1666",
          "title": "CISA KEV: CVE-2022-29303 \u2014 SolarView Compact Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-07-13",
          "sev": "crit"
        },
        {
          "id": "art-1678",
          "title": "CISA KEV: CVE-2019-17621 \u2014 D-Link DIR-859 Router Command Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-06-29",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-09-30"
    },
    {
      "value": "413e977ae7d359e2ea7fe32db73fa007ee97ee1e9e3c3f0b4163b100b3ec87c2",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1229",
          "title": "CISA KEV: CVE-2023-25280 \u2014 D-Link DIR-820 Router OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-09-30",
          "sev": "crit"
        },
        {
          "id": "art-1666",
          "title": "CISA KEV: CVE-2022-29303 \u2014 SolarView Compact Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-07-13",
          "sev": "crit"
        },
        {
          "id": "art-1678",
          "title": "CISA KEV: CVE-2019-17621 \u2014 D-Link DIR-859 Router Command Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-06-29",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-09-30"
    },
    {
      "value": "461f59a84ccb4805c4bbd37093df6e8791cdf1151b2746c46678dfe9f89ac79d",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1229",
          "title": "CISA KEV: CVE-2023-25280 \u2014 D-Link DIR-820 Router OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-09-30",
          "sev": "crit"
        },
        {
          "id": "art-1666",
          "title": "CISA KEV: CVE-2022-29303 \u2014 SolarView Compact Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-07-13",
          "sev": "crit"
        },
        {
          "id": "art-1678",
          "title": "CISA KEV: CVE-2019-17621 \u2014 D-Link DIR-859 Router Command Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-06-29",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-09-30"
    },
    {
      "value": "4cb8c90d1e1b2d725c2c1366700f11584f5697c9ef50d79e00f7dd2008e989a0",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1229",
          "title": "CISA KEV: CVE-2023-25280 \u2014 D-Link DIR-820 Router OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-09-30",
          "sev": "crit"
        },
        {
          "id": "art-1666",
          "title": "CISA KEV: CVE-2022-29303 \u2014 SolarView Compact Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-07-13",
          "sev": "crit"
        },
        {
          "id": "art-1678",
          "title": "CISA KEV: CVE-2019-17621 \u2014 D-Link DIR-859 Router Command Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-06-29",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-09-30"
    },
    {
      "value": "4f53eb7fbfa5b68cad3a0850b570cbbcb2d4864e62b5bf0492b54bde2bdbe44b",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1229",
          "title": "CISA KEV: CVE-2023-25280 \u2014 D-Link DIR-820 Router OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-09-30",
          "sev": "crit"
        },
        {
          "id": "art-1666",
          "title": "CISA KEV: CVE-2022-29303 \u2014 SolarView Compact Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-07-13",
          "sev": "crit"
        },
        {
          "id": "art-1678",
          "title": "CISA KEV: CVE-2019-17621 \u2014 D-Link DIR-859 Router Command Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-06-29",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-09-30"
    },
    {
      "value": "888f4a852642ce70197f77e213456ea2b3cfca4a592b94647827ca45adf2a5b8",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1229",
          "title": "CISA KEV: CVE-2023-25280 \u2014 D-Link DIR-820 Router OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-09-30",
          "sev": "crit"
        },
        {
          "id": "art-1666",
          "title": "CISA KEV: CVE-2022-29303 \u2014 SolarView Compact Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-07-13",
          "sev": "crit"
        },
        {
          "id": "art-1678",
          "title": "CISA KEV: CVE-2019-17621 \u2014 D-Link DIR-859 Router Command Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-06-29",
          "sev": "crit"
        },
        {
          "id": "art-1679",
          "title": "CISA KEV: CVE-2019-20500 \u2014 D-Link DWL-2600AP Access Point Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-06-29",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-09-30"
    },
    {
      "value": "aaf446e4e7bfc05a33c8d9e5acf56b1c7e95f2d919b98151ff2db327c333f089",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1229",
          "title": "CISA KEV: CVE-2023-25280 \u2014 D-Link DIR-820 Router OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-09-30",
          "sev": "crit"
        },
        {
          "id": "art-1666",
          "title": "CISA KEV: CVE-2022-29303 \u2014 SolarView Compact Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-07-13",
          "sev": "crit"
        },
        {
          "id": "art-1678",
          "title": "CISA KEV: CVE-2019-17621 \u2014 D-Link DIR-859 Router Command Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-06-29",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-09-30"
    },
    {
      "value": "aed078d3e65b5ff4dd4067ae30da5f3a96c87ec23ec5be44fc85b543c179b777",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1229",
          "title": "CISA KEV: CVE-2023-25280 \u2014 D-Link DIR-820 Router OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-09-30",
          "sev": "crit"
        },
        {
          "id": "art-1666",
          "title": "CISA KEV: CVE-2022-29303 \u2014 SolarView Compact Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-07-13",
          "sev": "crit"
        },
        {
          "id": "art-1678",
          "title": "CISA KEV: CVE-2019-17621 \u2014 D-Link DIR-859 Router Command Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-06-29",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-09-30"
    },
    {
      "value": "b43a8a56c10ba17ddd6fa9a8ce10ab264c6495b82a38620e9d54d66ec8677b0c",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1229",
          "title": "CISA KEV: CVE-2023-25280 \u2014 D-Link DIR-820 Router OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-09-30",
          "sev": "crit"
        },
        {
          "id": "art-1666",
          "title": "CISA KEV: CVE-2022-29303 \u2014 SolarView Compact Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-07-13",
          "sev": "crit"
        },
        {
          "id": "art-1678",
          "title": "CISA KEV: CVE-2019-17621 \u2014 D-Link DIR-859 Router Command Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-06-29",
          "sev": "crit"
        },
        {
          "id": "art-1679",
          "title": "CISA KEV: CVE-2019-20500 \u2014 D-Link DWL-2600AP Access Point Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-06-29",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-09-30"
    },
    {
      "value": "b45142a2d59d16991a38ea0a112078a6ce42c9e2ee28a74fb2ce7e1edf15dce3",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1229",
          "title": "CISA KEV: CVE-2023-25280 \u2014 D-Link DIR-820 Router OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-09-30",
          "sev": "crit"
        },
        {
          "id": "art-1666",
          "title": "CISA KEV: CVE-2022-29303 \u2014 SolarView Compact Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-07-13",
          "sev": "crit"
        },
        {
          "id": "art-1678",
          "title": "CISA KEV: CVE-2019-17621 \u2014 D-Link DIR-859 Router Command Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-06-29",
          "sev": "crit"
        },
        {
          "id": "art-1679",
          "title": "CISA KEV: CVE-2019-20500 \u2014 D-Link DWL-2600AP Access Point Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-06-29",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-09-30"
    },
    {
      "value": "eca42235a41dbd60615d91d564c91933b9903af2ef3f8356ec4cfff2880a2f19",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1229",
          "title": "CISA KEV: CVE-2023-25280 \u2014 D-Link DIR-820 Router OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-09-30",
          "sev": "crit"
        },
        {
          "id": "art-1666",
          "title": "CISA KEV: CVE-2022-29303 \u2014 SolarView Compact Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-07-13",
          "sev": "crit"
        },
        {
          "id": "art-1678",
          "title": "CISA KEV: CVE-2019-17621 \u2014 D-Link DIR-859 Router Command Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-06-29",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-09-30"
    },
    {
      "value": "CVE-2024-47076",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-1230",
          "title": "Zero-day RCE vulnerability found in CUPS - Common UNIX Printing System",
          "link": "https://snyk.io/blog/zero-day-rce-in-cups-vulnerability-sept-2024/",
          "published": "2024-09-27",
          "sev": "high"
        }
      ],
      "first_seen": "2024-09-27"
    },
    {
      "value": "CVE-2024-47175",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-1230",
          "title": "Zero-day RCE vulnerability found in CUPS - Common UNIX Printing System",
          "link": "https://snyk.io/blog/zero-day-rce-in-cups-vulnerability-sept-2024/",
          "published": "2024-09-27",
          "sev": "high"
        }
      ],
      "first_seen": "2024-09-27"
    },
    {
      "value": "CVE-2024-47176",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-1230",
          "title": "Zero-day RCE vulnerability found in CUPS - Common UNIX Printing System",
          "link": "https://snyk.io/blog/zero-day-rce-in-cups-vulnerability-sept-2024/",
          "published": "2024-09-27",
          "sev": "high"
        }
      ],
      "first_seen": "2024-09-27"
    },
    {
      "value": "CVE-2024-47177",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-1230",
          "title": "Zero-day RCE vulnerability found in CUPS - Common UNIX Printing System",
          "link": "https://snyk.io/blog/zero-day-rce-in-cups-vulnerability-sept-2024/",
          "published": "2024-09-27",
          "sev": "high"
        }
      ],
      "first_seen": "2024-09-27"
    },
    {
      "value": "CVE-2024-7593",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1234",
          "title": "CISA KEV: CVE-2024-7593 \u2014 Ivanti Virtual Traffic Manager Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-09-24",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-09-24"
    },
    {
      "value": "test.vip8025.mom",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1236",
          "title": "CISA KEV: CVE-2024-8963 \u2014 Ivanti Cloud Services Appliance (CSA) Path Traversal Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-09-19",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-09-19"
    },
    {
      "value": "vip8806.mom",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1236",
          "title": "CISA KEV: CVE-2024-8963 \u2014 Ivanti Cloud Services Appliance (CSA) Path Traversal Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-09-19",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-09-19"
    },
    {
      "value": "www.vip8025.mom",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1236",
          "title": "CISA KEV: CVE-2024-8963 \u2014 Ivanti Cloud Services Appliance (CSA) Path Traversal Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-09-19",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-09-19"
    },
    {
      "value": "156.251.172.80",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1236",
          "title": "CISA KEV: CVE-2024-8963 \u2014 Ivanti Cloud Services Appliance (CSA) Path Traversal Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-09-19",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-09-19"
    },
    {
      "value": "195.133.52.87",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1236",
          "title": "CISA KEV: CVE-2024-8963 \u2014 Ivanti Cloud Services Appliance (CSA) Path Traversal Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-09-19",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-09-19"
    },
    {
      "value": "8.218.239.22",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1236",
          "title": "CISA KEV: CVE-2024-8963 \u2014 Ivanti Cloud Services Appliance (CSA) Path Traversal Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-09-19",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-09-19"
    },
    {
      "value": "074739c7ccdee5baef649b7f7cb53668109be8f7e016294b66a5d1469803e42b",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1236",
          "title": "CISA KEV: CVE-2024-8963 \u2014 Ivanti Cloud Services Appliance (CSA) Path Traversal Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-09-19",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-09-19"
    },
    {
      "value": "4c86e8c21451074a52cc8d60a262c683aaf4cb6b2634fea8efdd866ea2dbd3aa",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1236",
          "title": "CISA KEV: CVE-2024-8963 \u2014 Ivanti Cloud Services Appliance (CSA) Path Traversal Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-09-19",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-09-19"
    },
    {
      "value": "61928ff36c5d8983853ec2f411860b97231729f047527434d3b2db8bf0b42d25",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1236",
          "title": "CISA KEV: CVE-2024-8963 \u2014 Ivanti Cloud Services Appliance (CSA) Path Traversal Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-09-19",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-09-19"
    },
    {
      "value": "7798b45ffc488356f7253805dc9c8d2210552bee39db9082f772185430360574",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1236",
          "title": "CISA KEV: CVE-2024-8963 \u2014 Ivanti Cloud Services Appliance (CSA) Path Traversal Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-09-19",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-09-19"
    },
    {
      "value": "9f97997581f513166aae47b3664ca23c4f4ea90c24916874ff82891e2cd6e01e",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1236",
          "title": "CISA KEV: CVE-2024-8963 \u2014 Ivanti Cloud Services Appliance (CSA) Path Traversal Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-09-19",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-09-19"
    },
    {
      "value": "af3f4ece0d98999077cef265c1af9610b96cb7cf3264c115cc6c210cdd9636fe",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1236",
          "title": "CISA KEV: CVE-2024-8963 \u2014 Ivanti Cloud Services Appliance (CSA) Path Traversal Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-09-19",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-09-19"
    },
    {
      "value": "c64bd109100aac96eba627ca94c1161c8329378e3e8c75a1763c26b70c921891",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1236",
          "title": "CISA KEV: CVE-2024-8963 \u2014 Ivanti Cloud Services Appliance (CSA) Path Traversal Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-09-19",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-09-19"
    },
    {
      "value": "cae96b72244855a3d98a42bb3f65daab1cd06e9be638553e2ebf1f8a66b5cc8a",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1236",
          "title": "CISA KEV: CVE-2024-8963 \u2014 Ivanti Cloud Services Appliance (CSA) Path Traversal Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-09-19",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-09-19"
    },
    {
      "value": "CVE-2020-0618",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1240",
          "title": "CISA KEV: CVE-2020-0618 \u2014 Microsoft SQL Server Reporting Services Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-09-18",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-09-18"
    },
    {
      "value": "CVE-2020-14644",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1238",
          "title": "CISA KEV: CVE-2020-14644 \u2014 Oracle WebLogic Server Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-09-18",
          "sev": "crit"
        },
        {
          "id": "art-1239",
          "title": "CISA KEV: CVE-2022-21445 \u2014 Oracle ADF Faces Deserialization of Untrusted Data Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-09-18",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-09-18"
    },
    {
      "value": "CVE-2022-21445",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1239",
          "title": "CISA KEV: CVE-2022-21445 \u2014 Oracle ADF Faces Deserialization of Untrusted Data Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-09-18",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-09-18"
    },
    {
      "value": "CVE-2022-21497",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1239",
          "title": "CISA KEV: CVE-2022-21445 \u2014 Oracle ADF Faces Deserialization of Untrusted Data Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-09-18",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-09-18"
    },
    {
      "value": "CVE-2024-27348",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1241",
          "title": "CISA KEV: CVE-2024-27348 \u2014 Apache HugeGraph-Server Improper Access Control Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-09-18",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-09-18"
    },
    {
      "value": "CVE-2013-0643",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1245",
          "title": "CISA KEV: CVE-2013-0643 \u2014 Adobe Flash Player Incorrect Default Permissions Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-09-17",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-09-17"
    },
    {
      "value": "CVE-2013-0648",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1244",
          "title": "CISA KEV: CVE-2013-0648 \u2014 Adobe Flash Player Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-09-17",
          "sev": "crit"
        },
        {
          "id": "art-1245",
          "title": "CISA KEV: CVE-2013-0643 \u2014 Adobe Flash Player Incorrect Default Permissions Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-09-17",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-09-17"
    },
    {
      "value": "CVE-2014-0502",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1243",
          "title": "CISA KEV: CVE-2014-0502 \u2014 Adobe Flash Player Double Free Vulnerablity",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-09-17",
          "sev": "crit"
        },
        {
          "id": "art-1246",
          "title": "CISA KEV: CVE-2014-0497 \u2014 Adobe Flash Player Integer Underflow Vulnerablity",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-09-17",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-09-17"
    },
    {
      "value": "adservice.no-ip.org",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1246",
          "title": "CISA KEV: CVE-2014-0497 \u2014 Adobe Flash Player Integer Underflow Vulnerablity",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-09-17",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-09-17"
    },
    {
      "value": "giftserv.hopto.org",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1246",
          "title": "CISA KEV: CVE-2014-0497 \u2014 Adobe Flash Player Integer Underflow Vulnerablity",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-09-17",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-09-17"
    },
    {
      "value": "ids.ns01.us",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1246",
          "title": "CISA KEV: CVE-2014-0497 \u2014 Adobe Flash Player Integer Underflow Vulnerablity",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-09-17",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-09-17"
    },
    {
      "value": "java.ns1.name",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1246",
          "title": "CISA KEV: CVE-2014-0497 \u2014 Adobe Flash Player Integer Underflow Vulnerablity",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-09-17",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-09-17"
    },
    {
      "value": "static.5ljob.net",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1246",
          "title": "CISA KEV: CVE-2014-0497 \u2014 Adobe Flash Player Integer Underflow Vulnerablity",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-09-17",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-09-17"
    },
    {
      "value": "wmi.ns01.us",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1246",
          "title": "CISA KEV: CVE-2014-0497 \u2014 Adobe Flash Player Integer Underflow Vulnerablity",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-09-17",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-09-17"
    },
    {
      "value": "103.246.246.103",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1246",
          "title": "CISA KEV: CVE-2014-0497 \u2014 Adobe Flash Player Integer Underflow Vulnerablity",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-09-17",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-09-17"
    },
    {
      "value": "192.74.246.219",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1246",
          "title": "CISA KEV: CVE-2014-0497 \u2014 Adobe Flash Player Integer Underflow Vulnerablity",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-09-17",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-09-17"
    },
    {
      "value": "194.183.224.75",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1246",
          "title": "CISA KEV: CVE-2014-0497 \u2014 Adobe Flash Player Integer Underflow Vulnerablity",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-09-17",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-09-17"
    },
    {
      "value": "74.126.177.68",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1246",
          "title": "CISA KEV: CVE-2014-0497 \u2014 Adobe Flash Player Integer Underflow Vulnerablity",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-09-17",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-09-17"
    },
    {
      "value": "9d4a89cdefc71e9bfadc7566d2d9d9d2bdf7dc2847df4fcbf01e0a342ab5eead",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1246",
          "title": "CISA KEV: CVE-2014-0497 \u2014 Adobe Flash Player Integer Underflow Vulnerablity",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-09-17",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-09-17"
    },
    {
      "value": "CVE-2024-6670",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1248",
          "title": "CISA KEV: CVE-2024-6670 \u2014 Progress WhatsUp Gold SQL Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-09-16",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-09-16"
    },
    {
      "value": "CVE-2024-6671",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1248",
          "title": "CISA KEV: CVE-2024-6670 \u2014 Progress WhatsUp Gold SQL Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-09-16",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-09-16"
    },
    {
      "value": "8c69830a50fb85d8a794fa46643493b2",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1248",
          "title": "CISA KEV: CVE-2024-6670 \u2014 Progress WhatsUp Gold SQL Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-09-16",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-09-16"
    },
    {
      "value": "bbcf7a68f4164a9f5f5cb2d9f30d9790",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1248",
          "title": "CISA KEV: CVE-2024-6670 \u2014 Progress WhatsUp Gold SQL Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-09-16",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-09-16"
    },
    {
      "value": "c67b03c0a91eaefffd2f2c79b5c26a2648b8d3c19a22cadf35453455ff08ead0",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1248",
          "title": "CISA KEV: CVE-2024-6670 \u2014 Progress WhatsUp Gold SQL Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-09-16",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-09-16"
    },
    {
      "value": "6edd7b3123de985846a805931ca8ee5f5f7ed7b160144aa0e066967bc7c0423a",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1250",
          "title": "CISA KEV: CVE-2024-8190 \u2014 Ivanti Cloud Services Appliance OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-09-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-09-13"
    },
    {
      "value": "CVE-2024-38014",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1252",
          "title": "CISA KEV: CVE-2024-38014 \u2014 Microsoft Windows Installer Improper Privilege Management Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-09-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-09-10"
    },
    {
      "value": "CVE-2024-38217",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1251",
          "title": "CISA KEV: CVE-2024-38217 \u2014 Microsoft Windows Mark of the Web (MOTW) Protection Mechanism Failure Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-09-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-09-10"
    },
    {
      "value": "CVE-2024-38226",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1253",
          "title": "CISA KEV: CVE-2024-38226 \u2014 Microsoft Publisher Protection Mechanism Failure Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-09-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-09-10"
    },
    {
      "value": "11dadc71018027c7e005a70c306532e5ea7abdc389964cbc85cf3b79f97f6b44",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1251",
          "title": "CISA KEV: CVE-2024-38217 \u2014 Microsoft Windows Mark of the Web (MOTW) Protection Mechanism Failure Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-09-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-09-10"
    },
    {
      "value": "4e213bd0a127f1bb24c4c0d971c2727097b04eed9c6e62a57110d168ccc3ba10",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1251",
          "title": "CISA KEV: CVE-2024-38217 \u2014 Microsoft Windows Mark of the Web (MOTW) Protection Mechanism Failure Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-09-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-09-10"
    },
    {
      "value": "ba35b8b4346b79b8bb4f97360025cb6befaf501b03149a3b5fef8f07bdf265c7",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1251",
          "title": "CISA KEV: CVE-2024-38217 \u2014 Microsoft Windows Mark of the Web (MOTW) Protection Mechanism Failure Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-09-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-09-10"
    },
    {
      "value": "CVE-2016-3714",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV",
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-1257",
          "title": "CISA KEV: CVE-2016-3714 \u2014 ImageMagick Improper Input Validation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-09-09",
          "sev": "crit"
        },
        {
          "id": "art-3221",
          "title": "How I was hacking docker containers by exploiting ImageMagick vulnerabilities",
          "link": "https://snyk.io/blog/hacking-docker-containers-by-exploiting-base-image-vulnerabilities/",
          "published": "2021-03-11",
          "sev": "high"
        }
      ],
      "first_seen": "2024-09-09"
    },
    {
      "value": "CVE-2017-1000253",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1256",
          "title": "CISA KEV: CVE-2017-1000253 \u2014 Linux Kernel PIE Stack Buffer Corruption Vulnerability ",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-09-09",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-09-09"
    },
    {
      "value": "104.194.11.34",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1255",
          "title": "CISA KEV: CVE-2024-40766 \u2014 SonicWall SonicOS Improper Access Control Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-09-09",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-09-09"
    },
    {
      "value": "107.155.93.154",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1255",
          "title": "CISA KEV: CVE-2024-40766 \u2014 SonicWall SonicOS Improper Access Control Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-09-09",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-09-09"
    },
    {
      "value": "107.175.102.58",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1255",
          "title": "CISA KEV: CVE-2024-40766 \u2014 SonicWall SonicOS Improper Access Control Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-09-09",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-09-09"
    },
    {
      "value": "144.168.41.74",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1255",
          "title": "CISA KEV: CVE-2024-40766 \u2014 SonicWall SonicOS Improper Access Control Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-09-09",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-09-09"
    },
    {
      "value": "155.117.117.34",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1255",
          "title": "CISA KEV: CVE-2024-40766 \u2014 SonicWall SonicOS Improper Access Control Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-09-09",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-09-09"
    },
    {
      "value": "162.210.196.101",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1255",
          "title": "CISA KEV: CVE-2024-40766 \u2014 SonicWall SonicOS Improper Access Control Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-09-09",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-09-09"
    },
    {
      "value": "185.174.100.199",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1255",
          "title": "CISA KEV: CVE-2024-40766 \u2014 SonicWall SonicOS Improper Access Control Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-09-09",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-09-09"
    },
    {
      "value": "185.181.230.108",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1255",
          "title": "CISA KEV: CVE-2024-40766 \u2014 SonicWall SonicOS Improper Access Control Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-09-09",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-09-09"
    },
    {
      "value": "185.33.86.2",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1255",
          "title": "CISA KEV: CVE-2024-40766 \u2014 SonicWall SonicOS Improper Access Control Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-09-09",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-09-09"
    },
    {
      "value": "193.163.194.7",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1255",
          "title": "CISA KEV: CVE-2024-40766 \u2014 SonicWall SonicOS Improper Access Control Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-09-09",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-09-09"
    },
    {
      "value": "193.239.236.149",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1255",
          "title": "CISA KEV: CVE-2024-40766 \u2014 SonicWall SonicOS Improper Access Control Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-09-09",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-09-09"
    },
    {
      "value": "193.29.63.226",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1255",
          "title": "CISA KEV: CVE-2024-40766 \u2014 SonicWall SonicOS Improper Access Control Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-09-09",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-09-09"
    },
    {
      "value": "194.33.45.194",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1255",
          "title": "CISA KEV: CVE-2024-40766 \u2014 SonicWall SonicOS Improper Access Control Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-09-09",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-09-09"
    },
    {
      "value": "206.168.190.143",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1255",
          "title": "CISA KEV: CVE-2024-40766 \u2014 SonicWall SonicOS Improper Access Control Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-09-09",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-09-09"
    },
    {
      "value": "207.188.6.17",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1255",
          "title": "CISA KEV: CVE-2024-40766 \u2014 SonicWall SonicOS Improper Access Control Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-09-09",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-09-09"
    },
    {
      "value": "23.94.54.125",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1255",
          "title": "CISA KEV: CVE-2024-40766 \u2014 SonicWall SonicOS Improper Access Control Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-09-09",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-09-09"
    },
    {
      "value": "31.222.247.64",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1255",
          "title": "CISA KEV: CVE-2024-40766 \u2014 SonicWall SonicOS Improper Access Control Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-09-09",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-09-09"
    },
    {
      "value": "38.114.123.167",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1255",
          "title": "CISA KEV: CVE-2024-40766 \u2014 SonicWall SonicOS Improper Access Control Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-09-09",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-09-09"
    },
    {
      "value": "38.114.123.229",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1255",
          "title": "CISA KEV: CVE-2024-40766 \u2014 SonicWall SonicOS Improper Access Control Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-09-09",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-09-09"
    },
    {
      "value": "45.55.76.210",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1255",
          "title": "CISA KEV: CVE-2024-40766 \u2014 SonicWall SonicOS Improper Access Control Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-09-09",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-09-09"
    },
    {
      "value": "45.56.163.58",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1255",
          "title": "CISA KEV: CVE-2024-40766 \u2014 SonicWall SonicOS Improper Access Control Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-09-09",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-09-09"
    },
    {
      "value": "45.66.249.93",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1255",
          "title": "CISA KEV: CVE-2024-40766 \u2014 SonicWall SonicOS Improper Access Control Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-09-09",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-09-09"
    },
    {
      "value": "62.76.147.106",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1255",
          "title": "CISA KEV: CVE-2024-40766 \u2014 SonicWall SonicOS Improper Access Control Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-09-09",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-09-09"
    },
    {
      "value": "77.247.126.239",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1255",
          "title": "CISA KEV: CVE-2024-40766 \u2014 SonicWall SonicOS Improper Access Control Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-09-09",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-09-09"
    },
    {
      "value": "79.141.160.33",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1255",
          "title": "CISA KEV: CVE-2024-40766 \u2014 SonicWall SonicOS Improper Access Control Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-09-09",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-09-09"
    },
    {
      "value": "79.141.173.235",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1255",
          "title": "CISA KEV: CVE-2024-40766 \u2014 SonicWall SonicOS Improper Access Control Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-09-09",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-09-09"
    },
    {
      "value": "83.229.17.123",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1255",
          "title": "CISA KEV: CVE-2024-40766 \u2014 SonicWall SonicOS Improper Access Control Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-09-09",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-09-09"
    },
    {
      "value": "83.229.17.135",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1255",
          "title": "CISA KEV: CVE-2024-40766 \u2014 SonicWall SonicOS Improper Access Control Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-09-09",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-09-09"
    },
    {
      "value": "83.229.17.148",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1255",
          "title": "CISA KEV: CVE-2024-40766 \u2014 SonicWall SonicOS Improper Access Control Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-09-09",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-09-09"
    },
    {
      "value": "91.191.214.170",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1255",
          "title": "CISA KEV: CVE-2024-40766 \u2014 SonicWall SonicOS Improper Access Control Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-09-09",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-09-09"
    },
    {
      "value": "CVE-2023-0568",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-1258",
          "title": "What you should know about PHP code security",
          "link": "https://snyk.io/blog/php-code-security/",
          "published": "2024-09-04",
          "sev": "high"
        }
      ],
      "first_seen": "2024-09-04"
    },
    {
      "value": "CVE-2023-0662",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-1258",
          "title": "What you should know about PHP code security",
          "link": "https://snyk.io/blog/php-code-security/",
          "published": "2024-09-04",
          "sev": "high"
        }
      ],
      "first_seen": "2024-09-04"
    },
    {
      "value": "CVE-2023-3823",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-1258",
          "title": "What you should know about PHP code security",
          "link": "https://snyk.io/blog/php-code-security/",
          "published": "2024-09-04",
          "sev": "high"
        }
      ],
      "first_seen": "2024-09-04"
    },
    {
      "value": "CVE-2021-20123",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1263",
          "title": "CISA KEV: CVE-2021-20123 \u2014 Draytek VigorConnect Path Traversal Vulnerability ",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-09-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-09-03"
    },
    {
      "value": "CVE-2021-20124",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1262",
          "title": "CISA KEV: CVE-2021-20124 \u2014 Draytek VigorConnect Path Traversal Vulnerability ",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-09-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-09-03"
    },
    {
      "value": "CVE-2024-7262",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1261",
          "title": "CISA KEV: CVE-2024-7262 \u2014 Kingsoft WPS Office Path Traversal Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-09-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-09-03"
    },
    {
      "value": "CVE-2024-7263",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1261",
          "title": "CISA KEV: CVE-2024-7262 \u2014 Kingsoft WPS Office Path Traversal Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-09-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-09-03"
    },
    {
      "value": "rammenale.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1261",
          "title": "CISA KEV: CVE-2024-7262 \u2014 Kingsoft WPS Office Path Traversal Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-09-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-09-03"
    },
    {
      "value": "131.153.206.231",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1261",
          "title": "CISA KEV: CVE-2024-7262 \u2014 Kingsoft WPS Office Path Traversal Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-09-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-09-03"
    },
    {
      "value": "162.222.214.48",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1261",
          "title": "CISA KEV: CVE-2024-7262 \u2014 Kingsoft WPS Office Path Traversal Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-09-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-09-03"
    },
    {
      "value": "9f88234068d7abad65979eb1df63efb5",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1261",
          "title": "CISA KEV: CVE-2024-7262 \u2014 Kingsoft WPS Office Path Traversal Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-09-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-09-03"
    },
    {
      "value": "b14ef85a60ac71c669cc960bdf580144",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1261",
          "title": "CISA KEV: CVE-2024-7262 \u2014 Kingsoft WPS Office Path Traversal Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-09-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-09-03"
    },
    {
      "value": "08906644b0ef1ee6478c45a6e0dd28533a9efc29",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1261",
          "title": "CISA KEV: CVE-2024-7262 \u2014 Kingsoft WPS Office Path Traversal Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-09-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-09-03"
    },
    {
      "value": "7509b4c506c01627c1a4c396161d07277f044ac6",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1261",
          "title": "CISA KEV: CVE-2024-7262 \u2014 Kingsoft WPS Office Path Traversal Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-09-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-09-03"
    },
    {
      "value": "6174276f94219bc386bdc628ca18eaec261998b7bd03077562fe93c268b42446",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1261",
          "title": "CISA KEV: CVE-2024-7262 \u2014 Kingsoft WPS Office Path Traversal Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-09-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-09-03"
    },
    {
      "value": "861911e953e6fd0a015b3a91a7528a388a535c83f4b9a5cf7366b8209d2f00c3",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1261",
          "title": "CISA KEV: CVE-2024-7262 \u2014 Kingsoft WPS Office Path Traversal Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-09-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-09-03"
    },
    {
      "value": "CVE-2022-22965",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "Snyk",
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1264",
          "title": "The persistent threat: Why major vulnerabilities like Log4Shell and Spring4Shell remain significant",
          "link": "https://snyk.io/blog/log4shell-spring4shell-threat/",
          "published": "2024-08-29",
          "sev": "high"
        },
        {
          "id": "art-2099",
          "title": "Controlling your server with a reverse shell attack",
          "link": "https://snyk.io/blog/reverse-shell-attack/",
          "published": "2022-08-10",
          "sev": "crit"
        },
        {
          "id": "art-2351",
          "title": "Spring4Shell extends to Glassfish and Payara: same vulnerability, new exploit",
          "link": "https://snyk.io/blog/spring4shell-rce-vulnerability-glassfish-payara/",
          "published": "2022-04-08",
          "sev": "crit"
        },
        {
          "id": "art-2360",
          "title": "CISA KEV: CVE-2022-22965 \u2014 Spring Framework JDK 9+ Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-04-04",
          "sev": "crit"
        },
        {
          "id": "art-2366",
          "title": "Spring4Shell: The zero-day RCE in the Spring Framework explained",
          "link": "https://snyk.io/blog/spring4shell-zero-day-rce-spring-framework-explained/",
          "published": "2022-04-01",
          "sev": "crit"
        },
        {
          "id": "art-2368",
          "title": "Spring4Shell: What we know about the Java RCE vulnerability",
          "link": "https://snyk.io/blog/is-there-such-a-thing-as-spring4shell/",
          "published": "2022-03-31",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-08-29"
    },
    {
      "value": "CVE-2024-7965",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1265",
          "title": "CISA KEV: CVE-2024-7965 \u2014 Google Chromium V8 Inappropriate Implementation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-08-28",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-08-28"
    },
    {
      "value": "CVE-2024-32113",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1267",
          "title": "CISA KEV: CVE-2024-38856 \u2014 Apache OFBiz Incorrect Authorization Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-08-27",
          "sev": "crit"
        },
        {
          "id": "art-1290",
          "title": "CISA KEV: CVE-2024-32113 \u2014 Apache OFBiz Path Traversal Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-08-07",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-08-27"
    },
    {
      "value": "CVE-2024-36104",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1267",
          "title": "CISA KEV: CVE-2024-38856 \u2014 Apache OFBiz Incorrect Authorization Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-08-27",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-08-27"
    },
    {
      "value": "CVE-2024-38856",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1267",
          "title": "CISA KEV: CVE-2024-38856 \u2014 Apache OFBiz Incorrect Authorization Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-08-27",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-08-27"
    },
    {
      "value": "CVE-2024-21338",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1270",
          "title": "CISA KEV: CVE-2024-7971 \u2014 Google Chromium V8 Type Confusion Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-08-26",
          "sev": "crit"
        },
        {
          "id": "art-1285",
          "title": "CISA KEV: CVE-2024-38193 \u2014 Microsoft Windows Ancillary Function Driver for WinSock Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-08-13",
          "sev": "crit"
        },
        {
          "id": "art-1412",
          "title": "CISA KEV: CVE-2024-21338 \u2014 Microsoft Windows Kernel Exposed IOCTL with Insufficient Access Control Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-03-04",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-08-26"
    },
    {
      "value": "CVE-2024-38106",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1270",
          "title": "CISA KEV: CVE-2024-7971 \u2014 Google Chromium V8 Type Confusion Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-08-26",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-08-26"
    },
    {
      "value": "CVE-2024-38193",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1270",
          "title": "CISA KEV: CVE-2024-7971 \u2014 Google Chromium V8 Type Confusion Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-08-26",
          "sev": "crit"
        },
        {
          "id": "art-1285",
          "title": "CISA KEV: CVE-2024-38193 \u2014 Microsoft Windows Ancillary Function Driver for WinSock Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-08-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-08-26"
    },
    {
      "value": "CVE-2024-7971",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1270",
          "title": "CISA KEV: CVE-2024-7971 \u2014 Google Chromium V8 Type Confusion Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-08-26",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-08-26"
    },
    {
      "value": "voyagorclub.space",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1270",
          "title": "CISA KEV: CVE-2024-7971 \u2014 Google Chromium V8 Type Confusion Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-08-26",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-08-26"
    },
    {
      "value": "weinsteinfrog.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1270",
          "title": "CISA KEV: CVE-2024-7971 \u2014 Google Chromium V8 Type Confusion Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-08-26",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-08-26"
    },
    {
      "value": "CVE-2024-39717",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1271",
          "title": "CISA KEV: CVE-2024-39717 \u2014 Versa Director Dangerous File Type Upload Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-08-23",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-08-23"
    },
    {
      "value": "4bcedac20a75e8f8833f4725adfc87577c32990c3783bf6c743f14599a176c37",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1271",
          "title": "CISA KEV: CVE-2024-39717 \u2014 Versa Director Dangerous File Type Upload Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-08-23",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-08-23"
    },
    {
      "value": "CVE-2021-31196",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1273",
          "title": "CISA KEV: CVE-2021-31196 \u2014 Microsoft Exchange Server Information Disclosure Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-08-21",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-08-21"
    },
    {
      "value": "CVE-2021-33045",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1275",
          "title": "CISA KEV: CVE-2021-33045 \u2014 Dahua IP Camera Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-08-21",
          "sev": "crit"
        },
        {
          "id": "art-1276",
          "title": "CISA KEV: CVE-2021-33044 \u2014 Dahua IP Camera Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-08-21",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-08-21"
    },
    {
      "value": "CVE-2022-0185",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1274",
          "title": "CISA KEV: CVE-2022-0185 \u2014 Linux Kernel Heap-Based Buffer Overflow Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-08-21",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-08-21"
    },
    {
      "value": "CVE-2024-23897",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1277",
          "title": "CISA KEV: CVE-2024-23897 \u2014 Jenkins Command Line Interface (CLI) Path Traversal Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-08-19",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-08-19"
    },
    {
      "value": "CVE-2024-28986",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1279",
          "title": "CISA KEV: CVE-2024-28986 \u2014 SolarWinds Web Help Desk Deserialization of Untrusted Data Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-08-15",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-08-15"
    },
    {
      "value": "CVE-2020-1380",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1287",
          "title": "CISA KEV: CVE-2024-38178 \u2014 Microsoft Windows Scripting Engine Memory Corruption Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-08-13",
          "sev": "crit"
        },
        {
          "id": "art-2939",
          "title": "CISA KEV: CVE-2020-0986 \u2014 Microsoft Windows Kernel Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        },
        {
          "id": "art-2977",
          "title": "CISA KEV: CVE-2020-1380 \u2014 Microsoft Internet Explorer Scripting Engine Memory Corruption Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-08-13"
    },
    {
      "value": "CVE-2022-41128",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1287",
          "title": "CISA KEV: CVE-2024-38178 \u2014 Microsoft Windows Scripting Engine Memory Corruption Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-08-13",
          "sev": "crit"
        },
        {
          "id": "art-1956",
          "title": "CISA KEV: CVE-2022-41128 \u2014 Microsoft Windows Scripting Languages Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-11-08",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-08-13"
    },
    {
      "value": "CVE-2023-36025",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1286",
          "title": "CISA KEV: CVE-2024-38213 \u2014 Microsoft Windows SmartScreen Security Feature Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-08-13",
          "sev": "crit"
        },
        {
          "id": "art-1372",
          "title": "CISA KEV: CVE-2024-29988 \u2014 Microsoft SmartScreen Prompt Security Feature Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-04-30",
          "sev": "crit"
        },
        {
          "id": "art-1429",
          "title": "CISA KEV: CVE-2024-21351 \u2014 Microsoft Windows SmartScreen Security Feature Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-02-13",
          "sev": "crit"
        },
        {
          "id": "art-1519",
          "title": "CISA KEV: CVE-2023-36025 \u2014 Microsoft Windows SmartScreen Security Feature Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-11-14",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-08-13"
    },
    {
      "value": "CVE-2024-21412",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1286",
          "title": "CISA KEV: CVE-2024-38213 \u2014 Microsoft Windows SmartScreen Security Feature Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-08-13",
          "sev": "crit"
        },
        {
          "id": "art-1372",
          "title": "CISA KEV: CVE-2024-29988 \u2014 Microsoft SmartScreen Prompt Security Feature Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-04-30",
          "sev": "crit"
        },
        {
          "id": "art-1428",
          "title": "CISA KEV: CVE-2024-21412 \u2014 Microsoft Windows Internet Shortcut Files Security Feature Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-02-13",
          "sev": "crit"
        },
        {
          "id": "art-1429",
          "title": "CISA KEV: CVE-2024-21351 \u2014 Microsoft Windows SmartScreen Security Feature Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-02-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-08-13"
    },
    {
      "value": "CVE-2024-29988",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1286",
          "title": "CISA KEV: CVE-2024-38213 \u2014 Microsoft Windows SmartScreen Security Feature Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-08-13",
          "sev": "crit"
        },
        {
          "id": "art-1372",
          "title": "CISA KEV: CVE-2024-29988 \u2014 Microsoft SmartScreen Prompt Security Feature Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-04-30",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-08-13"
    },
    {
      "value": "CVE-2024-38107",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1283",
          "title": "CISA KEV: CVE-2024-38107 \u2014 Microsoft Windows Power Dependency Coordinator Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-08-13",
          "sev": "crit"
        },
        {
          "id": "art-1284",
          "title": "CISA KEV: CVE-2024-38106 \u2014 Microsoft Windows Kernel Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-08-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-08-13"
    },
    {
      "value": "CVE-2024-38178",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1287",
          "title": "CISA KEV: CVE-2024-38178 \u2014 Microsoft Windows Scripting Engine Memory Corruption Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-08-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-08-13"
    },
    {
      "value": "CVE-2024-38189",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1288",
          "title": "CISA KEV: CVE-2024-38189 \u2014 Microsoft Project Remote Code Execution Vulnerability ",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-08-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-08-13"
    },
    {
      "value": "CVE-2024-38213",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1286",
          "title": "CISA KEV: CVE-2024-38213 \u2014 Microsoft Windows SmartScreen Security Feature Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-08-13",
          "sev": "crit"
        },
        {
          "id": "art-1372",
          "title": "CISA KEV: CVE-2024-29988 \u2014 Microsoft SmartScreen Prompt Security Feature Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-04-30",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-08-13"
    },
    {
      "value": "e11bb2478930d0b5f6c473464f2a2b6e",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1287",
          "title": "CISA KEV: CVE-2024-38178 \u2014 Microsoft Windows Scripting Engine Memory Corruption Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-08-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-08-13"
    },
    {
      "value": "1277b7f12af65d3590f7e06672413698255214dfab3bdf7668d5846577c00368",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1286",
          "title": "CISA KEV: CVE-2024-38213 \u2014 Microsoft Windows SmartScreen Security Feature Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-08-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-08-13"
    },
    {
      "value": "49bef5b4b64221297f90380092f6eba6014d81f6f517e82e42f4906087b20d19",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1286",
          "title": "CISA KEV: CVE-2024-38213 \u2014 Microsoft Windows SmartScreen Security Feature Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-08-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-08-13"
    },
    {
      "value": "736092b71a9686fde43d3c4abd941a6774721b90b17d946c9d05af19c84df0a4",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1287",
          "title": "CISA KEV: CVE-2024-38178 \u2014 Microsoft Windows Scripting Engine Memory Corruption Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-08-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-08-13"
    },
    {
      "value": "bb2f8dff11bd99bcfbc0544d29a5e690701fc242c8188e68192371768bec6f7d",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1286",
          "title": "CISA KEV: CVE-2024-38213 \u2014 Microsoft Windows SmartScreen Security Feature Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-08-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-08-13"
    },
    {
      "value": "CVE-2024-36971",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1291",
          "title": "CISA KEV: CVE-2024-36971 \u2014 Android Kernel Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-08-07",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-08-07"
    },
    {
      "value": "CVE-2018-0824",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1294",
          "title": "CISA KEV: CVE-2018-0824 \u2014 Microsoft COM for Windows Deserialization of Untrusted Data Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-08-05",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-08-05"
    },
    {
      "value": "w2.chatgptsfit.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1294",
          "title": "CISA KEV: CVE-2018-0824 \u2014 Microsoft COM for Windows Deserialization of Untrusted Data Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-08-05",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-08-05"
    },
    {
      "value": "103.56.114.69",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1294",
          "title": "CISA KEV: CVE-2018-0824 \u2014 Microsoft COM for Windows Deserialization of Untrusted Data Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-08-05",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-08-05"
    },
    {
      "value": "103.96.131.84",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1294",
          "title": "CISA KEV: CVE-2018-0824 \u2014 Microsoft COM for Windows Deserialization of Untrusted Data Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-08-05",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-08-05"
    },
    {
      "value": "45.85.76.10",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1294",
          "title": "CISA KEV: CVE-2018-0824 \u2014 Microsoft COM for Windows Deserialization of Untrusted Data Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-08-05",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-08-05"
    },
    {
      "value": "45.85.76.18",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1294",
          "title": "CISA KEV: CVE-2018-0824 \u2014 Microsoft COM for Windows Deserialization of Untrusted Data Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-08-05",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-08-05"
    },
    {
      "value": "58.64.204.145",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1294",
          "title": "CISA KEV: CVE-2018-0824 \u2014 Microsoft COM for Windows Deserialization of Untrusted Data Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-08-05",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-08-05"
    },
    {
      "value": "027443e516eabfc15ebf76a954c2c61e",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1294",
          "title": "CISA KEV: CVE-2018-0824 \u2014 Microsoft COM for Windows Deserialization of Untrusted Data Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-08-05",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-08-05"
    },
    {
      "value": "1647a2c92fc799bd83b0ee33c98ad187",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1294",
          "title": "CISA KEV: CVE-2018-0824 \u2014 Microsoft COM for Windows Deserialization of Untrusted Data Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-08-05",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-08-05"
    },
    {
      "value": "2c66bf055c6349408bf00ec3925cb678",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1294",
          "title": "CISA KEV: CVE-2018-0824 \u2014 Microsoft COM for Windows Deserialization of Untrusted Data Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-08-05",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-08-05"
    },
    {
      "value": "549d5b936e77f1067feb4e395f6f7b61",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1294",
          "title": "CISA KEV: CVE-2018-0824 \u2014 Microsoft COM for Windows Deserialization of Untrusted Data Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-08-05",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-08-05"
    },
    {
      "value": "623ac8801fb147ddc30c563f743441e0",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1294",
          "title": "CISA KEV: CVE-2018-0824 \u2014 Microsoft COM for Windows Deserialization of Untrusted Data Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-08-05",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-08-05"
    },
    {
      "value": "9ccb2f877777f3db8b1cb58440168ebd",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1294",
          "title": "CISA KEV: CVE-2018-0824 \u2014 Microsoft COM for Windows Deserialization of Untrusted Data Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-08-05",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-08-05"
    },
    {
      "value": "b39d28b5dc1770ece081b96a561511a0",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1294",
          "title": "CISA KEV: CVE-2018-0824 \u2014 Microsoft COM for Windows Deserialization of Untrusted Data Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-08-05",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-08-05"
    },
    {
      "value": "ccdcad8c74aac5c706cbad7e7ce085d1",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1294",
          "title": "CISA KEV: CVE-2018-0824 \u2014 Microsoft COM for Windows Deserialization of Untrusted Data Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-08-05",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-08-05"
    },
    {
      "value": "03501f7b4f398c682d1de2dc0c503e17f0212afe",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1294",
          "title": "CISA KEV: CVE-2018-0824 \u2014 Microsoft COM for Windows Deserialization of Untrusted Data Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-08-05",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-08-05"
    },
    {
      "value": "2634e0eec33e7fbf734f1a13b023ab8952fe6f03",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1294",
          "title": "CISA KEV: CVE-2018-0824 \u2014 Microsoft COM for Windows Deserialization of Untrusted Data Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-08-05",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-08-05"
    },
    {
      "value": "2adc28beb14583064d63819b3619794d58734d69",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1294",
          "title": "CISA KEV: CVE-2018-0824 \u2014 Microsoft COM for Windows Deserialization of Untrusted Data Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-08-05",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-08-05"
    },
    {
      "value": "4826fe7edbbfe546253c168e0f652e1500bb70bc",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1294",
          "title": "CISA KEV: CVE-2018-0824 \u2014 Microsoft COM for Windows Deserialization of Untrusted Data Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-08-05",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-08-05"
    },
    {
      "value": "884c36c7f146a4ac8941b8227a150daaf9b95dc7",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1294",
          "title": "CISA KEV: CVE-2018-0824 \u2014 Microsoft COM for Windows Deserialization of Untrusted Data Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-08-05",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-08-05"
    },
    {
      "value": "d594fb3a164a8adc678086c52d2422e7c9272ebe",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1294",
          "title": "CISA KEV: CVE-2018-0824 \u2014 Microsoft COM for Windows Deserialization of Untrusted Data Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-08-05",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-08-05"
    },
    {
      "value": "d8d7922a550db6afd661b74eaa97c8f59c76cf21",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1294",
          "title": "CISA KEV: CVE-2018-0824 \u2014 Microsoft COM for Windows Deserialization of Untrusted Data Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-08-05",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-08-05"
    },
    {
      "value": "f6aae5d8deaa50cbec0503e8219ea5ba0f26db8b",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1294",
          "title": "CISA KEV: CVE-2018-0824 \u2014 Microsoft COM for Windows Deserialization of Untrusted Data Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-08-05",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-08-05"
    },
    {
      "value": "087c475a1b5b36b7939f5ff12dc711ba591dd2c4227ccaa28d322425ef4d0d4c",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1294",
          "title": "CISA KEV: CVE-2018-0824 \u2014 Microsoft COM for Windows Deserialization of Untrusted Data Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-08-05",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-08-05"
    },
    {
      "value": "0ff80e4db32d1d45a0c2afdfd7a1be961c0fbd9d43613a22a989f9024cc1b1e9",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1294",
          "title": "CISA KEV: CVE-2018-0824 \u2014 Microsoft COM for Windows Deserialization of Untrusted Data Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-08-05",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-08-05"
    },
    {
      "value": "2149d481b863bec2240ffb64c68f7fb437458885c903a7b0c21aa44f88a69d86",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1294",
          "title": "CISA KEV: CVE-2018-0824 \u2014 Microsoft COM for Windows Deserialization of Untrusted Data Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-08-05",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-08-05"
    },
    {
      "value": "2e46fcadacfe9e2a63cfc18d95d5870de8b3414462bf14ba9e7c517678f235c9",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1294",
          "title": "CISA KEV: CVE-2018-0824 \u2014 Microsoft COM for Windows Deserialization of Untrusted Data Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-08-05",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-08-05"
    },
    {
      "value": "386eb7aa33c76ce671d6685f79512597f1fab28ea46c8ec7d89e58340081e2bd",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1294",
          "title": "CISA KEV: CVE-2018-0824 \u2014 Microsoft COM for Windows Deserialization of Untrusted Data Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-08-05",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-08-05"
    },
    {
      "value": "756ceb563d9283df1fd03252aee9e9621cd2cc7ddb45f596e16660fed1dd6442",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1294",
          "title": "CISA KEV: CVE-2018-0824 \u2014 Microsoft COM for Windows Deserialization of Untrusted Data Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-08-05",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-08-05"
    },
    {
      "value": "9dc827fb1c2e3c12ee39aa5ccf3b31f64051e0cdda9d2ac54caee6b235f52640",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1294",
          "title": "CISA KEV: CVE-2018-0824 \u2014 Microsoft COM for Windows Deserialization of Untrusted Data Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-08-05",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-08-05"
    },
    {
      "value": "abb2fe1f67a48b931258e47531884ca5502cec73996e686ca82eeba536258f67",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1294",
          "title": "CISA KEV: CVE-2018-0824 \u2014 Microsoft COM for Windows Deserialization of Untrusted Data Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-08-05",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-08-05"
    },
    {
      "value": "eba3138d0f3d2385b55b08d8886b1018834d194440691d33d612402ba8a11d28",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1294",
          "title": "CISA KEV: CVE-2018-0824 \u2014 Microsoft COM for Windows Deserialization of Untrusted Data Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-08-05",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-08-05"
    },
    {
      "value": "CVE-2024-24762",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-1296",
          "title": "A denial of service Regex breaks FastAPI security",
          "link": "https://snyk.io/blog/dos-regex-breaks-fastapi-security/",
          "published": "2024-07-31",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-07-31"
    },
    {
      "value": "CVE-2023-28252",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1298",
          "title": "CISA KEV: CVE-2024-37085 \u2014 VMware ESXi Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-07-30",
          "sev": "crit"
        },
        {
          "id": "art-1793",
          "title": "CISA KEV: CVE-2023-28252 \u2014 Microsoft Windows Common Log File System (CLFS) Driver Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-04-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-07-30"
    },
    {
      "value": "CVE-2024-37085",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1298",
          "title": "CISA KEV: CVE-2024-37085 \u2014 VMware ESXi Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-07-30",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-07-30"
    },
    {
      "value": "CVE-2023-45249",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1299",
          "title": "CISA KEV: CVE-2023-45249 \u2014 Acronis Cyber Infrastructure (ACI) Insecure Default Password Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-07-29",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-07-29"
    },
    {
      "value": "CVE-2024-4879",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1300",
          "title": "CISA KEV: CVE-2024-5217 \u2014 ServiceNow Incomplete List of Disallowed Inputs Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-07-29",
          "sev": "crit"
        },
        {
          "id": "art-1301",
          "title": "CISA KEV: CVE-2024-4879 \u2014 ServiceNow Improper Input Validation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-07-29",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-07-29"
    },
    {
      "value": "CVE-2024-5178",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1300",
          "title": "CISA KEV: CVE-2024-5217 \u2014 ServiceNow Incomplete List of Disallowed Inputs Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-07-29",
          "sev": "crit"
        },
        {
          "id": "art-1301",
          "title": "CISA KEV: CVE-2024-4879 \u2014 ServiceNow Improper Input Validation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-07-29",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-07-29"
    },
    {
      "value": "CVE-2024-5217",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1300",
          "title": "CISA KEV: CVE-2024-5217 \u2014 ServiceNow Incomplete List of Disallowed Inputs Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-07-29",
          "sev": "crit"
        },
        {
          "id": "art-1301",
          "title": "CISA KEV: CVE-2024-4879 \u2014 ServiceNow Improper Input Validation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-07-29",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-07-29"
    },
    {
      "value": "CVE-2012-4792",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1303",
          "title": "CISA KEV: CVE-2012-4792 \u2014 Microsoft Internet Explorer Use-After-Free Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-07-23",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-07-23"
    },
    {
      "value": "CVE-2024-39891",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1302",
          "title": "CISA KEV: CVE-2024-39891 \u2014 Twilio Authy Information Disclosure Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-07-23",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-07-23"
    },
    {
      "value": "48d56ec320ecf6c54a87a7540cf21340",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1303",
          "title": "CISA KEV: CVE-2012-4792 \u2014 Microsoft Internet Explorer Use-After-Free Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-07-23",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-07-23"
    },
    {
      "value": "2b9f1a858bb8cc18dc1e2184a872c183c327d3d4",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1303",
          "title": "CISA KEV: CVE-2012-4792 \u2014 Microsoft Internet Explorer Use-After-Free Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-07-23",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-07-23"
    },
    {
      "value": "ac335a4894485859d2cfd24b816f6929831c1e844164ceb2f90cbab5fa671965",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1303",
          "title": "CISA KEV: CVE-2012-4792 \u2014 Microsoft Internet Explorer Use-After-Free Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-07-23",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-07-23"
    },
    {
      "value": "CVE-2022-22948",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1307",
          "title": "CISA KEV: CVE-2022-22948 \u2014 VMware vCenter Server Incorrect Default File Permissions Vulnerability ",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-07-17",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-07-17"
    },
    {
      "value": "CVE-2023-20867",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1307",
          "title": "CISA KEV: CVE-2022-22948 \u2014 VMware vCenter Server Incorrect Default File Permissions Vulnerability ",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-07-17",
          "sev": "crit"
        },
        {
          "id": "art-1443",
          "title": "CISA KEV: CVE-2023-34048 \u2014 VMware vCenter Server Out-of-Bounds Write Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-01-22",
          "sev": "crit"
        },
        {
          "id": "art-1693",
          "title": "CISA KEV: CVE-2023-20867 \u2014 VMware Tools Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-06-23",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-07-17"
    },
    {
      "value": "CVE-2024-28995",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1308",
          "title": "CISA KEV: CVE-2024-28995 \u2014 SolarWinds Serv-U Path Traversal Vulnerability ",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-07-17",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-07-17"
    },
    {
      "value": "CVE-2024-2961",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1309",
          "title": "CISA KEV: CVE-2024-34102 \u2014 Adobe Commerce and Magento Open Source Improper Restriction of XML External Entity Reference (XXE) Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-07-17",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-07-17"
    },
    {
      "value": "CVE-2024-34102",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1309",
          "title": "CISA KEV: CVE-2024-34102 \u2014 Adobe Commerce and Magento Open Source Improper Restriction of XML External Entity Reference (XXE) Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-07-17",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-07-17"
    },
    {
      "value": "analytisgroup.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1309",
          "title": "CISA KEV: CVE-2024-34102 \u2014 Adobe Commerce and Magento Open Source Improper Restriction of XML External Entity Reference (XXE) Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-07-17",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-07-17"
    },
    {
      "value": "analytisweb.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1309",
          "title": "CISA KEV: CVE-2024-34102 \u2014 Adobe Commerce and Magento Open Source Improper Restriction of XML External Entity Reference (XXE) Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-07-17",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-07-17"
    },
    {
      "value": "bingforce.org",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1309",
          "title": "CISA KEV: CVE-2024-34102 \u2014 Adobe Commerce and Magento Open Source Improper Restriction of XML External Entity Reference (XXE) Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-07-17",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-07-17"
    },
    {
      "value": "bystats.io",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1309",
          "title": "CISA KEV: CVE-2024-34102 \u2014 Adobe Commerce and Magento Open Source Improper Restriction of XML External Entity Reference (XXE) Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-07-17",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-07-17"
    },
    {
      "value": "cdnstatics.net",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1309",
          "title": "CISA KEV: CVE-2024-34102 \u2014 Adobe Commerce and Magento Open Source Improper Restriction of XML External Entity Reference (XXE) Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-07-17",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-07-17"
    },
    {
      "value": "chartismart.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1309",
          "title": "CISA KEV: CVE-2024-34102 \u2014 Adobe Commerce and Magento Open Source Improper Restriction of XML External Entity Reference (XXE) Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-07-17",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-07-17"
    },
    {
      "value": "codecarawan.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1309",
          "title": "CISA KEV: CVE-2024-34102 \u2014 Adobe Commerce and Magento Open Source Improper Restriction of XML External Entity Reference (XXE) Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-07-17",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-07-17"
    },
    {
      "value": "creativeslim.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1309",
          "title": "CISA KEV: CVE-2024-34102 \u2014 Adobe Commerce and Magento Open Source Improper Restriction of XML External Entity Reference (XXE) Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-07-17",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-07-17"
    },
    {
      "value": "creatls.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1309",
          "title": "CISA KEV: CVE-2024-34102 \u2014 Adobe Commerce and Magento Open Source Improper Restriction of XML External Entity Reference (XXE) Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-07-17",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-07-17"
    },
    {
      "value": "desynlabtech.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1309",
          "title": "CISA KEV: CVE-2024-34102 \u2014 Adobe Commerce and Magento Open Source Improper Restriction of XML External Entity Reference (XXE) Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-07-17",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-07-17"
    },
    {
      "value": "easttrack.net",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1309",
          "title": "CISA KEV: CVE-2024-34102 \u2014 Adobe Commerce and Magento Open Source Improper Restriction of XML External Entity Reference (XXE) Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-07-17",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-07-17"
    },
    {
      "value": "foptimize.net",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1309",
          "title": "CISA KEV: CVE-2024-34102 \u2014 Adobe Commerce and Magento Open Source Improper Restriction of XML External Entity Reference (XXE) Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-07-17",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-07-17"
    },
    {
      "value": "gearplace.net",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1309",
          "title": "CISA KEV: CVE-2024-34102 \u2014 Adobe Commerce and Magento Open Source Improper Restriction of XML External Entity Reference (XXE) Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-07-17",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-07-17"
    },
    {
      "value": "getstylify.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1309",
          "title": "CISA KEV: CVE-2024-34102 \u2014 Adobe Commerce and Magento Open Source Improper Restriction of XML External Entity Reference (XXE) Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-07-17",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-07-17"
    },
    {
      "value": "graphiqsw.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1309",
          "title": "CISA KEV: CVE-2024-34102 \u2014 Adobe Commerce and Magento Open Source Improper Restriction of XML External Entity Reference (XXE) Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-07-17",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-07-17"
    },
    {
      "value": "happyllfe.online",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1309",
          "title": "CISA KEV: CVE-2024-34102 \u2014 Adobe Commerce and Magento Open Source Improper Restriction of XML External Entity Reference (XXE) Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-07-17",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-07-17"
    },
    {
      "value": "horlzonhub.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1309",
          "title": "CISA KEV: CVE-2024-34102 \u2014 Adobe Commerce and Magento Open Source Improper Restriction of XML External Entity Reference (XXE) Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-07-17",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-07-17"
    },
    {
      "value": "iconstaff.top",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1309",
          "title": "CISA KEV: CVE-2024-34102 \u2014 Adobe Commerce and Magento Open Source Improper Restriction of XML External Entity Reference (XXE) Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-07-17",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-07-17"
    },
    {
      "value": "infiniboosts.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1309",
          "title": "CISA KEV: CVE-2024-34102 \u2014 Adobe Commerce and Magento Open Source Improper Restriction of XML External Entity Reference (XXE) Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-07-17",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-07-17"
    },
    {
      "value": "jquerypackageus.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1309",
          "title": "CISA KEV: CVE-2024-34102 \u2014 Adobe Commerce and Magento Open Source Improper Restriction of XML External Entity Reference (XXE) Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-07-17",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-07-17"
    },
    {
      "value": "jstatic201.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1309",
          "title": "CISA KEV: CVE-2024-34102 \u2014 Adobe Commerce and Magento Open Source Improper Restriction of XML External Entity Reference (XXE) Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-07-17",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-07-17"
    },
    {
      "value": "marketiqhub.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1309",
          "title": "CISA KEV: CVE-2024-34102 \u2014 Adobe Commerce and Magento Open Source Improper Restriction of XML External Entity Reference (XXE) Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-07-17",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-07-17"
    },
    {
      "value": "novastraem.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1309",
          "title": "CISA KEV: CVE-2024-34102 \u2014 Adobe Commerce and Magento Open Source Improper Restriction of XML External Entity Reference (XXE) Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-07-17",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-07-17"
    },
    {
      "value": "quantunnquest.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1309",
          "title": "CISA KEV: CVE-2024-34102 \u2014 Adobe Commerce and Magento Open Source Improper Restriction of XML External Entity Reference (XXE) Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-07-17",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-07-17"
    },
    {
      "value": "radlantroots.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1309",
          "title": "CISA KEV: CVE-2024-34102 \u2014 Adobe Commerce and Magento Open Source Improper Restriction of XML External Entity Reference (XXE) Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-07-17",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-07-17"
    },
    {
      "value": "sellerstat.site",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1309",
          "title": "CISA KEV: CVE-2024-34102 \u2014 Adobe Commerce and Magento Open Source Improper Restriction of XML External Entity Reference (XXE) Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-07-17",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-07-17"
    },
    {
      "value": "sellifypro.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1309",
          "title": "CISA KEV: CVE-2024-34102 \u2014 Adobe Commerce and Magento Open Source Improper Restriction of XML External Entity Reference (XXE) Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-07-17",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-07-17"
    },
    {
      "value": "statspots.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1309",
          "title": "CISA KEV: CVE-2024-34102 \u2014 Adobe Commerce and Magento Open Source Improper Restriction of XML External Entity Reference (XXE) Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-07-17",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-07-17"
    },
    {
      "value": "techtnee.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1309",
          "title": "CISA KEV: CVE-2024-34102 \u2014 Adobe Commerce and Magento Open Source Improper Restriction of XML External Entity Reference (XXE) Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-07-17",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-07-17"
    },
    {
      "value": "trendgurupro.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1309",
          "title": "CISA KEV: CVE-2024-34102 \u2014 Adobe Commerce and Magento Open Source Improper Restriction of XML External Entity Reference (XXE) Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-07-17",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-07-17"
    },
    {
      "value": "104.36.229.32",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1309",
          "title": "CISA KEV: CVE-2024-34102 \u2014 Adobe Commerce and Magento Open Source Improper Restriction of XML External Entity Reference (XXE) Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-07-17",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-07-17"
    },
    {
      "value": "106.14.40.200",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1309",
          "title": "CISA KEV: CVE-2024-34102 \u2014 Adobe Commerce and Magento Open Source Improper Restriction of XML External Entity Reference (XXE) Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-07-17",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-07-17"
    },
    {
      "value": "120.245.64.189",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1308",
          "title": "CISA KEV: CVE-2024-28995 \u2014 SolarWinds Serv-U Path Traversal Vulnerability ",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-07-17",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-07-17"
    },
    {
      "value": "141.98.81.24",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1309",
          "title": "CISA KEV: CVE-2024-34102 \u2014 Adobe Commerce and Magento Open Source Improper Restriction of XML External Entity Reference (XXE) Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-07-17",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-07-17"
    },
    {
      "value": "141.98.82.3",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1309",
          "title": "CISA KEV: CVE-2024-34102 \u2014 Adobe Commerce and Magento Open Source Improper Restriction of XML External Entity Reference (XXE) Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-07-17",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-07-17"
    },
    {
      "value": "146.190.165.100",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1309",
          "title": "CISA KEV: CVE-2024-34102 \u2014 Adobe Commerce and Magento Open Source Improper Restriction of XML External Entity Reference (XXE) Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-07-17",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-07-17"
    },
    {
      "value": "15.204.207.175",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1309",
          "title": "CISA KEV: CVE-2024-34102 \u2014 Adobe Commerce and Magento Open Source Improper Restriction of XML External Entity Reference (XXE) Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-07-17",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-07-17"
    },
    {
      "value": "157.230.230.193",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1309",
          "title": "CISA KEV: CVE-2024-34102 \u2014 Adobe Commerce and Magento Open Source Improper Restriction of XML External Entity Reference (XXE) Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-07-17",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-07-17"
    },
    {
      "value": "159.223.136.255",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1309",
          "title": "CISA KEV: CVE-2024-34102 \u2014 Adobe Commerce and Magento Open Source Improper Restriction of XML External Entity Reference (XXE) Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-07-17",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-07-17"
    },
    {
      "value": "172.104.28.240",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1309",
          "title": "CISA KEV: CVE-2024-34102 \u2014 Adobe Commerce and Magento Open Source Improper Restriction of XML External Entity Reference (XXE) Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-07-17",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-07-17"
    },
    {
      "value": "173.255.242.28",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1309",
          "title": "CISA KEV: CVE-2024-34102 \u2014 Adobe Commerce and Magento Open Source Improper Restriction of XML External Entity Reference (XXE) Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-07-17",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-07-17"
    },
    {
      "value": "184.31.15.39",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1309",
          "title": "CISA KEV: CVE-2024-34102 \u2014 Adobe Commerce and Magento Open Source Improper Restriction of XML External Entity Reference (XXE) Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-07-17",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-07-17"
    },
    {
      "value": "184.31.15.70",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1309",
          "title": "CISA KEV: CVE-2024-34102 \u2014 Adobe Commerce and Magento Open Source Improper Restriction of XML External Entity Reference (XXE) Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-07-17",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-07-17"
    },
    {
      "value": "185.175.225.116",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1309",
          "title": "CISA KEV: CVE-2024-34102 \u2014 Adobe Commerce and Magento Open Source Improper Restriction of XML External Entity Reference (XXE) Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-07-17",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-07-17"
    },
    {
      "value": "185.193.126.86",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1309",
          "title": "CISA KEV: CVE-2024-34102 \u2014 Adobe Commerce and Magento Open Source Improper Restriction of XML External Entity Reference (XXE) Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-07-17",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-07-17"
    },
    {
      "value": "185.196.10.2",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1308",
          "title": "CISA KEV: CVE-2024-28995 \u2014 SolarWinds Serv-U Path Traversal Vulnerability ",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-07-17",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-07-17"
    },
    {
      "value": "193.233.128.167",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1309",
          "title": "CISA KEV: CVE-2024-34102 \u2014 Adobe Commerce and Magento Open Source Improper Restriction of XML External Entity Reference (XXE) Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-07-17",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-07-17"
    },
    {
      "value": "193.233.129.150",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1309",
          "title": "CISA KEV: CVE-2024-34102 \u2014 Adobe Commerce and Magento Open Source Improper Restriction of XML External Entity Reference (XXE) Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-07-17",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-07-17"
    },
    {
      "value": "193.233.130.84",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1309",
          "title": "CISA KEV: CVE-2024-34102 \u2014 Adobe Commerce and Magento Open Source Improper Restriction of XML External Entity Reference (XXE) Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-07-17",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-07-17"
    },
    {
      "value": "193.233.216.201",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1309",
          "title": "CISA KEV: CVE-2024-34102 \u2014 Adobe Commerce and Magento Open Source Improper Restriction of XML External Entity Reference (XXE) Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-07-17",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-07-17"
    },
    {
      "value": "193.233.217.12",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1309",
          "title": "CISA KEV: CVE-2024-34102 \u2014 Adobe Commerce and Magento Open Source Improper Restriction of XML External Entity Reference (XXE) Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-07-17",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-07-17"
    },
    {
      "value": "217.182.199.126",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1309",
          "title": "CISA KEV: CVE-2024-34102 \u2014 Adobe Commerce and Magento Open Source Improper Restriction of XML External Entity Reference (XXE) Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-07-17",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-07-17"
    },
    {
      "value": "221.4.215.215",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1308",
          "title": "CISA KEV: CVE-2024-28995 \u2014 SolarWinds Serv-U Path Traversal Vulnerability ",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-07-17",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-07-17"
    },
    {
      "value": "31.134.11.12",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1309",
          "title": "CISA KEV: CVE-2024-34102 \u2014 Adobe Commerce and Magento Open Source Improper Restriction of XML External Entity Reference (XXE) Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-07-17",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-07-17"
    },
    {
      "value": "31.134.11.69",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1309",
          "title": "CISA KEV: CVE-2024-34102 \u2014 Adobe Commerce and Magento Open Source Improper Restriction of XML External Entity Reference (XXE) Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-07-17",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-07-17"
    },
    {
      "value": "31.134.13.106",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1309",
          "title": "CISA KEV: CVE-2024-34102 \u2014 Adobe Commerce and Magento Open Source Improper Restriction of XML External Entity Reference (XXE) Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-07-17",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-07-17"
    },
    {
      "value": "37.9.41.91",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1309",
          "title": "CISA KEV: CVE-2024-34102 \u2014 Adobe Commerce and Magento Open Source Improper Restriction of XML External Entity Reference (XXE) Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-07-17",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-07-17"
    },
    {
      "value": "37.9.42.158",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1309",
          "title": "CISA KEV: CVE-2024-34102 \u2014 Adobe Commerce and Magento Open Source Improper Restriction of XML External Entity Reference (XXE) Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-07-17",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-07-17"
    },
    {
      "value": "85.239.43.38",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1309",
          "title": "CISA KEV: CVE-2024-34102 \u2014 Adobe Commerce and Magento Open Source Improper Restriction of XML External Entity Reference (XXE) Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-07-17",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-07-17"
    },
    {
      "value": "89.110.84.168",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1309",
          "title": "CISA KEV: CVE-2024-34102 \u2014 Adobe Commerce and Magento Open Source Improper Restriction of XML External Entity Reference (XXE) Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-07-17",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-07-17"
    },
    {
      "value": "91.92.243.104",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1309",
          "title": "CISA KEV: CVE-2024-34102 \u2014 Adobe Commerce and Magento Open Source Improper Restriction of XML External Entity Reference (XXE) Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-07-17",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-07-17"
    },
    {
      "value": "91.92.247.205",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1309",
          "title": "CISA KEV: CVE-2024-34102 \u2014 Adobe Commerce and Magento Open Source Improper Restriction of XML External Entity Reference (XXE) Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-07-17",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-07-17"
    },
    {
      "value": "92.112.184.102",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1309",
          "title": "CISA KEV: CVE-2024-34102 \u2014 Adobe Commerce and Magento Open Source Improper Restriction of XML External Entity Reference (XXE) Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-07-17",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-07-17"
    },
    {
      "value": "CVE-2024-36401",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1310",
          "title": "CISA KEV: CVE-2024-36401 \u2014 OSGeo GeoServer GeoTools Eval Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-07-15",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-07-15"
    },
    {
      "value": "1.download765.online",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1310",
          "title": "CISA KEV: CVE-2024-36401 \u2014 OSGeo GeoServer GeoTools Eval Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-07-15",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-07-15"
    },
    {
      "value": "9527527.xyz",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1310",
          "title": "CISA KEV: CVE-2024-36401 \u2014 OSGeo GeoServer GeoTools Eval Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-07-15",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-07-15"
    },
    {
      "value": "bots.gxz.me",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1310",
          "title": "CISA KEV: CVE-2024-36401 \u2014 OSGeo GeoServer GeoTools Eval Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-07-15",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-07-15"
    },
    {
      "value": "gsdasdfadfs.9527527.xyz",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1310",
          "title": "CISA KEV: CVE-2024-36401 \u2014 OSGeo GeoServer GeoTools Eval Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-07-15",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-07-15"
    },
    {
      "value": "oss.17ww.vip",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1310",
          "title": "CISA KEV: CVE-2024-36401 \u2014 OSGeo GeoServer GeoTools Eval Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-07-15",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-07-15"
    },
    {
      "value": "repositorylinux.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1310",
          "title": "CISA KEV: CVE-2024-36401 \u2014 OSGeo GeoServer GeoTools Eval Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-07-15",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-07-15"
    },
    {
      "value": "sdfasdfsf.9527527.xyz",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1310",
          "title": "CISA KEV: CVE-2024-36401 \u2014 OSGeo GeoServer GeoTools Eval Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-07-15",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-07-15"
    },
    {
      "value": "secure.systemupdatecdn.de",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1310",
          "title": "CISA KEV: CVE-2024-36401 \u2014 OSGeo GeoServer GeoTools Eval Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-07-15",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-07-15"
    },
    {
      "value": "trcpay.xyz",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1310",
          "title": "CISA KEV: CVE-2024-36401 \u2014 OSGeo GeoServer GeoTools Eval Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-07-15",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-07-15"
    },
    {
      "value": "112.133.194.254",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1310",
          "title": "CISA KEV: CVE-2024-36401 \u2014 OSGeo GeoServer GeoTools Eval Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-07-15",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-07-15"
    },
    {
      "value": "181.214.58.14",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1310",
          "title": "CISA KEV: CVE-2024-36401 \u2014 OSGeo GeoServer GeoTools Eval Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-07-15",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-07-15"
    },
    {
      "value": "188.214.27.50",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1310",
          "title": "CISA KEV: CVE-2024-36401 \u2014 OSGeo GeoServer GeoTools Eval Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-07-15",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-07-15"
    },
    {
      "value": "209.146.124.181",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1310",
          "title": "CISA KEV: CVE-2024-36401 \u2014 OSGeo GeoServer GeoTools Eval Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-07-15",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-07-15"
    },
    {
      "value": "47.253.46.11",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1310",
          "title": "CISA KEV: CVE-2024-36401 \u2014 OSGeo GeoServer GeoTools Eval Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-07-15",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-07-15"
    },
    {
      "value": "95.85.93.196",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1310",
          "title": "CISA KEV: CVE-2024-36401 \u2014 OSGeo GeoServer GeoTools Eval Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-07-15",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-07-15"
    },
    {
      "value": "1588bee7db42495ba7e6e34d217e6b82c5ab93f27c1eea68435cbb9e7792f9be",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1310",
          "title": "CISA KEV: CVE-2024-36401 \u2014 OSGeo GeoServer GeoTools Eval Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-07-15",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-07-15"
    },
    {
      "value": "1af8e068aa7377f0055640af581a412aa9d7288c912a93dd0d739657af0079fb",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1310",
          "title": "CISA KEV: CVE-2024-36401 \u2014 OSGeo GeoServer GeoTools Eval Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-07-15",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-07-15"
    },
    {
      "value": "20d97f144bf7b1662a13ac537715126b9b2f68eff46a4a09234743ae236f0177",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1310",
          "title": "CISA KEV: CVE-2024-36401 \u2014 OSGeo GeoServer GeoTools Eval Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-07-15",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-07-15"
    },
    {
      "value": "3c73ebc7a85accc65c9ee5bf151f70b990e5a12f27a843ca21c0f9d9a10fd17d",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1310",
          "title": "CISA KEV: CVE-2024-36401 \u2014 OSGeo GeoServer GeoTools Eval Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-07-15",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-07-15"
    },
    {
      "value": "50b7e615b8cdc45486b6ed1c1c081c7a92c262edb84318fa864531dcab753f82",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1310",
          "title": "CISA KEV: CVE-2024-36401 \u2014 OSGeo GeoServer GeoTools Eval Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-07-15",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-07-15"
    },
    {
      "value": "53994a35a57970dea48e97009f65ad045b69a83234b771b106446211376a6866",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1310",
          "title": "CISA KEV: CVE-2024-36401 \u2014 OSGeo GeoServer GeoTools Eval Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-07-15",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-07-15"
    },
    {
      "value": "5cc7e35254347f705422800bfb7fe29c6002e2537f6bac0ff996a720dfb5f48e",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1310",
          "title": "CISA KEV: CVE-2024-36401 \u2014 OSGeo GeoServer GeoTools Eval Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-07-15",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-07-15"
    },
    {
      "value": "7194ec436231c2a383ffc7c75eef4f5b5a952c18fa176ffd0830667835a80533",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1310",
          "title": "CISA KEV: CVE-2024-36401 \u2014 OSGeo GeoServer GeoTools Eval Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-07-15",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-07-15"
    },
    {
      "value": "79c9532fb6ef2742e207498bfe2b2ee09aa9773376ac0e56085083aab17b98be",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1310",
          "title": "CISA KEV: CVE-2024-36401 \u2014 OSGeo GeoServer GeoTools Eval Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-07-15",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-07-15"
    },
    {
      "value": "83fb74bb852bbd722e6ebc4e249e49cb4bb4194493a26d62d4bfcdfca2998412",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1310",
          "title": "CISA KEV: CVE-2024-36401 \u2014 OSGeo GeoServer GeoTools Eval Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-07-15",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-07-15"
    },
    {
      "value": "8d3440301bc94ed83cdafb69e4b0166d3a0020eb4f38e9fa159c2f13f14b2d29",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1310",
          "title": "CISA KEV: CVE-2024-36401 \u2014 OSGeo GeoServer GeoTools Eval Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-07-15",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-07-15"
    },
    {
      "value": "96cf27a66b629d2b19708c6887441a8422b40dc0e9e7c5c0f2212efe0b6b3323",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1310",
          "title": "CISA KEV: CVE-2024-36401 \u2014 OSGeo GeoServer GeoTools Eval Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-07-15",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-07-15"
    },
    {
      "value": "994b924b00fb56e12a6a987c4cdf65dd05a221c47b5fc0a7a2babf1f05c2ed38",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1310",
          "title": "CISA KEV: CVE-2024-36401 \u2014 OSGeo GeoServer GeoTools Eval Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-07-15",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-07-15"
    },
    {
      "value": "9bf642a7e14f0a0b0a784f00a0d1cf590ac60ae5ae378d29d435519f4d9dbf2b",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1310",
          "title": "CISA KEV: CVE-2024-36401 \u2014 OSGeo GeoServer GeoTools Eval Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-07-15",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-07-15"
    },
    {
      "value": "a13a979f4ca57450528bb6cd7aa2bf47d2eea211053eb1a14b8c4a44fd661831",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1310",
          "title": "CISA KEV: CVE-2024-36401 \u2014 OSGeo GeoServer GeoTools Eval Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-07-15",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-07-15"
    },
    {
      "value": "a9e7b5284182d3881c865895ee6e0fb03273eec3dcbf4bfc82dd2b069245beae",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1310",
          "title": "CISA KEV: CVE-2024-36401 \u2014 OSGeo GeoServer GeoTools Eval Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-07-15",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-07-15"
    },
    {
      "value": "addccd0ecb643251af2e79e878b19a8e9c8f1c87302e732ef057cdba821f4b30",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1310",
          "title": "CISA KEV: CVE-2024-36401 \u2014 OSGeo GeoServer GeoTools Eval Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-07-15",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-07-15"
    },
    {
      "value": "b3a015b6650ec9800fa878ff9a5f732013806c8dcb0e7069515dae0dd380fda4",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1310",
          "title": "CISA KEV: CVE-2024-36401 \u2014 OSGeo GeoServer GeoTools Eval Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-07-15",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-07-15"
    },
    {
      "value": "b60d7fb66caf103a04e81fb89dbb05111b4b0ef513f3769c8e0a8106ab01a075",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1310",
          "title": "CISA KEV: CVE-2024-36401 \u2014 OSGeo GeoServer GeoTools Eval Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-07-15",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-07-15"
    },
    {
      "value": "b67ab1b9b66fdc2c4ed1689698a54a347c2bdd6eaff87039ae337675243670d8",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1310",
          "title": "CISA KEV: CVE-2024-36401 \u2014 OSGeo GeoServer GeoTools Eval Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-07-15",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-07-15"
    },
    {
      "value": "b80e9466b7bb42959c29546b8c052e67fcaa0f591857617457d5d28348bd8860",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1310",
          "title": "CISA KEV: CVE-2024-36401 \u2014 OSGeo GeoServer GeoTools Eval Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-07-15",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-07-15"
    },
    {
      "value": "c226744b40e8f5d2cf95b4fb2537ff00e222ecc2d24c5096ecfadb14b4a47f97",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1310",
          "title": "CISA KEV: CVE-2024-36401 \u2014 OSGeo GeoServer GeoTools Eval Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-07-15",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-07-15"
    },
    {
      "value": "c3101b0b74d76a95ba91b6cc4945657e928d2dac8fdf926ffbf09031d46e9186",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1310",
          "title": "CISA KEV: CVE-2024-36401 \u2014 OSGeo GeoServer GeoTools Eval Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-07-15",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-07-15"
    },
    {
      "value": "d9dfe98b5fba09e17dbe29dfeb8deb7d777d4a3b0d670914691ed360b916116a",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1310",
          "title": "CISA KEV: CVE-2024-36401 \u2014 OSGeo GeoServer GeoTools Eval Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-07-15",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-07-15"
    },
    {
      "value": "d9e8b390f8e2e8a6c2308c723a6a812f59c055ecad4e9098a120e5c4c65d3905",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1310",
          "title": "CISA KEV: CVE-2024-36401 \u2014 OSGeo GeoServer GeoTools Eval Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-07-15",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-07-15"
    },
    {
      "value": "e8b0f5a952f07c83c4d67809ac0715c7164d518323d8038542e84aab8456db43",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1310",
          "title": "CISA KEV: CVE-2024-36401 \u2014 OSGeo GeoServer GeoTools Eval Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-07-15",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-07-15"
    },
    {
      "value": "f3d3572ef96c9c59e137425ca6804e1b86b7f8b57210a3724d567017460774de",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1310",
          "title": "CISA KEV: CVE-2024-36401 \u2014 OSGeo GeoServer GeoTools Eval Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-07-15",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-07-15"
    },
    {
      "value": "f7b97677b6387c1f02d429e98868bf6973a8dec14dfee2516a27e885d6b1c780",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1310",
          "title": "CISA KEV: CVE-2024-36401 \u2014 OSGeo GeoServer GeoTools Eval Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-07-15",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-07-15"
    },
    {
      "value": "fabbb4611fb9df5d8f208d9353be0b73c3942fe78903da096cbfe2f47c9e3566",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1310",
          "title": "CISA KEV: CVE-2024-36401 \u2014 OSGeo GeoServer GeoTools Eval Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-07-15",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-07-15"
    },
    {
      "value": "CVE-2024-23692",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1314",
          "title": "CISA KEV: CVE-2024-23692 \u2014 Rejetto HTTP File Server Improper Neutralization of Special Elements Used in a Template Engine Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-07-09",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-07-09"
    },
    {
      "value": "CVE-2024-38080",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1315",
          "title": "CISA KEV: CVE-2024-38080 \u2014 Microsoft Windows Hyper-V Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-07-09",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-07-09"
    },
    {
      "value": "CVE-2024-20399",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1317",
          "title": "CISA KEV: CVE-2024-20399 \u2014 Cisco NX-OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-07-02",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-07-02"
    },
    {
      "value": "CVE-2020-13965",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1320",
          "title": "CISA KEV: CVE-2020-13965 \u2014 Roundcube Webmail Cross-Site Scripting (XSS) Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-06-26",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-06-26"
    },
    {
      "value": "CVE-2022-24816",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1322",
          "title": "CISA KEV: CVE-2022-24816 \u2014 OSGeo GeoServer JAI-EXT Code Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-06-26",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-06-26"
    },
    {
      "value": "CVE-2022-2586",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1321",
          "title": "CISA KEV: CVE-2022-2586 \u2014 Linux Kernel Use-After-Free Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-06-26",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-06-26"
    },
    {
      "value": "CVE-2024-38526",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-1319",
          "title": "Polyfill supply chain attack embeds malware in JavaScript CDN assets",
          "link": "https://snyk.io/blog/polyfill-supply-chain-attack-js-cdn-assets/",
          "published": "2024-06-26",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-06-26"
    },
    {
      "value": "5f52353c.u.fn03.vip",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-1319",
          "title": "Polyfill supply chain attack embeds malware in JavaScript CDN assets",
          "link": "https://snyk.io/blog/polyfill-supply-chain-attack-js-cdn-assets/",
          "published": "2024-06-26",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-06-26"
    },
    {
      "value": "bootcdn.net",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-1319",
          "title": "Polyfill supply chain attack embeds malware in JavaScript CDN assets",
          "link": "https://snyk.io/blog/polyfill-supply-chain-attack-js-cdn-assets/",
          "published": "2024-06-26",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-06-26"
    },
    {
      "value": "bootcss.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-1319",
          "title": "Polyfill supply chain attack embeds malware in JavaScript CDN assets",
          "link": "https://snyk.io/blog/polyfill-supply-chain-attack-js-cdn-assets/",
          "published": "2024-06-26",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-06-26"
    },
    {
      "value": "cdn.polyfill.io",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-1319",
          "title": "Polyfill supply chain attack embeds malware in JavaScript CDN assets",
          "link": "https://snyk.io/blog/polyfill-supply-chain-attack-js-cdn-assets/",
          "published": "2024-06-26",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-06-26"
    },
    {
      "value": "cdn.polyfill.io.bsclink.cn",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-1319",
          "title": "Polyfill supply chain attack embeds malware in JavaScript CDN assets",
          "link": "https://snyk.io/blog/polyfill-supply-chain-attack-js-cdn-assets/",
          "published": "2024-06-26",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-06-26"
    },
    {
      "value": "googie-anaiytics.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-1319",
          "title": "Polyfill supply chain attack embeds malware in JavaScript CDN assets",
          "link": "https://snyk.io/blog/polyfill-supply-chain-attack-js-cdn-assets/",
          "published": "2024-06-26",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-06-26"
    },
    {
      "value": "kuurza.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-1319",
          "title": "Polyfill supply chain attack embeds malware in JavaScript CDN assets",
          "link": "https://snyk.io/blog/polyfill-supply-chain-attack-js-cdn-assets/",
          "published": "2024-06-26",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-06-26"
    },
    {
      "value": "newcrbpc.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-1319",
          "title": "Polyfill supply chain attack embeds malware in JavaScript CDN assets",
          "link": "https://snyk.io/blog/polyfill-supply-chain-attack-js-cdn-assets/",
          "published": "2024-06-26",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-06-26"
    },
    {
      "value": "polyfill.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-1319",
          "title": "Polyfill supply chain attack embeds malware in JavaScript CDN assets",
          "link": "https://snyk.io/blog/polyfill-supply-chain-attack-js-cdn-assets/",
          "published": "2024-06-26",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-06-26"
    },
    {
      "value": "polyfill.io",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-1319",
          "title": "Polyfill supply chain attack embeds malware in JavaScript CDN assets",
          "link": "https://snyk.io/blog/polyfill-supply-chain-attack-js-cdn-assets/",
          "published": "2024-06-26",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-06-26"
    },
    {
      "value": "polyfill.io.bsclink.cn",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-1319",
          "title": "Polyfill supply chain attack embeds malware in JavaScript CDN assets",
          "link": "https://snyk.io/blog/polyfill-supply-chain-attack-js-cdn-assets/",
          "published": "2024-06-26",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-06-26"
    },
    {
      "value": "polyfill.site",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-1319",
          "title": "Polyfill supply chain attack embeds malware in JavaScript CDN assets",
          "link": "https://snyk.io/blog/polyfill-supply-chain-attack-js-cdn-assets/",
          "published": "2024-06-26",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-06-26"
    },
    {
      "value": "polyfillcache.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-1319",
          "title": "Polyfill supply chain attack embeds malware in JavaScript CDN assets",
          "link": "https://snyk.io/blog/polyfill-supply-chain-attack-js-cdn-assets/",
          "published": "2024-06-26",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-06-26"
    },
    {
      "value": "staticfile.net",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-1319",
          "title": "Polyfill supply chain attack embeds malware in JavaScript CDN assets",
          "link": "https://snyk.io/blog/polyfill-supply-chain-attack-js-cdn-assets/",
          "published": "2024-06-26",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-06-26"
    },
    {
      "value": "staticfile.org",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-1319",
          "title": "Polyfill supply chain attack embeds malware in JavaScript CDN assets",
          "link": "https://snyk.io/blog/polyfill-supply-chain-attack-js-cdn-assets/",
          "published": "2024-06-26",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-06-26"
    },
    {
      "value": "union.macoms.la",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-1319",
          "title": "Polyfill supply chain attack embeds malware in JavaScript CDN assets",
          "link": "https://snyk.io/blog/polyfill-supply-chain-attack-js-cdn-assets/",
          "published": "2024-06-26",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-06-26"
    },
    {
      "value": "unionadjs.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-1319",
          "title": "Polyfill supply chain attack embeds malware in JavaScript CDN assets",
          "link": "https://snyk.io/blog/polyfill-supply-chain-attack-js-cdn-assets/",
          "published": "2024-06-26",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-06-26"
    },
    {
      "value": "w9.vty70.net",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-1319",
          "title": "Polyfill supply chain attack embeds malware in JavaScript CDN assets",
          "link": "https://snyk.io/blog/polyfill-supply-chain-attack-js-cdn-assets/",
          "published": "2024-06-26",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-06-26"
    },
    {
      "value": "wildcard.polyfill.io.bsclink.cn",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-1319",
          "title": "Polyfill supply chain attack embeds malware in JavaScript CDN assets",
          "link": "https://snyk.io/blog/polyfill-supply-chain-attack-js-cdn-assets/",
          "published": "2024-06-26",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-06-26"
    },
    {
      "value": "xhsbpza.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-1319",
          "title": "Polyfill supply chain attack embeds malware in JavaScript CDN assets",
          "link": "https://snyk.io/blog/polyfill-supply-chain-attack-js-cdn-assets/",
          "published": "2024-06-26",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-06-26"
    },
    {
      "value": "CVE-2024-1800",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1330",
          "title": "CISA KEV: CVE-2024-4358 \u2014 Progress Telerik Report Server Authentication Bypass by Spoofing Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-06-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-06-13"
    },
    {
      "value": "CVE-2024-26169",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1331",
          "title": "CISA KEV: CVE-2024-26169 \u2014 Microsoft Windows Error Reporting Service Improper Privilege Management Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-06-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-06-13"
    },
    {
      "value": "CVE-2024-32896",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1332",
          "title": "CISA KEV: CVE-2024-32896 \u2014 Android Pixel Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-06-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-06-13"
    },
    {
      "value": "CVE-2024-4358",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1330",
          "title": "CISA KEV: CVE-2024-4358 \u2014 Progress Telerik Report Server Authentication Bypass by Spoofing Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-06-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-06-13"
    },
    {
      "value": "1984cd0bf7b20c5bef58338f80e4e65e",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1331",
          "title": "CISA KEV: CVE-2024-26169 \u2014 Microsoft Windows Error Reporting Service Improper Privilege Management Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-06-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-06-13"
    },
    {
      "value": "acaf01f83da439915027c3e2e900c8dd",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1331",
          "title": "CISA KEV: CVE-2024-26169 \u2014 Microsoft Windows Error Reporting Service Improper Privilege Management Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-06-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-06-13"
    },
    {
      "value": "f17918862a190afd4649b2a6b4a34b5c",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1331",
          "title": "CISA KEV: CVE-2024-26169 \u2014 Microsoft Windows Error Reporting Service Improper Privilege Management Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-06-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-06-13"
    },
    {
      "value": "ff217dab57393592c6767de1c6a999eb",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1331",
          "title": "CISA KEV: CVE-2024-26169 \u2014 Microsoft Windows Error Reporting Service Improper Privilege Management Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-06-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-06-13"
    },
    {
      "value": "2861b4e463fa89e05f2d7d629fae5140cef49843",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1331",
          "title": "CISA KEV: CVE-2024-26169 \u2014 Microsoft Windows Error Reporting Service Improper Privilege Management Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-06-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-06-13"
    },
    {
      "value": "4ea121b4b45bab1e17fae11c8cce30241f5f8a75",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1331",
          "title": "CISA KEV: CVE-2024-26169 \u2014 Microsoft Windows Error Reporting Service Improper Privilege Management Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-06-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-06-13"
    },
    {
      "value": "b4b5963c62c07c2adcee093571afd0e9e765de3b",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1331",
          "title": "CISA KEV: CVE-2024-26169 \u2014 Microsoft Windows Error Reporting Service Improper Privilege Management Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-06-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-06-13"
    },
    {
      "value": "cc580c52f4263803255d65dfb6ab208be7f4a534",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1331",
          "title": "CISA KEV: CVE-2024-26169 \u2014 Microsoft Windows Error Reporting Service Improper Privilege Management Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-06-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-06-13"
    },
    {
      "value": "2408be22f6184cdccec7a34e2e79711ff4957e42f1ed7b7ad63f914d37dba625",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1331",
          "title": "CISA KEV: CVE-2024-26169 \u2014 Microsoft Windows Error Reporting Service Improper Privilege Management Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-06-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-06-13"
    },
    {
      "value": "3b3bd81232f517ba6d65c7838c205b301b0f27572fcfef9e5b86dd30a1d55a0d",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1331",
          "title": "CISA KEV: CVE-2024-26169 \u2014 Microsoft Windows Error Reporting Service Improper Privilege Management Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-06-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-06-13"
    },
    {
      "value": "4aae231fb5357c0647483181aeae47956ac66e42b6b134f5b90da76d8ec0ac63",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1331",
          "title": "CISA KEV: CVE-2024-26169 \u2014 Microsoft Windows Error Reporting Service Improper Privilege Management Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-06-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-06-13"
    },
    {
      "value": "a31e075bd5a2652917f91714fea4d272816c028d7734b36c84899cd583181b3d",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1331",
          "title": "CISA KEV: CVE-2024-26169 \u2014 Microsoft Windows Error Reporting Service Improper Privilege Management Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-06-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-06-13"
    },
    {
      "value": "b0903921e666ca3ffd45100a38c11d7e5c53ab38646715eafc6d1851ad41b92e",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1331",
          "title": "CISA KEV: CVE-2024-26169 \u2014 Microsoft Windows Error Reporting Service Improper Privilege Management Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-06-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-06-13"
    },
    {
      "value": "b73a7e25d224778172e394426c98b86215087d815296c71a3f76f738c720c1b0",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1331",
          "title": "CISA KEV: CVE-2024-26169 \u2014 Microsoft Windows Error Reporting Service Improper Privilege Management Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-06-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-06-13"
    },
    {
      "value": "CVE-2012-1823",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1335",
          "title": "CISA KEV: CVE-2024-4577 \u2014 PHP-CGI OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-06-12",
          "sev": "crit"
        },
        {
          "id": "art-2467",
          "title": "CISA KEV: CVE-2012-1823 \u2014 PHP-CGI Query String Parameter Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-06-12"
    },
    {
      "value": "CVE-2024-4610",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1336",
          "title": "CISA KEV: CVE-2024-4610 \u2014 Arm Mali GPU Kernel Driver Use-After-Free Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-06-12",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-06-12"
    },
    {
      "value": "178.16.55.224",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1335",
          "title": "CISA KEV: CVE-2024-4577 \u2014 PHP-CGI OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-06-12",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-06-12"
    },
    {
      "value": "88.218.76.13",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1335",
          "title": "CISA KEV: CVE-2024-4577 \u2014 PHP-CGI OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-06-12",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-06-12"
    },
    {
      "value": "5a2b9ddddea96f21d905036761ab27627bd6db4f5973b006f1e39d4acb04a618",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1335",
          "title": "CISA KEV: CVE-2024-4577 \u2014 PHP-CGI OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-06-12",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-06-12"
    },
    {
      "value": "95279881525d4ed4ce25777bb967ab87659e7f72235b76f9530456b48a00bac3",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1335",
          "title": "CISA KEV: CVE-2024-4577 \u2014 PHP-CGI OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-06-12",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-06-12"
    },
    {
      "value": "9562ad2c173b107a2baa7a4986825b52e881a935deb4356bf8b80b1ec6d41c53",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1335",
          "title": "CISA KEV: CVE-2024-4577 \u2014 PHP-CGI OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-06-12",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-06-12"
    },
    {
      "value": "CVE-2017-10271",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1342",
          "title": "CISA KEV: CVE-2017-3506 \u2014 Oracle WebLogic Server OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-06-03",
          "sev": "crit"
        },
        {
          "id": "art-2658",
          "title": "CISA KEV: CVE-2017-10271 \u2014 Oracle Corporation WebLogic Server Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-02-10",
          "sev": "crit"
        },
        {
          "id": "art-2722",
          "title": "CISA KEV: CVE-2019-2725 \u2014 Oracle WebLogic Server, Injection",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-01-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-06-03"
    },
    {
      "value": "CVE-2017-3506",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1342",
          "title": "CISA KEV: CVE-2017-3506 \u2014 Oracle WebLogic Server OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-06-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-06-03"
    },
    {
      "value": "CVE-2023-21839",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1342",
          "title": "CISA KEV: CVE-2017-3506 \u2014 Oracle WebLogic Server OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-06-03",
          "sev": "crit"
        },
        {
          "id": "art-1771",
          "title": "CISA KEV: CVE-2023-21839 \u2014 Oracle WebLogic Server Unspecified Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-05-01",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-06-03"
    },
    {
      "value": "su-94.letmaker.top",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1342",
          "title": "CISA KEV: CVE-2017-3506 \u2014 Oracle WebLogic Server OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-06-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-06-03"
    },
    {
      "value": "work.letmaker.top",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1342",
          "title": "CISA KEV: CVE-2017-3506 \u2014 Oracle WebLogic Server OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-06-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-06-03"
    },
    {
      "value": "179.43.155.202",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1342",
          "title": "CISA KEV: CVE-2017-3506 \u2014 Oracle WebLogic Server OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-06-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-06-03"
    },
    {
      "value": "217.182.205.238",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1342",
          "title": "CISA KEV: CVE-2017-3506 \u2014 Oracle WebLogic Server OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-06-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-06-03"
    },
    {
      "value": "79.110.49.232",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1342",
          "title": "CISA KEV: CVE-2017-3506 \u2014 Oracle WebLogic Server OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-06-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-06-03"
    },
    {
      "value": "87.121.105.232",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1342",
          "title": "CISA KEV: CVE-2017-3506 \u2014 Oracle WebLogic Server OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-06-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-06-03"
    },
    {
      "value": "89.169.52.37",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1342",
          "title": "CISA KEV: CVE-2017-3506 \u2014 Oracle WebLogic Server OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-06-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-06-03"
    },
    {
      "value": "89.185.85.102",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1342",
          "title": "CISA KEV: CVE-2017-3506 \u2014 Oracle WebLogic Server OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-06-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-06-03"
    },
    {
      "value": "0bf87b0e65713bf35c8cf54c9fa0015fa629624fd590cb4ba941cd7cdeda8050",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1342",
          "title": "CISA KEV: CVE-2017-3506 \u2014 Oracle WebLogic Server OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-06-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-06-03"
    },
    {
      "value": "2e32c5cea00f8e4c808eae806b14585e8672385df7449d2f6575927537ce8884",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1342",
          "title": "CISA KEV: CVE-2017-3506 \u2014 Oracle WebLogic Server OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-06-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-06-03"
    },
    {
      "value": "b380b771c7f5c2c26750e281101873772e10c8c1a0d2a2ff0aff1912b569ab93",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1342",
          "title": "CISA KEV: CVE-2017-3506 \u2014 Oracle WebLogic Server OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-06-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-06-03"
    },
    {
      "value": "e6e69e85962a402a35cbc5b75571dab3739c0b2f3861ba5853dbd140bae4e4da",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1342",
          "title": "CISA KEV: CVE-2017-3506 \u2014 Oracle WebLogic Server OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-06-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-06-03"
    },
    {
      "value": "f4d11b36a844a68bf9718cf720984468583efa6664fc99966115a44b9a20aa33",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1342",
          "title": "CISA KEV: CVE-2017-3506 \u2014 Oracle WebLogic Server OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-06-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-06-03"
    },
    {
      "value": "CVE-2024-1086",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1344",
          "title": "CISA KEV: CVE-2024-1086 \u2014 Linux Kernel Use-After-Free Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-05-30",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-05-30"
    },
    {
      "value": "CVE-2024-24919",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1345",
          "title": "CISA KEV: CVE-2024-24919 \u2014 Check Point Quantum Security Gateways Information Disclosure Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-05-30",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-05-30"
    },
    {
      "value": "125.229.221.55",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1345",
          "title": "CISA KEV: CVE-2024-24919 \u2014 Check Point Quantum Security Gateways Information Disclosure Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-05-30",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-05-30"
    },
    {
      "value": "45.88.91.78",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1345",
          "title": "CISA KEV: CVE-2024-24919 \u2014 Check Point Quantum Security Gateways Information Disclosure Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-05-30",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-05-30"
    },
    {
      "value": "d1e32373f9a5dab0cc79f785f8533d784e06e3205243ab4e85123158f023abee",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1344",
          "title": "CISA KEV: CVE-2024-1086 \u2014 Linux Kernel Use-After-Free Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-05-30",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-05-30"
    },
    {
      "value": "CVE-2024-4978",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1347",
          "title": "CISA KEV: CVE-2024-4978 \u2014 Justice AV Solutions (JAVS) Viewer Installer Embedded Malicious Code Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-05-29",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-05-29"
    },
    {
      "value": "45.120.177.178",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1347",
          "title": "CISA KEV: CVE-2024-4978 \u2014 Justice AV Solutions (JAVS) Viewer Installer Embedded Malicious Code Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-05-29",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-05-29"
    },
    {
      "value": "2183c102c107d11ae8aa1e9c0f2af3dc8fa462d0683a033d62a982364a0100d0",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1347",
          "title": "CISA KEV: CVE-2024-4978 \u2014 Justice AV Solutions (JAVS) Viewer Installer Embedded Malicious Code Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-05-29",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-05-29"
    },
    {
      "value": "4150452d8041a6ec73c447cbe3b1422203fffdfbf5c845dbac1bed74b33a5e09",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1347",
          "title": "CISA KEV: CVE-2024-4978 \u2014 Justice AV Solutions (JAVS) Viewer Installer Embedded Malicious Code Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-05-29",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-05-29"
    },
    {
      "value": "421a4ad2615941b177b6ec4ab5e239c14e62af2ab07c6df1741e2a62223223c4",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1347",
          "title": "CISA KEV: CVE-2024-4978 \u2014 Justice AV Solutions (JAVS) Viewer Installer Embedded Malicious Code Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-05-29",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-05-29"
    },
    {
      "value": "4f0ca76987edfe00022c8b9c48ad239229ea88532e2b7a7cd6811ae353cd1eda",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1347",
          "title": "CISA KEV: CVE-2024-4978 \u2014 Justice AV Solutions (JAVS) Viewer Installer Embedded Malicious Code Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-05-29",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-05-29"
    },
    {
      "value": "a5e24c10d595969858af422c6dff6bed5f9c6c49dc9622d694327323d8a57d72",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1347",
          "title": "CISA KEV: CVE-2024-4978 \u2014 Justice AV Solutions (JAVS) Viewer Installer Embedded Malicious Code Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-05-29",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-05-29"
    },
    {
      "value": "c65ee0f73f53b287654b6446ffe7264e0d93b24302e7f0036f5e7db3748749b9",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1347",
          "title": "CISA KEV: CVE-2024-4978 \u2014 Justice AV Solutions (JAVS) Viewer Installer Embedded Malicious Code Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-05-29",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-05-29"
    },
    {
      "value": "d8def4437bd76279ec6351b65156d670ec0fed24d904e6648de536fed1061671",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1347",
          "title": "CISA KEV: CVE-2024-4978 \u2014 Justice AV Solutions (JAVS) Viewer Installer Embedded Malicious Code Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-05-29",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-05-29"
    },
    {
      "value": "f8a734d5e7a7b99b29182dddf804d5daa9d876bf39ce7a04721794367a73da51",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1347",
          "title": "CISA KEV: CVE-2024-4978 \u2014 Justice AV Solutions (JAVS) Viewer Installer Embedded Malicious Code Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-05-29",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-05-29"
    },
    {
      "value": "fe408e2df48237b11cb724fa51b6d5e9c74c8f5d5b2955c22962095c7ed70b2c",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1347",
          "title": "CISA KEV: CVE-2024-4978 \u2014 Justice AV Solutions (JAVS) Viewer Installer Embedded Malicious Code Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-05-29",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-05-29"
    },
    {
      "value": "CVE-2024-5274",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1349",
          "title": "CISA KEV: CVE-2024-5274 \u2014 Google Chromium V8 Type Confusion Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-05-28",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-05-28"
    },
    {
      "value": "CVE-2020-17519",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1350",
          "title": "CISA KEV: CVE-2020-17519 \u2014 Apache Flink Improper Access Control Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-05-23",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-05-23"
    },
    {
      "value": "CVE-2023-37679",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1355",
          "title": "CISA KEV: CVE-2023-43208 \u2014 NextGen Healthcare Mirth Connect Deserialization of Untrusted Data Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-05-20",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-05-20"
    },
    {
      "value": "CVE-2023-43208",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1355",
          "title": "CISA KEV: CVE-2023-43208 \u2014 NextGen Healthcare Mirth Connect Deserialization of Untrusted Data Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-05-20",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-05-20"
    },
    {
      "value": "CVE-2024-4947",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1354",
          "title": "CISA KEV: CVE-2024-4947 \u2014 Google Chromium V8 Type Confusion Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-05-20",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-05-20"
    },
    {
      "value": "api.detankzone.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1354",
          "title": "CISA KEV: CVE-2024-4947 \u2014 Google Chromium V8 Type Confusion Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-05-20",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-05-20"
    },
    {
      "value": "ccwaterfall.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1354",
          "title": "CISA KEV: CVE-2024-4947 \u2014 Google Chromium V8 Type Confusion Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-05-20",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-05-20"
    },
    {
      "value": "detankzone.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1354",
          "title": "CISA KEV: CVE-2024-4947 \u2014 Google Chromium V8 Type Confusion Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-05-20",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-05-20"
    },
    {
      "value": "8312e556c4eec999204368d69ba91bf4",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1354",
          "title": "CISA KEV: CVE-2024-4947 \u2014 Google Chromium V8 Type Confusion Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-05-20",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-05-20"
    },
    {
      "value": "b2dc7aec2c6d2ffa28219ac288e4750c",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1354",
          "title": "CISA KEV: CVE-2024-4947 \u2014 Google Chromium V8 Type Confusion Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-05-20",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-05-20"
    },
    {
      "value": "7f28ad5ee9966410b15ca85b7facb70088a17c5f",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1354",
          "title": "CISA KEV: CVE-2024-4947 \u2014 Google Chromium V8 Type Confusion Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-05-20",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-05-20"
    },
    {
      "value": "e5da4ab6366c5690dfd1bb386c7fe0c78f6ed54f",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1354",
          "title": "CISA KEV: CVE-2024-4947 \u2014 Google Chromium V8 Type Confusion Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-05-20",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-05-20"
    },
    {
      "value": "59a37d7d2bf4cffe31407edd286a811d9600b68fe757829e30da4394ab65a4cc",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1354",
          "title": "CISA KEV: CVE-2024-4947 \u2014 Google Chromium V8 Type Confusion Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-05-20",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-05-20"
    },
    {
      "value": "7353ab9670133468081305bd442f7691cf2f2c1136f09d9508400546c417833a",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1354",
          "title": "CISA KEV: CVE-2024-4947 \u2014 Google Chromium V8 Type Confusion Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-05-20",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-05-20"
    },
    {
      "value": "CVE-2014-100005",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1358",
          "title": "CISA KEV: CVE-2014-100005 \u2014 D-Link DIR-600 Router Cross-Site Request Forgery (CSRF) Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-05-16",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-05-16"
    },
    {
      "value": "CVE-2021-40655",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1357",
          "title": "CISA KEV: CVE-2021-40655 \u2014 D-Link DIR-605 Router Information Disclosure Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-05-16",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-05-16"
    },
    {
      "value": "CVE-2024-4761",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1356",
          "title": "CISA KEV: CVE-2024-4761 \u2014 Google Chromium V8 Out-of-Bounds Memory Write Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-05-16",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-05-16"
    },
    {
      "value": "CVE-2024-30040",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1360",
          "title": "CISA KEV: CVE-2024-30040 \u2014 Microsoft Windows MSHTML Platform Security Feature Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-05-14",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-05-14"
    },
    {
      "value": "CVE-2024-30051",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1361",
          "title": "CISA KEV: CVE-2024-30051 \u2014  Microsoft DWM Core Library Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-05-14",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-05-14"
    },
    {
      "value": "CVE-2024-4671",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1363",
          "title": "CISA KEV: CVE-2024-4671 \u2014 Google Chromium Visuals Use-After-Free Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-05-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-05-13"
    },
    {
      "value": "CVE-2023-7028",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1369",
          "title": "CISA KEV: CVE-2023-7028 \u2014 GitLab Community and Enterprise Editions Improper Access Control Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-05-01",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-05-01"
    },
    {
      "value": "CVE-2024-20353",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1375",
          "title": "CISA KEV: CVE-2024-20359 \u2014 Cisco ASA and FTD Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-04-24",
          "sev": "crit"
        },
        {
          "id": "art-1376",
          "title": "CISA KEV: CVE-2024-20353 \u2014 Cisco ASA and FTD Denial of Service Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-04-24",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-04-24"
    },
    {
      "value": "CVE-2024-20358",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1375",
          "title": "CISA KEV: CVE-2024-20359 \u2014 Cisco ASA and FTD Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-04-24",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-04-24"
    },
    {
      "value": "CVE-2024-20359",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1375",
          "title": "CISA KEV: CVE-2024-20359 \u2014 Cisco ASA and FTD Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-04-24",
          "sev": "crit"
        },
        {
          "id": "art-1376",
          "title": "CISA KEV: CVE-2024-20353 \u2014 Cisco ASA and FTD Denial of Service Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-04-24",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-04-24"
    },
    {
      "value": "103.114.200.230",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1375",
          "title": "CISA KEV: CVE-2024-20359 \u2014 Cisco ASA and FTD Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-04-24",
          "sev": "crit"
        },
        {
          "id": "art-1376",
          "title": "CISA KEV: CVE-2024-20353 \u2014 Cisco ASA and FTD Denial of Service Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-04-24",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-04-24"
    },
    {
      "value": "121.227.168.69",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1375",
          "title": "CISA KEV: CVE-2024-20359 \u2014 Cisco ASA and FTD Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-04-24",
          "sev": "crit"
        },
        {
          "id": "art-1376",
          "title": "CISA KEV: CVE-2024-20353 \u2014 Cisco ASA and FTD Denial of Service Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-04-24",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-04-24"
    },
    {
      "value": "131.196.252.148",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1375",
          "title": "CISA KEV: CVE-2024-20359 \u2014 Cisco ASA and FTD Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-04-24",
          "sev": "crit"
        },
        {
          "id": "art-1376",
          "title": "CISA KEV: CVE-2024-20353 \u2014 Cisco ASA and FTD Denial of Service Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-04-24",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-04-24"
    },
    {
      "value": "172.105.90.154",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1375",
          "title": "CISA KEV: CVE-2024-20359 \u2014 Cisco ASA and FTD Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-04-24",
          "sev": "crit"
        },
        {
          "id": "art-1376",
          "title": "CISA KEV: CVE-2024-20353 \u2014 Cisco ASA and FTD Denial of Service Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-04-24",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-04-24"
    },
    {
      "value": "172.105.94.93",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1375",
          "title": "CISA KEV: CVE-2024-20359 \u2014 Cisco ASA and FTD Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-04-24",
          "sev": "crit"
        },
        {
          "id": "art-1376",
          "title": "CISA KEV: CVE-2024-20353 \u2014 Cisco ASA and FTD Denial of Service Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-04-24",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-04-24"
    },
    {
      "value": "176.31.18.153",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1375",
          "title": "CISA KEV: CVE-2024-20359 \u2014 Cisco ASA and FTD Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-04-24",
          "sev": "crit"
        },
        {
          "id": "art-1376",
          "title": "CISA KEV: CVE-2024-20353 \u2014 Cisco ASA and FTD Denial of Service Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-04-24",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-04-24"
    },
    {
      "value": "185.167.60.85",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1375",
          "title": "CISA KEV: CVE-2024-20359 \u2014 Cisco ASA and FTD Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-04-24",
          "sev": "crit"
        },
        {
          "id": "art-1376",
          "title": "CISA KEV: CVE-2024-20353 \u2014 Cisco ASA and FTD Denial of Service Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-04-24",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-04-24"
    },
    {
      "value": "185.227.111.17",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1375",
          "title": "CISA KEV: CVE-2024-20359 \u2014 Cisco ASA and FTD Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-04-24",
          "sev": "crit"
        },
        {
          "id": "art-1376",
          "title": "CISA KEV: CVE-2024-20353 \u2014 Cisco ASA and FTD Denial of Service Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-04-24",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-04-24"
    },
    {
      "value": "185.244.210.120",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1375",
          "title": "CISA KEV: CVE-2024-20359 \u2014 Cisco ASA and FTD Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-04-24",
          "sev": "crit"
        },
        {
          "id": "art-1376",
          "title": "CISA KEV: CVE-2024-20353 \u2014 Cisco ASA and FTD Denial of Service Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-04-24",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-04-24"
    },
    {
      "value": "185.244.210.65",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1375",
          "title": "CISA KEV: CVE-2024-20359 \u2014 Cisco ASA and FTD Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-04-24",
          "sev": "crit"
        },
        {
          "id": "art-1376",
          "title": "CISA KEV: CVE-2024-20353 \u2014 Cisco ASA and FTD Denial of Service Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-04-24",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-04-24"
    },
    {
      "value": "192.36.57.181",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1375",
          "title": "CISA KEV: CVE-2024-20359 \u2014 Cisco ASA and FTD Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-04-24",
          "sev": "crit"
        },
        {
          "id": "art-1376",
          "title": "CISA KEV: CVE-2024-20353 \u2014 Cisco ASA and FTD Denial of Service Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-04-24",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-04-24"
    },
    {
      "value": "194.4.49.6",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1375",
          "title": "CISA KEV: CVE-2024-20359 \u2014 Cisco ASA and FTD Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-04-24",
          "sev": "crit"
        },
        {
          "id": "art-1376",
          "title": "CISA KEV: CVE-2024-20353 \u2014 Cisco ASA and FTD Denial of Service Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-04-24",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-04-24"
    },
    {
      "value": "212.193.2.48",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1375",
          "title": "CISA KEV: CVE-2024-20359 \u2014 Cisco ASA and FTD Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-04-24",
          "sev": "crit"
        },
        {
          "id": "art-1376",
          "title": "CISA KEV: CVE-2024-20353 \u2014 Cisco ASA and FTD Denial of Service Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-04-24",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-04-24"
    },
    {
      "value": "213.156.138.68",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1375",
          "title": "CISA KEV: CVE-2024-20359 \u2014 Cisco ASA and FTD Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-04-24",
          "sev": "crit"
        },
        {
          "id": "art-1376",
          "title": "CISA KEV: CVE-2024-20353 \u2014 Cisco ASA and FTD Denial of Service Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-04-24",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-04-24"
    },
    {
      "value": "213.156.138.77",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1375",
          "title": "CISA KEV: CVE-2024-20359 \u2014 Cisco ASA and FTD Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-04-24",
          "sev": "crit"
        },
        {
          "id": "art-1376",
          "title": "CISA KEV: CVE-2024-20353 \u2014 Cisco ASA and FTD Denial of Service Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-04-24",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-04-24"
    },
    {
      "value": "213.156.138.78",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1375",
          "title": "CISA KEV: CVE-2024-20359 \u2014 Cisco ASA and FTD Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-04-24",
          "sev": "crit"
        },
        {
          "id": "art-1376",
          "title": "CISA KEV: CVE-2024-20353 \u2014 Cisco ASA and FTD Denial of Service Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-04-24",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-04-24"
    },
    {
      "value": "216.238.75.155",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1375",
          "title": "CISA KEV: CVE-2024-20359 \u2014 Cisco ASA and FTD Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-04-24",
          "sev": "crit"
        },
        {
          "id": "art-1376",
          "title": "CISA KEV: CVE-2024-20353 \u2014 Cisco ASA and FTD Denial of Service Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-04-24",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-04-24"
    },
    {
      "value": "45.77.52.253",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1375",
          "title": "CISA KEV: CVE-2024-20359 \u2014 Cisco ASA and FTD Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-04-24",
          "sev": "crit"
        },
        {
          "id": "art-1376",
          "title": "CISA KEV: CVE-2024-20353 \u2014 Cisco ASA and FTD Denial of Service Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-04-24",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-04-24"
    },
    {
      "value": "45.86.163.224",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1375",
          "title": "CISA KEV: CVE-2024-20359 \u2014 Cisco ASA and FTD Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-04-24",
          "sev": "crit"
        },
        {
          "id": "art-1376",
          "title": "CISA KEV: CVE-2024-20353 \u2014 Cisco ASA and FTD Denial of Service Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-04-24",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-04-24"
    },
    {
      "value": "51.15.145.37",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1375",
          "title": "CISA KEV: CVE-2024-20359 \u2014 Cisco ASA and FTD Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-04-24",
          "sev": "crit"
        },
        {
          "id": "art-1376",
          "title": "CISA KEV: CVE-2024-20353 \u2014 Cisco ASA and FTD Denial of Service Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-04-24",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-04-24"
    },
    {
      "value": "89.44.198.189",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1375",
          "title": "CISA KEV: CVE-2024-20359 \u2014 Cisco ASA and FTD Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-04-24",
          "sev": "crit"
        },
        {
          "id": "art-1376",
          "title": "CISA KEV: CVE-2024-20353 \u2014 Cisco ASA and FTD Denial of Service Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-04-24",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-04-24"
    },
    {
      "value": "89.44.198.196",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1375",
          "title": "CISA KEV: CVE-2024-20359 \u2014 Cisco ASA and FTD Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-04-24",
          "sev": "crit"
        },
        {
          "id": "art-1376",
          "title": "CISA KEV: CVE-2024-20353 \u2014 Cisco ASA and FTD Denial of Service Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-04-24",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-04-24"
    },
    {
      "value": "CVE-2022-38028",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1379",
          "title": "CISA KEV: CVE-2022-38028 \u2014 Microsoft Windows Print Spooler Privilege Escalation Vulnerability ",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-04-23",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-04-23"
    },
    {
      "value": "CVE-2024-3400",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1385",
          "title": "CISA KEV: CVE-2024-3400 \u2014 Palo Alto Networks PAN-OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-04-12",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-04-12"
    },
    {
      "value": "110.47.250.103",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1385",
          "title": "CISA KEV: CVE-2024-3400 \u2014 Palo Alto Networks PAN-OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-04-12",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-04-12"
    },
    {
      "value": "126.227.76.24",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1385",
          "title": "CISA KEV: CVE-2024-3400 \u2014 Palo Alto Networks PAN-OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-04-12",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-04-12"
    },
    {
      "value": "144.172.79.92",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1385",
          "title": "CISA KEV: CVE-2024-3400 \u2014 Palo Alto Networks PAN-OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-04-12",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-04-12"
    },
    {
      "value": "146.70.192.174",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1385",
          "title": "CISA KEV: CVE-2024-3400 \u2014 Palo Alto Networks PAN-OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-04-12",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-04-12"
    },
    {
      "value": "147.45.70.100",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1385",
          "title": "CISA KEV: CVE-2024-3400 \u2014 Palo Alto Networks PAN-OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-04-12",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-04-12"
    },
    {
      "value": "149.28.194.95",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1385",
          "title": "CISA KEV: CVE-2024-3400 \u2014 Palo Alto Networks PAN-OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-04-12",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-04-12"
    },
    {
      "value": "149.88.27.212",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1385",
          "title": "CISA KEV: CVE-2024-3400 \u2014 Palo Alto Networks PAN-OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-04-12",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-04-12"
    },
    {
      "value": "154.223.16.34",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1385",
          "title": "CISA KEV: CVE-2024-3400 \u2014 Palo Alto Networks PAN-OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-04-12",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-04-12"
    },
    {
      "value": "172.233.228.93",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1385",
          "title": "CISA KEV: CVE-2024-3400 \u2014 Palo Alto Networks PAN-OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-04-12",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-04-12"
    },
    {
      "value": "173.255.223.159",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1385",
          "title": "CISA KEV: CVE-2024-3400 \u2014 Palo Alto Networks PAN-OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-04-12",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-04-12"
    },
    {
      "value": "185.108.105.110",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1385",
          "title": "CISA KEV: CVE-2024-3400 \u2014 Palo Alto Networks PAN-OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-04-12",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-04-12"
    },
    {
      "value": "199.119.206.28",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1385",
          "title": "CISA KEV: CVE-2024-3400 \u2014 Palo Alto Networks PAN-OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-04-12",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-04-12"
    },
    {
      "value": "203.160.86.91",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1385",
          "title": "CISA KEV: CVE-2024-3400 \u2014 Palo Alto Networks PAN-OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-04-12",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-04-12"
    },
    {
      "value": "38.180.106.167",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1385",
          "title": "CISA KEV: CVE-2024-3400 \u2014 Palo Alto Networks PAN-OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-04-12",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-04-12"
    },
    {
      "value": "38.180.128.159",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1385",
          "title": "CISA KEV: CVE-2024-3400 \u2014 Palo Alto Networks PAN-OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-04-12",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-04-12"
    },
    {
      "value": "38.180.41.251",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1385",
          "title": "CISA KEV: CVE-2024-3400 \u2014 Palo Alto Networks PAN-OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-04-12",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-04-12"
    },
    {
      "value": "38.181.70.3",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1385",
          "title": "CISA KEV: CVE-2024-3400 \u2014 Palo Alto Networks PAN-OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-04-12",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-04-12"
    },
    {
      "value": "38.207.148.123",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1385",
          "title": "CISA KEV: CVE-2024-3400 \u2014 Palo Alto Networks PAN-OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-04-12",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-04-12"
    },
    {
      "value": "38.60.218.153",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1385",
          "title": "CISA KEV: CVE-2024-3400 \u2014 Palo Alto Networks PAN-OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-04-12",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-04-12"
    },
    {
      "value": "45.121.51.2",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1385",
          "title": "CISA KEV: CVE-2024-3400 \u2014 Palo Alto Networks PAN-OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-04-12",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-04-12"
    },
    {
      "value": "64.176.226.203",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1385",
          "title": "CISA KEV: CVE-2024-3400 \u2014 Palo Alto Networks PAN-OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-04-12",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-04-12"
    },
    {
      "value": "66.235.168.222",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1385",
          "title": "CISA KEV: CVE-2024-3400 \u2014 Palo Alto Networks PAN-OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-04-12",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-04-12"
    },
    {
      "value": "78.141.232.174",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1385",
          "title": "CISA KEV: CVE-2024-3400 \u2014 Palo Alto Networks PAN-OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-04-12",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-04-12"
    },
    {
      "value": "089801d87998fa193377b9bfe98e87ff",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1385",
          "title": "CISA KEV: CVE-2024-3400 \u2014 Palo Alto Networks PAN-OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-04-12",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-04-12"
    },
    {
      "value": "0c1554888ce9ed0da1583dbdf7b31651",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1385",
          "title": "CISA KEV: CVE-2024-3400 \u2014 Palo Alto Networks PAN-OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-04-12",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-04-12"
    },
    {
      "value": "427258462c745481c1ae47327182acd3",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1385",
          "title": "CISA KEV: CVE-2024-3400 \u2014 Palo Alto Networks PAN-OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-04-12",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-04-12"
    },
    {
      "value": "d31ec83a5a79451a46e980ebffb6e0e8",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1385",
          "title": "CISA KEV: CVE-2024-3400 \u2014 Palo Alto Networks PAN-OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-04-12",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-04-12"
    },
    {
      "value": "988fc0d23e6e30c2c46ccec9bbff50b7453b8ba9",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1385",
          "title": "CISA KEV: CVE-2024-3400 \u2014 Palo Alto Networks PAN-OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-04-12",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-04-12"
    },
    {
      "value": "a7c6f264b00d13808ceb76b3277ee5461ae1354e",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1385",
          "title": "CISA KEV: CVE-2024-3400 \u2014 Palo Alto Networks PAN-OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-04-12",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-04-12"
    },
    {
      "value": "161fd76c83e557269bee39a57baa2ccbbac679f59d9adff1e1b73b0f4bb277a6",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1385",
          "title": "CISA KEV: CVE-2024-3400 \u2014 Palo Alto Networks PAN-OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-04-12",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-04-12"
    },
    {
      "value": "35a5f8ac03b0e3865b3177892420cb34233c55240f452f00f9004e274a85703c",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1385",
          "title": "CISA KEV: CVE-2024-3400 \u2014 Palo Alto Networks PAN-OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-04-12",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-04-12"
    },
    {
      "value": "3de2a4392b8715bad070b2ae12243f166ead37830f7c6d24e778985927f9caac",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1385",
          "title": "CISA KEV: CVE-2024-3400 \u2014 Palo Alto Networks PAN-OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-04-12",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-04-12"
    },
    {
      "value": "448fbd7b3389fe2aa421de224d065cea7064de0869a036610e5363c931df5b7c",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1385",
          "title": "CISA KEV: CVE-2024-3400 \u2014 Palo Alto Networks PAN-OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-04-12",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-04-12"
    },
    {
      "value": "5460b51da26c060727d128f3b3d6415d1a4c25af6a29fef4cc6b867ad3659078",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1385",
          "title": "CISA KEV: CVE-2024-3400 \u2014 Palo Alto Networks PAN-OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-04-12",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-04-12"
    },
    {
      "value": "755f5b8bd67d226f24329dc960f59e11cb5735b930b4ed30b2df77572efb32e8",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1385",
          "title": "CISA KEV: CVE-2024-3400 \u2014 Palo Alto Networks PAN-OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-04-12",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-04-12"
    },
    {
      "value": "96dbec24ac64e7dd5fef6e2c26214c8fe5be3486d5c92d21d5dcb4f6c4e365b9",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1385",
          "title": "CISA KEV: CVE-2024-3400 \u2014 Palo Alto Networks PAN-OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-04-12",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-04-12"
    },
    {
      "value": "adba167a9df482aa991faaa0e0cde1182fb9acfbb0dc8d19148ce634608bab87",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1385",
          "title": "CISA KEV: CVE-2024-3400 \u2014 Palo Alto Networks PAN-OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-04-12",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-04-12"
    },
    {
      "value": "e315907415eb8cfcf3b6a4cd6602b392a3fe8ee0f79a2d51a81a928dbce950f8",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1385",
          "title": "CISA KEV: CVE-2024-3400 \u2014 Palo Alto Networks PAN-OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-04-12",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-04-12"
    },
    {
      "value": "fe07ca449e99827265ca95f9f56ec6543a4c5b712ed50038a9a153199e95a0b7",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1385",
          "title": "CISA KEV: CVE-2024-3400 \u2014 Palo Alto Networks PAN-OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-04-12",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-04-12"
    },
    {
      "value": "CVE-2024-3272",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1387",
          "title": "CISA KEV: CVE-2024-3273 \u2014 D-Link Multiple NAS Devices Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-04-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-04-11"
    },
    {
      "value": "CVE-2024-3273",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1387",
          "title": "CISA KEV: CVE-2024-3273 \u2014 D-Link Multiple NAS Devices Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-04-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-04-11"
    },
    {
      "value": "38.6.224.248",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1387",
          "title": "CISA KEV: CVE-2024-3273 \u2014 D-Link Multiple NAS Devices Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-04-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-04-11"
    },
    {
      "value": "859e679f8e8be4a4c895139fb7fb1b177627bbe712e1ed4c316ec85008426db8",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1387",
          "title": "CISA KEV: CVE-2024-3273 \u2014 D-Link Multiple NAS Devices Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-04-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-04-11"
    },
    {
      "value": "CVE-2023-45288",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-1389",
          "title": "Exploiting HTTP/2 CONTINUATION frames for DoS attacks",
          "link": "https://snyk.io/blog/exploiting-http-2-continuation-frames-dos-attacks/",
          "published": "2024-04-08",
          "sev": "high"
        }
      ],
      "first_seen": "2024-04-08"
    },
    {
      "value": "CVE-2024-24549",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-1389",
          "title": "Exploiting HTTP/2 CONTINUATION frames for DoS attacks",
          "link": "https://snyk.io/blog/exploiting-http-2-continuation-frames-dos-attacks/",
          "published": "2024-04-08",
          "sev": "high"
        }
      ],
      "first_seen": "2024-04-08"
    },
    {
      "value": "CVE-2024-2653",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-1389",
          "title": "Exploiting HTTP/2 CONTINUATION frames for DoS attacks",
          "link": "https://snyk.io/blog/exploiting-http-2-continuation-frames-dos-attacks/",
          "published": "2024-04-08",
          "sev": "high"
        }
      ],
      "first_seen": "2024-04-08"
    },
    {
      "value": "CVE-2024-27316",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-1389",
          "title": "Exploiting HTTP/2 CONTINUATION frames for DoS attacks",
          "link": "https://snyk.io/blog/exploiting-http-2-continuation-frames-dos-attacks/",
          "published": "2024-04-08",
          "sev": "high"
        }
      ],
      "first_seen": "2024-04-08"
    },
    {
      "value": "CVE-2024-2758",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-1389",
          "title": "Exploiting HTTP/2 CONTINUATION frames for DoS attacks",
          "link": "https://snyk.io/blog/exploiting-http-2-continuation-frames-dos-attacks/",
          "published": "2024-04-08",
          "sev": "high"
        }
      ],
      "first_seen": "2024-04-08"
    },
    {
      "value": "CVE-2024-27919",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-1389",
          "title": "Exploiting HTTP/2 CONTINUATION frames for DoS attacks",
          "link": "https://snyk.io/blog/exploiting-http-2-continuation-frames-dos-attacks/",
          "published": "2024-04-08",
          "sev": "high"
        }
      ],
      "first_seen": "2024-04-08"
    },
    {
      "value": "CVE-2024-27983",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-1389",
          "title": "Exploiting HTTP/2 CONTINUATION frames for DoS attacks",
          "link": "https://snyk.io/blog/exploiting-http-2-continuation-frames-dos-attacks/",
          "published": "2024-04-08",
          "sev": "high"
        }
      ],
      "first_seen": "2024-04-08"
    },
    {
      "value": "CVE-2024-28182",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-1389",
          "title": "Exploiting HTTP/2 CONTINUATION frames for DoS attacks",
          "link": "https://snyk.io/blog/exploiting-http-2-continuation-frames-dos-attacks/",
          "published": "2024-04-08",
          "sev": "high"
        }
      ],
      "first_seen": "2024-04-08"
    },
    {
      "value": "CVE-2024-30255",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-1389",
          "title": "Exploiting HTTP/2 CONTINUATION frames for DoS attacks",
          "link": "https://snyk.io/blog/exploiting-http-2-continuation-frames-dos-attacks/",
          "published": "2024-04-08",
          "sev": "high"
        }
      ],
      "first_seen": "2024-04-08"
    },
    {
      "value": "CVE-2024-31309",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-1389",
          "title": "Exploiting HTTP/2 CONTINUATION frames for DoS attacks",
          "link": "https://snyk.io/blog/exploiting-http-2-continuation-frames-dos-attacks/",
          "published": "2024-04-08",
          "sev": "high"
        }
      ],
      "first_seen": "2024-04-08"
    },
    {
      "value": "CVE-2024-29745",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1391",
          "title": "CISA KEV: CVE-2024-29745 \u2014 Android Pixel Information Disclosure Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-04-04",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-04-04"
    },
    {
      "value": "CVE-2024-29748",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1390",
          "title": "CISA KEV: CVE-2024-29748 \u2014 Android Pixel Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-04-04",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-04-04"
    },
    {
      "value": "CVE-2023-24955",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1395",
          "title": "CISA KEV: CVE-2023-24955 \u2014 Microsoft SharePoint Server Code Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-03-26",
          "sev": "crit"
        },
        {
          "id": "art-1453",
          "title": "CISA KEV: CVE-2023-29357 \u2014 Microsoft SharePoint Server Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-01-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-03-26"
    },
    {
      "value": "CVE-2023-29357",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1395",
          "title": "CISA KEV: CVE-2023-24955 \u2014 Microsoft SharePoint Server Code Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-03-26",
          "sev": "crit"
        },
        {
          "id": "art-1453",
          "title": "CISA KEV: CVE-2023-29357 \u2014 Microsoft SharePoint Server Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-01-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-03-26"
    },
    {
      "value": "CVE-2019-7256",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1396",
          "title": "CISA KEV: CVE-2019-7256 \u2014 Nice Linear eMerge E3-Series OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-03-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-03-25"
    },
    {
      "value": "CVE-2021-44529",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1397",
          "title": "CISA KEV: CVE-2021-44529 \u2014 Ivanti Endpoint Manager Cloud Service Appliance (EPM CSA) Code Injection Vulnerability ",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-03-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-03-25"
    },
    {
      "value": "CVE-2023-48788",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1398",
          "title": "CISA KEV: CVE-2023-48788 \u2014 Fortinet FortiClient EMS SQL Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-03-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-03-25"
    },
    {
      "value": "api.playanext.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1398",
          "title": "CISA KEV: CVE-2023-48788 \u2014 Fortinet FortiClient EMS SQL Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-03-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-03-25"
    },
    {
      "value": "azure-documents.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1398",
          "title": "CISA KEV: CVE-2023-48788 \u2014 Fortinet FortiClient EMS SQL Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-03-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-03-25"
    },
    {
      "value": "104.168.140.84",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1398",
          "title": "CISA KEV: CVE-2023-48788 \u2014 Fortinet FortiClient EMS SQL Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-03-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-03-25"
    },
    {
      "value": "128.199.207.131",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1398",
          "title": "CISA KEV: CVE-2023-48788 \u2014 Fortinet FortiClient EMS SQL Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-03-25",
          "sev": "crit"
        },
        {
          "id": "art-1575",
          "title": "CISA KEV: CVE-2023-42793 \u2014 JetBrains TeamCity Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-10-04",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-03-25"
    },
    {
      "value": "185.56.83.82",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1398",
          "title": "CISA KEV: CVE-2023-48788 \u2014 Fortinet FortiClient EMS SQL Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-03-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-03-25"
    },
    {
      "value": "212.113.106.100",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1398",
          "title": "CISA KEV: CVE-2023-48788 \u2014 Fortinet FortiClient EMS SQL Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-03-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-03-25"
    },
    {
      "value": "212.32.243.25",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1398",
          "title": "CISA KEV: CVE-2023-48788 \u2014 Fortinet FortiClient EMS SQL Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-03-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-03-25"
    },
    {
      "value": "77.246.103.110",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1398",
          "title": "CISA KEV: CVE-2023-48788 \u2014 Fortinet FortiClient EMS SQL Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-03-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-03-25"
    },
    {
      "value": "89.149.200.91",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1398",
          "title": "CISA KEV: CVE-2023-48788 \u2014 Fortinet FortiClient EMS SQL Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-03-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-03-25"
    },
    {
      "value": "95.181.173.172",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1398",
          "title": "CISA KEV: CVE-2023-48788 \u2014 Fortinet FortiClient EMS SQL Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-03-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-03-25"
    },
    {
      "value": "CVE-2024-1597",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-1401",
          "title": "Snyk users don't have to worry about NVD delays",
          "link": "https://snyk.io/blog/snyk-users-dont-have-to-worry-about-nvd-delays/",
          "published": "2024-03-13",
          "sev": "high"
        }
      ],
      "first_seen": "2024-03-13"
    },
    {
      "value": "CVE-2024-22243",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-1401",
          "title": "Snyk users don't have to worry about NVD delays",
          "link": "https://snyk.io/blog/snyk-users-dont-have-to-worry-about-nvd-delays/",
          "published": "2024-03-13",
          "sev": "high"
        }
      ],
      "first_seen": "2024-03-13"
    },
    {
      "value": "CVE-2024-27198",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1404",
          "title": "CISA KEV: CVE-2024-27198 \u2014 JetBrains TeamCity Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-03-07",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-03-07"
    },
    {
      "value": "CVE-2024-23225",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1406",
          "title": "CISA KEV: CVE-2024-23225 \u2014 Apple Multiple Products Memory Corruption Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-03-06",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-03-06"
    },
    {
      "value": "CVE-2024-23296",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1407",
          "title": "CISA KEV: CVE-2024-23296 \u2014 Apple Multiple Products Memory Corruption Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-03-06",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-03-06"
    },
    {
      "value": "CVE-2021-36380",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1410",
          "title": "CISA KEV: CVE-2021-36380 \u2014 Sunhillo SureLine OS Command Injection Vulnerablity",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-03-05",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-03-05"
    },
    {
      "value": "CVE-2023-21237",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1409",
          "title": "CISA KEV: CVE-2023-21237 \u2014 Android Pixel Information Disclosure Vulnerability ",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-03-05",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-03-05"
    },
    {
      "value": "CVE-2023-29360",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1416",
          "title": "CISA KEV: CVE-2023-29360 \u2014 Microsoft Streaming Service Untrusted Pointer Dereference Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-02-29",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-02-29"
    },
    {
      "value": "CVE-2024-1709",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1419",
          "title": "CISA KEV: CVE-2024-1709 \u2014 ConnectWise ScreenConnect Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-02-22",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-02-22"
    },
    {
      "value": "116.0.56.101",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1419",
          "title": "CISA KEV: CVE-2024-1709 \u2014 ConnectWise ScreenConnect Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-02-22",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-02-22"
    },
    {
      "value": "118.69.65.60",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1419",
          "title": "CISA KEV: CVE-2024-1709 \u2014 ConnectWise ScreenConnect Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-02-22",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-02-22"
    },
    {
      "value": "119.3.12.54",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1419",
          "title": "CISA KEV: CVE-2024-1709 \u2014 ConnectWise ScreenConnect Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-02-22",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-02-22"
    },
    {
      "value": "155.133.5.14",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1419",
          "title": "CISA KEV: CVE-2024-1709 \u2014 ConnectWise ScreenConnect Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-02-22",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-02-22"
    },
    {
      "value": "155.133.5.15",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1419",
          "title": "CISA KEV: CVE-2024-1709 \u2014 ConnectWise ScreenConnect Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-02-22",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-02-22"
    },
    {
      "value": "159.65.130.146",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1419",
          "title": "CISA KEV: CVE-2024-1709 \u2014 ConnectWise ScreenConnect Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-02-22",
          "sev": "crit"
        },
        {
          "id": "art-1454",
          "title": "CISA KEV: CVE-2023-46805 \u2014 Ivanti Connect Secure and Policy Secure Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-01-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-02-22"
    },
    {
      "value": "185.232.92.32",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1419",
          "title": "CISA KEV: CVE-2024-1709 \u2014 ConnectWise ScreenConnect Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-02-22",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-02-22"
    },
    {
      "value": "207.246.74.189",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1419",
          "title": "CISA KEV: CVE-2024-1709 \u2014 ConnectWise ScreenConnect Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-02-22",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-02-22"
    },
    {
      "value": "23.26.137.225",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1419",
          "title": "CISA KEV: CVE-2024-1709 \u2014 ConnectWise ScreenConnect Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-02-22",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-02-22"
    },
    {
      "value": "91.238.181.238",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1419",
          "title": "CISA KEV: CVE-2024-1709 \u2014 ConnectWise ScreenConnect Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-02-22",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-02-22"
    },
    {
      "value": "0d185ea3b0a49c2fa65bfd2757c9d0705657f0639fd36f196ac394fcd38c361d",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1419",
          "title": "CISA KEV: CVE-2024-1709 \u2014 ConnectWise ScreenConnect Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-02-22",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-02-22"
    },
    {
      "value": "11d2dde6c51e977ed6e3f3d3e256c78062ae41fe780aefecfba1627e66daf771",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1419",
          "title": "CISA KEV: CVE-2024-1709 \u2014 ConnectWise ScreenConnect Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-02-22",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-02-22"
    },
    {
      "value": "1362e6d43b068005f5d7c755e997e6202775430ac15a794014aa9a7a03a974e7",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1419",
          "title": "CISA KEV: CVE-2024-1709 \u2014 ConnectWise ScreenConnect Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-02-22",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-02-22"
    },
    {
      "value": "19fc383683b34ba31ed055dc2e546a64eecbe06d79b6cc346773478c84f25f92",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1419",
          "title": "CISA KEV: CVE-2024-1709 \u2014 ConnectWise ScreenConnect Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-02-22",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-02-22"
    },
    {
      "value": "254714b7028005596fd56bdbe30bfc77f02bbe274048d0982118d93966e79331",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1419",
          "title": "CISA KEV: CVE-2024-1709 \u2014 ConnectWise ScreenConnect Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-02-22",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-02-22"
    },
    {
      "value": "2da975fee507060baa1042fb45e8467579abf3f348f1fd37b86bb742db63438a",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1419",
          "title": "CISA KEV: CVE-2024-1709 \u2014 ConnectWise ScreenConnect Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-02-22",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-02-22"
    },
    {
      "value": "3818bb7adf60f8c2aeb5fe8c59b81fc7eb7f1471a80932610dc9a294ba7ba543",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1419",
          "title": "CISA KEV: CVE-2024-1709 \u2014 ConnectWise ScreenConnect Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-02-22",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-02-22"
    },
    {
      "value": "444338339260d884070de53554543785acc3c9772e92c5af1dff96e60e67c195",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1419",
          "title": "CISA KEV: CVE-2024-1709 \u2014 ConnectWise ScreenConnect Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-02-22",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-02-22"
    },
    {
      "value": "55e4ce3fe726043070ecd7de5a74b2459ea8bed19ef2a36ce7884b2ab0863047",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1419",
          "title": "CISA KEV: CVE-2024-1709 \u2014 ConnectWise ScreenConnect Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-02-22",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-02-22"
    },
    {
      "value": "858ddfe6530fb00adb467f26e2c8f119fef284e1e9b6c92f0634f403ee3e7913",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1419",
          "title": "CISA KEV: CVE-2024-1709 \u2014 ConnectWise ScreenConnect Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-02-22",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-02-22"
    },
    {
      "value": "86b5d7dd88b46a3e7c2fb58c01fbeb11dc7ad350370abfe648dbfad45edb8132",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1419",
          "title": "CISA KEV: CVE-2024-1709 \u2014 ConnectWise ScreenConnect Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-02-22",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-02-22"
    },
    {
      "value": "8c2d246bf93bf84f6d4376cd46d8fcc3cb9c96d9bef7d42c23ff222d8f66eeaf",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1419",
          "title": "CISA KEV: CVE-2024-1709 \u2014 ConnectWise ScreenConnect Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-02-22",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-02-22"
    },
    {
      "value": "8e51de4774d27ad31a83d5df060ba008148665ab9caf6bc889a5e3fba4d7e600",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1419",
          "title": "CISA KEV: CVE-2024-1709 \u2014 ConnectWise ScreenConnect Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-02-22",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-02-22"
    },
    {
      "value": "9b3327f9ea7c02c6909a472a3c1abb562b19ae72d733a8e2e990e975b5f8a5d0",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1419",
          "title": "CISA KEV: CVE-2024-1709 \u2014 ConnectWise ScreenConnect Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-02-22",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-02-22"
    },
    {
      "value": "a39d9b1b41157510d16e41e7c877b35452f201d02a05afa328f1bcd53d8ee016",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1419",
          "title": "CISA KEV: CVE-2024-1709 \u2014 ConnectWise ScreenConnect Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-02-22",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-02-22"
    },
    {
      "value": "a50d9954c0a50e5804065a8165b18571048160200249766bfa2f75d03c8cb6d0",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1419",
          "title": "CISA KEV: CVE-2024-1709 \u2014 ConnectWise ScreenConnect Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-02-22",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-02-22"
    },
    {
      "value": "b423d100e7aa2e576c8f21586f1d8924b34c3e9ed4cfdba40d121e21c3618445",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1419",
          "title": "CISA KEV: CVE-2024-1709 \u2014 ConnectWise ScreenConnect Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-02-22",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-02-22"
    },
    {
      "value": "c94038781c56ab85d2f110db4f45b86ccf269e77a3ff4b9133b96745ff97d25f",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1419",
          "title": "CISA KEV: CVE-2024-1709 \u2014 ConnectWise ScreenConnect Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-02-22",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-02-22"
    },
    {
      "value": "de42bd53cb0944da8bc33107796ecf296d00968725eed1763a8143cef90e2297",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1419",
          "title": "CISA KEV: CVE-2024-1709 \u2014 ConnectWise ScreenConnect Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-02-22",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-02-22"
    },
    {
      "value": "f1c7045badec0b9771da4a0f067eac99587d235d1ede35190080cd051d923da6",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1419",
          "title": "CISA KEV: CVE-2024-1709 \u2014 ConnectWise ScreenConnect Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-02-22",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-02-22"
    },
    {
      "value": "f3f5d3595559cad6019406d41f96fa88c69d693326cdf608c5fc4941fdf6a8ec",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1419",
          "title": "CISA KEV: CVE-2024-1709 \u2014 ConnectWise ScreenConnect Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-02-22",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-02-22"
    },
    {
      "value": "CVE-2020-3259",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1423",
          "title": "CISA KEV: CVE-2020-3259 \u2014 Cisco ASA and FTD Information Disclosure Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-02-15",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-02-15"
    },
    {
      "value": "CVE-2024-21410",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1424",
          "title": "CISA KEV: CVE-2024-21410 \u2014 Microsoft Exchange Server Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-02-15",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-02-15"
    },
    {
      "value": "CVE-2024-21351",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1429",
          "title": "CISA KEV: CVE-2024-21351 \u2014 Microsoft Windows SmartScreen Security Feature Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-02-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-02-13"
    },
    {
      "value": "21centuryart.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1429",
          "title": "CISA KEV: CVE-2024-21351 \u2014 Microsoft Windows SmartScreen Security Feature Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-02-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-02-13"
    },
    {
      "value": "fxbulls.ru",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1429",
          "title": "CISA KEV: CVE-2024-21351 \u2014 Microsoft Windows SmartScreen Security Feature Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-02-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-02-13"
    },
    {
      "value": "CVE-2023-4762",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1434",
          "title": "CISA KEV: CVE-2023-4762 \u2014 Google Chromium V8 Type Confusion Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-02-06",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-02-06"
    },
    {
      "value": "CVE-2022-48618",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1436",
          "title": "CISA KEV: CVE-2022-48618 \u2014 Apple Multiple Products Memory Corruption Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-01-31",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-01-31"
    },
    {
      "value": "CVE-2024-21893",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1437",
          "title": "CISA KEV: CVE-2024-21893 \u2014 Ivanti Connect Secure, Policy Secure, and Neurons Server-Side Request Forgery (SSRF) Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-01-31",
          "sev": "crit"
        },
        {
          "id": "art-1454",
          "title": "CISA KEV: CVE-2023-46805 \u2014 Ivanti Connect Secure and Policy Secure Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-01-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-01-31"
    },
    {
      "value": "CVE-2023-22527",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1439",
          "title": "CISA KEV: CVE-2023-22527 \u2014 Atlassian Confluence Data Center and Server Template Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-01-24",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-01-24"
    },
    {
      "value": "103.228.162.76",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1439",
          "title": "CISA KEV: CVE-2023-22527 \u2014 Atlassian Confluence Data Center and Server Template Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-01-24",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-01-24"
    },
    {
      "value": "111.26.72.177",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1439",
          "title": "CISA KEV: CVE-2023-22527 \u2014 Atlassian Confluence Data Center and Server Template Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-01-24",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-01-24"
    },
    {
      "value": "114.242.99.122",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1439",
          "title": "CISA KEV: CVE-2023-22527 \u2014 Atlassian Confluence Data Center and Server Template Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-01-24",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-01-24"
    },
    {
      "value": "120.237.168.25",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1439",
          "title": "CISA KEV: CVE-2023-22527 \u2014 Atlassian Confluence Data Center and Server Template Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-01-24",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-01-24"
    },
    {
      "value": "125.76.87.134",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1439",
          "title": "CISA KEV: CVE-2023-22527 \u2014 Atlassian Confluence Data Center and Server Template Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-01-24",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-01-24"
    },
    {
      "value": "128.199.150.109",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1439",
          "title": "CISA KEV: CVE-2023-22527 \u2014 Atlassian Confluence Data Center and Server Template Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-01-24",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-01-24"
    },
    {
      "value": "14.225.53.158",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1439",
          "title": "CISA KEV: CVE-2023-22527 \u2014 Atlassian Confluence Data Center and Server Template Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-01-24",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-01-24"
    },
    {
      "value": "14.225.53.21",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1439",
          "title": "CISA KEV: CVE-2023-22527 \u2014 Atlassian Confluence Data Center and Server Template Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-01-24",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-01-24"
    },
    {
      "value": "14.225.53.68",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1439",
          "title": "CISA KEV: CVE-2023-22527 \u2014 Atlassian Confluence Data Center and Server Template Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-01-24",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-01-24"
    },
    {
      "value": "161.97.172.232",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1439",
          "title": "CISA KEV: CVE-2023-22527 \u2014 Atlassian Confluence Data Center and Server Template Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-01-24",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-01-24"
    },
    {
      "value": "177.185.117.136",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1439",
          "title": "CISA KEV: CVE-2023-22527 \u2014 Atlassian Confluence Data Center and Server Template Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-01-24",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-01-24"
    },
    {
      "value": "179.0.190.32",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1439",
          "title": "CISA KEV: CVE-2023-22527 \u2014 Atlassian Confluence Data Center and Server Template Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-01-24",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-01-24"
    },
    {
      "value": "183.196.214.38",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1439",
          "title": "CISA KEV: CVE-2023-22527 \u2014 Atlassian Confluence Data Center and Server Template Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-01-24",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-01-24"
    },
    {
      "value": "183.57.45.194",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1439",
          "title": "CISA KEV: CVE-2023-22527 \u2014 Atlassian Confluence Data Center and Server Template Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-01-24",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-01-24"
    },
    {
      "value": "193.29.12.182",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1439",
          "title": "CISA KEV: CVE-2023-22527 \u2014 Atlassian Confluence Data Center and Server Template Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-01-24",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-01-24"
    },
    {
      "value": "193.8.172.178",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1439",
          "title": "CISA KEV: CVE-2023-22527 \u2014 Atlassian Confluence Data Center and Server Template Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-01-24",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-01-24"
    },
    {
      "value": "194.113.236.177",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1439",
          "title": "CISA KEV: CVE-2023-22527 \u2014 Atlassian Confluence Data Center and Server Template Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-01-24",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-01-24"
    },
    {
      "value": "202.142.95.131",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1439",
          "title": "CISA KEV: CVE-2023-22527 \u2014 Atlassian Confluence Data Center and Server Template Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-01-24",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-01-24"
    },
    {
      "value": "217.112.83.246",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1439",
          "title": "CISA KEV: CVE-2023-22527 \u2014 Atlassian Confluence Data Center and Server Template Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-01-24",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-01-24"
    },
    {
      "value": "219.139.101.136",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1439",
          "title": "CISA KEV: CVE-2023-22527 \u2014 Atlassian Confluence Data Center and Server Template Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-01-24",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-01-24"
    },
    {
      "value": "222.216.206.99",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1439",
          "title": "CISA KEV: CVE-2023-22527 \u2014 Atlassian Confluence Data Center and Server Template Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-01-24",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-01-24"
    },
    {
      "value": "222.217.86.135",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1439",
          "title": "CISA KEV: CVE-2023-22527 \u2014 Atlassian Confluence Data Center and Server Template Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-01-24",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-01-24"
    },
    {
      "value": "39.103.211.146",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1439",
          "title": "CISA KEV: CVE-2023-22527 \u2014 Atlassian Confluence Data Center and Server Template Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-01-24",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-01-24"
    },
    {
      "value": "39.98.218.14",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1439",
          "title": "CISA KEV: CVE-2023-22527 \u2014 Atlassian Confluence Data Center and Server Template Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-01-24",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-01-24"
    },
    {
      "value": "47.236.124.26",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1439",
          "title": "CISA KEV: CVE-2023-22527 \u2014 Atlassian Confluence Data Center and Server Template Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-01-24",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-01-24"
    },
    {
      "value": "47.93.204.111",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1439",
          "title": "CISA KEV: CVE-2023-22527 \u2014 Atlassian Confluence Data Center and Server Template Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-01-24",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-01-24"
    },
    {
      "value": "49.232.119.187",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1439",
          "title": "CISA KEV: CVE-2023-22527 \u2014 Atlassian Confluence Data Center and Server Template Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-01-24",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-01-24"
    },
    {
      "value": "5.157.38.50",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1439",
          "title": "CISA KEV: CVE-2023-22527 \u2014 Atlassian Confluence Data Center and Server Template Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-01-24",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-01-24"
    },
    {
      "value": "60.235.233.170",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1439",
          "title": "CISA KEV: CVE-2023-22527 \u2014 Atlassian Confluence Data Center and Server Template Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-01-24",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-01-24"
    },
    {
      "value": "64.190.113.197",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1439",
          "title": "CISA KEV: CVE-2023-22527 \u2014 Atlassian Confluence Data Center and Server Template Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-01-24",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-01-24"
    },
    {
      "value": "CVE-2023-34048",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1443",
          "title": "CISA KEV: CVE-2023-34048 \u2014 VMware vCenter Server Out-of-Bounds Write Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-01-22",
          "sev": "crit"
        },
        {
          "id": "art-1693",
          "title": "CISA KEV: CVE-2023-20867 \u2014 VMware Tools Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-06-23",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-01-22"
    },
    {
      "value": "CVE-2023-35078",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1446",
          "title": "CISA KEV: CVE-2023-35082 \u2014 Ivanti Endpoint Manager Mobile (EPMM) and MobileIron Core Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-01-18",
          "sev": "crit"
        },
        {
          "id": "art-1625",
          "title": "CISA KEV: CVE-2023-38035 \u2014 Ivanti Sentry Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-08-22",
          "sev": "crit"
        },
        {
          "id": "art-1647",
          "title": "CISA KEV: CVE-2023-35081 \u2014 Ivanti Endpoint Manager Mobile (EPMM) Path Traversal Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-07-31",
          "sev": "crit"
        },
        {
          "id": "art-1653",
          "title": "CISA KEV: CVE-2023-35078 \u2014 Ivanti Endpoint Manager Mobile Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-07-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-01-18"
    },
    {
      "value": "CVE-2023-35081",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1446",
          "title": "CISA KEV: CVE-2023-35082 \u2014 Ivanti Endpoint Manager Mobile (EPMM) and MobileIron Core Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-01-18",
          "sev": "crit"
        },
        {
          "id": "art-1625",
          "title": "CISA KEV: CVE-2023-38035 \u2014 Ivanti Sentry Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-08-22",
          "sev": "crit"
        },
        {
          "id": "art-1647",
          "title": "CISA KEV: CVE-2023-35081 \u2014 Ivanti Endpoint Manager Mobile (EPMM) Path Traversal Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-07-31",
          "sev": "crit"
        },
        {
          "id": "art-1653",
          "title": "CISA KEV: CVE-2023-35078 \u2014 Ivanti Endpoint Manager Mobile Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-07-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-01-18"
    },
    {
      "value": "CVE-2023-35082",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1446",
          "title": "CISA KEV: CVE-2023-35082 \u2014 Ivanti Endpoint Manager Mobile (EPMM) and MobileIron Core Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-01-18",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-01-18"
    },
    {
      "value": "CVE-2024-22195",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-1445",
          "title": "Understanding and mitigating the Jinja2 XSS vulnerability (CVE-2024-22195)",
          "link": "https://snyk.io/blog/jinja2-xss-vulnerability/",
          "published": "2024-01-18",
          "sev": "high"
        }
      ],
      "first_seen": "2024-01-18"
    },
    {
      "value": "CVE-2023-6548",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1449",
          "title": "CISA KEV: CVE-2023-6548 \u2014 Citrix NetScaler ADC and NetScaler Gateway Code Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-01-17",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-01-17"
    },
    {
      "value": "CVE-2023-6549",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1448",
          "title": "CISA KEV: CVE-2023-6549 \u2014 Citrix NetScaler ADC and NetScaler Gateway Buffer Overflow Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-01-17",
          "sev": "crit"
        },
        {
          "id": "art-1449",
          "title": "CISA KEV: CVE-2023-6548 \u2014 Citrix NetScaler ADC and NetScaler Gateway Code Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-01-17",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-01-17"
    },
    {
      "value": "CVE-2024-0519",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1447",
          "title": "CISA KEV: CVE-2024-0519 \u2014 Google Chromium V8 Out-of-Bounds Memory Access Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-01-17",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-01-17"
    },
    {
      "value": "CVE-2018-15133",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1451",
          "title": "CISA KEV: CVE-2018-15133 \u2014 Laravel Deserialization of Untrusted Data Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-01-16",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-01-16"
    },
    {
      "value": "mc.rockylinux.si",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1451",
          "title": "CISA KEV: CVE-2018-15133 \u2014 Laravel Deserialization of Untrusted Data Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-01-16",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-01-16"
    },
    {
      "value": "CVE-2023-46805",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1454",
          "title": "CISA KEV: CVE-2023-46805 \u2014 Ivanti Connect Secure and Policy Secure Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-01-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-01-10"
    },
    {
      "value": "CVE-2024-21887",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1454",
          "title": "CISA KEV: CVE-2023-46805 \u2014 Ivanti Connect Secure and Policy Secure Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-01-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-01-10"
    },
    {
      "value": "CVE-2024-21888",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1454",
          "title": "CISA KEV: CVE-2023-46805 \u2014 Ivanti Connect Secure and Policy Secure Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-01-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-01-10"
    },
    {
      "value": "api.d-n-s.name",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1454",
          "title": "CISA KEV: CVE-2023-46805 \u2014 Ivanti Connect Secure and Policy Secure Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-01-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-01-10"
    },
    {
      "value": "areekaweb.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1454",
          "title": "CISA KEV: CVE-2023-46805 \u2014 Ivanti Connect Secure and Policy Secure Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-01-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-01-10"
    },
    {
      "value": "clickcom.click",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1454",
          "title": "CISA KEV: CVE-2023-46805 \u2014 Ivanti Connect Secure and Policy Secure Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-01-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-01-10"
    },
    {
      "value": "clicko.click",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1454",
          "title": "CISA KEV: CVE-2023-46805 \u2014 Ivanti Connect Secure and Policy Secure Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-01-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-01-10"
    },
    {
      "value": "cpanel.netbar.org",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1454",
          "title": "CISA KEV: CVE-2023-46805 \u2014 Ivanti Connect Secure and Policy Secure Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-01-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-01-10"
    },
    {
      "value": "duorhytm.fun",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1454",
          "title": "CISA KEV: CVE-2023-46805 \u2014 Ivanti Connect Secure and Policy Secure Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-01-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-01-10"
    },
    {
      "value": "ehangmun.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1454",
          "title": "CISA KEV: CVE-2023-46805 \u2014 Ivanti Connect Secure and Policy Secure Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-01-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-01-10"
    },
    {
      "value": "entraide-internationale.fr",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1454",
          "title": "CISA KEV: CVE-2023-46805 \u2014 Ivanti Connect Secure and Policy Secure Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-01-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-01-10"
    },
    {
      "value": "gpoaccess.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1454",
          "title": "CISA KEV: CVE-2023-46805 \u2014 Ivanti Connect Secure and Policy Secure Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-01-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-01-10"
    },
    {
      "value": "line-api.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1454",
          "title": "CISA KEV: CVE-2023-46805 \u2014 Ivanti Connect Secure and Policy Secure Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-01-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-01-10"
    },
    {
      "value": "miltonhouse.nl",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1454",
          "title": "CISA KEV: CVE-2023-46805 \u2014 Ivanti Connect Secure and Policy Secure Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-01-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-01-10"
    },
    {
      "value": "secure-cama.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1454",
          "title": "CISA KEV: CVE-2023-46805 \u2014 Ivanti Connect Secure and Policy Secure Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-01-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-01-10"
    },
    {
      "value": "symantke.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1454",
          "title": "CISA KEV: CVE-2023-46805 \u2014 Ivanti Connect Secure and Policy Secure Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-01-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-01-10"
    },
    {
      "value": "webb-institute.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1454",
          "title": "CISA KEV: CVE-2023-46805 \u2014 Ivanti Connect Secure and Policy Secure Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-01-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-01-10"
    },
    {
      "value": "146.0.228.66",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1454",
          "title": "CISA KEV: CVE-2023-46805 \u2014 Ivanti Connect Secure and Policy Secure Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-01-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-01-10"
    },
    {
      "value": "173.220.106.166",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1454",
          "title": "CISA KEV: CVE-2023-46805 \u2014 Ivanti Connect Secure and Policy Secure Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-01-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-01-10"
    },
    {
      "value": "173.53.43.7",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1454",
          "title": "CISA KEV: CVE-2023-46805 \u2014 Ivanti Connect Secure and Policy Secure Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-01-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-01-10"
    },
    {
      "value": "186.179.39.235",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1454",
          "title": "CISA KEV: CVE-2023-46805 \u2014 Ivanti Connect Secure and Policy Secure Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-01-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-01-10"
    },
    {
      "value": "206.189.208.156",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1454",
          "title": "CISA KEV: CVE-2023-46805 \u2014 Ivanti Connect Secure and Policy Secure Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-01-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-01-10"
    },
    {
      "value": "45.61.136.14",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1454",
          "title": "CISA KEV: CVE-2023-46805 \u2014 Ivanti Connect Secure and Policy Secure Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-01-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-01-10"
    },
    {
      "value": "47.207.9.89",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1454",
          "title": "CISA KEV: CVE-2023-46805 \u2014 Ivanti Connect Secure and Policy Secure Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-01-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-01-10"
    },
    {
      "value": "50.213.208.89",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1454",
          "title": "CISA KEV: CVE-2023-46805 \u2014 Ivanti Connect Secure and Policy Secure Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-01-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-01-10"
    },
    {
      "value": "50.215.39.49",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1454",
          "title": "CISA KEV: CVE-2023-46805 \u2014 Ivanti Connect Secure and Policy Secure Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-01-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-01-10"
    },
    {
      "value": "50.243.177.161",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1454",
          "title": "CISA KEV: CVE-2023-46805 \u2014 Ivanti Connect Secure and Policy Secure Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-01-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-01-10"
    },
    {
      "value": "64.24.179.210",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1454",
          "title": "CISA KEV: CVE-2023-46805 \u2014 Ivanti Connect Secure and Policy Secure Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-01-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-01-10"
    },
    {
      "value": "71.127.149.194",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1454",
          "title": "CISA KEV: CVE-2023-46805 \u2014 Ivanti Connect Secure and Policy Secure Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-01-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-01-10"
    },
    {
      "value": "73.128.178.221",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1454",
          "title": "CISA KEV: CVE-2023-46805 \u2014 Ivanti Connect Secure and Policy Secure Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-01-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-01-10"
    },
    {
      "value": "75.145.224.109",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1454",
          "title": "CISA KEV: CVE-2023-46805 \u2014 Ivanti Connect Secure and Policy Secure Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-01-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-01-10"
    },
    {
      "value": "75.145.243.85",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1454",
          "title": "CISA KEV: CVE-2023-46805 \u2014 Ivanti Connect Secure and Policy Secure Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-01-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-01-10"
    },
    {
      "value": "8.137.112.245",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1454",
          "title": "CISA KEV: CVE-2023-46805 \u2014 Ivanti Connect Secure and Policy Secure Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-01-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-01-10"
    },
    {
      "value": "91.92.254.14",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1454",
          "title": "CISA KEV: CVE-2023-46805 \u2014 Ivanti Connect Secure and Policy Secure Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-01-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-01-10"
    },
    {
      "value": "98.160.48.170",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1454",
          "title": "CISA KEV: CVE-2023-46805 \u2014 Ivanti Connect Secure and Policy Secure Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-01-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-01-10"
    },
    {
      "value": "2ec505088b942c234f39a37188e80d7a",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1454",
          "title": "CISA KEV: CVE-2023-46805 \u2014 Ivanti Connect Secure and Policy Secure Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-01-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-01-10"
    },
    {
      "value": "3045f5b3d355a9ab26ab6f44cc831a83",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1454",
          "title": "CISA KEV: CVE-2023-46805 \u2014 Ivanti Connect Secure and Policy Secure Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-01-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-01-10"
    },
    {
      "value": "3d97f55a03ceb4f71671aa2ecf5b24e9",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1454",
          "title": "CISA KEV: CVE-2023-46805 \u2014 Ivanti Connect Secure and Policy Secure Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-01-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-01-10"
    },
    {
      "value": "465600cece80861497e8c1c86a07a23e",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1454",
          "title": "CISA KEV: CVE-2023-46805 \u2014 Ivanti Connect Secure and Policy Secure Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-01-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-01-10"
    },
    {
      "value": "8eb042da6ba683ef1bae460af103cc44",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1454",
          "title": "CISA KEV: CVE-2023-46805 \u2014 Ivanti Connect Secure and Policy Secure Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-01-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-01-10"
    },
    {
      "value": "a739bd4c2b9f3679f43579711448786f",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1454",
          "title": "CISA KEV: CVE-2023-46805 \u2014 Ivanti Connect Secure and Policy Secure Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-01-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-01-10"
    },
    {
      "value": "a81813f70151a022ea1065b7f4d6b5ab",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1454",
          "title": "CISA KEV: CVE-2023-46805 \u2014 Ivanti Connect Secure and Policy Secure Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-01-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-01-10"
    },
    {
      "value": "d0c7a334a4d9dcd3c6335ae13bee59ea",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1454",
          "title": "CISA KEV: CVE-2023-46805 \u2014 Ivanti Connect Secure and Policy Secure Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-01-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-01-10"
    },
    {
      "value": "e8489983d73ed30a4240a14b1f161254",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1454",
          "title": "CISA KEV: CVE-2023-46805 \u2014 Ivanti Connect Secure and Policy Secure Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-01-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-01-10"
    },
    {
      "value": "CVE-2016-20017",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1457",
          "title": "CISA KEV: CVE-2016-20017 \u2014 D-Link DSL-2750B Devices Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-01-08",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-01-08"
    },
    {
      "value": "CVE-2023-23752",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1456",
          "title": "CISA KEV: CVE-2023-23752 \u2014 Joomla! Improper Access Control Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-01-08",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-01-08"
    },
    {
      "value": "CVE-2023-27524",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1459",
          "title": "CISA KEV: CVE-2023-27524 \u2014 Apache Superset Insecure Default Initialization of Resource Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-01-08",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-01-08"
    },
    {
      "value": "CVE-2023-32434",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1458",
          "title": "CISA KEV: CVE-2023-41990 \u2014 Apple Multiple Products Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-01-08",
          "sev": "crit"
        },
        {
          "id": "art-1652",
          "title": "CISA KEV: CVE-2023-38606 \u2014 Apple Multiple Products Kernel Unspecified Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-07-26",
          "sev": "crit"
        },
        {
          "id": "art-1690",
          "title": "CISA KEV: CVE-2023-32434 \u2014 Apple Multiple Products Integer Overflow Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-06-23",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-01-08"
    },
    {
      "value": "CVE-2023-32435",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1458",
          "title": "CISA KEV: CVE-2023-41990 \u2014 Apple Multiple Products Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-01-08",
          "sev": "crit"
        },
        {
          "id": "art-1652",
          "title": "CISA KEV: CVE-2023-38606 \u2014 Apple Multiple Products Kernel Unspecified Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-07-26",
          "sev": "crit"
        },
        {
          "id": "art-1690",
          "title": "CISA KEV: CVE-2023-32434 \u2014 Apple Multiple Products Integer Overflow Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-06-23",
          "sev": "crit"
        },
        {
          "id": "art-1691",
          "title": "CISA KEV: CVE-2023-32435 \u2014 Apple Multiple Products WebKit Memory Corruption Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-06-23",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-01-08"
    },
    {
      "value": "CVE-2023-38606",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1458",
          "title": "CISA KEV: CVE-2023-41990 \u2014 Apple Multiple Products Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-01-08",
          "sev": "crit"
        },
        {
          "id": "art-1652",
          "title": "CISA KEV: CVE-2023-38606 \u2014 Apple Multiple Products Kernel Unspecified Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-07-26",
          "sev": "crit"
        },
        {
          "id": "art-1690",
          "title": "CISA KEV: CVE-2023-32434 \u2014 Apple Multiple Products Integer Overflow Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-06-23",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-01-08"
    },
    {
      "value": "CVE-2023-41990",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1458",
          "title": "CISA KEV: CVE-2023-41990 \u2014 Apple Multiple Products Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-01-08",
          "sev": "crit"
        },
        {
          "id": "art-1652",
          "title": "CISA KEV: CVE-2023-38606 \u2014 Apple Multiple Products Kernel Unspecified Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-07-26",
          "sev": "crit"
        },
        {
          "id": "art-1690",
          "title": "CISA KEV: CVE-2023-32434 \u2014 Apple Multiple Products Integer Overflow Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-06-23",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-01-08"
    },
    {
      "value": "h4ck4fun.xyz",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1461",
          "title": "CISA KEV: CVE-2023-38203 \u2014 Adobe ColdFusion Deserialization of Untrusted Data Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-01-08",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-01-08"
    },
    {
      "value": "mooo-ng.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1461",
          "title": "CISA KEV: CVE-2023-38203 \u2014 Adobe ColdFusion Deserialization of Untrusted Data Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-01-08",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-01-08"
    },
    {
      "value": "redteam.tf",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1461",
          "title": "CISA KEV: CVE-2023-38203 \u2014 Adobe ColdFusion Deserialization of Untrusted Data Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-01-08",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-01-08"
    },
    {
      "value": "103.255.177.55",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1461",
          "title": "CISA KEV: CVE-2023-38203 \u2014 Adobe ColdFusion Deserialization of Untrusted Data Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-01-08",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-01-08"
    },
    {
      "value": "113.141.91.61",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1460",
          "title": "CISA KEV: CVE-2023-29300 \u2014 Adobe ColdFusion Deserialization of Untrusted Data Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-01-08",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-01-08"
    },
    {
      "value": "81.68.197.3",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1461",
          "title": "CISA KEV: CVE-2023-38203 \u2014 Adobe ColdFusion Deserialization of Untrusted Data Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-01-08",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-01-08"
    },
    {
      "value": "81.68.214.122",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1461",
          "title": "CISA KEV: CVE-2023-38203 \u2014 Adobe ColdFusion Deserialization of Untrusted Data Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-01-08",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-01-08"
    },
    {
      "value": "82.156.147.183",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1461",
          "title": "CISA KEV: CVE-2023-38203 \u2014 Adobe ColdFusion Deserialization of Untrusted Data Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-01-08",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-01-08"
    },
    {
      "value": "4f22fea4d0fadd2e01139021f98f04d3cae678e6526feb61fa8a6eceda13296a",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1461",
          "title": "CISA KEV: CVE-2023-38203 \u2014 Adobe ColdFusion Deserialization of Untrusted Data Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-01-08",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-01-08"
    },
    {
      "value": "590d3088ed566cb3d85d48f4914cc657ee49b7d33e85c72167e7c72d81d4cb6c",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1461",
          "title": "CISA KEV: CVE-2023-38203 \u2014 Adobe ColdFusion Deserialization of Untrusted Data Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-01-08",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-01-08"
    },
    {
      "value": "7c6f0bae1e588821bd5d66cd98f52b7005e054279748c2c851647097fa2ae2df",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1461",
          "title": "CISA KEV: CVE-2023-38203 \u2014 Adobe ColdFusion Deserialization of Untrusted Data Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-01-08",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-01-08"
    },
    {
      "value": "808f0f85aee6be3d3f3dd4bb827f556401c4d69a642ba4b1cb3645368954622e",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1461",
          "title": "CISA KEV: CVE-2023-38203 \u2014 Adobe ColdFusion Deserialization of Untrusted Data Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-01-08",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-01-08"
    },
    {
      "value": "cb493680d1a8ee7a70a2d339ece0b190db02fba4ba6af3b2c26a6b4841902d52",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1460",
          "title": "CISA KEV: CVE-2023-29300 \u2014 Adobe ColdFusion Deserialization of Untrusted Data Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-01-08",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-01-08"
    },
    {
      "value": "d6910571564cc4c61b1277334701c612fd3a25b96b63b267d64fcf48a5998254",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1460",
          "title": "CISA KEV: CVE-2023-29300 \u2014 Adobe ColdFusion Deserialization of Untrusted Data Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-01-08",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-01-08"
    },
    {
      "value": "CVE-2023-2868",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1465",
          "title": "CISA KEV: CVE-2023-7101 \u2014 Spreadsheet::ParseExcel Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-01-02",
          "sev": "crit"
        },
        {
          "id": "art-1730",
          "title": "CISA KEV: CVE-2023-2868 \u2014 Barracuda Networks ESG Appliance Improper Input Validation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-05-26",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-01-02"
    },
    {
      "value": "CVE-2023-50164",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-1464",
          "title": "Krampus delivers an end-of-year Struts vulnerability",
          "link": "https://snyk.io/blog/struts-path-traversal-vulnerability/",
          "published": "2024-01-02",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-01-02"
    },
    {
      "value": "CVE-2023-7024",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1466",
          "title": "CISA KEV: CVE-2023-7024 \u2014 Google Chromium WebRTC Heap Buffer Overflow Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-01-02",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-01-02"
    },
    {
      "value": "CVE-2023-7101",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1465",
          "title": "CISA KEV: CVE-2023-7101 \u2014 Spreadsheet::ParseExcel Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-01-02",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-01-02"
    },
    {
      "value": "CVE-2023-7102",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1465",
          "title": "CISA KEV: CVE-2023-7101 \u2014 Spreadsheet::ParseExcel Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-01-02",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-01-02"
    },
    {
      "value": "bestfindthetruth.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1465",
          "title": "CISA KEV: CVE-2023-7101 \u2014 Spreadsheet::ParseExcel Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-01-02",
          "sev": "crit"
        },
        {
          "id": "art-1730",
          "title": "CISA KEV: CVE-2023-2868 \u2014 Barracuda Networks ESG Appliance Improper Input Validation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-05-26",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-01-02"
    },
    {
      "value": "fessionalwork.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1465",
          "title": "CISA KEV: CVE-2023-7101 \u2014 Spreadsheet::ParseExcel Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-01-02",
          "sev": "crit"
        },
        {
          "id": "art-1730",
          "title": "CISA KEV: CVE-2023-2868 \u2014 Barracuda Networks ESG Appliance Improper Input Validation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-05-26",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-01-02"
    },
    {
      "value": "gesturefavour.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1465",
          "title": "CISA KEV: CVE-2023-7101 \u2014 Spreadsheet::ParseExcel Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-01-02",
          "sev": "crit"
        },
        {
          "id": "art-1730",
          "title": "CISA KEV: CVE-2023-2868 \u2014 Barracuda Networks ESG Appliance Improper Input Validation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-05-26",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-01-02"
    },
    {
      "value": "goldenunder.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1465",
          "title": "CISA KEV: CVE-2023-7101 \u2014 Spreadsheet::ParseExcel Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-01-02",
          "sev": "crit"
        },
        {
          "id": "art-1730",
          "title": "CISA KEV: CVE-2023-2868 \u2014 Barracuda Networks ESG Appliance Improper Input Validation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-05-26",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-01-02"
    },
    {
      "value": "singamofing.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1465",
          "title": "CISA KEV: CVE-2023-7101 \u2014 Spreadsheet::ParseExcel Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-01-02",
          "sev": "crit"
        },
        {
          "id": "art-1730",
          "title": "CISA KEV: CVE-2023-2868 \u2014 Barracuda Networks ESG Appliance Improper Input Validation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-05-26",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-01-02"
    },
    {
      "value": "singnode.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1465",
          "title": "CISA KEV: CVE-2023-7101 \u2014 Spreadsheet::ParseExcel Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-01-02",
          "sev": "crit"
        },
        {
          "id": "art-1730",
          "title": "CISA KEV: CVE-2023-2868 \u2014 Barracuda Networks ESG Appliance Improper Input Validation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-05-26",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-01-02"
    },
    {
      "value": "togetheroffway.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1465",
          "title": "CISA KEV: CVE-2023-7101 \u2014 Spreadsheet::ParseExcel Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-01-02",
          "sev": "crit"
        },
        {
          "id": "art-1730",
          "title": "CISA KEV: CVE-2023-2868 \u2014 Barracuda Networks ESG Appliance Improper Input Validation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-05-26",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-01-02"
    },
    {
      "value": "troublendsef.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1465",
          "title": "CISA KEV: CVE-2023-7101 \u2014 Spreadsheet::ParseExcel Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-01-02",
          "sev": "crit"
        },
        {
          "id": "art-1730",
          "title": "CISA KEV: CVE-2023-2868 \u2014 Barracuda Networks ESG Appliance Improper Input Validation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-05-26",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-01-02"
    },
    {
      "value": "107.148.41.146",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1465",
          "title": "CISA KEV: CVE-2023-7101 \u2014 Spreadsheet::ParseExcel Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-01-02",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-01-02"
    },
    {
      "value": "23.224.99.242",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1465",
          "title": "CISA KEV: CVE-2023-7101 \u2014 Spreadsheet::ParseExcel Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-01-02",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-01-02"
    },
    {
      "value": "23.224.99.243",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1465",
          "title": "CISA KEV: CVE-2023-7101 \u2014 Spreadsheet::ParseExcel Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-01-02",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-01-02"
    },
    {
      "value": "23.224.99.244",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1465",
          "title": "CISA KEV: CVE-2023-7101 \u2014 Spreadsheet::ParseExcel Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-01-02",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-01-02"
    },
    {
      "value": "23.224.99.245",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1465",
          "title": "CISA KEV: CVE-2023-7101 \u2014 Spreadsheet::ParseExcel Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-01-02",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-01-02"
    },
    {
      "value": "23.224.99.246",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1465",
          "title": "CISA KEV: CVE-2023-7101 \u2014 Spreadsheet::ParseExcel Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-01-02",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-01-02"
    },
    {
      "value": "23.225.35.234",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1465",
          "title": "CISA KEV: CVE-2023-7101 \u2014 Spreadsheet::ParseExcel Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-01-02",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-01-02"
    },
    {
      "value": "23.225.35.235",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1465",
          "title": "CISA KEV: CVE-2023-7101 \u2014 Spreadsheet::ParseExcel Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-01-02",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-01-02"
    },
    {
      "value": "23.225.35.236",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1465",
          "title": "CISA KEV: CVE-2023-7101 \u2014 Spreadsheet::ParseExcel Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-01-02",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-01-02"
    },
    {
      "value": "23.225.35.237",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1465",
          "title": "CISA KEV: CVE-2023-7101 \u2014 Spreadsheet::ParseExcel Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-01-02",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-01-02"
    },
    {
      "value": "23.225.35.238",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1465",
          "title": "CISA KEV: CVE-2023-7101 \u2014 Spreadsheet::ParseExcel Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-01-02",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-01-02"
    },
    {
      "value": "2b172fe3329260611a9022e71acdebca",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1465",
          "title": "CISA KEV: CVE-2023-7101 \u2014 Spreadsheet::ParseExcel Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-01-02",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-01-02"
    },
    {
      "value": "7b83e4bd880bb9d7904e8f553c2736e3",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1465",
          "title": "CISA KEV: CVE-2023-7101 \u2014 Spreadsheet::ParseExcel Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-01-02",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-01-02"
    },
    {
      "value": "d493aab1319f10c633f6d223da232a27",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1465",
          "title": "CISA KEV: CVE-2023-7101 \u2014 Spreadsheet::ParseExcel Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-01-02",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-01-02"
    },
    {
      "value": "e7842edc7868c8c5cf0480dd98bcfe76",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1465",
          "title": "CISA KEV: CVE-2023-7101 \u2014 Spreadsheet::ParseExcel Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-01-02",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-01-02"
    },
    {
      "value": "118fad9e1f03b8b1abe00529c61dc3edfda043b787c9084180d83535b4d177b7",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1465",
          "title": "CISA KEV: CVE-2023-7101 \u2014 Spreadsheet::ParseExcel Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-01-02",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-01-02"
    },
    {
      "value": "34494ecb02a1cccadda1c7693c45666e1fe3928cc83576f8f07380801b07d8ba",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1465",
          "title": "CISA KEV: CVE-2023-7101 \u2014 Spreadsheet::ParseExcel Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-01-02",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-01-02"
    },
    {
      "value": "803cb5a7de1fe0067a9eeb220dfc24ca56f3f571a986180e146b6cf387855bdd",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1465",
          "title": "CISA KEV: CVE-2023-7101 \u2014 Spreadsheet::ParseExcel Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-01-02",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-01-02"
    },
    {
      "value": "952c5f45d203d8f1a7532e5b59af8e3306b5c1c53a30624b6733e0176d8d1acd",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1465",
          "title": "CISA KEV: CVE-2023-7101 \u2014 Spreadsheet::ParseExcel Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2024-01-02",
          "sev": "crit"
        }
      ],
      "first_seen": "2024-01-02"
    },
    {
      "value": "CVE-2023-47565",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1470",
          "title": "CISA KEV: CVE-2023-49897 \u2014 FXC AE1021, AE1021PE OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-12-21",
          "sev": "crit"
        },
        {
          "id": "art-1471",
          "title": "CISA KEV: CVE-2023-47565 \u2014 QNAP VioStor NVR OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-12-21",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-12-21"
    },
    {
      "value": "CVE-2023-49897",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1470",
          "title": "CISA KEV: CVE-2023-49897 \u2014 FXC AE1021, AE1021PE OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-12-21",
          "sev": "crit"
        },
        {
          "id": "art-1471",
          "title": "CISA KEV: CVE-2023-47565 \u2014 QNAP VioStor NVR OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-12-21",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-12-21"
    },
    {
      "value": "chinkona.buzz",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1471",
          "title": "CISA KEV: CVE-2023-47565 \u2014 QNAP VioStor NVR OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-12-21",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-12-21"
    },
    {
      "value": "dfvzfvd.help",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1470",
          "title": "CISA KEV: CVE-2023-49897 \u2014 FXC AE1021, AE1021PE OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-12-21",
          "sev": "crit"
        },
        {
          "id": "art-1471",
          "title": "CISA KEV: CVE-2023-47565 \u2014 QNAP VioStor NVR OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-12-21",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-12-21"
    },
    {
      "value": "dogeating.monster",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1471",
          "title": "CISA KEV: CVE-2023-47565 \u2014 QNAP VioStor NVR OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-12-21",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-12-21"
    },
    {
      "value": "dogeatingchink.uno",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1470",
          "title": "CISA KEV: CVE-2023-49897 \u2014 FXC AE1021, AE1021PE OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-12-21",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-12-21"
    },
    {
      "value": "homehitter.tk",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1470",
          "title": "CISA KEV: CVE-2023-49897 \u2014 FXC AE1021, AE1021PE OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-12-21",
          "sev": "crit"
        },
        {
          "id": "art-1471",
          "title": "CISA KEV: CVE-2023-47565 \u2014 QNAP VioStor NVR OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-12-21",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-12-21"
    },
    {
      "value": "hujunxa.cc",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1471",
          "title": "CISA KEV: CVE-2023-47565 \u2014 QNAP VioStor NVR OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-12-21",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-12-21"
    },
    {
      "value": "husd8uasd9.online",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1470",
          "title": "CISA KEV: CVE-2023-49897 \u2014 FXC AE1021, AE1021PE OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-12-21",
          "sev": "crit"
        },
        {
          "id": "art-1471",
          "title": "CISA KEV: CVE-2023-47565 \u2014 QNAP VioStor NVR OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-12-21",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-12-21"
    },
    {
      "value": "iaxtpa.parody",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1471",
          "title": "CISA KEV: CVE-2023-47565 \u2014 QNAP VioStor NVR OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-12-21",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-12-21"
    },
    {
      "value": "infectedchink.cat",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1470",
          "title": "CISA KEV: CVE-2023-49897 \u2014 FXC AE1021, AE1021PE OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-12-21",
          "sev": "crit"
        },
        {
          "id": "art-1471",
          "title": "CISA KEV: CVE-2023-47565 \u2014 QNAP VioStor NVR OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-12-21",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-12-21"
    },
    {
      "value": "infectedchink.online",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1470",
          "title": "CISA KEV: CVE-2023-49897 \u2014 FXC AE1021, AE1021PE OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-12-21",
          "sev": "crit"
        },
        {
          "id": "art-1471",
          "title": "CISA KEV: CVE-2023-47565 \u2014 QNAP VioStor NVR OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-12-21",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-12-21"
    },
    {
      "value": "opewu.homes",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1470",
          "title": "CISA KEV: CVE-2023-49897 \u2014 FXC AE1021, AE1021PE OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-12-21",
          "sev": "crit"
        },
        {
          "id": "art-1471",
          "title": "CISA KEV: CVE-2023-47565 \u2014 QNAP VioStor NVR OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-12-21",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-12-21"
    },
    {
      "value": "pqahzam.ink",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1470",
          "title": "CISA KEV: CVE-2023-49897 \u2014 FXC AE1021, AE1021PE OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-12-21",
          "sev": "crit"
        },
        {
          "id": "art-1471",
          "title": "CISA KEV: CVE-2023-47565 \u2014 QNAP VioStor NVR OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-12-21",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-12-21"
    },
    {
      "value": "skid.uno",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1471",
          "title": "CISA KEV: CVE-2023-47565 \u2014 QNAP VioStor NVR OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-12-21",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-12-21"
    },
    {
      "value": "wu.qwewu.site",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1470",
          "title": "CISA KEV: CVE-2023-49897 \u2014 FXC AE1021, AE1021PE OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-12-21",
          "sev": "crit"
        },
        {
          "id": "art-1471",
          "title": "CISA KEV: CVE-2023-47565 \u2014 QNAP VioStor NVR OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-12-21",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-12-21"
    },
    {
      "value": "162.220.166.114",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1470",
          "title": "CISA KEV: CVE-2023-49897 \u2014 FXC AE1021, AE1021PE OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-12-21",
          "sev": "crit"
        },
        {
          "id": "art-1471",
          "title": "CISA KEV: CVE-2023-47565 \u2014 QNAP VioStor NVR OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-12-21",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-12-21"
    },
    {
      "value": "162.246.20.236",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1470",
          "title": "CISA KEV: CVE-2023-49897 \u2014 FXC AE1021, AE1021PE OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-12-21",
          "sev": "crit"
        },
        {
          "id": "art-1471",
          "title": "CISA KEV: CVE-2023-47565 \u2014 QNAP VioStor NVR OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-12-21",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-12-21"
    },
    {
      "value": "185.150.26.226",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1470",
          "title": "CISA KEV: CVE-2023-49897 \u2014 FXC AE1021, AE1021PE OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-12-21",
          "sev": "crit"
        },
        {
          "id": "art-1471",
          "title": "CISA KEV: CVE-2023-47565 \u2014 QNAP VioStor NVR OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-12-21",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-12-21"
    },
    {
      "value": "185.225.74.161",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1470",
          "title": "CISA KEV: CVE-2023-49897 \u2014 FXC AE1021, AE1021PE OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-12-21",
          "sev": "crit"
        },
        {
          "id": "art-1471",
          "title": "CISA KEV: CVE-2023-47565 \u2014 QNAP VioStor NVR OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-12-21",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-12-21"
    },
    {
      "value": "194.153.216.164",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1470",
          "title": "CISA KEV: CVE-2023-49897 \u2014 FXC AE1021, AE1021PE OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-12-21",
          "sev": "crit"
        },
        {
          "id": "art-1471",
          "title": "CISA KEV: CVE-2023-47565 \u2014 QNAP VioStor NVR OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-12-21",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-12-21"
    },
    {
      "value": "194.180.48.202",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1470",
          "title": "CISA KEV: CVE-2023-49897 \u2014 FXC AE1021, AE1021PE OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-12-21",
          "sev": "crit"
        },
        {
          "id": "art-1471",
          "title": "CISA KEV: CVE-2023-47565 \u2014 QNAP VioStor NVR OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-12-21",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-12-21"
    },
    {
      "value": "194.38.21.42",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1470",
          "title": "CISA KEV: CVE-2023-49897 \u2014 FXC AE1021, AE1021PE OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-12-21",
          "sev": "crit"
        },
        {
          "id": "art-1471",
          "title": "CISA KEV: CVE-2023-47565 \u2014 QNAP VioStor NVR OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-12-21",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-12-21"
    },
    {
      "value": "45.139.105.145",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1470",
          "title": "CISA KEV: CVE-2023-49897 \u2014 FXC AE1021, AE1021PE OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-12-21",
          "sev": "crit"
        },
        {
          "id": "art-1471",
          "title": "CISA KEV: CVE-2023-47565 \u2014 QNAP VioStor NVR OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-12-21",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-12-21"
    },
    {
      "value": "45.142.182.96",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1470",
          "title": "CISA KEV: CVE-2023-49897 \u2014 FXC AE1021, AE1021PE OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-12-21",
          "sev": "crit"
        },
        {
          "id": "art-1471",
          "title": "CISA KEV: CVE-2023-47565 \u2014 QNAP VioStor NVR OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-12-21",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-12-21"
    },
    {
      "value": "45.95.147.226",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1470",
          "title": "CISA KEV: CVE-2023-49897 \u2014 FXC AE1021, AE1021PE OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-12-21",
          "sev": "crit"
        },
        {
          "id": "art-1471",
          "title": "CISA KEV: CVE-2023-47565 \u2014 QNAP VioStor NVR OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-12-21",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-12-21"
    },
    {
      "value": "5.181.80.102",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1470",
          "title": "CISA KEV: CVE-2023-49897 \u2014 FXC AE1021, AE1021PE OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-12-21",
          "sev": "crit"
        },
        {
          "id": "art-1471",
          "title": "CISA KEV: CVE-2023-47565 \u2014 QNAP VioStor NVR OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-12-21",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-12-21"
    },
    {
      "value": "5.181.80.126",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1470",
          "title": "CISA KEV: CVE-2023-49897 \u2014 FXC AE1021, AE1021PE OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-12-21",
          "sev": "crit"
        },
        {
          "id": "art-1471",
          "title": "CISA KEV: CVE-2023-47565 \u2014 QNAP VioStor NVR OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-12-21",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-12-21"
    },
    {
      "value": "5.181.80.127",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1470",
          "title": "CISA KEV: CVE-2023-49897 \u2014 FXC AE1021, AE1021PE OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-12-21",
          "sev": "crit"
        },
        {
          "id": "art-1471",
          "title": "CISA KEV: CVE-2023-47565 \u2014 QNAP VioStor NVR OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-12-21",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-12-21"
    },
    {
      "value": "5.181.80.53",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1470",
          "title": "CISA KEV: CVE-2023-49897 \u2014 FXC AE1021, AE1021PE OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-12-21",
          "sev": "crit"
        },
        {
          "id": "art-1471",
          "title": "CISA KEV: CVE-2023-47565 \u2014 QNAP VioStor NVR OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-12-21",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-12-21"
    },
    {
      "value": "5.181.80.54",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1470",
          "title": "CISA KEV: CVE-2023-49897 \u2014 FXC AE1021, AE1021PE OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-12-21",
          "sev": "crit"
        },
        {
          "id": "art-1471",
          "title": "CISA KEV: CVE-2023-47565 \u2014 QNAP VioStor NVR OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-12-21",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-12-21"
    },
    {
      "value": "5.181.80.55",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1470",
          "title": "CISA KEV: CVE-2023-49897 \u2014 FXC AE1021, AE1021PE OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-12-21",
          "sev": "crit"
        },
        {
          "id": "art-1471",
          "title": "CISA KEV: CVE-2023-47565 \u2014 QNAP VioStor NVR OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-12-21",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-12-21"
    },
    {
      "value": "5.181.80.59",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1470",
          "title": "CISA KEV: CVE-2023-49897 \u2014 FXC AE1021, AE1021PE OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-12-21",
          "sev": "crit"
        },
        {
          "id": "art-1471",
          "title": "CISA KEV: CVE-2023-47565 \u2014 QNAP VioStor NVR OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-12-21",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-12-21"
    },
    {
      "value": "5.181.80.72",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1470",
          "title": "CISA KEV: CVE-2023-49897 \u2014 FXC AE1021, AE1021PE OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-12-21",
          "sev": "crit"
        },
        {
          "id": "art-1471",
          "title": "CISA KEV: CVE-2023-47565 \u2014 QNAP VioStor NVR OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-12-21",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-12-21"
    },
    {
      "value": "5.181.80.77",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1470",
          "title": "CISA KEV: CVE-2023-49897 \u2014 FXC AE1021, AE1021PE OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-12-21",
          "sev": "crit"
        },
        {
          "id": "art-1471",
          "title": "CISA KEV: CVE-2023-47565 \u2014 QNAP VioStor NVR OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-12-21",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-12-21"
    },
    {
      "value": "5.181.80.81",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1470",
          "title": "CISA KEV: CVE-2023-49897 \u2014 FXC AE1021, AE1021PE OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-12-21",
          "sev": "crit"
        },
        {
          "id": "art-1471",
          "title": "CISA KEV: CVE-2023-47565 \u2014 QNAP VioStor NVR OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-12-21",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-12-21"
    },
    {
      "value": "62.113.113.168",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1470",
          "title": "CISA KEV: CVE-2023-49897 \u2014 FXC AE1021, AE1021PE OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-12-21",
          "sev": "crit"
        },
        {
          "id": "art-1471",
          "title": "CISA KEV: CVE-2023-47565 \u2014 QNAP VioStor NVR OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-12-21",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-12-21"
    },
    {
      "value": "85.217.144.207",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1470",
          "title": "CISA KEV: CVE-2023-49897 \u2014 FXC AE1021, AE1021PE OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-12-21",
          "sev": "crit"
        },
        {
          "id": "art-1471",
          "title": "CISA KEV: CVE-2023-47565 \u2014 QNAP VioStor NVR OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-12-21",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-12-21"
    },
    {
      "value": "89.190.156.145",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1470",
          "title": "CISA KEV: CVE-2023-49897 \u2014 FXC AE1021, AE1021PE OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-12-21",
          "sev": "crit"
        },
        {
          "id": "art-1471",
          "title": "CISA KEV: CVE-2023-47565 \u2014 QNAP VioStor NVR OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-12-21",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-12-21"
    },
    {
      "value": "91.92.254.4",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1470",
          "title": "CISA KEV: CVE-2023-49897 \u2014 FXC AE1021, AE1021PE OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-12-21",
          "sev": "crit"
        },
        {
          "id": "art-1471",
          "title": "CISA KEV: CVE-2023-47565 \u2014 QNAP VioStor NVR OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-12-21",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-12-21"
    },
    {
      "value": "95.214.27.10",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1470",
          "title": "CISA KEV: CVE-2023-49897 \u2014 FXC AE1021, AE1021PE OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-12-21",
          "sev": "crit"
        },
        {
          "id": "art-1471",
          "title": "CISA KEV: CVE-2023-47565 \u2014 QNAP VioStor NVR OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-12-21",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-12-21"
    },
    {
      "value": "29f11b5d4dbd6d06d4906b9035f5787e16f9e23134a2cc43dfc1165127c89bff",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1470",
          "title": "CISA KEV: CVE-2023-49897 \u2014 FXC AE1021, AE1021PE OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-12-21",
          "sev": "crit"
        },
        {
          "id": "art-1471",
          "title": "CISA KEV: CVE-2023-47565 \u2014 QNAP VioStor NVR OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-12-21",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-12-21"
    },
    {
      "value": "35fcc2058ae3a0af68c5ed7452e57ff286abe6ded68bf59078abd9e7b11ea90a",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1470",
          "title": "CISA KEV: CVE-2023-49897 \u2014 FXC AE1021, AE1021PE OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-12-21",
          "sev": "crit"
        },
        {
          "id": "art-1471",
          "title": "CISA KEV: CVE-2023-47565 \u2014 QNAP VioStor NVR OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-12-21",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-12-21"
    },
    {
      "value": "3f3c2e779f8e3d7f2cc81536ef72d96dd1c7b7691b6e613f5f76c3d02909edd8",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1470",
          "title": "CISA KEV: CVE-2023-49897 \u2014 FXC AE1021, AE1021PE OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-12-21",
          "sev": "crit"
        },
        {
          "id": "art-1471",
          "title": "CISA KEV: CVE-2023-47565 \u2014 QNAP VioStor NVR OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-12-21",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-12-21"
    },
    {
      "value": "75ef686859010d6164bcd6a4d6cf8a590754ccc3ea45c47ace420b02649ec380",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1470",
          "title": "CISA KEV: CVE-2023-49897 \u2014 FXC AE1021, AE1021PE OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-12-21",
          "sev": "crit"
        },
        {
          "id": "art-1471",
          "title": "CISA KEV: CVE-2023-47565 \u2014 QNAP VioStor NVR OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-12-21",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-12-21"
    },
    {
      "value": "7cc62a1bb2db82e76183eb06e4ca84e07a78cfb71241f21212afd1e01cb308b2",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1470",
          "title": "CISA KEV: CVE-2023-49897 \u2014 FXC AE1021, AE1021PE OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-12-21",
          "sev": "crit"
        },
        {
          "id": "art-1471",
          "title": "CISA KEV: CVE-2023-47565 \u2014 QNAP VioStor NVR OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-12-21",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-12-21"
    },
    {
      "value": "8777f9af3564b109b43cbcf1fd1a24180f5cf424965050594ce73d754a4e1099",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1470",
          "title": "CISA KEV: CVE-2023-49897 \u2014 FXC AE1021, AE1021PE OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-12-21",
          "sev": "crit"
        },
        {
          "id": "art-1471",
          "title": "CISA KEV: CVE-2023-47565 \u2014 QNAP VioStor NVR OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-12-21",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-12-21"
    },
    {
      "value": "8e64de3ac6818b4271d3de5d8e4a5d166d13d12804da01ce1cdb7510d8922cc6",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1470",
          "title": "CISA KEV: CVE-2023-49897 \u2014 FXC AE1021, AE1021PE OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-12-21",
          "sev": "crit"
        },
        {
          "id": "art-1471",
          "title": "CISA KEV: CVE-2023-47565 \u2014 QNAP VioStor NVR OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-12-21",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-12-21"
    },
    {
      "value": "a3b78818bbef4fd55f704c96c203765b5ab37723bc87aac6aa7ebfcc76dfa06d",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1470",
          "title": "CISA KEV: CVE-2023-49897 \u2014 FXC AE1021, AE1021PE OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-12-21",
          "sev": "crit"
        },
        {
          "id": "art-1471",
          "title": "CISA KEV: CVE-2023-47565 \u2014 QNAP VioStor NVR OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-12-21",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-12-21"
    },
    {
      "value": "a4975366f0c5b5b52fb371ff2cb034006955b3e3ae064e5700cc5365f27a1d26",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1470",
          "title": "CISA KEV: CVE-2023-49897 \u2014 FXC AE1021, AE1021PE OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-12-21",
          "sev": "crit"
        },
        {
          "id": "art-1471",
          "title": "CISA KEV: CVE-2023-47565 \u2014 QNAP VioStor NVR OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-12-21",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-12-21"
    },
    {
      "value": "ac43c52b42b123e2530538273dfb12e3b70178aa1dee6d4fd5198c08bfeb4dc1",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1470",
          "title": "CISA KEV: CVE-2023-49897 \u2014 FXC AE1021, AE1021PE OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-12-21",
          "sev": "crit"
        },
        {
          "id": "art-1471",
          "title": "CISA KEV: CVE-2023-47565 \u2014 QNAP VioStor NVR OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-12-21",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-12-21"
    },
    {
      "value": "cd93264637cd3bf19b706afc19944dfb88cd27969aaf0077559e56842d9a0f87",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1470",
          "title": "CISA KEV: CVE-2023-49897 \u2014 FXC AE1021, AE1021PE OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-12-21",
          "sev": "crit"
        },
        {
          "id": "art-1471",
          "title": "CISA KEV: CVE-2023-47565 \u2014 QNAP VioStor NVR OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-12-21",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-12-21"
    },
    {
      "value": "cfbcbb876064c2cf671bdae61544649fa13debbbe58b72cf8c630b5bfc0649f9",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1470",
          "title": "CISA KEV: CVE-2023-49897 \u2014 FXC AE1021, AE1021PE OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-12-21",
          "sev": "crit"
        },
        {
          "id": "art-1471",
          "title": "CISA KEV: CVE-2023-47565 \u2014 QNAP VioStor NVR OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-12-21",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-12-21"
    },
    {
      "value": "dabdd4b5a3a70c64c031126fad36a4c45feb69a45e1028d79da6b443291addb8",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1470",
          "title": "CISA KEV: CVE-2023-49897 \u2014 FXC AE1021, AE1021PE OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-12-21",
          "sev": "crit"
        },
        {
          "id": "art-1471",
          "title": "CISA KEV: CVE-2023-47565 \u2014 QNAP VioStor NVR OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-12-21",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-12-21"
    },
    {
      "value": "f8abf9fb17f59cbd7381aa9f5f2e1952628897cee368defd6baa6885d74f3ecc",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1470",
          "title": "CISA KEV: CVE-2023-49897 \u2014 FXC AE1021, AE1021PE OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-12-21",
          "sev": "crit"
        },
        {
          "id": "art-1471",
          "title": "CISA KEV: CVE-2023-47565 \u2014 QNAP VioStor NVR OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-12-21",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-12-21"
    },
    {
      "value": "CVE-2021-21708",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-1474",
          "title": "Vulnerability disclosure: Which comes first, the security bug in PHP or the CVE?",
          "link": "https://snyk.io/blog/vulnerability-disclosure-php-use-after-free/",
          "published": "2023-12-19",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-12-19"
    },
    {
      "value": "CVE-2022-28368",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-1474",
          "title": "Vulnerability disclosure: Which comes first, the security bug in PHP or the CVE?",
          "link": "https://snyk.io/blog/vulnerability-disclosure-php-use-after-free/",
          "published": "2023-12-19",
          "sev": "crit"
        },
        {
          "id": "art-2481",
          "title": "dompdf security alert: RCE vulnerability found in popular PHP PDF library",
          "link": "https://snyk.io/blog/security-alert-php-pdf-library-dompdf-rce/",
          "published": "2022-03-18",
          "sev": "high"
        }
      ],
      "first_seen": "2023-12-19"
    },
    {
      "value": "CVE-2023-6448",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1481",
          "title": "CISA KEV: CVE-2023-6448 \u2014 Unitronics Vision PLC and HMI Insecure Default Password Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-12-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-12-11"
    },
    {
      "value": "3ac8308a7378dfe047eacd393c861d32df34bb47535972eb0a35631ab964d14d",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1482",
          "title": "CISA KEV: CVE-2023-41266 \u2014 Qlik Sense Path Traversal Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-12-07",
          "sev": "crit"
        },
        {
          "id": "art-1483",
          "title": "CISA KEV: CVE-2023-41265 \u2014 Qlik Sense HTTP Tunneling Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-12-07",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-12-07"
    },
    {
      "value": "6cb87cad36f56aefcefbe754605c00ac92e640857fd7ca5faab7b9542ef80c96",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1482",
          "title": "CISA KEV: CVE-2023-41266 \u2014 Qlik Sense Path Traversal Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-12-07",
          "sev": "crit"
        },
        {
          "id": "art-1483",
          "title": "CISA KEV: CVE-2023-41265 \u2014 Qlik Sense HTTP Tunneling Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-12-07",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-12-07"
    },
    {
      "value": "828e81aa16b2851561fff6d3127663ea2d1d68571f06cbd732fdf5672086924d",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1482",
          "title": "CISA KEV: CVE-2023-41266 \u2014 Qlik Sense Path Traversal Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-12-07",
          "sev": "crit"
        },
        {
          "id": "art-1483",
          "title": "CISA KEV: CVE-2023-41265 \u2014 Qlik Sense HTTP Tunneling Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-12-07",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-12-07"
    },
    {
      "value": "90b009b15eb1b5bc4a990ecdd86375fa25eaa67a8515ae6c6b3b58815d46fa82",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1482",
          "title": "CISA KEV: CVE-2023-41266 \u2014 Qlik Sense Path Traversal Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-12-07",
          "sev": "crit"
        },
        {
          "id": "art-1483",
          "title": "CISA KEV: CVE-2023-41265 \u2014 Qlik Sense HTTP Tunneling Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-12-07",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-12-07"
    },
    {
      "value": "CVE-2020-11261",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1487",
          "title": "CISA KEV: CVE-2023-33107 \u2014 Qualcomm Multiple Chipsets Integer Overflow Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-12-05",
          "sev": "crit"
        },
        {
          "id": "art-2776",
          "title": "CISA KEV: CVE-2020-11261 \u2014 Qualcomm Multiple Chipsets Improper Input Validation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-12-01",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-12-05"
    },
    {
      "value": "CVE-2022-22071",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1487",
          "title": "CISA KEV: CVE-2023-33107 \u2014 Qualcomm Multiple Chipsets Integer Overflow Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-12-05",
          "sev": "crit"
        },
        {
          "id": "art-1488",
          "title": "CISA KEV: CVE-2023-33106 \u2014 Qualcomm Multiple Chipsets Use of Out-of-Range Pointer Offset Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-12-05",
          "sev": "crit"
        },
        {
          "id": "art-1490",
          "title": "CISA KEV: CVE-2022-22071 \u2014 Qualcomm Multiple Chipsets Use-After-Free Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-12-05",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-12-05"
    },
    {
      "value": "CVE-2023-33063",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1487",
          "title": "CISA KEV: CVE-2023-33107 \u2014 Qualcomm Multiple Chipsets Integer Overflow Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-12-05",
          "sev": "crit"
        },
        {
          "id": "art-1488",
          "title": "CISA KEV: CVE-2023-33106 \u2014 Qualcomm Multiple Chipsets Use of Out-of-Range Pointer Offset Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-12-05",
          "sev": "crit"
        },
        {
          "id": "art-1489",
          "title": "CISA KEV: CVE-2023-33063 \u2014 Qualcomm Multiple Chipsets Use-After-Free Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-12-05",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-12-05"
    },
    {
      "value": "CVE-2023-33106",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1487",
          "title": "CISA KEV: CVE-2023-33107 \u2014 Qualcomm Multiple Chipsets Integer Overflow Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-12-05",
          "sev": "crit"
        },
        {
          "id": "art-1488",
          "title": "CISA KEV: CVE-2023-33106 \u2014 Qualcomm Multiple Chipsets Use of Out-of-Range Pointer Offset Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-12-05",
          "sev": "crit"
        },
        {
          "id": "art-1489",
          "title": "CISA KEV: CVE-2023-33063 \u2014 Qualcomm Multiple Chipsets Use-After-Free Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-12-05",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-12-05"
    },
    {
      "value": "CVE-2023-33107",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1487",
          "title": "CISA KEV: CVE-2023-33107 \u2014 Qualcomm Multiple Chipsets Integer Overflow Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-12-05",
          "sev": "crit"
        },
        {
          "id": "art-1488",
          "title": "CISA KEV: CVE-2023-33106 \u2014 Qualcomm Multiple Chipsets Use of Out-of-Range Pointer Offset Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-12-05",
          "sev": "crit"
        },
        {
          "id": "art-1489",
          "title": "CISA KEV: CVE-2023-33063 \u2014 Qualcomm Multiple Chipsets Use-After-Free Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-12-05",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-12-05"
    },
    {
      "value": "CVE-2023-42916",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1494",
          "title": "CISA KEV: CVE-2023-42916 \u2014 Apple Multiple Products WebKit Out-of-Bounds Read Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-12-04",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-12-04"
    },
    {
      "value": "CVE-2023-42917",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1493",
          "title": "CISA KEV: CVE-2023-42917 \u2014 Apple Multiple Products WebKit Memory Corruption Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-12-04",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-12-04"
    },
    {
      "value": "CVE-2023-49103",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1499",
          "title": "CISA KEV: CVE-2023-49103 \u2014 ownCloud graphapi Information Disclosure Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-11-30",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-11-30"
    },
    {
      "value": "CVE-2023-6345",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1498",
          "title": "CISA KEV: CVE-2023-6345 \u2014 Google Skia Integer Overflow Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-11-30",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-11-30"
    },
    {
      "value": "CVE-2023-5654",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-1506",
          "title": "Exploring WebExtension security vulnerabilities in React Developer Tools and Vue.js devtools",
          "link": "https://snyk.io/blog/webextension-security-vulnerabilities-react-developer-tools-vue-js/",
          "published": "2023-11-27",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-11-27"
    },
    {
      "value": "CVE-2023-5718",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-1506",
          "title": "Exploring WebExtension security vulnerabilities in React Developer Tools and Vue.js devtools",
          "link": "https://snyk.io/blog/webextension-security-vulnerabilities-react-developer-tools-vue-js/",
          "published": "2023-11-27",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-11-27"
    },
    {
      "value": "CVE-2017-9841",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1510",
          "title": "CISA KEV: CVE-2023-4911 \u2014 GNU C Library Buffer Overflow Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-11-21",
          "sev": "crit"
        },
        {
          "id": "art-2645",
          "title": "CISA KEV: CVE-2017-9841 \u2014 PHPUnit Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-02-15",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-11-21"
    },
    {
      "value": "CVE-2023-4911",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1510",
          "title": "CISA KEV: CVE-2023-4911 \u2014 GNU C Library Buffer Overflow Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-11-21",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-11-21"
    },
    {
      "value": "haxx.in",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1510",
          "title": "CISA KEV: CVE-2023-4911 \u2014 GNU C Library Buffer Overflow Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-11-21",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-11-21"
    },
    {
      "value": "194.233.65.92",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1510",
          "title": "CISA KEV: CVE-2023-4911 \u2014 GNU C Library Buffer Overflow Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-11-21",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-11-21"
    },
    {
      "value": "5d3c00b79be956d4175d0d5fd1d4f1f9",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1510",
          "title": "CISA KEV: CVE-2023-4911 \u2014 GNU C Library Buffer Overflow Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-11-21",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-11-21"
    },
    {
      "value": "5dce322f5284213912012e7ba2440da0",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1510",
          "title": "CISA KEV: CVE-2023-4911 \u2014 GNU C Library Buffer Overflow Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-11-21",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-11-21"
    },
    {
      "value": "9a868bb2456bcde27cde7985145ef6fc",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1510",
          "title": "CISA KEV: CVE-2023-4911 \u2014 GNU C Library Buffer Overflow Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-11-21",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-11-21"
    },
    {
      "value": "ea685e738adedc02ca1a63ebe8ed939e",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1510",
          "title": "CISA KEV: CVE-2023-4911 \u2014 GNU C Library Buffer Overflow Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-11-21",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-11-21"
    },
    {
      "value": "CVE-2020-2551",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1516",
          "title": "CISA KEV: CVE-2020-2551 \u2014 Oracle Fusion Middleware Unspecified Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-11-16",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-11-16"
    },
    {
      "value": "CVE-2023-1671",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1515",
          "title": "CISA KEV: CVE-2023-1671 \u2014 Sophos Web Appliance Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-11-16",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-11-16"
    },
    {
      "value": "CVE-2023-36584",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1514",
          "title": "CISA KEV: CVE-2023-36584 \u2014 Microsoft Windows Mark of the Web (MOTW) Security Feature Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-11-16",
          "sev": "crit"
        },
        {
          "id": "art-1664",
          "title": "CISA KEV: CVE-2023-36884 \u2014 Microsoft Windows Search Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-07-17",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-11-16"
    },
    {
      "value": "CVE-2023-36884",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1514",
          "title": "CISA KEV: CVE-2023-36584 \u2014 Microsoft Windows Mark of the Web (MOTW) Security Feature Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-11-16",
          "sev": "crit"
        },
        {
          "id": "art-1664",
          "title": "CISA KEV: CVE-2023-36884 \u2014 Microsoft Windows Search Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-07-17",
          "sev": "crit"
        },
        {
          "id": "art-1671",
          "title": "CISA KEV: CVE-2023-32049 \u2014 Microsoft Windows Defender SmartScreen Security Feature Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-07-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-11-16"
    },
    {
      "value": "CVE-2022-21896",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1518",
          "title": "CISA KEV: CVE-2023-36033 \u2014 Microsoft Windows Desktop Window Manager (DWM) Core Library Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-11-14",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-11-14"
    },
    {
      "value": "CVE-2022-21902",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1518",
          "title": "CISA KEV: CVE-2023-36033 \u2014 Microsoft Windows Desktop Window Manager (DWM) Core Library Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-11-14",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-11-14"
    },
    {
      "value": "CVE-2023-36033",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1518",
          "title": "CISA KEV: CVE-2023-36033 \u2014 Microsoft Windows Desktop Window Manager (DWM) Core Library Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-11-14",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-11-14"
    },
    {
      "value": "CVE-2023-36036",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1520",
          "title": "CISA KEV: CVE-2023-36036 \u2014 Microsoft Windows Cloud Files Mini Filter Driver Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-11-14",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-11-14"
    },
    {
      "value": "3a3feea7ededb728efce89a6d74a823d700e2fe9994bc8791e132bf548473e93",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1518",
          "title": "CISA KEV: CVE-2023-36033 \u2014 Microsoft Windows Desktop Window Manager (DWM) Core Library Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-11-14",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-11-14"
    },
    {
      "value": "97cf4e82a902de6a1530499af32afdcf6f79253a10f51b89f92e84ae503f89c3",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1518",
          "title": "CISA KEV: CVE-2023-36033 \u2014 Microsoft Windows Desktop Window Manager (DWM) Core Library Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-11-14",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-11-14"
    },
    {
      "value": "CVE-2023-36844",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1523",
          "title": "CISA KEV: CVE-2023-36844 \u2014 Juniper Junos OS EX Series PHP External Variable Modification Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-11-13",
          "sev": "crit"
        },
        {
          "id": "art-1525",
          "title": "CISA KEV: CVE-2023-36846 \u2014 Juniper Junos OS SRX Series Missing Authentication for Critical Function Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-11-13",
          "sev": "crit"
        },
        {
          "id": "art-1526",
          "title": "CISA KEV: CVE-2023-36847 \u2014 Juniper Junos OS EX Series Missing Authentication for Critical Function Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-11-13",
          "sev": "crit"
        },
        {
          "id": "art-1527",
          "title": "CISA KEV: CVE-2023-36851 \u2014 Juniper Junos OS SRX Series Missing Authentication for Critical Function Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-11-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-11-13"
    },
    {
      "value": "CVE-2023-36845",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1523",
          "title": "CISA KEV: CVE-2023-36844 \u2014 Juniper Junos OS EX Series PHP External Variable Modification Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-11-13",
          "sev": "crit"
        },
        {
          "id": "art-1524",
          "title": "CISA KEV: CVE-2023-36845 \u2014 Juniper Junos OS EX Series and SRX Series PHP External Variable Modification Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-11-13",
          "sev": "crit"
        },
        {
          "id": "art-1525",
          "title": "CISA KEV: CVE-2023-36846 \u2014 Juniper Junos OS SRX Series Missing Authentication for Critical Function Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-11-13",
          "sev": "crit"
        },
        {
          "id": "art-1526",
          "title": "CISA KEV: CVE-2023-36847 \u2014 Juniper Junos OS EX Series Missing Authentication for Critical Function Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-11-13",
          "sev": "crit"
        },
        {
          "id": "art-1527",
          "title": "CISA KEV: CVE-2023-36851 \u2014 Juniper Junos OS SRX Series Missing Authentication for Critical Function Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-11-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-11-13"
    },
    {
      "value": "CVE-2023-36846",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1523",
          "title": "CISA KEV: CVE-2023-36844 \u2014 Juniper Junos OS EX Series PHP External Variable Modification Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-11-13",
          "sev": "crit"
        },
        {
          "id": "art-1525",
          "title": "CISA KEV: CVE-2023-36846 \u2014 Juniper Junos OS SRX Series Missing Authentication for Critical Function Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-11-13",
          "sev": "crit"
        },
        {
          "id": "art-1526",
          "title": "CISA KEV: CVE-2023-36847 \u2014 Juniper Junos OS EX Series Missing Authentication for Critical Function Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-11-13",
          "sev": "crit"
        },
        {
          "id": "art-1527",
          "title": "CISA KEV: CVE-2023-36851 \u2014 Juniper Junos OS SRX Series Missing Authentication for Critical Function Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-11-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-11-13"
    },
    {
      "value": "CVE-2023-36847",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1523",
          "title": "CISA KEV: CVE-2023-36844 \u2014 Juniper Junos OS EX Series PHP External Variable Modification Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-11-13",
          "sev": "crit"
        },
        {
          "id": "art-1525",
          "title": "CISA KEV: CVE-2023-36846 \u2014 Juniper Junos OS SRX Series Missing Authentication for Critical Function Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-11-13",
          "sev": "crit"
        },
        {
          "id": "art-1526",
          "title": "CISA KEV: CVE-2023-36847 \u2014 Juniper Junos OS EX Series Missing Authentication for Critical Function Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-11-13",
          "sev": "crit"
        },
        {
          "id": "art-1527",
          "title": "CISA KEV: CVE-2023-36851 \u2014 Juniper Junos OS SRX Series Missing Authentication for Critical Function Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-11-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-11-13"
    },
    {
      "value": "CVE-2023-36851",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1527",
          "title": "CISA KEV: CVE-2023-36851 \u2014 Juniper Junos OS SRX Series Missing Authentication for Critical Function Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-11-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-11-13"
    },
    {
      "value": "CVE-2023-47246",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1522",
          "title": "CISA KEV: CVE-2023-47246 \u2014 SysAid Server Path Traversal Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-11-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-11-13"
    },
    {
      "value": "179.60.150.34",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1522",
          "title": "CISA KEV: CVE-2023-47246 \u2014 SysAid Server Path Traversal Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-11-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-11-13"
    },
    {
      "value": "45.155.37.105",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1522",
          "title": "CISA KEV: CVE-2023-47246 \u2014 SysAid Server Path Traversal Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-11-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-11-13"
    },
    {
      "value": "45.182.189.100",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1522",
          "title": "CISA KEV: CVE-2023-47246 \u2014 SysAid Server Path Traversal Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-11-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-11-13"
    },
    {
      "value": "81.19.138.52",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1522",
          "title": "CISA KEV: CVE-2023-47246 \u2014 SysAid Server Path Traversal Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-11-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-11-13"
    },
    {
      "value": "98d4184379fb6cf08a57f2bc937887965ae3e9c977a87a5c6443bf5c055bfd18",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1522",
          "title": "CISA KEV: CVE-2023-47246 \u2014 SysAid Server Path Traversal Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-11-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-11-13"
    },
    {
      "value": "b5acf14cdac40be590318dee95425d0746e85b1b7b1cbd14da66f21f2522bf4d",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1522",
          "title": "CISA KEV: CVE-2023-47246 \u2014 SysAid Server Path Traversal Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-11-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-11-13"
    },
    {
      "value": "be4334ce0be2683878c5b9fb911a4fb9beaaa09845028215134081268621df38",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1522",
          "title": "CISA KEV: CVE-2023-47246 \u2014 SysAid Server Path Traversal Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-11-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-11-13"
    },
    {
      "value": "f0fb710ee7b2a7f07acdf87cba7b79331ead0eda74276150fde8413b7793fcd7",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1522",
          "title": "CISA KEV: CVE-2023-47246 \u2014 SysAid Server Path Traversal Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-11-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-11-13"
    },
    {
      "value": "us-east-2.compute.internal",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "med",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-1528",
          "title": "Real-time threat protection with Snyk and SentinelOne",
          "link": "https://snyk.io/blog/snyk-sentinelone-built-time-runtime-solution/",
          "published": "2023-11-09",
          "sev": "med"
        }
      ],
      "first_seen": "2023-11-09"
    },
    {
      "value": "8656c04d40b0b3900721ddf26ea43c5f5f646b7b",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "med",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-1528",
          "title": "Real-time threat protection with Snyk and SentinelOne",
          "link": "https://snyk.io/blog/snyk-sentinelone-built-time-runtime-solution/",
          "published": "2023-11-09",
          "sev": "med"
        }
      ],
      "first_seen": "2023-11-09"
    },
    {
      "value": "CVE-2023-29552",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1532",
          "title": "CISA KEV: CVE-2023-29552 \u2014 Service Location Protocol (SLP) Denial-of-Service Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-11-08",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-11-08"
    },
    {
      "value": "CVE-2023-22515",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1534",
          "title": "CISA KEV: CVE-2023-22518 \u2014 Atlassian Confluence Data Center and Server Improper Authorization Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-11-07",
          "sev": "crit"
        },
        {
          "id": "art-1569",
          "title": "CISA KEV: CVE-2023-22515 \u2014 Atlassian Confluence Data Center and Server Broken Access Control Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-10-05",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-11-07"
    },
    {
      "value": "CVE-2023-22518",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1534",
          "title": "CISA KEV: CVE-2023-22518 \u2014 Atlassian Confluence Data Center and Server Improper Authorization Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-11-07",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-11-07"
    },
    {
      "value": "j3qxmk6g5sk3zw62i2yhjnwmhm55rfz47fdyfkhaithlpelfjdokdxad.onion",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1534",
          "title": "CISA KEV: CVE-2023-22518 \u2014 Atlassian Confluence Data Center and Server Improper Authorization Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-11-07",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-11-07"
    },
    {
      "value": "193.176.179.41",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1534",
          "title": "CISA KEV: CVE-2023-22518 \u2014 Atlassian Confluence Data Center and Server Improper Authorization Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-11-07",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-11-07"
    },
    {
      "value": "193.187.172.73",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1534",
          "title": "CISA KEV: CVE-2023-22518 \u2014 Atlassian Confluence Data Center and Server Improper Authorization Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-11-07",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-11-07"
    },
    {
      "value": "193.43.72.11",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1534",
          "title": "CISA KEV: CVE-2023-22518 \u2014 Atlassian Confluence Data Center and Server Improper Authorization Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-11-07",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-11-07"
    },
    {
      "value": "45.145.6.112",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1534",
          "title": "CISA KEV: CVE-2023-22518 \u2014 Atlassian Confluence Data Center and Server Improper Authorization Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-11-07",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-11-07"
    },
    {
      "value": "81b760d4057c7c704f18c3f6b3e6b2c4",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1534",
          "title": "CISA KEV: CVE-2023-22518 \u2014 Atlassian Confluence Data Center and Server Improper Authorization Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-11-07",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-11-07"
    },
    {
      "value": "1243e256f9e806652ba8e719273494f84795bbfe",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1534",
          "title": "CISA KEV: CVE-2023-22518 \u2014 Atlassian Confluence Data Center and Server Improper Authorization Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-11-07",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-11-07"
    },
    {
      "value": "2c3b2a6e741cb5d3be7299de007983f1f86c0ef5",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1534",
          "title": "CISA KEV: CVE-2023-22518 \u2014 Atlassian Confluence Data Center and Server Improper Authorization Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-11-07",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-11-07"
    },
    {
      "value": "47c6fdf51760c13d2602909ddbbb84ef8e33f992",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1534",
          "title": "CISA KEV: CVE-2023-22518 \u2014 Atlassian Confluence Data Center and Server Improper Authorization Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-11-07",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-11-07"
    },
    {
      "value": "8988ef7abd931496d7bbdf7db1a67c9def0641d9",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1534",
          "title": "CISA KEV: CVE-2023-22518 \u2014 Atlassian Confluence Data Center and Server Improper Authorization Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-11-07",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-11-07"
    },
    {
      "value": "ada7160c49cb22f569265fe3719fa2713a24dcf1",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1534",
          "title": "CISA KEV: CVE-2023-22518 \u2014 Atlassian Confluence Data Center and Server Improper Authorization Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-11-07",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-11-07"
    },
    {
      "value": "f4384ca1c2250d58a17e692ce2a8efd7dcc97a73",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1534",
          "title": "CISA KEV: CVE-2023-22518 \u2014 Atlassian Confluence Data Center and Server Improper Authorization Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-11-07",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-11-07"
    },
    {
      "value": "4ed46b98d047f5ed26553c6f4fded7209933ca9632b998d265870e3557a5cdfe",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1534",
          "title": "CISA KEV: CVE-2023-22518 \u2014 Atlassian Confluence Data Center and Server Improper Authorization Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-11-07",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-11-07"
    },
    {
      "value": "CVE-2023-46604",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1539",
          "title": "CISA KEV: CVE-2023-46604 \u2014 Apache ActiveMQ Deserialization of Untrusted Data Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-11-02",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-11-02"
    },
    {
      "value": "hellokittycat.online",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1539",
          "title": "CISA KEV: CVE-2023-46604 \u2014 Apache ActiveMQ Deserialization of Untrusted Data Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-11-02",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-11-02"
    },
    {
      "value": "166.62.100.62",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1539",
          "title": "CISA KEV: CVE-2023-46604 \u2014 Apache ActiveMQ Deserialization of Untrusted Data Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-11-02",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-11-02"
    },
    {
      "value": "172.245.16.125",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1539",
          "title": "CISA KEV: CVE-2023-46604 \u2014 Apache ActiveMQ Deserialization of Untrusted Data Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-11-02",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-11-02"
    },
    {
      "value": "CVE-2023-46747",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1541",
          "title": "CISA KEV: CVE-2023-46748 \u2014 F5 BIG-IP Configuration Utility SQL Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-10-31",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-10-31"
    },
    {
      "value": "CVE-2023-46748",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1541",
          "title": "CISA KEV: CVE-2023-46748 \u2014 F5 BIG-IP Configuration Utility SQL Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-10-31",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-10-31"
    },
    {
      "value": "CVE-2023-5631",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1544",
          "title": "CISA KEV: CVE-2023-5631 \u2014 Roundcube Webmail Persistent Cross-Site Scripting (XSS) Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-10-26",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-10-26"
    },
    {
      "value": "recsecas.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1544",
          "title": "CISA KEV: CVE-2023-5631 \u2014 Roundcube Webmail Persistent Cross-Site Scripting (XSS) Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-10-26",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-10-26"
    },
    {
      "value": "38.180.76.31",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1544",
          "title": "CISA KEV: CVE-2023-5631 \u2014 Roundcube Webmail Persistent Cross-Site Scripting (XSS) Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-10-26",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-10-26"
    },
    {
      "value": "8BF7FCC70F6CE032217D9210EF30314DDD6B8135",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1544",
          "title": "CISA KEV: CVE-2023-5631 \u2014 Roundcube Webmail Persistent Cross-Site Scripting (XSS) Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-10-26",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-10-26"
    },
    {
      "value": "97ED594EF2B5755F0549C6C5758377C0B87CFAE0",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1544",
          "title": "CISA KEV: CVE-2023-5631 \u2014 Roundcube Webmail Persistent Cross-Site Scripting (XSS) Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-10-26",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-10-26"
    },
    {
      "value": "CVE-2023-46133",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-1545",
          "title": "Weak Hash vulnerability discovered in crypto-js and crypto-es (CVE-2023-46233 & CVE-2023-46133)",
          "link": "https://snyk.io/blog/weak-hash-vulnerability-crypto-js-crypto-es/",
          "published": "2023-10-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-10-25"
    },
    {
      "value": "CVE-2023-46233",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-1545",
          "title": "Weak Hash vulnerability discovered in crypto-js and crypto-es (CVE-2023-46233 & CVE-2023-46133)",
          "link": "https://snyk.io/blog/weak-hash-vulnerability-crypto-js-crypto-es/",
          "published": "2023-10-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-10-25"
    },
    {
      "value": "CVE-2021-23369",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-1547",
          "title": "Adding Snyk security to Jira and Bitbucket Cloud",
          "link": "https://snyk.io/blog/adding-snyk-security-jira-bitbucket-cloud/",
          "published": "2023-10-25",
          "sev": "high"
        }
      ],
      "first_seen": "2023-10-25"
    },
    {
      "value": "CVE-2023-20198",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1552",
          "title": "CISA KEV: CVE-2023-20273 \u2014 Cisco IOS XE Web UI Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-10-23",
          "sev": "crit"
        },
        {
          "id": "art-1556",
          "title": "CISA KEV: CVE-2023-20198 \u2014 Cisco IOS XE Web UI Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-10-16",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-10-23"
    },
    {
      "value": "CVE-2023-20273",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1552",
          "title": "CISA KEV: CVE-2023-20273 \u2014 Cisco IOS XE Web UI Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-10-23",
          "sev": "crit"
        },
        {
          "id": "art-1556",
          "title": "CISA KEV: CVE-2023-20198 \u2014 Cisco IOS XE Web UI Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-10-16",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-10-23"
    },
    {
      "value": "154.53.56.231",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1552",
          "title": "CISA KEV: CVE-2023-20273 \u2014 Cisco IOS XE Web UI Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-10-23",
          "sev": "crit"
        },
        {
          "id": "art-1556",
          "title": "CISA KEV: CVE-2023-20198 \u2014 Cisco IOS XE Web UI Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-10-16",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-10-23"
    },
    {
      "value": "5.149.249.74",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1552",
          "title": "CISA KEV: CVE-2023-20273 \u2014 Cisco IOS XE Web UI Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-10-23",
          "sev": "crit"
        },
        {
          "id": "art-1556",
          "title": "CISA KEV: CVE-2023-20198 \u2014 Cisco IOS XE Web UI Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-10-16",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-10-23"
    },
    {
      "value": "CVE-2023-4966",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1554",
          "title": "CISA KEV: CVE-2023-4966 \u2014 Citrix NetScaler ADC and NetScaler Gateway Buffer Overflow Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-10-18",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-10-18"
    },
    {
      "value": "154.53.63.93",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1556",
          "title": "CISA KEV: CVE-2023-20198 \u2014 Cisco IOS XE Web UI Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-10-16",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-10-16"
    },
    {
      "value": "CVE-2023-44487",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "Snyk",
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1559",
          "title": "Find and fix HTTP/2 rapid reset zero-day vulnerability CVE-2023-44487",
          "link": "https://snyk.io/blog/find-fix-http-2-rapid-reset-zero-day-vulnerability-cve-2023-44487/",
          "published": "2023-10-11",
          "sev": "high"
        },
        {
          "id": "art-1566",
          "title": "CISA KEV: CVE-2023-44487 \u2014 HTTP/2 Rapid Reset Attack Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-10-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-10-11"
    },
    {
      "value": "CVE-2023-20109",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1563",
          "title": "CISA KEV: CVE-2023-20109 \u2014 Cisco IOS and IOS XE Group Encrypted Transport VPN Out-of-Bounds Write Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-10-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-10-10"
    },
    {
      "value": "CVE-2023-21608",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1562",
          "title": "CISA KEV: CVE-2023-21608 \u2014 Adobe Acrobat and Reader Use-After-Free Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-10-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-10-10"
    },
    {
      "value": "CVE-2023-36563",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1565",
          "title": "CISA KEV: CVE-2023-36563 \u2014 Microsoft WordPad Information Disclosure Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-10-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-10-10"
    },
    {
      "value": "CVE-2023-41763",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1564",
          "title": "CISA KEV: CVE-2023-41763 \u2014 Microsoft Skype for Business Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-10-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-10-10"
    },
    {
      "value": "CVE-2023-40044",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1570",
          "title": "CISA KEV: CVE-2023-40044 \u2014 Progress WS_FTP Server Deserialization of Untrusted Data Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-10-05",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-10-05"
    },
    {
      "value": "CVE-2023-42657",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1570",
          "title": "CISA KEV: CVE-2023-40044 \u2014 Progress WS_FTP Server Deserialization of Untrusted Data Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-10-05",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-10-05"
    },
    {
      "value": "CVE-2023-42824",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1571",
          "title": "CISA KEV: CVE-2023-42824 \u2014 Apple iOS and iPadOS Kernel Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-10-05",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-10-05"
    },
    {
      "value": "2adc9m0bc70noboyvgt357r5gwmnady2.oastify.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1570",
          "title": "CISA KEV: CVE-2023-40044 \u2014 Progress WS_FTP Server Deserialization of Untrusted Data Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-10-05",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-10-05"
    },
    {
      "value": "realtime-v1.backendapi-fe4.workers.dev",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1570",
          "title": "CISA KEV: CVE-2023-40044 \u2014 Progress WS_FTP Server Deserialization of Untrusted Data Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-10-05",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-10-05"
    },
    {
      "value": "status.backendapi-fe4.workers.dev",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1570",
          "title": "CISA KEV: CVE-2023-40044 \u2014 Progress WS_FTP Server Deserialization of Untrusted Data Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-10-05",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-10-05"
    },
    {
      "value": "103.163.187.12",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1570",
          "title": "CISA KEV: CVE-2023-40044 \u2014 Progress WS_FTP Server Deserialization of Untrusted Data Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-10-05",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-10-05"
    },
    {
      "value": "104.128.89.92",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1569",
          "title": "CISA KEV: CVE-2023-22515 \u2014 Atlassian Confluence Data Center and Server Broken Access Control Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-10-05",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-10-05"
    },
    {
      "value": "161.35.27.144",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1570",
          "title": "CISA KEV: CVE-2023-40044 \u2014 Progress WS_FTP Server Deserialization of Untrusted Data Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-10-05",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-10-05"
    },
    {
      "value": "162.243.161.105",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1570",
          "title": "CISA KEV: CVE-2023-40044 \u2014 Progress WS_FTP Server Deserialization of Untrusted Data Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-10-05",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-10-05"
    },
    {
      "value": "172.245.213.135",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1570",
          "title": "CISA KEV: CVE-2023-40044 \u2014 Progress WS_FTP Server Deserialization of Untrusted Data Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-10-05",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-10-05"
    },
    {
      "value": "192.69.90.31",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1569",
          "title": "CISA KEV: CVE-2023-22515 \u2014 Atlassian Confluence Data Center and Server Broken Access Control Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-10-05",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-10-05"
    },
    {
      "value": "199.193.127.231",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1569",
          "title": "CISA KEV: CVE-2023-22515 \u2014 Atlassian Confluence Data Center and Server Broken Access Control Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-10-05",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-10-05"
    },
    {
      "value": "23.105.208.154",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1569",
          "title": "CISA KEV: CVE-2023-22515 \u2014 Atlassian Confluence Data Center and Server Broken Access Control Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-10-05",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-10-05"
    },
    {
      "value": "64.227.126.135",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1570",
          "title": "CISA KEV: CVE-2023-40044 \u2014 Progress WS_FTP Server Deserialization of Untrusted Data Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-10-05",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-10-05"
    },
    {
      "value": "86.48.3.172",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1570",
          "title": "CISA KEV: CVE-2023-40044 \u2014 Progress WS_FTP Server Deserialization of Untrusted Data Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-10-05",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-10-05"
    },
    {
      "value": "CVE-2023-28229",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1576",
          "title": "CISA KEV: CVE-2023-28229 \u2014 Microsoft Windows CNG Key Isolation Service Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-10-04",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-10-04"
    },
    {
      "value": "CVE-2023-42793",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1575",
          "title": "CISA KEV: CVE-2023-42793 \u2014 JetBrains TeamCity Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-10-04",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-10-04"
    },
    {
      "value": "3dkit.org",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1575",
          "title": "CISA KEV: CVE-2023-42793 \u2014 JetBrains TeamCity Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-10-04",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-10-04"
    },
    {
      "value": "aeon-petro.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1575",
          "title": "CISA KEV: CVE-2023-42793 \u2014 JetBrains TeamCity Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-10-04",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-10-04"
    },
    {
      "value": "bandarpowder.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1575",
          "title": "CISA KEV: CVE-2023-42793 \u2014 JetBrains TeamCity Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-10-04",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-10-04"
    },
    {
      "value": "commune-fraita.ma",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1575",
          "title": "CISA KEV: CVE-2023-42793 \u2014 JetBrains TeamCity Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-10-04",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-10-04"
    },
    {
      "value": "dersmarketim.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1575",
          "title": "CISA KEV: CVE-2023-42793 \u2014 JetBrains TeamCity Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-10-04",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-10-04"
    },
    {
      "value": "fisheries-states-codes-camps.trycloudflare.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1575",
          "title": "CISA KEV: CVE-2023-42793 \u2014 JetBrains TeamCity Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-10-04",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-10-04"
    },
    {
      "value": "galerielamy.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1575",
          "title": "CISA KEV: CVE-2023-42793 \u2014 JetBrains TeamCity Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-10-04",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-10-04"
    },
    {
      "value": "mge.sn",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1575",
          "title": "CISA KEV: CVE-2023-42793 \u2014 JetBrains TeamCity Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-10-04",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-10-04"
    },
    {
      "value": "olidhealth.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1575",
          "title": "CISA KEV: CVE-2023-42793 \u2014 JetBrains TeamCity Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-10-04",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-10-04"
    },
    {
      "value": "ultasrv.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1575",
          "title": "CISA KEV: CVE-2023-42793 \u2014 JetBrains TeamCity Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-10-04",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-10-04"
    },
    {
      "value": "vadtalmandir.org",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1575",
          "title": "CISA KEV: CVE-2023-42793 \u2014 JetBrains TeamCity Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-10-04",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-10-04"
    },
    {
      "value": "103.76.128.34",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1575",
          "title": "CISA KEV: CVE-2023-42793 \u2014 JetBrains TeamCity Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-10-04",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-10-04"
    },
    {
      "value": "147.78.149.201",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1575",
          "title": "CISA KEV: CVE-2023-42793 \u2014 JetBrains TeamCity Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-10-04",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-10-04"
    },
    {
      "value": "162.19.71.175",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1575",
          "title": "CISA KEV: CVE-2023-42793 \u2014 JetBrains TeamCity Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-10-04",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-10-04"
    },
    {
      "value": "167.114.3.69",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1575",
          "title": "CISA KEV: CVE-2023-42793 \u2014 JetBrains TeamCity Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-10-04",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-10-04"
    },
    {
      "value": "45.133.7.124",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1575",
          "title": "CISA KEV: CVE-2023-42793 \u2014 JetBrains TeamCity Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-10-04",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-10-04"
    },
    {
      "value": "45.133.7.129",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1575",
          "title": "CISA KEV: CVE-2023-42793 \u2014 JetBrains TeamCity Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-10-04",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-10-04"
    },
    {
      "value": "45.133.7.154",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1575",
          "title": "CISA KEV: CVE-2023-42793 \u2014 JetBrains TeamCity Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-10-04",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-10-04"
    },
    {
      "value": "45.133.7.156",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1575",
          "title": "CISA KEV: CVE-2023-42793 \u2014 JetBrains TeamCity Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-10-04",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-10-04"
    },
    {
      "value": "45.138.16.63",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1575",
          "title": "CISA KEV: CVE-2023-42793 \u2014 JetBrains TeamCity Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-10-04",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-10-04"
    },
    {
      "value": "92.38.177.14",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1575",
          "title": "CISA KEV: CVE-2023-42793 \u2014 JetBrains TeamCity Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-10-04",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-10-04"
    },
    {
      "value": "2df317b8a408d2ad5c94b9de6f20bbef03e46066",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1575",
          "title": "CISA KEV: CVE-2023-42793 \u2014 JetBrains TeamCity Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-10-04",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-10-04"
    },
    {
      "value": "3a32e516c037c37f7bf83171e167511ba53870a7",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1575",
          "title": "CISA KEV: CVE-2023-42793 \u2014 JetBrains TeamCity Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-10-04",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-10-04"
    },
    {
      "value": "4fed3d5de4df20d961831be6194b9d595b943bc9",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1575",
          "title": "CISA KEV: CVE-2023-42793 \u2014 JetBrains TeamCity Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-10-04",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-10-04"
    },
    {
      "value": "51aa6e5186ede77545e99b14b8f7e8180a0c6933",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1575",
          "title": "CISA KEV: CVE-2023-42793 \u2014 JetBrains TeamCity Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-10-04",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-10-04"
    },
    {
      "value": "5ce062f210e1a5026cb53e9949865312ee477e3c",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1575",
          "title": "CISA KEV: CVE-2023-42793 \u2014 JetBrains TeamCity Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-10-04",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-10-04"
    },
    {
      "value": "682b9ac9448707024985ad54476acfbf642a03b9",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1575",
          "title": "CISA KEV: CVE-2023-42793 \u2014 JetBrains TeamCity Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-10-04",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-10-04"
    },
    {
      "value": "8f5780056107dbc2bb59d63f454d8523091ddde2",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1575",
          "title": "CISA KEV: CVE-2023-42793 \u2014 JetBrains TeamCity Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-10-04",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-10-04"
    },
    {
      "value": "a4b03f1e981ccdd7e08e786c72283d5551671edf",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1575",
          "title": "CISA KEV: CVE-2023-42793 \u2014 JetBrains TeamCity Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-10-04",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-10-04"
    },
    {
      "value": "a66d76d86448965e57d7be96a57529c497e4b99d",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1575",
          "title": "CISA KEV: CVE-2023-42793 \u2014 JetBrains TeamCity Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-10-04",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-10-04"
    },
    {
      "value": "bcbadf744954660f9a46324649eda6a14d724cbc",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1575",
          "title": "CISA KEV: CVE-2023-42793 \u2014 JetBrains TeamCity Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-10-04",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-10-04"
    },
    {
      "value": "d4411f70e0dcc2f88d74ae7251d51c6676075f6f",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1575",
          "title": "CISA KEV: CVE-2023-42793 \u2014 JetBrains TeamCity Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-10-04",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-10-04"
    },
    {
      "value": "f836173805a8c4d4ee319fdefe4a5e92f3f55f32",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1575",
          "title": "CISA KEV: CVE-2023-42793 \u2014 JetBrains TeamCity Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-10-04",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-10-04"
    },
    {
      "value": "000752074544950ae9020a35ccd77de277f1cd5026b4b9559279dc3b86965eee",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1575",
          "title": "CISA KEV: CVE-2023-42793 \u2014 JetBrains TeamCity Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-10-04",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-10-04"
    },
    {
      "value": "0be1908566efb9d23a98797884f2827de040e4cedb642b60ed66e208715ed4aa",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1575",
          "title": "CISA KEV: CVE-2023-42793 \u2014 JetBrains TeamCity Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-10-04",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-10-04"
    },
    {
      "value": "d9add2bfdfebfa235575687de356f0cefb3e4c55964c4cb8bfdcdc58294eeaca",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1575",
          "title": "CISA KEV: CVE-2023-42793 \u2014 JetBrains TeamCity Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-10-04",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-10-04"
    },
    {
      "value": "e06f29dccfe90ae80812c2357171b5c48fba189ae103d28e972067b107e58795",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1575",
          "title": "CISA KEV: CVE-2023-42793 \u2014 JetBrains TeamCity Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-10-04",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-10-04"
    },
    {
      "value": "f251144f7ad0be0045034a1fc33fb896e8c32874e0b05869ff5783e14c062486",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1575",
          "title": "CISA KEV: CVE-2023-42793 \u2014 JetBrains TeamCity Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-10-04",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-10-04"
    },
    {
      "value": "fa7f6ac04ec118dd807c1377599f9d369096c6d8fb1ed24ac7a6ec0e817eaab6",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1575",
          "title": "CISA KEV: CVE-2023-42793 \u2014 JetBrains TeamCity Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-10-04",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-10-04"
    },
    {
      "value": "CVE-2023-38545",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-1572",
          "title": "High severity vulnerability found in libcurl and curl (CVE-2023-38545)",
          "link": "https://snyk.io/blog/curl-high-severity-vulnerability-oct-2023/",
          "published": "2023-10-04",
          "sev": "high"
        }
      ],
      "first_seen": "2023-10-04"
    },
    {
      "value": "CVE-2023-38546",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-1572",
          "title": "High severity vulnerability found in libcurl and curl (CVE-2023-38545)",
          "link": "https://snyk.io/blog/curl-high-severity-vulnerability-oct-2023/",
          "published": "2023-10-04",
          "sev": "high"
        }
      ],
      "first_seen": "2023-10-04"
    },
    {
      "value": "CVE-2023-4211",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1578",
          "title": "CISA KEV: CVE-2023-4211 \u2014 Arm Mali GPU Kernel Driver Use-After-Free Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-10-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-10-03"
    },
    {
      "value": "CVE-2023-5217",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1580",
          "title": "CISA KEV: CVE-2023-5217 \u2014 Google Chromium libvpx Heap Buffer Overflow Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-10-02",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-10-02"
    },
    {
      "value": "CVE-2018-14667",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1582",
          "title": "CISA KEV: CVE-2018-14667 \u2014 Red Hat JBoss RichFaces Framework Expression Language Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-09-28",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-09-28"
    },
    {
      "value": "CVE-2023-41061",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "Snyk",
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1581",
          "title": "Critical WebP 0-day security CVE-2023-4863 impacts wider software ecosystem",
          "link": "https://snyk.io/blog/critical-webp-0-day-cve-2023-4863/",
          "published": "2023-09-28",
          "sev": "high"
        },
        {
          "id": "art-1609",
          "title": "CISA KEV: CVE-2023-41064 \u2014 Apple iOS, iPadOS, and macOS ImageIO Buffer Overflow Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-09-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-09-28"
    },
    {
      "value": "CVE-2023-41064",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "Snyk",
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1581",
          "title": "Critical WebP 0-day security CVE-2023-4863 impacts wider software ecosystem",
          "link": "https://snyk.io/blog/critical-webp-0-day-cve-2023-4863/",
          "published": "2023-09-28",
          "sev": "high"
        },
        {
          "id": "art-1609",
          "title": "CISA KEV: CVE-2023-41064 \u2014 Apple iOS, iPadOS, and macOS ImageIO Buffer Overflow Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-09-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-09-28"
    },
    {
      "value": "CVE-2023-4863",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "Snyk",
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1581",
          "title": "Critical WebP 0-day security CVE-2023-4863 impacts wider software ecosystem",
          "link": "https://snyk.io/blog/critical-webp-0-day-cve-2023-4863/",
          "published": "2023-09-28",
          "sev": "high"
        },
        {
          "id": "art-1604",
          "title": "CISA KEV: CVE-2023-4863 \u2014 Google Chromium WebP Heap-Based Buffer Overflow Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-09-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-09-28"
    },
    {
      "value": "CVE-2023-5129",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-1581",
          "title": "Critical WebP 0-day security CVE-2023-4863 impacts wider software ecosystem",
          "link": "https://snyk.io/blog/critical-webp-0-day-cve-2023-4863/",
          "published": "2023-09-28",
          "sev": "high"
        }
      ],
      "first_seen": "2023-09-28"
    },
    {
      "value": "CVE-2023-41991",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1585",
          "title": "CISA KEV: CVE-2023-41991 \u2014 Apple Multiple Products Improper Certificate Validation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-09-25",
          "sev": "crit"
        },
        {
          "id": "art-1586",
          "title": "CISA KEV: CVE-2023-41992 \u2014 Apple Multiple Products Kernel Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-09-25",
          "sev": "crit"
        },
        {
          "id": "art-1587",
          "title": "CISA KEV: CVE-2023-41993 \u2014 Apple Multiple Products WebKit Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-09-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-09-25"
    },
    {
      "value": "CVE-2023-41992",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1585",
          "title": "CISA KEV: CVE-2023-41991 \u2014 Apple Multiple Products Improper Certificate Validation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-09-25",
          "sev": "crit"
        },
        {
          "id": "art-1586",
          "title": "CISA KEV: CVE-2023-41992 \u2014 Apple Multiple Products Kernel Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-09-25",
          "sev": "crit"
        },
        {
          "id": "art-1587",
          "title": "CISA KEV: CVE-2023-41993 \u2014 Apple Multiple Products WebKit Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-09-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-09-25"
    },
    {
      "value": "CVE-2023-41993",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1585",
          "title": "CISA KEV: CVE-2023-41991 \u2014 Apple Multiple Products Improper Certificate Validation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-09-25",
          "sev": "crit"
        },
        {
          "id": "art-1586",
          "title": "CISA KEV: CVE-2023-41992 \u2014 Apple Multiple Products Kernel Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-09-25",
          "sev": "crit"
        },
        {
          "id": "art-1587",
          "title": "CISA KEV: CVE-2023-41993 \u2014 Apple Multiple Products WebKit Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-09-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-09-25"
    },
    {
      "value": "almal-news.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1585",
          "title": "CISA KEV: CVE-2023-41991 \u2014 Apple Multiple Products Improper Certificate Validation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-09-25",
          "sev": "crit"
        },
        {
          "id": "art-1586",
          "title": "CISA KEV: CVE-2023-41992 \u2014 Apple Multiple Products Kernel Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-09-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-09-25"
    },
    {
      "value": "betly.me",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1585",
          "title": "CISA KEV: CVE-2023-41991 \u2014 Apple Multiple Products Improper Certificate Validation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-09-25",
          "sev": "crit"
        },
        {
          "id": "art-1586",
          "title": "CISA KEV: CVE-2023-41992 \u2014 Apple Multiple Products Kernel Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-09-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-09-25"
    },
    {
      "value": "c.betly.me",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1585",
          "title": "CISA KEV: CVE-2023-41991 \u2014 Apple Multiple Products Improper Certificate Validation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-09-25",
          "sev": "crit"
        },
        {
          "id": "art-1586",
          "title": "CISA KEV: CVE-2023-41992 \u2014 Apple Multiple Products Kernel Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-09-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-09-25"
    },
    {
      "value": "chat-support.support",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1585",
          "title": "CISA KEV: CVE-2023-41991 \u2014 Apple Multiple Products Improper Certificate Validation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-09-25",
          "sev": "crit"
        },
        {
          "id": "art-1586",
          "title": "CISA KEV: CVE-2023-41992 \u2014 Apple Multiple Products Kernel Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-09-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-09-25"
    },
    {
      "value": "cibeg.online",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1585",
          "title": "CISA KEV: CVE-2023-41991 \u2014 Apple Multiple Products Improper Certificate Validation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-09-25",
          "sev": "crit"
        },
        {
          "id": "art-1586",
          "title": "CISA KEV: CVE-2023-41992 \u2014 Apple Multiple Products Kernel Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-09-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-09-25"
    },
    {
      "value": "notifications-sec.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1585",
          "title": "CISA KEV: CVE-2023-41991 \u2014 Apple Multiple Products Improper Certificate Validation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-09-25",
          "sev": "crit"
        },
        {
          "id": "art-1586",
          "title": "CISA KEV: CVE-2023-41992 \u2014 Apple Multiple Products Kernel Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-09-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-09-25"
    },
    {
      "value": "sec-flare.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1585",
          "title": "CISA KEV: CVE-2023-41991 \u2014 Apple Multiple Products Improper Certificate Validation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-09-25",
          "sev": "crit"
        },
        {
          "id": "art-1586",
          "title": "CISA KEV: CVE-2023-41992 \u2014 Apple Multiple Products Kernel Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-09-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-09-25"
    },
    {
      "value": "t-bit.me",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1585",
          "title": "CISA KEV: CVE-2023-41991 \u2014 Apple Multiple Products Improper Certificate Validation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-09-25",
          "sev": "crit"
        },
        {
          "id": "art-1586",
          "title": "CISA KEV: CVE-2023-41992 \u2014 Apple Multiple Products Kernel Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-09-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-09-25"
    },
    {
      "value": "verifyurl.me",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1585",
          "title": "CISA KEV: CVE-2023-41991 \u2014 Apple Multiple Products Improper Certificate Validation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-09-25",
          "sev": "crit"
        },
        {
          "id": "art-1586",
          "title": "CISA KEV: CVE-2023-41992 \u2014 Apple Multiple Products Kernel Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-09-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-09-25"
    },
    {
      "value": "wa-info.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1585",
          "title": "CISA KEV: CVE-2023-41991 \u2014 Apple Multiple Products Improper Certificate Validation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-09-25",
          "sev": "crit"
        },
        {
          "id": "art-1586",
          "title": "CISA KEV: CVE-2023-41992 \u2014 Apple Multiple Products Kernel Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-09-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-09-25"
    },
    {
      "value": "whatssapp.co",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1585",
          "title": "CISA KEV: CVE-2023-41991 \u2014 Apple Multiple Products Improper Certificate Validation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-09-25",
          "sev": "crit"
        },
        {
          "id": "art-1586",
          "title": "CISA KEV: CVE-2023-41992 \u2014 Apple Multiple Products Kernel Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-09-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-09-25"
    },
    {
      "value": "wts-app.info",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1585",
          "title": "CISA KEV: CVE-2023-41991 \u2014 Apple Multiple Products Improper Certificate Validation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-09-25",
          "sev": "crit"
        },
        {
          "id": "art-1586",
          "title": "CISA KEV: CVE-2023-41992 \u2014 Apple Multiple Products Kernel Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-09-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-09-25"
    },
    {
      "value": "41.206.153.241",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1585",
          "title": "CISA KEV: CVE-2023-41991 \u2014 Apple Multiple Products Improper Certificate Validation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-09-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-09-25"
    },
    {
      "value": "7af95e7782a807967508a25c6709bd7a2686378b47fab56ccb23341324b7fe40",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1585",
          "title": "CISA KEV: CVE-2023-41991 \u2014 Apple Multiple Products Improper Certificate Validation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-09-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-09-25"
    },
    {
      "value": "85d8f504cadb55851a393a13a026f1833ed6db32cb07882415e029e709ae0750",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1585",
          "title": "CISA KEV: CVE-2023-41991 \u2014 Apple Multiple Products Improper Certificate Validation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-09-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-09-25"
    },
    {
      "value": "e3314bcd085bd547d9b977351ab72a8b83093c47a73eb5502db4b98e0db42cac",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1585",
          "title": "CISA KEV: CVE-2023-41991 \u2014 Apple Multiple Products Improper Certificate Validation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-09-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-09-25"
    },
    {
      "value": "CVE-2023-41179",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1589",
          "title": "CISA KEV: CVE-2023-41179 \u2014 Trend Micro Apex One and Worry-Free Business Security Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-09-21",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-09-21"
    },
    {
      "value": "CVE-2023-28434",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1592",
          "title": "CISA KEV: CVE-2023-28434 \u2014 MinIO Security Feature Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-09-19",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-09-19"
    },
    {
      "value": "CVE-2017-6884",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1596",
          "title": "CISA KEV: CVE-2017-6884 \u2014 Zyxel EMG2926 Routers Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-09-18",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-09-18"
    },
    {
      "value": "CVE-2021-3129",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1597",
          "title": "CISA KEV: CVE-2021-3129 \u2014 Laravel Ignition File Upload Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-09-18",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-09-18"
    },
    {
      "value": "CVE-2022-22265",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1594",
          "title": "CISA KEV: CVE-2022-22265 \u2014 Samsung Mobile Devices Use-After-Free Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-09-18",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-09-18"
    },
    {
      "value": "CVE-2023-26369",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1599",
          "title": "CISA KEV: CVE-2023-26369 \u2014 Adobe Acrobat and Reader Out-of-Bounds Write Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-09-14",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-09-14"
    },
    {
      "value": "CVE-2023-20269",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1603",
          "title": "CISA KEV: CVE-2023-20269 \u2014 Cisco Adaptive Security Appliance and Firepower Threat Defense Unauthorized Access Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-09-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-09-13"
    },
    {
      "value": "CVE-2023-35674",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1602",
          "title": "CISA KEV: CVE-2023-35674 \u2014 Android Framework Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-09-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-09-13"
    },
    {
      "value": "CVE-2023-36761",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1606",
          "title": "CISA KEV: CVE-2023-36761 \u2014 Microsoft Word Information Disclosure Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-09-12",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-09-12"
    },
    {
      "value": "CVE-2023-36802",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1607",
          "title": "CISA KEV: CVE-2023-36802 \u2014 Microsoft Streaming Service Proxy Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-09-12",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-09-12"
    },
    {
      "value": "CVE-2023-33246",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1612",
          "title": "CISA KEV: CVE-2023-33246 \u2014 Apache RocketMQ Command Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-09-06",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-09-06"
    },
    {
      "value": "103.85.25.121",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1612",
          "title": "CISA KEV: CVE-2023-33246 \u2014 Apache RocketMQ Command Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-09-06",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-09-06"
    },
    {
      "value": "134.209.58.230",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1612",
          "title": "CISA KEV: CVE-2023-33246 \u2014 Apache RocketMQ Command Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-09-06",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-09-06"
    },
    {
      "value": "45.15.158.124",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1612",
          "title": "CISA KEV: CVE-2023-33246 \u2014 Apache RocketMQ Command Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-09-06",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-09-06"
    },
    {
      "value": "94.156.6.110",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1612",
          "title": "CISA KEV: CVE-2023-33246 \u2014 Apache RocketMQ Command Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-09-06",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-09-06"
    },
    {
      "value": "1d489a41395be76a8101c2e1eba383253a291f4e84a9da389c6b58913786b8ac",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1612",
          "title": "CISA KEV: CVE-2023-33246 \u2014 Apache RocketMQ Command Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-09-06",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-09-06"
    },
    {
      "value": "49062378ab3e4a0d78c6db662efb4dbc680808fb75834b4674809bc8903adaea",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1612",
          "title": "CISA KEV: CVE-2023-33246 \u2014 Apache RocketMQ Command Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-09-06",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-09-06"
    },
    {
      "value": "4feb3dcfe57e3b112568ddd1897b68aeb134ef8addd27b660530442ea1e49cbb",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1612",
          "title": "CISA KEV: CVE-2023-33246 \u2014 Apache RocketMQ Command Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-09-06",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-09-06"
    },
    {
      "value": "d7843904e1c25055e14cae8b44b28f9dd4706c0ad8b03f55dfcded36ce8423a0",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1612",
          "title": "CISA KEV: CVE-2023-33246 \u2014 Apache RocketMQ Command Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-09-06",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-09-06"
    },
    {
      "value": "f93e9bc9583058d82d2d3fe35117cbb9a553d54e7149846b2dc94446f0836201",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1612",
          "title": "CISA KEV: CVE-2023-33246 \u2014 Apache RocketMQ Command Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-09-06",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-09-06"
    },
    {
      "value": "CVE-2023-32315",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1622",
          "title": "CISA KEV: CVE-2023-32315 \u2014 Ignite Realtime Openfire Path Traversal Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-08-24",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-08-24"
    },
    {
      "value": "CVE-2023-27532",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1626",
          "title": "CISA KEV: CVE-2023-27532 \u2014 Veeam Backup & Replication Cloud Connect Missing Authentication for Critical Function Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-08-22",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-08-22"
    },
    {
      "value": "CVE-2023-38035",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1625",
          "title": "CISA KEV: CVE-2023-38035 \u2014 Ivanti Sentry Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-08-22",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-08-22"
    },
    {
      "value": "149.28.106.252",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1626",
          "title": "CISA KEV: CVE-2023-27532 \u2014 Veeam Backup & Replication Cloud Connect Missing Authentication for Critical Function Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-08-22",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-08-22"
    },
    {
      "value": "149.28.99.61",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1626",
          "title": "CISA KEV: CVE-2023-27532 \u2014 Veeam Backup & Replication Cloud Connect Missing Authentication for Critical Function Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-08-22",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-08-22"
    },
    {
      "value": "162.248.225.115",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1626",
          "title": "CISA KEV: CVE-2023-27532 \u2014 Veeam Backup & Replication Cloud Connect Missing Authentication for Critical Function Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-08-22",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-08-22"
    },
    {
      "value": "194.87.148.41",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1626",
          "title": "CISA KEV: CVE-2023-27532 \u2014 Veeam Backup & Replication Cloud Connect Missing Authentication for Critical Function Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-08-22",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-08-22"
    },
    {
      "value": "195.123.244.162",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1626",
          "title": "CISA KEV: CVE-2023-27532 \u2014 Veeam Backup & Replication Cloud Connect Missing Authentication for Critical Function Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-08-22",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-08-22"
    },
    {
      "value": "217.12.206.176",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1626",
          "title": "CISA KEV: CVE-2023-27532 \u2014 Veeam Backup & Replication Cloud Connect Missing Authentication for Critical Function Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-08-22",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-08-22"
    },
    {
      "value": "45.136.199.128",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1626",
          "title": "CISA KEV: CVE-2023-27532 \u2014 Veeam Backup & Replication Cloud Connect Missing Authentication for Critical Function Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-08-22",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-08-22"
    },
    {
      "value": "45.76.232.205",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1626",
          "title": "CISA KEV: CVE-2023-27532 \u2014 Veeam Backup & Replication Cloud Connect Missing Authentication for Critical Function Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-08-22",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-08-22"
    },
    {
      "value": "77.238.245.11",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1626",
          "title": "CISA KEV: CVE-2023-27532 \u2014 Veeam Backup & Replication Cloud Connect Missing Authentication for Critical Function Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-08-22",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-08-22"
    },
    {
      "value": "77.75.230.112",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1626",
          "title": "CISA KEV: CVE-2023-27532 \u2014 Veeam Backup & Replication Cloud Connect Missing Authentication for Critical Function Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-08-22",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-08-22"
    },
    {
      "value": "91.149.243.181",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1626",
          "title": "CISA KEV: CVE-2023-27532 \u2014 Veeam Backup & Replication Cloud Connect Missing Authentication for Critical Function Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-08-22",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-08-22"
    },
    {
      "value": "91.199.147.152",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1626",
          "title": "CISA KEV: CVE-2023-27532 \u2014 Veeam Backup & Replication Cloud Connect Missing Authentication for Critical Function Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-08-22",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-08-22"
    },
    {
      "value": "95.217.49.123",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1626",
          "title": "CISA KEV: CVE-2023-27532 \u2014 Veeam Backup & Replication Cloud Connect Missing Authentication for Critical Function Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-08-22",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-08-22"
    },
    {
      "value": "107EC3A7ED7AD908774AD18E3E03D4B999D4690C",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1626",
          "title": "CISA KEV: CVE-2023-27532 \u2014 Veeam Backup & Replication Cloud Connect Missing Authentication for Critical Function Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-08-22",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-08-22"
    },
    {
      "value": "2C56E9BEEA9F0801E0110A7DC5549B4FA0661362",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1626",
          "title": "CISA KEV: CVE-2023-27532 \u2014 Veeam Backup & Replication Cloud Connect Missing Authentication for Critical Function Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-08-22",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-08-22"
    },
    {
      "value": "5E460A517F0579B831B09EC99EF158AC0DD3D4FA",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1626",
          "title": "CISA KEV: CVE-2023-27532 \u2014 Veeam Backup & Replication Cloud Connect Missing Authentication for Critical Function Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-08-22",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-08-22"
    },
    {
      "value": "8687B6B1508A93556D6E30D14E5C4EE9971F2D80",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1626",
          "title": "CISA KEV: CVE-2023-27532 \u2014 Veeam Backup & Replication Cloud Connect Missing Authentication for Critical Function Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-08-22",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-08-22"
    },
    {
      "value": "B621F8C5E9033718B4E9D47A2F0ECCB9783F612A",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1626",
          "title": "CISA KEV: CVE-2023-27532 \u2014 Veeam Backup & Replication Cloud Connect Missing Authentication for Critical Function Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-08-22",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-08-22"
    },
    {
      "value": "CB704D2E8DF80FD3500A5B817966DC262D80DDB8",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1626",
          "title": "CISA KEV: CVE-2023-27532 \u2014 Veeam Backup & Replication Cloud Connect Missing Authentication for Critical Function Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-08-22",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-08-22"
    },
    {
      "value": "E5480A47172E3F75DBF0384F4CA82C7B47910E0F",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1626",
          "title": "CISA KEV: CVE-2023-27532 \u2014 Veeam Backup & Replication Cloud Connect Missing Authentication for Critical Function Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-08-22",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-08-22"
    },
    {
      "value": "CVE-2023-24489",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1630",
          "title": "CISA KEV: CVE-2023-24489 \u2014 Citrix Content Collaboration ShareFile Improper Access Control Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-08-16",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-08-16"
    },
    {
      "value": "CVE-2023-38180",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1635",
          "title": "CISA KEV: CVE-2023-38180 \u2014 Microsoft .NET Core and Visual Studio Denial-of-Service Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-08-09",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-08-09"
    },
    {
      "value": "CVE-2022-229",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-1634",
          "title": "Manage security issues in Jira with Snyk Security in Jira Cloud",
          "link": "https://snyk.io/blog/snyk-security-in-jira-cloud/",
          "published": "2023-08-09",
          "sev": "high"
        }
      ],
      "first_seen": "2023-08-09"
    },
    {
      "value": "CVE-2022-22967",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-1634",
          "title": "Manage security issues in Jira with Snyk Security in Jira Cloud",
          "link": "https://snyk.io/blog/snyk-security-in-jira-cloud/",
          "published": "2023-08-09",
          "sev": "high"
        }
      ],
      "first_seen": "2023-08-09"
    },
    {
      "value": "cdn.devlooped.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-1633",
          "title": ".NET developers alert: Moq NuGET package exfiltrates user emails from git",
          "link": "https://snyk.io/blog/moq-package-exfiltrates-user-emails/",
          "published": "2023-08-09",
          "sev": "high"
        }
      ],
      "first_seen": "2023-08-09"
    },
    {
      "value": "CVE-2023-37580",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1650",
          "title": "CISA KEV: CVE-2023-37580 \u2014 Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting (XSS) Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-07-27",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-07-27"
    },
    {
      "value": "applicationdevsoc.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1650",
          "title": "CISA KEV: CVE-2023-37580 \u2014 Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting (XSS) Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-07-27",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-07-27"
    },
    {
      "value": "ntcpk.org",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1650",
          "title": "CISA KEV: CVE-2023-37580 \u2014 Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting (XSS) Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-07-27",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-07-27"
    },
    {
      "value": "obsorth.opwtjnpoc.ml",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1650",
          "title": "CISA KEV: CVE-2023-37580 \u2014 Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting (XSS) Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-07-27",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-07-27"
    },
    {
      "value": "CVE-2023-3519",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1660",
          "title": "CISA KEV: CVE-2023-3519 \u2014 Citrix NetScaler ADC and NetScaler Gateway Code Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-07-19",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-07-19"
    },
    {
      "value": "216.41.162.172",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1660",
          "title": "CISA KEV: CVE-2023-3519 \u2014 Citrix NetScaler ADC and NetScaler Gateway Code Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-07-19",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-07-19"
    },
    {
      "value": "216.51.171.17",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1660",
          "title": "CISA KEV: CVE-2023-3519 \u2014 Citrix NetScaler ADC and NetScaler Gateway Code Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-07-19",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-07-19"
    },
    {
      "value": "293fe23849cffb460e8d28691c640a5292fd4649b0f94a019b45cc586be83fd9",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1660",
          "title": "CISA KEV: CVE-2023-3519 \u2014 Citrix NetScaler ADC and NetScaler Gateway Code Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-07-19",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-07-19"
    },
    {
      "value": "104.234.239.26",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1664",
          "title": "CISA KEV: CVE-2023-36884 \u2014 Microsoft Windows Search Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-07-17",
          "sev": "crit"
        },
        {
          "id": "art-1671",
          "title": "CISA KEV: CVE-2023-32049 \u2014 Microsoft Windows Defender SmartScreen Security Feature Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-07-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-07-17"
    },
    {
      "value": "a61b2eafcf39715031357df6b01e85e0d1ea2e8ee1dfec241b114e18f7a1163f",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1664",
          "title": "CISA KEV: CVE-2023-36884 \u2014 Microsoft Windows Search Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-07-17",
          "sev": "crit"
        },
        {
          "id": "art-1671",
          "title": "CISA KEV: CVE-2023-32049 \u2014 Microsoft Windows Defender SmartScreen Security Feature Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-07-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-07-17"
    },
    {
      "value": "e7cfeb023c3160a7366f209a16a6f6ea5a0bc9a3ddc16c6cba758114dfe6b539",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1664",
          "title": "CISA KEV: CVE-2023-36884 \u2014 Microsoft Windows Search Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-07-17",
          "sev": "crit"
        },
        {
          "id": "art-1671",
          "title": "CISA KEV: CVE-2023-32049 \u2014 Microsoft Windows Defender SmartScreen Security Feature Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-07-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-07-17"
    },
    {
      "value": "CVE-2022-29303",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1666",
          "title": "CISA KEV: CVE-2022-29303 \u2014 SolarView Compact Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-07-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-07-13"
    },
    {
      "value": "CVE-2022-31374",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1666",
          "title": "CISA KEV: CVE-2022-29303 \u2014 SolarView Compact Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-07-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-07-13"
    },
    {
      "value": "CVE-2022-44354",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1666",
          "title": "CISA KEV: CVE-2022-29303 \u2014 SolarView Compact Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-07-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-07-13"
    },
    {
      "value": "CVE-2023-23333",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1666",
          "title": "CISA KEV: CVE-2022-29303 \u2014 SolarView Compact Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-07-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-07-13"
    },
    {
      "value": "CVE-2023-37450",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1667",
          "title": "CISA KEV: CVE-2023-37450 \u2014 Apple Multiple Products WebKit Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-07-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-07-13"
    },
    {
      "value": "CVE-2022-31199",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1674",
          "title": "CISA KEV: CVE-2022-31199 \u2014 Netwrix Auditor Insecure Object Deserialization Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-07-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-07-11"
    },
    {
      "value": "CVE-2023-32046",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1670",
          "title": "CISA KEV: CVE-2023-32046 \u2014 Microsoft Windows MSHTML Platform Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-07-11",
          "sev": "crit"
        },
        {
          "id": "art-1673",
          "title": "CISA KEV: CVE-2023-36874 \u2014 Microsoft Windows Error Reporting Service Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-07-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-07-11"
    },
    {
      "value": "CVE-2023-32049",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1671",
          "title": "CISA KEV: CVE-2023-32049 \u2014 Microsoft Windows Defender SmartScreen Security Feature Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-07-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-07-11"
    },
    {
      "value": "CVE-2023-35311",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1671",
          "title": "CISA KEV: CVE-2023-32049 \u2014 Microsoft Windows Defender SmartScreen Security Feature Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-07-11",
          "sev": "crit"
        },
        {
          "id": "art-1672",
          "title": "CISA KEV: CVE-2023-35311 \u2014 Microsoft Outlook Security Feature Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-07-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-07-11"
    },
    {
      "value": "CVE-2023-36874",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1673",
          "title": "CISA KEV: CVE-2023-36874 \u2014 Microsoft Windows Error Reporting Service Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-07-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-07-11"
    },
    {
      "value": "66.23.226.102",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1671",
          "title": "CISA KEV: CVE-2023-32049 \u2014 Microsoft Windows Defender SmartScreen Security Feature Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-07-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-07-11"
    },
    {
      "value": "74.50.94.156",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1671",
          "title": "CISA KEV: CVE-2023-32049 \u2014 Microsoft Windows Defender SmartScreen Security Feature Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-07-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-07-11"
    },
    {
      "value": "94.232.40.34",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1671",
          "title": "CISA KEV: CVE-2023-32049 \u2014 Microsoft Windows Defender SmartScreen Security Feature Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-07-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-07-11"
    },
    {
      "value": "07377209fe68a98e9bca310d9749daa4eb79558e9fc419cf0b02a9e37679038d",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1671",
          "title": "CISA KEV: CVE-2023-32049 \u2014 Microsoft Windows Defender SmartScreen Security Feature Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-07-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-07-11"
    },
    {
      "value": "1a7bb878c826fe0ca9a0677ed072ee9a57a228a09ee02b3c5bd00f54f354930f",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1671",
          "title": "CISA KEV: CVE-2023-32049 \u2014 Microsoft Windows Defender SmartScreen Security Feature Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-07-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-07-11"
    },
    {
      "value": "3a3138c5add59d2172ad33bc6761f2f82ba344f3d03a2269c623f22c1a35df97",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1671",
          "title": "CISA KEV: CVE-2023-32049 \u2014 Microsoft Windows Defender SmartScreen Security Feature Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-07-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-07-11"
    },
    {
      "value": "CVE-2021-29256",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1675",
          "title": "CISA KEV: CVE-2021-29256 \u2014 Arm Mali GPU Kernel Driver Use-After-Free Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-07-07",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-07-07"
    },
    {
      "value": "CVE-2019-17621",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1678",
          "title": "CISA KEV: CVE-2019-17621 \u2014 D-Link DIR-859 Router Command Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-06-29",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-06-29"
    },
    {
      "value": "CVE-2019-20500",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1679",
          "title": "CISA KEV: CVE-2019-20500 \u2014 D-Link DWL-2600AP Access Point Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-06-29",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-06-29"
    },
    {
      "value": "CVE-2021-25371",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1684",
          "title": "CISA KEV: CVE-2021-25371 \u2014 Samsung Mobile Devices Unspecified Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-06-29",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-06-29"
    },
    {
      "value": "CVE-2021-25372",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1685",
          "title": "CISA KEV: CVE-2021-25372 \u2014 Samsung Mobile Devices Improper Boundary Check Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-06-29",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-06-29"
    },
    {
      "value": "CVE-2021-25394",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1682",
          "title": "CISA KEV: CVE-2021-25394 \u2014 Samsung Mobile Devices Race Condition Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-06-29",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-06-29"
    },
    {
      "value": "CVE-2021-25395",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1683",
          "title": "CISA KEV: CVE-2021-25395 \u2014 Samsung Mobile Devices Race Condition Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-06-29",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-06-29"
    },
    {
      "value": "CVE-2021-25487",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1680",
          "title": "CISA KEV: CVE-2021-25487 \u2014 Samsung Mobile Devices Out-of-Bounds Read Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-06-29",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-06-29"
    },
    {
      "value": "CVE-2021-25489",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1681",
          "title": "CISA KEV: CVE-2021-25489 \u2014 Samsung Mobile Devices Improper Input Validation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-06-29",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-06-29"
    },
    {
      "value": "CVE-2023-27992",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1694",
          "title": "CISA KEV: CVE-2023-27992 \u2014 Zyxel Multiple NAS Devices Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-06-23",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-06-23"
    },
    {
      "value": "CVE-2023-32439",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1692",
          "title": "CISA KEV: CVE-2023-32439 \u2014 Apple Multiple Products WebKit Type Confusion Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-06-23",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-06-23"
    },
    {
      "value": "backuprabbit.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1690",
          "title": "CISA KEV: CVE-2023-32434 \u2014 Apple Multiple Products Integer Overflow Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-06-23",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-06-23"
    },
    {
      "value": "cloudsponcer.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1690",
          "title": "CISA KEV: CVE-2023-32434 \u2014 Apple Multiple Products Integer Overflow Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-06-23",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-06-23"
    },
    {
      "value": "snoweeanalytics.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1690",
          "title": "CISA KEV: CVE-2023-32434 \u2014 Apple Multiple Products Integer Overflow Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-06-23",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-06-23"
    },
    {
      "value": "topographyupdates.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1690",
          "title": "CISA KEV: CVE-2023-32434 \u2014 Apple Multiple Products Integer Overflow Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-06-23",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-06-23"
    },
    {
      "value": "unlimitedteacup.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1690",
          "title": "CISA KEV: CVE-2023-32434 \u2014 Apple Multiple Products Integer Overflow Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-06-23",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-06-23"
    },
    {
      "value": "virtuallaughing.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1690",
          "title": "CISA KEV: CVE-2023-32434 \u2014 Apple Multiple Products Integer Overflow Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-06-23",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-06-23"
    },
    {
      "value": "CVE-2016-0165",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1702",
          "title": "CISA KEV: CVE-2016-0165 \u2014 Microsoft Win32k Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-06-22",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-06-22"
    },
    {
      "value": "CVE-2016-9079",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1701",
          "title": "CISA KEV: CVE-2016-9079 \u2014 Mozilla Firefox, Firefox ESR, and Thunderbird Use-After-Free Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-06-22",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-06-22"
    },
    {
      "value": "CVE-2023-20887",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1697",
          "title": "CISA KEV: CVE-2023-20887 \u2014 Vmware Aria Operations for Networks Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-06-22",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-06-22"
    },
    {
      "value": "CVE-2022-1471",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-1703",
          "title": "SnakeYaml 2.0: Solving the unsafe deserialization vulnerability",
          "link": "https://snyk.io/blog/snakeyaml-unsafe-deserialization-vulnerability/",
          "published": "2023-06-21",
          "sev": "crit"
        },
        {
          "id": "art-1909",
          "title": "Unsafe deserialization vulnerability in SnakeYaml (CVE-2022-1471)",
          "link": "https://snyk.io/blog/unsafe-deserialization-snakeyaml-java-cve-2022-1471/",
          "published": "2022-12-14",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-06-21"
    },
    {
      "value": "CVE-2023-3079",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1718",
          "title": "CISA KEV: CVE-2023-3079 \u2014 Google Chromium V8 Type Confusion Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-06-07",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-06-07"
    },
    {
      "value": "CVE-2023-33009",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1722",
          "title": "CISA KEV: CVE-2023-33009 \u2014 Zyxel Multiple Firewalls Buffer Overflow Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-06-05",
          "sev": "crit"
        },
        {
          "id": "art-1723",
          "title": "CISA KEV: CVE-2023-33010 \u2014 Zyxel Multiple Firewalls Buffer Overflow Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-06-05",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-06-05"
    },
    {
      "value": "CVE-2023-33010",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1722",
          "title": "CISA KEV: CVE-2023-33009 \u2014 Zyxel Multiple Firewalls Buffer Overflow Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-06-05",
          "sev": "crit"
        },
        {
          "id": "art-1723",
          "title": "CISA KEV: CVE-2023-33010 \u2014 Zyxel Multiple Firewalls Buffer Overflow Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-06-05",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-06-05"
    },
    {
      "value": "0b3220b11698b1436d1d866ac07cc90018e59884e91a8cb71ef8924309f1e0e9",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1724",
          "title": "CISA KEV: CVE-2023-34362 \u2014 Progress MOVEit Transfer SQL Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-06-02",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-06-02"
    },
    {
      "value": "CVE-2023-28771",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1727",
          "title": "CISA KEV: CVE-2023-28771 \u2014 Zyxel Multiple Firewalls OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-05-31",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-05-31"
    },
    {
      "value": "101.229.146.218",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1730",
          "title": "CISA KEV: CVE-2023-2868 \u2014 Barracuda Networks ESG Appliance Improper Input Validation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-05-26",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-05-26"
    },
    {
      "value": "103.146.179.101",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1730",
          "title": "CISA KEV: CVE-2023-2868 \u2014 Barracuda Networks ESG Appliance Improper Input Validation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-05-26",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-05-26"
    },
    {
      "value": "103.27.108.62",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1730",
          "title": "CISA KEV: CVE-2023-2868 \u2014 Barracuda Networks ESG Appliance Improper Input Validation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-05-26",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-05-26"
    },
    {
      "value": "103.77.192.13",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1730",
          "title": "CISA KEV: CVE-2023-2868 \u2014 Barracuda Networks ESG Appliance Improper Input Validation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-05-26",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-05-26"
    },
    {
      "value": "103.77.192.88",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1730",
          "title": "CISA KEV: CVE-2023-2868 \u2014 Barracuda Networks ESG Appliance Improper Input Validation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-05-26",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-05-26"
    },
    {
      "value": "103.93.78.142",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1730",
          "title": "CISA KEV: CVE-2023-2868 \u2014 Barracuda Networks ESG Appliance Improper Input Validation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-05-26",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-05-26"
    },
    {
      "value": "104.156.229.226",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1730",
          "title": "CISA KEV: CVE-2023-2868 \u2014 Barracuda Networks ESG Appliance Improper Input Validation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-05-26",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-05-26"
    },
    {
      "value": "104.223.20.222",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1730",
          "title": "CISA KEV: CVE-2023-2868 \u2014 Barracuda Networks ESG Appliance Improper Input Validation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-05-26",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-05-26"
    },
    {
      "value": "107.148.149.156",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1730",
          "title": "CISA KEV: CVE-2023-2868 \u2014 Barracuda Networks ESG Appliance Improper Input Validation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-05-26",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-05-26"
    },
    {
      "value": "107.148.219.227",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1730",
          "title": "CISA KEV: CVE-2023-2868 \u2014 Barracuda Networks ESG Appliance Improper Input Validation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-05-26",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-05-26"
    },
    {
      "value": "107.148.219.53",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1730",
          "title": "CISA KEV: CVE-2023-2868 \u2014 Barracuda Networks ESG Appliance Improper Input Validation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-05-26",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-05-26"
    },
    {
      "value": "107.148.219.54",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1730",
          "title": "CISA KEV: CVE-2023-2868 \u2014 Barracuda Networks ESG Appliance Improper Input Validation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-05-26",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-05-26"
    },
    {
      "value": "107.148.219.55",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1730",
          "title": "CISA KEV: CVE-2023-2868 \u2014 Barracuda Networks ESG Appliance Improper Input Validation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-05-26",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-05-26"
    },
    {
      "value": "107.148.223.196",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1730",
          "title": "CISA KEV: CVE-2023-2868 \u2014 Barracuda Networks ESG Appliance Improper Input Validation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-05-26",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-05-26"
    },
    {
      "value": "107.173.62.158",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1730",
          "title": "CISA KEV: CVE-2023-2868 \u2014 Barracuda Networks ESG Appliance Improper Input Validation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-05-26",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-05-26"
    },
    {
      "value": "137.175.19.25",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1730",
          "title": "CISA KEV: CVE-2023-2868 \u2014 Barracuda Networks ESG Appliance Improper Input Validation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-05-26",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-05-26"
    },
    {
      "value": "137.175.28.251",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1730",
          "title": "CISA KEV: CVE-2023-2868 \u2014 Barracuda Networks ESG Appliance Improper Input Validation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-05-26",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-05-26"
    },
    {
      "value": "137.175.30.36",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1730",
          "title": "CISA KEV: CVE-2023-2868 \u2014 Barracuda Networks ESG Appliance Improper Input Validation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-05-26",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-05-26"
    },
    {
      "value": "137.175.30.86",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1730",
          "title": "CISA KEV: CVE-2023-2868 \u2014 Barracuda Networks ESG Appliance Improper Input Validation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-05-26",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-05-26"
    },
    {
      "value": "137.175.51.147",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1730",
          "title": "CISA KEV: CVE-2023-2868 \u2014 Barracuda Networks ESG Appliance Improper Input Validation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-05-26",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-05-26"
    },
    {
      "value": "137.175.53.17",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1730",
          "title": "CISA KEV: CVE-2023-2868 \u2014 Barracuda Networks ESG Appliance Improper Input Validation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-05-26",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-05-26"
    },
    {
      "value": "137.175.53.170",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1730",
          "title": "CISA KEV: CVE-2023-2868 \u2014 Barracuda Networks ESG Appliance Improper Input Validation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-05-26",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-05-26"
    },
    {
      "value": "137.175.53.218",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1730",
          "title": "CISA KEV: CVE-2023-2868 \u2014 Barracuda Networks ESG Appliance Improper Input Validation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-05-26",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-05-26"
    },
    {
      "value": "137.175.60.252",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1730",
          "title": "CISA KEV: CVE-2023-2868 \u2014 Barracuda Networks ESG Appliance Improper Input Validation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-05-26",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-05-26"
    },
    {
      "value": "137.175.60.253",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1730",
          "title": "CISA KEV: CVE-2023-2868 \u2014 Barracuda Networks ESG Appliance Improper Input Validation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-05-26",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-05-26"
    },
    {
      "value": "137.175.78.66",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1730",
          "title": "CISA KEV: CVE-2023-2868 \u2014 Barracuda Networks ESG Appliance Improper Input Validation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-05-26",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-05-26"
    },
    {
      "value": "139.84.227.9",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1730",
          "title": "CISA KEV: CVE-2023-2868 \u2014 Barracuda Networks ESG Appliance Improper Input Validation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-05-26",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-05-26"
    },
    {
      "value": "155.94.160.72",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1730",
          "title": "CISA KEV: CVE-2023-2868 \u2014 Barracuda Networks ESG Appliance Improper Input Validation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-05-26",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-05-26"
    },
    {
      "value": "182.239.114.135",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1730",
          "title": "CISA KEV: CVE-2023-2868 \u2014 Barracuda Networks ESG Appliance Improper Input Validation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-05-26",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-05-26"
    },
    {
      "value": "192.74.226.142",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1730",
          "title": "CISA KEV: CVE-2023-2868 \u2014 Barracuda Networks ESG Appliance Improper Input Validation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-05-26",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-05-26"
    },
    {
      "value": "0d67f50a0bf7a3a017784146ac41ada0",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1730",
          "title": "CISA KEV: CVE-2023-2868 \u2014 Barracuda Networks ESG Appliance Improper Input Validation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-05-26",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-05-26"
    },
    {
      "value": "177add288b289d43236d2dba33e65956",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1730",
          "title": "CISA KEV: CVE-2023-2868 \u2014 Barracuda Networks ESG Appliance Improper Input Validation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-05-26",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-05-26"
    },
    {
      "value": "1fea55b7c9d13d822a64b2370d015da7",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1730",
          "title": "CISA KEV: CVE-2023-2868 \u2014 Barracuda Networks ESG Appliance Improper Input Validation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-05-26",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-05-26"
    },
    {
      "value": "2ccb9759800154de817bf779a52d48f8",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1730",
          "title": "CISA KEV: CVE-2023-2868 \u2014 Barracuda Networks ESG Appliance Improper Input Validation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-05-26",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-05-26"
    },
    {
      "value": "35cf6faf442d325961935f660e2ab5a0",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1730",
          "title": "CISA KEV: CVE-2023-2868 \u2014 Barracuda Networks ESG Appliance Improper Input Validation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-05-26",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-05-26"
    },
    {
      "value": "3b93b524db66f8bb3df8279a141734bb",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1730",
          "title": "CISA KEV: CVE-2023-2868 \u2014 Barracuda Networks ESG Appliance Improper Input Validation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-05-26",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-05-26"
    },
    {
      "value": "407738e565b4e9dafb07b782ebcf46b0",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1730",
          "title": "CISA KEV: CVE-2023-2868 \u2014 Barracuda Networks ESG Appliance Improper Input Validation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-05-26",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-05-26"
    },
    {
      "value": "42722b7d04f58dcb8bd80fe41c7ea09e",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1730",
          "title": "CISA KEV: CVE-2023-2868 \u2014 Barracuda Networks ESG Appliance Improper Input Validation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-05-26",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-05-26"
    },
    {
      "value": "436587bad5e061a7e594f9971d89c468",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1730",
          "title": "CISA KEV: CVE-2023-2868 \u2014 Barracuda Networks ESG Appliance Improper Input Validation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-05-26",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-05-26"
    },
    {
      "value": "4ca4f582418b2cc0626700511a6315c0",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1730",
          "title": "CISA KEV: CVE-2023-2868 \u2014 Barracuda Networks ESG Appliance Improper Input Validation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-05-26",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-05-26"
    },
    {
      "value": "5392fb400bd671d4b185fb35a9b23fd3",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1730",
          "title": "CISA KEV: CVE-2023-2868 \u2014 Barracuda Networks ESG Appliance Improper Input Validation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-05-26",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-05-26"
    },
    {
      "value": "5d6cba7909980a7b424b133fbac634ac",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1730",
          "title": "CISA KEV: CVE-2023-2868 \u2014 Barracuda Networks ESG Appliance Improper Input Validation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-05-26",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-05-26"
    },
    {
      "value": "5fdee67c82f5480edfa54afc5a9dc834",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1730",
          "title": "CISA KEV: CVE-2023-2868 \u2014 Barracuda Networks ESG Appliance Improper Input Validation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-05-26",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-05-26"
    },
    {
      "value": "666da297066a2596cacb13b3da9572bf",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1730",
          "title": "CISA KEV: CVE-2023-2868 \u2014 Barracuda Networks ESG Appliance Improper Input Validation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-05-26",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-05-26"
    },
    {
      "value": "694cdb49879f1321abb4605adf634935",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1730",
          "title": "CISA KEV: CVE-2023-2868 \u2014 Barracuda Networks ESG Appliance Improper Input Validation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-05-26",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-05-26"
    },
    {
      "value": "6f79ef58b354fd33824c96625590c244",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1730",
          "title": "CISA KEV: CVE-2023-2868 \u2014 Barracuda Networks ESG Appliance Improper Input Validation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-05-26",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-05-26"
    },
    {
      "value": "827d507aa3bde0ef903ca5dec60cdec8",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1730",
          "title": "CISA KEV: CVE-2023-2868 \u2014 Barracuda Networks ESG Appliance Improper Input Validation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-05-26",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-05-26"
    },
    {
      "value": "82eaf69de710abdc5dea7cd5cb56cf04",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1730",
          "title": "CISA KEV: CVE-2023-2868 \u2014 Barracuda Networks ESG Appliance Improper Input Validation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-05-26",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-05-26"
    },
    {
      "value": "85c5b6c408e4bdb87da6764a75008adf",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1730",
          "title": "CISA KEV: CVE-2023-2868 \u2014 Barracuda Networks ESG Appliance Improper Input Validation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-05-26",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-05-26"
    },
    {
      "value": "87847445f9524671022d70f2a812728f",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1730",
          "title": "CISA KEV: CVE-2023-2868 \u2014 Barracuda Networks ESG Appliance Improper Input Validation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-05-26",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-05-26"
    },
    {
      "value": "878cf1de91f3ae543fd290c31adcbda4",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1730",
          "title": "CISA KEV: CVE-2023-2868 \u2014 Barracuda Networks ESG Appliance Improper Input Validation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-05-26",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-05-26"
    },
    {
      "value": "9033dc5bac76542b9b752064a56c6ee4",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1730",
          "title": "CISA KEV: CVE-2023-2868 \u2014 Barracuda Networks ESG Appliance Improper Input Validation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-05-26",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-05-26"
    },
    {
      "value": "ac4fb6d0bfc871be6f68bfa647fc0125",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1730",
          "title": "CISA KEV: CVE-2023-2868 \u2014 Barracuda Networks ESG Appliance Improper Input Validation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-05-26",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-05-26"
    },
    {
      "value": "c528b6398c86f8bdcfa3f9de7837ebfe",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1730",
          "title": "CISA KEV: CVE-2023-2868 \u2014 Barracuda Networks ESG Appliance Improper Input Validation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-05-26",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-05-26"
    },
    {
      "value": "cd2813f0260d63ad5adf0446253c2172",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1730",
          "title": "CISA KEV: CVE-2023-2868 \u2014 Barracuda Networks ESG Appliance Improper Input Validation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-05-26",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-05-26"
    },
    {
      "value": "ce67bb99bc1e26f6cb1f968bc1b1ec21",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1730",
          "title": "CISA KEV: CVE-2023-2868 \u2014 Barracuda Networks ESG Appliance Improper Input Validation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-05-26",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-05-26"
    },
    {
      "value": "d098fe9674b6b4cb540699c5eb452cb5",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1730",
          "title": "CISA KEV: CVE-2023-2868 \u2014 Barracuda Networks ESG Appliance Improper Input Validation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-05-26",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-05-26"
    },
    {
      "value": "e4e86c273a2b67a605f5d4686783e0cc",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1730",
          "title": "CISA KEV: CVE-2023-2868 \u2014 Barracuda Networks ESG Appliance Improper Input Validation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-05-26",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-05-26"
    },
    {
      "value": "e52871d82de01b7e7f134c776703f696",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1730",
          "title": "CISA KEV: CVE-2023-2868 \u2014 Barracuda Networks ESG Appliance Improper Input Validation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-05-26",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-05-26"
    },
    {
      "value": "e80a85250263d58cc1a1dc39d6cf3942",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1730",
          "title": "CISA KEV: CVE-2023-2868 \u2014 Barracuda Networks ESG Appliance Improper Input Validation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-05-26",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-05-26"
    },
    {
      "value": "CVE-2023-28204",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1738",
          "title": "CISA KEV: CVE-2023-28204 \u2014 Apple Multiple Products WebKit Out-of-Bounds Read Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-05-22",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-05-22"
    },
    {
      "value": "CVE-2023-32373",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1739",
          "title": "CISA KEV: CVE-2023-32373 \u2014 Apple Multiple Products WebKit Use-After-Free Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-05-22",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-05-22"
    },
    {
      "value": "CVE-2023-32409",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1737",
          "title": "CISA KEV: CVE-2023-32409 \u2014 Apple Multiple Products WebKit Sandbox Escape Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-05-22",
          "sev": "crit"
        },
        {
          "id": "art-1738",
          "title": "CISA KEV: CVE-2023-28204 \u2014 Apple Multiple Products WebKit Out-of-Bounds Read Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-05-22",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-05-22"
    },
    {
      "value": "CVE-2004-1464",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1741",
          "title": "CISA KEV: CVE-2004-1464 \u2014 Cisco IOS Denial-of-Service Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-05-19",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-05-19"
    },
    {
      "value": "CVE-2016-6415",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1742",
          "title": "CISA KEV: CVE-2016-6415 \u2014 Cisco IOS, IOS XR, and IOS XE IKEv1 Information Disclosure Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-05-19",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-05-19"
    },
    {
      "value": "CVE-2023-21492",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1743",
          "title": "CISA KEV: CVE-2023-21492 \u2014 Samsung Mobile Devices Insertion of Sensitive Information Into Log File Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-05-19",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-05-19"
    },
    {
      "value": "CVE-2010-3904",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1753",
          "title": "CISA KEV: CVE-2010-3904 \u2014 Linux Kernel Improper Input Validation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-05-12",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-05-12"
    },
    {
      "value": "CVE-2014-0196",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1752",
          "title": "CISA KEV: CVE-2014-0196 \u2014 Linux Kernel Race Condition Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-05-12",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-05-12"
    },
    {
      "value": "CVE-2015-5317",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1754",
          "title": "CISA KEV: CVE-2015-5317 \u2014 Jenkins User Interface (UI) Information Disclosure Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-05-12",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-05-12"
    },
    {
      "value": "CVE-2016-3427",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1755",
          "title": "CISA KEV: CVE-2016-3427 \u2014 Oracle Java SE and JRockit Unspecified Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-05-12",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-05-12"
    },
    {
      "value": "CVE-2021-3560",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1751",
          "title": "CISA KEV: CVE-2021-3560 \u2014 Red Hat Polkit Incorrect Authorization Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-05-12",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-05-12"
    },
    {
      "value": "CVE-2023-25717",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1750",
          "title": "CISA KEV: CVE-2023-25717 \u2014 Multiple Ruckus Wireless Products CSRF and RCE Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-05-12",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-05-12"
    },
    {
      "value": "163.123.142.146",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1750",
          "title": "CISA KEV: CVE-2023-25717 \u2014 Multiple Ruckus Wireless Products CSRF and RCE Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-05-12",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-05-12"
    },
    {
      "value": "45.153.243.39",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1750",
          "title": "CISA KEV: CVE-2023-25717 \u2014 Multiple Ruckus Wireless Products CSRF and RCE Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-05-12",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-05-12"
    },
    {
      "value": "47.87.154.192",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1750",
          "title": "CISA KEV: CVE-2023-25717 \u2014 Multiple Ruckus Wireless Products CSRF and RCE Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-05-12",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-05-12"
    },
    {
      "value": "d2ad2d8d1b7dac89f2fb977c6b2c36a9",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1750",
          "title": "CISA KEV: CVE-2023-25717 \u2014 Multiple Ruckus Wireless Products CSRF and RCE Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-05-12",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-05-12"
    },
    {
      "value": "86d630159a13b4a594e3eae23ccbda891a67f696",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1750",
          "title": "CISA KEV: CVE-2023-25717 \u2014 Multiple Ruckus Wireless Products CSRF and RCE Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-05-12",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-05-12"
    },
    {
      "value": "1298da097b1c5bdce63f580e14e2c1b372c409476747356a8e9cfaf62b94513d",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1750",
          "title": "CISA KEV: CVE-2023-25717 \u2014 Multiple Ruckus Wireless Products CSRF and RCE Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-05-12",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-05-12"
    },
    {
      "value": "2e7136f760f04b1ed7033251a14fef1be1e82ddcbff44dae30db12fe52e0a78a",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1750",
          "title": "CISA KEV: CVE-2023-25717 \u2014 Multiple Ruckus Wireless Products CSRF and RCE Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-05-12",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-05-12"
    },
    {
      "value": "3441e88c80e82b933bb09e660d229d74f7b753a188700fe018e74c2db7b2aaa0",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1750",
          "title": "CISA KEV: CVE-2023-25717 \u2014 Multiple Ruckus Wireless Products CSRF and RCE Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-05-12",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-05-12"
    },
    {
      "value": "3c9998b8451022beee346f1afe18cab84e867b43c14ba9c7f04e5c559bfc4c3a",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1750",
          "title": "CISA KEV: CVE-2023-25717 \u2014 Multiple Ruckus Wireless Products CSRF and RCE Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-05-12",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-05-12"
    },
    {
      "value": "55e921a196c92c659305aa9de3edf6297803b60012f83967562a57547875fec1",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1750",
          "title": "CISA KEV: CVE-2023-25717 \u2014 Multiple Ruckus Wireless Products CSRF and RCE Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-05-12",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-05-12"
    },
    {
      "value": "b71b4f478479505f1bfb43663b4a4666ec98cd324acb16892ecb876ade5ca6f9",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1750",
          "title": "CISA KEV: CVE-2023-25717 \u2014 Multiple Ruckus Wireless Products CSRF and RCE Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-05-12",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-05-12"
    },
    {
      "value": "c4925a91ed853920d8acee79bf0bb9342da4dabc0a2970823027f39ede399bce",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1750",
          "title": "CISA KEV: CVE-2023-25717 \u2014 Multiple Ruckus Wireless Products CSRF and RCE Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-05-12",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-05-12"
    },
    {
      "value": "e740a0d2e42c09e912c43ecdc4dcbd8e92896ac3f725830d16aaa3eddf07fd5c",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1750",
          "title": "CISA KEV: CVE-2023-25717 \u2014 Multiple Ruckus Wireless Products CSRF and RCE Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-05-12",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-05-12"
    },
    {
      "value": "ea064dd91d8d9e6036e99f5348e078c43f99fdf98500614bffb736c4b0fff408",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1750",
          "title": "CISA KEV: CVE-2023-25717 \u2014 Multiple Ruckus Wireless Products CSRF and RCE Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-05-12",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-05-12"
    },
    {
      "value": "f42c6cea4c47bf0cbef666a8052633ab85ab6ac5b99b7e31faa1e198c4dd1ee1",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1750",
          "title": "CISA KEV: CVE-2023-25717 \u2014 Multiple Ruckus Wireless Products CSRF and RCE Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-05-12",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-05-12"
    },
    {
      "value": "CVE-2023-29336",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1760",
          "title": "CISA KEV: CVE-2023-29336 \u2014 Microsoft Win32K Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-05-09",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-05-09"
    },
    {
      "value": "CVE-2022-2237",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-1759",
          "title": "Secure JavaScript URL validation",
          "link": "https://snyk.io/blog/secure-javascript-url-validation/",
          "published": "2023-05-09",
          "sev": "high"
        }
      ],
      "first_seen": "2023-05-09"
    },
    {
      "value": "CVE-2021-45046",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV",
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-1770",
          "title": "CISA KEV: CVE-2021-45046 \u2014 Apache Log4j2 Deserialization of Untrusted Data Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-05-01",
          "sev": "crit"
        },
        {
          "id": "art-1937",
          "title": "How Atlassian used Snyk to solve Log4Shell",
          "link": "https://snyk.io/blog/how-atlassian-used-snyk-to-solve-log4shell/",
          "published": "2022-11-16",
          "sev": "high"
        },
        {
          "id": "art-2269",
          "title": "How LiveRamp used Snyk to remediate Log4Shell",
          "link": "https://snyk.io/blog/liveramp-used-snyk-to-remediate-log4shell/",
          "published": "2022-05-19",
          "sev": "high"
        },
        {
          "id": "art-2715",
          "title": "URL confusion vulnerabilities in the wild: Exploring parser inconsistencies",
          "link": "https://snyk.io/blog/url-confusion-vulnerabilities/",
          "published": "2022-01-10",
          "sev": "crit"
        },
        {
          "id": "art-2747",
          "title": "Log4j 2.16 High Severity Vulnerability (CVE-2021-45105) Discovered",
          "link": "https://snyk.io/blog/log4j-2-16-vulnerability-cve-2021-45105-discovered/",
          "published": "2021-12-18",
          "sev": "high"
        },
        {
          "id": "art-2748",
          "title": "Find Log4Shell vulnerabilities in your unmanaged and shaded jars with the Snyk CLI",
          "link": "https://snyk.io/blog/new-snyk-cli-command-finds-log4shell-in-unmanaged-undeclared-java-code/",
          "published": "2021-12-18",
          "sev": "high"
        },
        {
          "id": "art-2749",
          "title": "Log4j 2.15 vulnerability CVE-2021-45046 upgraded to a critical severity arbitrary code execution",
          "link": "https://snyk.io/blog/log4j-2-15-vulnerability-cve-2021-45046-critical-ace/",
          "published": "2021-12-17",
          "sev": "high"
        },
        {
          "id": "art-2751",
          "title": "Log4Shell in a nutshell (for non-developers & non-Java developers)",
          "link": "https://snyk.io/blog/log4shell-in-a-nutshell/",
          "published": "2021-12-15",
          "sev": "high"
        },
        {
          "id": "art-2756",
          "title": "The Log4j vulnerability and its impact on software supply chain security",
          "link": "https://snyk.io/blog/log4j-vulnerability-software-supply-chain-security-log4shell/",
          "published": "2021-12-13",
          "sev": "high"
        },
        {
          "id": "art-2757",
          "title": "Find and fix the Log4Shell exploit fast with Snyk",
          "link": "https://snyk.io/blog/find-fix-log4shell-quickly-snyk/",
          "published": "2021-12-13",
          "sev": "high"
        },
        {
          "id": "art-2758",
          "title": "Log4j vulnerability explained: Prevent Log4Shell RCE by updating to version 2.17.1",
          "link": "https://snyk.io/blog/log4j-rce-log4shell-vulnerability-cve-2021-44228/",
          "published": "2021-12-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-05-01"
    },
    {
      "value": "CVE-2022-3602",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-1772",
          "title": "Lessons from OpenSSL vulnerabilities part 2: Finding and fixing supply chain vulnerabilities",
          "link": "https://snyk.io/blog/lessons-from-openssl-vulnerabilities-part-2/",
          "published": "2023-04-26",
          "sev": "crit"
        },
        {
          "id": "art-1781",
          "title": "Lessons from OpenSSL vulnerabilities part 1: Preparing your supply chain for the next critical vulnerability",
          "link": "https://snyk.io/blog/lessons-from-openssl-vulnerabilities-part-1/",
          "published": "2023-04-19",
          "sev": "crit"
        },
        {
          "id": "art-1962",
          "title": "Update: OpenSSL high severity vulnerabilities",
          "link": "https://snyk.io/blog/openssl-high-severity-vulnerabilities/",
          "published": "2022-11-03",
          "sev": "crit"
        },
        {
          "id": "art-1968",
          "title": "New OpenSSL critical vulnerability: What you need to know",
          "link": "https://snyk.io/blog/new-openssl-critical-vulnerability/",
          "published": "2022-10-31",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-04-26"
    },
    {
      "value": "CVE-2022-3786",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-1772",
          "title": "Lessons from OpenSSL vulnerabilities part 2: Finding and fixing supply chain vulnerabilities",
          "link": "https://snyk.io/blog/lessons-from-openssl-vulnerabilities-part-2/",
          "published": "2023-04-26",
          "sev": "crit"
        },
        {
          "id": "art-1781",
          "title": "Lessons from OpenSSL vulnerabilities part 1: Preparing your supply chain for the next critical vulnerability",
          "link": "https://snyk.io/blog/lessons-from-openssl-vulnerabilities-part-1/",
          "published": "2023-04-19",
          "sev": "crit"
        },
        {
          "id": "art-1962",
          "title": "Update: OpenSSL high severity vulnerabilities",
          "link": "https://snyk.io/blog/openssl-high-severity-vulnerabilities/",
          "published": "2022-11-03",
          "sev": "crit"
        },
        {
          "id": "art-1968",
          "title": "New OpenSSL critical vulnerability: What you need to know",
          "link": "https://snyk.io/blog/new-openssl-critical-vulnerability/",
          "published": "2022-10-31",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-04-26"
    },
    {
      "value": "CVE-2023-2136",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1779",
          "title": "CISA KEV: CVE-2023-2136 \u2014 Google Chrome Skia Integer Overflow Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-04-21",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-04-21"
    },
    {
      "value": "CVE-2023-27350",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1778",
          "title": "CISA KEV: CVE-2023-27350 \u2014 PaperCut MF/NG Improper Access Control Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-04-21",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-04-21"
    },
    {
      "value": "CVE-2023-28432",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1777",
          "title": "CISA KEV: CVE-2023-28432 \u2014 MinIO Information Disclosure Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-04-21",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-04-21"
    },
    {
      "value": "102.130.112.157",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1778",
          "title": "CISA KEV: CVE-2023-27350 \u2014 PaperCut MF/NG Improper Access Control Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-04-21",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-04-21"
    },
    {
      "value": "172.106.112.46",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1778",
          "title": "CISA KEV: CVE-2023-27350 \u2014 PaperCut MF/NG Improper Access Control Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-04-21",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-04-21"
    },
    {
      "value": "192.160.102.164",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1778",
          "title": "CISA KEV: CVE-2023-27350 \u2014 PaperCut MF/NG Improper Access Control Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-04-21",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-04-21"
    },
    {
      "value": "CVE-2017-6742",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1782",
          "title": "CISA KEV: CVE-2017-6742 \u2014 Cisco IOS and IOS XE Software SNMP Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-04-19",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-04-19"
    },
    {
      "value": "CVE-2017-5941",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-1783",
          "title": "Preventing insecure deserialization in Node.js",
          "link": "https://snyk.io/blog/preventing-insecure-deserialization-node-js/",
          "published": "2023-04-17",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-04-17"
    },
    {
      "value": "CVE-2017-5954",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-1783",
          "title": "Preventing insecure deserialization in Node.js",
          "link": "https://snyk.io/blog/preventing-insecure-deserialization-node-js/",
          "published": "2023-04-17",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-04-17"
    },
    {
      "value": "CVE-2019-8526",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1784",
          "title": "CISA KEV: CVE-2019-8526 \u2014 Apple macOS Use-After-Free Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-04-17",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-04-17"
    },
    {
      "value": "CVE-2023-2033",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1785",
          "title": "CISA KEV: CVE-2023-2033 \u2014 Google Chromium V8 Type Confusion Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-04-17",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-04-17"
    },
    {
      "value": "CVE-2023-20963",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1789",
          "title": "CISA KEV: CVE-2023-20963 \u2014 Android Framework Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-04-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-04-13"
    },
    {
      "value": "CVE-2023-29492",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1790",
          "title": "CISA KEV: CVE-2023-29492 \u2014 Novi Survey Insecure Deserialization Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-04-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-04-13"
    },
    {
      "value": "devsetgroup.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1793",
          "title": "CISA KEV: CVE-2023-28252 \u2014 Microsoft Windows Common Log File System (CLFS) Driver Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-04-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-04-11"
    },
    {
      "value": "qooqle.top",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1793",
          "title": "CISA KEV: CVE-2023-28252 \u2014 Microsoft Windows Common Log File System (CLFS) Driver Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-04-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-04-11"
    },
    {
      "value": "vnssinc.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1793",
          "title": "CISA KEV: CVE-2023-28252 \u2014 Microsoft Windows Common Log File System (CLFS) Driver Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-04-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-04-11"
    },
    {
      "value": "vsexec.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1793",
          "title": "CISA KEV: CVE-2023-28252 \u2014 Microsoft Windows Common Log File System (CLFS) Driver Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-04-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-04-11"
    },
    {
      "value": "1e4dd35b16ddc59c1ecf240c22b8a4c4",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1793",
          "title": "CISA KEV: CVE-2023-28252 \u2014 Microsoft Windows Common Log File System (CLFS) Driver Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-04-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-04-11"
    },
    {
      "value": "46168ed7dbe33ffc4179974f8bf401aa",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1793",
          "title": "CISA KEV: CVE-2023-28252 \u2014 Microsoft Windows Common Log File System (CLFS) Driver Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-04-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-04-11"
    },
    {
      "value": "8800e6f1501f69a0a04ce709e9fa251c",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1793",
          "title": "CISA KEV: CVE-2023-28252 \u2014 Microsoft Windows Common Log File System (CLFS) Driver Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-04-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-04-11"
    },
    {
      "value": "a2313d7fdb2f8f5e5c1962e22b504a17",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1793",
          "title": "CISA KEV: CVE-2023-28252 \u2014 Microsoft Windows Common Log File System (CLFS) Driver Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-04-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-04-11"
    },
    {
      "value": "f23be19024fcc7c8f885dfa16634e6e7",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1793",
          "title": "CISA KEV: CVE-2023-28252 \u2014 Microsoft Windows Common Log File System (CLFS) Driver Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-04-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-04-11"
    },
    {
      "value": "CVE-2023-28205",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1796",
          "title": "CISA KEV: CVE-2023-28205 \u2014 Apple Multiple Products WebKit Use-After-Free Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-04-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-04-10"
    },
    {
      "value": "CVE-2023-28206",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1797",
          "title": "CISA KEV: CVE-2023-28206 \u2014 Apple iOS, iPadOS, and macOS IOSurfaceAccelerator Out-of-Bounds Write Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-04-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-04-10"
    },
    {
      "value": "CVE-2019-1388",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1801",
          "title": "CISA KEV: CVE-2019-1388 \u2014 Microsoft Windows Certificate Dialog Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-04-07",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-04-07"
    },
    {
      "value": "CVE-2021-27876",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1798",
          "title": "CISA KEV: CVE-2021-27876 \u2014 Veritas Backup Exec Agent File Access Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-04-07",
          "sev": "crit"
        },
        {
          "id": "art-1799",
          "title": "CISA KEV: CVE-2021-27877 \u2014 Veritas Backup Exec Agent Improper Authentication Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-04-07",
          "sev": "crit"
        },
        {
          "id": "art-1800",
          "title": "CISA KEV: CVE-2021-27878 \u2014 Veritas Backup Exec Agent Command Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-04-07",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-04-07"
    },
    {
      "value": "CVE-2021-27877",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1798",
          "title": "CISA KEV: CVE-2021-27876 \u2014 Veritas Backup Exec Agent File Access Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-04-07",
          "sev": "crit"
        },
        {
          "id": "art-1799",
          "title": "CISA KEV: CVE-2021-27877 \u2014 Veritas Backup Exec Agent Improper Authentication Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-04-07",
          "sev": "crit"
        },
        {
          "id": "art-1800",
          "title": "CISA KEV: CVE-2021-27878 \u2014 Veritas Backup Exec Agent Command Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-04-07",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-04-07"
    },
    {
      "value": "CVE-2021-27878",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1798",
          "title": "CISA KEV: CVE-2021-27876 \u2014 Veritas Backup Exec Agent File Access Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-04-07",
          "sev": "crit"
        },
        {
          "id": "art-1799",
          "title": "CISA KEV: CVE-2021-27877 \u2014 Veritas Backup Exec Agent Improper Authentication Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-04-07",
          "sev": "crit"
        },
        {
          "id": "art-1800",
          "title": "CISA KEV: CVE-2021-27878 \u2014 Veritas Backup Exec Agent Command Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-04-07",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-04-07"
    },
    {
      "value": "CVE-2023-26083",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1802",
          "title": "CISA KEV: CVE-2023-26083 \u2014 Arm Mali GPU Kernel Driver Information Disclosure Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-04-07",
          "sev": "crit"
        },
        {
          "id": "art-1821",
          "title": "CISA KEV: CVE-2023-0266 \u2014 Linux Kernel Use-After-Free Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-03-30",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-04-07"
    },
    {
      "value": "185.141.62.123",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1798",
          "title": "CISA KEV: CVE-2021-27876 \u2014 Veritas Backup Exec Agent File Access Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-04-07",
          "sev": "crit"
        },
        {
          "id": "art-1799",
          "title": "CISA KEV: CVE-2021-27877 \u2014 Veritas Backup Exec Agent Improper Authentication Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-04-07",
          "sev": "crit"
        },
        {
          "id": "art-1800",
          "title": "CISA KEV: CVE-2021-27878 \u2014 Veritas Backup Exec Agent Command Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-04-07",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-04-07"
    },
    {
      "value": "185.99.135.115",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1798",
          "title": "CISA KEV: CVE-2021-27876 \u2014 Veritas Backup Exec Agent File Access Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-04-07",
          "sev": "crit"
        },
        {
          "id": "art-1799",
          "title": "CISA KEV: CVE-2021-27877 \u2014 Veritas Backup Exec Agent Improper Authentication Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-04-07",
          "sev": "crit"
        },
        {
          "id": "art-1800",
          "title": "CISA KEV: CVE-2021-27878 \u2014 Veritas Backup Exec Agent Command Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-04-07",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-04-07"
    },
    {
      "value": "45.61.138.109",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1798",
          "title": "CISA KEV: CVE-2021-27876 \u2014 Veritas Backup Exec Agent File Access Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-04-07",
          "sev": "crit"
        },
        {
          "id": "art-1799",
          "title": "CISA KEV: CVE-2021-27877 \u2014 Veritas Backup Exec Agent Improper Authentication Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-04-07",
          "sev": "crit"
        },
        {
          "id": "art-1800",
          "title": "CISA KEV: CVE-2021-27878 \u2014 Veritas Backup Exec Agent Command Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-04-07",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-04-07"
    },
    {
      "value": "5.199.169.209",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1798",
          "title": "CISA KEV: CVE-2021-27876 \u2014 Veritas Backup Exec Agent File Access Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-04-07",
          "sev": "crit"
        },
        {
          "id": "art-1799",
          "title": "CISA KEV: CVE-2021-27877 \u2014 Veritas Backup Exec Agent Improper Authentication Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-04-07",
          "sev": "crit"
        },
        {
          "id": "art-1800",
          "title": "CISA KEV: CVE-2021-27878 \u2014 Veritas Backup Exec Agent Command Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-04-07",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-04-07"
    },
    {
      "value": "17424a22f01b7b996810ba1274f7b8e9",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1798",
          "title": "CISA KEV: CVE-2021-27876 \u2014 Veritas Backup Exec Agent File Access Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-04-07",
          "sev": "crit"
        },
        {
          "id": "art-1799",
          "title": "CISA KEV: CVE-2021-27877 \u2014 Veritas Backup Exec Agent Improper Authentication Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-04-07",
          "sev": "crit"
        },
        {
          "id": "art-1800",
          "title": "CISA KEV: CVE-2021-27878 \u2014 Veritas Backup Exec Agent Command Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-04-07",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-04-07"
    },
    {
      "value": "1f437347917f0a4ced71fb7df53b1a05",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1798",
          "title": "CISA KEV: CVE-2021-27876 \u2014 Veritas Backup Exec Agent File Access Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-04-07",
          "sev": "crit"
        },
        {
          "id": "art-1799",
          "title": "CISA KEV: CVE-2021-27877 \u2014 Veritas Backup Exec Agent Improper Authentication Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-04-07",
          "sev": "crit"
        },
        {
          "id": "art-1800",
          "title": "CISA KEV: CVE-2021-27878 \u2014 Veritas Backup Exec Agent Command Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-04-07",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-04-07"
    },
    {
      "value": "24b0f58f014bd259b57f346fb5aed2ea",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1798",
          "title": "CISA KEV: CVE-2021-27876 \u2014 Veritas Backup Exec Agent File Access Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-04-07",
          "sev": "crit"
        },
        {
          "id": "art-1799",
          "title": "CISA KEV: CVE-2021-27877 \u2014 Veritas Backup Exec Agent Improper Authentication Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-04-07",
          "sev": "crit"
        },
        {
          "id": "art-1800",
          "title": "CISA KEV: CVE-2021-27878 \u2014 Veritas Backup Exec Agent Command Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-04-07",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-04-07"
    },
    {
      "value": "4fdabe571b66ceec3448939bfb3ffcd1",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1798",
          "title": "CISA KEV: CVE-2021-27876 \u2014 Veritas Backup Exec Agent File Access Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-04-07",
          "sev": "crit"
        },
        {
          "id": "art-1799",
          "title": "CISA KEV: CVE-2021-27877 \u2014 Veritas Backup Exec Agent Improper Authentication Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-04-07",
          "sev": "crit"
        },
        {
          "id": "art-1800",
          "title": "CISA KEV: CVE-2021-27878 \u2014 Veritas Backup Exec Agent Command Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-04-07",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-04-07"
    },
    {
      "value": "5fe66b2835511f9d4d3703b6c639b866",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1798",
          "title": "CISA KEV: CVE-2021-27876 \u2014 Veritas Backup Exec Agent File Access Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-04-07",
          "sev": "crit"
        },
        {
          "id": "art-1799",
          "title": "CISA KEV: CVE-2021-27877 \u2014 Veritas Backup Exec Agent Improper Authentication Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-04-07",
          "sev": "crit"
        },
        {
          "id": "art-1800",
          "title": "CISA KEV: CVE-2021-27878 \u2014 Veritas Backup Exec Agent Command Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-04-07",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-04-07"
    },
    {
      "value": "68d3bf2c363144ec6874ab360fdda00a",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1798",
          "title": "CISA KEV: CVE-2021-27876 \u2014 Veritas Backup Exec Agent File Access Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-04-07",
          "sev": "crit"
        },
        {
          "id": "art-1799",
          "title": "CISA KEV: CVE-2021-27877 \u2014 Veritas Backup Exec Agent Improper Authentication Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-04-07",
          "sev": "crit"
        },
        {
          "id": "art-1800",
          "title": "CISA KEV: CVE-2021-27878 \u2014 Veritas Backup Exec Agent Command Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-04-07",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-04-07"
    },
    {
      "value": "b41dc7bef82ef384bc884973f3d0e8ca",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1798",
          "title": "CISA KEV: CVE-2021-27876 \u2014 Veritas Backup Exec Agent File Access Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-04-07",
          "sev": "crit"
        },
        {
          "id": "art-1799",
          "title": "CISA KEV: CVE-2021-27877 \u2014 Veritas Backup Exec Agent Improper Authentication Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-04-07",
          "sev": "crit"
        },
        {
          "id": "art-1800",
          "title": "CISA KEV: CVE-2021-27878 \u2014 Veritas Backup Exec Agent Command Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-04-07",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-04-07"
    },
    {
      "value": "c590a84b8c72cf18f35ae166f815c9df",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1798",
          "title": "CISA KEV: CVE-2021-27876 \u2014 Veritas Backup Exec Agent File Access Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-04-07",
          "sev": "crit"
        },
        {
          "id": "art-1799",
          "title": "CISA KEV: CVE-2021-27877 \u2014 Veritas Backup Exec Agent Improper Authentication Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-04-07",
          "sev": "crit"
        },
        {
          "id": "art-1800",
          "title": "CISA KEV: CVE-2021-27878 \u2014 Veritas Backup Exec Agent Command Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-04-07",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-04-07"
    },
    {
      "value": "da202cc4b3679fdb47003d603a93c90d",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1798",
          "title": "CISA KEV: CVE-2021-27876 \u2014 Veritas Backup Exec Agent File Access Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-04-07",
          "sev": "crit"
        },
        {
          "id": "art-1799",
          "title": "CISA KEV: CVE-2021-27877 \u2014 Veritas Backup Exec Agent Improper Authentication Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-04-07",
          "sev": "crit"
        },
        {
          "id": "art-1800",
          "title": "CISA KEV: CVE-2021-27878 \u2014 Veritas Backup Exec Agent Command Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-04-07",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-04-07"
    },
    {
      "value": "e31270e4a6f215f45abad65916da9db4",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1798",
          "title": "CISA KEV: CVE-2021-27876 \u2014 Veritas Backup Exec Agent File Access Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-04-07",
          "sev": "crit"
        },
        {
          "id": "art-1799",
          "title": "CISA KEV: CVE-2021-27877 \u2014 Veritas Backup Exec Agent Improper Authentication Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-04-07",
          "sev": "crit"
        },
        {
          "id": "art-1800",
          "title": "CISA KEV: CVE-2021-27878 \u2014 Veritas Backup Exec Agent Command Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-04-07",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-04-07"
    },
    {
      "value": "ee6e0cb1b3b7601696e9a05ce66e7f37",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1798",
          "title": "CISA KEV: CVE-2021-27876 \u2014 Veritas Backup Exec Agent File Access Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-04-07",
          "sev": "crit"
        },
        {
          "id": "art-1799",
          "title": "CISA KEV: CVE-2021-27877 \u2014 Veritas Backup Exec Agent Improper Authentication Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-04-07",
          "sev": "crit"
        },
        {
          "id": "art-1800",
          "title": "CISA KEV: CVE-2021-27878 \u2014 Veritas Backup Exec Agent Command Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-04-07",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-04-07"
    },
    {
      "value": "f66e1d717b54b95cf32154b770e10ba4",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1798",
          "title": "CISA KEV: CVE-2021-27876 \u2014 Veritas Backup Exec Agent File Access Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-04-07",
          "sev": "crit"
        },
        {
          "id": "art-1799",
          "title": "CISA KEV: CVE-2021-27877 \u2014 Veritas Backup Exec Agent Improper Authentication Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-04-07",
          "sev": "crit"
        },
        {
          "id": "art-1800",
          "title": "CISA KEV: CVE-2021-27878 \u2014 Veritas Backup Exec Agent Command Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-04-07",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-04-07"
    },
    {
      "value": "CVE-2022-27926",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1812",
          "title": "CISA KEV: CVE-2022-27926 \u2014 Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting (XSS) Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-04-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-04-03"
    },
    {
      "value": "bugiplaysec.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1812",
          "title": "CISA KEV: CVE-2022-27926 \u2014 Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting (XSS) Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-04-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-04-03"
    },
    {
      "value": "nepalihemp.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1812",
          "title": "CISA KEV: CVE-2022-27926 \u2014 Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting (XSS) Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-04-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-04-03"
    },
    {
      "value": "ocs-romastassec.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1812",
          "title": "CISA KEV: CVE-2022-27926 \u2014 Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting (XSS) Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-04-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-04-03"
    },
    {
      "value": "ocspdep.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1812",
          "title": "CISA KEV: CVE-2022-27926 \u2014 Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting (XSS) Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-04-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-04-03"
    },
    {
      "value": "oscp-avanguard.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1812",
          "title": "CISA KEV: CVE-2022-27926 \u2014 Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting (XSS) Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-04-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-04-03"
    },
    {
      "value": "troadsecow.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1812",
          "title": "CISA KEV: CVE-2022-27926 \u2014 Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting (XSS) Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-04-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-04-03"
    },
    {
      "value": "CVE-2013-3163",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1815",
          "title": "CISA KEV: CVE-2013-3163 \u2014 Microsoft Internet Explorer Memory Corruption Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-03-30",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-03-30"
    },
    {
      "value": "CVE-2017-7494",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1816",
          "title": "CISA KEV: CVE-2017-7494 \u2014 Samba Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-03-30",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-03-30"
    },
    {
      "value": "CVE-2021-30900",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1819",
          "title": "CISA KEV: CVE-2021-30900 \u2014 Apple iOS, iPadOS, and macOS Out-of-Bounds Write Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-03-30",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-03-30"
    },
    {
      "value": "CVE-2022-22706",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1821",
          "title": "CISA KEV: CVE-2023-0266 \u2014 Linux Kernel Use-After-Free Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-03-30",
          "sev": "crit"
        },
        {
          "id": "art-1823",
          "title": "CISA KEV: CVE-2022-22706 \u2014 Arm Mali GPU Kernel Driver Unspecified Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-03-30",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-03-30"
    },
    {
      "value": "CVE-2022-3038",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1821",
          "title": "CISA KEV: CVE-2023-0266 \u2014 Linux Kernel Use-After-Free Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-03-30",
          "sev": "crit"
        },
        {
          "id": "art-1822",
          "title": "CISA KEV: CVE-2022-3038 \u2014 Google Chromium Network Service Use-After-Free Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-03-30",
          "sev": "crit"
        },
        {
          "id": "art-1823",
          "title": "CISA KEV: CVE-2022-22706 \u2014 Arm Mali GPU Kernel Driver Unspecified Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-03-30",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-03-30"
    },
    {
      "value": "CVE-2022-38181",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1820",
          "title": "CISA KEV: CVE-2022-38181 \u2014 Arm Mali GPU Kernel Driver Use-After-Free Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-03-30",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-03-30"
    },
    {
      "value": "CVE-2022-39197",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1818",
          "title": "CISA KEV: CVE-2022-39197 \u2014 Fortra Cobalt Strike Teamserver Cross-Site Scripting (XSS) Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-03-30",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-03-30"
    },
    {
      "value": "CVE-2022-4262",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1821",
          "title": "CISA KEV: CVE-2023-0266 \u2014 Linux Kernel Use-After-Free Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-03-30",
          "sev": "crit"
        },
        {
          "id": "art-1823",
          "title": "CISA KEV: CVE-2022-22706 \u2014 Arm Mali GPU Kernel Driver Unspecified Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-03-30",
          "sev": "crit"
        },
        {
          "id": "art-1923",
          "title": "CISA KEV: CVE-2022-4262 \u2014 Google Chromium V8 Type Confusion Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-12-05",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-03-30"
    },
    {
      "value": "CVE-2022-42948",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1817",
          "title": "CISA KEV: CVE-2022-42948 \u2014 Fortra Cobalt Strike User Interface Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-03-30",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-03-30"
    },
    {
      "value": "CVE-2023-0266",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1821",
          "title": "CISA KEV: CVE-2023-0266 \u2014 Linux Kernel Use-After-Free Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-03-30",
          "sev": "crit"
        },
        {
          "id": "art-1823",
          "title": "CISA KEV: CVE-2022-22706 \u2014 Arm Mali GPU Kernel Driver Unspecified Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-03-30",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-03-30"
    },
    {
      "value": "anglesyen.org",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1823",
          "title": "CISA KEV: CVE-2022-22706 \u2014 Arm Mali GPU Kernel Driver Unspecified Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-03-30",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-03-30"
    },
    {
      "value": "sufficeconfigure.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1823",
          "title": "CISA KEV: CVE-2022-22706 \u2014 Arm Mali GPU Kernel Driver Unspecified Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-03-30",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-03-30"
    },
    {
      "value": "3.72.6.53",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-1827",
          "title": "The rising trend of malicious packages in open source ecosystems",
          "link": "https://snyk.io/blog/malicious-packages-open-source-ecosystems/",
          "published": "2023-03-23",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-03-23"
    },
    {
      "value": "CVE-2021-3807",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-1831",
          "title": "New language-specific Snyk Top 10 for open source vulnerabilities",
          "link": "https://snyk.io/blog/language-specific-snyk-top-10-open-source-2022/",
          "published": "2023-03-15",
          "sev": "high"
        },
        {
          "id": "art-2059",
          "title": "Solve Hack the Box and other CTF challenges with Snyk",
          "link": "https://snyk.io/blog/solve-hack-the-box-and-ctf-challenges-with-snyk/",
          "published": "2022-09-01",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-03-15"
    },
    {
      "value": "CVE-2023-26360",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1833",
          "title": "CISA KEV: CVE-2023-26360 \u2014 Adobe ColdFusion Deserialization of Untrusted Data Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-03-15",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-03-15"
    },
    {
      "value": "CVE-2021-43138",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-1831",
          "title": "New language-specific Snyk Top 10 for open source vulnerabilities",
          "link": "https://snyk.io/blog/language-specific-snyk-top-10-open-source-2022/",
          "published": "2023-03-15",
          "sev": "high"
        }
      ],
      "first_seen": "2023-03-15"
    },
    {
      "value": "CVE-2022-2144",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-1831",
          "title": "New language-specific Snyk Top 10 for open source vulnerabilities",
          "link": "https://snyk.io/blog/language-specific-snyk-top-10-open-source-2022/",
          "published": "2023-03-15",
          "sev": "high"
        }
      ],
      "first_seen": "2023-03-15"
    },
    {
      "value": "CVE-2022-2421",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-1831",
          "title": "New language-specific Snyk Top 10 for open source vulnerabilities",
          "link": "https://snyk.io/blog/language-specific-snyk-top-10-open-source-2022/",
          "published": "2023-03-15",
          "sev": "high"
        }
      ],
      "first_seen": "2023-03-15"
    },
    {
      "value": "CVE-2022-24858",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-1831",
          "title": "New language-specific Snyk Top 10 for open source vulnerabilities",
          "link": "https://snyk.io/blog/language-specific-snyk-top-10-open-source-2022/",
          "published": "2023-03-15",
          "sev": "high"
        }
      ],
      "first_seen": "2023-03-15"
    },
    {
      "value": "CVE-2022-25319",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-1831",
          "title": "New language-specific Snyk Top 10 for open source vulnerabilities",
          "link": "https://snyk.io/blog/language-specific-snyk-top-10-open-source-2022/",
          "published": "2023-03-15",
          "sev": "high"
        }
      ],
      "first_seen": "2023-03-15"
    },
    {
      "value": "CVE-2022-3518",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-1831",
          "title": "New language-specific Snyk Top 10 for open source vulnerabilities",
          "link": "https://snyk.io/blog/language-specific-snyk-top-10-open-source-2022/",
          "published": "2023-03-15",
          "sev": "high"
        }
      ],
      "first_seen": "2023-03-15"
    },
    {
      "value": "CVE-2022-41328",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1836",
          "title": "CISA KEV: CVE-2022-41328 \u2014 Fortinet FortiOS Path Traversal Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-03-14",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-03-14"
    },
    {
      "value": "CVE-2022-44698",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1835",
          "title": "CISA KEV: CVE-2023-24880 \u2014 Microsoft Windows SmartScreen Security Feature Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-03-14",
          "sev": "crit"
        },
        {
          "id": "art-1913",
          "title": "CISA KEV: CVE-2022-44698 \u2014 Microsoft Defender SmartScreen Security Feature Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-12-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-03-14"
    },
    {
      "value": "CVE-2023-23397",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1834",
          "title": "CISA KEV: CVE-2023-23397 \u2014 Microsoft Office Outlook Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-03-14",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-03-14"
    },
    {
      "value": "CVE-2023-24880",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1835",
          "title": "CISA KEV: CVE-2023-24880 \u2014 Microsoft Windows SmartScreen Security Feature Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-03-14",
          "sev": "crit"
        },
        {
          "id": "art-1913",
          "title": "CISA KEV: CVE-2022-44698 \u2014 Microsoft Defender SmartScreen Security Feature Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-12-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-03-14"
    },
    {
      "value": "101.255.119.42",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1834",
          "title": "CISA KEV: CVE-2023-23397 \u2014 Microsoft Office Outlook Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-03-14",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-03-14"
    },
    {
      "value": "113.160.234.229",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1834",
          "title": "CISA KEV: CVE-2023-23397 \u2014 Microsoft Office Outlook Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-03-14",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-03-14"
    },
    {
      "value": "168.205.200.55",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1834",
          "title": "CISA KEV: CVE-2023-23397 \u2014 Microsoft Office Outlook Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-03-14",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-03-14"
    },
    {
      "value": "181.209.99.204",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1834",
          "title": "CISA KEV: CVE-2023-23397 \u2014 Microsoft Office Outlook Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-03-14",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-03-14"
    },
    {
      "value": "185.132.17.160",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1834",
          "title": "CISA KEV: CVE-2023-23397 \u2014 Microsoft Office Outlook Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-03-14",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-03-14"
    },
    {
      "value": "213.32.252.221",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1834",
          "title": "CISA KEV: CVE-2023-23397 \u2014 Microsoft Office Outlook Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-03-14",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-03-14"
    },
    {
      "value": "24.142.165.2",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1834",
          "title": "CISA KEV: CVE-2023-23397 \u2014 Microsoft Office Outlook Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-03-14",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-03-14"
    },
    {
      "value": "42.98.5.225",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1834",
          "title": "CISA KEV: CVE-2023-23397 \u2014 Microsoft Office Outlook Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-03-14",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-03-14"
    },
    {
      "value": "47.252.20.90",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1836",
          "title": "CISA KEV: CVE-2022-41328 \u2014 Fortinet FortiOS Path Traversal Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-03-14",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-03-14"
    },
    {
      "value": "5.199.162.132",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1834",
          "title": "CISA KEV: CVE-2023-23397 \u2014 Microsoft Office Outlook Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-03-14",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-03-14"
    },
    {
      "value": "50.173.136.70",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1834",
          "title": "CISA KEV: CVE-2023-23397 \u2014 Microsoft Office Outlook Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-03-14",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-03-14"
    },
    {
      "value": "61.14.68.33",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1834",
          "title": "CISA KEV: CVE-2023-23397 \u2014 Microsoft Office Outlook Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-03-14",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-03-14"
    },
    {
      "value": "69.162.253.21",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1834",
          "title": "CISA KEV: CVE-2023-23397 \u2014 Microsoft Office Outlook Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-03-14",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-03-14"
    },
    {
      "value": "69.51.2.106",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1834",
          "title": "CISA KEV: CVE-2023-23397 \u2014 Microsoft Office Outlook Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-03-14",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-03-14"
    },
    {
      "value": "82.196.113.102",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1834",
          "title": "CISA KEV: CVE-2023-23397 \u2014 Microsoft Office Outlook Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-03-14",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-03-14"
    },
    {
      "value": "85.195.206.7",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1834",
          "title": "CISA KEV: CVE-2023-23397 \u2014 Microsoft Office Outlook Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-03-14",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-03-14"
    },
    {
      "value": "3e43511c4f7f551290292394c4e21de7",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1836",
          "title": "CISA KEV: CVE-2022-41328 \u2014 Fortinet FortiOS Path Traversal Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-03-14",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-03-14"
    },
    {
      "value": "53a69adac914808eced2bf8155a7512d",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1836",
          "title": "CISA KEV: CVE-2022-41328 \u2014 Fortinet FortiOS Path Traversal Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-03-14",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-03-14"
    },
    {
      "value": "88711ebc99e1390f1ce2f42a6de0654d",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1836",
          "title": "CISA KEV: CVE-2022-41328 \u2014 Fortinet FortiOS Path Traversal Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-03-14",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-03-14"
    },
    {
      "value": "9ce2459168cf4b5af494776a70e0feda",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1836",
          "title": "CISA KEV: CVE-2022-41328 \u2014 Fortinet FortiOS Path Traversal Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-03-14",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-03-14"
    },
    {
      "value": "a388ebaef45add5da503e4bf2b9da546",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1836",
          "title": "CISA KEV: CVE-2022-41328 \u2014 Fortinet FortiOS Path Traversal Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-03-14",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-03-14"
    },
    {
      "value": "a86a8fe875a89816e5808588154a067e",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1836",
          "title": "CISA KEV: CVE-2022-41328 \u2014 Fortinet FortiOS Path Traversal Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-03-14",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-03-14"
    },
    {
      "value": "b6e92149efaf78e9ce7552297505b9d5",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1836",
          "title": "CISA KEV: CVE-2022-41328 \u2014 Fortinet FortiOS Path Traversal Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-03-14",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-03-14"
    },
    {
      "value": "e2d2884869f48f40b32fb27cc3bdefff",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1836",
          "title": "CISA KEV: CVE-2022-41328 \u2014 Fortinet FortiOS Path Traversal Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-03-14",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-03-14"
    },
    {
      "value": "1a077212735617a665a6b631e34a6aedcbc41713",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1836",
          "title": "CISA KEV: CVE-2022-41328 \u2014 Fortinet FortiOS Path Traversal Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-03-14",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-03-14"
    },
    {
      "value": "3109b890901499f7ebb90f8870a7d1617d27e7c9",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1836",
          "title": "CISA KEV: CVE-2022-41328 \u2014 Fortinet FortiOS Path Traversal Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-03-14",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-03-14"
    },
    {
      "value": "75c092098e3409d366a46fdde6a92ff97d29cee1",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1836",
          "title": "CISA KEV: CVE-2022-41328 \u2014 Fortinet FortiOS Path Traversal Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-03-14",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-03-14"
    },
    {
      "value": "86f3623b3fb8d5303b6c9d8295292a5c2ceb2889",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1836",
          "title": "CISA KEV: CVE-2022-41328 \u2014 Fortinet FortiOS Path Traversal Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-03-14",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-03-14"
    },
    {
      "value": "8c40fc87fa3b25a559585b10a8ca11c81fb09f75",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1836",
          "title": "CISA KEV: CVE-2022-41328 \u2014 Fortinet FortiOS Path Traversal Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-03-14",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-03-14"
    },
    {
      "value": "8ef5159944d048fe84e51a818c9b11ebcfa98517",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1836",
          "title": "CISA KEV: CVE-2022-41328 \u2014 Fortinet FortiOS Path Traversal Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-03-14",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-03-14"
    },
    {
      "value": "9dca7f1af5752bb007e5cc55acd2511f03049ee5",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1836",
          "title": "CISA KEV: CVE-2022-41328 \u2014 Fortinet FortiOS Path Traversal Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-03-14",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-03-14"
    },
    {
      "value": "b8bdaa1bd204a6c710875b0c4265655d1fd37d52",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1836",
          "title": "CISA KEV: CVE-2022-41328 \u2014 Fortinet FortiOS Path Traversal Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-03-14",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-03-14"
    },
    {
      "value": "d5f8436e9815358e33b8243abda76c9b398943e2",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1836",
          "title": "CISA KEV: CVE-2022-41328 \u2014 Fortinet FortiOS Path Traversal Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-03-14",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-03-14"
    },
    {
      "value": "18afbad17dee0e4330a85b782e8e580c6125d8a7127cda69ad0e2728d505a6f5",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1836",
          "title": "CISA KEV: CVE-2022-41328 \u2014 Fortinet FortiOS Path Traversal Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-03-14",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-03-14"
    },
    {
      "value": "2266667af7532a32b9c21c330a9fe56356ca66610e39654804a7262f2af61017",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1836",
          "title": "CISA KEV: CVE-2022-41328 \u2014 Fortinet FortiOS Path Traversal Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-03-14",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-03-14"
    },
    {
      "value": "245e4646e5d984c2da4cfe223bb2fae679441bcf42b254fc193ae97dc32af7ad",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1836",
          "title": "CISA KEV: CVE-2022-41328 \u2014 Fortinet FortiOS Path Traversal Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-03-14",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-03-14"
    },
    {
      "value": "33c22b2db8c0948c67204485972d2eb856e13dca16132371337fc3534e3df16d",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1836",
          "title": "CISA KEV: CVE-2022-41328 \u2014 Fortinet FortiOS Path Traversal Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-03-14",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-03-14"
    },
    {
      "value": "4e4c5e5ca588bd84b67a37b654ec522768fa83e535ff795a5c196da8f8b9737d",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1836",
          "title": "CISA KEV: CVE-2022-41328 \u2014 Fortinet FortiOS Path Traversal Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-03-14",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-03-14"
    },
    {
      "value": "77e3a3bc905f9a172e95ba70bf01c3236e6c6423f537fa728b1bda5a40a77fe3",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1835",
          "title": "CISA KEV: CVE-2023-24880 \u2014 Microsoft Windows SmartScreen Security Feature Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-03-14",
          "sev": "crit"
        },
        {
          "id": "art-1913",
          "title": "CISA KEV: CVE-2022-44698 \u2014 Microsoft Defender SmartScreen Security Feature Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-12-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-03-14"
    },
    {
      "value": "8efb4e8bc17486b816088679d8b10f8985a31bc93488c4b65116f56872c1ff16",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1835",
          "title": "CISA KEV: CVE-2023-24880 \u2014 Microsoft Windows SmartScreen Security Feature Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-03-14",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-03-14"
    },
    {
      "value": "9fb09fe6db61fbdd19ac9c368e2f64fb9606119649830762fa467719c480ed44",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1836",
          "title": "CISA KEV: CVE-2022-41328 \u2014 Fortinet FortiOS Path Traversal Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-03-14",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-03-14"
    },
    {
      "value": "a00fed53b1ece4610c8b52934c20af3667d455f092a77f8d9bc46fdb9047e41a",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1836",
          "title": "CISA KEV: CVE-2022-41328 \u2014 Fortinet FortiOS Path Traversal Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-03-14",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-03-14"
    },
    {
      "value": "abefe121e5c895bf63be80152ccbe2d7bb5ad985aa3ab989bcb7c0804b90d004",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1836",
          "title": "CISA KEV: CVE-2022-41328 \u2014 Fortinet FortiOS Path Traversal Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-03-14",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-03-14"
    },
    {
      "value": "ad89fb8819f98e38cddf6135004e1d93e8c8e4cba681ba16d408c4d69317eb47",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1835",
          "title": "CISA KEV: CVE-2023-24880 \u2014 Microsoft Windows SmartScreen Security Feature Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-03-14",
          "sev": "crit"
        },
        {
          "id": "art-1913",
          "title": "CISA KEV: CVE-2022-44698 \u2014 Microsoft Defender SmartScreen Security Feature Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-12-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-03-14"
    },
    {
      "value": "eb6af99148f0ce5b58e414162ff2b7567b4cf08953862a088996365ff306014b",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1836",
          "title": "CISA KEV: CVE-2022-41328 \u2014 Fortinet FortiOS Path Traversal Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-03-14",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-03-14"
    },
    {
      "value": "CVE-2020-5741",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1839",
          "title": "CISA KEV: CVE-2020-5741 \u2014 Plex Media Server Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-03-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-03-10"
    },
    {
      "value": "CVE-2021-39144",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1838",
          "title": "CISA KEV: CVE-2021-39144 \u2014 XStream Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-03-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-03-10"
    },
    {
      "value": "CVE-2022-28810",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1842",
          "title": "CISA KEV: CVE-2022-28810 \u2014 Zoho ManageEngine ADSelfService Plus Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-03-07",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-03-07"
    },
    {
      "value": "CVE-2022-35914",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1844",
          "title": "CISA KEV: CVE-2022-35914 \u2014 Teclib GLPI Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-03-07",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-03-07"
    },
    {
      "value": "CVE-2023-32007",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1843",
          "title": "CISA KEV: CVE-2022-33891 \u2014 Apache Spark Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-03-07",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-03-07"
    },
    {
      "value": "CVE-2023-1065",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-1850",
          "title": "API authentication vulnerability found in Snyk Kubernetes integration (CVE-2023-1065)",
          "link": "https://snyk.io/blog/api-auth-vuln-snyk-kubernetes-cve-2023-1065/",
          "published": "2023-02-28",
          "sev": "high"
        }
      ],
      "first_seen": "2023-02-28"
    },
    {
      "value": "CVE-2022-36537",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1852",
          "title": "CISA KEV: CVE-2022-36537 \u2014 ZK Framework AuUploader Unspecified Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-02-27",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-02-27"
    },
    {
      "value": "142.11.195.29",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1852",
          "title": "CISA KEV: CVE-2022-36537 \u2014 ZK Framework AuUploader Unspecified Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-02-27",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-02-27"
    },
    {
      "value": "45.159.248.213",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1852",
          "title": "CISA KEV: CVE-2022-36537 \u2014 ZK Framework AuUploader Unspecified Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-02-27",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-02-27"
    },
    {
      "value": "45.61.139.187",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1852",
          "title": "CISA KEV: CVE-2022-36537 \u2014 ZK Framework AuUploader Unspecified Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-02-27",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-02-27"
    },
    {
      "value": "5.8.33.147",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1852",
          "title": "CISA KEV: CVE-2022-36537 \u2014 ZK Framework AuUploader Unspecified Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-02-27",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-02-27"
    },
    {
      "value": "77.91.101.140",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1852",
          "title": "CISA KEV: CVE-2022-36537 \u2014 ZK Framework AuUploader Unspecified Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-02-27",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-02-27"
    },
    {
      "value": "CVE-2023-26153",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-1853",
          "title": "Finding YAML Deserialization with Snyk Code",
          "link": "https://snyk.io/blog/finding-yaml-injection-with-snyk-code/",
          "published": "2023-02-23",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-02-23"
    },
    {
      "value": "CVE-2022-41223",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1858",
          "title": "CISA KEV: CVE-2022-41223 \u2014 Mitel MiVoice Connect Code Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-02-21",
          "sev": "crit"
        },
        {
          "id": "art-1859",
          "title": "CISA KEV: CVE-2022-40765 \u2014 Mitel MiVoice Connect Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-02-21",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-02-21"
    },
    {
      "value": "CVE-2022-47986",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1857",
          "title": "CISA KEV: CVE-2022-47986 \u2014 IBM Aspera Faspex Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-02-21",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-02-21"
    },
    {
      "value": "CVE-2022-46169",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1862",
          "title": "CISA KEV: CVE-2022-46169 \u2014 Cacti Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-02-16",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-02-16"
    },
    {
      "value": "CVE-2023-21715",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1865",
          "title": "CISA KEV: CVE-2023-21715 \u2014 Microsoft Office Publisher Security Feature Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-02-14",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-02-14"
    },
    {
      "value": "CVE-2023-21823",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1868",
          "title": "CISA KEV: CVE-2023-21823 \u2014 Microsoft Windows Graphic Component Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-02-14",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-02-14"
    },
    {
      "value": "CVE-2023-23376",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1866",
          "title": "CISA KEV: CVE-2023-23376 \u2014 Microsoft Windows Common Log File System (CLFS) Driver Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-02-14",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-02-14"
    },
    {
      "value": "CVE-2023-23514",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1867",
          "title": "CISA KEV: CVE-2023-23529 \u2014 Apple Multiple Products WebKit Type Confusion Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-02-14",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-02-14"
    },
    {
      "value": "CVE-2023-23529",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1867",
          "title": "CISA KEV: CVE-2023-23529 \u2014 Apple Multiple Products WebKit Type Confusion Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-02-14",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-02-14"
    },
    {
      "value": "CVE-2015-2291",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1869",
          "title": "CISA KEV: CVE-2015-2291 \u2014 Intel Ethernet Diagnostics Driver for Windows Denial-of-Service Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-02-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-02-10"
    },
    {
      "value": "CVE-2022-24989",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1870",
          "title": "CISA KEV: CVE-2022-24990 \u2014 TerraMaster OS Remote Command Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-02-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-02-10"
    },
    {
      "value": "CVE-2022-24990",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1870",
          "title": "CISA KEV: CVE-2022-24990 \u2014 TerraMaster OS Remote Command Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-02-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-02-10"
    },
    {
      "value": "CVE-2023-0669",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1871",
          "title": "CISA KEV: CVE-2023-0669 \u2014 Fortra GoAnywhere MFT Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-02-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-02-10"
    },
    {
      "value": "b6e82a4e6d8b715588bf4252f896e40b766ef981d941d0968f29a3a444f68fef",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1869",
          "title": "CISA KEV: CVE-2015-2291 \u2014 Intel Ethernet Diagnostics Driver for Windows Denial-of-Service Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-02-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-02-10"
    },
    {
      "value": "e23283e75ed2bdabf6c703236f5518b4ca37d32f78d3d65b073496c12c643cfe",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1869",
          "title": "CISA KEV: CVE-2015-2291 \u2014 Intel Ethernet Diagnostics Driver for Windows Denial-of-Service Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-02-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-02-10"
    },
    {
      "value": "CVE-2022-21587",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1877",
          "title": "CISA KEV: CVE-2022-21587 \u2014 Oracle E-Business Suite Unspecified Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-02-02",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-02-02"
    },
    {
      "value": "CVE-2023-22952",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1878",
          "title": "CISA KEV: CVE-2023-22952 \u2014 Multiple SugarCRM Products Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-02-02",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-02-02"
    },
    {
      "value": "CVE-2017-11317",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1882",
          "title": "CISA KEV: CVE-2017-11357 \u2014 Telerik UI for ASP.NET AJAX Insecure Direct Object Reference Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-01-26",
          "sev": "crit"
        },
        {
          "id": "art-2350",
          "title": "CISA KEV: CVE-2017-11317 \u2014 Telerik UI for ASP.NET AJAX Unrestricted File Upload Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-04-11",
          "sev": "crit"
        },
        {
          "id": "art-3012",
          "title": "CISA KEV: CVE-2019-18935 \u2014 Progress Telerik UI for ASP.NET AJAX Deserialization of Untrusted Data Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        },
        {
          "id": "art-3047",
          "title": "CISA KEV: CVE-2017-9248 \u2014 Progress Telerik UI for ASP.NET AJAX and Sitefinity Cryptographic Weakness Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-01-26"
    },
    {
      "value": "CVE-2017-11357",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1882",
          "title": "CISA KEV: CVE-2017-11357 \u2014 Telerik UI for ASP.NET AJAX Insecure Direct Object Reference Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-01-26",
          "sev": "crit"
        },
        {
          "id": "art-2350",
          "title": "CISA KEV: CVE-2017-11317 \u2014 Telerik UI for ASP.NET AJAX Unrestricted File Upload Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-04-11",
          "sev": "crit"
        },
        {
          "id": "art-3012",
          "title": "CISA KEV: CVE-2019-18935 \u2014 Progress Telerik UI for ASP.NET AJAX Deserialization of Untrusted Data Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        },
        {
          "id": "art-3047",
          "title": "CISA KEV: CVE-2017-9248 \u2014 Progress Telerik UI for ASP.NET AJAX and Sitefinity Cryptographic Weakness Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-01-26"
    },
    {
      "value": "CVE-2019-",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-1883",
          "title": "Snyk enhances ServiceNow with comprehensive insights into vulnerabilities in open source software",
          "link": "https://snyk.io/blog/snyk-servicenow-partnership/",
          "published": "2023-01-24",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-01-24"
    },
    {
      "value": "CVE-2022-47966",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1884",
          "title": "CISA KEV: CVE-2022-47966 \u2014 Zoho ManageEngine Multiple Products Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-01-23",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-01-23"
    },
    {
      "value": "0xx1.kaspenskyupdates.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1884",
          "title": "CISA KEV: CVE-2022-47966 \u2014 Zoho ManageEngine Multiple Products Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-01-23",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-01-23"
    },
    {
      "value": "icy51j1b6sbewpauivxwfrmcu30vok.oastify.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1884",
          "title": "CISA KEV: CVE-2022-47966 \u2014 Zoho ManageEngine Multiple Products Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-01-23",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-01-23"
    },
    {
      "value": "satoshidisk.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1884",
          "title": "CISA KEV: CVE-2022-47966 \u2014 Zoho ManageEngine Multiple Products Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-01-23",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-01-23"
    },
    {
      "value": "104.223.35.221",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1884",
          "title": "CISA KEV: CVE-2022-47966 \u2014 Zoho ManageEngine Multiple Products Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-01-23",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-01-23"
    },
    {
      "value": "111.68.7.122",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1884",
          "title": "CISA KEV: CVE-2022-47966 \u2014 Zoho ManageEngine Multiple Products Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-01-23",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-01-23"
    },
    {
      "value": "135.181.121.232",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1884",
          "title": "CISA KEV: CVE-2022-47966 \u2014 Zoho ManageEngine Multiple Products Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-01-23",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-01-23"
    },
    {
      "value": "139.99.118.61",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1884",
          "title": "CISA KEV: CVE-2022-47966 \u2014 Zoho ManageEngine Multiple Products Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-01-23",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-01-23"
    },
    {
      "value": "143.244.153.229",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1884",
          "title": "CISA KEV: CVE-2022-47966 \u2014 Zoho ManageEngine Multiple Products Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-01-23",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-01-23"
    },
    {
      "value": "146.4.21.94",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1884",
          "title": "CISA KEV: CVE-2022-47966 \u2014 Zoho ManageEngine Multiple Products Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-01-23",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-01-23"
    },
    {
      "value": "146.70.126.178",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1884",
          "title": "CISA KEV: CVE-2022-47966 \u2014 Zoho ManageEngine Multiple Products Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-01-23",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-01-23"
    },
    {
      "value": "149.28.57.130",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1884",
          "title": "CISA KEV: CVE-2022-47966 \u2014 Zoho ManageEngine Multiple Products Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-01-23",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-01-23"
    },
    {
      "value": "160.20.147.145",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1884",
          "title": "CISA KEV: CVE-2022-47966 \u2014 Zoho ManageEngine Multiple Products Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-01-23",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-01-23"
    },
    {
      "value": "185.163.45.86",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1884",
          "title": "CISA KEV: CVE-2022-47966 \u2014 Zoho ManageEngine Multiple Products Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-01-23",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-01-23"
    },
    {
      "value": "192.142.226.153",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1884",
          "title": "CISA KEV: CVE-2022-47966 \u2014 Zoho ManageEngine Multiple Products Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-01-23",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-01-23"
    },
    {
      "value": "212.192.246.232",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1884",
          "title": "CISA KEV: CVE-2022-47966 \u2014 Zoho ManageEngine Multiple Products Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-01-23",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-01-23"
    },
    {
      "value": "45.146.7.20",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1884",
          "title": "CISA KEV: CVE-2022-47966 \u2014 Zoho ManageEngine Multiple Products Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-01-23",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-01-23"
    },
    {
      "value": "45.154.14.194",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1884",
          "title": "CISA KEV: CVE-2022-47966 \u2014 Zoho ManageEngine Multiple Products Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-01-23",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-01-23"
    },
    {
      "value": "5.255.107.19",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1884",
          "title": "CISA KEV: CVE-2022-47966 \u2014 Zoho ManageEngine Multiple Products Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-01-23",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-01-23"
    },
    {
      "value": "78.141.247.105",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1884",
          "title": "CISA KEV: CVE-2022-47966 \u2014 Zoho ManageEngine Multiple Products Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-01-23",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-01-23"
    },
    {
      "value": "79.141.162.36",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1884",
          "title": "CISA KEV: CVE-2022-47966 \u2014 Zoho ManageEngine Multiple Products Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-01-23",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-01-23"
    },
    {
      "value": "80.85.156.184",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1884",
          "title": "CISA KEV: CVE-2022-47966 \u2014 Zoho ManageEngine Multiple Products Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-01-23",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-01-23"
    },
    {
      "value": "199cb4936f7ef64fa134eb3cefff0518",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1884",
          "title": "CISA KEV: CVE-2022-47966 \u2014 Zoho ManageEngine Multiple Products Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-01-23",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-01-23"
    },
    {
      "value": "383b0d0dda2d7557b5cca518f53256b9",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1884",
          "title": "CISA KEV: CVE-2022-47966 \u2014 Zoho ManageEngine Multiple Products Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-01-23",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-01-23"
    },
    {
      "value": "4960591cc04b080827020393f21c405b",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1884",
          "title": "CISA KEV: CVE-2022-47966 \u2014 Zoho ManageEngine Multiple Products Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-01-23",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-01-23"
    },
    {
      "value": "527c71c523d275c8367b67bbebf48e9f",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1884",
          "title": "CISA KEV: CVE-2022-47966 \u2014 Zoho ManageEngine Multiple Products Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-01-23",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-01-23"
    },
    {
      "value": "53deb494057bb8e5d72b0f53bab1cb44",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1884",
          "title": "CISA KEV: CVE-2022-47966 \u2014 Zoho ManageEngine Multiple Products Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-01-23",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-01-23"
    },
    {
      "value": "5c0227204548c5a768c2e11da02ff774",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1884",
          "title": "CISA KEV: CVE-2022-47966 \u2014 Zoho ManageEngine Multiple Products Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-01-23",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-01-23"
    },
    {
      "value": "61e82cae3c97887e4b367e507c4995ed",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1884",
          "title": "CISA KEV: CVE-2022-47966 \u2014 Zoho ManageEngine Multiple Products Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-01-23",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-01-23"
    },
    {
      "value": "6e3b1169aac82b4d0e8ea0a24d1477d5",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1884",
          "title": "CISA KEV: CVE-2022-47966 \u2014 Zoho ManageEngine Multiple Products Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-01-23",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-01-23"
    },
    {
      "value": "8da896375e5d33e7d7486dbf71d008d8",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1884",
          "title": "CISA KEV: CVE-2022-47966 \u2014 Zoho ManageEngine Multiple Products Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-01-23",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-01-23"
    },
    {
      "value": "9758c592ef4b9a2279f8e80e992248b6",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1884",
          "title": "CISA KEV: CVE-2022-47966 \u2014 Zoho ManageEngine Multiple Products Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-01-23",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-01-23"
    },
    {
      "value": "988038d8407d510c905183b8f6c421d6",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1884",
          "title": "CISA KEV: CVE-2022-47966 \u2014 Zoho ManageEngine Multiple Products Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-01-23",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-01-23"
    },
    {
      "value": "9a1d9fe9b1223273c314632d04008384",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1884",
          "title": "CISA KEV: CVE-2022-47966 \u2014 Zoho ManageEngine Multiple Products Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-01-23",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-01-23"
    },
    {
      "value": "b777226ef93acdb168980bbca82a48fe",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1884",
          "title": "CISA KEV: CVE-2022-47966 \u2014 Zoho ManageEngine Multiple Products Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-01-23",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-01-23"
    },
    {
      "value": "bfe79b11ee1b82ae95b14fd53b6c3fd3",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1884",
          "title": "CISA KEV: CVE-2022-47966 \u2014 Zoho ManageEngine Multiple Products Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-01-23",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-01-23"
    },
    {
      "value": "c027d641c4c1e9d9ad048cda2af85db6",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1884",
          "title": "CISA KEV: CVE-2022-47966 \u2014 Zoho ManageEngine Multiple Products Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-01-23",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-01-23"
    },
    {
      "value": "e0fb946c00b140693e3cf5de258c22a1",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1884",
          "title": "CISA KEV: CVE-2022-47966 \u2014 Zoho ManageEngine Multiple Products Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-01-23",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-01-23"
    },
    {
      "value": "e2c644343fad304ccde047f3301066ba",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1884",
          "title": "CISA KEV: CVE-2022-47966 \u2014 Zoho ManageEngine Multiple Products Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-01-23",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-01-23"
    },
    {
      "value": "e3cff253b9ad9050eb57d957624b796e",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1884",
          "title": "CISA KEV: CVE-2022-47966 \u2014 Zoho ManageEngine Multiple Products Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-01-23",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-01-23"
    },
    {
      "value": "edac597788e7c3df14a5fdcd13ee8916",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1884",
          "title": "CISA KEV: CVE-2022-47966 \u2014 Zoho ManageEngine Multiple Products Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-01-23",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-01-23"
    },
    {
      "value": "CVE-2022-44877",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1886",
          "title": "CISA KEV: CVE-2022-44877 \u2014 CWP Control Web Panel OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-01-17",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-01-17"
    },
    {
      "value": "CVE-2022-41040",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1892",
          "title": "CISA KEV: CVE-2022-41080 \u2014 Microsoft Exchange Server Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-01-10",
          "sev": "crit"
        },
        {
          "id": "art-2014",
          "title": "CISA KEV: CVE-2022-41082 \u2014 Microsoft Exchange Server Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-09-30",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-01-10"
    },
    {
      "value": "CVE-2022-41080",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1892",
          "title": "CISA KEV: CVE-2022-41080 \u2014 Microsoft Exchange Server Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-01-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-01-10"
    },
    {
      "value": "CVE-2022-41082",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1892",
          "title": "CISA KEV: CVE-2022-41080 \u2014 Microsoft Exchange Server Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-01-10",
          "sev": "crit"
        },
        {
          "id": "art-2014",
          "title": "CISA KEV: CVE-2022-41082 \u2014 Microsoft Exchange Server Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-09-30",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-01-10"
    },
    {
      "value": "CVE-2023-21674",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1893",
          "title": "CISA KEV: CVE-2023-21674 \u2014 Microsoft Windows Advanced Local Procedure Call (ALPC) Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-01-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-01-10"
    },
    {
      "value": "45.76.141.84",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1892",
          "title": "CISA KEV: CVE-2022-41080 \u2014 Microsoft Exchange Server Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-01-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-01-10"
    },
    {
      "value": "45.76.143.143",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1892",
          "title": "CISA KEV: CVE-2022-41080 \u2014 Microsoft Exchange Server Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2023-01-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2023-01-10"
    },
    {
      "value": "potrax.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-1895",
          "title": "Supply chain security incident at CircleCI: Rotate your secrets",
          "link": "https://snyk.io/blog/supply-chain-security-incident-circleci-secrets/",
          "published": "2023-01-07",
          "sev": "high"
        }
      ],
      "first_seen": "2023-01-07"
    },
    {
      "value": "111.90.149.55",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-1895",
          "title": "Supply chain security incident at CircleCI: Rotate your secrets",
          "link": "https://snyk.io/blog/supply-chain-security-incident-circleci-secrets/",
          "published": "2023-01-07",
          "sev": "high"
        }
      ],
      "first_seen": "2023-01-07"
    },
    {
      "value": "178.249.214.10",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-1895",
          "title": "Supply chain security incident at CircleCI: Rotate your secrets",
          "link": "https://snyk.io/blog/supply-chain-security-incident-circleci-secrets/",
          "published": "2023-01-07",
          "sev": "high"
        }
      ],
      "first_seen": "2023-01-07"
    },
    {
      "value": "178.249.214.25",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-1895",
          "title": "Supply chain security incident at CircleCI: Rotate your secrets",
          "link": "https://snyk.io/blog/supply-chain-security-incident-circleci-secrets/",
          "published": "2023-01-07",
          "sev": "high"
        }
      ],
      "first_seen": "2023-01-07"
    },
    {
      "value": "188.68.229.52",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-1895",
          "title": "Supply chain security incident at CircleCI: Rotate your secrets",
          "link": "https://snyk.io/blog/supply-chain-security-incident-circleci-secrets/",
          "published": "2023-01-07",
          "sev": "high"
        }
      ],
      "first_seen": "2023-01-07"
    },
    {
      "value": "72.18.132.58",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-1895",
          "title": "Supply chain security incident at CircleCI: Rotate your secrets",
          "link": "https://snyk.io/blog/supply-chain-security-incident-circleci-secrets/",
          "published": "2023-01-07",
          "sev": "high"
        }
      ],
      "first_seen": "2023-01-07"
    },
    {
      "value": "89.36.78.109",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-1895",
          "title": "Supply chain security incident at CircleCI: Rotate your secrets",
          "link": "https://snyk.io/blog/supply-chain-security-incident-circleci-secrets/",
          "published": "2023-01-07",
          "sev": "high"
        }
      ],
      "first_seen": "2023-01-07"
    },
    {
      "value": "89.36.78.135",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-1895",
          "title": "Supply chain security incident at CircleCI: Rotate your secrets",
          "link": "https://snyk.io/blog/supply-chain-security-incident-circleci-secrets/",
          "published": "2023-01-07",
          "sev": "high"
        }
      ],
      "first_seen": "2023-01-07"
    },
    {
      "value": "89.36.78.75",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-1895",
          "title": "Supply chain security incident at CircleCI: Rotate your secrets",
          "link": "https://snyk.io/blog/supply-chain-security-incident-circleci-secrets/",
          "published": "2023-01-07",
          "sev": "high"
        }
      ],
      "first_seen": "2023-01-07"
    },
    {
      "value": "8913e38592228adc067d82f66c150d87004ec946e579d4a00c53b61444ff35bf",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-1895",
          "title": "Supply chain security incident at CircleCI: Rotate your secrets",
          "link": "https://snyk.io/blog/supply-chain-security-incident-circleci-secrets/",
          "published": "2023-01-07",
          "sev": "high"
        }
      ],
      "first_seen": "2023-01-07"
    },
    {
      "value": "CVE-2018-18809",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1899",
          "title": "CISA KEV: CVE-2018-18809 \u2014 TIBCO JasperReports Library Directory Traversal Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-12-29",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-12-29"
    },
    {
      "value": "CVE-2018-5430",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1898",
          "title": "CISA KEV: CVE-2018-5430 \u2014 TIBCO JasperReports Server Information Disclosure Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-12-29",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-12-29"
    },
    {
      "value": "CVE-2022-31692",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-1906",
          "title": "Exploring the Spring Security authorization bypass (CVE-2022-31692)",
          "link": "https://snyk.io/blog/spring-security-authorization-bypass-cve-2022-31692/",
          "published": "2022-12-16",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-12-16"
    },
    {
      "value": "CVE-2022-42856",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1910",
          "title": "CISA KEV: CVE-2022-42856 \u2014 Apple iOS Type Confusion Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-12-14",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-12-14"
    },
    {
      "value": "CVE-2022-26500",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1915",
          "title": "CISA KEV: CVE-2022-26500 \u2014 Veeam Backup & Replication Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-12-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-12-13"
    },
    {
      "value": "CVE-2022-26501",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1916",
          "title": "CISA KEV: CVE-2022-26501 \u2014 Veeam Backup & Replication Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-12-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-12-13"
    },
    {
      "value": "CVE-2022-27518",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1914",
          "title": "CISA KEV: CVE-2022-27518 \u2014 Citrix Application Delivery Controller (ADC) and Gateway Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-12-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-12-13"
    },
    {
      "value": "103.131.189.143",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1912",
          "title": "CISA KEV: CVE-2022-42475 \u2014 Fortinet FortiOS Heap-Based Buffer Overflow Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-12-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-12-13"
    },
    {
      "value": "107.148.27.117",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1912",
          "title": "CISA KEV: CVE-2022-42475 \u2014 Fortinet FortiOS Heap-Based Buffer Overflow Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-12-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-12-13"
    },
    {
      "value": "137.175.30.138",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1912",
          "title": "CISA KEV: CVE-2022-42475 \u2014 Fortinet FortiOS Heap-Based Buffer Overflow Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-12-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-12-13"
    },
    {
      "value": "139.180.128.142",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1912",
          "title": "CISA KEV: CVE-2022-42475 \u2014 Fortinet FortiOS Heap-Based Buffer Overflow Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-12-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-12-13"
    },
    {
      "value": "139.180.184.197",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1912",
          "title": "CISA KEV: CVE-2022-42475 \u2014 Fortinet FortiOS Heap-Based Buffer Overflow Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-12-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-12-13"
    },
    {
      "value": "139.99.35.116",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1912",
          "title": "CISA KEV: CVE-2022-42475 \u2014 Fortinet FortiOS Heap-Based Buffer Overflow Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-12-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-12-13"
    },
    {
      "value": "139.99.37.119",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1912",
          "title": "CISA KEV: CVE-2022-42475 \u2014 Fortinet FortiOS Heap-Based Buffer Overflow Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-12-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-12-13"
    },
    {
      "value": "146.70.157.133",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1912",
          "title": "CISA KEV: CVE-2022-42475 \u2014 Fortinet FortiOS Heap-Based Buffer Overflow Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-12-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-12-13"
    },
    {
      "value": "155.138.224.122",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1912",
          "title": "CISA KEV: CVE-2022-42475 \u2014 Fortinet FortiOS Heap-Based Buffer Overflow Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-12-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-12-13"
    },
    {
      "value": "156.251.162.111",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1912",
          "title": "CISA KEV: CVE-2022-42475 \u2014 Fortinet FortiOS Heap-Based Buffer Overflow Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-12-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-12-13"
    },
    {
      "value": "156.251.162.76",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1912",
          "title": "CISA KEV: CVE-2022-42475 \u2014 Fortinet FortiOS Heap-Based Buffer Overflow Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-12-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-12-13"
    },
    {
      "value": "156.251.163.122",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1912",
          "title": "CISA KEV: CVE-2022-42475 \u2014 Fortinet FortiOS Heap-Based Buffer Overflow Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-12-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-12-13"
    },
    {
      "value": "156.251.163.19",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1912",
          "title": "CISA KEV: CVE-2022-42475 \u2014 Fortinet FortiOS Heap-Based Buffer Overflow Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-12-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-12-13"
    },
    {
      "value": "158.247.221.101",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1912",
          "title": "CISA KEV: CVE-2022-42475 \u2014 Fortinet FortiOS Heap-Based Buffer Overflow Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-12-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-12-13"
    },
    {
      "value": "172.247.168.153",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1912",
          "title": "CISA KEV: CVE-2022-42475 \u2014 Fortinet FortiOS Heap-Based Buffer Overflow Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-12-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-12-13"
    },
    {
      "value": "185.174.136.20",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1912",
          "title": "CISA KEV: CVE-2022-42475 \u2014 Fortinet FortiOS Heap-Based Buffer Overflow Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-12-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-12-13"
    },
    {
      "value": "185.250.149.32",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1912",
          "title": "CISA KEV: CVE-2022-42475 \u2014 Fortinet FortiOS Heap-Based Buffer Overflow Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-12-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-12-13"
    },
    {
      "value": "188.34.130.40",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1912",
          "title": "CISA KEV: CVE-2022-42475 \u2014 Fortinet FortiOS Heap-Based Buffer Overflow Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-12-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-12-13"
    },
    {
      "value": "193.36.119.61",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1912",
          "title": "CISA KEV: CVE-2022-42475 \u2014 Fortinet FortiOS Heap-Based Buffer Overflow Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-12-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-12-13"
    },
    {
      "value": "194.62.42.105",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1912",
          "title": "CISA KEV: CVE-2022-42475 \u2014 Fortinet FortiOS Heap-Based Buffer Overflow Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-12-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-12-13"
    },
    {
      "value": "45.86.229.220",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1912",
          "title": "CISA KEV: CVE-2022-42475 \u2014 Fortinet FortiOS Heap-Based Buffer Overflow Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-12-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-12-13"
    },
    {
      "value": "45.86.231.71",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1912",
          "title": "CISA KEV: CVE-2022-42475 \u2014 Fortinet FortiOS Heap-Based Buffer Overflow Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-12-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-12-13"
    },
    {
      "value": "66.42.91.32",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1912",
          "title": "CISA KEV: CVE-2022-42475 \u2014 Fortinet FortiOS Heap-Based Buffer Overflow Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-12-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-12-13"
    },
    {
      "value": "08cbaafb176ce6118f7e4e0b2d2d77cf",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1912",
          "title": "CISA KEV: CVE-2022-42475 \u2014 Fortinet FortiOS Heap-Based Buffer Overflow Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-12-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-12-13"
    },
    {
      "value": "12e28c14bb7f7b9513a02e5857592ad7",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1912",
          "title": "CISA KEV: CVE-2022-42475 \u2014 Fortinet FortiOS Heap-Based Buffer Overflow Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-12-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-12-13"
    },
    {
      "value": "3191cb2e06e9a30792309813793f78b6",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1912",
          "title": "CISA KEV: CVE-2022-42475 \u2014 Fortinet FortiOS Heap-Based Buffer Overflow Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-12-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-12-13"
    },
    {
      "value": "4548fa6625cb154ab320833186117393",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1912",
          "title": "CISA KEV: CVE-2022-42475 \u2014 Fortinet FortiOS Heap-Based Buffer Overflow Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-12-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-12-13"
    },
    {
      "value": "54bbea35b095ddfe9740df97b693627b",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1912",
          "title": "CISA KEV: CVE-2022-42475 \u2014 Fortinet FortiOS Heap-Based Buffer Overflow Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-12-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-12-13"
    },
    {
      "value": "856341349dd954d82b112ba9165c4563",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1912",
          "title": "CISA KEV: CVE-2022-42475 \u2014 Fortinet FortiOS Heap-Based Buffer Overflow Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-12-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-12-13"
    },
    {
      "value": "ae0839351721db5a9c269fd75dcb57ce",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1912",
          "title": "CISA KEV: CVE-2022-42475 \u2014 Fortinet FortiOS Heap-Based Buffer Overflow Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-12-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-12-13"
    },
    {
      "value": "bdc2d2f5d5246f8956711bcce9f456b6",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1912",
          "title": "CISA KEV: CVE-2022-42475 \u2014 Fortinet FortiOS Heap-Based Buffer Overflow Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-12-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-12-13"
    },
    {
      "value": "e3f640d8785c0c864739529889b1863a",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1912",
          "title": "CISA KEV: CVE-2022-42475 \u2014 Fortinet FortiOS Heap-Based Buffer Overflow Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-12-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-12-13"
    },
    {
      "value": "e5d989b651b3eb351e10e408d5a062b3",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1912",
          "title": "CISA KEV: CVE-2022-42475 \u2014 Fortinet FortiOS Heap-Based Buffer Overflow Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-12-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-12-13"
    },
    {
      "value": "f68c3f72270800ea675889e82bb02fb8",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1912",
          "title": "CISA KEV: CVE-2022-42475 \u2014 Fortinet FortiOS Heap-Based Buffer Overflow Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-12-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-12-13"
    },
    {
      "value": "0184e3d3dd8f4778d192d07e2caf44211141a570d45bb47a87894c68ebebeabb",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1912",
          "title": "CISA KEV: CVE-2022-42475 \u2014 Fortinet FortiOS Heap-Based Buffer Overflow Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-12-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-12-13"
    },
    {
      "value": "26f5bc698dfec8e771b781dc19941e2d657eb87fe8669e1f75d9e5a1bb4db1db",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1913",
          "title": "CISA KEV: CVE-2022-44698 \u2014 Microsoft Defender SmartScreen Security Feature Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-12-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-12-13"
    },
    {
      "value": "3da407c1a30d810aaff9a04dfc1ef5861062ebdf0e6d0f6823ca682ca08c37da",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1912",
          "title": "CISA KEV: CVE-2022-42475 \u2014 Fortinet FortiOS Heap-Based Buffer Overflow Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-12-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-12-13"
    },
    {
      "value": "61aae0e18c41ec4f610676680d26f6c6e1d4d5aa4e5092e40915fe806b679cd4",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1912",
          "title": "CISA KEV: CVE-2022-42475 \u2014 Fortinet FortiOS Heap-Based Buffer Overflow Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-12-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-12-13"
    },
    {
      "value": "6fb41b33304b65e6e35f04e8cc70f7a24cd36e29bbb97266de68afcf113f9a5f",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1913",
          "title": "CISA KEV: CVE-2022-44698 \u2014 Microsoft Defender SmartScreen Security Feature Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-12-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-12-13"
    },
    {
      "value": "8ca16991684f7384c12b6622b8d1bcd23bc27f186f499c2059770ddd3031f274",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1913",
          "title": "CISA KEV: CVE-2022-44698 \u2014 Microsoft Defender SmartScreen Security Feature Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-12-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-12-13"
    },
    {
      "value": "c5df8f8328103380943d8ead5345ca9fe8a9d495634db53cf9ea3266e353a3b1",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1913",
          "title": "CISA KEV: CVE-2022-44698 \u2014 Microsoft Defender SmartScreen Security Feature Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-12-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-12-13"
    },
    {
      "value": "CVE-2022-22984",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-1925",
          "title": "Code injection vulnerabilities (CVSSv3 5.8) found in Snyk CLI and IDE plugins",
          "link": "https://snyk.io/blog/code-injection-vulns-cli-ide-plugins-medium-sev/",
          "published": "2022-11-30",
          "sev": "high"
        }
      ],
      "first_seen": "2022-11-30"
    },
    {
      "value": "CVE-2022-24441",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-1925",
          "title": "Code injection vulnerabilities (CVSSv3 5.8) found in Snyk CLI and IDE plugins",
          "link": "https://snyk.io/blog/code-injection-vulns-cli-ide-plugins-medium-sev/",
          "published": "2022-11-30",
          "sev": "high"
        }
      ],
      "first_seen": "2022-11-30"
    },
    {
      "value": "CVE-2021-35587",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1929",
          "title": "CISA KEV: CVE-2021-35587 \u2014 Oracle Fusion Middleware Unspecified Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-11-28",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-11-28"
    },
    {
      "value": "CVE-2022-4135",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1930",
          "title": "CISA KEV: CVE-2022-4135 \u2014 Google Chromium GPU Heap Buffer Overflow Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-11-28",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-11-28"
    },
    {
      "value": "CVE-2022-41049",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1941",
          "title": "CISA KEV: CVE-2022-41049 \u2014 Microsoft Windows Mark of the Web (MOTW) Security Feature Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-11-14",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-11-14"
    },
    {
      "value": "CVE-2022-26068",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-1945",
          "title": "Fetch the Flag CTF 2022 writeup: Not So Smart Fridge",
          "link": "https://snyk.io/blog/fetch-the-flag-ctf-2022-writeup-not-so-smart-fridge/",
          "published": "2022-11-10",
          "sev": "high"
        }
      ],
      "first_seen": "2022-11-10"
    },
    {
      "value": "moongoose.c.ctf-snyk.io",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-1948",
          "title": "Fetch the Flag CTF 2022 writeup: Moongoose",
          "link": "https://snyk.io/blog/fetch-the-flag-ctf-2022-writeup-moongoose/",
          "published": "2022-11-10",
          "sev": "high"
        }
      ],
      "first_seen": "2022-11-10"
    },
    {
      "value": "pay-attention.c.ctf-snyk.io",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-1947",
          "title": "Fetch the Flag CTF 2022 writeup: Treasure Trove",
          "link": "https://snyk.io/blog/fetch-the-flag-ctf-2022-writeup-treasure-trove/",
          "published": "2022-11-10",
          "sev": "high"
        }
      ],
      "first_seen": "2022-11-10"
    },
    {
      "value": "disposable-message.c.ctf-snyk.io",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "med",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-1944",
          "title": "Fetch the Flag CTF 2022 writeup: Disposable Message",
          "link": "https://snyk.io/blog/fetch-the-flag-ctf-2022-writeup-disposable-message/",
          "published": "2022-11-10",
          "sev": "med"
        }
      ],
      "first_seen": "2022-11-10"
    },
    {
      "value": "CVE-2014-3744",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-1950",
          "title": "Fetch the Flag CTF 2022 writeup: File Explorer",
          "link": "https://snyk.io/blog/fetch-the-flag-ctf-2022-writeup-file-explorer/",
          "published": "2022-11-09",
          "sev": "high"
        }
      ],
      "first_seen": "2022-11-09"
    },
    {
      "value": "file-explorer.c.ctf-snyk.io",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-1950",
          "title": "Fetch the Flag CTF 2022 writeup: File Explorer",
          "link": "https://snyk.io/blog/fetch-the-flag-ctf-2022-writeup-file-explorer/",
          "published": "2022-11-09",
          "sev": "high"
        }
      ],
      "first_seen": "2022-11-09"
    },
    {
      "value": "CVE-2021-25337",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1957",
          "title": "CISA KEV: CVE-2021-25337 \u2014 Samsung Mobile Devices Improper Access Control Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-11-08",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-11-08"
    },
    {
      "value": "CVE-2021-25369",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1957",
          "title": "CISA KEV: CVE-2021-25337 \u2014 Samsung Mobile Devices Improper Access Control Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-11-08",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-11-08"
    },
    {
      "value": "CVE-2021-25370",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1957",
          "title": "CISA KEV: CVE-2021-25337 \u2014 Samsung Mobile Devices Improper Access Control Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-11-08",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-11-08"
    },
    {
      "value": "CVE-2022-23812",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-1952",
          "title": "NPM security: preventing supply chain attacks",
          "link": "https://snyk.io/blog/npm-security-preventing-supply-chain-attacks/",
          "published": "2022-11-08",
          "sev": "crit"
        },
        {
          "id": "art-2058",
          "title": "The npm faker package and the unexpected demise of open source libraries",
          "link": "https://snyk.io/blog/npm-faker-package-open-source-libraries/",
          "published": "2022-09-02",
          "sev": "crit"
        },
        {
          "id": "art-2480",
          "title": "Protestware is trending in open source: 4 different types and their impact",
          "link": "https://snyk.io/blog/protestware-open-source-types-impact/",
          "published": "2022-03-22",
          "sev": "crit"
        },
        {
          "id": "art-2482",
          "title": "Alert: peacenotwar module sabotages npm developers in the node-ipc package to protest the invasion of Ukraine",
          "link": "https://snyk.io/blog/peacenotwar-malicious-npm-node-ipc-package-vulnerability/",
          "published": "2022-03-16",
          "sev": "high"
        }
      ],
      "first_seen": "2022-11-08"
    },
    {
      "value": "CVE-2022-41073",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1954",
          "title": "CISA KEV: CVE-2022-41073 \u2014 Microsoft Windows Print Spooler Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-11-08",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-11-08"
    },
    {
      "value": "CVE-2022-41091",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1953",
          "title": "CISA KEV: CVE-2022-41091 \u2014 Microsoft Windows Mark of the Web (MOTW) Security Feature Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-11-08",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-11-08"
    },
    {
      "value": "CVE-2022-41125",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1955",
          "title": "CISA KEV: CVE-2022-41125 \u2014 Microsoft Windows CNG Key Isolation Service Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-11-08",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-11-08"
    },
    {
      "value": "ms-office.services",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1956",
          "title": "CISA KEV: CVE-2022-41128 \u2014 Microsoft Windows Scripting Languages Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-11-08",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-11-08"
    },
    {
      "value": "ms-offices.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1956",
          "title": "CISA KEV: CVE-2022-41128 \u2014 Microsoft Windows Scripting Languages Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-11-08",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-11-08"
    },
    {
      "value": "openxmlformat.org",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1956",
          "title": "CISA KEV: CVE-2022-41128 \u2014 Microsoft Windows Scripting Languages Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-11-08",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-11-08"
    },
    {
      "value": "template-openxml.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1956",
          "title": "CISA KEV: CVE-2022-41128 \u2014 Microsoft Windows Scripting Languages Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-11-08",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-11-08"
    },
    {
      "value": "word-template.net",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1956",
          "title": "CISA KEV: CVE-2022-41128 \u2014 Microsoft Windows Scripting Languages Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-11-08",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-11-08"
    },
    {
      "value": "08f93351d0d3905bee5b0c2b9215d448abb0d3cf49c0f8b666c46df4fcc007cb",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1956",
          "title": "CISA KEV: CVE-2022-41128 \u2014 Microsoft Windows Scripting Languages Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-11-08",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-11-08"
    },
    {
      "value": "3bff571823421c013e79cc10793f238f4252f7d7ac91f9ef41435af0a8c09a39",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1956",
          "title": "CISA KEV: CVE-2022-41128 \u2014 Microsoft Windows Scripting Languages Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-11-08",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-11-08"
    },
    {
      "value": "56ca24b57c4559f834c190d50b0fe89dd4a4040a078ca1f267d0bbc7849e9ed7",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1956",
          "title": "CISA KEV: CVE-2022-41128 \u2014 Microsoft Windows Scripting Languages Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-11-08",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-11-08"
    },
    {
      "value": "926a947ea2b59d3e9a5a6875b4de2bd071b15260370f4da5e2a60ece3517a32f",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1956",
          "title": "CISA KEV: CVE-2022-41128 \u2014 Microsoft Windows Scripting Languages Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-11-08",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-11-08"
    },
    {
      "value": "af5fb99d3ff18bc625fb63f792ed7cd955171ab509c2f8e7c7ee44515e09cebf",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1956",
          "title": "CISA KEV: CVE-2022-41128 \u2014 Microsoft Windows Scripting Languages Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-11-08",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-11-08"
    },
    {
      "value": "c49b4d370ad0dcd1e28ee8f525ac8e3c12a34cfcf62ebb733ec74cca59b29f82",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1956",
          "title": "CISA KEV: CVE-2022-41128 \u2014 Microsoft Windows Scripting Languages Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-11-08",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-11-08"
    },
    {
      "value": "CVE-2022-3723",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1971",
          "title": "CISA KEV: CVE-2022-3723 \u2014 Google Chromium V8 Type Confusion Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-10-28",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-10-28"
    },
    {
      "value": "CVE-2022-42827",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1975",
          "title": "CISA KEV: CVE-2022-42827 \u2014 Apple iOS and iPadOS Out-of-Bounds Write Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-10-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-10-25"
    },
    {
      "value": "CVE-2018-19320",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1979",
          "title": "CISA KEV: CVE-2018-19323 \u2014 GIGABYTE Multiple Products Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-10-24",
          "sev": "crit"
        },
        {
          "id": "art-1982",
          "title": "CISA KEV: CVE-2018-19320 \u2014 GIGABYTE Multiple Products Unspecified Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-10-24",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-10-24"
    },
    {
      "value": "CVE-2018-19321",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1979",
          "title": "CISA KEV: CVE-2018-19323 \u2014 GIGABYTE Multiple Products Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-10-24",
          "sev": "crit"
        },
        {
          "id": "art-1981",
          "title": "CISA KEV: CVE-2018-19321 \u2014 GIGABYTE Multiple Products Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-10-24",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-10-24"
    },
    {
      "value": "CVE-2018-19322",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1979",
          "title": "CISA KEV: CVE-2018-19323 \u2014 GIGABYTE Multiple Products Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-10-24",
          "sev": "crit"
        },
        {
          "id": "art-1980",
          "title": "CISA KEV: CVE-2018-19322 \u2014 GIGABYTE Multiple Products Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-10-24",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-10-24"
    },
    {
      "value": "CVE-2018-19323",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1979",
          "title": "CISA KEV: CVE-2018-19323 \u2014 GIGABYTE Multiple Products Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-10-24",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-10-24"
    },
    {
      "value": "CVE-2020-3153",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1978",
          "title": "CISA KEV: CVE-2020-3153 \u2014 Cisco AnyConnect Secure Mobility Client for Windows Uncontrolled Search Path Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-10-24",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-10-24"
    },
    {
      "value": "CVE-2020-3433",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1977",
          "title": "CISA KEV: CVE-2020-3433 \u2014 Cisco AnyConnect Secure Mobility Client for Windows DLL Hijacking Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-10-24",
          "sev": "crit"
        },
        {
          "id": "art-1978",
          "title": "CISA KEV: CVE-2020-3153 \u2014 Cisco AnyConnect Secure Mobility Client for Windows Uncontrolled Search Path Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-10-24",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-10-24"
    },
    {
      "value": "0b15b5cc64caf0c6ad9bd759eb35383b1f718edf3d7ab4cd912d0d8c1826edf8",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1979",
          "title": "CISA KEV: CVE-2018-19323 \u2014 GIGABYTE Multiple Products Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-10-24",
          "sev": "crit"
        },
        {
          "id": "art-1982",
          "title": "CISA KEV: CVE-2018-19320 \u2014 GIGABYTE Multiple Products Unspecified Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-10-24",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-10-24"
    },
    {
      "value": "31f4cfb4c71da44120752721103a16512444c13c2ac2d857a7e6f13cb679b427",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1979",
          "title": "CISA KEV: CVE-2018-19323 \u2014 GIGABYTE Multiple Products Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-10-24",
          "sev": "crit"
        },
        {
          "id": "art-1982",
          "title": "CISA KEV: CVE-2018-19320 \u2014 GIGABYTE Multiple Products Unspecified Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-10-24",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-10-24"
    },
    {
      "value": "791c32a95f401f7464214960e49e716656f6fd6fff135ac2a6ba607236d3346e",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1979",
          "title": "CISA KEV: CVE-2018-19323 \u2014 GIGABYTE Multiple Products Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-10-24",
          "sev": "crit"
        },
        {
          "id": "art-1982",
          "title": "CISA KEV: CVE-2018-19320 \u2014 GIGABYTE Multiple Products Unspecified Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-10-24",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-10-24"
    },
    {
      "value": "99c3cc348f8ee4e87bce45b1dd185d31830c370ac43fd3e39ac50340f029ef79",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1979",
          "title": "CISA KEV: CVE-2018-19323 \u2014 GIGABYTE Multiple Products Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-10-24",
          "sev": "crit"
        },
        {
          "id": "art-1982",
          "title": "CISA KEV: CVE-2018-19320 \u2014 GIGABYTE Multiple Products Unspecified Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-10-24",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-10-24"
    },
    {
      "value": "CVE-2015-1197",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1986",
          "title": "CISA KEV: CVE-2022-41352 \u2014 Synacor Zimbra Collaboration Suite (ZCS) Arbitrary File Upload Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-10-20",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-10-20"
    },
    {
      "value": "CVE-2021-3493",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1987",
          "title": "CISA KEV: CVE-2021-3493 \u2014 Linux Kernel Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-10-20",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-10-20"
    },
    {
      "value": "CVE-2022-41352",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-1986",
          "title": "CISA KEV: CVE-2022-41352 \u2014 Synacor Zimbra Collaboration Suite (ZCS) Arbitrary File Upload Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-10-20",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-10-20"
    },
    {
      "value": "CVE-2022-42889",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-1989",
          "title": "Reviewing CVE-2022-42889: The arbitrary code execution vulnerability in Apache Commons Text",
          "link": "https://snyk.io/blog/reviewing-cve-2022-42889-in-apache-commons-text/",
          "published": "2022-10-18",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-10-18"
    },
    {
      "value": "CVE-2022-40684",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2001",
          "title": "CISA KEV: CVE-2022-40684 \u2014 Fortinet Multiple Products Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-10-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-10-11"
    },
    {
      "value": "CVE-2022-41033",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2002",
          "title": "CISA KEV: CVE-2022-41033 \u2014 Microsoft Windows COM+ Event System Service Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-10-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-10-11"
    },
    {
      "value": "CVE-2022-40764",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-2011",
          "title": "Command injection vulnerability in Snyk CLI released prior to September 1, 2022 (older than v1.996.0)",
          "link": "https://snyk.io/blog/command-injection-vulnerability-cve-2022-40764/",
          "published": "2022-10-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-10-03"
    },
    {
      "value": "CVE-2022-36804",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2015",
          "title": "CISA KEV: CVE-2022-36804 \u2014 Atlassian Bitbucket Server and Data Center Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-09-30",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-09-30"
    },
    {
      "value": "CVE-2022-3236",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2023",
          "title": "CISA KEV: CVE-2022-3236 \u2014 Sophos Firewall Code Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-09-23",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-09-23"
    },
    {
      "value": "CVE-2022-35405",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2024",
          "title": "CISA KEV: CVE-2022-35405 \u2014 Zoho ManageEngine Multiple Products Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-09-22",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-09-22"
    },
    {
      "value": "CVE-2010-2568",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2035",
          "title": "CISA KEV: CVE-2010-2568 \u2014 Microsoft Windows Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-09-15",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-09-15"
    },
    {
      "value": "CVE-2013-2094",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2034",
          "title": "CISA KEV: CVE-2013-2094 \u2014 Linux Kernel Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-09-15",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-09-15"
    },
    {
      "value": "CVE-2013-2596",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2033",
          "title": "CISA KEV: CVE-2013-2596 \u2014 Linux Kernel Integer Overflow Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-09-15",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-09-15"
    },
    {
      "value": "CVE-2013-2597",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2032",
          "title": "CISA KEV: CVE-2013-2597 \u2014 Code Aurora ACDB Audio Driver Stack-based Buffer Overflow Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-09-15",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-09-15"
    },
    {
      "value": "CVE-2013-6282",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2031",
          "title": "CISA KEV: CVE-2013-6282 \u2014 Linux Kernel Improper Input Validation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-09-15",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-09-15"
    },
    {
      "value": "CVE-2022-40139",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2030",
          "title": "CISA KEV: CVE-2022-40139 \u2014 Trend Micro Apex One and Apex One as a Service Improper Validation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-09-15",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-09-15"
    },
    {
      "value": "recipient.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-2029",
          "title": "Avoiding SMTP Injection: A Whitebox primer",
          "link": "https://snyk.io/blog/avoiding-smtp-injection/",
          "published": "2022-09-15",
          "sev": "high"
        }
      ],
      "first_seen": "2022-09-15"
    },
    {
      "value": "sender.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-2029",
          "title": "Avoiding SMTP Injection: A Whitebox primer",
          "link": "https://snyk.io/blog/avoiding-smtp-injection/",
          "published": "2022-09-15",
          "sev": "high"
        }
      ],
      "first_seen": "2022-09-15"
    },
    {
      "value": "CVE-2022-32917",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2037",
          "title": "CISA KEV: CVE-2022-32917 \u2014 Apple iOS, iPadOS, and macOS Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-09-14",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-09-14"
    },
    {
      "value": "CVE-2022-37969",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2036",
          "title": "CISA KEV: CVE-2022-37969 \u2014 Microsoft Windows Common Log File System (CLFS) Driver Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-09-14",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-09-14"
    },
    {
      "value": "CVE-2011-1823",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2052",
          "title": "CISA KEV: CVE-2011-1823 \u2014 Android OS Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-09-08",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-09-08"
    },
    {
      "value": "CVE-2011-4723",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2051",
          "title": "CISA KEV: CVE-2011-4723 \u2014 D-Link DIR-300 Router Cleartext Storage of a Password Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-09-08",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-09-08"
    },
    {
      "value": "CVE-2017-5521",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2050",
          "title": "CISA KEV: CVE-2017-5521 \u2014 NETGEAR Multiple Devices Exposure of Sensitive Information Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-09-08",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-09-08"
    },
    {
      "value": "CVE-2018-13374",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2049",
          "title": "CISA KEV: CVE-2018-13374 \u2014 Fortinet FortiOS and FortiADC Improper Access Control Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-09-08",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-09-08"
    },
    {
      "value": "CVE-2018-2628",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2048",
          "title": "CISA KEV: CVE-2018-2628 \u2014 Oracle WebLogic Server Unspecified Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-09-08",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-09-08"
    },
    {
      "value": "CVE-2018-6530",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2047",
          "title": "CISA KEV: CVE-2018-6530 \u2014 D-Link Multiple Routers OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-09-08",
          "sev": "crit"
        },
        {
          "id": "art-2664",
          "title": "CISA KEV: CVE-2015-2051 \u2014 D-Link DIR-645 Router Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-02-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-09-08"
    },
    {
      "value": "CVE-2018-7445",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2046",
          "title": "CISA KEV: CVE-2018-7445 \u2014 MikroTik RouterOS Stack-Based Buffer Overflow Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-09-08",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-09-08"
    },
    {
      "value": "CVE-2020-9934",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2045",
          "title": "CISA KEV: CVE-2020-9934 \u2014 Apple iOS, iPadOS, and macOS Input Validation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-09-08",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-09-08"
    },
    {
      "value": "CVE-2022-26258",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2044",
          "title": "CISA KEV: CVE-2022-26258 \u2014 D-Link DIR-820L Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-09-08",
          "sev": "crit"
        },
        {
          "id": "art-2664",
          "title": "CISA KEV: CVE-2015-2051 \u2014 D-Link DIR-645 Router Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-02-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-09-08"
    },
    {
      "value": "CVE-2022-27593",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2043",
          "title": "CISA KEV: CVE-2022-27593 \u2014 QNAP Photo Station Externally Controlled Reference Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-09-08",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-09-08"
    },
    {
      "value": "CVE-2022-3075",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2042",
          "title": "CISA KEV: CVE-2022-3075 \u2014 Google Chromium Mojo Insufficient Data Validation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-09-08",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-09-08"
    },
    {
      "value": "CVE-2021-23639",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-2059",
          "title": "Solve Hack the Box and other CTF challenges with Snyk",
          "link": "https://snyk.io/blog/solve-hack-the-box-and-ctf-challenges-with-snyk/",
          "published": "2022-09-01",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-09-01"
    },
    {
      "value": "CVE-2022-21680",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-2059",
          "title": "Solve Hack the Box and other CTF challenges with Snyk",
          "link": "https://snyk.io/blog/solve-hack-the-box-and-ctf-challenges-with-snyk/",
          "published": "2022-09-01",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-09-01"
    },
    {
      "value": "CVE-2022-21681",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-2059",
          "title": "Solve Hack the Box and other CTF challenges with Snyk",
          "link": "https://snyk.io/blog/solve-hack-the-box-and-ctf-challenges-with-snyk/",
          "published": "2022-09-01",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-09-01"
    },
    {
      "value": "CVE-2020-28949",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2076",
          "title": "CISA KEV: CVE-2020-28949 \u2014 PEAR Archive_Tar Deserialization of Untrusted Data Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-08-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-08-25"
    },
    {
      "value": "CVE-2020-36193",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2075",
          "title": "CISA KEV: CVE-2020-36193 \u2014 PEAR Archive_Tar Improper Link Resolution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-08-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-08-25"
    },
    {
      "value": "CVE-2021-31010",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2074",
          "title": "CISA KEV: CVE-2021-31010 \u2014 Apple iOS, macOS, watchOS Sandbox Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-08-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-08-25"
    },
    {
      "value": "CVE-2021-38406",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2073",
          "title": "CISA KEV: CVE-2021-38406 \u2014 Delta Electronics DOPSoft 2 Improper Input Validation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-08-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-08-25"
    },
    {
      "value": "CVE-2021-39226",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2072",
          "title": "CISA KEV: CVE-2021-39226 \u2014 Grafana Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-08-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-08-25"
    },
    {
      "value": "CVE-2022-2294",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2071",
          "title": "CISA KEV: CVE-2022-2294 \u2014 WebRTC Heap Buffer Overflow Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-08-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-08-25"
    },
    {
      "value": "CVE-2022-22963",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV",
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-2070",
          "title": "CISA KEV: CVE-2022-22963 \u2014 VMware Tanzu Spring Cloud Function Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-08-25",
          "sev": "crit"
        },
        {
          "id": "art-2368",
          "title": "Spring4Shell: What we know about the Java RCE vulnerability",
          "link": "https://snyk.io/blog/is-there-such-a-thing-as-spring4shell/",
          "published": "2022-03-31",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-08-25"
    },
    {
      "value": "CVE-2022-24112",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2069",
          "title": "CISA KEV: CVE-2022-24112 \u2014 Apache APISIX Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-08-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-08-25"
    },
    {
      "value": "CVE-2022-24706",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2068",
          "title": "CISA KEV: CVE-2022-24706 \u2014 Apache CouchDB Insecure Default Initialization of Resource Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-08-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-08-25"
    },
    {
      "value": "CVE-2022-26352",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2067",
          "title": "CISA KEV: CVE-2022-26352 \u2014 dotCMS Unrestricted Upload of File Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-08-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-08-25"
    },
    {
      "value": "stylishblock.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2071",
          "title": "CISA KEV: CVE-2022-2294 \u2014 WebRTC Heap Buffer Overflow Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-08-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-08-25"
    },
    {
      "value": "185.14.30.35",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2068",
          "title": "CISA KEV: CVE-2022-24706 \u2014 Apache CouchDB Insecure Default Initialization of Resource Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-08-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-08-25"
    },
    {
      "value": "193.106.191.48",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2068",
          "title": "CISA KEV: CVE-2022-24706 \u2014 Apache CouchDB Insecure Default Initialization of Resource Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-08-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-08-25"
    },
    {
      "value": "212.22.77.79",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2068",
          "title": "CISA KEV: CVE-2022-24706 \u2014 Apache CouchDB Insecure Default Initialization of Resource Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-08-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-08-25"
    },
    {
      "value": "91.241.19.134",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2068",
          "title": "CISA KEV: CVE-2022-24706 \u2014 Apache CouchDB Insecure Default Initialization of Resource Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-08-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-08-25"
    },
    {
      "value": "95.182.120.164",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2068",
          "title": "CISA KEV: CVE-2022-24706 \u2014 Apache CouchDB Insecure Default Initialization of Resource Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-08-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-08-25"
    },
    {
      "value": "5bab937d057b35ffd4e50e2c170863f9b40fbf9424f66d0ddeae2a62b6403937",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2068",
          "title": "CISA KEV: CVE-2022-24706 \u2014 Apache CouchDB Insecure Default Initialization of Resource Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-08-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-08-25"
    },
    {
      "value": "5d2530b809fd069f97b30a5938d471dd2145341b5793a70656aad6045445cf6d",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2068",
          "title": "CISA KEV: CVE-2022-24706 \u2014 Apache CouchDB Insecure Default Initialization of Resource Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-08-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-08-25"
    },
    {
      "value": "c38c21120d8c17688f9aeb2af5bdafb6b75e1d2673b025b720e50232f888808a",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2068",
          "title": "CISA KEV: CVE-2022-24706 \u2014 Apache CouchDB Insecure Default Initialization of Resource Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-08-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-08-25"
    },
    {
      "value": "d318cdb5fee75d647c784a6dcb2a5a613143caf7740087726911bab35206b666",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2068",
          "title": "CISA KEV: CVE-2022-24706 \u2014 Apache CouchDB Insecure Default Initialization of Resource Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-08-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-08-25"
    },
    {
      "value": "CVE-2022-21187",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-2080",
          "title": "Rediscovering argument injection when using VCS tools \u2014 git and mercurial",
          "link": "https://snyk.io/blog/argument-injection-when-using-git-and-mercurial/",
          "published": "2022-08-23",
          "sev": "high"
        }
      ],
      "first_seen": "2022-08-23"
    },
    {
      "value": "CVE-2022-21223",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-2080",
          "title": "Rediscovering argument injection when using VCS tools \u2014 git and mercurial",
          "link": "https://snyk.io/blog/argument-injection-when-using-git-and-mercurial/",
          "published": "2022-08-23",
          "sev": "high"
        }
      ],
      "first_seen": "2022-08-23"
    },
    {
      "value": "CVE-2022-21235",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-2080",
          "title": "Rediscovering argument injection when using VCS tools \u2014 git and mercurial",
          "link": "https://snyk.io/blog/argument-injection-when-using-git-and-mercurial/",
          "published": "2022-08-23",
          "sev": "high"
        }
      ],
      "first_seen": "2022-08-23"
    },
    {
      "value": "CVE-2022-23915",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-2080",
          "title": "Rediscovering argument injection when using VCS tools \u2014 git and mercurial",
          "link": "https://snyk.io/blog/argument-injection-when-using-git-and-mercurial/",
          "published": "2022-08-23",
          "sev": "high"
        }
      ],
      "first_seen": "2022-08-23"
    },
    {
      "value": "CVE-2022-24065",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-2080",
          "title": "Rediscovering argument injection when using VCS tools \u2014 git and mercurial",
          "link": "https://snyk.io/blog/argument-injection-when-using-git-and-mercurial/",
          "published": "2022-08-23",
          "sev": "high"
        }
      ],
      "first_seen": "2022-08-23"
    },
    {
      "value": "CVE-2022-24433",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-2080",
          "title": "Rediscovering argument injection when using VCS tools \u2014 git and mercurial",
          "link": "https://snyk.io/blog/argument-injection-when-using-git-and-mercurial/",
          "published": "2022-08-23",
          "sev": "high"
        }
      ],
      "first_seen": "2022-08-23"
    },
    {
      "value": "CVE-2022-24440",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-2080",
          "title": "Rediscovering argument injection when using VCS tools \u2014 git and mercurial",
          "link": "https://snyk.io/blog/argument-injection-when-using-git-and-mercurial/",
          "published": "2022-08-23",
          "sev": "high"
        }
      ],
      "first_seen": "2022-08-23"
    },
    {
      "value": "CVE-2022-25648",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-2080",
          "title": "Rediscovering argument injection when using VCS tools \u2014 git and mercurial",
          "link": "https://snyk.io/blog/argument-injection-when-using-git-and-mercurial/",
          "published": "2022-08-23",
          "sev": "high"
        }
      ],
      "first_seen": "2022-08-23"
    },
    {
      "value": "CVE-2022-25766",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-2080",
          "title": "Rediscovering argument injection when using VCS tools \u2014 git and mercurial",
          "link": "https://snyk.io/blog/argument-injection-when-using-git-and-mercurial/",
          "published": "2022-08-23",
          "sev": "high"
        }
      ],
      "first_seen": "2022-08-23"
    },
    {
      "value": "CVE-2022-25865",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-2080",
          "title": "Rediscovering argument injection when using VCS tools \u2014 git and mercurial",
          "link": "https://snyk.io/blog/argument-injection-when-using-git-and-mercurial/",
          "published": "2022-08-23",
          "sev": "high"
        }
      ],
      "first_seen": "2022-08-23"
    },
    {
      "value": "CVE-2022-25866",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-2080",
          "title": "Rediscovering argument injection when using VCS tools \u2014 git and mercurial",
          "link": "https://snyk.io/blog/argument-injection-when-using-git-and-mercurial/",
          "published": "2022-08-23",
          "sev": "high"
        }
      ],
      "first_seen": "2022-08-23"
    },
    {
      "value": "CVE-2022-26945",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-2080",
          "title": "Rediscovering argument injection when using VCS tools \u2014 git and mercurial",
          "link": "https://snyk.io/blog/argument-injection-when-using-git-and-mercurial/",
          "published": "2022-08-23",
          "sev": "high"
        }
      ],
      "first_seen": "2022-08-23"
    },
    {
      "value": "CVE-2022-29184",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-2080",
          "title": "Rediscovering argument injection when using VCS tools \u2014 git and mercurial",
          "link": "https://snyk.io/blog/argument-injection-when-using-git-and-mercurial/",
          "published": "2022-08-23",
          "sev": "high"
        }
      ],
      "first_seen": "2022-08-23"
    },
    {
      "value": "CVE-2015-7547",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-2082",
          "title": "How open source C++ code can introduce security risks",
          "link": "https://snyk.io/blog/how-open-source-c-code-can-introduce-security-risks/",
          "published": "2022-08-22",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-08-22"
    },
    {
      "value": "CVE-2022-0028",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2084",
          "title": "CISA KEV: CVE-2022-0028 \u2014 Palo Alto Networks PAN-OS Reflected Amplification Denial-of-Service Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-08-22",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-08-22"
    },
    {
      "value": "104.248.94.23",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-2082",
          "title": "How open source C++ code can introduce security risks",
          "link": "https://snyk.io/blog/how-open-source-c-code-can-introduce-security-risks/",
          "published": "2022-08-22",
          "sev": "crit"
        },
        {
          "id": "art-2773",
          "title": "Responsible disclosure: CodeCov CEO & CTO share learnings from the breach",
          "link": "https://snyk.io/blog/codecov-ceo-cto-share-learnings-from-breach-tsd/",
          "published": "2021-12-09",
          "sev": "high"
        }
      ],
      "first_seen": "2022-08-22"
    },
    {
      "value": "CVE-2017-15944",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2092",
          "title": "CISA KEV: CVE-2017-15944 \u2014 Palo Alto Networks PAN-OS Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-08-18",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-08-18"
    },
    {
      "value": "CVE-2022-21971",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2091",
          "title": "CISA KEV: CVE-2022-21971 \u2014 Microsoft Windows Runtime Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-08-18",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-08-18"
    },
    {
      "value": "CVE-2022-22536",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2086",
          "title": "CISA KEV: CVE-2022-22536 \u2014 SAP Multiple Products HTTP Request Smuggling Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-08-18",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-08-18"
    },
    {
      "value": "CVE-2022-26923",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2090",
          "title": "CISA KEV: CVE-2022-26923 \u2014 Microsoft Active Directory Domain Services Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-08-18",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-08-18"
    },
    {
      "value": "CVE-2022-2856",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2089",
          "title": "CISA KEV: CVE-2022-2856 \u2014 Google Chromium Intents Insufficient Input Validation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-08-18",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-08-18"
    },
    {
      "value": "CVE-2022-32893",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2087",
          "title": "CISA KEV: CVE-2022-32894 \u2014 Apple iOS and macOS Out-of-Bounds Write Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-08-18",
          "sev": "crit"
        },
        {
          "id": "art-2088",
          "title": "CISA KEV: CVE-2022-32893 \u2014 Apple iOS and macOS Out-of-Bounds Write Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-08-18",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-08-18"
    },
    {
      "value": "CVE-2022-32894",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2087",
          "title": "CISA KEV: CVE-2022-32894 \u2014 Apple iOS and macOS Out-of-Bounds Write Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-08-18",
          "sev": "crit"
        },
        {
          "id": "art-2088",
          "title": "CISA KEV: CVE-2022-32893 \u2014 Apple iOS and macOS Out-of-Bounds Write Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-08-18",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-08-18"
    },
    {
      "value": "cdn.discordapp.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-2095",
          "title": "Snyk finds PyPi malware that steals Discord and Roblox credential and payment info",
          "link": "https://snyk.io/blog/pypi-malware-discord-roblox-credential-payment-info/",
          "published": "2022-08-16",
          "sev": "high"
        }
      ],
      "first_seen": "2022-08-16"
    },
    {
      "value": "github.com/Rdimo/Discord-Injection",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-2095",
          "title": "Snyk finds PyPi malware that steals Discord and Roblox credential and payment info",
          "link": "https://snyk.io/blog/pypi-malware-discord-roblox-credential-payment-info/",
          "published": "2022-08-16",
          "sev": "high"
        }
      ],
      "first_seen": "2022-08-16"
    },
    {
      "value": "https://cdn.discordapp.com/attachments/1003368479442874518/1003368773983682592/ZYRBX.exe",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-2095",
          "title": "Snyk finds PyPi malware that steals Discord and Roblox credential and payment info",
          "link": "https://snyk.io/blog/pypi-malware-discord-roblox-credential-payment-info/",
          "published": "2022-08-16",
          "sev": "high"
        }
      ],
      "first_seen": "2022-08-16"
    },
    {
      "value": "https://cdn.discordapp.com/attachments/1003368479442874518/1003368774335991898/ZYXMN.exe",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-2095",
          "title": "Snyk finds PyPi malware that steals Discord and Roblox credential and payment info",
          "link": "https://snyk.io/blog/pypi-malware-discord-roblox-credential-payment-info/",
          "published": "2022-08-16",
          "sev": "high"
        }
      ],
      "first_seen": "2022-08-16"
    },
    {
      "value": "https://discord.com/api/webhooks/1003603061530431539/mAOhFLrtafsu1jC3G1_nRR5by1zBTtd4xxdxZPVFkOlCUqMeze6TcUQ3zbR9zVsvG5-m",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-2095",
          "title": "Snyk finds PyPi malware that steals Discord and Roblox credential and payment info",
          "link": "https://snyk.io/blog/pypi-malware-discord-roblox-credential-payment-info/",
          "published": "2022-08-16",
          "sev": "high"
        }
      ],
      "first_seen": "2022-08-16"
    },
    {
      "value": "CVE-2022-27924",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2098",
          "title": "CISA KEV: CVE-2022-27925 \u2014 Synacor Zimbra Collaboration Suite (ZCS) Arbitrary File Upload Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-08-11",
          "sev": "crit"
        },
        {
          "id": "art-2107",
          "title": "CISA KEV: CVE-2022-27924 \u2014 Synacor Zimbra Collaboration Suite (ZCS) Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-08-04",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-08-11"
    },
    {
      "value": "CVE-2022-27925",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2098",
          "title": "CISA KEV: CVE-2022-27925 \u2014 Synacor Zimbra Collaboration Suite (ZCS) Arbitrary File Upload Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-08-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-08-11"
    },
    {
      "value": "CVE-2022-37042",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2098",
          "title": "CISA KEV: CVE-2022-27925 \u2014 Synacor Zimbra Collaboration Suite (ZCS) Arbitrary File Upload Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-08-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-08-11"
    },
    {
      "value": "CVE-2022-33980",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-2099",
          "title": "Controlling your server with a reverse shell attack",
          "link": "https://snyk.io/blog/reverse-shell-attack/",
          "published": "2022-08-10",
          "sev": "crit"
        },
        {
          "id": "art-2124",
          "title": "Exploring CVE-2022-33980: the Apache Commons configuration RCE vulnerability",
          "link": "https://snyk.io/blog/cve-2022-33980-apache-commons-configuration-rce-vulnerability/",
          "published": "2022-07-08",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-08-10"
    },
    {
      "value": "CVE-2022-30333",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2102",
          "title": "CISA KEV: CVE-2022-30333 \u2014 RARLAB UnRAR Directory Traversal Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-08-09",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-08-09"
    },
    {
      "value": "CVE-2022-34713",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2101",
          "title": "CISA KEV: CVE-2022-34713 \u2014 Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-08-09",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-08-09"
    },
    {
      "value": "CVE-2022-26138",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2111",
          "title": "CISA KEV: CVE-2022-26138 \u2014 Atlassian Questions For Confluence App Hard-coded Credentials Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-07-29",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-07-29"
    },
    {
      "value": "CVE-2021-28550",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2123",
          "title": "CISA KEV: CVE-2022-22047 \u2014 Microsoft Windows Client Server Runtime Subsystem (CSRSS) Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-07-12",
          "sev": "crit"
        },
        {
          "id": "art-2808",
          "title": "CISA KEV: CVE-2021-28550 \u2014 Adobe Acrobat and Reader Use-After-Free Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        },
        {
          "id": "art-2932",
          "title": "CISA KEV: CVE-2021-31199 \u2014 Microsoft Enhanced Cryptographic Provider Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        },
        {
          "id": "art-2935",
          "title": "CISA KEV: CVE-2021-31201 \u2014 Microsoft Enhanced Cryptographic Provider Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-07-12"
    },
    {
      "value": "CVE-2021-31199",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2123",
          "title": "CISA KEV: CVE-2022-22047 \u2014 Microsoft Windows Client Server Runtime Subsystem (CSRSS) Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-07-12",
          "sev": "crit"
        },
        {
          "id": "art-2932",
          "title": "CISA KEV: CVE-2021-31199 \u2014 Microsoft Enhanced Cryptographic Provider Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        },
        {
          "id": "art-2935",
          "title": "CISA KEV: CVE-2021-31201 \u2014 Microsoft Enhanced Cryptographic Provider Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-07-12"
    },
    {
      "value": "CVE-2021-31201",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2123",
          "title": "CISA KEV: CVE-2022-22047 \u2014 Microsoft Windows Client Server Runtime Subsystem (CSRSS) Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-07-12",
          "sev": "crit"
        },
        {
          "id": "art-2932",
          "title": "CISA KEV: CVE-2021-31199 \u2014 Microsoft Enhanced Cryptographic Provider Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        },
        {
          "id": "art-2935",
          "title": "CISA KEV: CVE-2021-31201 \u2014 Microsoft Enhanced Cryptographic Provider Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-07-12"
    },
    {
      "value": "CVE-2021-36948",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2123",
          "title": "CISA KEV: CVE-2022-22047 \u2014 Microsoft Windows Client Server Runtime Subsystem (CSRSS) Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-07-12",
          "sev": "crit"
        },
        {
          "id": "art-2932",
          "title": "CISA KEV: CVE-2021-31199 \u2014 Microsoft Enhanced Cryptographic Provider Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        },
        {
          "id": "art-2944",
          "title": "CISA KEV: CVE-2021-36948 \u2014 Microsoft Windows Update Medic Service Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-07-12"
    },
    {
      "value": "CVE-2022-22047",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2123",
          "title": "CISA KEV: CVE-2022-22047 \u2014 Microsoft Windows Client Server Runtime Subsystem (CSRSS) Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-07-12",
          "sev": "crit"
        },
        {
          "id": "art-2932",
          "title": "CISA KEV: CVE-2021-31199 \u2014 Microsoft Enhanced Cryptographic Provider Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-07-12"
    },
    {
      "value": "acrobatrelay.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2123",
          "title": "CISA KEV: CVE-2022-22047 \u2014 Microsoft Windows Client Server Runtime Subsystem (CSRSS) Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-07-12",
          "sev": "crit"
        },
        {
          "id": "art-2932",
          "title": "CISA KEV: CVE-2021-31199 \u2014 Microsoft Enhanced Cryptographic Provider Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-07-12"
    },
    {
      "value": "demo3.dsirf.eu",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2123",
          "title": "CISA KEV: CVE-2022-22047 \u2014 Microsoft Windows Client Server Runtime Subsystem (CSRSS) Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-07-12",
          "sev": "crit"
        },
        {
          "id": "art-2932",
          "title": "CISA KEV: CVE-2021-31199 \u2014 Microsoft Enhanced Cryptographic Provider Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-07-12"
    },
    {
      "value": "finconsult.cc",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2123",
          "title": "CISA KEV: CVE-2022-22047 \u2014 Microsoft Windows Client Server Runtime Subsystem (CSRSS) Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-07-12",
          "sev": "crit"
        },
        {
          "id": "art-2932",
          "title": "CISA KEV: CVE-2021-31199 \u2014 Microsoft Enhanced Cryptographic Provider Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-07-12"
    },
    {
      "value": "realmetaldns.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2123",
          "title": "CISA KEV: CVE-2022-22047 \u2014 Microsoft Windows Client Server Runtime Subsystem (CSRSS) Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-07-12",
          "sev": "crit"
        },
        {
          "id": "art-2932",
          "title": "CISA KEV: CVE-2021-31199 \u2014 Microsoft Enhanced Cryptographic Provider Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-07-12"
    },
    {
      "value": "02a59fe2c94151a08d75a692b550e66a8738eb47f0001234c600b562bf8c227d",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2123",
          "title": "CISA KEV: CVE-2022-22047 \u2014 Microsoft Windows Client Server Runtime Subsystem (CSRSS) Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-07-12",
          "sev": "crit"
        },
        {
          "id": "art-2932",
          "title": "CISA KEV: CVE-2021-31199 \u2014 Microsoft Enhanced Cryptographic Provider Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-07-12"
    },
    {
      "value": "0588f61dc7e4b24554cffe4ea56d043d8f6139d2569bc180d4a77cf75b68792f",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2123",
          "title": "CISA KEV: CVE-2022-22047 \u2014 Microsoft Windows Client Server Runtime Subsystem (CSRSS) Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-07-12",
          "sev": "crit"
        },
        {
          "id": "art-2932",
          "title": "CISA KEV: CVE-2021-31199 \u2014 Microsoft Enhanced Cryptographic Provider Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-07-12"
    },
    {
      "value": "441a3810b9e89bae12eea285a63f92e98181e9fb9efd6c57ef6d265435484964",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2123",
          "title": "CISA KEV: CVE-2022-22047 \u2014 Microsoft Windows Client Server Runtime Subsystem (CSRSS) Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-07-12",
          "sev": "crit"
        },
        {
          "id": "art-2932",
          "title": "CISA KEV: CVE-2021-31199 \u2014 Microsoft Enhanced Cryptographic Provider Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-07-12"
    },
    {
      "value": "4611340fdade4e36f074f75294194b64dcf2ec0db00f3d958956b4b0d6586431",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2123",
          "title": "CISA KEV: CVE-2022-22047 \u2014 Microsoft Windows Client Server Runtime Subsystem (CSRSS) Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-07-12",
          "sev": "crit"
        },
        {
          "id": "art-2932",
          "title": "CISA KEV: CVE-2021-31199 \u2014 Microsoft Enhanced Cryptographic Provider Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-07-12"
    },
    {
      "value": "5d169e083faa73f2920c8593fb95f599dad93d34a6aa2b0f794be978e44c8206",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2123",
          "title": "CISA KEV: CVE-2022-22047 \u2014 Microsoft Windows Client Server Runtime Subsystem (CSRSS) Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-07-12",
          "sev": "crit"
        },
        {
          "id": "art-2932",
          "title": "CISA KEV: CVE-2021-31199 \u2014 Microsoft Enhanced Cryptographic Provider Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-07-12"
    },
    {
      "value": "78c255a98003a101fa5ba3f49c50c6922b52ede601edac5db036ab72efc57629",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2123",
          "title": "CISA KEV: CVE-2022-22047 \u2014 Microsoft Windows Client Server Runtime Subsystem (CSRSS) Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-07-12",
          "sev": "crit"
        },
        {
          "id": "art-2932",
          "title": "CISA KEV: CVE-2021-31199 \u2014 Microsoft Enhanced Cryptographic Provider Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-07-12"
    },
    {
      "value": "7f29b69eb1af1cc6c1998bad980640bfe779525fd5bb775bc36a0ce3789a8bfc",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2123",
          "title": "CISA KEV: CVE-2022-22047 \u2014 Microsoft Windows Client Server Runtime Subsystem (CSRSS) Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-07-12",
          "sev": "crit"
        },
        {
          "id": "art-2932",
          "title": "CISA KEV: CVE-2021-31199 \u2014 Microsoft Enhanced Cryptographic Provider Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-07-12"
    },
    {
      "value": "7f84bf6a016ca15e654fb5ebc36fd7407cb32c69a0335a32bfc36cb91e36184d",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2123",
          "title": "CISA KEV: CVE-2022-22047 \u2014 Microsoft Windows Client Server Runtime Subsystem (CSRSS) Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-07-12",
          "sev": "crit"
        },
        {
          "id": "art-2932",
          "title": "CISA KEV: CVE-2021-31199 \u2014 Microsoft Enhanced Cryptographic Provider Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-07-12"
    },
    {
      "value": "894138dfeee756e366c65a197b4dbef8816406bc32697fac6621601debe17d53",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2123",
          "title": "CISA KEV: CVE-2022-22047 \u2014 Microsoft Windows Client Server Runtime Subsystem (CSRSS) Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-07-12",
          "sev": "crit"
        },
        {
          "id": "art-2932",
          "title": "CISA KEV: CVE-2021-31199 \u2014 Microsoft Enhanced Cryptographic Provider Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-07-12"
    },
    {
      "value": "afab2e77dc14831f1719e746042063a8ec107de0e9730249d5681d07f598e5ec",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2123",
          "title": "CISA KEV: CVE-2022-22047 \u2014 Microsoft Windows Client Server Runtime Subsystem (CSRSS) Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-07-12",
          "sev": "crit"
        },
        {
          "id": "art-2932",
          "title": "CISA KEV: CVE-2021-31199 \u2014 Microsoft Enhanced Cryptographic Provider Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-07-12"
    },
    {
      "value": "c96ae21b4cf2e28eec222cfe6ca903c4767a068630a73eca58424f9a975c6b7d",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2123",
          "title": "CISA KEV: CVE-2022-22047 \u2014 Microsoft Windows Client Server Runtime Subsystem (CSRSS) Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-07-12",
          "sev": "crit"
        },
        {
          "id": "art-2932",
          "title": "CISA KEV: CVE-2021-31199 \u2014 Microsoft Enhanced Cryptographic Provider Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-07-12"
    },
    {
      "value": "cbae79f66f724e0fe1705d6b5db3cc8a4e89f6bdf4c37004aa1d45eeab26e84b",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2123",
          "title": "CISA KEV: CVE-2022-22047 \u2014 Microsoft Windows Client Server Runtime Subsystem (CSRSS) Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-07-12",
          "sev": "crit"
        },
        {
          "id": "art-2932",
          "title": "CISA KEV: CVE-2021-31199 \u2014 Microsoft Enhanced Cryptographic Provider Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-07-12"
    },
    {
      "value": "e64bea4032cf2694e85ede1745811e7585d3580821a00ae1b9123bb3d2d442d6",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2123",
          "title": "CISA KEV: CVE-2022-22047 \u2014 Microsoft Windows Client Server Runtime Subsystem (CSRSS) Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-07-12",
          "sev": "crit"
        },
        {
          "id": "art-2932",
          "title": "CISA KEV: CVE-2021-31199 \u2014 Microsoft Enhanced Cryptographic Provider Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-07-12"
    },
    {
      "value": "fa30be45c5c5a8f679b42ae85410f6099f66fe2b38eb7aa460bcc022babb41ca",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2123",
          "title": "CISA KEV: CVE-2022-22047 \u2014 Microsoft Windows Client Server Runtime Subsystem (CSRSS) Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-07-12",
          "sev": "crit"
        },
        {
          "id": "art-2932",
          "title": "CISA KEV: CVE-2021-31199 \u2014 Microsoft Enhanced Cryptographic Provider Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-07-12"
    },
    {
      "value": "fd6515a71530b8329e2c0104d0866c5c6f87546d4b44cc17bbb03e64663b11fc",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2123",
          "title": "CISA KEV: CVE-2022-22047 \u2014 Microsoft Windows Client Server Runtime Subsystem (CSRSS) Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-07-12",
          "sev": "crit"
        },
        {
          "id": "art-2932",
          "title": "CISA KEV: CVE-2021-31199 \u2014 Microsoft Enhanced Cryptographic Provider Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-07-12"
    },
    {
      "value": "CVE-2021-36942",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2127",
          "title": "CISA KEV: CVE-2022-26925 \u2014 Microsoft Windows LSA Spoofing Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-07-01",
          "sev": "crit"
        },
        {
          "id": "art-2954",
          "title": "CISA KEV: CVE-2021-31207 \u2014 Microsoft Exchange Server Security Feature Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        },
        {
          "id": "art-2965",
          "title": "CISA KEV: CVE-2021-36942 \u2014 Microsoft Windows Local Security Authority (LSA) Spoofing Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-07-01"
    },
    {
      "value": "CVE-2022-26925",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2127",
          "title": "CISA KEV: CVE-2022-26925 \u2014 Microsoft Windows LSA Spoofing Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-07-01",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-07-01"
    },
    {
      "value": "CVE-2018-4344",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2139",
          "title": "CISA KEV: CVE-2018-4344 \u2014 Apple Multiple Products Memory Corruption Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-06-27",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-06-27"
    },
    {
      "value": "CVE-2019-8605",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2138",
          "title": "CISA KEV: CVE-2019-8605 \u2014 Apple Multiple Products Use-After-Free Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-06-27",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-06-27"
    },
    {
      "value": "CVE-2020-3837",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2136",
          "title": "CISA KEV: CVE-2020-3837 \u2014 Apple Multiple Products Memory Corruption Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-06-27",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-06-27"
    },
    {
      "value": "CVE-2020-9907",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2137",
          "title": "CISA KEV: CVE-2020-9907 \u2014 Apple Multiple Products Memory Corruption Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-06-27",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-06-27"
    },
    {
      "value": "CVE-2021-30533",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2133",
          "title": "CISA KEV: CVE-2021-30533 \u2014 Google Chromium PopupBlocker Security Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-06-27",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-06-27"
    },
    {
      "value": "CVE-2021-30983",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2135",
          "title": "CISA KEV: CVE-2021-30983 \u2014 Apple iOS and iPadOS Buffer Overflow Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-06-27",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-06-27"
    },
    {
      "value": "CVE-2021-4034",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV",
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-2134",
          "title": "CISA KEV: CVE-2021-4034 \u2014 Red Hat Polkit Out-of-Bounds Read and Write Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-06-27",
          "sev": "crit"
        },
        {
          "id": "art-2677",
          "title": "Analyzing the PwnKit local privilege escalation exploit",
          "link": "https://snyk.io/blog/pwnkit-linux-exploit-cve-2021-4034/",
          "published": "2022-01-29",
          "sev": "high"
        }
      ],
      "first_seen": "2022-06-27"
    },
    {
      "value": "CVE-2022-29499",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2132",
          "title": "CISA KEV: CVE-2022-29499 \u2014 Mitel MiVoice Connect Data Validation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-06-27",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-06-27"
    },
    {
      "value": "137.184.181.252",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2132",
          "title": "CISA KEV: CVE-2022-29499 \u2014 Mitel MiVoice Connect Data Validation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-06-27",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-06-27"
    },
    {
      "value": "138.197.218.11",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2132",
          "title": "CISA KEV: CVE-2022-29499 \u2014 Mitel MiVoice Connect Data Validation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-06-27",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-06-27"
    },
    {
      "value": "138.68.19.94",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2132",
          "title": "CISA KEV: CVE-2022-29499 \u2014 Mitel MiVoice Connect Data Validation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-06-27",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-06-27"
    },
    {
      "value": "138.68.59.16",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2132",
          "title": "CISA KEV: CVE-2022-29499 \u2014 Mitel MiVoice Connect Data Validation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-06-27",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-06-27"
    },
    {
      "value": "159.65.248.159",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2132",
          "title": "CISA KEV: CVE-2022-29499 \u2014 Mitel MiVoice Connect Data Validation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-06-27",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-06-27"
    },
    {
      "value": "206.188.197.125",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2132",
          "title": "CISA KEV: CVE-2022-29499 \u2014 Mitel MiVoice Connect Data Validation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-06-27",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-06-27"
    },
    {
      "value": "64.190.113.100",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2132",
          "title": "CISA KEV: CVE-2022-29499 \u2014 Mitel MiVoice Connect Data Validation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-06-27",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-06-27"
    },
    {
      "value": "07838ac8fd5a59bb741aae0cf3abf48296677be7ac0864c4f124c2e168c0af94",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2132",
          "title": "CISA KEV: CVE-2022-29499 \u2014 Mitel MiVoice Connect Data Validation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-06-27",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-06-27"
    },
    {
      "value": "97ff99fd824a02106d20d167e2a2b647244712a558639524e7db1e6a2064a68d",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2132",
          "title": "CISA KEV: CVE-2022-29499 \u2014 Mitel MiVoice Connect Data Validation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-06-27",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-06-27"
    },
    {
      "value": "CVE-2022-30190",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2144",
          "title": "CISA KEV: CVE-2022-30190 \u2014 Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-06-14",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-06-14"
    },
    {
      "value": "8e0be5e1035777f2ea373593c214d29ad146dd0453e9b8a1cad16d787c0be632",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2144",
          "title": "CISA KEV: CVE-2022-30190 \u2014 Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-06-14",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-06-14"
    },
    {
      "value": "b63fbf80351b3480c62a6a5158334ec8e91fecd057f6c19e4b4dd3febaa9d447",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2144",
          "title": "CISA KEV: CVE-2022-30190 \u2014 Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-06-14",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-06-14"
    },
    {
      "value": "e7faa6c18d4906257652253755cf8f9a739c10938db369878907f8ed7dd8524d",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2144",
          "title": "CISA KEV: CVE-2022-30190 \u2014 Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-06-14",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-06-14"
    },
    {
      "value": "CVE-2016-2386",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2147",
          "title": "CISA KEV: CVE-2016-2386 \u2014 SAP NetWeaver SQL Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-06-09",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-06-09"
    },
    {
      "value": "CVE-2016-2388",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2148",
          "title": "CISA KEV: CVE-2016-2388 \u2014 SAP NetWeaver Information Disclosure Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-06-09",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-06-09"
    },
    {
      "value": "CVE-2021-38163",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2146",
          "title": "CISA KEV: CVE-2021-38163 \u2014 SAP NetWeaver Unrestricted File Upload Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-06-09",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-06-09"
    },
    {
      "value": "CVE-2006-2492",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2185",
          "title": "CISA KEV: CVE-2006-2492 \u2014 Microsoft Word Malformed Object Pointer Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-06-08",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-06-08"
    },
    {
      "value": "CVE-2007-5659",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2184",
          "title": "CISA KEV: CVE-2007-5659 \u2014 Adobe Acrobat and Reader Buffer Overflow Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-06-08",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-06-08"
    },
    {
      "value": "CVE-2008-0655",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2183",
          "title": "CISA KEV: CVE-2008-0655 \u2014 Adobe Acrobat and Reader Unspecified Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-06-08",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-06-08"
    },
    {
      "value": "CVE-2009-0557",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2182",
          "title": "CISA KEV: CVE-2009-0557 \u2014 Microsoft Office Object Record Corruption Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-06-08",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-06-08"
    },
    {
      "value": "CVE-2009-0563",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2181",
          "title": "CISA KEV: CVE-2009-0563 \u2014 Microsoft Office Buffer Overflow Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-06-08",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-06-08"
    },
    {
      "value": "CVE-2009-1862",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2180",
          "title": "CISA KEV: CVE-2009-1862 \u2014 Adobe Acrobat and Reader, Flash Player Unspecified Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-06-08",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-06-08"
    },
    {
      "value": "CVE-2009-3953",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2179",
          "title": "CISA KEV: CVE-2009-3953 \u2014 Adobe Acrobat and Reader Universal 3D Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-06-08",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-06-08"
    },
    {
      "value": "CVE-2009-4324",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2178",
          "title": "CISA KEV: CVE-2009-4324 \u2014 Adobe Acrobat and Reader Use-After-Free Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-06-08",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-06-08"
    },
    {
      "value": "CVE-2010-1297",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2177",
          "title": "CISA KEV: CVE-2010-1297 \u2014 Adobe Flash Player Memory Corruption Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-06-08",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-06-08"
    },
    {
      "value": "CVE-2010-2572",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2176",
          "title": "CISA KEV: CVE-2010-2572 \u2014 Microsoft PowerPoint Buffer Overflow Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-06-08",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-06-08"
    },
    {
      "value": "CVE-2010-2883",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2175",
          "title": "CISA KEV: CVE-2010-2883 \u2014 Adobe Acrobat and Reader Stack-Based Buffer Overflow Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-06-08",
          "sev": "crit"
        },
        {
          "id": "art-2184",
          "title": "CISA KEV: CVE-2007-5659 \u2014 Adobe Acrobat and Reader Buffer Overflow Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-06-08",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-06-08"
    },
    {
      "value": "CVE-2011-0609",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2174",
          "title": "CISA KEV: CVE-2011-0609 \u2014 Adobe Flash Player Unspecified Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-06-08",
          "sev": "crit"
        },
        {
          "id": "art-2180",
          "title": "CISA KEV: CVE-2009-1862 \u2014 Adobe Acrobat and Reader, Flash Player Unspecified Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-06-08",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-06-08"
    },
    {
      "value": "CVE-2011-0611",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2169",
          "title": "CISA KEV: CVE-2012-1889 \u2014 Microsoft XML Core Services Memory Corruption Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-06-08",
          "sev": "crit"
        },
        {
          "id": "art-2607",
          "title": "CISA KEV: CVE-2011-0611 \u2014 Adobe Flash Player Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-06-08"
    },
    {
      "value": "CVE-2011-2462",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2173",
          "title": "CISA KEV: CVE-2011-2462 \u2014 Adobe Reader and Acrobat Universal 3D Memory Corruption Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-06-08",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-06-08"
    },
    {
      "value": "CVE-2012-0151",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2172",
          "title": "CISA KEV: CVE-2012-0151 \u2014 Microsoft Windows Authenticode Signature Verification Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-06-08",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-06-08"
    },
    {
      "value": "CVE-2012-0754",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2171",
          "title": "CISA KEV: CVE-2012-0754 \u2014 Adobe Flash Player Memory Corruption Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-06-08",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-06-08"
    },
    {
      "value": "CVE-2012-0767",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2170",
          "title": "CISA KEV: CVE-2012-0767 \u2014 Adobe Flash Player Cross-Site Scripting (XSS) Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-06-08",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-06-08"
    },
    {
      "value": "CVE-2012-1889",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2169",
          "title": "CISA KEV: CVE-2012-1889 \u2014 Microsoft XML Core Services Memory Corruption Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-06-08",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-06-08"
    },
    {
      "value": "CVE-2012-4969",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2168",
          "title": "CISA KEV: CVE-2012-4969 \u2014 Microsoft Internet Explorer Use-After-Free Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-06-08",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-06-08"
    },
    {
      "value": "CVE-2012-5054",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2167",
          "title": "CISA KEV: CVE-2012-5054 \u2014 Adobe Flash Player Integer Overflow Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-06-08",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-06-08"
    },
    {
      "value": "CVE-2013-1331",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2166",
          "title": "CISA KEV: CVE-2013-1331 \u2014 Microsoft Office Buffer Overflow Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-06-08",
          "sev": "crit"
        },
        {
          "id": "art-2181",
          "title": "CISA KEV: CVE-2009-0563 \u2014 Microsoft Office Buffer Overflow Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-06-08",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-06-08"
    },
    {
      "value": "CVE-2016-1646",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2165",
          "title": "CISA KEV: CVE-2016-1646 \u2014 Google Chromium V8 Out-of-Bounds Read Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-06-08",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-06-08"
    },
    {
      "value": "CVE-2016-5198",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2164",
          "title": "CISA KEV: CVE-2016-5198 \u2014 Google Chromium V8 Out-of-Bounds Memory Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-06-08",
          "sev": "crit"
        },
        {
          "id": "art-2165",
          "title": "CISA KEV: CVE-2016-1646 \u2014 Google Chromium V8 Out-of-Bounds Read Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-06-08",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-06-08"
    },
    {
      "value": "CVE-2017-5030",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2163",
          "title": "CISA KEV: CVE-2017-5030 \u2014 Google Chromium V8 Memory Corruption Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-06-08",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-06-08"
    },
    {
      "value": "CVE-2017-5070",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2162",
          "title": "CISA KEV: CVE-2017-5070 \u2014 Google Chromium V8 Type Confusion Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-06-08",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-06-08"
    },
    {
      "value": "CVE-2017-6862",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2161",
          "title": "CISA KEV: CVE-2017-6862 \u2014 NETGEAR Multiple Devices Buffer Overflow Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-06-08",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-06-08"
    },
    {
      "value": "CVE-2018-17463",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2160",
          "title": "CISA KEV: CVE-2018-17463 \u2014 Google Chromium V8 Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-06-08",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-06-08"
    },
    {
      "value": "CVE-2018-17480",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2159",
          "title": "CISA KEV: CVE-2018-17480 \u2014 Google Chromium V8 Out-of-Bounds Write Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-06-08",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-06-08"
    },
    {
      "value": "CVE-2018-4990",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2158",
          "title": "CISA KEV: CVE-2018-4990 \u2014 Adobe Acrobat and Reader Double Free Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-06-08",
          "sev": "crit"
        },
        {
          "id": "art-2178",
          "title": "CISA KEV: CVE-2009-4324 \u2014 Adobe Acrobat and Reader Use-After-Free Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-06-08",
          "sev": "crit"
        },
        {
          "id": "art-2496",
          "title": "CISA KEV: CVE-2018-8120 \u2014 Microsoft Win32k Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-15",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-06-08"
    },
    {
      "value": "CVE-2018-6065",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2157",
          "title": "CISA KEV: CVE-2018-6065 \u2014 Google Chromium V8 Integer Overflow Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-06-08",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-06-08"
    },
    {
      "value": "CVE-2019-15271",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2156",
          "title": "CISA KEV: CVE-2019-15271 \u2014 Cisco RV Series Routers Deserialization of Untrusted Data Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-06-08",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-06-08"
    },
    {
      "value": "CVE-2019-5825",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2155",
          "title": "CISA KEV: CVE-2019-5825 \u2014 Google Chromium V8 Out-of-Bounds Write Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-06-08",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-06-08"
    },
    {
      "value": "CVE-2019-7192",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2154",
          "title": "CISA KEV: CVE-2019-7192 \u2014 QNAP Photo Station Improper Access Control Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-06-08",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-06-08"
    },
    {
      "value": "CVE-2019-7193",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2153",
          "title": "CISA KEV: CVE-2019-7193 \u2014 QNAP QTS Improper Input Validation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-06-08",
          "sev": "crit"
        },
        {
          "id": "art-2154",
          "title": "CISA KEV: CVE-2019-7192 \u2014 QNAP Photo Station Improper Access Control Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-06-08",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-06-08"
    },
    {
      "value": "CVE-2019-7194",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2152",
          "title": "CISA KEV: CVE-2019-7194 \u2014 QNAP Photo Station Path Traversal Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-06-08",
          "sev": "crit"
        },
        {
          "id": "art-2154",
          "title": "CISA KEV: CVE-2019-7192 \u2014 QNAP Photo Station Improper Access Control Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-06-08",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-06-08"
    },
    {
      "value": "CVE-2019-7195",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2151",
          "title": "CISA KEV: CVE-2019-7195 \u2014 QNAP Photo Station Path Traversal Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-06-08",
          "sev": "crit"
        },
        {
          "id": "art-2154",
          "title": "CISA KEV: CVE-2019-7192 \u2014 QNAP Photo Station Improper Access Control Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-06-08",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-06-08"
    },
    {
      "value": "ccnslc.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2173",
          "title": "CISA KEV: CVE-2011-2462 \u2014 Adobe Reader and Acrobat Universal 3D Memory Corruption Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-06-08",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-06-08"
    },
    {
      "value": "desktop.newcarstyle.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2173",
          "title": "CISA KEV: CVE-2011-2462 \u2014 Adobe Reader and Acrobat Universal 3D Memory Corruption Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-06-08",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-06-08"
    },
    {
      "value": "documents.mypicture.info",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2171",
          "title": "CISA KEV: CVE-2012-0754 \u2014 Adobe Flash Player Memory Corruption Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-06-08",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-06-08"
    },
    {
      "value": "edns.biz",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2171",
          "title": "CISA KEV: CVE-2012-0754 \u2014 Adobe Flash Player Memory Corruption Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-06-08",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-06-08"
    },
    {
      "value": "info.kimfishions.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2173",
          "title": "CISA KEV: CVE-2011-2462 \u2014 Adobe Reader and Acrobat Universal 3D Memory Corruption Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-06-08",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-06-08"
    },
    {
      "value": "kiki.edns.biz",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2171",
          "title": "CISA KEV: CVE-2012-0754 \u2014 Adobe Flash Player Memory Corruption Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-06-08",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-06-08"
    },
    {
      "value": "mypicture.info",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2171",
          "title": "CISA KEV: CVE-2012-0754 \u2014 Adobe Flash Player Memory Corruption Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-06-08",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-06-08"
    },
    {
      "value": "prettylikeher.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2173",
          "title": "CISA KEV: CVE-2011-2462 \u2014 Adobe Reader and Acrobat Universal 3D Memory Corruption Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-06-08",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-06-08"
    },
    {
      "value": "199.192.156.134",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2171",
          "title": "CISA KEV: CVE-2012-0754 \u2014 Adobe Flash Player Memory Corruption Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-06-08",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-06-08"
    },
    {
      "value": "208.115.230.76",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2171",
          "title": "CISA KEV: CVE-2012-0754 \u2014 Adobe Flash Player Memory Corruption Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-06-08",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-06-08"
    },
    {
      "value": "61.196.209.58",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2171",
          "title": "CISA KEV: CVE-2012-0754 \u2014 Adobe Flash Player Memory Corruption Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-06-08",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-06-08"
    },
    {
      "value": "71.36.88.82",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2173",
          "title": "CISA KEV: CVE-2011-2462 \u2014 Adobe Reader and Acrobat Universal 3D Memory Corruption Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-06-08",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-06-08"
    },
    {
      "value": "128a66cc3efe6f424c3fedcc4b6235ac",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2171",
          "title": "CISA KEV: CVE-2012-0754 \u2014 Adobe Flash Player Memory Corruption Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-06-08",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-06-08"
    },
    {
      "value": "1e46c60e65ae9f9c9c8850372d8da491",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2173",
          "title": "CISA KEV: CVE-2011-2462 \u2014 Adobe Reader and Acrobat Universal 3D Memory Corruption Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-06-08",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-06-08"
    },
    {
      "value": "2172079c9c4aa385624de6b4987dbc15",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2173",
          "title": "CISA KEV: CVE-2011-2462 \u2014 Adobe Reader and Acrobat Universal 3D Memory Corruption Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-06-08",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-06-08"
    },
    {
      "value": "517fe6ba9417e6c8b4d0a0b3b9c4c9a9",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2173",
          "title": "CISA KEV: CVE-2011-2462 \u2014 Adobe Reader and Acrobat Universal 3D Memory Corruption Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-06-08",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-06-08"
    },
    {
      "value": "601f8f52cedf043ee4d3d3c83706329f",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2173",
          "title": "CISA KEV: CVE-2011-2462 \u2014 Adobe Reader and Acrobat Universal 3D Memory Corruption Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-06-08",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-06-08"
    },
    {
      "value": "721fda5df552f4130218ad9bd2a4ab78",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2173",
          "title": "CISA KEV: CVE-2011-2462 \u2014 Adobe Reader and Acrobat Universal 3D Memory Corruption Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-06-08",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-06-08"
    },
    {
      "value": "7eab072b76abc4c3e8cba8173c79890c",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2173",
          "title": "CISA KEV: CVE-2011-2462 \u2014 Adobe Reader and Acrobat Universal 3D Memory Corruption Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-06-08",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-06-08"
    },
    {
      "value": "8933598c8b1fa5e493497b11c48da4f2",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2171",
          "title": "CISA KEV: CVE-2012-0754 \u2014 Adobe Flash Player Memory Corruption Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-06-08",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-06-08"
    },
    {
      "value": "b025b06549caae5a7c1d23ac1d014892",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2173",
          "title": "CISA KEV: CVE-2011-2462 \u2014 Adobe Reader and Acrobat Universal 3D Memory Corruption Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-06-08",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-06-08"
    },
    {
      "value": "b9872f4b6d2290de75a7ff2874a28850",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2173",
          "title": "CISA KEV: CVE-2011-2462 \u2014 Adobe Reader and Acrobat Universal 3D Memory Corruption Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-06-08",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-06-08"
    },
    {
      "value": "ba7793845fe2a02187263a96e8daaec6",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2173",
          "title": "CISA KEV: CVE-2011-2462 \u2014 Adobe Reader and Acrobat Universal 3D Memory Corruption Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-06-08",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-06-08"
    },
    {
      "value": "cb3dcde34fd9ff0e19381d99b02f9692",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2171",
          "title": "CISA KEV: CVE-2012-0754 \u2014 Adobe Flash Player Memory Corruption Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-06-08",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-06-08"
    },
    {
      "value": "e769a920b12d019679c43a9a4c0d7e2c",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2173",
          "title": "CISA KEV: CVE-2011-2462 \u2014 Adobe Reader and Acrobat Universal 3D Memory Corruption Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-06-08",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-06-08"
    },
    {
      "value": "e92a4fc283eb2802ad6d0e24c7fcc857",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2171",
          "title": "CISA KEV: CVE-2012-0754 \u2014 Adobe Flash Player Memory Corruption Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-06-08",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-06-08"
    },
    {
      "value": "fd1be09e499e8e380424b3835fc973a8",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2171",
          "title": "CISA KEV: CVE-2012-0754 \u2014 Adobe Flash Player Memory Corruption Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-06-08",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-06-08"
    },
    {
      "value": "fd778c023020a23311b68127bf7e7692",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2173",
          "title": "CISA KEV: CVE-2011-2462 \u2014 Adobe Reader and Acrobat Universal 3D Memory Corruption Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-06-08",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-06-08"
    },
    {
      "value": "2dd92dcfe5a46143b9a879122432e48ef0b9016736b66cd322f5c9fb5d3441dd",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2171",
          "title": "CISA KEV: CVE-2012-0754 \u2014 Adobe Flash Player Memory Corruption Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-06-08",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-06-08"
    },
    {
      "value": "68360603794c0f6d1aff9f6853dbdbb1860a89269d3147dab768034d4195ca62",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2171",
          "title": "CISA KEV: CVE-2012-0754 \u2014 Adobe Flash Player Memory Corruption Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-06-08",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-06-08"
    },
    {
      "value": "CVE-2021-23771",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-2186",
          "title": "Safer together: Snyk and CISPA collaborate for the greater good",
          "link": "https://snyk.io/blog/safer-together-snyk-and-cispa-collaborate/",
          "published": "2022-06-06",
          "sev": "high"
        }
      ],
      "first_seen": "2022-06-06"
    },
    {
      "value": "CVE-2022-21144",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-2186",
          "title": "Safer together: Snyk and CISPA collaborate for the greater good",
          "link": "https://snyk.io/blog/safer-together-snyk-and-cispa-collaborate/",
          "published": "2022-06-06",
          "sev": "high"
        }
      ],
      "first_seen": "2022-06-06"
    },
    {
      "value": "154.146.34.145",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2188",
          "title": "CISA KEV: CVE-2022-26134 \u2014 Atlassian Confluence Server and Data Center Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-06-02",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-06-02"
    },
    {
      "value": "154.16.105.147",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2188",
          "title": "CISA KEV: CVE-2022-26134 \u2014 Atlassian Confluence Server and Data Center Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-06-02",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-06-02"
    },
    {
      "value": "156.146.34.46",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2188",
          "title": "CISA KEV: CVE-2022-26134 \u2014 Atlassian Confluence Server and Data Center Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-06-02",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-06-02"
    },
    {
      "value": "156.146.34.52",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2188",
          "title": "CISA KEV: CVE-2022-26134 \u2014 Atlassian Confluence Server and Data Center Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-06-02",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-06-02"
    },
    {
      "value": "156.146.34.9",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2188",
          "title": "CISA KEV: CVE-2022-26134 \u2014 Atlassian Confluence Server and Data Center Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-06-02",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-06-02"
    },
    {
      "value": "156.146.56.136",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2188",
          "title": "CISA KEV: CVE-2022-26134 \u2014 Atlassian Confluence Server and Data Center Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-06-02",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-06-02"
    },
    {
      "value": "198.147.22.148",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2188",
          "title": "CISA KEV: CVE-2022-26134 \u2014 Atlassian Confluence Server and Data Center Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-06-02",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-06-02"
    },
    {
      "value": "221.178.126.244",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2188",
          "title": "CISA KEV: CVE-2022-26134 \u2014 Atlassian Confluence Server and Data Center Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-06-02",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-06-02"
    },
    {
      "value": "45.43.19.91",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2188",
          "title": "CISA KEV: CVE-2022-26134 \u2014 Atlassian Confluence Server and Data Center Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-06-02",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-06-02"
    },
    {
      "value": "59.163.248.170",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2188",
          "title": "CISA KEV: CVE-2022-26134 \u2014 Atlassian Confluence Server and Data Center Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-06-02",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-06-02"
    },
    {
      "value": "64.64.228.239",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2188",
          "title": "CISA KEV: CVE-2022-26134 \u2014 Atlassian Confluence Server and Data Center Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-06-02",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-06-02"
    },
    {
      "value": "66.115.182.102",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2188",
          "title": "CISA KEV: CVE-2022-26134 \u2014 Atlassian Confluence Server and Data Center Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-06-02",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-06-02"
    },
    {
      "value": "66.115.182.111",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2188",
          "title": "CISA KEV: CVE-2022-26134 \u2014 Atlassian Confluence Server and Data Center Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-06-02",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-06-02"
    },
    {
      "value": "67.149.61.16",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2188",
          "title": "CISA KEV: CVE-2022-26134 \u2014 Atlassian Confluence Server and Data Center Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-06-02",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-06-02"
    },
    {
      "value": "98.32.230.38",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2188",
          "title": "CISA KEV: CVE-2022-26134 \u2014 Atlassian Confluence Server and Data Center Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-06-02",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-06-02"
    },
    {
      "value": "ea18fb65d92e1f0671f23372bacf60e7",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2188",
          "title": "CISA KEV: CVE-2022-26134 \u2014 Atlassian Confluence Server and Data Center Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-06-02",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-06-02"
    },
    {
      "value": "f8df4dd46f02dc86d37d46cf4793e036",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2188",
          "title": "CISA KEV: CVE-2022-26134 \u2014 Atlassian Confluence Server and Data Center Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-06-02",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-06-02"
    },
    {
      "value": "4c02c3a150de6b70d6fca584c29888202cc1deef",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2188",
          "title": "CISA KEV: CVE-2022-26134 \u2014 Atlassian Confluence Server and Data Center Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-06-02",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-06-02"
    },
    {
      "value": "80b327ec19c7d14cc10511060ed3a4abffc821af",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2188",
          "title": "CISA KEV: CVE-2022-26134 \u2014 Atlassian Confluence Server and Data Center Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-06-02",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-06-02"
    },
    {
      "value": "CVE-2010-0738",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2225",
          "title": "CISA KEV: CVE-2010-0738 \u2014 Red Hat JBoss Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-05-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-05-25"
    },
    {
      "value": "CVE-2010-0840",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2224",
          "title": "CISA KEV: CVE-2010-0840 \u2014 Oracle JRE Unspecified Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-05-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-05-25"
    },
    {
      "value": "CVE-2010-1428",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2223",
          "title": "CISA KEV: CVE-2010-1428 \u2014 Red Hat JBoss Information Disclosure Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-05-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-05-25"
    },
    {
      "value": "CVE-2012-1710",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2222",
          "title": "CISA KEV: CVE-2012-1710 \u2014 Oracle Fusion Middleware Unspecified Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-05-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-05-25"
    },
    {
      "value": "CVE-2013-0074",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2221",
          "title": "CISA KEV: CVE-2013-0074 \u2014 Microsoft Silverlight Double Dereference Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-05-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-05-25"
    },
    {
      "value": "CVE-2013-0422",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2220",
          "title": "CISA KEV: CVE-2013-0422 \u2014 Oracle JRE Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-05-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-05-25"
    },
    {
      "value": "CVE-2013-0431",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2219",
          "title": "CISA KEV: CVE-2013-0431 \u2014 Oracle JRE Sandbox Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-05-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-05-25"
    },
    {
      "value": "CVE-2013-2423",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2218",
          "title": "CISA KEV: CVE-2013-2423 \u2014 Oracle JRE Unspecified Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-05-25",
          "sev": "crit"
        },
        {
          "id": "art-2219",
          "title": "CISA KEV: CVE-2013-0431 \u2014 Oracle JRE Sandbox Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-05-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-05-25"
    },
    {
      "value": "CVE-2013-3896",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2217",
          "title": "CISA KEV: CVE-2013-3896 \u2014 Microsoft Silverlight Information Disclosure Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-05-25",
          "sev": "crit"
        },
        {
          "id": "art-2221",
          "title": "CISA KEV: CVE-2013-0074 \u2014 Microsoft Silverlight Double Dereference Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-05-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-05-25"
    },
    {
      "value": "CVE-2013-3993",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2216",
          "title": "CISA KEV: CVE-2013-3993 \u2014 IBM InfoSphere BigInsights Invalid Input Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-05-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-05-25"
    },
    {
      "value": "CVE-2013-7331",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2215",
          "title": "CISA KEV: CVE-2013-7331 \u2014 Microsoft Internet Explorer Information Disclosure Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-05-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-05-25"
    },
    {
      "value": "CVE-2014-0546",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2211",
          "title": "CISA KEV: CVE-2014-0546 \u2014 Adobe Reader and Acrobat Sandbox Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-05-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-05-25"
    },
    {
      "value": "CVE-2014-2817",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2212",
          "title": "CISA KEV: CVE-2014-2817 \u2014 Microsoft Internet Explorer Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-05-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-05-25"
    },
    {
      "value": "CVE-2014-3153",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2214",
          "title": "CISA KEV: CVE-2014-3153 \u2014 Linux Kernel Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-05-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-05-25"
    },
    {
      "value": "CVE-2014-4077",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2213",
          "title": "CISA KEV: CVE-2014-4077 \u2014 Microsoft IME Japanese Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-05-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-05-25"
    },
    {
      "value": "CVE-2014-4123",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2210",
          "title": "CISA KEV: CVE-2014-4123 \u2014 Microsoft Internet Explorer Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-05-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-05-25"
    },
    {
      "value": "CVE-2014-4148",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2208",
          "title": "CISA KEV: CVE-2014-4148 \u2014 Microsoft Windows Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-05-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-05-25"
    },
    {
      "value": "CVE-2014-8439",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2209",
          "title": "CISA KEV: CVE-2014-8439 \u2014 Adobe Flash Player Dereferenced Pointer Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-05-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-05-25"
    },
    {
      "value": "CVE-2015-0016",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2199",
          "title": "CISA KEV: CVE-2015-0016 \u2014 Microsoft Windows TS WebProxy Directory Traversal Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-05-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-05-25"
    },
    {
      "value": "CVE-2015-0071",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2200",
          "title": "CISA KEV: CVE-2015-0071 \u2014 Microsoft Internet Explorer ASLR Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-05-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-05-25"
    },
    {
      "value": "CVE-2015-0310",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2198",
          "title": "CISA KEV: CVE-2015-0310 \u2014 Adobe Flash Player ASLR Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-05-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-05-25"
    },
    {
      "value": "CVE-2015-0311",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2198",
          "title": "CISA KEV: CVE-2015-0310 \u2014 Adobe Flash Player ASLR Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-05-25",
          "sev": "crit"
        },
        {
          "id": "art-2340",
          "title": "CISA KEV: CVE-2015-0311 \u2014 Adobe Flash Player Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-04-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-05-25"
    },
    {
      "value": "CVE-2015-1671",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2207",
          "title": "CISA KEV: CVE-2015-1671 \u2014 Microsoft Windows Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-05-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-05-25"
    },
    {
      "value": "CVE-2015-1769",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2203",
          "title": "CISA KEV: CVE-2015-1769 \u2014 Microsoft Windows Mount Manager Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-05-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-05-25"
    },
    {
      "value": "CVE-2015-2360",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2201",
          "title": "CISA KEV: CVE-2015-2360 \u2014 Microsoft Win32k Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-05-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-05-25"
    },
    {
      "value": "CVE-2015-2425",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2202",
          "title": "CISA KEV: CVE-2015-2425 \u2014 Microsoft Internet Explorer Memory Corruption Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-05-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-05-25"
    },
    {
      "value": "CVE-2015-4495",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2204",
          "title": "CISA KEV: CVE-2015-4495 \u2014 Mozilla Firefox Security Feature Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-05-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-05-25"
    },
    {
      "value": "CVE-2015-6175",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2206",
          "title": "CISA KEV: CVE-2015-6175 \u2014 Microsoft Windows Kernel Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-05-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-05-25"
    },
    {
      "value": "CVE-2015-8651",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2205",
          "title": "CISA KEV: CVE-2015-8651 \u2014 Adobe Flash Player Integer Overflow Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-05-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-05-25"
    },
    {
      "value": "CVE-2016-0034",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2197",
          "title": "CISA KEV: CVE-2016-0034 \u2014 Microsoft Silverlight Runtime Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-05-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-05-25"
    },
    {
      "value": "CVE-2016-0189",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2199",
          "title": "CISA KEV: CVE-2015-0016 \u2014 Microsoft Windows TS WebProxy Directory Traversal Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-05-25",
          "sev": "crit"
        },
        {
          "id": "art-2393",
          "title": "CISA KEV: CVE-2016-0189 \u2014 Microsoft Internet Explorer Memory Corruption Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-28",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-05-25"
    },
    {
      "value": "CVE-2016-0984",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2196",
          "title": "CISA KEV: CVE-2016-0984 \u2014 Adobe Flash Player and AIR Use-After-Free Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-05-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-05-25"
    },
    {
      "value": "CVE-2016-1010",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2195",
          "title": "CISA KEV: CVE-2016-1010 \u2014 Adobe Flash Player and AIR Integer Overflow Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-05-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-05-25"
    },
    {
      "value": "CVE-2016-3393",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2193",
          "title": "CISA KEV: CVE-2016-3393 \u2014 Microsoft Windows Graphics Device Interface (GDI) Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-05-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-05-25"
    },
    {
      "value": "CVE-2016-7256",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2194",
          "title": "CISA KEV: CVE-2016-7256 \u2014 Microsoft Windows Open Type Font Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-05-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-05-25"
    },
    {
      "value": "CVE-2019-3010",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2192",
          "title": "CISA KEV: CVE-2019-3010 \u2014 Oracle Solaris Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-05-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-05-25"
    },
    {
      "value": "besexeweryopko.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2221",
          "title": "CISA KEV: CVE-2013-0074 \u2014 Microsoft Silverlight Double Dereference Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-05-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-05-25"
    },
    {
      "value": "cnacom-organied.rhcloud.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2199",
          "title": "CISA KEV: CVE-2015-0016 \u2014 Microsoft Windows TS WebProxy Directory Traversal Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-05-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-05-25"
    },
    {
      "value": "disabilitybenefitsinsider.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2221",
          "title": "CISA KEV: CVE-2013-0074 \u2014 Microsoft Silverlight Double Dereference Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-05-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-05-25"
    },
    {
      "value": "img.hitres.in",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2221",
          "title": "CISA KEV: CVE-2013-0074 \u2014 Microsoft Silverlight Double Dereference Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-05-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-05-25"
    },
    {
      "value": "jvdsdveee.pw",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2221",
          "title": "CISA KEV: CVE-2013-0074 \u2014 Microsoft Silverlight Double Dereference Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-05-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-05-25"
    },
    {
      "value": "peragretisque.yevgenimalkin.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2221",
          "title": "CISA KEV: CVE-2013-0074 \u2014 Microsoft Silverlight Double Dereference Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-05-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-05-25"
    },
    {
      "value": "www1.gh1pn3avb63m2.4pu.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2221",
          "title": "CISA KEV: CVE-2013-0074 \u2014 Microsoft Silverlight Double Dereference Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-05-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-05-25"
    },
    {
      "value": "www2.h-qo05lqa59ljh7.wpbh.org",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2221",
          "title": "CISA KEV: CVE-2013-0074 \u2014 Microsoft Silverlight Double Dereference Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-05-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-05-25"
    },
    {
      "value": "www3.3b812bc6.kjyg.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2221",
          "title": "CISA KEV: CVE-2013-0074 \u2014 Microsoft Silverlight Double Dereference Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-05-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-05-25"
    },
    {
      "value": "74.200.214.226",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2199",
          "title": "CISA KEV: CVE-2015-0016 \u2014 Microsoft Windows TS WebProxy Directory Traversal Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-05-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-05-25"
    },
    {
      "value": "01ce22f87227f869b7978dc5fe625e16",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2197",
          "title": "CISA KEV: CVE-2016-0034 \u2014 Microsoft Silverlight Runtime Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-05-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-05-25"
    },
    {
      "value": "167a0ffcfb6d828f5090b58d0b3c6b30",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2221",
          "title": "CISA KEV: CVE-2013-0074 \u2014 Microsoft Silverlight Double Dereference Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-05-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-05-25"
    },
    {
      "value": "22a9f342eb367ea9b00508adb738d858",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2197",
          "title": "CISA KEV: CVE-2016-0034 \u2014 Microsoft Silverlight Runtime Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-05-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-05-25"
    },
    {
      "value": "5f36a4c019d559f1be9fdd0cd770be2e",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2221",
          "title": "CISA KEV: CVE-2013-0074 \u2014 Microsoft Silverlight Double Dereference Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-05-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-05-25"
    },
    {
      "value": "5faca70a46982cb945cd8e4b3a544aa8",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2221",
          "title": "CISA KEV: CVE-2013-0074 \u2014 Microsoft Silverlight Double Dereference Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-05-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-05-25"
    },
    {
      "value": "6a01421a9bd82f02051ce6a4ea4e2edc",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2197",
          "title": "CISA KEV: CVE-2016-0034 \u2014 Microsoft Silverlight Runtime Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-05-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-05-25"
    },
    {
      "value": "7043831f829fd8305a59cc6df09cc8b6",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2221",
          "title": "CISA KEV: CVE-2013-0074 \u2014 Microsoft Silverlight Double Dereference Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-05-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-05-25"
    },
    {
      "value": "83b0c1ff586044dbc6c0b99c55e27534",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2221",
          "title": "CISA KEV: CVE-2013-0074 \u2014 Microsoft Silverlight Double Dereference Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-05-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-05-25"
    },
    {
      "value": "acfa9c664016bfe5db92557e923744f0",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2199",
          "title": "CISA KEV: CVE-2015-0016 \u2014 Microsoft Windows TS WebProxy Directory Traversal Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-05-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-05-25"
    },
    {
      "value": "b61b986194de5fef36d805923a0f9379",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2221",
          "title": "CISA KEV: CVE-2013-0074 \u2014 Microsoft Silverlight Double Dereference Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-05-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-05-25"
    },
    {
      "value": "bdcfe33dbc7f86b929ddfbfa7a4ce43d",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2221",
          "title": "CISA KEV: CVE-2013-0074 \u2014 Microsoft Silverlight Double Dereference Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-05-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-05-25"
    },
    {
      "value": "cb9f864eb3b63172d01f9f45d849cc15",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2221",
          "title": "CISA KEV: CVE-2013-0074 \u2014 Microsoft Silverlight Double Dereference Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-05-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-05-25"
    },
    {
      "value": "ce056895e07d2a9d04c5e8db844013ea",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2221",
          "title": "CISA KEV: CVE-2013-0074 \u2014 Microsoft Silverlight Double Dereference Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-05-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-05-25"
    },
    {
      "value": "dc7647bc7896912b0fea4b93815e7fd0",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2221",
          "title": "CISA KEV: CVE-2013-0074 \u2014 Microsoft Silverlight Double Dereference Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-05-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-05-25"
    },
    {
      "value": "061be17741f0918bbf458812f6a04ebf3b70dea5",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2218",
          "title": "CISA KEV: CVE-2013-2423 \u2014 Oracle JRE Unspecified Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-05-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-05-25"
    },
    {
      "value": "28dc42c7b66a6a9e45d07397f1be684e1acb1372",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2218",
          "title": "CISA KEV: CVE-2013-2423 \u2014 Oracle JRE Unspecified Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-05-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-05-25"
    },
    {
      "value": "3866d78f233e5458c3244043b43006e9b3213582",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2218",
          "title": "CISA KEV: CVE-2013-2423 \u2014 Oracle JRE Unspecified Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-05-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-05-25"
    },
    {
      "value": "5b90f226256b2853e38ffab6f3b1cb651b9f90b2",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2218",
          "title": "CISA KEV: CVE-2013-2423 \u2014 Oracle JRE Unspecified Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-05-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-05-25"
    },
    {
      "value": "5e0ad173659e9e2e06d89ffa3e98738a6ddecdac",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2218",
          "title": "CISA KEV: CVE-2013-2423 \u2014 Oracle JRE Unspecified Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-05-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-05-25"
    },
    {
      "value": "6c388af46e222a264344c67168d21569cf6e088c",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2218",
          "title": "CISA KEV: CVE-2013-2423 \u2014 Oracle JRE Unspecified Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-05-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-05-25"
    },
    {
      "value": "8619454ec435a727f52ca795c2b1316420e82c4e",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2218",
          "title": "CISA KEV: CVE-2013-2423 \u2014 Oracle JRE Unspecified Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-05-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-05-25"
    },
    {
      "value": "3242561cc9bb3e131e0738078e2e44886df307035f3be0bd3defbbc631e34c80",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2197",
          "title": "CISA KEV: CVE-2016-0034 \u2014 Microsoft Silverlight Runtime Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-05-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-05-25"
    },
    {
      "value": "acb74c05a1b0f97cc1a45661ea72a67a080b77f8eb9849ca440037a077461f6b",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2197",
          "title": "CISA KEV: CVE-2016-0034 \u2014 Microsoft Silverlight Runtime Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-05-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-05-25"
    },
    {
      "value": "e535cf04335e92587f640432d4ec3838b4605cd7e3864cfba2db94baae060415",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2197",
          "title": "CISA KEV: CVE-2016-0034 \u2014 Microsoft Silverlight Runtime Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-05-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-05-25"
    },
    {
      "value": "CVE-2016-0162",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2239",
          "title": "CISA KEV: CVE-2016-0162 \u2014 Microsoft Internet Explorer Information Disclosure Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-05-24",
          "sev": "crit"
        },
        {
          "id": "art-2240",
          "title": "CISA KEV: CVE-2016-3351 \u2014 Microsoft Internet Explorer and Edge Information Disclosure Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-05-24",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-05-24"
    },
    {
      "value": "CVE-2016-3298",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2246",
          "title": "CISA KEV: CVE-2016-3298 \u2014 Microsoft Internet Explorer Messaging API Information Disclosure Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-05-24",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-05-24"
    },
    {
      "value": "CVE-2016-3351",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2240",
          "title": "CISA KEV: CVE-2016-3351 \u2014 Microsoft Internet Explorer and Edge Information Disclosure Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-05-24",
          "sev": "crit"
        },
        {
          "id": "art-2246",
          "title": "CISA KEV: CVE-2016-3298 \u2014 Microsoft Internet Explorer Messaging API Information Disclosure Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-05-24",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-05-24"
    },
    {
      "value": "CVE-2016-4655",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2241",
          "title": "CISA KEV: CVE-2016-4655 \u2014 Apple iOS Information Disclosure Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-05-24",
          "sev": "crit"
        },
        {
          "id": "art-2242",
          "title": "CISA KEV: CVE-2016-4656 \u2014 Apple iOS Memory Corruption Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-05-24",
          "sev": "crit"
        },
        {
          "id": "art-2243",
          "title": "CISA KEV: CVE-2016-4657 \u2014 Apple iOS Webkit Memory Corruption Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-05-24",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-05-24"
    },
    {
      "value": "CVE-2016-4656",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2242",
          "title": "CISA KEV: CVE-2016-4656 \u2014 Apple iOS Memory Corruption Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-05-24",
          "sev": "crit"
        },
        {
          "id": "art-2243",
          "title": "CISA KEV: CVE-2016-4657 \u2014 Apple iOS Webkit Memory Corruption Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-05-24",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-05-24"
    },
    {
      "value": "CVE-2016-4657",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2242",
          "title": "CISA KEV: CVE-2016-4656 \u2014 Apple iOS Memory Corruption Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-05-24",
          "sev": "crit"
        },
        {
          "id": "art-2243",
          "title": "CISA KEV: CVE-2016-4657 \u2014 Apple iOS Webkit Memory Corruption Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-05-24",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-05-24"
    },
    {
      "value": "CVE-2016-6366",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2244",
          "title": "CISA KEV: CVE-2016-6366 \u2014 Cisco Adaptive Security Appliance (ASA) SNMP Buffer Overflow Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-05-24",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-05-24"
    },
    {
      "value": "CVE-2016-6367",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2245",
          "title": "CISA KEV: CVE-2016-6367 \u2014 Cisco Adaptive Security Appliance (ASA) CLI Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-05-24",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-05-24"
    },
    {
      "value": "CVE-2017-0005",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2233",
          "title": "CISA KEV: CVE-2017-0005 \u2014 Microsoft Windows Graphics Device Interface (GDI) Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-05-24",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-05-24"
    },
    {
      "value": "CVE-2017-0022",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2232",
          "title": "CISA KEV: CVE-2017-0022 \u2014 Microsoft XML Core Services Information Disclosure Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-05-24",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-05-24"
    },
    {
      "value": "CVE-2017-0147",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2231",
          "title": "CISA KEV: CVE-2017-0147 \u2014 Microsoft Windows SMBv1 Information Disclosure Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-05-24",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-05-24"
    },
    {
      "value": "CVE-2017-0149",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2234",
          "title": "CISA KEV: CVE-2017-0149 \u2014 Microsoft Internet Explorer Memory Corruption Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-05-24",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-05-24"
    },
    {
      "value": "CVE-2017-0210",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2235",
          "title": "CISA KEV: CVE-2017-0210 \u2014 Microsoft Internet Explorer Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-05-24",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-05-24"
    },
    {
      "value": "CVE-2017-18362",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2238",
          "title": "CISA KEV: CVE-2017-18362 \u2014 Kaseya VSA SQL Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-05-24",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-05-24"
    },
    {
      "value": "CVE-2017-8291",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2236",
          "title": "CISA KEV: CVE-2017-8291 \u2014 Artifex Ghostscript Type Confusion Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-05-24",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-05-24"
    },
    {
      "value": "CVE-2017-8543",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2237",
          "title": "CISA KEV: CVE-2017-8543 \u2014 Microsoft Windows Search Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-05-24",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-05-24"
    },
    {
      "value": "CVE-2018-19943",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2230",
          "title": "CISA KEV: CVE-2018-19943 \u2014 QNAP NAS File Station Cross-Site Scripting Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-05-24",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-05-24"
    },
    {
      "value": "CVE-2018-19949",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2229",
          "title": "CISA KEV: CVE-2018-19949 \u2014 QNAP NAS File Station Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-05-24",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-05-24"
    },
    {
      "value": "CVE-2018-19953",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2228",
          "title": "CISA KEV: CVE-2018-19953 \u2014 QNAP NAS File Station Cross-Site Scripting Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-05-24",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-05-24"
    },
    {
      "value": "CVE-2018-8611",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2227",
          "title": "CISA KEV: CVE-2018-8611 \u2014 Microsoft Windows Kernel Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-05-24",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-05-24"
    },
    {
      "value": "aalaan.tv",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2243",
          "title": "CISA KEV: CVE-2016-4657 \u2014 Apple iOS Webkit Memory Corruption Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-05-24",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-05-24"
    },
    {
      "value": "apis.crosif.fr",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2246",
          "title": "CISA KEV: CVE-2016-3298 \u2014 Microsoft Internet Explorer Messaging API Information Disclosure Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-05-24",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-05-24"
    },
    {
      "value": "denwey.site",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2246",
          "title": "CISA KEV: CVE-2016-3298 \u2014 Microsoft Internet Explorer Messaging API Information Disclosure Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-05-24",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-05-24"
    },
    {
      "value": "forete.site",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2246",
          "title": "CISA KEV: CVE-2016-3298 \u2014 Microsoft Internet Explorer Messaging API Information Disclosure Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-05-24",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-05-24"
    },
    {
      "value": "jpitohuiny.chinchillawalk.site",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2246",
          "title": "CISA KEV: CVE-2016-3298 \u2014 Microsoft Internet Explorer Messaging API Information Disclosure Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-05-24",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-05-24"
    },
    {
      "value": "manoraonline.net",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2243",
          "title": "CISA KEV: CVE-2016-4657 \u2014 Apple iOS Webkit Memory Corruption Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-05-24",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-05-24"
    },
    {
      "value": "nbbrnofl.hotemichael.site",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2246",
          "title": "CISA KEV: CVE-2016-3298 \u2014 Microsoft Internet Explorer Messaging API Information Disclosure Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-05-24",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-05-24"
    },
    {
      "value": "pkgio.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-2226",
          "title": "Snyk finds 200+ malicious npm packages, including Cobalt Strike dependency confusion attacks",
          "link": "https://snyk.io/blog/snyk-200-malicious-npm-packages-cobalt-strike-dependency-confusion-attacks/",
          "published": "2022-05-24",
          "sev": "crit"
        },
        {
          "id": "art-2296",
          "title": "Targeted npm dependency confusion attack caught red-handed",
          "link": "https://snyk.io/blog/npm-dependency-confusion-attack-gxm-reference/",
          "published": "2022-04-30",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-05-24"
    },
    {
      "value": "sms.webadv.co",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2243",
          "title": "CISA KEV: CVE-2016-4657 \u2014 Apple iOS Webkit Memory Corruption Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-05-24",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-05-24"
    },
    {
      "value": "www.pkgio.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-2226",
          "title": "Snyk finds 200+ malicious npm packages, including Cobalt Strike dependency confusion attacks",
          "link": "https://snyk.io/blog/snyk-200-malicious-npm-packages-cobalt-strike-dependency-confusion-attacks/",
          "published": "2022-05-24",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-05-24"
    },
    {
      "value": "162.209.103.68",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2243",
          "title": "CISA KEV: CVE-2016-4657 \u2014 Apple iOS Webkit Memory Corruption Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-05-24",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-05-24"
    },
    {
      "value": "45.76.145.77",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2246",
          "title": "CISA KEV: CVE-2016-3298 \u2014 Microsoft Internet Explorer Messaging API Information Disclosure Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-05-24",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-05-24"
    },
    {
      "value": "5.135.68.242",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2246",
          "title": "CISA KEV: CVE-2016-3298 \u2014 Microsoft Internet Explorer Messaging API Information Disclosure Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-05-24",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-05-24"
    },
    {
      "value": "51.255.146.122",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2246",
          "title": "CISA KEV: CVE-2016-3298 \u2014 Microsoft Internet Explorer Messaging API Information Disclosure Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-05-24",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-05-24"
    },
    {
      "value": "52.8.153.44",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2243",
          "title": "CISA KEV: CVE-2016-4657 \u2014 Apple iOS Webkit Memory Corruption Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-05-24",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-05-24"
    },
    {
      "value": "52.8.52.166",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2243",
          "title": "CISA KEV: CVE-2016-4657 \u2014 Apple iOS Webkit Memory Corruption Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-05-24",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-05-24"
    },
    {
      "value": "94.23.212.89",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2246",
          "title": "CISA KEV: CVE-2016-3298 \u2014 Microsoft Internet Explorer Messaging API Information Disclosure Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-05-24",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-05-24"
    },
    {
      "value": "634a80e37e4b32706ad1ea4a2ff414473618a8c42a369880db7cc127c0eb705e",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2233",
          "title": "CISA KEV: CVE-2017-0005 \u2014 Microsoft Windows Graphics Device Interface (GDI) Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-05-24",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-05-24"
    },
    {
      "value": "ae512f13136774b4aab79ebcc378927143be77181e3b256e6f9940ce73696de4",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2233",
          "title": "CISA KEV: CVE-2017-0005 \u2014 Microsoft Windows Graphics Device Interface (GDI) Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-05-24",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-05-24"
    },
    {
      "value": "CVE-2018-5002",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2266",
          "title": "CISA KEV: CVE-2018-5002 \u2014 Adobe Flash Player Stack-based Buffer Overflow Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-05-23",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-05-23"
    },
    {
      "value": "CVE-2018-8589",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2267",
          "title": "CISA KEV: CVE-2018-8589 \u2014 Microsoft Win32k Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-05-23",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-05-23"
    },
    {
      "value": "CVE-2019-0676",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2255",
          "title": "CISA KEV: CVE-2019-0676 \u2014 Microsoft Internet Explorer Information Disclosure Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-05-23",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-05-23"
    },
    {
      "value": "CVE-2019-0703",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2257",
          "title": "CISA KEV: CVE-2019-0703 \u2014 Microsoft Windows SMB Information Disclosure Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-05-23",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-05-23"
    },
    {
      "value": "CVE-2019-0808",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2256",
          "title": "CISA KEV: CVE-2019-5786 \u2014 Google Chrome Blink Use-After-Free Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-05-23",
          "sev": "crit"
        },
        {
          "id": "art-2991",
          "title": "CISA KEV: CVE-2019-0808 \u2014 Microsoft Win32k Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-05-23"
    },
    {
      "value": "CVE-2019-0880",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2258",
          "title": "CISA KEV: CVE-2019-0880 \u2014 Microsoft Windows Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-05-23",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-05-23"
    },
    {
      "value": "CVE-2019-1130",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2265",
          "title": "CISA KEV: CVE-2019-1130 \u2014 Microsoft Windows AppX Deployment Service Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-05-23",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-05-23"
    },
    {
      "value": "CVE-2019-11707",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2260",
          "title": "CISA KEV: CVE-2019-11707 \u2014 Mozilla Firefox and Thunderbird Type Confusion Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-05-23",
          "sev": "crit"
        },
        {
          "id": "art-2261",
          "title": "CISA KEV: CVE-2019-11708 \u2014 Mozilla Firefox and Thunderbird Sandbox Escape Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-05-23",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-05-23"
    },
    {
      "value": "CVE-2019-11708",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2260",
          "title": "CISA KEV: CVE-2019-11707 \u2014 Mozilla Firefox and Thunderbird Type Confusion Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-05-23",
          "sev": "crit"
        },
        {
          "id": "art-2261",
          "title": "CISA KEV: CVE-2019-11708 \u2014 Mozilla Firefox and Thunderbird Sandbox Escape Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-05-23",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-05-23"
    },
    {
      "value": "CVE-2019-13720",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2259",
          "title": "CISA KEV: CVE-2019-13720 \u2014 Google Chrome WebAudio Use-After-Free Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-05-23",
          "sev": "crit"
        },
        {
          "id": "art-2720",
          "title": "CISA KEV: CVE-2019-1458 \u2014 Microsoft Win32k Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-01-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-05-23"
    },
    {
      "value": "CVE-2019-1385",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2264",
          "title": "CISA KEV: CVE-2019-1385 \u2014 Microsoft Windows AppX Deployment Extensions Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-05-23",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-05-23"
    },
    {
      "value": "CVE-2019-1458",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2259",
          "title": "CISA KEV: CVE-2019-13720 \u2014 Google Chrome WebAudio Use-After-Free Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-05-23",
          "sev": "crit"
        },
        {
          "id": "art-2720",
          "title": "CISA KEV: CVE-2019-1458 \u2014 Microsoft Win32k Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-01-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-05-23"
    },
    {
      "value": "CVE-2019-18426",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2263",
          "title": "CISA KEV: CVE-2019-18426 \u2014 WhatsApp Cross-Site Scripting Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-05-23",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-05-23"
    },
    {
      "value": "CVE-2019-5786",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2256",
          "title": "CISA KEV: CVE-2019-5786 \u2014 Google Chrome Blink Use-After-Free Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-05-23",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-05-23"
    },
    {
      "value": "CVE-2019-7286",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2253",
          "title": "CISA KEV: CVE-2019-7286 \u2014 Apple Multiple Products Memory Corruption Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-05-23",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-05-23"
    },
    {
      "value": "CVE-2019-7287",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2253",
          "title": "CISA KEV: CVE-2019-7286 \u2014 Apple Multiple Products Memory Corruption Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-05-23",
          "sev": "crit"
        },
        {
          "id": "art-2254",
          "title": "CISA KEV: CVE-2019-7287 \u2014 Apple iOS Memory Corruption Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-05-23",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-05-23"
    },
    {
      "value": "CVE-2019-8720",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2262",
          "title": "CISA KEV: CVE-2019-8720 \u2014 WebKitGTK Memory Corruption Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-05-23",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-05-23"
    },
    {
      "value": "CVE-2020-0638",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2252",
          "title": "CISA KEV: CVE-2020-0638 \u2014 Microsoft Update Notification Manager Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-05-23",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-05-23"
    },
    {
      "value": "CVE-2020-1027",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2251",
          "title": "CISA KEV: CVE-2020-1027 \u2014 Microsoft Windows Kernel Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-05-23",
          "sev": "crit"
        },
        {
          "id": "art-2258",
          "title": "CISA KEV: CVE-2019-0880 \u2014 Microsoft Windows Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-05-23",
          "sev": "crit"
        },
        {
          "id": "art-2900",
          "title": "CISA KEV: CVE-2020-6418 \u2014 Google Chromium V8 Type Confusion Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-05-23"
    },
    {
      "value": "CVE-2021-0920",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2249",
          "title": "CISA KEV: CVE-2021-0920 \u2014 Android Kernel Race Condition Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-05-23",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-05-23"
    },
    {
      "value": "CVE-2021-1048",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2248",
          "title": "CISA KEV: CVE-2021-1048 \u2014 Android Kernel Use-After-Free Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-05-23",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-05-23"
    },
    {
      "value": "CVE-2021-30883",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2250",
          "title": "CISA KEV: CVE-2021-30883 \u2014 Apple Multiple Products Memory Corruption Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-05-23",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-05-23"
    },
    {
      "value": "CVE-2022-20821",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2247",
          "title": "CISA KEV: CVE-2022-20821 \u2014 Cisco IOS XR Open Port Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-05-23",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-05-23"
    },
    {
      "value": "behindcorona.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2259",
          "title": "CISA KEV: CVE-2019-13720 \u2014 Google Chrome WebAudio Use-After-Free Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-05-23",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-05-23"
    },
    {
      "value": "code.jquery.cdn.behindcorona.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2259",
          "title": "CISA KEV: CVE-2019-13720 \u2014 Google Chrome WebAudio Use-After-Free Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-05-23",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-05-23"
    },
    {
      "value": "185.49.69.210",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2260",
          "title": "CISA KEV: CVE-2019-11707 \u2014 Mozilla Firefox and Thunderbird Type Confusion Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-05-23",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-05-23"
    },
    {
      "value": "27e941683d09a7405a9e806cc7d156c9",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2259",
          "title": "CISA KEV: CVE-2019-13720 \u2014 Google Chrome WebAudio Use-After-Free Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-05-23",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-05-23"
    },
    {
      "value": "474d33349c808c86f0039d6130eb1c3e",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2260",
          "title": "CISA KEV: CVE-2019-11707 \u2014 Mozilla Firefox and Thunderbird Type Confusion Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-05-23",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-05-23"
    },
    {
      "value": "8f3cd9299b2f241daf1f5057ba0b9054",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2259",
          "title": "CISA KEV: CVE-2019-13720 \u2014 Google Chrome WebAudio Use-After-Free Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-05-23",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-05-23"
    },
    {
      "value": "bfad2737fe8ea987c1cc5f8f38031677",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2260",
          "title": "CISA KEV: CVE-2019-11707 \u2014 Mozilla Firefox and Thunderbird Type Confusion Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-05-23",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-05-23"
    },
    {
      "value": "c494e0efe766d657a55a1fd37f5d94c1",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2260",
          "title": "CISA KEV: CVE-2019-11707 \u2014 Mozilla Firefox and Thunderbird Type Confusion Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-05-23",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-05-23"
    },
    {
      "value": "c8030abb9b95ba961a1c8ebcab43c862",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2260",
          "title": "CISA KEV: CVE-2019-11707 \u2014 Mozilla Firefox and Thunderbird Type Confusion Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-05-23",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-05-23"
    },
    {
      "value": "e5d4af62734babc54f43d8a11f640be2",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2260",
          "title": "CISA KEV: CVE-2019-11707 \u2014 Mozilla Firefox and Thunderbird Type Confusion Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-05-23",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-05-23"
    },
    {
      "value": "ece82aa35ebd3223504634661d07bd41",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2260",
          "title": "CISA KEV: CVE-2019-11707 \u2014 Mozilla Firefox and Thunderbird Type Confusion Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-05-23",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-05-23"
    },
    {
      "value": "f614909fbd57ece81d00b01958338ec2",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2259",
          "title": "CISA KEV: CVE-2019-13720 \u2014 Google Chrome WebAudio Use-After-Free Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-05-23",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-05-23"
    },
    {
      "value": "23017a55b3d25a2597b7148214fd8fb2372591a5",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2260",
          "title": "CISA KEV: CVE-2019-11707 \u2014 Mozilla Firefox and Thunderbird Type Confusion Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-05-23",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-05-23"
    },
    {
      "value": "35373d07c2e408838812ff210aa28d90e97e38f2d0132a86085b0d54256cc1cd",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2259",
          "title": "CISA KEV: CVE-2019-13720 \u2014 Google Chrome WebAudio Use-After-Free Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-05-23",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-05-23"
    },
    {
      "value": "8fb2558765cf648305493e1dfea7a2b26f4fc8f44ff72c95e9165a904a9a6a48",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2259",
          "title": "CISA KEV: CVE-2019-13720 \u2014 Google Chrome WebAudio Use-After-Free Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-05-23",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-05-23"
    },
    {
      "value": "cafe8f704095b1f5e0a885f75b1b41a7395a1c62fd893ef44348f9702b3a0deb",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2259",
          "title": "CISA KEV: CVE-2019-13720 \u2014 Google Chrome WebAudio Use-After-Free Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-05-23",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-05-23"
    },
    {
      "value": "CVE-2021-45105",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-2269",
          "title": "How LiveRamp used Snyk to remediate Log4Shell",
          "link": "https://snyk.io/blog/liveramp-used-snyk-to-remediate-log4shell/",
          "published": "2022-05-19",
          "sev": "high"
        },
        {
          "id": "art-2747",
          "title": "Log4j 2.16 High Severity Vulnerability (CVE-2021-45105) Discovered",
          "link": "https://snyk.io/blog/log4j-2-16-vulnerability-cve-2021-45105-discovered/",
          "published": "2021-12-18",
          "sev": "high"
        },
        {
          "id": "art-2749",
          "title": "Log4j 2.15 vulnerability CVE-2021-45046 upgraded to a critical severity arbitrary code execution",
          "link": "https://snyk.io/blog/log4j-2-15-vulnerability-cve-2021-45046-critical-ace/",
          "published": "2021-12-17",
          "sev": "high"
        },
        {
          "id": "art-2751",
          "title": "Log4Shell in a nutshell (for non-developers & non-Java developers)",
          "link": "https://snyk.io/blog/log4shell-in-a-nutshell/",
          "published": "2021-12-15",
          "sev": "high"
        },
        {
          "id": "art-2756",
          "title": "The Log4j vulnerability and its impact on software supply chain security",
          "link": "https://snyk.io/blog/log4j-vulnerability-software-supply-chain-security-log4shell/",
          "published": "2021-12-13",
          "sev": "high"
        },
        {
          "id": "art-2757",
          "title": "Find and fix the Log4Shell exploit fast with Snyk",
          "link": "https://snyk.io/blog/find-fix-log4shell-quickly-snyk/",
          "published": "2021-12-13",
          "sev": "high"
        }
      ],
      "first_seen": "2022-05-19"
    },
    {
      "value": "CVE-2022-22947",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2274",
          "title": "CISA KEV: CVE-2022-22947 \u2014 VMware Spring Cloud Gateway Code Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-05-16",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-05-16"
    },
    {
      "value": "CVE-2022-1388",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2277",
          "title": "CISA KEV: CVE-2022-1388 \u2014 F5 BIG-IP Missing Authentication Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-05-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-05-10"
    },
    {
      "value": "CVE-2014-0160",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2292",
          "title": "CISA KEV: CVE-2014-0160 \u2014 OpenSSL Information Disclosure Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-05-04",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-05-04"
    },
    {
      "value": "CVE-2014-0322",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2291",
          "title": "CISA KEV: CVE-2014-0322 \u2014 Microsoft Internet Explorer Use-After-Free Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-05-04",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-05-04"
    },
    {
      "value": "CVE-2014-4113",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2290",
          "title": "CISA KEV: CVE-2014-4113 \u2014 Microsoft Win32k Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-05-04",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-05-04"
    },
    {
      "value": "CVE-2019-8506",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2289",
          "title": "CISA KEV: CVE-2019-8506 \u2014 Apple Multiple Products Type Confusion Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-05-04",
          "sev": "crit"
        },
        {
          "id": "art-2843",
          "title": "CISA KEV: CVE-2021-30869 \u2014 Apple iOS, iPadOS, and macOS Type Confusion Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-05-04"
    },
    {
      "value": "CVE-2021-1789",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2288",
          "title": "CISA KEV: CVE-2021-1789 \u2014 Apple Multiple Products Type Confusion Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-05-04",
          "sev": "crit"
        },
        {
          "id": "art-2843",
          "title": "CISA KEV: CVE-2021-30869 \u2014 Apple iOS, iPadOS, and macOS Type Confusion Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-05-04"
    },
    {
      "value": "CVE-2021-3156",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "Snyk",
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2286",
          "title": "3\u00a0Jedi-inspired lessons to level up your JavaScript security",
          "link": "https://snyk.io/blog/jedi-lessons-to-level-up-javascript-security/",
          "published": "2022-05-04",
          "sev": "crit"
        },
        {
          "id": "art-2354",
          "title": "CISA KEV: CVE-2021-3156 \u2014 Sudo Heap-Based Buffer Overflow Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-04-06",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-05-04"
    },
    {
      "value": "CVE-2003-1564",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-2298",
          "title": "Under the C: A glance at C/C++ vulnerabilities in Python land",
          "link": "https://snyk.io/blog/under-the-c-vulnerabilities-in-python/",
          "published": "2022-04-28",
          "sev": "high"
        }
      ],
      "first_seen": "2022-04-28"
    },
    {
      "value": "CVE-2019-1003029",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2311",
          "title": "CISA KEV: CVE-2019-1003029 \u2014 Jenkins Script Security Plugin Sandbox Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-04-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-04-25"
    },
    {
      "value": "CVE-2021-40450",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2310",
          "title": "CISA KEV: CVE-2021-40450 \u2014 Microsoft Win32k Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-04-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-04-25"
    },
    {
      "value": "CVE-2021-41357",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2309",
          "title": "CISA KEV: CVE-2021-41357 \u2014 Microsoft Win32k Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-04-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-04-25"
    },
    {
      "value": "CVE-2022-0847",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV",
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-2308",
          "title": "CISA KEV: CVE-2022-0847 \u2014 Linux Kernel Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-04-25",
          "sev": "crit"
        },
        {
          "id": "art-2501",
          "title": "\"Dirty Pipe\" Linux vulnerability and your containerized applications (CVE-2022-0847)",
          "link": "https://snyk.io/blog/dirty-pipe-vulnerability-cve-2022-0847-containerized-applications/",
          "published": "2022-03-09",
          "sev": "high"
        }
      ],
      "first_seen": "2022-04-25"
    },
    {
      "value": "CVE-2022-21919",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2307",
          "title": "CISA KEV: CVE-2022-21919 \u2014 Microsoft Windows User Profile Service Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-04-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-04-25"
    },
    {
      "value": "CVE-2022-26904",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2306",
          "title": "CISA KEV: CVE-2022-26904 \u2014 Microsoft Windows User Profile Service Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-04-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-04-25"
    },
    {
      "value": "CVE-2018-6882",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2317",
          "title": "CISA KEV: CVE-2018-6882 \u2014 Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting (XSS) Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-04-19",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-04-19"
    },
    {
      "value": "CVE-2019-3568",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2318",
          "title": "CISA KEV: CVE-2019-3568 \u2014 WhatsApp VOIP Stack Buffer Overflow Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-04-19",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-04-19"
    },
    {
      "value": "CVE-2021-23682",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-2316",
          "title": "Modernizing SAST rules maintenance to catch vulnerabilities faster",
          "link": "https://snyk.io/blog/modernizing-sast-rules-maintenance-catch-vulnerabilities-faster/",
          "published": "2022-04-19",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-04-19"
    },
    {
      "value": "CVE-2022-22718",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2319",
          "title": "CISA KEV: CVE-2022-22718 \u2014 Microsoft Windows Print Spooler Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-04-19",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-04-19"
    },
    {
      "value": "CVE-2010-5330",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2328",
          "title": "CISA KEV: CVE-2010-5330 \u2014 Ubiquiti AirOS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-04-15",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-04-15"
    },
    {
      "value": "CVE-2014-0780",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2327",
          "title": "CISA KEV: CVE-2014-0780 \u2014 InduSoft Web Studio NTWebServer Directory Traversal Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-04-15",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-04-15"
    },
    {
      "value": "CVE-2016-4523",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2326",
          "title": "CISA KEV: CVE-2016-4523 \u2014 Trihedral VTScada (formerly VTS) Denial-of-Service Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-04-15",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-04-15"
    },
    {
      "value": "CVE-2018-7841",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2325",
          "title": "CISA KEV: CVE-2018-7841 \u2014 Schneider Electric U.motion Builder SQL Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-04-15",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-04-15"
    },
    {
      "value": "CVE-2019-16057",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2324",
          "title": "CISA KEV: CVE-2019-16057 \u2014 D-Link DNS-320 Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-04-15",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-04-15"
    },
    {
      "value": "CVE-2019-3929",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2323",
          "title": "CISA KEV: CVE-2019-3929 \u2014 Crestron Multiple Products Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-04-15",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-04-15"
    },
    {
      "value": "CVE-2022-1364",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2322",
          "title": "CISA KEV: CVE-2022-1364 \u2014 Google Chromium V8 Type Confusion Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-04-15",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-04-15"
    },
    {
      "value": "CVE-2022-22954",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2321",
          "title": "CISA KEV: CVE-2022-22960 \u2014 VMware Multiple Products Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-04-15",
          "sev": "crit"
        },
        {
          "id": "art-2330",
          "title": "CISA KEV: CVE-2022-22954 \u2014 VMware Workspace ONE Access and Identity Manager Server-Side Template Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-04-14",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-04-15"
    },
    {
      "value": "CVE-2022-22960",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2321",
          "title": "CISA KEV: CVE-2022-22960 \u2014 VMware Multiple Products Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-04-15",
          "sev": "crit"
        },
        {
          "id": "art-2330",
          "title": "CISA KEV: CVE-2022-22954 \u2014 VMware Workspace ONE Access and Identity Manager Server-Side Template Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-04-14",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-04-15"
    },
    {
      "value": "84.38.133.149",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2321",
          "title": "CISA KEV: CVE-2022-22960 \u2014 VMware Multiple Products Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-04-15",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-04-15"
    },
    {
      "value": "5b0bfda04a1e0d8dcb02556dc4e56e6a",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2321",
          "title": "CISA KEV: CVE-2022-22960 \u2014 VMware Multiple Products Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-04-15",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-04-15"
    },
    {
      "value": "f8ff5c72e8ffa2112b01802113148bd1",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2321",
          "title": "CISA KEV: CVE-2022-22960 \u2014 VMware Multiple Products Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-04-15",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-04-15"
    },
    {
      "value": "CVE-2002-0639",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-2320",
          "title": "An unintimidating introduction to the dark arts of C/C++ vulnerabilities",
          "link": "https://snyk.io/blog/unintimidating-intro-to-c-cpp-vulnerabilities/",
          "published": "2022-04-15",
          "sev": "high"
        }
      ],
      "first_seen": "2022-04-15"
    },
    {
      "value": "CVE-2020-9365",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-2320",
          "title": "An unintimidating introduction to the dark arts of C/C++ vulnerabilities",
          "link": "https://snyk.io/blog/unintimidating-intro-to-c-cpp-vulnerabilities/",
          "published": "2022-04-15",
          "sev": "high"
        }
      ],
      "first_seen": "2022-04-15"
    },
    {
      "value": "cnc.goodpackets.cc",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2330",
          "title": "CISA KEV: CVE-2022-22954 \u2014 VMware Workspace ONE Access and Identity Manager Server-Side Template Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-04-14",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-04-14"
    },
    {
      "value": "CVE-2014-9163",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2341",
          "title": "CISA KEV: CVE-2014-9163 \u2014 Adobe Flash Player Stack-Based Buffer Overflow Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-04-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-04-13"
    },
    {
      "value": "CVE-2015-0313",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2339",
          "title": "CISA KEV: CVE-2015-0313 \u2014 Adobe Flash Player Use-After-Free Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-04-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-04-13"
    },
    {
      "value": "CVE-2015-2502",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2338",
          "title": "CISA KEV: CVE-2015-2502 \u2014 Microsoft Internet Explorer Memory Corruption Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-04-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-04-13"
    },
    {
      "value": "CVE-2015-3113",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2337",
          "title": "CISA KEV: CVE-2015-3113 \u2014 Adobe Flash Player Heap-Based Buffer Overflow Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-04-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-04-13"
    },
    {
      "value": "CVE-2015-5122",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2336",
          "title": "CISA KEV: CVE-2015-5122 \u2014 Adobe Flash Player Use-After-Free Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-04-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-04-13"
    },
    {
      "value": "CVE-2015-5123",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2335",
          "title": "CISA KEV: CVE-2015-5123 \u2014 Adobe Flash Player Use-After-Free Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-04-13",
          "sev": "crit"
        },
        {
          "id": "art-2336",
          "title": "CISA KEV: CVE-2015-5122 \u2014 Adobe Flash Player Use-After-Free Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-04-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-04-13"
    },
    {
      "value": "CVE-2018-20753",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2334",
          "title": "CISA KEV: CVE-2018-20753 \u2014 Kaseya VSA Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-04-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-04-13"
    },
    {
      "value": "CVE-2018-7600",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2333",
          "title": "CISA KEV: CVE-2018-7602 \u2014 Drupal Core Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-04-13",
          "sev": "crit"
        },
        {
          "id": "art-2877",
          "title": "CISA KEV: CVE-2018-7600 \u2014 Drupal Core Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-04-13"
    },
    {
      "value": "CVE-2018-7602",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2333",
          "title": "CISA KEV: CVE-2018-7602 \u2014 Drupal Core Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-04-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-04-13"
    },
    {
      "value": "CVE-2022-24521",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2332",
          "title": "CISA KEV: CVE-2022-24521 \u2014 Microsoft Windows CLFS Driver Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-04-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-04-13"
    },
    {
      "value": "104.160.176.178",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2333",
          "title": "CISA KEV: CVE-2018-7602 \u2014 Drupal Core Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-04-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-04-13"
    },
    {
      "value": "142.44.240.14",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2333",
          "title": "CISA KEV: CVE-2018-7602 \u2014 Drupal Core Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-04-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-04-13"
    },
    {
      "value": "145.239.93.215",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2333",
          "title": "CISA KEV: CVE-2018-7602 \u2014 Drupal Core Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-04-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-04-13"
    },
    {
      "value": "188.166.148.89",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2333",
          "title": "CISA KEV: CVE-2018-7602 \u2014 Drupal Core Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-04-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-04-13"
    },
    {
      "value": "192.241.247.212",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2333",
          "title": "CISA KEV: CVE-2018-7602 \u2014 Drupal Core Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-04-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-04-13"
    },
    {
      "value": "195.22.126.16",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2333",
          "title": "CISA KEV: CVE-2018-7602 \u2014 Drupal Core Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-04-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-04-13"
    },
    {
      "value": "195.22.127.225",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2333",
          "title": "CISA KEV: CVE-2018-7602 \u2014 Drupal Core Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-04-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-04-13"
    },
    {
      "value": "198.50.179.109",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2333",
          "title": "CISA KEV: CVE-2018-7602 \u2014 Drupal Core Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-04-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-04-13"
    },
    {
      "value": "217.182.231.56",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2333",
          "title": "CISA KEV: CVE-2018-7602 \u2014 Drupal Core Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-04-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-04-13"
    },
    {
      "value": "93.174.93.149",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2333",
          "title": "CISA KEV: CVE-2018-7602 \u2014 Drupal Core Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-04-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-04-13"
    },
    {
      "value": "94.41.167.11",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2333",
          "title": "CISA KEV: CVE-2018-7602 \u2014 Drupal Core Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-04-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-04-13"
    },
    {
      "value": "046a9c9838269fc5f76890b141bb39d22e6b9456",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2333",
          "title": "CISA KEV: CVE-2018-7602 \u2014 Drupal Core Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-04-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-04-13"
    },
    {
      "value": "0f4a3e0c6523fe0a0677f91182a1eabc536ff480",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2333",
          "title": "CISA KEV: CVE-2018-7602 \u2014 Drupal Core Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-04-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-04-13"
    },
    {
      "value": "68efd61193fc9b70394abb2327de2bf6b1f368b7",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2333",
          "title": "CISA KEV: CVE-2018-7602 \u2014 Drupal Core Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-04-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-04-13"
    },
    {
      "value": "7602c5cbc63e1bf2e484db63c94d5a22b7e17304",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2333",
          "title": "CISA KEV: CVE-2018-7602 \u2014 Drupal Core Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-04-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-04-13"
    },
    {
      "value": "8360f0d2df9008240f1d5e0f8acdbd2c98bad58c",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2333",
          "title": "CISA KEV: CVE-2018-7602 \u2014 Drupal Core Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-04-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-04-13"
    },
    {
      "value": "8822037953274ddd9f78b49ee73185be20e5e3ef",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2333",
          "title": "CISA KEV: CVE-2018-7602 \u2014 Drupal Core Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-04-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-04-13"
    },
    {
      "value": "94c2ea3cf1cdb034df2e9aa5779fa0472396bff7",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2333",
          "title": "CISA KEV: CVE-2018-7602 \u2014 Drupal Core Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-04-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-04-13"
    },
    {
      "value": "c84dc265859d58827369eb25b752b6305b8306e7",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2333",
          "title": "CISA KEV: CVE-2018-7602 \u2014 Drupal Core Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-04-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-04-13"
    },
    {
      "value": "cb00248b8bcd91e68c08a061a91cc3317db5724b",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2333",
          "title": "CISA KEV: CVE-2018-7602 \u2014 Drupal Core Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-04-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-04-13"
    },
    {
      "value": "d7eb30269b3ba40ef59c0acef8948898fa54895f",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2333",
          "title": "CISA KEV: CVE-2018-7602 \u2014 Drupal Core Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-04-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-04-13"
    },
    {
      "value": "e6f914790b3888a46dff60f51a98c7191208685a",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2333",
          "title": "CISA KEV: CVE-2018-7602 \u2014 Drupal Core Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-04-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-04-13"
    },
    {
      "value": "e9e09b90cfdc1cd2ddb867385afa60816a7ee7d5",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2333",
          "title": "CISA KEV: CVE-2018-7602 \u2014 Drupal Core Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-04-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-04-13"
    },
    {
      "value": "f92f1b03bcc45b692716789387d837905c8d4d76",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2333",
          "title": "CISA KEV: CVE-2018-7602 \u2014 Drupal Core Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-04-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-04-13"
    },
    {
      "value": "fcdd9c19b6b134dc31b3b688002eb51cac76a3ff",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2333",
          "title": "CISA KEV: CVE-2018-7602 \u2014 Drupal Core Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-04-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-04-13"
    },
    {
      "value": "CVE-2020-2509",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2349",
          "title": "CISA KEV: CVE-2020-2509 \u2014 QNAP Network-Attached Storage (NAS) Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-04-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-04-11"
    },
    {
      "value": "CVE-2021-22600",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2348",
          "title": "CISA KEV: CVE-2021-22600 \u2014 Linux Kernel Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-04-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-04-11"
    },
    {
      "value": "CVE-2021-27852",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2347",
          "title": "CISA KEV: CVE-2021-27852 \u2014 Checkbox Survey Deserialization of Untrusted Data Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-04-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-04-11"
    },
    {
      "value": "CVE-2021-39793",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2346",
          "title": "CISA KEV: CVE-2021-39793 \u2014 Google Pixel Out-of-Bounds Write Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-04-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-04-11"
    },
    {
      "value": "CVE-2021-42278",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2344",
          "title": "CISA KEV: CVE-2021-42287 \u2014 Microsoft Active Directory Domain Services Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-04-11",
          "sev": "crit"
        },
        {
          "id": "art-2345",
          "title": "CISA KEV: CVE-2021-42278 \u2014 Microsoft Active Directory Domain Services Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-04-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-04-11"
    },
    {
      "value": "CVE-2021-42287",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2344",
          "title": "CISA KEV: CVE-2021-42287 \u2014 Microsoft Active Directory Domain Services Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-04-11",
          "sev": "crit"
        },
        {
          "id": "art-2345",
          "title": "CISA KEV: CVE-2021-42278 \u2014 Microsoft Active Directory Domain Services Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-04-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-04-11"
    },
    {
      "value": "CVE-2022-23176",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2343",
          "title": "CISA KEV: CVE-2022-23176 \u2014 WatchGuard Firebox and XTM Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-04-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-04-11"
    },
    {
      "value": "104.225.129.102",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2350",
          "title": "CISA KEV: CVE-2017-11317 \u2014 Telerik UI for ASP.NET AJAX Unrestricted File Upload Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-04-11",
          "sev": "crit"
        },
        {
          "id": "art-3012",
          "title": "CISA KEV: CVE-2019-18935 \u2014 Progress Telerik UI for ASP.NET AJAX Deserialization of Untrusted Data Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        },
        {
          "id": "art-3047",
          "title": "CISA KEV: CVE-2017-9248 \u2014 Progress Telerik UI for ASP.NET AJAX and Sitefinity Cryptographic Weakness Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-04-11"
    },
    {
      "value": "137.184.130.162",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2350",
          "title": "CISA KEV: CVE-2017-11317 \u2014 Telerik UI for ASP.NET AJAX Unrestricted File Upload Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-04-11",
          "sev": "crit"
        },
        {
          "id": "art-3012",
          "title": "CISA KEV: CVE-2019-18935 \u2014 Progress Telerik UI for ASP.NET AJAX Deserialization of Untrusted Data Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        },
        {
          "id": "art-3047",
          "title": "CISA KEV: CVE-2017-9248 \u2014 Progress Telerik UI for ASP.NET AJAX and Sitefinity Cryptographic Weakness Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-04-11"
    },
    {
      "value": "144.96.103.245",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2350",
          "title": "CISA KEV: CVE-2017-11317 \u2014 Telerik UI for ASP.NET AJAX Unrestricted File Upload Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-04-11",
          "sev": "crit"
        },
        {
          "id": "art-3012",
          "title": "CISA KEV: CVE-2019-18935 \u2014 Progress Telerik UI for ASP.NET AJAX Deserialization of Untrusted Data Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        },
        {
          "id": "art-3047",
          "title": "CISA KEV: CVE-2017-9248 \u2014 Progress Telerik UI for ASP.NET AJAX and Sitefinity Cryptographic Weakness Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-04-11"
    },
    {
      "value": "149.28.85.24",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2350",
          "title": "CISA KEV: CVE-2017-11317 \u2014 Telerik UI for ASP.NET AJAX Unrestricted File Upload Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-04-11",
          "sev": "crit"
        },
        {
          "id": "art-3012",
          "title": "CISA KEV: CVE-2019-18935 \u2014 Progress Telerik UI for ASP.NET AJAX Deserialization of Untrusted Data Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        },
        {
          "id": "art-3047",
          "title": "CISA KEV: CVE-2017-9248 \u2014 Progress Telerik UI for ASP.NET AJAX and Sitefinity Cryptographic Weakness Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-04-11"
    },
    {
      "value": "184.168.104.171",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2350",
          "title": "CISA KEV: CVE-2017-11317 \u2014 Telerik UI for ASP.NET AJAX Unrestricted File Upload Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-04-11",
          "sev": "crit"
        },
        {
          "id": "art-3012",
          "title": "CISA KEV: CVE-2019-18935 \u2014 Progress Telerik UI for ASP.NET AJAX Deserialization of Untrusted Data Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        },
        {
          "id": "art-3047",
          "title": "CISA KEV: CVE-2017-9248 \u2014 Progress Telerik UI for ASP.NET AJAX and Sitefinity Cryptographic Weakness Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-04-11"
    },
    {
      "value": "185.186.245.72",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2350",
          "title": "CISA KEV: CVE-2017-11317 \u2014 Telerik UI for ASP.NET AJAX Unrestricted File Upload Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-04-11",
          "sev": "crit"
        },
        {
          "id": "art-3012",
          "title": "CISA KEV: CVE-2019-18935 \u2014 Progress Telerik UI for ASP.NET AJAX Deserialization of Untrusted Data Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        },
        {
          "id": "art-3047",
          "title": "CISA KEV: CVE-2017-9248 \u2014 Progress Telerik UI for ASP.NET AJAX and Sitefinity Cryptographic Weakness Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-04-11"
    },
    {
      "value": "193.8.172.113",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2350",
          "title": "CISA KEV: CVE-2017-11317 \u2014 Telerik UI for ASP.NET AJAX Unrestricted File Upload Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-04-11",
          "sev": "crit"
        },
        {
          "id": "art-3012",
          "title": "CISA KEV: CVE-2019-18935 \u2014 Progress Telerik UI for ASP.NET AJAX Deserialization of Untrusted Data Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        },
        {
          "id": "art-3047",
          "title": "CISA KEV: CVE-2017-9248 \u2014 Progress Telerik UI for ASP.NET AJAX and Sitefinity Cryptographic Weakness Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-04-11"
    },
    {
      "value": "193.8.172.13",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2350",
          "title": "CISA KEV: CVE-2017-11317 \u2014 Telerik UI for ASP.NET AJAX Unrestricted File Upload Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-04-11",
          "sev": "crit"
        },
        {
          "id": "art-3012",
          "title": "CISA KEV: CVE-2019-18935 \u2014 Progress Telerik UI for ASP.NET AJAX Deserialization of Untrusted Data Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        },
        {
          "id": "art-3047",
          "title": "CISA KEV: CVE-2017-9248 \u2014 Progress Telerik UI for ASP.NET AJAX and Sitefinity Cryptographic Weakness Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-04-11"
    },
    {
      "value": "216.120.201.12",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2350",
          "title": "CISA KEV: CVE-2017-11317 \u2014 Telerik UI for ASP.NET AJAX Unrestricted File Upload Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-04-11",
          "sev": "crit"
        },
        {
          "id": "art-3012",
          "title": "CISA KEV: CVE-2019-18935 \u2014 Progress Telerik UI for ASP.NET AJAX Deserialization of Untrusted Data Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        },
        {
          "id": "art-3047",
          "title": "CISA KEV: CVE-2017-9248 \u2014 Progress Telerik UI for ASP.NET AJAX and Sitefinity Cryptographic Weakness Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-04-11"
    },
    {
      "value": "45.77.212.12",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2350",
          "title": "CISA KEV: CVE-2017-11317 \u2014 Telerik UI for ASP.NET AJAX Unrestricted File Upload Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-04-11",
          "sev": "crit"
        },
        {
          "id": "art-3012",
          "title": "CISA KEV: CVE-2019-18935 \u2014 Progress Telerik UI for ASP.NET AJAX Deserialization of Untrusted Data Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        },
        {
          "id": "art-3047",
          "title": "CISA KEV: CVE-2017-9248 \u2014 Progress Telerik UI for ASP.NET AJAX and Sitefinity Cryptographic Weakness Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-04-11"
    },
    {
      "value": "5.34.178.246",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2350",
          "title": "CISA KEV: CVE-2017-11317 \u2014 Telerik UI for ASP.NET AJAX Unrestricted File Upload Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-04-11",
          "sev": "crit"
        },
        {
          "id": "art-3012",
          "title": "CISA KEV: CVE-2019-18935 \u2014 Progress Telerik UI for ASP.NET AJAX Deserialization of Untrusted Data Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        },
        {
          "id": "art-3047",
          "title": "CISA KEV: CVE-2017-9248 \u2014 Progress Telerik UI for ASP.NET AJAX and Sitefinity Cryptographic Weakness Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-04-11"
    },
    {
      "value": "79.133.124.242",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2350",
          "title": "CISA KEV: CVE-2017-11317 \u2014 Telerik UI for ASP.NET AJAX Unrestricted File Upload Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-04-11",
          "sev": "crit"
        },
        {
          "id": "art-3012",
          "title": "CISA KEV: CVE-2019-18935 \u2014 Progress Telerik UI for ASP.NET AJAX Deserialization of Untrusted Data Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        },
        {
          "id": "art-3047",
          "title": "CISA KEV: CVE-2017-9248 \u2014 Progress Telerik UI for ASP.NET AJAX and Sitefinity Cryptographic Weakness Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-04-11"
    },
    {
      "value": "92.38.169.193",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2350",
          "title": "CISA KEV: CVE-2017-11317 \u2014 Telerik UI for ASP.NET AJAX Unrestricted File Upload Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-04-11",
          "sev": "crit"
        },
        {
          "id": "art-3012",
          "title": "CISA KEV: CVE-2019-18935 \u2014 Progress Telerik UI for ASP.NET AJAX Deserialization of Untrusted Data Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        },
        {
          "id": "art-3047",
          "title": "CISA KEV: CVE-2017-9248 \u2014 Progress Telerik UI for ASP.NET AJAX and Sitefinity Cryptographic Weakness Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-04-11"
    },
    {
      "value": "92.38.176.109",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2350",
          "title": "CISA KEV: CVE-2017-11317 \u2014 Telerik UI for ASP.NET AJAX Unrestricted File Upload Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-04-11",
          "sev": "crit"
        },
        {
          "id": "art-3012",
          "title": "CISA KEV: CVE-2019-18935 \u2014 Progress Telerik UI for ASP.NET AJAX Deserialization of Untrusted Data Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        },
        {
          "id": "art-3047",
          "title": "CISA KEV: CVE-2017-9248 \u2014 Progress Telerik UI for ASP.NET AJAX and Sitefinity Cryptographic Weakness Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-04-11"
    },
    {
      "value": "92.38.176.130",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2350",
          "title": "CISA KEV: CVE-2017-11317 \u2014 Telerik UI for ASP.NET AJAX Unrestricted File Upload Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-04-11",
          "sev": "crit"
        },
        {
          "id": "art-3012",
          "title": "CISA KEV: CVE-2019-18935 \u2014 Progress Telerik UI for ASP.NET AJAX Deserialization of Untrusted Data Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        },
        {
          "id": "art-3047",
          "title": "CISA KEV: CVE-2017-9248 \u2014 Progress Telerik UI for ASP.NET AJAX and Sitefinity Cryptographic Weakness Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-04-11"
    },
    {
      "value": "37e173b932596af62fefc4dc10c8551d",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2350",
          "title": "CISA KEV: CVE-2017-11317 \u2014 Telerik UI for ASP.NET AJAX Unrestricted File Upload Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-04-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-04-11"
    },
    {
      "value": "815d262d38a26d5695606d03d5a1a49b9c00915ead1d8a2c04eb47846100e93f",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2350",
          "title": "CISA KEV: CVE-2017-11317 \u2014 Telerik UI for ASP.NET AJAX Unrestricted File Upload Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-04-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-04-11"
    },
    {
      "value": "CVE-2010-1622",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-2351",
          "title": "Spring4Shell extends to Glassfish and Payara: same vulnerability, new exploit",
          "link": "https://snyk.io/blog/spring4shell-rce-vulnerability-glassfish-payara/",
          "published": "2022-04-08",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-04-08"
    },
    {
      "value": "CVE-2020-1914",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-2352",
          "title": "Getting started with React Native security",
          "link": "https://snyk.io/blog/getting-started-react-native-security/",
          "published": "2022-04-07",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-04-07"
    },
    {
      "value": "CVE-2017-0148",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2356",
          "title": "CISA KEV: CVE-2017-0148 \u2014 Microsoft SMBv1 Server Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-04-06",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-04-06"
    },
    {
      "value": "CVE-2021-31166",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2355",
          "title": "CISA KEV: CVE-2021-31166 \u2014 Microsoft HTTP Protocol Stack Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-04-06",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-04-06"
    },
    {
      "value": "CVE-2016-5674",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2363",
          "title": "CISA KEV: CVE-2021-45382 \u2014 D-Link Multiple Routers Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-04-04",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-04-04"
    },
    {
      "value": "CVE-2021-23514",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-2359",
          "title": "Exploring 3 types of directory traversal vulnerabilities in C/C++",
          "link": "https://snyk.io/blog/exploring-3-types-of-directory-traversal-vulnerabilities-in-c-c/",
          "published": "2022-04-04",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-04-04"
    },
    {
      "value": "CVE-2021-23520",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-2359",
          "title": "Exploring 3 types of directory traversal vulnerabilities in C/C++",
          "link": "https://snyk.io/blog/exploring-3-types-of-directory-traversal-vulnerabilities-in-c-c/",
          "published": "2022-04-04",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-04-04"
    },
    {
      "value": "CVE-2021-23521",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-2359",
          "title": "Exploring 3 types of directory traversal vulnerabilities in C/C++",
          "link": "https://snyk.io/blog/exploring-3-types-of-directory-traversal-vulnerabilities-in-c-c/",
          "published": "2022-04-04",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-04-04"
    },
    {
      "value": "CVE-2021-4045",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2363",
          "title": "CISA KEV: CVE-2021-45382 \u2014 D-Link Multiple Routers Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-04-04",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-04-04"
    },
    {
      "value": "CVE-2021-45382",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2363",
          "title": "CISA KEV: CVE-2021-45382 \u2014 D-Link Multiple Routers Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-04-04",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-04-04"
    },
    {
      "value": "CVE-2022-22674",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2362",
          "title": "CISA KEV: CVE-2022-22674 \u2014 Apple macOS Out-of-Bounds Read Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-04-04",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-04-04"
    },
    {
      "value": "CVE-2022-22675",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2361",
          "title": "CISA KEV: CVE-2022-22675 \u2014 Apple macOS Out-of-Bounds Write Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-04-04",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-04-04"
    },
    {
      "value": "CVE-2022-25299",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-2359",
          "title": "Exploring 3 types of directory traversal vulnerabilities in C/C++",
          "link": "https://snyk.io/blog/exploring-3-types-of-directory-traversal-vulnerabilities-in-c-c/",
          "published": "2022-04-04",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-04-04"
    },
    {
      "value": "test6.ggdd.co.uk",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV",
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-2360",
          "title": "CISA KEV: CVE-2022-22965 \u2014 Spring Framework JDK 9+ Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-04-04",
          "sev": "crit"
        },
        {
          "id": "art-2368",
          "title": "Spring4Shell: What we know about the Java RCE vulnerability",
          "link": "https://snyk.io/blog/is-there-such-a-thing-as-spring4shell/",
          "published": "2022-03-31",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-04-04"
    },
    {
      "value": "107.174.133.167",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV",
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-2360",
          "title": "CISA KEV: CVE-2022-22965 \u2014 Spring Framework JDK 9+ Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-04-04",
          "sev": "crit"
        },
        {
          "id": "art-2368",
          "title": "Spring4Shell: What we know about the Java RCE vulnerability",
          "link": "https://snyk.io/blog/is-there-such-a-thing-as-spring4shell/",
          "published": "2022-03-31",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-04-04"
    },
    {
      "value": "194.31.98.186",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV",
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-2360",
          "title": "CISA KEV: CVE-2022-22965 \u2014 Spring Framework JDK 9+ Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-04-04",
          "sev": "crit"
        },
        {
          "id": "art-2368",
          "title": "Spring4Shell: What we know about the Java RCE vulnerability",
          "link": "https://snyk.io/blog/is-there-such-a-thing-as-spring4shell/",
          "published": "2022-03-31",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-04-04"
    },
    {
      "value": "CVE-2021-21551",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2373",
          "title": "CISA KEV: CVE-2021-21551 \u2014 Dell dbutil Driver Insufficient Access Control Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-31",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-31"
    },
    {
      "value": "CVE-2021-28799",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2372",
          "title": "CISA KEV: CVE-2021-28799 \u2014 QNAP NAS Improper Authorization Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-31",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-31"
    },
    {
      "value": "CVE-2021-34484",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2371",
          "title": "CISA KEV: CVE-2021-34484 \u2014 Microsoft Windows User Profile Service Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-31",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-31"
    },
    {
      "value": "CVE-2022-1040",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2370",
          "title": "CISA KEV: CVE-2022-1040 \u2014 Sophos Firewall Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-31",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-31"
    },
    {
      "value": "CVE-2022-26871",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2369",
          "title": "CISA KEV: CVE-2022-26871 \u2014 Trend Micro Apex Central Arbitrary File Upload Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-31",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-31"
    },
    {
      "value": "109.74.204.123",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-2368",
          "title": "Spring4Shell: What we know about the Java RCE vulnerability",
          "link": "https://snyk.io/blog/is-there-such-a-thing-as-spring4shell/",
          "published": "2022-03-31",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-31"
    },
    {
      "value": "118.70.80.143",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2374",
          "title": "CISA KEV: CVE-2018-10562 \u2014 Dasan GPON Routers Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-31",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-31"
    },
    {
      "value": "149.28.96.126",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2374",
          "title": "CISA KEV: CVE-2018-10562 \u2014 Dasan GPON Routers Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-31",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-31"
    },
    {
      "value": "172.104.159.48",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-2368",
          "title": "Spring4Shell: What we know about the Java RCE vulnerability",
          "link": "https://snyk.io/blog/is-there-such-a-thing-as-spring4shell/",
          "published": "2022-03-31",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-31"
    },
    {
      "value": "178.79.148.229",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-2368",
          "title": "Spring4Shell: What we know about the Java RCE vulnerability",
          "link": "https://snyk.io/blog/is-there-such-a-thing-as-spring4shell/",
          "published": "2022-03-31",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-31"
    },
    {
      "value": "185.246.152.173",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2374",
          "title": "CISA KEV: CVE-2018-10562 \u2014 Dasan GPON Routers Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-31",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-31"
    },
    {
      "value": "210.245.26.180",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2374",
          "title": "CISA KEV: CVE-2018-10562 \u2014 Dasan GPON Routers Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-31",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-31"
    },
    {
      "value": "46.243.189.102",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2374",
          "title": "CISA KEV: CVE-2018-10562 \u2014 Dasan GPON Routers Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-31",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-31"
    },
    {
      "value": "46.243.189.60",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2374",
          "title": "CISA KEV: CVE-2018-10562 \u2014 Dasan GPON Routers Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-31",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-31"
    },
    {
      "value": "5.253.204.37",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-2368",
          "title": "Spring4Shell: What we know about the Java RCE vulnerability",
          "link": "https://snyk.io/blog/is-there-such-a-thing-as-spring4shell/",
          "published": "2022-03-31",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-31"
    },
    {
      "value": "51.15.106.135",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2374",
          "title": "CISA KEV: CVE-2018-10562 \u2014 Dasan GPON Routers Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-31",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-31"
    },
    {
      "value": "82.165.137.177",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-2368",
          "title": "Spring4Shell: What we know about the Java RCE vulnerability",
          "link": "https://snyk.io/blog/is-there-such-a-thing-as-spring4shell/",
          "published": "2022-03-31",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-31"
    },
    {
      "value": "084bd27e151fef55b5d80025c3114d35",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2373",
          "title": "CISA KEV: CVE-2021-21551 \u2014 Dell dbutil Driver Insufficient Access Control Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-31",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-31"
    },
    {
      "value": "8cca32fb1fe4826007b087b4aee20941",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2374",
          "title": "CISA KEV: CVE-2018-10562 \u2014 Dasan GPON Routers Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-31",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-31"
    },
    {
      "value": "8e2c6a92a024f8b8bb3c086b86fa50f9",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2374",
          "title": "CISA KEV: CVE-2018-10562 \u2014 Dasan GPON Routers Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-31",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-31"
    },
    {
      "value": "c6dc9f7cf09a267fefe53c5c481e7ea0",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2374",
          "title": "CISA KEV: CVE-2018-10562 \u2014 Dasan GPON Routers Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-31",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-31"
    },
    {
      "value": "c996d7971c49252c582171d9380360f2",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2373",
          "title": "CISA KEV: CVE-2021-21551 \u2014 Dell dbutil Driver Insufficient Access Control Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-31",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-31"
    },
    {
      "value": "d2fd132ab7bbc6bbb87a84f026fa0244",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2373",
          "title": "CISA KEV: CVE-2021-21551 \u2014 Dell dbutil Driver Insufficient Access Control Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-31",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-31"
    },
    {
      "value": "e06e1e7993ea310ce0fba9dd76cdf377",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2374",
          "title": "CISA KEV: CVE-2018-10562 \u2014 Dasan GPON Routers Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-31",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-31"
    },
    {
      "value": "ed1306e24196533553571d5433312a2d",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2374",
          "title": "CISA KEV: CVE-2018-10562 \u2014 Dasan GPON Routers Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-31",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-31"
    },
    {
      "value": "10b30bdee43b3a2ec4aa63375577ade650269d25",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2373",
          "title": "CISA KEV: CVE-2021-21551 \u2014 Dell dbutil Driver Insufficient Access Control Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-31",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-31"
    },
    {
      "value": "c6920171fa6dff2c17eb83befb5fd28e8dddf5f0",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2373",
          "title": "CISA KEV: CVE-2021-21551 \u2014 Dell dbutil Driver Insufficient Access Control Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-31",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-31"
    },
    {
      "value": "c948ae14761095e4d76b55d9de86412258be7afd",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2373",
          "title": "CISA KEV: CVE-2021-21551 \u2014 Dell dbutil Driver Insufficient Access Control Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-31",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-31"
    },
    {
      "value": "0296e2ce999e67c76352613a718e11516fe1b0efc3ffdb8918fc999dd76a73a5",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2373",
          "title": "CISA KEV: CVE-2021-21551 \u2014 Dell dbutil Driver Insufficient Access Control Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-31",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-31"
    },
    {
      "value": "87e38e7aeaaaa96efe1a74f59fca8371de93544b7af22862eb0e574cec49c7c3",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2373",
          "title": "CISA KEV: CVE-2021-21551 \u2014 Dell dbutil Driver Insufficient Access Control Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-31",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-31"
    },
    {
      "value": "ddbf5ecca5c8086afde1fb4f551e9e6400e94f4428fe7fb5559da5cffa654cc1",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2373",
          "title": "CISA KEV: CVE-2021-21551 \u2014 Dell dbutil Driver Insufficient Access Control Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-31",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-31"
    },
    {
      "value": "CVE-2014-2570",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-2375",
          "title": "Using the Snyk Vulnerability Database to find projects for The Big Fix",
          "link": "https://snyk.io/blog/the-big-fix-snyk-vulnerability-database/",
          "published": "2022-03-30",
          "sev": "high"
        },
        {
          "id": "art-2635",
          "title": "Using the Snyk Vulnerability database to identify projects for The Big Fix",
          "link": "https://snyk.io/blog/using-the-snyk-vulnerability-database-to-identify-projects-for-the-big-fix/",
          "published": "2022-02-16",
          "sev": "high"
        }
      ],
      "first_seen": "2022-03-30"
    },
    {
      "value": "CVE-2010-4398",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2409",
          "title": "CISA KEV: CVE-2010-4398 \u2014 Microsoft Windows Kernel Stack-Based Buffer Overflow Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-28",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-28"
    },
    {
      "value": "CVE-2011-2005",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2408",
          "title": "CISA KEV: CVE-2011-2005 \u2014 Microsoft Ancillary Function Driver (afd.sys) Improper Input Validation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-28",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-28"
    },
    {
      "value": "CVE-2012-0518",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2407",
          "title": "CISA KEV: CVE-2012-0518 \u2014 Oracle Fusion Middleware Unspecified Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-28",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-28"
    },
    {
      "value": "CVE-2012-2034",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2406",
          "title": "CISA KEV: CVE-2012-2034 \u2014 Adobe Flash Player Memory Corruption Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-28",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-28"
    },
    {
      "value": "CVE-2012-2539",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2405",
          "title": "CISA KEV: CVE-2012-2539 \u2014 Microsoft Word Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-28",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-28"
    },
    {
      "value": "CVE-2012-5076",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2404",
          "title": "CISA KEV: CVE-2012-5076 \u2014 Oracle Java SE Sandbox Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-28",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-28"
    },
    {
      "value": "CVE-2013-1690",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2403",
          "title": "CISA KEV: CVE-2013-1690 \u2014 Mozilla Firefox and Thunderbird Denial-of-Service Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-28",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-28"
    },
    {
      "value": "CVE-2013-2465",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2402",
          "title": "CISA KEV: CVE-2013-2465 \u2014 Oracle Java SE Unspecified Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-28",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-28"
    },
    {
      "value": "CVE-2013-2551",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2401",
          "title": "CISA KEV: CVE-2013-2551 \u2014 Microsoft Internet Explorer Use-After-Free Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-28",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-28"
    },
    {
      "value": "CVE-2013-2729",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2400",
          "title": "CISA KEV: CVE-2013-2729 \u2014 Adobe Reader and Acrobat Arbitrary Integer Overflow Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-28",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-28"
    },
    {
      "value": "CVE-2013-3660",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2399",
          "title": "CISA KEV: CVE-2013-3660 \u2014 Microsoft Win32k Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-28",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-28"
    },
    {
      "value": "CVE-2015-1770",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2398",
          "title": "CISA KEV: CVE-2015-1770 \u2014 Microsoft Office Uninitialized Memory Use Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-28",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-28"
    },
    {
      "value": "CVE-2015-2419",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2397",
          "title": "CISA KEV: CVE-2015-2419 \u2014 Microsoft Internet Explorer Memory Corruption Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-28",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-28"
    },
    {
      "value": "CVE-2015-2426",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2396",
          "title": "CISA KEV: CVE-2015-2426 \u2014 Microsoft Windows Adobe Type Manager Library Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-28",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-28"
    },
    {
      "value": "CVE-2016-0040",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2395",
          "title": "CISA KEV: CVE-2016-0040 \u2014 Microsoft Windows Kernel Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-28",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-28"
    },
    {
      "value": "CVE-2016-0151",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2394",
          "title": "CISA KEV: CVE-2016-0151 \u2014 Microsoft Windows CSRSS Security Feature Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-28",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-28"
    },
    {
      "value": "CVE-2016-7200",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2391",
          "title": "CISA KEV: CVE-2016-7201 \u2014 Microsoft Edge Memory Corruption Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-28",
          "sev": "crit"
        },
        {
          "id": "art-2392",
          "title": "CISA KEV: CVE-2016-7200 \u2014 Microsoft Edge Memory Corruption Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-28",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-28"
    },
    {
      "value": "CVE-2016-7201",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2391",
          "title": "CISA KEV: CVE-2016-7201 \u2014 Microsoft Edge Memory Corruption Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-28",
          "sev": "crit"
        },
        {
          "id": "art-2392",
          "title": "CISA KEV: CVE-2016-7200 \u2014 Microsoft Edge Memory Corruption Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-28",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-28"
    },
    {
      "value": "CVE-2017-0037",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2390",
          "title": "CISA KEV: CVE-2017-0037 \u2014 Microsoft Edge and Internet Explorer Type Confusion Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-28",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-28"
    },
    {
      "value": "CVE-2017-0059",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2389",
          "title": "CISA KEV: CVE-2017-0059 \u2014 Microsoft Internet Explorer Information Disclosure Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-28",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-28"
    },
    {
      "value": "CVE-2017-0213",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2388",
          "title": "CISA KEV: CVE-2017-0213 \u2014 Microsoft Windows Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-28",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-28"
    },
    {
      "value": "CVE-2018-8405",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2387",
          "title": "CISA KEV: CVE-2018-8405 \u2014 Microsoft DirectX Graphics Kernel Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-28",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-28"
    },
    {
      "value": "CVE-2018-8406",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2386",
          "title": "CISA KEV: CVE-2018-8406 \u2014 Microsoft DirectX Graphics Kernel Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-28",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-28"
    },
    {
      "value": "CVE-2018-8440",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2385",
          "title": "CISA KEV: CVE-2018-8440 \u2014 Microsoft Windows Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-28",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-28"
    },
    {
      "value": "CVE-2019-7483",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2384",
          "title": "CISA KEV: CVE-2019-7483 \u2014 SonicWall SMA100 Directory Traversal Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-28",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-28"
    },
    {
      "value": "CVE-2021-20028",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2383",
          "title": "CISA KEV: CVE-2021-20028 \u2014 SonicWall Secure Remote Access (SRA) SQL Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-28",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-28"
    },
    {
      "value": "CVE-2021-26085",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2382",
          "title": "CISA KEV: CVE-2021-26085 \u2014 Atlassian Confluence Server Pre-Authorization Arbitrary File Read Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-28",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-28"
    },
    {
      "value": "CVE-2021-34486",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2381",
          "title": "CISA KEV: CVE-2021-34486 \u2014 Microsoft Windows Event Tracing Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-28",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-28"
    },
    {
      "value": "CVE-2021-38646",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2380",
          "title": "CISA KEV: CVE-2021-38646 \u2014 Microsoft Office Access Connectivity Engine Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-28",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-28"
    },
    {
      "value": "CVE-2022-0543",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2379",
          "title": "CISA KEV: CVE-2022-0543 \u2014 Debian-specific Redis Server Lua Sandbox Escape Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-28",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-28"
    },
    {
      "value": "CVE-2022-1096",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2378",
          "title": "CISA KEV: CVE-2022-1096 \u2014 Google Chromium V8 Type Confusion Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-28",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-28"
    },
    {
      "value": "buyyou.org",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2391",
          "title": "CISA KEV: CVE-2016-7201 \u2014 Microsoft Edge Memory Corruption Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-28",
          "sev": "crit"
        },
        {
          "id": "art-2392",
          "title": "CISA KEV: CVE-2016-7200 \u2014 Microsoft Edge Memory Corruption Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-28",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-28"
    },
    {
      "value": "fastfuriedts.org",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2391",
          "title": "CISA KEV: CVE-2016-7201 \u2014 Microsoft Edge Memory Corruption Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-28",
          "sev": "crit"
        },
        {
          "id": "art-2392",
          "title": "CISA KEV: CVE-2016-7200 \u2014 Microsoft Edge Memory Corruption Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-28",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-28"
    },
    {
      "value": "felixesedit.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2391",
          "title": "CISA KEV: CVE-2016-7201 \u2014 Microsoft Edge Memory Corruption Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-28",
          "sev": "crit"
        },
        {
          "id": "art-2392",
          "title": "CISA KEV: CVE-2016-7200 \u2014 Microsoft Edge Memory Corruption Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-28",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-28"
    },
    {
      "value": "monobrosexeld.org",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2391",
          "title": "CISA KEV: CVE-2016-7201 \u2014 Microsoft Edge Memory Corruption Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-28",
          "sev": "crit"
        },
        {
          "id": "art-2392",
          "title": "CISA KEV: CVE-2016-7200 \u2014 Microsoft Edge Memory Corruption Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-28",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-28"
    },
    {
      "value": "reveild.space",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2392",
          "title": "CISA KEV: CVE-2016-7200 \u2014 Microsoft Edge Memory Corruption Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-28",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-28"
    },
    {
      "value": "reveiled.space",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2391",
          "title": "CISA KEV: CVE-2016-7201 \u2014 Microsoft Edge Memory Corruption Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-28",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-28"
    },
    {
      "value": "vfwdgpx.amentionq.win",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2391",
          "title": "CISA KEV: CVE-2016-7201 \u2014 Microsoft Edge Memory Corruption Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-28",
          "sev": "crit"
        },
        {
          "id": "art-2392",
          "title": "CISA KEV: CVE-2016-7200 \u2014 Microsoft Edge Memory Corruption Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-28",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-28"
    },
    {
      "value": "106.246.224.219",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2379",
          "title": "CISA KEV: CVE-2022-0543 \u2014 Debian-specific Redis Server Lua Sandbox Escape Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-28",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-28"
    },
    {
      "value": "149.56.115.166",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2391",
          "title": "CISA KEV: CVE-2016-7201 \u2014 Microsoft Edge Memory Corruption Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-28",
          "sev": "crit"
        },
        {
          "id": "art-2392",
          "title": "CISA KEV: CVE-2016-7200 \u2014 Microsoft Edge Memory Corruption Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-28",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-28"
    },
    {
      "value": "204.44.118.228",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2391",
          "title": "CISA KEV: CVE-2016-7201 \u2014 Microsoft Edge Memory Corruption Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-28",
          "sev": "crit"
        },
        {
          "id": "art-2392",
          "title": "CISA KEV: CVE-2016-7200 \u2014 Microsoft Edge Memory Corruption Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-28",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-28"
    },
    {
      "value": "45.32.113.97",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2391",
          "title": "CISA KEV: CVE-2016-7201 \u2014 Microsoft Edge Memory Corruption Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-28",
          "sev": "crit"
        },
        {
          "id": "art-2392",
          "title": "CISA KEV: CVE-2016-7200 \u2014 Microsoft Edge Memory Corruption Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-28",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-28"
    },
    {
      "value": "67.198.186.254",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2391",
          "title": "CISA KEV: CVE-2016-7201 \u2014 Microsoft Edge Memory Corruption Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-28",
          "sev": "crit"
        },
        {
          "id": "art-2392",
          "title": "CISA KEV: CVE-2016-7200 \u2014 Microsoft Edge Memory Corruption Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-28",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-28"
    },
    {
      "value": "1232980a2bffc5423f50dab4453b8363412acb55",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2402",
          "title": "CISA KEV: CVE-2013-2465 \u2014 Oracle Java SE Unspecified Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-28",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-28"
    },
    {
      "value": "2c353782b7fe6280f73e3ff5d01b1f7ccfdfc0ee",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2402",
          "title": "CISA KEV: CVE-2013-2465 \u2014 Oracle Java SE Unspecified Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-28",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-28"
    },
    {
      "value": "2d35aebfa9772562bd2757e7b50da9ad68227767",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2402",
          "title": "CISA KEV: CVE-2013-2465 \u2014 Oracle Java SE Unspecified Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-28",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-28"
    },
    {
      "value": "31cb898d1f9daa95d0e04626adae283471d7c7b8",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2402",
          "title": "CISA KEV: CVE-2013-2465 \u2014 Oracle Java SE Unspecified Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-28",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-28"
    },
    {
      "value": "4787f4e7ba4d16cf569c41c77d55fde806f90cba",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2402",
          "title": "CISA KEV: CVE-2013-2465 \u2014 Oracle Java SE Unspecified Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-28",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-28"
    },
    {
      "value": "65ec5926aa212cf9bf65154772df8ffbe1530bea",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2402",
          "title": "CISA KEV: CVE-2013-2465 \u2014 Oracle Java SE Unspecified Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-28",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-28"
    },
    {
      "value": "eb45fa565a33aeb01b65eda72918f90f5fa90838",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2402",
          "title": "CISA KEV: CVE-2013-2465 \u2014 Oracle Java SE Unspecified Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-28",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-28"
    },
    {
      "value": "6c919213b5318cdb60d67a4b4ace709dfb7e544982c0e101c8526eff067c8332",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2391",
          "title": "CISA KEV: CVE-2016-7201 \u2014 Microsoft Edge Memory Corruption Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-28",
          "sev": "crit"
        },
        {
          "id": "art-2392",
          "title": "CISA KEV: CVE-2016-7200 \u2014 Microsoft Edge Memory Corruption Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-28",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-28"
    },
    {
      "value": "b5567655caabb75af68f6ea33c7a22dbc1a6006ca427da6be0066c093f592610",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2391",
          "title": "CISA KEV: CVE-2016-7201 \u2014 Microsoft Edge Memory Corruption Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-28",
          "sev": "crit"
        },
        {
          "id": "art-2392",
          "title": "CISA KEV: CVE-2016-7200 \u2014 Microsoft Edge Memory Corruption Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-28",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-28"
    },
    {
      "value": "CVE-2005-2773",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2475",
          "title": "CISA KEV: CVE-2005-2773 \u2014 HP OpenView Network Node Manager Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-25"
    },
    {
      "value": "CVE-2009-0927",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2474",
          "title": "CISA KEV: CVE-2009-0927 \u2014 Adobe Reader and Adobe Acrobat Stack-Based Buffer Overflow Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-25"
    },
    {
      "value": "CVE-2009-1151",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2473",
          "title": "CISA KEV: CVE-2009-1151 \u2014 phpMyAdmin Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-25"
    },
    {
      "value": "CVE-2009-2055",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2472",
          "title": "CISA KEV: CVE-2009-2055 \u2014 Cisco IOS XR Border Gateway Protocol (BGP) Denial-of-Service Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-25"
    },
    {
      "value": "CVE-2009-3960",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2471",
          "title": "CISA KEV: CVE-2010-2861 \u2014 Adobe ColdFusion Directory Traversal Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-25",
          "sev": "crit"
        },
        {
          "id": "art-2518",
          "title": "CISA KEV: CVE-2009-3960 \u2014 Adobe BlazeDS Information Disclosure Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-07",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-25"
    },
    {
      "value": "CVE-2010-2861",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2471",
          "title": "CISA KEV: CVE-2010-2861 \u2014 Adobe ColdFusion Directory Traversal Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-25"
    },
    {
      "value": "CVE-2010-3035",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2470",
          "title": "CISA KEV: CVE-2010-3035 \u2014 Cisco IOS XR Border Gateway Protocol (BGP) Denial-of-Service Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-25"
    },
    {
      "value": "CVE-2010-4344",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2469",
          "title": "CISA KEV: CVE-2010-4344 \u2014 Exim Heap-Based Buffer Overflow Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-25"
    },
    {
      "value": "CVE-2010-4345",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2468",
          "title": "CISA KEV: CVE-2010-4345 \u2014 Exim Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-25"
    },
    {
      "value": "CVE-2013-2251",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2466",
          "title": "CISA KEV: CVE-2013-2251 \u2014 Apache Struts Improper Input Validation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-25"
    },
    {
      "value": "CVE-2013-4810",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2465",
          "title": "CISA KEV: CVE-2013-4810 \u2014 HP Multiple Products Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-25"
    },
    {
      "value": "CVE-2013-5223",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2464",
          "title": "CISA KEV: CVE-2013-5223 \u2014 D-Link DSL-2760U Gateway Cross-Site Scripting Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-25"
    },
    {
      "value": "CVE-2014-0130",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2463",
          "title": "CISA KEV: CVE-2014-0130 \u2014 Ruby on Rails Directory Traversal Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-25"
    },
    {
      "value": "CVE-2014-3120",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2462",
          "title": "CISA KEV: CVE-2014-3120 \u2014 Elasticsearch Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-25"
    },
    {
      "value": "CVE-2014-6287",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2461",
          "title": "CISA KEV: CVE-2014-6287 \u2014 Rejetto HTTP File Server (HFS) Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-25"
    },
    {
      "value": "CVE-2014-6324",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2460",
          "title": "CISA KEV: CVE-2014-6324 \u2014 Microsoft Kerberos Key Distribution Center (KDC) Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-25"
    },
    {
      "value": "CVE-2014-6332",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2459",
          "title": "CISA KEV: CVE-2014-6332 \u2014 Microsoft Windows Object Linking & Embedding (OLE) Automation Array Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-25"
    },
    {
      "value": "CVE-2015-0666",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2458",
          "title": "CISA KEV: CVE-2015-0666 \u2014 Cisco Prime Data Center Network Manager (DCNM) Directory Traversal Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-25"
    },
    {
      "value": "CVE-2015-1187",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2457",
          "title": "CISA KEV: CVE-2015-1187 \u2014 D-Link and TRENDnet Multiple Devices Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-25"
    },
    {
      "value": "CVE-2015-1427",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2456",
          "title": "CISA KEV: CVE-2015-1427 \u2014 Elasticsearch Groovy Scripting Engine Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-25"
    },
    {
      "value": "CVE-2015-3035",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2455",
          "title": "CISA KEV: CVE-2015-3035 \u2014 TP-Link Multiple Archer Devices Directory Traversal Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-25"
    },
    {
      "value": "CVE-2015-4068",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2454",
          "title": "CISA KEV: CVE-2015-4068 \u2014 Arcserve Unified Data Protection (UDP) Directory Traversal Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-25"
    },
    {
      "value": "CVE-2016-0752",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2453",
          "title": "CISA KEV: CVE-2016-0752 \u2014 Ruby on Rails Directory Traversal Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-25"
    },
    {
      "value": "CVE-2016-10174",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2452",
          "title": "CISA KEV: CVE-2016-10174 \u2014 NETGEAR WNR2000v5 Router Buffer Overflow Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-25"
    },
    {
      "value": "CVE-2016-11021",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2451",
          "title": "CISA KEV: CVE-2016-11021 \u2014 D-Link DCS-930L Devices OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-25"
    },
    {
      "value": "CVE-2016-1555",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2450",
          "title": "CISA KEV: CVE-2016-1555 \u2014 NETGEAR Multiple WAP Devices Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-25"
    },
    {
      "value": "CVE-2016-4171",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2449",
          "title": "CISA KEV: CVE-2016-4171 \u2014 Adobe Flash Player Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-25"
    },
    {
      "value": "CVE-2016-7892",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2448",
          "title": "CISA KEV: CVE-2016-7892 \u2014 Adobe Flash Player Use-After-Free Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-25"
    },
    {
      "value": "CVE-2017-0146",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2447",
          "title": "CISA KEV: CVE-2017-0146 \u2014 Microsoft Windows SMB Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-25"
    },
    {
      "value": "CVE-2017-12615",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2446",
          "title": "CISA KEV: CVE-2017-12615 \u2014 Apache Tomcat on Windows Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-25"
    },
    {
      "value": "CVE-2017-12617",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2445",
          "title": "CISA KEV: CVE-2017-12617 \u2014 Apache Tomcat Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-25",
          "sev": "crit"
        },
        {
          "id": "art-2446",
          "title": "CISA KEV: CVE-2017-12615 \u2014 Apache Tomcat on Windows Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-25"
    },
    {
      "value": "CVE-2017-6316",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2443",
          "title": "CISA KEV: CVE-2017-6316 \u2014 Citrix Multiple Products Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-25"
    },
    {
      "value": "CVE-2017-6334",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2442",
          "title": "CISA KEV: CVE-2017-6334 \u2014 NETGEAR DGN2200 Devices OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-25"
    },
    {
      "value": "CVE-2018-0125",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2441",
          "title": "CISA KEV: CVE-2018-0125 \u2014 Cisco VPN Routers Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-25"
    },
    {
      "value": "CVE-2018-0147",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2440",
          "title": "CISA KEV: CVE-2018-0147 \u2014 Cisco Secure Access Control System Java Deserialization Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-25"
    },
    {
      "value": "CVE-2018-11138",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2439",
          "title": "CISA KEV: CVE-2018-11138 \u2014 Quest KACE System Management Appliance Remote Command Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-25"
    },
    {
      "value": "CVE-2018-1273",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2438",
          "title": "CISA KEV: CVE-2018-1273 \u2014 VMware Tanzu Spring Data Commons Property Binder Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-25"
    },
    {
      "value": "CVE-2018-14839",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2437",
          "title": "CISA KEV: CVE-2018-14839 \u2014 LG N1A1 NAS Remote Command Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-25"
    },
    {
      "value": "CVE-2018-6961",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2436",
          "title": "CISA KEV: CVE-2018-6961 \u2014 VMware SD-WAN Edge by VeloCloud Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-25"
    },
    {
      "value": "CVE-2018-8174",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2435",
          "title": "CISA KEV: CVE-2018-8373 \u2014 Microsoft Scripting Engine Memory Corruption Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-25",
          "sev": "crit"
        },
        {
          "id": "art-2642",
          "title": "CISA KEV: CVE-2018-8174 \u2014 Microsoft Windows VBScript Engine Out-of-Bounds Write Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-02-15",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-25"
    },
    {
      "value": "CVE-2018-8373",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2435",
          "title": "CISA KEV: CVE-2018-8373 \u2014 Microsoft Scripting Engine Memory Corruption Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-25"
    },
    {
      "value": "CVE-2018-8414",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2434",
          "title": "CISA KEV: CVE-2018-8414 \u2014 Microsoft Windows Shell Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-25",
          "sev": "crit"
        },
        {
          "id": "art-2447",
          "title": "CISA KEV: CVE-2017-0146 \u2014 Microsoft Windows SMB Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-25"
    },
    {
      "value": "CVE-2019-0903",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2433",
          "title": "CISA KEV: CVE-2019-0903 \u2014 Microsoft GDI Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-25"
    },
    {
      "value": "CVE-2019-1003030",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2432",
          "title": "CISA KEV: CVE-2019-1003030 \u2014 Jenkins Matrix Project Plugin Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-25"
    },
    {
      "value": "CVE-2019-10068",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2431",
          "title": "CISA KEV: CVE-2019-10068 \u2014 Kentico Xperience Deserialization of Untrusted Data Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-25"
    },
    {
      "value": "CVE-2019-11043",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2430",
          "title": "CISA KEV: CVE-2019-11043 \u2014 PHP FastCGI Process Manager (FPM) Buffer Overflow Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-25"
    },
    {
      "value": "CVE-2019-12989",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2429",
          "title": "CISA KEV: CVE-2019-12989 \u2014 Citrix SD-WAN and NetScaler SQL Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-25"
    },
    {
      "value": "CVE-2019-12991",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2428",
          "title": "CISA KEV: CVE-2019-12991 \u2014 Citrix SD-WAN and NetScaler Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-25"
    },
    {
      "value": "CVE-2019-15107",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2427",
          "title": "CISA KEV: CVE-2019-15107 \u2014 Webmin Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-25"
    },
    {
      "value": "CVE-2019-16920",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2426",
          "title": "CISA KEV: CVE-2019-16920 \u2014 D-Link Multiple Routers Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-25"
    },
    {
      "value": "CVE-2019-2616",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2425",
          "title": "CISA KEV: CVE-2019-2616 \u2014 Oracle BI Publisher Unauthorized Access Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-25"
    },
    {
      "value": "CVE-2019-6340",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2424",
          "title": "CISA KEV: CVE-2019-6340 \u2014 Drupal Core Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-25",
          "sev": "crit"
        },
        {
          "id": "art-2433",
          "title": "CISA KEV: CVE-2019-0903 \u2014 Microsoft GDI Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-25"
    },
    {
      "value": "CVE-2020-1631",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2423",
          "title": "CISA KEV: CVE-2020-1631 \u2014 Juniper Junos OS Path Traversal Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-25"
    },
    {
      "value": "CVE-2020-1956",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2422",
          "title": "CISA KEV: CVE-2020-1956 \u2014 Apache Kylin OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-25"
    },
    {
      "value": "CVE-2020-2021",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2421",
          "title": "CISA KEV: CVE-2020-2021 \u2014 Palo Alto Networks PAN-OS Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-25"
    },
    {
      "value": "CVE-2020-2506",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2420",
          "title": "CISA KEV: CVE-2020-2506 \u2014 QNAP Helpdesk Improper Access Control Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-25"
    },
    {
      "value": "CVE-2020-25223",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2419",
          "title": "CISA KEV: CVE-2020-25223 \u2014 Sophos SG UTM Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-25"
    },
    {
      "value": "CVE-2020-5410",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2418",
          "title": "CISA KEV: CVE-2020-5410 \u2014 VMware Tanzu Spring Cloud Config Directory Traversal Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-25"
    },
    {
      "value": "CVE-2020-7247",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2417",
          "title": "CISA KEV: CVE-2020-7247 \u2014 OpenSMTPD Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-25"
    },
    {
      "value": "CVE-2020-9054",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2416",
          "title": "CISA KEV: CVE-2020-9054 \u2014 Zyxel Multiple NAS Devices OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-25"
    },
    {
      "value": "CVE-2020-9377",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2415",
          "title": "CISA KEV: CVE-2020-9377 \u2014 D-Link DIR-610 Devices Remote Command Execution",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-25"
    },
    {
      "value": "CVE-2021-22941",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2414",
          "title": "CISA KEV: CVE-2021-22941 \u2014 Citrix ShareFile Improper Access Control Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-25"
    },
    {
      "value": "CVE-2021-42237",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2413",
          "title": "CISA KEV: CVE-2021-42237 \u2014 Sitecore XP Remote Command Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-25"
    },
    {
      "value": "CVE-2022-21999",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2412",
          "title": "CISA KEV: CVE-2022-21999 \u2014 Microsoft Windows Print Spooler Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-25"
    },
    {
      "value": "CVE-2022-26143",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2411",
          "title": "CISA KEV: CVE-2022-26143 \u2014 MiCollab, MiVoice Business Express Access Control Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-25"
    },
    {
      "value": "CVE-2022-26318",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2410",
          "title": "CISA KEV: CVE-2022-26318 \u2014 WatchGuard Firebox and XTM Appliances Arbitrary Code Execution",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-25"
    },
    {
      "value": "windows-updater.net",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2435",
          "title": "CISA KEV: CVE-2018-8373 \u2014 Microsoft Scripting Engine Memory Corruption Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-25"
    },
    {
      "value": "107.181.187.184",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2414",
          "title": "CISA KEV: CVE-2021-22941 \u2014 Citrix ShareFile Improper Access Control Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-25"
    },
    {
      "value": "188.119.149.160",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2414",
          "title": "CISA KEV: CVE-2021-22941 \u2014 Citrix ShareFile Improper Access Control Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-25"
    },
    {
      "value": "45.61.136.39",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2414",
          "title": "CISA KEV: CVE-2021-22941 \u2014 Citrix ShareFile Improper Access Control Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-25"
    },
    {
      "value": "45.84.196.75",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2416",
          "title": "CISA KEV: CVE-2020-9054 \u2014 Zyxel Multiple NAS Devices OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-25"
    },
    {
      "value": "46228151b547c905de9772211ce559592498e0c8894379f14adb1ef6c44f8933",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2416",
          "title": "CISA KEV: CVE-2020-9054 \u2014 Zyxel Multiple NAS Devices OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-25"
    },
    {
      "value": "5f918c2b5316c52cbb564269b116ce63935691ee6debe06ce1693ad29dbb5740",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2416",
          "title": "CISA KEV: CVE-2020-9054 \u2014 Zyxel Multiple NAS Devices OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-25"
    },
    {
      "value": "675f4af00520905e31ff96ecef2d4dc77166481f584da89a39a798ea18ae2144",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2416",
          "title": "CISA KEV: CVE-2020-9054 \u2014 Zyxel Multiple NAS Devices OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-25"
    },
    {
      "value": "753914aa3549e52af2627992731ca18e702f652391c161483f532173daeb0bbd",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2416",
          "title": "CISA KEV: CVE-2020-9054 \u2014 Zyxel Multiple NAS Devices OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-25"
    },
    {
      "value": "8c0c4d8d727bff5e03f6b2aae125d3e3607948d9dff578b18be0add2fff3411c",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2416",
          "title": "CISA KEV: CVE-2020-9054 \u2014 Zyxel Multiple NAS Devices OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-25"
    },
    {
      "value": "8fa54788885679e4677296fca4fe4e949ca85783a057750c658543645fb8682f",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2416",
          "title": "CISA KEV: CVE-2020-9054 \u2014 Zyxel Multiple NAS Devices OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-25"
    },
    {
      "value": "90392af3fdc7af968cc6d054fc1a99c5156de5b1834d6432076c40d548283c22",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2416",
          "title": "CISA KEV: CVE-2020-9054 \u2014 Zyxel Multiple NAS Devices OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-25"
    },
    {
      "value": "a059e47b4c76b6bbd70ca4db6b454fd9aa19e5a0487c8032fe54fa707b0f926d",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2416",
          "title": "CISA KEV: CVE-2020-9054 \u2014 Zyxel Multiple NAS Devices OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-25"
    },
    {
      "value": "ce793ddec5410c5104d0ea23809a40dd222473e3d984a1e531e735aebf46c9dc",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2416",
          "title": "CISA KEV: CVE-2020-9054 \u2014 Zyxel Multiple NAS Devices OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-25"
    },
    {
      "value": "api.ipgeolocation.io",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-2482",
          "title": "Alert: peacenotwar module sabotages npm developers in the node-ipc package to protest the invasion of Ukraine",
          "link": "https://snyk.io/blog/peacenotwar-malicious-npm-node-ipc-package-vulnerability/",
          "published": "2022-03-16",
          "sev": "high"
        }
      ],
      "first_seen": "2022-03-16"
    },
    {
      "value": "CVE-2015-2546",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2499",
          "title": "CISA KEV: CVE-2015-2546 \u2014 Microsoft Win32k Memory Corruption Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-15",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-15"
    },
    {
      "value": "CVE-2016-3309",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2498",
          "title": "CISA KEV: CVE-2016-3309 \u2014 Microsoft Windows Kernel Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-15",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-15"
    },
    {
      "value": "CVE-2017-0101",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2497",
          "title": "CISA KEV: CVE-2017-0101 \u2014 Microsoft Windows Transaction Manager Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-15",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-15"
    },
    {
      "value": "CVE-2018-8120",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2496",
          "title": "CISA KEV: CVE-2018-8120 \u2014 Microsoft Win32k Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-15",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-15"
    },
    {
      "value": "CVE-2019-0543",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2495",
          "title": "CISA KEV: CVE-2019-0543 \u2014 Microsoft Windows Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-15",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-15"
    },
    {
      "value": "CVE-2019-0841",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2494",
          "title": "CISA KEV: CVE-2019-0841 \u2014 Microsoft Windows AppX Deployment Service (AppXSVC) Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-15",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-15"
    },
    {
      "value": "CVE-2019-1064",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2493",
          "title": "CISA KEV: CVE-2019-1064 \u2014 Microsoft Windows AppX Deployment Service (AppXSVC) Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-15",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-15"
    },
    {
      "value": "CVE-2019-1069",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2492",
          "title": "CISA KEV: CVE-2019-1069 \u2014 Microsoft Task Scheduler Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-15",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-15"
    },
    {
      "value": "CVE-2019-1129",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2491",
          "title": "CISA KEV: CVE-2019-1129 \u2014 Microsoft Windows AppX Deployment Service (AppXSVC) Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-15",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-15"
    },
    {
      "value": "CVE-2019-1132",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2490",
          "title": "CISA KEV: CVE-2019-1132 \u2014 Microsoft Win32k Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-15",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-15"
    },
    {
      "value": "CVE-2019-1253",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2489",
          "title": "CISA KEV: CVE-2019-1253 \u2014 Microsoft Windows AppX Deployment Server Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-15",
          "sev": "crit"
        },
        {
          "id": "art-2491",
          "title": "CISA KEV: CVE-2019-1129 \u2014 Microsoft Windows AppX Deployment Service (AppXSVC) Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-15",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-15"
    },
    {
      "value": "CVE-2019-1315",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2488",
          "title": "CISA KEV: CVE-2019-1315 \u2014 Microsoft Windows Error Reporting Manager Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-15",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-15"
    },
    {
      "value": "CVE-2019-1322",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2486",
          "title": "CISA KEV: CVE-2019-1405 \u2014 Microsoft Windows Universal Plug and Play (UPnP) Service Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-15",
          "sev": "crit"
        },
        {
          "id": "art-2487",
          "title": "CISA KEV: CVE-2019-1322 \u2014 Microsoft Windows Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-15",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-15"
    },
    {
      "value": "CVE-2019-1405",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2486",
          "title": "CISA KEV: CVE-2019-1405 \u2014 Microsoft Windows Universal Plug and Play (UPnP) Service Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-15",
          "sev": "crit"
        },
        {
          "id": "art-2487",
          "title": "CISA KEV: CVE-2019-1322 \u2014 Microsoft Windows Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-15",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-15"
    },
    {
      "value": "CVE-2020-5135",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2485",
          "title": "CISA KEV: CVE-2020-5135 \u2014 SonicWall SonicOS Buffer Overflow Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-15",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-15"
    },
    {
      "value": "hdfilm-seyret.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2490",
          "title": "CISA KEV: CVE-2019-1132 \u2014 Microsoft Win32k Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-15",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-15"
    },
    {
      "value": "redmond.corp-microsoft.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2490",
          "title": "CISA KEV: CVE-2019-1132 \u2014 Microsoft Win32k Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-15",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-15"
    },
    {
      "value": "secure-telemetry.net",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2490",
          "title": "CISA KEV: CVE-2019-1132 \u2014 Microsoft Win32k Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-15",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-15"
    },
    {
      "value": "services-glbdns2.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2490",
          "title": "CISA KEV: CVE-2019-1132 \u2014 Microsoft Win32k Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-15",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-15"
    },
    {
      "value": "win10.ipv6-microsoft.org",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2490",
          "title": "CISA KEV: CVE-2019-1132 \u2014 Microsoft Win32k Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-15",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-15"
    },
    {
      "value": "2F2640720CCE2F83CA2F0633330F13651384DD6A",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2490",
          "title": "CISA KEV: CVE-2019-1132 \u2014 Microsoft Win32k Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-15",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-15"
    },
    {
      "value": "9C3434EBDF29E5A4762AFB610EA59714D8BE2392",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2490",
          "title": "CISA KEV: CVE-2019-1132 \u2014 Microsoft Win32k Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-15",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-15"
    },
    {
      "value": "C17C335B7DDB5C8979444EC36AB668AE8E4E0A72",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2490",
          "title": "CISA KEV: CVE-2019-1132 \u2014 Microsoft Win32k Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-15",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-15"
    },
    {
      "value": "E0F3557EA9F2BA4F7074CAA0D0CF3B187C4472FF",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2490",
          "title": "CISA KEV: CVE-2019-1132 \u2014 Microsoft Win32k Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-15",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-15"
    },
    {
      "value": "CVE-2021-3507",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-2505",
          "title": "Simplifying container security with Snyk\u2019s security expertise",
          "link": "https://snyk.io/blog/simplifying-container-security-snyk-expertise/",
          "published": "2022-03-08",
          "sev": "high"
        }
      ],
      "first_seen": "2022-03-08"
    },
    {
      "value": "CVE-2013-0625",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2517",
          "title": "CISA KEV: CVE-2013-0625 \u2014 Adobe ColdFusion Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-07",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-07"
    },
    {
      "value": "CVE-2013-0629",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2516",
          "title": "CISA KEV: CVE-2013-0629 \u2014 Adobe ColdFusion Directory Traversal Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-07",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-07"
    },
    {
      "value": "CVE-2013-0631",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2515",
          "title": "CISA KEV: CVE-2013-0631 \u2014 Adobe ColdFusion Information Disclosure Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-07",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-07"
    },
    {
      "value": "CVE-2017-6077",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2513",
          "title": "CISA KEV: CVE-2017-6077 \u2014 NETGEAR DGN2200 Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-07",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-07"
    },
    {
      "value": "CVE-2018-1000861",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2512",
          "title": "CISA KEV: CVE-2019-11581 \u2014 Atlassian Jira Server and Data Center Server-Side Template Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-07",
          "sev": "crit"
        },
        {
          "id": "art-2655",
          "title": "CISA KEV: CVE-2018-1000861 \u2014 Jenkins Stapler Web Framework Deserialization of Untrusted Data Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-02-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-07"
    },
    {
      "value": "CVE-2019-0192",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2512",
          "title": "CISA KEV: CVE-2019-11581 \u2014 Atlassian Jira Server and Data Center Server-Side Template Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-07",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-07"
    },
    {
      "value": "CVE-2019-0708",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2512",
          "title": "CISA KEV: CVE-2019-11581 \u2014 Atlassian Jira Server and Data Center Server-Side Template Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-07",
          "sev": "crit"
        },
        {
          "id": "art-2949",
          "title": "CISA KEV: CVE-2019-0708 \u2014 Microsoft Remote Desktop Services Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-07"
    },
    {
      "value": "CVE-2019-10149",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2512",
          "title": "CISA KEV: CVE-2019-11581 \u2014 Atlassian Jira Server and Data Center Server-Side Template Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-07",
          "sev": "crit"
        },
        {
          "id": "art-2727",
          "title": "CISA KEV: CVE-2019-10149 \u2014 Exim Mail Transfer Agent (MTA) Improper Input Validation",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-01-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-07"
    },
    {
      "value": "CVE-2019-11581",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2512",
          "title": "CISA KEV: CVE-2019-11581 \u2014 Atlassian Jira Server and Data Center Server-Side Template Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-07",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-07"
    },
    {
      "value": "CVE-2019-7238",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2512",
          "title": "CISA KEV: CVE-2019-11581 \u2014 Atlassian Jira Server and Data Center Server-Side Template Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-07",
          "sev": "crit"
        },
        {
          "id": "art-2763",
          "title": "CISA KEV: CVE-2019-7238 \u2014 Sonatype Nexus Repository Manager Incorrect Access Control Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-12-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-07"
    },
    {
      "value": "CVE-2020-8218",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2511",
          "title": "CISA KEV: CVE-2020-8218 \u2014 Pulse Connect Secure Code Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-07",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-07"
    },
    {
      "value": "CVE-2021-21973",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2510",
          "title": "CISA KEV: CVE-2021-21973 \u2014 VMware vCenter Server and Cloud Foundation Server Side Request Forgery (SSRF) Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-07",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-07"
    },
    {
      "value": "CVE-2022-26485",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2509",
          "title": "CISA KEV: CVE-2022-26485 \u2014 Mozilla Firefox Use-After-Free Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-07",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-07"
    },
    {
      "value": "CVE-2022-26486",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2508",
          "title": "CISA KEV: CVE-2022-26486 \u2014 Mozilla Firefox Use-After-Free Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-07",
          "sev": "crit"
        },
        {
          "id": "art-2509",
          "title": "CISA KEV: CVE-2022-26485 \u2014 Mozilla Firefox Use-After-Free Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-07",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-07"
    },
    {
      "value": "7dc5fb4e.ngrok.io",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2512",
          "title": "CISA KEV: CVE-2019-11581 \u2014 Atlassian Jira Server and Data Center Server-Side Template Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-07",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-07"
    },
    {
      "value": "9d842cb6.ngrok.io",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2512",
          "title": "CISA KEV: CVE-2019-11581 \u2014 Atlassian Jira Server and Data Center Server-Side Template Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-07",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-07"
    },
    {
      "value": "z5r6anrjbcasuikp.onion.to",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2512",
          "title": "CISA KEV: CVE-2019-11581 \u2014 Atlassian Jira Server and Data Center Server-Side Template Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-07",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-07"
    },
    {
      "value": "18.188.14.65",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2512",
          "title": "CISA KEV: CVE-2019-11581 \u2014 Atlassian Jira Server and Data Center Server-Side Template Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-07",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-07"
    },
    {
      "value": "3.14.202.129",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2512",
          "title": "CISA KEV: CVE-2019-11581 \u2014 Atlassian Jira Server and Data Center Server-Side Template Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-07",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-07"
    },
    {
      "value": "3.14.212.173",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2512",
          "title": "CISA KEV: CVE-2019-11581 \u2014 Atlassian Jira Server and Data Center Server-Side Template Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-07",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-07"
    },
    {
      "value": "3.17.202.129",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2512",
          "title": "CISA KEV: CVE-2019-11581 \u2014 Atlassian Jira Server and Data Center Server-Side Template Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-07",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-07"
    },
    {
      "value": "3.19.3.150",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2512",
          "title": "CISA KEV: CVE-2019-11581 \u2014 Atlassian Jira Server and Data Center Server-Side Template Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-07",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-07"
    },
    {
      "value": "f839fc8e7f22be30d73286fd665c8c3c",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2512",
          "title": "CISA KEV: CVE-2019-11581 \u2014 Atlassian Jira Server and Data Center Server-Side Template Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-07",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-07"
    },
    {
      "value": "26ebeac4492616baf977903bb8deb7803bd5a22d8a005f02398c188b0375dfa4",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2512",
          "title": "CISA KEV: CVE-2019-11581 \u2014 Atlassian Jira Server and Data Center Server-Side Template Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-07",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-07"
    },
    {
      "value": "b17829d758e8689143456240ebd79b420f963722707246f5dc9b085a411f7b5e",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2512",
          "title": "CISA KEV: CVE-2019-11581 \u2014 Atlassian Jira Server and Data Center Server-Side Template Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-07",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-07"
    },
    {
      "value": "c47d8dfa8337d21e3c3e1560ac4f6713bfd686bce2d7a4ef268fe992d8f93a52",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2512",
          "title": "CISA KEV: CVE-2019-11581 \u2014 Atlassian Jira Server and Data Center Server-Side Template Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-07",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-07"
    },
    {
      "value": "cdf11a1fa7e551fe6be1f170ba9dedee80401396adf7e39ccde5df635c1117a9",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2512",
          "title": "CISA KEV: CVE-2019-11581 \u2014 Atlassian Jira Server and Data Center Server-Side Template Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-07",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-07"
    },
    {
      "value": "CVE-2002-0367",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2616",
          "title": "CISA KEV: CVE-2002-0367 \u2014 Microsoft Windows Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-03"
    },
    {
      "value": "CVE-2004-0210",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2615",
          "title": "CISA KEV: CVE-2004-0210 \u2014 Microsoft Windows Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-03",
          "sev": "crit"
        },
        {
          "id": "art-2616",
          "title": "CISA KEV: CVE-2002-0367 \u2014 Microsoft Windows Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-03"
    },
    {
      "value": "CVE-2008-2992",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2614",
          "title": "CISA KEV: CVE-2008-2992 \u2014 Adobe Reader and Acrobat Input Validation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-03"
    },
    {
      "value": "CVE-2008-3431",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2613",
          "title": "CISA KEV: CVE-2008-3431 \u2014 Oracle VirtualBox Insufficient Input Validation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-03"
    },
    {
      "value": "CVE-2009-1123",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2612",
          "title": "CISA KEV: CVE-2009-1123 \u2014 Microsoft Windows Improper Input Validation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-03"
    },
    {
      "value": "CVE-2009-3129",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2611",
          "title": "CISA KEV: CVE-2009-3129 \u2014 Microsoft Excel Featheader Record Memory Corruption Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-03"
    },
    {
      "value": "CVE-2010-0188",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2610",
          "title": "CISA KEV: CVE-2010-0188 \u2014 Adobe Reader and Acrobat Arbitrary Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-03"
    },
    {
      "value": "CVE-2010-0232",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2609",
          "title": "CISA KEV: CVE-2010-0232 \u2014 Microsoft Windows Kernel Exception Handler Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-03"
    },
    {
      "value": "CVE-2010-3333",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2608",
          "title": "CISA KEV: CVE-2010-3333 \u2014 Microsoft Office Stack-based Buffer Overflow Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-03"
    },
    {
      "value": "CVE-2011-1889",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2606",
          "title": "CISA KEV: CVE-2011-1889 \u2014 Microsoft Forefront TMG Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-03"
    },
    {
      "value": "CVE-2011-3544",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2605",
          "title": "CISA KEV: CVE-2011-3544 \u2014 Oracle Java SE Runtime Environment (JRE) Arbitrary Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-03"
    },
    {
      "value": "CVE-2012-0158",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2584",
          "title": "CISA KEV: CVE-2015-2590 \u2014 Oracle Java SE and Java SE Embedded Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-03",
          "sev": "crit"
        },
        {
          "id": "art-2968",
          "title": "CISA KEV: CVE-2012-0158 \u2014 Microsoft MSCOMCTL.OCX Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-03"
    },
    {
      "value": "CVE-2012-0507",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2604",
          "title": "CISA KEV: CVE-2012-0507 \u2014 Oracle Java SE Runtime Environment (JRE) Arbitrary Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-03"
    },
    {
      "value": "CVE-2012-1535",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2603",
          "title": "CISA KEV: CVE-2012-1535 \u2014 Adobe Flash Player Arbitrary Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-03"
    },
    {
      "value": "CVE-2012-1723",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2602",
          "title": "CISA KEV: CVE-2012-1723 \u2014 Oracle Java SE Runtime Environment (JRE) Arbitrary Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-03"
    },
    {
      "value": "CVE-2012-1856",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2601",
          "title": "CISA KEV: CVE-2012-1856 \u2014 Microsoft Office MSCOMCTL.OCX Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-03"
    },
    {
      "value": "CVE-2012-4681",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2600",
          "title": "CISA KEV: CVE-2012-4681 \u2014 Oracle Java SE Runtime Environment (JRE) Arbitrary Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-03",
          "sev": "crit"
        },
        {
          "id": "art-2602",
          "title": "CISA KEV: CVE-2012-1723 \u2014 Oracle Java SE Runtime Environment (JRE) Arbitrary Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-03",
          "sev": "crit"
        },
        {
          "id": "art-2604",
          "title": "CISA KEV: CVE-2012-0507 \u2014 Oracle Java SE Runtime Environment (JRE) Arbitrary Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-03"
    },
    {
      "value": "CVE-2013-0632",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2599",
          "title": "CISA KEV: CVE-2013-0632 \u2014 Adobe ColdFusion Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-03"
    },
    {
      "value": "CVE-2013-0640",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2598",
          "title": "CISA KEV: CVE-2013-0640 \u2014 Adobe Reader and Acrobat Memory Corruption Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-03"
    },
    {
      "value": "CVE-2013-0641",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2597",
          "title": "CISA KEV: CVE-2013-0641 \u2014 Adobe Reader Buffer Overflow Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-03",
          "sev": "crit"
        },
        {
          "id": "art-2598",
          "title": "CISA KEV: CVE-2013-0640 \u2014 Adobe Reader and Acrobat Memory Corruption Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-03"
    },
    {
      "value": "CVE-2013-1347",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2596",
          "title": "CISA KEV: CVE-2013-1347 \u2014 Microsoft Internet Explorer Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-03"
    },
    {
      "value": "CVE-2013-1675",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2595",
          "title": "CISA KEV: CVE-2013-1675 \u2014 Mozilla Firefox Information Disclosure Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-03"
    },
    {
      "value": "CVE-2013-3346",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2594",
          "title": "CISA KEV: CVE-2013-3346 \u2014 Adobe Reader and Acrobat Memory Corruption Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-03"
    },
    {
      "value": "CVE-2013-3897",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2593",
          "title": "CISA KEV: CVE-2013-3897 \u2014 Microsoft Internet Explorer Use-After-Free Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-03"
    },
    {
      "value": "CVE-2013-5065",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2592",
          "title": "CISA KEV: CVE-2013-5065 \u2014 Microsoft Windows Kernel Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-03",
          "sev": "crit"
        },
        {
          "id": "art-2594",
          "title": "CISA KEV: CVE-2013-3346 \u2014 Adobe Reader and Acrobat Memory Corruption Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-03"
    },
    {
      "value": "CVE-2014-0496",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2591",
          "title": "CISA KEV: CVE-2014-0496 \u2014 Adobe Reader and Acrobat Use-After-Free Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-03"
    },
    {
      "value": "CVE-2014-4114",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2590",
          "title": "CISA KEV: CVE-2014-4114 \u2014 Microsoft Windows Object Linking & Embedding (OLE) Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-03"
    },
    {
      "value": "CVE-2015-1642",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2589",
          "title": "CISA KEV: CVE-2015-1642 \u2014 Microsoft Office Memory Corruption Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-03"
    },
    {
      "value": "CVE-2015-1701",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2583",
          "title": "CISA KEV: CVE-2015-3043 \u2014 Adobe Flash Player Memory Corruption Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-03",
          "sev": "crit"
        },
        {
          "id": "art-2588",
          "title": "CISA KEV: CVE-2015-1701 \u2014 Microsoft Win32k Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-03"
    },
    {
      "value": "CVE-2015-2387",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2587",
          "title": "CISA KEV: CVE-2015-2387 \u2014 Microsoft ATM Font Driver Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-03",
          "sev": "crit"
        },
        {
          "id": "art-2588",
          "title": "CISA KEV: CVE-2015-1701 \u2014 Microsoft Win32k Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-03"
    },
    {
      "value": "CVE-2015-2424",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2586",
          "title": "CISA KEV: CVE-2015-2424 \u2014 Microsoft PowerPoint Memory Corruption Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-03"
    },
    {
      "value": "CVE-2015-2545",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2585",
          "title": "CISA KEV: CVE-2015-2545 \u2014 Microsoft Office Malformed EPS File Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-03"
    },
    {
      "value": "CVE-2015-2590",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2582",
          "title": "CISA KEV: CVE-2015-4902 \u2014 Oracle Java SE Integrity Check Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-03",
          "sev": "crit"
        },
        {
          "id": "art-2584",
          "title": "CISA KEV: CVE-2015-2590 \u2014 Oracle Java SE and Java SE Embedded Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-03"
    },
    {
      "value": "CVE-2015-3043",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2583",
          "title": "CISA KEV: CVE-2015-3043 \u2014 Adobe Flash Player Memory Corruption Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-03"
    },
    {
      "value": "CVE-2015-4902",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2582",
          "title": "CISA KEV: CVE-2015-4902 \u2014 Oracle Java SE Integrity Check Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-03",
          "sev": "crit"
        },
        {
          "id": "art-2584",
          "title": "CISA KEV: CVE-2015-2590 \u2014 Oracle Java SE and Java SE Embedded Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-03"
    },
    {
      "value": "CVE-2015-5119",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2581",
          "title": "CISA KEV: CVE-2015-5119 \u2014 Adobe Flash Player Use-After-Free Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-03"
    },
    {
      "value": "CVE-2015-7645",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2580",
          "title": "CISA KEV: CVE-2015-7645 \u2014 Adobe Flash Player Arbitrary Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-03",
          "sev": "crit"
        },
        {
          "id": "art-2582",
          "title": "CISA KEV: CVE-2015-4902 \u2014 Oracle Java SE Integrity Check Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-03"
    },
    {
      "value": "CVE-2016-0099",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2579",
          "title": "CISA KEV: CVE-2016-0099 \u2014 Microsoft Windows Secondary Logon Service Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-03"
    },
    {
      "value": "CVE-2016-1019",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2578",
          "title": "CISA KEV: CVE-2016-1019 \u2014 Adobe Flash Player Arbitrary Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-03"
    },
    {
      "value": "CVE-2016-4117",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2577",
          "title": "CISA KEV: CVE-2016-4117 \u2014 Adobe Flash Player Arbitrary Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-03",
          "sev": "crit"
        },
        {
          "id": "art-2603",
          "title": "CISA KEV: CVE-2012-1535 \u2014 Adobe Flash Player Arbitrary Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-03"
    },
    {
      "value": "CVE-2016-7193",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2575",
          "title": "CISA KEV: CVE-2016-7193 \u2014 Microsoft Office Memory Corruption Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-03",
          "sev": "crit"
        },
        {
          "id": "art-2589",
          "title": "CISA KEV: CVE-2015-1642 \u2014 Microsoft Office Memory Corruption Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-03"
    },
    {
      "value": "CVE-2016-7255",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2573",
          "title": "CISA KEV: CVE-2016-7855 \u2014 Adobe Flash Player Use-After-Free Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-03",
          "sev": "crit"
        },
        {
          "id": "art-2948",
          "title": "CISA KEV: CVE-2016-7255 \u2014 Microsoft Win32k Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-03"
    },
    {
      "value": "CVE-2016-7262",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2574",
          "title": "CISA KEV: CVE-2016-7262 \u2014 Microsoft Office Security Feature Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-03"
    },
    {
      "value": "CVE-2016-7855",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2573",
          "title": "CISA KEV: CVE-2016-7855 \u2014 Adobe Flash Player Use-After-Free Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-03",
          "sev": "crit"
        },
        {
          "id": "art-2581",
          "title": "CISA KEV: CVE-2015-5119 \u2014 Adobe Flash Player Use-After-Free Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-03",
          "sev": "crit"
        },
        {
          "id": "art-2948",
          "title": "CISA KEV: CVE-2016-7255 \u2014 Microsoft Win32k Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-03"
    },
    {
      "value": "CVE-2016-8562",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2572",
          "title": "CISA KEV: CVE-2016-8562 \u2014 Siemens SIMATIC CP 1543-1 Improper Privilege Management Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-03"
    },
    {
      "value": "CVE-2017-0001",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2571",
          "title": "CISA KEV: CVE-2017-0001 \u2014 Microsoft Graphics Device Interface (GDI) Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-03"
    },
    {
      "value": "CVE-2017-0261",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2570",
          "title": "CISA KEV: CVE-2017-0261 \u2014 Microsoft Office Use-After-Free Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-03"
    },
    {
      "value": "CVE-2017-11292",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2569",
          "title": "CISA KEV: CVE-2017-11292 \u2014 Adobe Flash Player Type Confusion Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-03"
    },
    {
      "value": "CVE-2017-11826",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2568",
          "title": "CISA KEV: CVE-2017-11826 \u2014 Microsoft Office Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-03"
    },
    {
      "value": "CVE-2017-12231",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2567",
          "title": "CISA KEV: CVE-2017-12231 \u2014 Cisco IOS Software Network Address Translation Denial-of-Service Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-03"
    },
    {
      "value": "CVE-2017-12232",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2566",
          "title": "CISA KEV: CVE-2017-12232 \u2014 Cisco IOS Software for Cisco Integrated Services Routers Denial-of-Service Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-03"
    },
    {
      "value": "CVE-2017-12233",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2565",
          "title": "CISA KEV: CVE-2017-12233 \u2014 Cisco IOS Software Common Industrial Protocol Request Denial-of-Service Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-03"
    },
    {
      "value": "CVE-2017-12234",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2564",
          "title": "CISA KEV: CVE-2017-12234 \u2014 Cisco IOS Software Common Industrial Protocol Request Denial-of-Service Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-03"
    },
    {
      "value": "CVE-2017-12235",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2563",
          "title": "CISA KEV: CVE-2017-12235 \u2014 Cisco IOS Software for Cisco Industrial Ethernet Switches PROFINET Denial-of-Service Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-03"
    },
    {
      "value": "CVE-2017-12237",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2562",
          "title": "CISA KEV: CVE-2017-12237 \u2014 Cisco IOS and IOS XE Software Internet Key Exchange Denial-of-Service Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-03"
    },
    {
      "value": "CVE-2017-12238",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2561",
          "title": "CISA KEV: CVE-2017-12238 \u2014 Cisco Catalyst 6800 Series Switches VPLS Denial-of-Service Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-03"
    },
    {
      "value": "CVE-2017-12240",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2560",
          "title": "CISA KEV: CVE-2017-12240 \u2014 Cisco IOS and IOS XE Software DHCP Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-03"
    },
    {
      "value": "CVE-2017-12319",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2559",
          "title": "CISA KEV: CVE-2017-12319 \u2014 Cisco IOS XE Software Ethernet Virtual Private Network Border Gateway Protocol Denial-of-Service Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-03"
    },
    {
      "value": "CVE-2017-6627",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2558",
          "title": "CISA KEV: CVE-2017-6627 \u2014 Cisco IOS Software and Cisco IOS XE Software UDP Packet Processing Denial-of-Service Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-03"
    },
    {
      "value": "CVE-2017-6663",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2557",
          "title": "CISA KEV: CVE-2017-6663 \u2014 Cisco IOS Software and Cisco IOS XE Software Denial-of-Service Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-03"
    },
    {
      "value": "CVE-2017-6736",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2556",
          "title": "CISA KEV: CVE-2017-6736 \u2014 Cisco IOS and IOS XE Software SNMP Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-03",
          "sev": "crit"
        },
        {
          "id": "art-2560",
          "title": "CISA KEV: CVE-2017-12240 \u2014 Cisco IOS and IOS XE Software DHCP Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-03"
    },
    {
      "value": "CVE-2017-6737",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2555",
          "title": "CISA KEV: CVE-2017-6737 \u2014 Cisco IOS and IOS XE Software SNMP Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-03"
    },
    {
      "value": "CVE-2017-6738",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2554",
          "title": "CISA KEV: CVE-2017-6738 \u2014 Cisco IOS and IOS XE Software SNMP Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-03"
    },
    {
      "value": "CVE-2017-6739",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2553",
          "title": "CISA KEV: CVE-2017-6739 \u2014 Cisco IOS and IOS XE Software SNMP Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-03"
    },
    {
      "value": "CVE-2017-6740",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2552",
          "title": "CISA KEV: CVE-2017-6740 \u2014 Cisco IOS and IOS XE Software SNMP Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-03"
    },
    {
      "value": "CVE-2017-6743",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2551",
          "title": "CISA KEV: CVE-2017-6743 \u2014 Cisco IOS and IOS XE Software SNMP Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-03"
    },
    {
      "value": "CVE-2017-6744",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2550",
          "title": "CISA KEV: CVE-2017-6744 \u2014 Cisco IOS Software SNMP Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-03"
    },
    {
      "value": "CVE-2017-8540",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2549",
          "title": "CISA KEV: CVE-2017-8540 \u2014 Microsoft Malware Protection Engine Improper Restriction of Operations Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-03"
    },
    {
      "value": "CVE-2018-0151",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2548",
          "title": "CISA KEV: CVE-2018-0151 \u2014 Cisco IOS Software and Cisco IOS XE Software Quality of Service Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-03",
          "sev": "crit"
        },
        {
          "id": "art-2550",
          "title": "CISA KEV: CVE-2017-6744 \u2014 Cisco IOS Software SNMP Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-03"
    },
    {
      "value": "CVE-2018-0154",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2547",
          "title": "CISA KEV: CVE-2018-0154 \u2014 Cisco IOS Software Integrated Services Module for VPN Denial-of-Service Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-03",
          "sev": "crit"
        },
        {
          "id": "art-2566",
          "title": "CISA KEV: CVE-2017-12232 \u2014 Cisco IOS Software for Cisco Integrated Services Routers Denial-of-Service Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-03"
    },
    {
      "value": "CVE-2018-0155",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2546",
          "title": "CISA KEV: CVE-2018-0155 \u2014 Cisco Catalyst Bidirectional Forwarding Detection Denial-of-Service Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-03"
    },
    {
      "value": "CVE-2018-0156",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2545",
          "title": "CISA KEV: CVE-2018-0156 \u2014 Cisco IOS Software and Cisco IOS XE Software Smart Install Denial-of-Service Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-03"
    },
    {
      "value": "CVE-2018-0158",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2544",
          "title": "CISA KEV: CVE-2018-0158 \u2014 Cisco IOS and XE Software Internet Key Exchange Memory Leak Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-03"
    },
    {
      "value": "CVE-2018-0159",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2543",
          "title": "CISA KEV: CVE-2018-0159 \u2014 Cisco IOS and XE Software Internet Key Exchange Version 1 Denial-of-Service Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-03"
    },
    {
      "value": "CVE-2018-0161",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2542",
          "title": "CISA KEV: CVE-2018-0161 \u2014 Cisco IOS Software Resource Management Errors Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-03"
    },
    {
      "value": "CVE-2018-0167",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2541",
          "title": "CISA KEV: CVE-2018-0167 \u2014 Cisco IOS, XR, and XE Software Buffer Overflow Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-03"
    },
    {
      "value": "CVE-2018-0172",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2540",
          "title": "CISA KEV: CVE-2018-0172 \u2014 Cisco IOS and IOS XE Software Improper Input Validation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-03"
    },
    {
      "value": "CVE-2018-0173",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2539",
          "title": "CISA KEV: CVE-2018-0173 \u2014 Cisco IOS and IOS XE Software Improper Input Validation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-03"
    },
    {
      "value": "CVE-2018-0174",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2538",
          "title": "CISA KEV: CVE-2018-0174 \u2014 Cisco IOS Software and Cisco IOS XE Software Improper Input Validation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-03",
          "sev": "crit"
        },
        {
          "id": "art-2539",
          "title": "CISA KEV: CVE-2018-0173 \u2014 Cisco IOS and IOS XE Software Improper Input Validation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-03"
    },
    {
      "value": "CVE-2018-0175",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2537",
          "title": "CISA KEV: CVE-2018-0175 \u2014 Cisco IOS, XR, and XE Software Buffer Overflow Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-03"
    },
    {
      "value": "CVE-2018-0179",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2536",
          "title": "CISA KEV: CVE-2018-0179 \u2014 Cisco IOS Software Denial-of-Service Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-03"
    },
    {
      "value": "CVE-2018-0180",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2535",
          "title": "CISA KEV: CVE-2018-0180 \u2014 Cisco IOS Software Denial-of-Service Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-03"
    },
    {
      "value": "CVE-2018-8298",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2534",
          "title": "CISA KEV: CVE-2018-8298 \u2014 ChakraCore Scripting Engine Type Confusion Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-03"
    },
    {
      "value": "CVE-2018-8581",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2533",
          "title": "CISA KEV: CVE-2018-8581 \u2014 Microsoft Exchange Server Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-03"
    },
    {
      "value": "CVE-2019-1297",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2532",
          "title": "CISA KEV: CVE-2019-1297 \u2014 Microsoft Excel Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-03",
          "sev": "crit"
        },
        {
          "id": "art-2568",
          "title": "CISA KEV: CVE-2017-11826 \u2014 Microsoft Office Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-03"
    },
    {
      "value": "CVE-2019-1652",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2531",
          "title": "CISA KEV: CVE-2019-1652 \u2014 Cisco Small Business Routers Improper Input Validation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-03",
          "sev": "crit"
        },
        {
          "id": "art-2863",
          "title": "CISA KEV: CVE-2019-1653 \u2014 Cisco Small Business RV320 and RV325 Routers Information Disclosure Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-03"
    },
    {
      "value": "CVE-2019-1653",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2531",
          "title": "CISA KEV: CVE-2019-1652 \u2014 Cisco Small Business Routers Improper Input Validation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-03",
          "sev": "crit"
        },
        {
          "id": "art-2863",
          "title": "CISA KEV: CVE-2019-1653 \u2014 Cisco Small Business RV320 and RV325 Routers Information Disclosure Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-03"
    },
    {
      "value": "CVE-2019-16928",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2530",
          "title": "CISA KEV: CVE-2019-16928 \u2014 Exim Out-of-bounds Write Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-03"
    },
    {
      "value": "CVE-2020-11899",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2529",
          "title": "CISA KEV: CVE-2020-11899 \u2014 Treck TCP/IP stack Out-of-Bounds Read Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-03"
    },
    {
      "value": "CVE-2020-1938",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV",
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-2528",
          "title": "CISA KEV: CVE-2020-1938 \u2014 Apache Tomcat Improper Privilege Management Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-03",
          "sev": "crit"
        },
        {
          "id": "art-3437",
          "title": "Ghostcat breach affects all Tomcat versions",
          "link": "https://snyk.io/blog/ghostcat-breach-affects-all-tomcat-versions/",
          "published": "2020-02-26",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-03"
    },
    {
      "value": "CVE-2021-41379",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2527",
          "title": "CISA KEV: CVE-2021-41379 \u2014 Microsoft Windows Installer Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-03",
          "sev": "crit"
        },
        {
          "id": "art-2592",
          "title": "CISA KEV: CVE-2013-5065 \u2014 Microsoft Windows Kernel Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-03"
    },
    {
      "value": "CVE-2022-20699",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2526",
          "title": "CISA KEV: CVE-2022-20699 \u2014 Cisco Small Business RV Series Routers Stack-based Buffer Overflow Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-03"
    },
    {
      "value": "CVE-2022-20700",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2525",
          "title": "CISA KEV: CVE-2022-20700 \u2014 Cisco Small Business RV Series Routers Stack-based Buffer Overflow Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-03"
    },
    {
      "value": "CVE-2022-20701",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2524",
          "title": "CISA KEV: CVE-2022-20701 \u2014 Cisco Small Business RV Series Routers Stack-based Buffer Overflow Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-03"
    },
    {
      "value": "CVE-2022-20703",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2523",
          "title": "CISA KEV: CVE-2022-20703 \u2014 Cisco Small Business RV Series Routers Stack-based Buffer Overflow Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-03"
    },
    {
      "value": "CVE-2022-20708",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2522",
          "title": "CISA KEV: CVE-2022-20708 \u2014 Cisco Small Business RV Series Routers Stack-based Buffer Overflow Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-03"
    },
    {
      "value": "dol.ns01.us",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2596",
          "title": "CISA KEV: CVE-2013-1347 \u2014 Microsoft Internet Explorer Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-03"
    },
    {
      "value": "liciayee.dyndns-free.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2607",
          "title": "CISA KEV: CVE-2011-0611 \u2014 Adobe Flash Player Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-03"
    },
    {
      "value": "microsoftupdate.ns1.name",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2596",
          "title": "CISA KEV: CVE-2013-1347 \u2014 Microsoft Internet Explorer Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-03"
    },
    {
      "value": "ssl-icloud.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2583",
          "title": "CISA KEV: CVE-2015-3043 \u2014 Adobe Flash Player Memory Corruption Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-03"
    },
    {
      "value": "1.234.31.142",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2593",
          "title": "CISA KEV: CVE-2013-3897 \u2014 Microsoft Internet Explorer Use-After-Free Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-03"
    },
    {
      "value": "1.234.31.153",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2593",
          "title": "CISA KEV: CVE-2013-3897 \u2014 Microsoft Internet Explorer Use-After-Free Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-03"
    },
    {
      "value": "1.234.31.154",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2593",
          "title": "CISA KEV: CVE-2013-3897 \u2014 Microsoft Internet Explorer Use-After-Free Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-03"
    },
    {
      "value": "208.106.153.173",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2607",
          "title": "CISA KEV: CVE-2011-0611 \u2014 Adobe Flash Player Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-03"
    },
    {
      "value": "218.38.77.104",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2607",
          "title": "CISA KEV: CVE-2011-0611 \u2014 Adobe Flash Player Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-03"
    },
    {
      "value": "60.234.77.197",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2607",
          "title": "CISA KEV: CVE-2011-0611 \u2014 Adobe Flash Player Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-03"
    },
    {
      "value": "63.223.113.63",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2607",
          "title": "CISA KEV: CVE-2011-0611 \u2014 Adobe Flash Player Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-03"
    },
    {
      "value": "87.236.215.246",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2583",
          "title": "CISA KEV: CVE-2015-3043 \u2014 Adobe Flash Player Memory Corruption Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-03"
    },
    {
      "value": "96.44.136.115",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2596",
          "title": "CISA KEV: CVE-2013-1347 \u2014 Microsoft Internet Explorer Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-03"
    },
    {
      "value": "41bb0ff7b57a354e4c9f65dfd47ea3ae",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2607",
          "title": "CISA KEV: CVE-2011-0611 \u2014 Adobe Flash Player Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-03"
    },
    {
      "value": "78c628fc44fe40bff47176613d3e1776",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2607",
          "title": "CISA KEV: CVE-2011-0611 \u2014 Adobe Flash Player Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-03"
    },
    {
      "value": "803b0cfe58f766e3e717992ca8a8f9e9",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2607",
          "title": "CISA KEV: CVE-2011-0611 \u2014 Adobe Flash Player Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-03"
    },
    {
      "value": "96cf54e6d7e228a2c6418aba93d6bd49",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2607",
          "title": "CISA KEV: CVE-2011-0611 \u2014 Adobe Flash Player Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-03"
    },
    {
      "value": "9bdefcc465c73fc5eedf41ebf47b5f6c",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2607",
          "title": "CISA KEV: CVE-2011-0611 \u2014 Adobe Flash Player Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-03"
    },
    {
      "value": "a421d074611188cfcfcedba55cc7e194",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2607",
          "title": "CISA KEV: CVE-2011-0611 \u2014 Adobe Flash Player Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-03"
    },
    {
      "value": "a51edd010f3c0d33249be771891265cb",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2607",
          "title": "CISA KEV: CVE-2011-0611 \u2014 Adobe Flash Player Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-03"
    },
    {
      "value": "d1bfe000e745207c32343bfe5abd94c9",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2607",
          "title": "CISA KEV: CVE-2011-0611 \u2014 Adobe Flash Player Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-03"
    },
    {
      "value": "ec2420e3b03316f13dc922cf7dd48cef",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2607",
          "title": "CISA KEV: CVE-2011-0611 \u2014 Adobe Flash Player Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-03"
    },
    {
      "value": "f27990c8369205d5167f7d64b7749ff8",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2607",
          "title": "CISA KEV: CVE-2011-0611 \u2014 Adobe Flash Player Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-03"
    },
    {
      "value": "0ac9da07feff242f4eaaca081b11b645f4435f03",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2607",
          "title": "CISA KEV: CVE-2011-0611 \u2014 Adobe Flash Player Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-03"
    },
    {
      "value": "45573ee5d89c1d7e7adb98149cca2dfee48b5d1f",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2607",
          "title": "CISA KEV: CVE-2011-0611 \u2014 Adobe Flash Player Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-03"
    },
    {
      "value": "5cc31b8cc90c9cda4781517678e27a15cf55d27d",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2607",
          "title": "CISA KEV: CVE-2011-0611 \u2014 Adobe Flash Player Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-03"
    },
    {
      "value": "6f969aad92fe9340d00b31eab95355088767b9ed",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2607",
          "title": "CISA KEV: CVE-2011-0611 \u2014 Adobe Flash Player Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-03"
    },
    {
      "value": "820699d9999ea3ba07e7f0d0c7f08fe10eae1d2d",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2607",
          "title": "CISA KEV: CVE-2011-0611 \u2014 Adobe Flash Player Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-03"
    },
    {
      "value": "aaff5eabe5d803742dbb8b405e7a7c4cb659f12c",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2607",
          "title": "CISA KEV: CVE-2011-0611 \u2014 Adobe Flash Player Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-03"
    },
    {
      "value": "c9de4570d5022e55102e4edfac55b46a2362ef0d",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2607",
          "title": "CISA KEV: CVE-2011-0611 \u2014 Adobe Flash Player Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-03"
    },
    {
      "value": "ca044e91761e633a0580c947adc39a6ca248e5e9",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2607",
          "title": "CISA KEV: CVE-2011-0611 \u2014 Adobe Flash Player Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-03"
    },
    {
      "value": "e6a3c14eb59a681115878432f5519138b69b5847",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2607",
          "title": "CISA KEV: CVE-2011-0611 \u2014 Adobe Flash Player Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-03"
    },
    {
      "value": "a43bafb2af2a1adcd1371ab3810b2908b591bc32798f3ad35ad662cf967b12fd",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2527",
          "title": "CISA KEV: CVE-2021-41379 \u2014 Microsoft Windows Installer Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-03-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-03-03"
    },
    {
      "value": "registry.terraform.io",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "med",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-2519",
          "title": "Adding Container and IaC security to the Snyk plugin for Jetbrains",
          "link": "https://snyk.io/blog/snyk-jetbrains-plugin-iac-container/",
          "published": "2022-03-03",
          "sev": "med"
        }
      ],
      "first_seen": "2022-03-03"
    },
    {
      "value": "CVE-2014-6352",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2625",
          "title": "CISA KEV: CVE-2014-6352 \u2014 Microsoft Windows Code Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-02-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-02-25"
    },
    {
      "value": "CVE-2017-0222",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2624",
          "title": "CISA KEV: CVE-2017-0222 \u2014 Microsoft Internet Explorer Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-02-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-02-25"
    },
    {
      "value": "CVE-2017-8570",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2623",
          "title": "CISA KEV: CVE-2017-8570 \u2014 Microsoft Office Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-02-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-02-25"
    },
    {
      "value": "CVE-2022-24682",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2622",
          "title": "CISA KEV: CVE-2022-24682 \u2014 Synacor Zimbra Collaborate Suite (ZCS) Cross-Site Scripting Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-02-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-02-25"
    },
    {
      "value": "amazon-check.cf",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2622",
          "title": "CISA KEV: CVE-2022-24682 \u2014 Synacor Zimbra Collaborate Suite (ZCS) Cross-Site Scripting Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-02-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-02-25"
    },
    {
      "value": "amazon-check.ga",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2622",
          "title": "CISA KEV: CVE-2022-24682 \u2014 Synacor Zimbra Collaborate Suite (ZCS) Cross-Site Scripting Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-02-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-02-25"
    },
    {
      "value": "amazon-check.gq",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2622",
          "title": "CISA KEV: CVE-2022-24682 \u2014 Synacor Zimbra Collaborate Suite (ZCS) Cross-Site Scripting Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-02-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-02-25"
    },
    {
      "value": "amazon-check.tk",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2622",
          "title": "CISA KEV: CVE-2022-24682 \u2014 Synacor Zimbra Collaborate Suite (ZCS) Cross-Site Scripting Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-02-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-02-25"
    },
    {
      "value": "amazon-team.tk",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2622",
          "title": "CISA KEV: CVE-2022-24682 \u2014 Synacor Zimbra Collaborate Suite (ZCS) Cross-Site Scripting Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-02-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-02-25"
    },
    {
      "value": "bruising-intellect.ml",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2622",
          "title": "CISA KEV: CVE-2022-24682 \u2014 Synacor Zimbra Collaborate Suite (ZCS) Cross-Site Scripting Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-02-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-02-25"
    },
    {
      "value": "findtruth.ml",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2622",
          "title": "CISA KEV: CVE-2022-24682 \u2014 Synacor Zimbra Collaborate Suite (ZCS) Cross-Site Scripting Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-02-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-02-25"
    },
    {
      "value": "iceywindflow.cf",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2622",
          "title": "CISA KEV: CVE-2022-24682 \u2014 Synacor Zimbra Collaborate Suite (ZCS) Cross-Site Scripting Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-02-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-02-25"
    },
    {
      "value": "iceywindflow.gq",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2622",
          "title": "CISA KEV: CVE-2022-24682 \u2014 Synacor Zimbra Collaborate Suite (ZCS) Cross-Site Scripting Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-02-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-02-25"
    },
    {
      "value": "iceywindflow.ml",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2622",
          "title": "CISA KEV: CVE-2022-24682 \u2014 Synacor Zimbra Collaborate Suite (ZCS) Cross-Site Scripting Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-02-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-02-25"
    },
    {
      "value": "mail.bruising-intellect.ml",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2622",
          "title": "CISA KEV: CVE-2022-24682 \u2014 Synacor Zimbra Collaborate Suite (ZCS) Cross-Site Scripting Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-02-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-02-25"
    },
    {
      "value": "news-online.ml",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2622",
          "title": "CISA KEV: CVE-2022-24682 \u2014 Synacor Zimbra Collaborate Suite (ZCS) Cross-Site Scripting Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-02-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-02-25"
    },
    {
      "value": "news-voice.ml",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2622",
          "title": "CISA KEV: CVE-2022-24682 \u2014 Synacor Zimbra Collaborate Suite (ZCS) Cross-Site Scripting Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-02-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-02-25"
    },
    {
      "value": "newsonline.gq",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2622",
          "title": "CISA KEV: CVE-2022-24682 \u2014 Synacor Zimbra Collaborate Suite (ZCS) Cross-Site Scripting Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-02-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-02-25"
    },
    {
      "value": "petapixel.fun",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2623",
          "title": "CISA KEV: CVE-2017-8570 \u2014 Microsoft Office Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-02-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-02-25"
    },
    {
      "value": "playquicksand.cf",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2622",
          "title": "CISA KEV: CVE-2022-24682 \u2014 Synacor Zimbra Collaborate Suite (ZCS) Cross-Site Scripting Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-02-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-02-25"
    },
    {
      "value": "playquicksand.gq",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2622",
          "title": "CISA KEV: CVE-2022-24682 \u2014 Synacor Zimbra Collaborate Suite (ZCS) Cross-Site Scripting Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-02-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-02-25"
    },
    {
      "value": "playquicksand.ml",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2622",
          "title": "CISA KEV: CVE-2022-24682 \u2014 Synacor Zimbra Collaborate Suite (ZCS) Cross-Site Scripting Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-02-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-02-25"
    },
    {
      "value": "playquicksand.tk",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2622",
          "title": "CISA KEV: CVE-2022-24682 \u2014 Synacor Zimbra Collaborate Suite (ZCS) Cross-Site Scripting Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-02-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-02-25"
    },
    {
      "value": "secretstep.tk",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2622",
          "title": "CISA KEV: CVE-2022-24682 \u2014 Synacor Zimbra Collaborate Suite (ZCS) Cross-Site Scripting Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-02-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-02-25"
    },
    {
      "value": "spiritfield.cf",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2622",
          "title": "CISA KEV: CVE-2022-24682 \u2014 Synacor Zimbra Collaborate Suite (ZCS) Cross-Site Scripting Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-02-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-02-25"
    },
    {
      "value": "spiritfield.ga",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2622",
          "title": "CISA KEV: CVE-2022-24682 \u2014 Synacor Zimbra Collaborate Suite (ZCS) Cross-Site Scripting Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-02-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-02-25"
    },
    {
      "value": "spiritfield.ml",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2622",
          "title": "CISA KEV: CVE-2022-24682 \u2014 Synacor Zimbra Collaborate Suite (ZCS) Cross-Site Scripting Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-02-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-02-25"
    },
    {
      "value": "spiritfield.tk",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2622",
          "title": "CISA KEV: CVE-2022-24682 \u2014 Synacor Zimbra Collaborate Suite (ZCS) Cross-Site Scripting Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-02-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-02-25"
    },
    {
      "value": "spiritx.ga",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2622",
          "title": "CISA KEV: CVE-2022-24682 \u2014 Synacor Zimbra Collaborate Suite (ZCS) Cross-Site Scripting Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-02-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-02-25"
    },
    {
      "value": "thunderchannel.cf",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2622",
          "title": "CISA KEV: CVE-2022-24682 \u2014 Synacor Zimbra Collaborate Suite (ZCS) Cross-Site Scripting Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-02-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-02-25"
    },
    {
      "value": "thunderchannel.tk",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2622",
          "title": "CISA KEV: CVE-2022-24682 \u2014 Synacor Zimbra Collaborate Suite (ZCS) Cross-Site Scripting Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-02-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-02-25"
    },
    {
      "value": "update.secretstep.tk",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2622",
          "title": "CISA KEV: CVE-2022-24682 \u2014 Synacor Zimbra Collaborate Suite (ZCS) Cross-Site Scripting Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-02-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-02-25"
    },
    {
      "value": "weavesilk.space",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2623",
          "title": "CISA KEV: CVE-2017-8570 \u2014 Microsoft Office Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-02-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-02-25"
    },
    {
      "value": "windsoft.cf",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2622",
          "title": "CISA KEV: CVE-2022-24682 \u2014 Synacor Zimbra Collaborate Suite (ZCS) Cross-Site Scripting Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-02-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-02-25"
    },
    {
      "value": "yahoo-corporation.ml",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2622",
          "title": "CISA KEV: CVE-2022-24682 \u2014 Synacor Zimbra Collaborate Suite (ZCS) Cross-Site Scripting Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-02-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-02-25"
    },
    {
      "value": "yahoo-corporation.tk",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2622",
          "title": "CISA KEV: CVE-2022-24682 \u2014 Synacor Zimbra Collaborate Suite (ZCS) Cross-Site Scripting Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-02-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-02-25"
    },
    {
      "value": "108.160.133.32",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2622",
          "title": "CISA KEV: CVE-2022-24682 \u2014 Synacor Zimbra Collaborate Suite (ZCS) Cross-Site Scripting Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-02-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-02-25"
    },
    {
      "value": "172.86.75.158",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2622",
          "title": "CISA KEV: CVE-2022-24682 \u2014 Synacor Zimbra Collaborate Suite (ZCS) Cross-Site Scripting Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-02-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-02-25"
    },
    {
      "value": "206.166.251.141",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2622",
          "title": "CISA KEV: CVE-2022-24682 \u2014 Synacor Zimbra Collaborate Suite (ZCS) Cross-Site Scripting Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-02-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-02-25"
    },
    {
      "value": "206.166.251.166",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2622",
          "title": "CISA KEV: CVE-2022-24682 \u2014 Synacor Zimbra Collaborate Suite (ZCS) Cross-Site Scripting Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-02-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-02-25"
    },
    {
      "value": "CVE-2022-24086",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "Snyk",
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2627",
          "title": "Magento security requires additional patch to fix sanitization vulnerability",
          "link": "https://snyk.io/blog/magento-vulnerability-cve-2022-24087-sanitization/",
          "published": "2022-02-24",
          "sev": "crit"
        },
        {
          "id": "art-2633",
          "title": "CVE-2022-24086 Vulnerability alert for websites using Magento Ecommerce",
          "link": "https://snyk.io/blog/vulnerability-alert-for-websites-using-magento-ecommerce/",
          "published": "2022-02-17",
          "sev": "crit"
        },
        {
          "id": "art-2639",
          "title": "CISA KEV: CVE-2022-24086 \u2014 Adobe Commerce and Magento Open Source Improper Input Validation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-02-15",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-02-24"
    },
    {
      "value": "CVE-2022-24087",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "Snyk",
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2627",
          "title": "Magento security requires additional patch to fix sanitization vulnerability",
          "link": "https://snyk.io/blog/magento-vulnerability-cve-2022-24087-sanitization/",
          "published": "2022-02-24",
          "sev": "crit"
        },
        {
          "id": "art-2633",
          "title": "CVE-2022-24086 Vulnerability alert for websites using Magento Ecommerce",
          "link": "https://snyk.io/blog/vulnerability-alert-for-websites-using-magento-ecommerce/",
          "published": "2022-02-17",
          "sev": "crit"
        },
        {
          "id": "art-2639",
          "title": "CISA KEV: CVE-2022-24086 \u2014 Adobe Commerce and Magento Open Source Improper Input Validation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-02-15",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-02-24"
    },
    {
      "value": "45.134.20.11",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "Snyk",
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2627",
          "title": "Magento security requires additional patch to fix sanitization vulnerability",
          "link": "https://snyk.io/blog/magento-vulnerability-cve-2022-24087-sanitization/",
          "published": "2022-02-24",
          "sev": "crit"
        },
        {
          "id": "art-2633",
          "title": "CVE-2022-24086 Vulnerability alert for websites using Magento Ecommerce",
          "link": "https://snyk.io/blog/vulnerability-alert-for-websites-using-magento-ecommerce/",
          "published": "2022-02-17",
          "sev": "crit"
        },
        {
          "id": "art-2639",
          "title": "CISA KEV: CVE-2022-24086 \u2014 Adobe Commerce and Magento Open Source Improper Input Validation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-02-15",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-02-24"
    },
    {
      "value": "CVE-2022-23131",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2629",
          "title": "CISA KEV: CVE-2022-23131 \u2014 Zabbix Frontend Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-02-22",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-02-22"
    },
    {
      "value": "CVE-2022-23134",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2630",
          "title": "CISA KEV: CVE-2022-23134 \u2014 Zabbix Frontend Improper Access Control Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-02-22",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-02-22"
    },
    {
      "value": "CVE-2013-3906",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2647",
          "title": "CISA KEV: CVE-2013-3906 \u2014 Microsoft Graphics Component Memory Corruption Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-02-15",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-02-15"
    },
    {
      "value": "CVE-2014-1761",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2646",
          "title": "CISA KEV: CVE-2014-1761 \u2014 Microsoft Word Memory Corruption Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-02-15",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-02-15"
    },
    {
      "value": "CVE-2018-15982",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2644",
          "title": "CISA KEV: CVE-2018-15982 \u2014 Adobe Flash Player Use-After-Free Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-02-15",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-02-15"
    },
    {
      "value": "CVE-2018-20250",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2643",
          "title": "CISA KEV: CVE-2018-20250 \u2014 WinRAR Absolute Path Traversal Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-02-15",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-02-15"
    },
    {
      "value": "CVE-2019-0752",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2641",
          "title": "CISA KEV: CVE-2019-0752 \u2014 Microsoft Internet Explorer Type Confusion Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-02-15",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-02-15"
    },
    {
      "value": "CVE-2021-23727",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-2637",
          "title": "Case study: Python RCE vulnerability in Celery",
          "link": "https://snyk.io/blog/python-rce-vulnerability/",
          "published": "2022-02-15",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-02-15"
    },
    {
      "value": "CVE-2022-0609",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2640",
          "title": "CISA KEV: CVE-2022-0609 \u2014 Google Chromium Animation Use-After-Free Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-02-15",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-02-15"
    },
    {
      "value": "blockchainnews.vip",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2640",
          "title": "CISA KEV: CVE-2022-0609 \u2014 Google Chromium Animation Use-After-Free Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-02-15",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-02-15"
    },
    {
      "value": "chainnews-star.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2640",
          "title": "CISA KEV: CVE-2022-0609 \u2014 Google Chromium Animation Use-After-Free Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-02-15",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-02-15"
    },
    {
      "value": "colasprint.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2640",
          "title": "CISA KEV: CVE-2022-0609 \u2014 Google Chromium Animation Use-After-Free Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-02-15",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-02-15"
    },
    {
      "value": "disneycareers.net",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2640",
          "title": "CISA KEV: CVE-2022-0609 \u2014 Google Chromium Animation Use-After-Free Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-02-15",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-02-15"
    },
    {
      "value": "financialtimes365.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2640",
          "title": "CISA KEV: CVE-2022-0609 \u2014 Google Chromium Animation Use-After-Free Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-02-15",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-02-15"
    },
    {
      "value": "find-dreamjob.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2640",
          "title": "CISA KEV: CVE-2022-0609 \u2014 Google Chromium Animation Use-After-Free Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-02-15",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-02-15"
    },
    {
      "value": "fireblocks.vip",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2640",
          "title": "CISA KEV: CVE-2022-0609 \u2014 Google Chromium Animation Use-After-Free Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-02-15",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-02-15"
    },
    {
      "value": "gatexpiring.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2640",
          "title": "CISA KEV: CVE-2022-0609 \u2014 Google Chromium Animation Use-After-Free Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-02-15",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-02-15"
    },
    {
      "value": "gbclabs.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2640",
          "title": "CISA KEV: CVE-2022-0609 \u2014 Google Chromium Animation Use-After-Free Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-02-15",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-02-15"
    },
    {
      "value": "giantblock.org",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2640",
          "title": "CISA KEV: CVE-2022-0609 \u2014 Google Chromium Animation Use-After-Free Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-02-15",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-02-15"
    },
    {
      "value": "humingbot.io",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2640",
          "title": "CISA KEV: CVE-2022-0609 \u2014 Google Chromium Animation Use-After-Free Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-02-15",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-02-15"
    },
    {
      "value": "indeedus.org",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2640",
          "title": "CISA KEV: CVE-2022-0609 \u2014 Google Chromium Animation Use-After-Free Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-02-15",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-02-15"
    },
    {
      "value": "onlynova.org",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2640",
          "title": "CISA KEV: CVE-2022-0609 \u2014 Google Chromium Animation Use-After-Free Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-02-15",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-02-15"
    },
    {
      "value": "teenbeanjs.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2640",
          "title": "CISA KEV: CVE-2022-0609 \u2014 Google Chromium Animation Use-After-Free Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-02-15",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-02-15"
    },
    {
      "value": "varietyjob.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2640",
          "title": "CISA KEV: CVE-2022-0609 \u2014 Google Chromium Animation Use-After-Free Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-02-15",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-02-15"
    },
    {
      "value": "ziprecruiters.org",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2640",
          "title": "CISA KEV: CVE-2022-0609 \u2014 Google Chromium Animation Use-After-Free Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-02-15",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-02-15"
    },
    {
      "value": "116.99.50.13",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2645",
          "title": "CISA KEV: CVE-2017-9841 \u2014 PHPUnit Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-02-15",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-02-15"
    },
    {
      "value": "125.135.169.171",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2645",
          "title": "CISA KEV: CVE-2017-9841 \u2014 PHPUnit Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-02-15",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-02-15"
    },
    {
      "value": "167.86.88.40",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2645",
          "title": "CISA KEV: CVE-2017-9841 \u2014 PHPUnit Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-02-15",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-02-15"
    },
    {
      "value": "185.177.72.51",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2645",
          "title": "CISA KEV: CVE-2017-9841 \u2014 PHPUnit Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-02-15",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-02-15"
    },
    {
      "value": "185.177.72.68",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2645",
          "title": "CISA KEV: CVE-2017-9841 \u2014 PHPUnit Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-02-15",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-02-15"
    },
    {
      "value": "185.38.148.2",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2645",
          "title": "CISA KEV: CVE-2017-9841 \u2014 PHPUnit Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-02-15",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-02-15"
    },
    {
      "value": "66.179.137.126",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2645",
          "title": "CISA KEV: CVE-2017-9841 \u2014 PHPUnit Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-02-15",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-02-15"
    },
    {
      "value": "83.168.88.41",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2645",
          "title": "CISA KEV: CVE-2017-9841 \u2014 PHPUnit Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-02-15",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-02-15"
    },
    {
      "value": "7dd89c99ed7cec0ebc4afa8cd010f1f1",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2647",
          "title": "CISA KEV: CVE-2013-3906 \u2014 Microsoft Graphics Component Memory Corruption Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-02-15",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-02-15"
    },
    {
      "value": "03a41d29e3c9763093aca13f1cc8bcc41b201a6839c381aaaccf891204335685",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2640",
          "title": "CISA KEV: CVE-2022-0609 \u2014 Google Chromium Animation Use-After-Free Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-02-15",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-02-15"
    },
    {
      "value": "CVE-2022-22620",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2649",
          "title": "CISA KEV: CVE-2022-22620 \u2014 Apple iOS, iPadOS, and macOS Webkit Use-After-Free Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-02-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-02-11"
    },
    {
      "value": "CVE-2014-4404",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2667",
          "title": "CISA KEV: CVE-2014-4404 \u2014 Apple OS X Heap-Based Buffer Overflow Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-02-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-02-10"
    },
    {
      "value": "CVE-2015-1130",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2666",
          "title": "CISA KEV: CVE-2015-1130 \u2014 Apple OS X Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-02-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-02-10"
    },
    {
      "value": "CVE-2015-1635",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2665",
          "title": "CISA KEV: CVE-2015-1635 \u2014 Microsoft HTTP.sys Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-02-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-02-10"
    },
    {
      "value": "CVE-2015-2051",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2664",
          "title": "CISA KEV: CVE-2015-2051 \u2014 D-Link DIR-645 Router Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-02-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-02-10"
    },
    {
      "value": "CVE-2016-3088",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2663",
          "title": "CISA KEV: CVE-2016-3088 \u2014 Apache ActiveMQ Improper Input Validation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-02-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-02-10"
    },
    {
      "value": "CVE-2017-0144",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2658",
          "title": "CISA KEV: CVE-2017-10271 \u2014 Oracle Corporation WebLogic Server Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-02-10",
          "sev": "crit"
        },
        {
          "id": "art-2662",
          "title": "CISA KEV: CVE-2017-0144 \u2014 Microsoft SMBv1 Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-02-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-02-10"
    },
    {
      "value": "CVE-2017-0145",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2661",
          "title": "CISA KEV: CVE-2017-0145 \u2014 Microsoft SMBv1 Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-02-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-02-10"
    },
    {
      "value": "CVE-2017-0262",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2659",
          "title": "CISA KEV: CVE-2017-0263 \u2014 Microsoft Win32k Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-02-10",
          "sev": "crit"
        },
        {
          "id": "art-2660",
          "title": "CISA KEV: CVE-2017-0262 \u2014 Microsoft Office Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-02-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-02-10"
    },
    {
      "value": "CVE-2017-0263",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2659",
          "title": "CISA KEV: CVE-2017-0263 \u2014 Microsoft Win32k Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-02-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-02-10"
    },
    {
      "value": "CVE-2017-8464",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2657",
          "title": "CISA KEV: CVE-2017-8464 \u2014 Microsoft Windows Shell (.lnk) Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-02-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-02-10"
    },
    {
      "value": "CVE-2017-9791",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2656",
          "title": "CISA KEV: CVE-2017-9791 \u2014 Apache Struts 1 Improper Input Validation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-02-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-02-10"
    },
    {
      "value": "CVE-2019-2725",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2658",
          "title": "CISA KEV: CVE-2017-10271 \u2014 Oracle Corporation WebLogic Server Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-02-10",
          "sev": "crit"
        },
        {
          "id": "art-2722",
          "title": "CISA KEV: CVE-2019-2725 \u2014 Oracle WebLogic Server, Injection",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-01-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-02-10"
    },
    {
      "value": "CVE-2020-0796",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2654",
          "title": "CISA KEV: CVE-2020-0796 \u2014 Microsoft SMBv3 Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-02-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-02-10"
    },
    {
      "value": "CVE-2021-36934",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2653",
          "title": "CISA KEV: CVE-2021-36934 \u2014 Microsoft Windows SAM Local Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-02-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-02-10"
    },
    {
      "value": "CVE-2022-28958",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2664",
          "title": "CISA KEV: CVE-2015-2051 \u2014 D-Link DIR-645 Router Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-02-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-02-10"
    },
    {
      "value": "aplebzu47wgazapdqks6vrcv6zcnjppkbxbr6wketf56nf6aq2nmyoyd.onion",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2658",
          "title": "CISA KEV: CVE-2017-10271 \u2014 Oracle Corporation WebLogic Server Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-02-10",
          "sev": "crit"
        },
        {
          "id": "art-2722",
          "title": "CISA KEV: CVE-2019-2725 \u2014 Oracle WebLogic Server, Injection",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-01-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-02-10"
    },
    {
      "value": "decryptor.top",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2658",
          "title": "CISA KEV: CVE-2017-10271 \u2014 Oracle Corporation WebLogic Server Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-02-10",
          "sev": "crit"
        },
        {
          "id": "art-2722",
          "title": "CISA KEV: CVE-2019-2725 \u2014 Oracle WebLogic Server, Injection",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-01-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-02-10"
    },
    {
      "value": "vpn.komaru.today",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2664",
          "title": "CISA KEV: CVE-2015-2051 \u2014 D-Link DIR-645 Router Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-02-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-02-10"
    },
    {
      "value": "wmdmediacodecs.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2659",
          "title": "CISA KEV: CVE-2017-0263 \u2014 Microsoft Win32k Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-02-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-02-10"
    },
    {
      "value": "107.174.47.156",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2658",
          "title": "CISA KEV: CVE-2017-10271 \u2014 Oracle Corporation WebLogic Server Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-02-10",
          "sev": "crit"
        },
        {
          "id": "art-2722",
          "title": "CISA KEV: CVE-2019-2725 \u2014 Oracle WebLogic Server, Injection",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-01-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-02-10"
    },
    {
      "value": "159.203.15.179",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2664",
          "title": "CISA KEV: CVE-2015-2051 \u2014 D-Link DIR-645 Router Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-02-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-02-10"
    },
    {
      "value": "165.22.155.69",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2658",
          "title": "CISA KEV: CVE-2017-10271 \u2014 Oracle Corporation WebLogic Server Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-02-10",
          "sev": "crit"
        },
        {
          "id": "art-2722",
          "title": "CISA KEV: CVE-2019-2725 \u2014 Oracle WebLogic Server, Injection",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-01-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-02-10"
    },
    {
      "value": "185.161.70.34",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2658",
          "title": "CISA KEV: CVE-2017-10271 \u2014 Oracle Corporation WebLogic Server Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-02-10",
          "sev": "crit"
        },
        {
          "id": "art-2722",
          "title": "CISA KEV: CVE-2019-2725 \u2014 Oracle WebLogic Server, Injection",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-01-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-02-10"
    },
    {
      "value": "188.166.74.218",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2658",
          "title": "CISA KEV: CVE-2017-10271 \u2014 Oracle Corporation WebLogic Server Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-02-10",
          "sev": "crit"
        },
        {
          "id": "art-2722",
          "title": "CISA KEV: CVE-2019-2725 \u2014 Oracle WebLogic Server, Injection",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-01-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-02-10"
    },
    {
      "value": "202.144.193.184",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2658",
          "title": "CISA KEV: CVE-2017-10271 \u2014 Oracle Corporation WebLogic Server Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-02-10",
          "sev": "crit"
        },
        {
          "id": "art-2722",
          "title": "CISA KEV: CVE-2019-2725 \u2014 Oracle WebLogic Server, Injection",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-01-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-02-10"
    },
    {
      "value": "205.185.122.99",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2658",
          "title": "CISA KEV: CVE-2017-10271 \u2014 Oracle Corporation WebLogic Server Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-02-10",
          "sev": "crit"
        },
        {
          "id": "art-2722",
          "title": "CISA KEV: CVE-2019-2725 \u2014 Oracle WebLogic Server, Injection",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-01-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-02-10"
    },
    {
      "value": "26404fede71f3f713175a3a3cebc619b",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2658",
          "title": "CISA KEV: CVE-2017-10271 \u2014 Oracle Corporation WebLogic Server Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-02-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-02-10"
    },
    {
      "value": "3421a769308d39d4e9c7e8caecaf7fc4",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2658",
          "title": "CISA KEV: CVE-2017-10271 \u2014 Oracle Corporation WebLogic Server Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-02-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-02-10"
    },
    {
      "value": "3542ac729035c0f3db186ddf2178b6a0",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2658",
          "title": "CISA KEV: CVE-2017-10271 \u2014 Oracle Corporation WebLogic Server Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-02-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-02-10"
    },
    {
      "value": "3aad3fabf29f9df65dcbd0f308ff0fa8",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2658",
          "title": "CISA KEV: CVE-2017-10271 \u2014 Oracle Corporation WebLogic Server Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-02-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-02-10"
    },
    {
      "value": "933633f2acfc5909c83f5c73b6fc97cc",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2658",
          "title": "CISA KEV: CVE-2017-10271 \u2014 Oracle Corporation WebLogic Server Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-02-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-02-10"
    },
    {
      "value": "9c91b5cf6eced54abb82d1050c5893f2",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2658",
          "title": "CISA KEV: CVE-2017-10271 \u2014 Oracle Corporation WebLogic Server Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-02-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-02-10"
    },
    {
      "value": "b3a831bfa590274902c77b6c7d4c31ae",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2658",
          "title": "CISA KEV: CVE-2017-10271 \u2014 Oracle Corporation WebLogic Server Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-02-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-02-10"
    },
    {
      "value": "b47daf937897043745df81f32b9d7565",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2658",
          "title": "CISA KEV: CVE-2017-10271 \u2014 Oracle Corporation WebLogic Server Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-02-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-02-10"
    },
    {
      "value": "d3d10faa69a10ac754e3b7dde9178c22",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2658",
          "title": "CISA KEV: CVE-2017-10271 \u2014 Oracle Corporation WebLogic Server Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-02-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-02-10"
    },
    {
      "value": "f8e92d8b5488ea76c40601c8f1a08790",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2659",
          "title": "CISA KEV: CVE-2017-0263 \u2014 Microsoft Win32k Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-02-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-02-10"
    },
    {
      "value": "33135d6e0b8ac14693758ca2e37f27059e202ee72b419ab362fc07d232bb8a10",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2658",
          "title": "CISA KEV: CVE-2017-10271 \u2014 Oracle Corporation WebLogic Server Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-02-10",
          "sev": "crit"
        },
        {
          "id": "art-2722",
          "title": "CISA KEV: CVE-2019-2725 \u2014 Oracle WebLogic Server, Injection",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-01-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-02-10"
    },
    {
      "value": "3e35f125ea1256a443dcc4eee612f87025f9af7c45a22e95e5a2bd3e53f491eb",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2658",
          "title": "CISA KEV: CVE-2017-10271 \u2014 Oracle Corporation WebLogic Server Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-02-10",
          "sev": "crit"
        },
        {
          "id": "art-2722",
          "title": "CISA KEV: CVE-2019-2725 \u2014 Oracle WebLogic Server, Injection",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-01-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-02-10"
    },
    {
      "value": "46BB6E2F80B6CB96FF7D0F78B3BDBC496B69EB7F22CE15EFCAA275F07CFAE075",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2664",
          "title": "CISA KEV: CVE-2015-2051 \u2014 D-Link DIR-645 Router Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-02-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-02-10"
    },
    {
      "value": "4f9020f7e1c2a43a08c117b8d3323421eb1c920b5bad70adb92cbbf882cdf3a9",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2658",
          "title": "CISA KEV: CVE-2017-10271 \u2014 Oracle Corporation WebLogic Server Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-02-10",
          "sev": "crit"
        },
        {
          "id": "art-2722",
          "title": "CISA KEV: CVE-2019-2725 \u2014 Oracle WebLogic Server, Injection",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-01-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-02-10"
    },
    {
      "value": "B7EE57A42C6A4545AC6D6C29E1075FA1628E1D09B8C1572C848A70112D4C90A1",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2664",
          "title": "CISA KEV: CVE-2015-2051 \u2014 D-Link DIR-645 Router Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-02-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-02-10"
    },
    {
      "value": "c213492008177ae1cda8903a46fb1b766f41c58051f1527237a597243885a87e",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2658",
          "title": "CISA KEV: CVE-2017-10271 \u2014 Oracle Corporation WebLogic Server Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-02-10",
          "sev": "crit"
        },
        {
          "id": "art-2722",
          "title": "CISA KEV: CVE-2019-2725 \u2014 Oracle WebLogic Server, Injection",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-01-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-02-10"
    },
    {
      "value": "c799b4a7d14bb911e40c427517eeef96111383a4b3960c8707a27055eef8ecb0",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2658",
          "title": "CISA KEV: CVE-2017-10271 \u2014 Oracle Corporation WebLogic Server Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-02-10",
          "sev": "crit"
        },
        {
          "id": "art-2722",
          "title": "CISA KEV: CVE-2019-2725 \u2014 Oracle WebLogic Server, Injection",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-01-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-02-10"
    },
    {
      "value": "CVE-2022-1025",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-2651",
          "title": "Lessons learned from the Argo CD zero-day vulnerability (CVE-2022-24348)",
          "link": "https://snyk.io/blog/argo-cd-zero-day-cve-2022-24348-lessons-supply-chain/",
          "published": "2022-02-10",
          "sev": "high"
        }
      ],
      "first_seen": "2022-02-10"
    },
    {
      "value": "CVE-2022-24348",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-2651",
          "title": "Lessons learned from the Argo CD zero-day vulnerability (CVE-2022-24348)",
          "link": "https://snyk.io/blog/argo-cd-zero-day-cve-2022-24348-lessons-supply-chain/",
          "published": "2022-02-10",
          "sev": "high"
        }
      ],
      "first_seen": "2022-02-10"
    },
    {
      "value": "CVE-2022-21882",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2673",
          "title": "CISA KEV: CVE-2022-21882 \u2014 Microsoft Win32k Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-02-04",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-02-04"
    },
    {
      "value": "CVE-2014-1776",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2683",
          "title": "CISA KEV: CVE-2014-1776 \u2014 Microsoft Internet Explorer Memory Corruption Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-01-28",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-01-28"
    },
    {
      "value": "CVE-2017-5689",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2682",
          "title": "CISA KEV: CVE-2017-5689 \u2014 Intel Active Management Technology (AMT), Small Business Technology (SBT), and Standard Manageability Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-01-28",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-01-28"
    },
    {
      "value": "CVE-2020-0787",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2681",
          "title": "CISA KEV: CVE-2020-0787 \u2014 Microsoft Windows Background Intelligent Transfer Service (BITS) Improper Privilege Management Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-01-28",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-01-28"
    },
    {
      "value": "CVE-2020-5722",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2680",
          "title": "CISA KEV: CVE-2020-5722 \u2014 Grandstream Networks UCM6200 Series SQL Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-01-28",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-01-28"
    },
    {
      "value": "CVE-2022-22587",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2678",
          "title": "CISA KEV: CVE-2022-22587 \u2014 Apple Memory Corruption Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-01-28",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-01-28"
    },
    {
      "value": "evil.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-2688",
          "title": "Stranger Danger: Live hack of how a Log4Shell exploit works",
          "link": "https://snyk.io/blog/stranger-danger-live-hack-log4shell-exploit/",
          "published": "2022-01-25",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-01-25"
    },
    {
      "value": "CVE-2006-1547",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2690",
          "title": "CISA KEV: CVE-2006-1547 \u2014 Apache Struts 1 ActionForm Denial-of-Service Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-01-21",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-01-21"
    },
    {
      "value": "CVE-2012-0391",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2691",
          "title": "CISA KEV: CVE-2012-0391 \u2014 Apache Struts 2 Improper Input Validation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-01-21",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-01-21"
    },
    {
      "value": "CVE-2018-8453",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2692",
          "title": "CISA KEV: CVE-2018-8453 \u2014 Microsoft Win32k Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-01-21",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-01-21"
    },
    {
      "value": "CVE-2021-35247",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2693",
          "title": "CISA KEV: CVE-2021-35247 \u2014 SolarWinds Serv-U Improper Input Validation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-01-21",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-01-21"
    },
    {
      "value": "api.rogerscorp.org",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2693",
          "title": "CISA KEV: CVE-2021-35247 \u2014 SolarWinds Serv-U Improper Input Validation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-01-21",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-01-21"
    },
    {
      "value": "api.sophosantivirus.ga",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2693",
          "title": "CISA KEV: CVE-2021-35247 \u2014 SolarWinds Serv-U Improper Input Validation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-01-21",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-01-21"
    },
    {
      "value": "apicon.nvidialab.us",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2693",
          "title": "CISA KEV: CVE-2021-35247 \u2014 SolarWinds Serv-U Improper Input Validation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-01-21",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-01-21"
    },
    {
      "value": "service.trendmrcio.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2693",
          "title": "CISA KEV: CVE-2021-35247 \u2014 SolarWinds Serv-U Improper Input Validation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-01-21",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-01-21"
    },
    {
      "value": "shelves-design.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2692",
          "title": "CISA KEV: CVE-2018-8453 \u2014 Microsoft Win32k Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-01-21",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-01-21"
    },
    {
      "value": "w2zmii7kjb81pfj0ped16kg8szyvmk.burpcollaborator.net",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2693",
          "title": "CISA KEV: CVE-2021-35247 \u2014 SolarWinds Serv-U Improper Input Validation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-01-21",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-01-21"
    },
    {
      "value": "weekendstrips.net",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2692",
          "title": "CISA KEV: CVE-2018-8453 \u2014 Microsoft Win32k Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-01-21",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-01-21"
    },
    {
      "value": "139.180.217.203",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2693",
          "title": "CISA KEV: CVE-2021-35247 \u2014 SolarWinds Serv-U Improper Input Validation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-01-21",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-01-21"
    },
    {
      "value": "CVE-2020-11978",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2708",
          "title": "CISA KEV: CVE-2020-11978 \u2014 Apache Airflow Command Injection",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-01-18",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-01-18"
    },
    {
      "value": "CVE-2020-13671",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2707",
          "title": "CISA KEV: CVE-2020-13671 \u2014 Drupal core Un-restricted Upload of File",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-01-18",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-01-18"
    },
    {
      "value": "CVE-2020-13927",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2709",
          "title": "CISA KEV: CVE-2020-13927 \u2014 Apache Airflow's Experimental API Authentication Bypass",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-01-18",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-01-18"
    },
    {
      "value": "CVE-2020-14864",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2706",
          "title": "CISA KEV: CVE-2020-14864 \u2014 Oracle Business Intelligence Enterprise Edition Path Transversal",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-01-18",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-01-18"
    },
    {
      "value": "CVE-2021-21315",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2704",
          "title": "CISA KEV: CVE-2021-21315 \u2014 System Information Library for Node.JS Command Injection",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-01-18",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-01-18"
    },
    {
      "value": "CVE-2021-21975",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2703",
          "title": "CISA KEV: CVE-2021-21975 \u2014 VMware Server Side Request Forgery in vRealize Operations Manager API",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-01-18",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-01-18"
    },
    {
      "value": "CVE-2021-21983",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2703",
          "title": "CISA KEV: CVE-2021-21975 \u2014 VMware Server Side Request Forgery in vRealize Operations Manager API",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-01-18",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-01-18"
    },
    {
      "value": "CVE-2021-22991",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2705",
          "title": "CISA KEV: CVE-2021-22991 \u2014 F5 BIG-IP Traffic Management Microkernel Buffer Overflow",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-01-18",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-01-18"
    },
    {
      "value": "CVE-2021-25296",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2698",
          "title": "CISA KEV: CVE-2021-25296 \u2014 Nagios XI OS Command Injection",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-01-18",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-01-18"
    },
    {
      "value": "CVE-2021-25297",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2699",
          "title": "CISA KEV: CVE-2021-25297 \u2014 Nagios XI OS Command Injection",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-01-18",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-01-18"
    },
    {
      "value": "CVE-2021-25298",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2700",
          "title": "CISA KEV: CVE-2021-25298 \u2014 Nagios XI OS Command Injection",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-01-18",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-01-18"
    },
    {
      "value": "CVE-2021-32648",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2697",
          "title": "CISA KEV: CVE-2021-32648 \u2014 October CMS Improper Authentication",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-01-18",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-01-18"
    },
    {
      "value": "CVE-2021-33766",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2702",
          "title": "CISA KEV: CVE-2021-33766 \u2014 Microsoft Exchange Server Information Disclosure",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-01-18",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-01-18"
    },
    {
      "value": "CVE-2021-40870",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2701",
          "title": "CISA KEV: CVE-2021-40870 \u2014 Aviatrix Controller Unrestricted Upload of File",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-01-18",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-01-18"
    },
    {
      "value": "a196c6b8ffcb97ffb276d04f354696e2391311db3841ae16c8c9f56f36a38e92",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2697",
          "title": "CISA KEV: CVE-2021-32648 \u2014 October CMS Improper Authentication",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-01-18",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-01-18"
    },
    {
      "value": "brianvermeer.nl",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "med",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-2713",
          "title": "New years resolution: Don\u2019t show my security tokens when hacking my demo application on stage",
          "link": "https://snyk.io/blog/dont-show-security-tokens-on-stage/",
          "published": "2022-01-12",
          "sev": "med"
        }
      ],
      "first_seen": "2022-01-12"
    },
    {
      "value": "CVE-2013-3900",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2721",
          "title": "CISA KEV: CVE-2013-3900 \u2014 Microsoft WinVerifyTrust function Remote Code Execution",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-01-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-01-10"
    },
    {
      "value": "CVE-2015-7450",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2728",
          "title": "CISA KEV: CVE-2015-7450 \u2014 IBM WebSphere Application Server and Server Hypervisor Edition Code Injection.",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-01-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-01-10"
    },
    {
      "value": "CVE-2017-1000486",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2729",
          "title": "CISA KEV: CVE-2017-1000486 \u2014 Primetek Primefaces Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-01-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-01-10"
    },
    {
      "value": "CVE-2018-13382",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2724",
          "title": "CISA KEV: CVE-2018-13382 \u2014 Fortinet FortiOS and FortiProxy Improper Authorization",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-01-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-01-10"
    },
    {
      "value": "CVE-2018-13383",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2725",
          "title": "CISA KEV: CVE-2018-13383 \u2014 Fortinet FortiOS and FortiProxy Out-of-bounds Write",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-01-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-01-10"
    },
    {
      "value": "CVE-2019-1579",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2726",
          "title": "CISA KEV: CVE-2019-1579 \u2014 Palo Alto Networks PAN-OS Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-01-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-01-10"
    },
    {
      "value": "CVE-2019-7609",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2730",
          "title": "CISA KEV: CVE-2019-7609 \u2014 Kibana Arbitrary Code Execution",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-01-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-01-10"
    },
    {
      "value": "CVE-2020-6572",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2719",
          "title": "CISA KEV: CVE-2020-6572 \u2014 Google Chrome Media Use-After-Free Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-01-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-01-10"
    },
    {
      "value": "CVE-2021-22017",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2717",
          "title": "CISA KEV: CVE-2021-22017 \u2014 VMware vCenter Server Improper Access Control",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-01-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-01-10"
    },
    {
      "value": "CVE-2021-23385",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-2715",
          "title": "URL confusion vulnerabilities in the wild: Exploring parser inconsistencies",
          "link": "https://snyk.io/blog/url-confusion-vulnerabilities/",
          "published": "2022-01-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-01-10"
    },
    {
      "value": "CVE-2021-23393",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-2715",
          "title": "URL confusion vulnerabilities in the wild: Exploring parser inconsistencies",
          "link": "https://snyk.io/blog/url-confusion-vulnerabilities/",
          "published": "2022-01-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-01-10"
    },
    {
      "value": "CVE-2021-23401",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-2715",
          "title": "URL confusion vulnerabilities in the wild: Exploring parser inconsistencies",
          "link": "https://snyk.io/blog/url-confusion-vulnerabilities/",
          "published": "2022-01-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-01-10"
    },
    {
      "value": "CVE-2021-23414",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-2715",
          "title": "URL confusion vulnerabilities in the wild: Exploring parser inconsistencies",
          "link": "https://snyk.io/blog/url-confusion-vulnerabilities/",
          "published": "2022-01-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-01-10"
    },
    {
      "value": "CVE-2021-23435",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-2715",
          "title": "URL confusion vulnerabilities in the wild: Exploring parser inconsistencies",
          "link": "https://snyk.io/blog/url-confusion-vulnerabilities/",
          "published": "2022-01-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-01-10"
    },
    {
      "value": "CVE-2021-27860",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2731",
          "title": "CISA KEV: CVE-2021-27860 \u2014 FatPipe WARP, IPVPN, and MPVPN Configuration Upload exploit",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-01-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-01-10"
    },
    {
      "value": "CVE-2021-32618",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-2715",
          "title": "URL confusion vulnerabilities in the wild: Exploring parser inconsistencies",
          "link": "https://snyk.io/blog/url-confusion-vulnerabilities/",
          "published": "2022-01-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-01-10"
    },
    {
      "value": "CVE-2021-33056",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-2715",
          "title": "URL confusion vulnerabilities in the wild: Exploring parser inconsistencies",
          "link": "https://snyk.io/blog/url-confusion-vulnerabilities/",
          "published": "2022-01-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-01-10"
    },
    {
      "value": "CVE-2021-37352",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-2715",
          "title": "URL confusion vulnerabilities in the wild: Exploring parser inconsistencies",
          "link": "https://snyk.io/blog/url-confusion-vulnerabilities/",
          "published": "2022-01-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-01-10"
    },
    {
      "value": "arg0s-co.uk",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2722",
          "title": "CISA KEV: CVE-2019-2725 \u2014 Oracle WebLogic Server, Injection",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-01-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-01-10"
    },
    {
      "value": "hostapp.be",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2727",
          "title": "CISA KEV: CVE-2019-10149 \u2014 Exim Mail Transfer Agent (MTA) Improper Input Validation",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-01-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-01-10"
    },
    {
      "value": "life.zerobytes.cc",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2718",
          "title": "CISA KEV: CVE-2021-36260 \u2014 Hikvision Improper Input Validation",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-01-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-01-10"
    },
    {
      "value": "projectstore.guru",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2722",
          "title": "CISA KEV: CVE-2019-2725 \u2014 Oracle WebLogic Server, Injection",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-01-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-01-10"
    },
    {
      "value": "103.94.157.5",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2727",
          "title": "CISA KEV: CVE-2019-10149 \u2014 Exim Mail Transfer Agent (MTA) Improper Input Validation",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-01-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-01-10"
    },
    {
      "value": "130.61.54.136",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2722",
          "title": "CISA KEV: CVE-2019-2725 \u2014 Oracle WebLogic Server, Injection",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-01-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-01-10"
    },
    {
      "value": "165.227.78.159",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2722",
          "title": "CISA KEV: CVE-2019-2725 \u2014 Oracle WebLogic Server, Injection",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-01-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-01-10"
    },
    {
      "value": "173.212.214.137",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2727",
          "title": "CISA KEV: CVE-2019-10149 \u2014 Exim Mail Transfer Agent (MTA) Improper Input Validation",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-01-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-01-10"
    },
    {
      "value": "185.106.120.118",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2723",
          "title": "CISA KEV: CVE-2019-9670 \u2014 Synacor Zimbra Collaboration Suite (ZCS) Improper Restriction of XML External Entity Reference",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-01-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-01-10"
    },
    {
      "value": "199.195.250.233",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2718",
          "title": "CISA KEV: CVE-2021-36260 \u2014 Hikvision Improper Input Validation",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-01-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-01-10"
    },
    {
      "value": "45.146.165.123",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2723",
          "title": "CISA KEV: CVE-2019-9670 \u2014 Synacor Zimbra Collaboration Suite (ZCS) Improper Restriction of XML External Entity Reference",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-01-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-01-10"
    },
    {
      "value": "45.55.211.79",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2722",
          "title": "CISA KEV: CVE-2019-2725 \u2014 Oracle WebLogic Server, Injection",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-01-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-01-10"
    },
    {
      "value": "95.216.13.196",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2727",
          "title": "CISA KEV: CVE-2019-10149 \u2014 Exim Mail Transfer Agent (MTA) Improper Input Validation",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-01-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-01-10"
    },
    {
      "value": "0fa207940ea53e2b54a2b769d8ab033a6b2c5e08c78bf4d7dade79849960b54d",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2722",
          "title": "CISA KEV: CVE-2019-2725 \u2014 Oracle WebLogic Server, Injection",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-01-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-01-10"
    },
    {
      "value": "1dce6f3ba4a8d355df21a17584c514697ee0c37b51ab5657bc5b3a297b65955f",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2718",
          "title": "CISA KEV: CVE-2021-36260 \u2014 Hikvision Improper Input Validation",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-01-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-01-10"
    },
    {
      "value": "34dffdb04ca07b014cdaee857690f86e490050335291ccc84c94994fa91e0160",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2722",
          "title": "CISA KEV: CVE-2019-2725 \u2014 Oracle WebLogic Server, Injection",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-01-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-01-10"
    },
    {
      "value": "38414bb5850a7076f4b33bf81bac9db0376a4df188355fac39d80193d7c7f557",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2718",
          "title": "CISA KEV: CVE-2021-36260 \u2014 Hikvision Improper Input Validation",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-01-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-01-10"
    },
    {
      "value": "74bc2f9a81ad2cc609b7730dbabb146506f58244e5e655cbb42044913384a6ac",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2722",
          "title": "CISA KEV: CVE-2019-2725 \u2014 Oracle WebLogic Server, Injection",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-01-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-01-10"
    },
    {
      "value": "95ac3903127b74f8e4d73d987f5e3736f5bdd909ba756260e187b6bf53fb1a05",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2722",
          "title": "CISA KEV: CVE-2019-2725 \u2014 Oracle WebLogic Server, Injection",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-01-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-01-10"
    },
    {
      "value": "fa2bccdb9db2583c2f9ff6a536e824f4311c9a8a9842505a0323f027b8b51451",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2722",
          "title": "CISA KEV: CVE-2019-2725 \u2014 Oracle WebLogic Server, Injection",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2022-01-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-01-10"
    },
    {
      "value": "CVE-2021-23567",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-2732",
          "title": "Open source maintainer pulls the plug on npm packages colors and faker, now what?",
          "link": "https://snyk.io/blog/open-source-npm-packages-colors-faker/",
          "published": "2022-01-09",
          "sev": "crit"
        }
      ],
      "first_seen": "2022-01-09"
    },
    {
      "value": "CVE-2021-44832",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-2739",
          "title": "New Log4j 2.17.1 fixes CVE-2021-44832 remote code execution (but it\u2019s not as bad as it sounds)",
          "link": "https://snyk.io/blog/new-log4j-2-17-1-fixes-cve-2021-44832-remote-code-execution-but-its-not-as-bad-as-it-sounds/",
          "published": "2021-12-29",
          "sev": "high"
        },
        {
          "id": "art-2749",
          "title": "Log4j 2.15 vulnerability CVE-2021-45046 upgraded to a critical severity arbitrary code execution",
          "link": "https://snyk.io/blog/log4j-2-15-vulnerability-cve-2021-45046-critical-ace/",
          "published": "2021-12-17",
          "sev": "high"
        },
        {
          "id": "art-2751",
          "title": "Log4Shell in a nutshell (for non-developers & non-Java developers)",
          "link": "https://snyk.io/blog/log4shell-in-a-nutshell/",
          "published": "2021-12-15",
          "sev": "high"
        },
        {
          "id": "art-2756",
          "title": "The Log4j vulnerability and its impact on software supply chain security",
          "link": "https://snyk.io/blog/log4j-vulnerability-software-supply-chain-security-log4shell/",
          "published": "2021-12-13",
          "sev": "high"
        },
        {
          "id": "art-2757",
          "title": "Find and fix the Log4Shell exploit fast with Snyk",
          "link": "https://snyk.io/blog/find-fix-log4shell-quickly-snyk/",
          "published": "2021-12-13",
          "sev": "high"
        },
        {
          "id": "art-2758",
          "title": "Log4j vulnerability explained: Prevent Log4Shell RCE by updating to version 2.17.1",
          "link": "https://snyk.io/blog/log4j-rce-log4shell-vulnerability-cve-2021-44228/",
          "published": "2021-12-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-12-29"
    },
    {
      "value": "CVE-2021-4104",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-2739",
          "title": "New Log4j 2.17.1 fixes CVE-2021-44832 remote code execution (but it\u2019s not as bad as it sounds)",
          "link": "https://snyk.io/blog/new-log4j-2-17-1-fixes-cve-2021-44832-remote-code-execution-but-its-not-as-bad-as-it-sounds/",
          "published": "2021-12-29",
          "sev": "high"
        },
        {
          "id": "art-2749",
          "title": "Log4j 2.15 vulnerability CVE-2021-45046 upgraded to a critical severity arbitrary code execution",
          "link": "https://snyk.io/blog/log4j-2-15-vulnerability-cve-2021-45046-critical-ace/",
          "published": "2021-12-17",
          "sev": "high"
        },
        {
          "id": "art-2750",
          "title": "Security in context: When is a CVE not a CVE?",
          "link": "https://snyk.io/blog/when-is-a-cve-not-a-cve/",
          "published": "2021-12-17",
          "sev": "high"
        },
        {
          "id": "art-2756",
          "title": "The Log4j vulnerability and its impact on software supply chain security",
          "link": "https://snyk.io/blog/log4j-vulnerability-software-supply-chain-security-log4shell/",
          "published": "2021-12-13",
          "sev": "high"
        }
      ],
      "first_seen": "2021-12-29"
    },
    {
      "value": "CVE-2021-42550",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-2750",
          "title": "Security in context: When is a CVE not a CVE?",
          "link": "https://snyk.io/blog/when-is-a-cve-not-a-cve/",
          "published": "2021-12-17",
          "sev": "high"
        }
      ],
      "first_seen": "2021-12-17"
    },
    {
      "value": "CVE-2021-4102",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2753",
          "title": "CISA KEV: CVE-2021-4102 \u2014 Google Chromium V8 Use-After-Free Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-12-15",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-12-15"
    },
    {
      "value": "CVE-2021-43890",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2752",
          "title": "CISA KEV: CVE-2021-43890 \u2014 Microsoft Windows AppX Installer Spoofing Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-12-15",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-12-15"
    },
    {
      "value": "CVE-2010-1871",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2768",
          "title": "CISA KEV: CVE-2010-1871 \u2014 Red Hat Linux JBoss Seam 2 Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-12-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-12-10"
    },
    {
      "value": "CVE-2017-12149",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2767",
          "title": "CISA KEV: CVE-2017-12149 \u2014 Red Hat JBoss Application Server Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-12-10",
          "sev": "crit"
        },
        {
          "id": "art-2768",
          "title": "CISA KEV: CVE-2010-1871 \u2014 Red Hat Linux JBoss Seam 2 Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-12-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-12-10"
    },
    {
      "value": "CVE-2017-17562",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2766",
          "title": "CISA KEV: CVE-2017-17562 \u2014 Embedthis GoAhead Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-12-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-12-10"
    },
    {
      "value": "CVE-2019-0193",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2764",
          "title": "CISA KEV: CVE-2019-0193 \u2014 Apache Solr DataImportHandler Code Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-12-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-12-10"
    },
    {
      "value": "CVE-2019-10758",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2771",
          "title": "CISA KEV: CVE-2019-10758 \u2014 MongoDB mongo-express Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-12-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-12-10"
    },
    {
      "value": "CVE-2019-13272",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2761",
          "title": "CISA KEV: CVE-2019-13272 \u2014 Linux Kernel Improper Privilege Management Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-12-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-12-10"
    },
    {
      "value": "CVE-2020-17463",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2769",
          "title": "CISA KEV: CVE-2020-17463 \u2014 Fuel CMS SQL Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-12-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-12-10"
    },
    {
      "value": "CVE-2020-8816",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2770",
          "title": "CISA KEV: CVE-2020-8816 \u2014 Pi-Hole AdminLTE Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-12-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-12-10"
    },
    {
      "value": "CVE-2021-35394",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2762",
          "title": "CISA KEV: CVE-2021-35394 \u2014 Realtek Jungle SDK Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-12-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-12-10"
    },
    {
      "value": "CVE-2021-44168",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2765",
          "title": "CISA KEV: CVE-2021-44168 \u2014 Fortinet FortiOS Arbitrary File Download",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-12-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-12-10"
    },
    {
      "value": "CVE-2021-44515",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2760",
          "title": "CISA KEV: CVE-2021-44515 \u2014 Zoho Desktop Central Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-12-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-12-10"
    },
    {
      "value": "103.149.137.124",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2762",
          "title": "CISA KEV: CVE-2021-35394 \u2014 Realtek Jungle SDK Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-12-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-12-10"
    },
    {
      "value": "135.148.104.21",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2762",
          "title": "CISA KEV: CVE-2021-35394 \u2014 Realtek Jungle SDK Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-12-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-12-10"
    },
    {
      "value": "172.81.41.196",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2762",
          "title": "CISA KEV: CVE-2021-35394 \u2014 Realtek Jungle SDK Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-12-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-12-10"
    },
    {
      "value": "185.205.12.157",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2762",
          "title": "CISA KEV: CVE-2021-35394 \u2014 Realtek Jungle SDK Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-12-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-12-10"
    },
    {
      "value": "199.195.251.190",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2762",
          "title": "CISA KEV: CVE-2021-35394 \u2014 Realtek Jungle SDK Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-12-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-12-10"
    },
    {
      "value": "9809bdf6e9981fbc3ad515b731124342",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2760",
          "title": "CISA KEV: CVE-2021-44515 \u2014 Zoho Desktop Central Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-12-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-12-10"
    },
    {
      "value": "178.62.86.114",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-2773",
          "title": "Responsible disclosure: CodeCov CEO & CTO share learnings from the breach",
          "link": "https://snyk.io/blog/codecov-ceo-cto-share-learnings-from-breach-tsd/",
          "published": "2021-12-09",
          "sev": "high"
        }
      ],
      "first_seen": "2021-12-09"
    },
    {
      "value": "185.211.156.78",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-2773",
          "title": "Responsible disclosure: CodeCov CEO & CTO share learnings from the breach",
          "link": "https://snyk.io/blog/codecov-ceo-cto-share-learnings-from-breach-tsd/",
          "published": "2021-12-09",
          "sev": "high"
        }
      ],
      "first_seen": "2021-12-09"
    },
    {
      "value": "79.135.72.34",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "high",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-2773",
          "title": "Responsible disclosure: CodeCov CEO & CTO share learnings from the breach",
          "link": "https://snyk.io/blog/codecov-ceo-cto-share-learnings-from-breach-tsd/",
          "published": "2021-12-09",
          "sev": "high"
        }
      ],
      "first_seen": "2021-12-09"
    },
    {
      "value": "CVE-2019-5481",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-2774",
          "title": "Snyk Open Source adds beta C/C++ security scanning for unmanaged OSS",
          "link": "https://snyk.io/blog/snyk-launches-beta-support-for-cpp/",
          "published": "2021-12-08",
          "sev": "high"
        }
      ],
      "first_seen": "2021-12-08"
    },
    {
      "value": "CVE-2019-5482",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-2774",
          "title": "Snyk Open Source adds beta C/C++ security scanning for unmanaged OSS",
          "link": "https://snyk.io/blog/snyk-launches-beta-support-for-cpp/",
          "published": "2021-12-08",
          "sev": "high"
        }
      ],
      "first_seen": "2021-12-08"
    },
    {
      "value": "CVE-2020-8285",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-2774",
          "title": "Snyk Open Source adds beta C/C++ security scanning for unmanaged OSS",
          "link": "https://snyk.io/blog/snyk-launches-beta-support-for-cpp/",
          "published": "2021-12-08",
          "sev": "high"
        }
      ],
      "first_seen": "2021-12-08"
    },
    {
      "value": "CVE-2020-8286",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-2774",
          "title": "Snyk Open Source adds beta C/C++ security scanning for unmanaged OSS",
          "link": "https://snyk.io/blog/snyk-launches-beta-support-for-cpp/",
          "published": "2021-12-08",
          "sev": "high"
        }
      ],
      "first_seen": "2021-12-08"
    },
    {
      "value": "CVE-2021-22876",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-2774",
          "title": "Snyk Open Source adds beta C/C++ security scanning for unmanaged OSS",
          "link": "https://snyk.io/blog/snyk-launches-beta-support-for-cpp/",
          "published": "2021-12-08",
          "sev": "high"
        }
      ],
      "first_seen": "2021-12-08"
    },
    {
      "value": "CVE-2021-22898",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-2774",
          "title": "Snyk Open Source adds beta C/C++ security scanning for unmanaged OSS",
          "link": "https://snyk.io/blog/snyk-launches-beta-support-for-cpp/",
          "published": "2021-12-08",
          "sev": "high"
        }
      ],
      "first_seen": "2021-12-08"
    },
    {
      "value": "CVE-2018-14847",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2777",
          "title": "CISA KEV: CVE-2018-14847 \u2014 MikroTik Router OS Directory Traversal Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-12-01",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-12-01"
    },
    {
      "value": "CVE-2021-37415",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2778",
          "title": "CISA KEV: CVE-2021-37415 \u2014 Zoho ManageEngine ServiceDesk Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-12-01",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-12-01"
    },
    {
      "value": "CVE-2021-40438",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2779",
          "title": "CISA KEV: CVE-2021-40438 \u2014 Apache HTTP Server-Side Request Forgery (SSRF)",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-12-01",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-12-01"
    },
    {
      "value": "CVE-2021-40539",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2780",
          "title": "CISA KEV: CVE-2021-44077 \u2014 Zoho ManageEngine ServiceDesk Plus Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-12-01",
          "sev": "crit"
        },
        {
          "id": "art-3075",
          "title": "CISA KEV: CVE-2021-40539 \u2014 Zoho ManageEngine ADSelfService Plus Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-12-01"
    },
    {
      "value": "CVE-2021-44077",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2780",
          "title": "CISA KEV: CVE-2021-44077 \u2014 Zoho ManageEngine ServiceDesk Plus Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-12-01",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-12-01"
    },
    {
      "value": "67ee552d7c1d46885b91628c603f24b66a9755858e098748f7e7862a71baa015",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2780",
          "title": "CISA KEV: CVE-2021-44077 \u2014 Zoho ManageEngine ServiceDesk Plus Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-12-01",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-12-01"
    },
    {
      "value": "ecd8c9967b0127a12d6db61964a82970ee5d38f82618d5db4d8eddbb3b5726b7",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2780",
          "title": "CISA KEV: CVE-2021-44077 \u2014 Zoho ManageEngine ServiceDesk Plus Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-12-01",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-12-01"
    },
    {
      "value": "CVE-2019-12384",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "med",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-2775",
          "title": "Java JSON deserialization problems with the Jackson ObjectMapper",
          "link": "https://snyk.io/blog/java-json-deserialization-problems-jackson-objectmapper/",
          "published": "2021-12-01",
          "sev": "med"
        }
      ],
      "first_seen": "2021-12-01"
    },
    {
      "value": "CVE-2021-22204",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2786",
          "title": "CISA KEV: CVE-2021-22204 \u2014 ExifTool Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-17",
          "sev": "crit"
        },
        {
          "id": "art-2878",
          "title": "CISA KEV: CVE-2021-22205 \u2014 GitLab Community and Enterprise Editions Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-17"
    },
    {
      "value": "CVE-2021-40449",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2787",
          "title": "CISA KEV: CVE-2021-40449 \u2014 Microsoft Windows Win32k Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-17",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-17"
    },
    {
      "value": "CVE-2021-42292",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2789",
          "title": "CISA KEV: CVE-2021-42292 \u2014 Microsoft Excel Security Feature Bypass",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-17",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-17"
    },
    {
      "value": "CVE-2021-42321",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2788",
          "title": "CISA KEV: CVE-2021-42321 \u2014 Microsoft Exchange Server Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-17",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-17"
    },
    {
      "value": "CVE-2010-5326",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-3030",
          "title": "CISA KEV: CVE-2010-5326 \u2014 SAP NetWeaver Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "CVE-2012-3152",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-3006",
          "title": "CISA KEV: CVE-2012-3152 \u2014 Oracle Fusion Middleware Unspecified Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "CVE-2012-3153",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-3006",
          "title": "CISA KEV: CVE-2012-3152 \u2014 Oracle Fusion Middleware Unspecified Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "CVE-2014-1812",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2921",
          "title": "CISA KEV: CVE-2014-1812 \u2014 Microsoft Windows Group Policy Preferences Password Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "CVE-2015-1641",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2969",
          "title": "CISA KEV: CVE-2015-1641 \u2014 Microsoft Office Memory Corruption Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "CVE-2015-1805",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2813",
          "title": "CISA KEV: CVE-2019-2215 \u2014 Android Kernel Use-After-Free Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "CVE-2015-3636",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2813",
          "title": "CISA KEV: CVE-2019-2215 \u2014 Android Kernel Use-After-Free Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "CVE-2015-4852",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-3008",
          "title": "CISA KEV: CVE-2015-4852 \u2014 Oracle WebLogic Server Deserialization of Untrusted Data Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "CVE-2016-0167",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2923",
          "title": "CISA KEV: CVE-2016-0167 \u2014 Microsoft Win32k Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        },
        {
          "id": "art-2948",
          "title": "CISA KEV: CVE-2016-7255 \u2014 Microsoft Win32k Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "CVE-2016-0185",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2928",
          "title": "CISA KEV: CVE-2016-0185 \u2014 Microsoft Windows Media Center Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "CVE-2016-3235",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2995",
          "title": "CISA KEV: CVE-2016-3235 \u2014 Microsoft Office OLE DLL Side Loading Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "CVE-2016-3643",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-3038",
          "title": "CISA KEV: CVE-2016-3643 \u2014 SolarWinds Virtualization Manager Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "CVE-2016-3715",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2913",
          "title": "CISA KEV: CVE-2016-3715 \u2014 ImageMagick Arbitrary File Deletion Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "CVE-2016-3718",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2914",
          "title": "CISA KEV: CVE-2016-3718 \u2014 ImageMagick Server-Side Request Forgery (SSRF) Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "CVE-2016-3976",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-3029",
          "title": "CISA KEV: CVE-2018-2380 \u2014 SAP Customer Relationship Management (CRM) Path Traversal Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        },
        {
          "id": "art-3034",
          "title": "CISA KEV: CVE-2016-3976 \u2014 SAP NetWeaver Directory Traversal Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "CVE-2016-4437",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2817",
          "title": "CISA KEV: CVE-2016-4437 \u2014 Apache Shiro Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "CVE-2016-9563",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-3031",
          "title": "CISA KEV: CVE-2016-9563 \u2014 SAP NetWeaver XML External Entity (XXE) Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "CVE-2017-0143",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2947",
          "title": "CISA KEV: CVE-2017-0143 \u2014 Microsoft Windows Server Message Block (SMBv1) Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "CVE-2017-0199",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2976",
          "title": "CISA KEV: CVE-2017-0199 \u2014 Microsoft Office and WordPad Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "CVE-2017-11774",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2979",
          "title": "CISA KEV: CVE-2017-11774 \u2014 Microsoft Office Outlook Security Feature Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "CVE-2017-11882",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2972",
          "title": "CISA KEV: CVE-2017-11882 \u2014 Microsoft Office Memory Corruption Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "CVE-2017-16651",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-3025",
          "title": "CISA KEV: CVE-2017-16651 \u2014 Roundcube Webmail File Disclosure Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "CVE-2017-5638",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2820",
          "title": "CISA KEV: CVE-2017-5638 \u2014 Apache Struts Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "CVE-2017-6327",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-3045",
          "title": "CISA KEV: CVE-2017-6327 \u2014 Symantec Messaging Gateway Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "CVE-2017-7269",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2943",
          "title": "CISA KEV: CVE-2017-7269 \u2014 Microsoft Windows Server Buffer Overflow Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "CVE-2017-8759",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2962",
          "title": "CISA KEV: CVE-2017-8759 \u2014 Microsoft .NET Framework Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        },
        {
          "id": "art-2976",
          "title": "CISA KEV: CVE-2017-0199 \u2014 Microsoft Office and WordPad Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "CVE-2017-9805",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2814",
          "title": "CISA KEV: CVE-2017-9805 \u2014 Apache Struts Deserialization of Untrusted Data Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "CVE-2017-9822",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2874",
          "title": "CISA KEV: CVE-2017-9822 \u2014 DotNetNuke (DNN) Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "CVE-2018-0171",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2858",
          "title": "CISA KEV: CVE-2018-0171 \u2014 Cisco IOS and IOS XE Software Smart Install Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "CVE-2018-0296",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2864",
          "title": "CISA KEV: CVE-2018-0296 \u2014 Cisco Adaptive Security Appliance (ASA) Denial-of-Service Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "CVE-2018-0798",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2967",
          "title": "CISA KEV: CVE-2018-0798 \u2014 Microsoft Office Memory Corruption Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "CVE-2018-0802",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2967",
          "title": "CISA KEV: CVE-2018-0798 \u2014 Microsoft Office Memory Corruption Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "CVE-2018-11776",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2821",
          "title": "CISA KEV: CVE-2018-11776 \u2014 Apache Struts Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "CVE-2018-13379",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2887",
          "title": "CISA KEV: CVE-2018-13379 \u2014 Fortinet FortiOS SSL VPN Path Traversal Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "CVE-2018-15811",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2873",
          "title": "CISA KEV: CVE-2018-15811 \u2014 DotNetNuke (DNN) Inadequate Encryption Strength Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "CVE-2018-15961",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2810",
          "title": "CISA KEV: CVE-2018-15961 \u2014 Adobe ColdFusion Unrestricted File Upload Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "CVE-2018-18325",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2873",
          "title": "CISA KEV: CVE-2018-15811 \u2014 DotNetNuke (DNN) Inadequate Encryption Strength Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "CVE-2018-20062",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-3051",
          "title": "CISA KEV: CVE-2018-20062 \u2014 ThinkPHP \"noneCms\" Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "CVE-2018-2380",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-3029",
          "title": "CISA KEV: CVE-2018-2380 \u2014 SAP Customer Relationship Management (CRM) Path Traversal Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "CVE-2018-4878",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2811",
          "title": "CISA KEV: CVE-2018-4878 \u2014 Adobe Flash Player Use-After-Free Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "CVE-2018-4939",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2809",
          "title": "CISA KEV: CVE-2018-4939 \u2014 Adobe ColdFusion Deserialization of Untrusted Data Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "CVE-2018-6789",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2879",
          "title": "CISA KEV: CVE-2018-6789 \u2014 Exim Buffer Overflow Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "CVE-2018-8653",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2963",
          "title": "CISA KEV: CVE-2018-8653 \u2014 Microsoft Internet Explorer Scripting Engine Memory Corruption Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "CVE-2019-0211",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2816",
          "title": "CISA KEV: CVE-2019-0211 \u2014 Apache HTTP Server Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "CVE-2019-0541",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2971",
          "title": "CISA KEV: CVE-2019-0541 \u2014 Microsoft MSHTML Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "CVE-2019-0604",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2989",
          "title": "CISA KEV: CVE-2019-0604 \u2014 Microsoft SharePoint Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "CVE-2019-0797",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2964",
          "title": "CISA KEV: CVE-2019-0797 \u2014 Microsoft Win32k Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "CVE-2019-0803",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2955",
          "title": "CISA KEV: CVE-2019-0803 \u2014 Microsoft Win32k Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        },
        {
          "id": "art-2966",
          "title": "CISA KEV: CVE-2019-1215 \u2014 Microsoft Windows Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "CVE-2019-0859",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2960",
          "title": "CISA KEV: CVE-2019-0859 \u2014 Microsoft Win32k Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "CVE-2019-0863",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2996",
          "title": "CISA KEV: CVE-2019-0863 \u2014 Microsoft Windows Error Reporting (WER) Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "CVE-2019-11510",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-3019",
          "title": "CISA KEV: CVE-2019-11510 \u2014 Ivanti Pulse Connect Secure Arbitrary File Read Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "CVE-2019-11539",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-3020",
          "title": "CISA KEV: CVE-2019-11539 \u2014 Ivanti Pulse Connect Secure and Policy Secure Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "CVE-2019-11580",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2851",
          "title": "CISA KEV: CVE-2019-11580 \u2014 Atlassian Crowd and Crowd Data Center Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "CVE-2019-11634",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2870",
          "title": "CISA KEV: CVE-2019-11634 \u2014 Citrix Workspace Application and Receiver for Windows Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "CVE-2019-1214",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2994",
          "title": "CISA KEV: CVE-2019-1214 \u2014 Microsoft Windows Privilege Common Log File System (CLFS) Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        },
        {
          "id": "art-2997",
          "title": "CISA KEV: CVE-2021-36955 \u2014 Microsoft Windows Common Log File System (CLFS) Driver Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "CVE-2019-1215",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2966",
          "title": "CISA KEV: CVE-2019-1215 \u2014 Microsoft Windows Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "CVE-2019-13608",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2865",
          "title": "CISA KEV: CVE-2019-13608 \u2014 Citrix StoreFront Server XML External Entity (XXE) Processing Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "CVE-2019-1367",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2975",
          "title": "CISA KEV: CVE-2019-1367 \u2014 Microsoft Internet Explorer Scripting Engine Memory Corruption Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "CVE-2019-1429",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2978",
          "title": "CISA KEV: CVE-2019-1429 \u2014 Microsoft Internet Explorer Scripting Engine Memory Corruption Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "CVE-2019-15752",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2875",
          "title": "CISA KEV: CVE-2019-15752 \u2014 Docker Desktop Community Edition Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "CVE-2019-15949",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-3002",
          "title": "CISA KEV: CVE-2019-15949 \u2014 Nagios XI Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "CVE-2019-16256",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-3035",
          "title": "CISA KEV: CVE-2019-16256 \u2014 SIMalliance Toolbox Browser Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "CVE-2019-16759",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-3062",
          "title": "CISA KEV: CVE-2019-16759 \u2014 vBulletin PHP Module Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "CVE-2019-17026",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-3001",
          "title": "CISA KEV: CVE-2019-17026 \u2014 Mozilla Firefox And Thunderbird Type Confusion Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "CVE-2019-17558",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2818",
          "title": "CISA KEV: CVE-2019-17558 \u2014 Apache Solr VelocityResponseWriter Plug-In Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "CVE-2019-18187",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-3053",
          "title": "CISA KEV: CVE-2019-18187 \u2014 Trend Micro OfficeScan Directory Traversal Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "CVE-2019-18988",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-3046",
          "title": "CISA KEV: CVE-2019-18988 \u2014 TeamViewer Desktop Bypass Remote Login Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "CVE-2019-19356",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-3004",
          "title": "CISA KEV: CVE-2019-19356 \u2014 Netis WF2419 Devices Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "CVE-2019-19781",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2869",
          "title": "CISA KEV: CVE-2019-19781 \u2014 Citrix ADC, Gateway, and SD-WAN WANOP Appliance Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "CVE-2019-20085",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-3060",
          "title": "CISA KEV: CVE-2019-20085 \u2014 TVT NVMS-1000 Directory Traversal Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "CVE-2019-2215",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2813",
          "title": "CISA KEV: CVE-2019-2215 \u2014 Android Kernel Use-After-Free Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "CVE-2019-3396",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2852",
          "title": "CISA KEV: CVE-2019-3396 \u2014 Atlassian Confluence Server and Data Center Server-Side Template Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "CVE-2019-3398",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2849",
          "title": "CISA KEV: CVE-2019-3398 \u2014 Atlassian Confluence Server and Data Center Path Traversal Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "CVE-2019-4716",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2912",
          "title": "CISA KEV: CVE-2019-4716 \u2014 IBM Planning Analytics Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "CVE-2019-5544",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-3063",
          "title": "CISA KEV: CVE-2019-5544 \u2014 VMware ESXi and Horizon DaaS OpenSLP Heap-Based Buffer Overflow Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        },
        {
          "id": "art-3064",
          "title": "CISA KEV: CVE-2020-3992 \u2014 VMware ESXi OpenSLP Use-After-Free Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "CVE-2019-5591",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2885",
          "title": "CISA KEV: CVE-2019-5591 \u2014 Fortinet FortiOS Default Configuration Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "CVE-2019-6223",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2823",
          "title": "CISA KEV: CVE-2019-6223 \u2014 Apple iOS and macOS Group Facetime Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "CVE-2019-7481",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-3041",
          "title": "CISA KEV: CVE-2019-7481 \u2014 SonicWall SMA100 SQL Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        },
        {
          "id": "art-3042",
          "title": "CISA KEV: CVE-2021-20016 \u2014 SonicWall SSLVPN SMA100 SQL Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "CVE-2019-8394",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-3077",
          "title": "CISA KEV: CVE-2019-8394 \u2014 Zoho ManageEngine ServiceDesk Plus (SDP) File Upload Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "CVE-2019-9082",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-3052",
          "title": "CISA KEV: CVE-2019-9082 \u2014 ThinkPHP Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "CVE-2019-9978",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-3073",
          "title": "CISA KEV: CVE-2019-9978 \u2014 WordPress Social Warfare Plugin Cross-Site Scripting (XSS) Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "CVE-2020-0041",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2813",
          "title": "CISA KEV: CVE-2019-2215 \u2014 Android Kernel Use-After-Free Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "CVE-2020-0069",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2813",
          "title": "CISA KEV: CVE-2019-2215 \u2014 Android Kernel Use-After-Free Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "CVE-2020-0601",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2988",
          "title": "CISA KEV: CVE-2020-0601 \u2014 Microsoft Windows CryptoAPI Spoofing Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "CVE-2020-0646",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2990",
          "title": "CISA KEV: CVE-2020-0646 \u2014 Microsoft .NET Framework Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "CVE-2020-0674",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2973",
          "title": "CISA KEV: CVE-2020-0674 \u2014 Microsoft Internet Explorer Scripting Engine Memory Corruption Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        },
        {
          "id": "art-3001",
          "title": "CISA KEV: CVE-2019-17026 \u2014 Mozilla Firefox And Thunderbird Type Confusion Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "CVE-2020-0683",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2929",
          "title": "CISA KEV: CVE-2020-0683 \u2014 Microsoft Windows Installer Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "CVE-2020-0878",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2924",
          "title": "CISA KEV: CVE-2020-0878 \u2014 Microsoft Edge and Internet Explorer Memory Corruption Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        },
        {
          "id": "art-2975",
          "title": "CISA KEV: CVE-2019-1367 \u2014 Microsoft Internet Explorer Scripting Engine Memory Corruption Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "CVE-2020-0938",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2900",
          "title": "CISA KEV: CVE-2020-6418 \u2014 Google Chromium V8 Type Confusion Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        },
        {
          "id": "art-2937",
          "title": "CISA KEV: CVE-2020-0938 \u2014 Microsoft Windows Adobe Font Manager Library Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        },
        {
          "id": "art-2940",
          "title": "CISA KEV: CVE-2020-1020 \u2014 Microsoft Windows Adobe Font Manager Library Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "CVE-2020-0968",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2980",
          "title": "CISA KEV: CVE-2020-0968 \u2014 Microsoft Internet Explorer Scripting Engine Memory Corruption Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "CVE-2020-0986",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2939",
          "title": "CISA KEV: CVE-2020-0986 \u2014 Microsoft Windows Kernel Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "CVE-2020-10148",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-3036",
          "title": "CISA KEV: CVE-2020-10148 \u2014 SolarWinds Orion Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "CVE-2020-10181",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-3044",
          "title": "CISA KEV: CVE-2020-10181 \u2014 Sumavision EMR Cross-Site Request Forgery (CSRF) Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "CVE-2020-10189",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-3076",
          "title": "CISA KEV: CVE-2020-10189 \u2014 Zoho ManageEngine Desktop Central File Upload Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "CVE-2020-10199",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-3039",
          "title": "CISA KEV: CVE-2020-10199 \u2014 Sonatype Nexus Repository Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "CVE-2020-1020",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2900",
          "title": "CISA KEV: CVE-2020-6418 \u2014 Google Chromium V8 Type Confusion Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        },
        {
          "id": "art-2940",
          "title": "CISA KEV: CVE-2020-1020 \u2014 Microsoft Windows Adobe Font Manager Library Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "CVE-2020-10221",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-3023",
          "title": "CISA KEV: CVE-2020-10221 \u2014 rConfig OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "CVE-2020-1040",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2956",
          "title": "CISA KEV: CVE-2020-1040 \u2014 Microsoft Hyper-V RemoteFX vGPU Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "CVE-2020-1054",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2985",
          "title": "CISA KEV: CVE-2020-1054 \u2014 Microsoft Win32k Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "CVE-2020-1147",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2993",
          "title": "CISA KEV: CVE-2020-1147 \u2014 Microsoft .NET Framework, SharePoint, and Visual Studio Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "CVE-2020-11651",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-3026",
          "title": "CISA KEV: CVE-2020-11652 \u2014 SaltStack Salt Path Traversal Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        },
        {
          "id": "art-3027",
          "title": "CISA KEV: CVE-2020-11651 \u2014 SaltStack Salt Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "CVE-2020-11652",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-3026",
          "title": "CISA KEV: CVE-2020-11652 \u2014 SaltStack Salt Path Traversal Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        },
        {
          "id": "art-3027",
          "title": "CISA KEV: CVE-2020-11651 \u2014 SaltStack Salt Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "CVE-2020-11738",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-3072",
          "title": "CISA KEV: CVE-2020-11738 \u2014 WordPress Snap Creek Duplicator Plugin File Download Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "CVE-2020-12271",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-3043",
          "title": "CISA KEV: CVE-2020-12271 \u2014 Sophos SFOS SQL Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "CVE-2020-12812",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2886",
          "title": "CISA KEV: CVE-2020-12812 \u2014 Fortinet FortiOS SSL VPN Improper Authentication Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "CVE-2020-1350",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2958",
          "title": "CISA KEV: CVE-2020-1350 \u2014 Microsoft Windows DNS Server Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "CVE-2020-1464",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2951",
          "title": "CISA KEV: CVE-2020-1464 \u2014 Microsoft Windows Spoofing Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        },
        {
          "id": "art-2988",
          "title": "CISA KEV: CVE-2020-0601 \u2014 Microsoft Windows CryptoAPI Spoofing Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "CVE-2020-1472",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2981",
          "title": "CISA KEV: CVE-2020-1472 \u2014 Microsoft Netlogon Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "CVE-2020-14750",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-3009",
          "title": "CISA KEV: CVE-2020-14750 \u2014 Oracle WebLogic Server Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "CVE-2020-14871",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-3007",
          "title": "CISA KEV: CVE-2020-14871 \u2014 Oracle Solaris and Zettabyte File System (ZFS) Unspecified Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "CVE-2020-14882",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-3009",
          "title": "CISA KEV: CVE-2020-14750 \u2014 Oracle WebLogic Server Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        },
        {
          "id": "art-3010",
          "title": "CISA KEV: CVE-2020-14883 \u2014 Oracle WebLogic Server Unspecified Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "CVE-2020-14883",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-3010",
          "title": "CISA KEV: CVE-2020-14883 \u2014 Oracle WebLogic Server Unspecified Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "CVE-2020-15505",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2915",
          "title": "CISA KEV: CVE-2020-15505 \u2014 Ivanti MobileIron Multiple Products Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "CVE-2020-15999",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV",
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-2888",
          "title": "CISA KEV: CVE-2020-16010 \u2014 Google Chrome for Android UI Heap Buffer Overflow Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        },
        {
          "id": "art-3276",
          "title": "Buffer overflow in Chromium affecting multiple packages",
          "link": "https://snyk.io/blog/buffer-overflow-in-chromium-affecting-multiple-packages/",
          "published": "2020-11-23",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "CVE-2020-16009",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2888",
          "title": "CISA KEV: CVE-2020-16010 \u2014 Google Chrome for Android UI Heap Buffer Overflow Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        },
        {
          "id": "art-2892",
          "title": "CISA KEV: CVE-2020-16009 \u2014 Google Chromium V8 Type Confusion Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "CVE-2020-16010",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2888",
          "title": "CISA KEV: CVE-2020-16010 \u2014 Google Chrome for Android UI Heap Buffer Overflow Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "CVE-2020-16013",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2894",
          "title": "CISA KEV: CVE-2020-16013 \u2014 Google Chromium V8 Incorrect Implementation Vulnerabililty",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "CVE-2020-16017",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2890",
          "title": "CISA KEV: CVE-2020-16017 \u2014 Google Chrome Use-After-Free Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "CVE-2020-16846",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-3028",
          "title": "CISA KEV: CVE-2020-16846 \u2014 SaltStack Salt Shell Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "CVE-2020-17087",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2888",
          "title": "CISA KEV: CVE-2020-16010 \u2014 Google Chrome for Android UI Heap Buffer Overflow Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        },
        {
          "id": "art-2930",
          "title": "CISA KEV: CVE-2020-17087 \u2014 Microsoft Windows Kernel Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "CVE-2020-17144",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2938",
          "title": "CISA KEV: CVE-2020-17144 \u2014 Microsoft Exchange Server Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "CVE-2020-17496",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-3062",
          "title": "CISA KEV: CVE-2019-16759 \u2014 vBulletin PHP Module Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "CVE-2020-17530",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2819",
          "title": "CISA KEV: CVE-2020-17530 \u2014 Apache Struts Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "CVE-2020-24557",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-3056",
          "title": "CISA KEV: CVE-2020-24557 \u2014 Trend Micro Multiple Products Improper Access Control Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "CVE-2020-25213",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-3071",
          "title": "CISA KEV: CVE-2020-25213 \u2014 WordPress File Manager Plugin Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "CVE-2020-25506",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2872",
          "title": "CISA KEV: CVE-2020-25506 \u2014 D-Link DNS-320 Device Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "CVE-2020-25592",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-3028",
          "title": "CISA KEV: CVE-2020-16846 \u2014 SaltStack Salt Shell Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "CVE-2020-26919",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-3003",
          "title": "CISA KEV: CVE-2020-26919 \u2014 Netgear JGS516PE Devices Missing Function Level Access Control Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "CVE-2020-27930",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2825",
          "title": "CISA KEV: CVE-2020-27930 \u2014 Apple Multiple Products Memory Corruption Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        },
        {
          "id": "art-2827",
          "title": "CISA KEV: CVE-2020-27950 \u2014 Apple Multiple Products Memory Initialization Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        },
        {
          "id": "art-2828",
          "title": "CISA KEV: CVE-2020-27932 \u2014 Apple Multiple Products Type Confusion Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "CVE-2020-27932",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2827",
          "title": "CISA KEV: CVE-2020-27950 \u2014 Apple Multiple Products Memory Initialization Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        },
        {
          "id": "art-2828",
          "title": "CISA KEV: CVE-2020-27932 \u2014 Apple Multiple Products Type Confusion Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        },
        {
          "id": "art-2843",
          "title": "CISA KEV: CVE-2021-30869 \u2014 Apple iOS, iPadOS, and macOS Type Confusion Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "CVE-2020-27950",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2827",
          "title": "CISA KEV: CVE-2020-27950 \u2014 Apple Multiple Products Memory Initialization Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        },
        {
          "id": "art-2828",
          "title": "CISA KEV: CVE-2020-27932 \u2014 Apple Multiple Products Type Confusion Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "CVE-2020-28188",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2917",
          "title": "CISA KEV: CVE-2020-7961 \u2014 Liferay Portal Deserialization of Untrusted Data Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "CVE-2020-29557",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2871",
          "title": "CISA KEV: CVE-2020-29557 \u2014 D-Link DIR-825 R1 Devices Buffer Overflow Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "CVE-2020-29583",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-3078",
          "title": "CISA KEV: CVE-2020-29583 \u2014 Zyxel Multiple Products Use of Hard-Coded Credentials Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "CVE-2020-3118",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2859",
          "title": "CISA KEV: CVE-2020-3118 \u2014 Cisco IOS XR Software Discovery Protocol Format String Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "CVE-2020-3161",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2862",
          "title": "CISA KEV: CVE-2020-3161 \u2014 Cisco IP Phones Web Server Remote Code Execution and Denial-of-Service Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "CVE-2020-3452",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2854",
          "title": "CISA KEV: CVE-2020-3452 \u2014 Cisco ASA and FTD Read-Only Path Traversal Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "CVE-2020-3566",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2860",
          "title": "CISA KEV: CVE-2020-3566 \u2014 Cisco IOS XR Software DVMRP Memory Exhaustion Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        },
        {
          "id": "art-2861",
          "title": "CISA KEV: CVE-2020-3569 \u2014 Cisco IOS XR Software DVMRP Memory Exhaustion Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "CVE-2020-3569",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2860",
          "title": "CISA KEV: CVE-2020-3566 \u2014 Cisco IOS XR Software DVMRP Memory Exhaustion Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        },
        {
          "id": "art-2861",
          "title": "CISA KEV: CVE-2020-3569 \u2014 Cisco IOS XR Software DVMRP Memory Exhaustion Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "CVE-2020-3580",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2855",
          "title": "CISA KEV: CVE-2020-3580 \u2014 Cisco ASA and FTD Cross-Site Scripting (XSS) Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "CVE-2020-3950",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-3065",
          "title": "CISA KEV: CVE-2020-3950 \u2014 VMware Multiple Products Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "CVE-2020-3952",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-3067",
          "title": "CISA KEV: CVE-2020-3952 \u2014 VMware vCenter Server Information Disclosure Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "CVE-2020-3992",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-3064",
          "title": "CISA KEV: CVE-2020-3992 \u2014 VMware ESXi OpenSLP Use-After-Free Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "CVE-2020-4006",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-3070",
          "title": "CISA KEV: CVE-2020-4006 \u2014 Multiple VMware Products Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "CVE-2020-4427",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2910",
          "title": "CISA KEV: CVE-2020-4427 \u2014 IBM Data Risk Manager Security Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "CVE-2020-4428",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2911",
          "title": "CISA KEV: CVE-2020-4428 \u2014 IBM Data Risk Manager Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "CVE-2020-4430",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2909",
          "title": "CISA KEV: CVE-2020-4430 \u2014 IBM Data Risk Manager Directory Traversal Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "CVE-2020-5735",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2812",
          "title": "CISA KEV: CVE-2020-5735 \u2014 Amcrest Cameras and NVR Stack-based Buffer Overflow Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "CVE-2020-5847",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-3061",
          "title": "CISA KEV: CVE-2020-5849 \u2014 Unraid Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "CVE-2020-5849",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-3061",
          "title": "CISA KEV: CVE-2020-5849 \u2014 Unraid Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "CVE-2020-5902",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2882",
          "title": "CISA KEV: CVE-2020-5902 \u2014 F5 BIG-IP Traffic Management User Interface (TMUI) Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "CVE-2020-6207",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-3033",
          "title": "CISA KEV: CVE-2020-6207 \u2014 SAP Solution Manager Missing Authentication for Critical Function Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "CVE-2020-6287",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-3029",
          "title": "CISA KEV: CVE-2018-2380 \u2014 SAP Customer Relationship Management (CRM) Path Traversal Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        },
        {
          "id": "art-3032",
          "title": "CISA KEV: CVE-2020-6287 \u2014 SAP NetWeaver Missing Authentication for Critical Function Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "CVE-2020-6418",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2900",
          "title": "CISA KEV: CVE-2020-6418 \u2014 Google Chromium V8 Type Confusion Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "CVE-2020-6819",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2999",
          "title": "CISA KEV: CVE-2020-6819 \u2014 Mozilla Firefox And Thunderbird Use-After-Free Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "CVE-2020-6820",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-3000",
          "title": "CISA KEV: CVE-2020-6820 \u2014 Mozilla Firefox And Thunderbird Use-After-Free Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "CVE-2020-7961",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2917",
          "title": "CISA KEV: CVE-2020-7961 \u2014 Liferay Portal Deserialization of Untrusted Data Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "CVE-2020-8193",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2866",
          "title": "CISA KEV: CVE-2020-8193 \u2014 Citrix ADC, Gateway, and SD-WAN WANOP Appliance Authorization Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        },
        {
          "id": "art-2867",
          "title": "CISA KEV: CVE-2020-8195 \u2014 Citrix ADC, Gateway, and SD-WAN WANOP Appliance Information Disclosure Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "CVE-2020-8195",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2867",
          "title": "CISA KEV: CVE-2020-8195 \u2014 Citrix ADC, Gateway, and SD-WAN WANOP Appliance Information Disclosure Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "CVE-2020-8196",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2867",
          "title": "CISA KEV: CVE-2020-8195 \u2014 Citrix ADC, Gateway, and SD-WAN WANOP Appliance Information Disclosure Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        },
        {
          "id": "art-2868",
          "title": "CISA KEV: CVE-2020-8196 \u2014 Citrix ADC, Gateway, and SD-WAN WANOP Appliance Information Disclosure Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "CVE-2020-8243",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-3014",
          "title": "CISA KEV: CVE-2020-8243 \u2014 Ivanti Pulse Connect Secure Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "CVE-2020-8260",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-3017",
          "title": "CISA KEV: CVE-2020-8260 \u2014 Ivanti Pulse Connect Secure Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "CVE-2020-8467",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-3054",
          "title": "CISA KEV: CVE-2020-8467 \u2014 Trend Micro Apex One and OfficeScan Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        },
        {
          "id": "art-3057",
          "title": "CISA KEV: CVE-2020-8599 \u2014 Trend Micro Apex One and OfficeScan Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "CVE-2020-8468",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-3055",
          "title": "CISA KEV: CVE-2020-8468 \u2014 Trend Micro Multiple Products Content Validation Escape Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "CVE-2020-8599",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-3057",
          "title": "CISA KEV: CVE-2020-8599 \u2014 Trend Micro Apex One and OfficeScan Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "CVE-2020-8644",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-3011",
          "title": "CISA KEV: CVE-2020-8644 \u2014 PlaySMS Server-Side Template Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "CVE-2020-8655",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2881",
          "title": "CISA KEV: CVE-2020-8655 \u2014 EyesOfNetwork Improper Privilege Management Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "CVE-2020-8657",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2880",
          "title": "CISA KEV: CVE-2020-8657 \u2014 EyesOfNetwork Use of Hard-Coded Credentials Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "CVE-2020-9818",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2829",
          "title": "CISA KEV: CVE-2020-9818 \u2014 Apple iOS, iPadOS, and watchOS Out-of-Bounds Write Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        },
        {
          "id": "art-2830",
          "title": "CISA KEV: CVE-2020-9819 \u2014 Apple iOS, iPadOS, and watchOS Memory Corruption Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "CVE-2020-9819",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2829",
          "title": "CISA KEV: CVE-2020-9818 \u2014 Apple iOS, iPadOS, and watchOS Out-of-Bounds Write Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        },
        {
          "id": "art-2830",
          "title": "CISA KEV: CVE-2020-9819 \u2014 Apple iOS, iPadOS, and watchOS Memory Corruption Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "CVE-2020-9859",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2844",
          "title": "CISA KEV: CVE-2020-9859 \u2014 Apple Multiple Products Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "CVE-2021-1497",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2856",
          "title": "CISA KEV: CVE-2021-1497 \u2014 Cisco HyperFlex HX Installer Virtual Machine Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        },
        {
          "id": "art-2857",
          "title": "CISA KEV: CVE-2021-1498 \u2014 Cisco HyperFlex HX Data Platform Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "CVE-2021-1498",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2857",
          "title": "CISA KEV: CVE-2021-1498 \u2014 Cisco HyperFlex HX Data Platform Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "CVE-2021-1647",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2926",
          "title": "CISA KEV: CVE-2021-1647 \u2014 Microsoft Defender Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "CVE-2021-1675",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2953",
          "title": "CISA KEV: CVE-2021-34527 \u2014 Microsoft Windows Print Spooler Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        },
        {
          "id": "art-2986",
          "title": "CISA KEV: CVE-2021-1675 \u2014 Microsoft Windows Print Spooler Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "CVE-2021-1732",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2952",
          "title": "CISA KEV: CVE-2021-1732 \u2014 Microsoft Win32k Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "CVE-2021-1782",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2832",
          "title": "CISA KEV: CVE-2021-1782 \u2014 Apple Multiple Products Race Condition Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        },
        {
          "id": "art-2833",
          "title": "CISA KEV: CVE-2021-1870 \u2014 Apple iOS, iPadOS, and macOS WebKit Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "CVE-2021-1870",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2833",
          "title": "CISA KEV: CVE-2021-1870 \u2014 Apple iOS, iPadOS, and macOS WebKit Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "CVE-2021-1871",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2833",
          "title": "CISA KEV: CVE-2021-1870 \u2014 Apple iOS, iPadOS, and macOS WebKit Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        },
        {
          "id": "art-2834",
          "title": "CISA KEV: CVE-2021-1871 \u2014 Apple iOS, iPadOS, and macOS WebKit Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "CVE-2021-1879",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2835",
          "title": "CISA KEV: CVE-2021-1879 \u2014 Apple iOS, iPadOS, and watchOS WebKit Cross-Site Scripting (XSS) Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "CVE-2021-1905",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-3022",
          "title": "CISA KEV: CVE-2021-1905 \u2014 Qualcomm Multiple Chipsets Use-After-Free Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "CVE-2021-1906",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-3021",
          "title": "CISA KEV: CVE-2021-1906 \u2014 Qualcomm Multiple Chipsets Detection of Error Condition Without Action Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "CVE-2021-20016",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-3042",
          "title": "CISA KEV: CVE-2021-20016 \u2014 SonicWall SSLVPN SMA100 SQL Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "CVE-2021-20021",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-3040",
          "title": "CISA KEV: CVE-2021-20021 \u2014 SonicWall Email Security Improper Privilege Management Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "CVE-2021-20022",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-3040",
          "title": "CISA KEV: CVE-2021-20021 \u2014 SonicWall Email Security Improper Privilege Management Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "CVE-2021-20023",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-3040",
          "title": "CISA KEV: CVE-2021-20021 \u2014 SonicWall Email Security Improper Privilege Management Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "CVE-2021-20090",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2845",
          "title": "CISA KEV: CVE-2021-20090 \u2014 Arcadyan Buffalo Firmware Path Traversal Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "CVE-2021-21017",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2807",
          "title": "CISA KEV: CVE-2021-21017 \u2014 Adobe Acrobat and Reader Heap-based Buffer Overflow Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "CVE-2021-21148",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2896",
          "title": "CISA KEV: CVE-2021-21148 \u2014 Google Chromium V8 Heap Buffer Overflow Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "CVE-2021-21166",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2889",
          "title": "CISA KEV: CVE-2021-21166 \u2014 Google Chromium Race Condition Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "CVE-2021-21193",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2906",
          "title": "CISA KEV: CVE-2021-21193 \u2014 Google Chromium Blink Use-After-Free Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "CVE-2021-21206",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2902",
          "title": "CISA KEV: CVE-2021-21206 \u2014 Google Chromium Blink Use-After-Free Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "CVE-2021-21220",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2907",
          "title": "CISA KEV: CVE-2021-21220 \u2014 Google Chromium V8 Improper Input Validation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        },
        {
          "id": "art-2925",
          "title": "CISA KEV: CVE-2021-31955 \u2014 Microsoft Windows Kernel Information Disclosure Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        },
        {
          "id": "art-2934",
          "title": "CISA KEV: CVE-2021-31956 \u2014 Microsoft Windows NTFS Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "CVE-2021-21224",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2905",
          "title": "CISA KEV: CVE-2021-21224 \u2014 Google Chromium V8 Type Confusion Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        },
        {
          "id": "art-2925",
          "title": "CISA KEV: CVE-2021-31955 \u2014 Microsoft Windows Kernel Information Disclosure Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        },
        {
          "id": "art-2934",
          "title": "CISA KEV: CVE-2021-31956 \u2014 Microsoft Windows NTFS Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "CVE-2021-21972",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-3068",
          "title": "CISA KEV: CVE-2021-21972 \u2014 VMware vCenter Server Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "CVE-2021-21974",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-3063",
          "title": "CISA KEV: CVE-2019-5544 \u2014 VMware ESXi and Horizon DaaS OpenSLP Heap-Based Buffer Overflow Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "CVE-2021-21985",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-3069",
          "title": "CISA KEV: CVE-2021-21985 \u2014 VMware vCenter Server Improper Input Validation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "CVE-2021-22005",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-3066",
          "title": "CISA KEV: CVE-2021-22005 \u2014 VMware vCenter Server File Upload Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "CVE-2021-22205",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2878",
          "title": "CISA KEV: CVE-2021-22205 \u2014 GitLab Community and Enterprise Editions Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "CVE-2021-22502",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2920",
          "title": "CISA KEV: CVE-2021-22502 \u2014 Micro Focus Operation Bridge Report (OBR) Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "CVE-2021-22506",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2919",
          "title": "CISA KEV: CVE-2021-22506 \u2014 Micro Focus Access Manager Information Leakage Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "CVE-2021-22893",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-3013",
          "title": "CISA KEV: CVE-2021-22893 \u2014 Ivanti Pulse Connect Secure Use-After-Free Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        },
        {
          "id": "art-3015",
          "title": "CISA KEV: CVE-2021-22900 \u2014 Ivanti Pulse Connect Secure Unrestricted File Upload Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "CVE-2021-22894",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-3016",
          "title": "CISA KEV: CVE-2021-22894 \u2014 Ivanti Pulse Connect Secure Collaboration Suite Buffer Overflow Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "CVE-2021-22899",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-3018",
          "title": "CISA KEV: CVE-2021-22899 \u2014 Ivanti Pulse Connect Secure Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        },
        {
          "id": "art-3020",
          "title": "CISA KEV: CVE-2019-11539 \u2014 Ivanti Pulse Connect Secure and Policy Secure Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "CVE-2021-22900",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-3015",
          "title": "CISA KEV: CVE-2021-22900 \u2014 Ivanti Pulse Connect Secure Unrestricted File Upload Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "CVE-2021-22986",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2883",
          "title": "CISA KEV: CVE-2021-22986 \u2014 F5 BIG-IP and BIG-IQ Centralized Management iControl REST Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "CVE-2021-23434",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-2802",
          "title": "JavaScript type confusion: Bypassed input validation (and how to remediate)",
          "link": "https://snyk.io/blog/remediate-javascript-type-confusion-bypassed-input-validation/",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "CVE-2021-23436",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-2802",
          "title": "JavaScript type confusion: Bypassed input validation (and how to remediate)",
          "link": "https://snyk.io/blog/remediate-javascript-type-confusion-bypassed-input-validation/",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "CVE-2021-23438",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-2802",
          "title": "JavaScript type confusion: Bypassed input validation (and how to remediate)",
          "link": "https://snyk.io/blog/remediate-javascript-type-confusion-bypassed-input-validation/",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "CVE-2021-23440",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-2802",
          "title": "JavaScript type confusion: Bypassed input validation (and how to remediate)",
          "link": "https://snyk.io/blog/remediate-javascript-type-confusion-bypassed-input-validation/",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "CVE-2021-23443",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-2802",
          "title": "JavaScript type confusion: Bypassed input validation (and how to remediate)",
          "link": "https://snyk.io/blog/remediate-javascript-type-confusion-bypassed-input-validation/",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "CVE-2021-23444",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-2802",
          "title": "JavaScript type confusion: Bypassed input validation (and how to remediate)",
          "link": "https://snyk.io/blog/remediate-javascript-type-confusion-bypassed-input-validation/",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "CVE-2021-23874",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2918",
          "title": "CISA KEV: CVE-2021-23874 \u2014 McAfee Total Protection (MTP) Improper Privilege Management Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "CVE-2021-26084",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2850",
          "title": "CISA KEV: CVE-2021-26084 \u2014 Atlassian Confluence Server and Data Center Object-Graph Navigation Language (OGNL) Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "CVE-2021-26411",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2959",
          "title": "CISA KEV: CVE-2021-26411 \u2014 Microsoft Internet Explorer Memory Corruption Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "CVE-2021-26855",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2982",
          "title": "CISA KEV: CVE-2021-26855 \u2014 Microsoft Exchange Server Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        },
        {
          "id": "art-2992",
          "title": "CISA KEV: CVE-2021-26857 \u2014 Microsoft Exchange Server Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "CVE-2021-26857",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2992",
          "title": "CISA KEV: CVE-2021-26857 \u2014 Microsoft Exchange Server Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "CVE-2021-26858",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2983",
          "title": "CISA KEV: CVE-2021-26858 \u2014 Microsoft Exchange Server Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        },
        {
          "id": "art-2992",
          "title": "CISA KEV: CVE-2021-26857 \u2014 Microsoft Exchange Server Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "CVE-2021-27059",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2974",
          "title": "CISA KEV: CVE-2021-27059 \u2014 Microsoft Office Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "CVE-2021-27065",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2982",
          "title": "CISA KEV: CVE-2021-26855 \u2014 Microsoft Exchange Server Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        },
        {
          "id": "art-2984",
          "title": "CISA KEV: CVE-2021-27065 \u2014 Microsoft Exchange Server Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        },
        {
          "id": "art-2992",
          "title": "CISA KEV: CVE-2021-26857 \u2014 Microsoft Exchange Server Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "CVE-2021-27085",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2970",
          "title": "CISA KEV: CVE-2021-27085 \u2014 Microsoft Internet Explorer Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "CVE-2021-27101",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2803",
          "title": "CISA KEV: CVE-2021-27104 \u2014 Accellion FTA OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        },
        {
          "id": "art-2804",
          "title": "CISA KEV: CVE-2021-27102 \u2014 Accellion FTA OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        },
        {
          "id": "art-2805",
          "title": "CISA KEV: CVE-2021-27101 \u2014 Accellion FTA SQL Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        },
        {
          "id": "art-2806",
          "title": "CISA KEV: CVE-2021-27103 \u2014 Accellion FTA Server-Side Request Forgery (SSRF) Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "CVE-2021-27102",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2803",
          "title": "CISA KEV: CVE-2021-27104 \u2014 Accellion FTA OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        },
        {
          "id": "art-2804",
          "title": "CISA KEV: CVE-2021-27102 \u2014 Accellion FTA OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        },
        {
          "id": "art-2805",
          "title": "CISA KEV: CVE-2021-27101 \u2014 Accellion FTA SQL Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        },
        {
          "id": "art-2806",
          "title": "CISA KEV: CVE-2021-27103 \u2014 Accellion FTA Server-Side Request Forgery (SSRF) Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "CVE-2021-27103",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2803",
          "title": "CISA KEV: CVE-2021-27104 \u2014 Accellion FTA OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        },
        {
          "id": "art-2804",
          "title": "CISA KEV: CVE-2021-27102 \u2014 Accellion FTA OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        },
        {
          "id": "art-2805",
          "title": "CISA KEV: CVE-2021-27101 \u2014 Accellion FTA SQL Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        },
        {
          "id": "art-2806",
          "title": "CISA KEV: CVE-2021-27103 \u2014 Accellion FTA Server-Side Request Forgery (SSRF) Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "CVE-2021-27104",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2803",
          "title": "CISA KEV: CVE-2021-27104 \u2014 Accellion FTA OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        },
        {
          "id": "art-2804",
          "title": "CISA KEV: CVE-2021-27102 \u2014 Accellion FTA OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        },
        {
          "id": "art-2805",
          "title": "CISA KEV: CVE-2021-27101 \u2014 Accellion FTA SQL Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        },
        {
          "id": "art-2806",
          "title": "CISA KEV: CVE-2021-27103 \u2014 Accellion FTA Server-Side Request Forgery (SSRF) Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "CVE-2021-27561",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-3074",
          "title": "CISA KEV: CVE-2021-27561 \u2014 Yealink Device Management Server-Side Request Forgery (SSRF) Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "CVE-2021-27562",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2846",
          "title": "CISA KEV: CVE-2021-27562 \u2014 Arm Trusted Firmware Out-of-Bounds Write Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "CVE-2021-28310",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2957",
          "title": "CISA KEV: CVE-2021-28310 \u2014 Microsoft Win32k Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "CVE-2021-28663",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2847",
          "title": "CISA KEV: CVE-2021-28664 \u2014 Arm Mali Graphics Processing Unit (GPU) Unspecified Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        },
        {
          "id": "art-2848",
          "title": "CISA KEV: CVE-2021-28663 \u2014 Arm Mali Graphics Processing Unit (GPU) Use-After-Free Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "CVE-2021-28664",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2847",
          "title": "CISA KEV: CVE-2021-28664 \u2014 Arm Mali Graphics Processing Unit (GPU) Unspecified Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "CVE-2021-3007",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2917",
          "title": "CISA KEV: CVE-2020-7961 \u2014 Liferay Portal Deserialization of Untrusted Data Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "CVE-2021-30116",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2916",
          "title": "CISA KEV: CVE-2021-30116 \u2014 Kaseya Virtual System/Server Administrator (VSA) Information Disclosure Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "CVE-2021-30551",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2898",
          "title": "CISA KEV: CVE-2021-30551 \u2014 Google Chromium V8 Type Confusion Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "CVE-2021-30554",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2901",
          "title": "CISA KEV: CVE-2021-30554 \u2014 Google Chromium WebGL Use-After-Free Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "CVE-2021-30563",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2908",
          "title": "CISA KEV: CVE-2021-30563 \u2014 Google Chromium V8 Type Confusion Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "CVE-2021-30632",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2893",
          "title": "CISA KEV: CVE-2021-30632 \u2014 Google Chromium V8 Out-of-Bounds Write Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "CVE-2021-30633",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2893",
          "title": "CISA KEV: CVE-2021-30632 \u2014 Google Chromium V8 Out-of-Bounds Write Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        },
        {
          "id": "art-2895",
          "title": "CISA KEV: CVE-2021-30633 \u2014 Google Chromium Indexed DB API Use-After-Free Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "CVE-2021-30657",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2839",
          "title": "CISA KEV: CVE-2021-30657 \u2014 Apple macOS Unspecified Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "CVE-2021-30661",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2836",
          "title": "CISA KEV: CVE-2021-30661 \u2014 Apple Multiple Products WebKit Storage Use-After-Free Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "CVE-2021-30663",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2841",
          "title": "CISA KEV: CVE-2021-30663 \u2014 Apple Multiple Products WebKit Integer Overflow Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "CVE-2021-30665",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2840",
          "title": "CISA KEV: CVE-2021-30665 \u2014 Apple Multiple Products WebKit Memory Corruption Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "CVE-2021-30666",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2837",
          "title": "CISA KEV: CVE-2021-30666 \u2014 Apple iOS WebKit Buffer Overflow Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        },
        {
          "id": "art-2842",
          "title": "CISA KEV: CVE-2021-30761 \u2014 Apple iOS WebKit Memory Corruption Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "CVE-2021-30713",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2838",
          "title": "CISA KEV: CVE-2021-30713 \u2014 Apple macOS Unspecified Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "CVE-2021-30761",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2842",
          "title": "CISA KEV: CVE-2021-30761 \u2014 Apple iOS WebKit Memory Corruption Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "CVE-2021-30762",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2831",
          "title": "CISA KEV: CVE-2021-30762 \u2014 Apple iOS WebKit Use-After-Free Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "CVE-2021-30807",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2826",
          "title": "CISA KEV: CVE-2021-30807 \u2014 Apple Multiple Products Memory Corruption Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "CVE-2021-30858",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2822",
          "title": "CISA KEV: CVE-2021-30858 \u2014 Apple iOS, iPadOS, macOS Use-After-Free Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "CVE-2021-30860",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2824",
          "title": "CISA KEV: CVE-2021-30860 \u2014 Apple Multiple Products Integer Overflow Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        },
        {
          "id": "art-2840",
          "title": "CISA KEV: CVE-2021-30665 \u2014 Apple Multiple Products WebKit Memory Corruption Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "CVE-2021-30869",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2843",
          "title": "CISA KEV: CVE-2021-30869 \u2014 Apple iOS, iPadOS, and macOS Type Confusion Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "CVE-2021-31207",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2942",
          "title": "CISA KEV: CVE-2021-34523 \u2014 Microsoft Exchange Server Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        },
        {
          "id": "art-2950",
          "title": "CISA KEV: CVE-2021-34473 \u2014 Microsoft Exchange Server Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        },
        {
          "id": "art-2954",
          "title": "CISA KEV: CVE-2021-31207 \u2014 Microsoft Exchange Server Security Feature Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "CVE-2021-31755",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-3048",
          "title": "CISA KEV: CVE-2021-31755 \u2014 Tenda AC11 Router Stack Buffer Overflow Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "CVE-2021-31955",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2925",
          "title": "CISA KEV: CVE-2021-31955 \u2014 Microsoft Windows Kernel Information Disclosure Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        },
        {
          "id": "art-2934",
          "title": "CISA KEV: CVE-2021-31956 \u2014 Microsoft Windows NTFS Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "CVE-2021-31956",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2925",
          "title": "CISA KEV: CVE-2021-31955 \u2014 Microsoft Windows Kernel Information Disclosure Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        },
        {
          "id": "art-2934",
          "title": "CISA KEV: CVE-2021-31956 \u2014 Microsoft Windows NTFS Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "CVE-2021-31979",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2936",
          "title": "CISA KEV: CVE-2021-31979 \u2014 Microsoft Windows Kernel Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "CVE-2021-33739",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2927",
          "title": "CISA KEV: CVE-2021-33739 \u2014 Microsoft Desktop Window Manager (DWM) Core Library Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "CVE-2021-33742",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2931",
          "title": "CISA KEV: CVE-2021-33742 \u2014 Microsoft Windows MSHTML Platform Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "CVE-2021-33771",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2933",
          "title": "CISA KEV: CVE-2021-33771 \u2014 Microsoft Windows Kernel Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "CVE-2021-34448",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2987",
          "title": "CISA KEV: CVE-2021-34448 \u2014 Microsoft Windows Scripting Engine Memory Corruption Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "CVE-2021-34473",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2942",
          "title": "CISA KEV: CVE-2021-34523 \u2014 Microsoft Exchange Server Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        },
        {
          "id": "art-2950",
          "title": "CISA KEV: CVE-2021-34473 \u2014 Microsoft Exchange Server Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        },
        {
          "id": "art-2954",
          "title": "CISA KEV: CVE-2021-31207 \u2014 Microsoft Exchange Server Security Feature Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "CVE-2021-34523",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2942",
          "title": "CISA KEV: CVE-2021-34523 \u2014 Microsoft Exchange Server Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        },
        {
          "id": "art-2950",
          "title": "CISA KEV: CVE-2021-34473 \u2014 Microsoft Exchange Server Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        },
        {
          "id": "art-2954",
          "title": "CISA KEV: CVE-2021-31207 \u2014 Microsoft Exchange Server Security Feature Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "CVE-2021-34527",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2953",
          "title": "CISA KEV: CVE-2021-34527 \u2014 Microsoft Windows Print Spooler Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "CVE-2021-35211",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-3037",
          "title": "CISA KEV: CVE-2021-35211 \u2014 SolarWinds Serv-U Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "CVE-2021-35395",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-3024",
          "title": "CISA KEV: CVE-2021-35395 \u2014 Realtek AP-Router SDK Buffer Overflow Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "CVE-2021-35464",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2884",
          "title": "CISA KEV: CVE-2021-35464 \u2014 ForgeRock Access Management (AM) Core Server Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "CVE-2021-36741",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-3059",
          "title": "CISA KEV: CVE-2021-36741 \u2014 Trend Micro Multiple Products Improper Input Validation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "CVE-2021-36742",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-3058",
          "title": "CISA KEV: CVE-2021-36742 \u2014 Trend Micro Multiple Products Improper Input Validation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        },
        {
          "id": "art-3059",
          "title": "CISA KEV: CVE-2021-36741 \u2014 Trend Micro Multiple Products Improper Input Validation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "CVE-2021-36955",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2997",
          "title": "CISA KEV: CVE-2021-36955 \u2014 Microsoft Windows Common Log File System (CLFS) Driver Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "CVE-2021-37973",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2897",
          "title": "CISA KEV: CVE-2021-37973 \u2014 Google Chromium Portals Use-After-Free Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "CVE-2021-37975",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2899",
          "title": "CISA KEV: CVE-2021-37975 \u2014 Google Chromium V8 Use-After-Free Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "CVE-2021-37976",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2891",
          "title": "CISA KEV: CVE-2021-37976 \u2014 Google Chromium Information Disclosure Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "CVE-2021-38000",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2903",
          "title": "CISA KEV: CVE-2021-38000 \u2014 Google Chromium Intents Improper Input Validation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "CVE-2021-38003",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2903",
          "title": "CISA KEV: CVE-2021-38000 \u2014 Google Chromium Intents Improper Input Validation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        },
        {
          "id": "art-2904",
          "title": "CISA KEV: CVE-2021-38003 \u2014 Google Chromium V8 Memory Corruption Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "CVE-2021-38645",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2941",
          "title": "CISA KEV: CVE-2021-38645 \u2014 Microsoft Open Management Infrastructure (OMI) Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "CVE-2021-38647",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2922",
          "title": "CISA KEV: CVE-2021-38647 \u2014 Microsoft Open Management Infrastructure (OMI) Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        },
        {
          "id": "art-2941",
          "title": "CISA KEV: CVE-2021-38645 \u2014 Microsoft Open Management Infrastructure (OMI) Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        },
        {
          "id": "art-2945",
          "title": "CISA KEV: CVE-2021-38649 \u2014 Microsoft Open Management Infrastructure (OMI) Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "CVE-2021-38648",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2941",
          "title": "CISA KEV: CVE-2021-38645 \u2014 Microsoft Open Management Infrastructure (OMI) Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        },
        {
          "id": "art-2998",
          "title": "CISA KEV: CVE-2021-38648 \u2014 Microsoft Open Management Infrastructure (OMI) Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "CVE-2021-38649",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2941",
          "title": "CISA KEV: CVE-2021-38645 \u2014 Microsoft Open Management Infrastructure (OMI) Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        },
        {
          "id": "art-2945",
          "title": "CISA KEV: CVE-2021-38649 \u2014 Microsoft Open Management Infrastructure (OMI) Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "CVE-2021-40444",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2961",
          "title": "CISA KEV: CVE-2021-40444 \u2014 Microsoft MSHTML Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "CVE-2021-41773",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2815",
          "title": "CISA KEV: CVE-2021-42013 \u2014 Apache HTTP Server Path Traversal Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "CVE-2021-42013",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2815",
          "title": "CISA KEV: CVE-2021-42013 \u2014 Apache HTTP Server Path Traversal Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "CVE-2021-42258",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2853",
          "title": "CISA KEV: CVE-2021-42258 \u2014 BQE BillQuick Web Suite SQL Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "acne-school.ru",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-3073",
          "title": "CISA KEV: CVE-2019-9978 \u2014 WordPress Social Warfare Plugin Cross-Site Scripting (XSS) Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "ado-read-parser.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2935",
          "title": "CISA KEV: CVE-2021-31201 \u2014 Microsoft Enhanced Cryptographic Provider Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "adoberelations.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2838",
          "title": "CISA KEV: CVE-2021-30713 \u2014 Apple macOS Unspecified Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "adobestats.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2838",
          "title": "CISA KEV: CVE-2021-30713 \u2014 Apple macOS Unspecified Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "apple-webservice.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2843",
          "title": "CISA KEV: CVE-2021-30869 \u2014 Apple iOS, iPadOS, and macOS Type Confusion Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "appleid-server.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2843",
          "title": "CISA KEV: CVE-2021-30869 \u2014 Apple iOS, iPadOS, and macOS Type Confusion Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "atecasec.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2838",
          "title": "CISA KEV: CVE-2021-30713 \u2014 Apple macOS Unspecified Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "avsvmcloud.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-3036",
          "title": "CISA KEV: CVE-2020-10148 \u2014 SolarWinds Orion Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "cmd.irannetworkteam.org",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2869",
          "title": "CISA KEV: CVE-2019-19781 \u2014 Citrix ADC, Gateway, and SD-WAN WANOP Appliance Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "customcoverinc.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-3073",
          "title": "CISA KEV: CVE-2019-9978 \u2014 WordPress Social Warfare Plugin Cross-Site Scripting (XSS) Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "debugmex.dsirflabs.eu",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2932",
          "title": "CISA KEV: CVE-2021-31199 \u2014 Microsoft Enhanced Cryptographic Provider Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "exchange.dumb1.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-3076",
          "title": "CISA KEV: CVE-2020-10189 \u2014 Zoho ManageEngine Desktop Central File Upload Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "findmymacs.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2838",
          "title": "CISA KEV: CVE-2021-30713 \u2014 Apple macOS Unspecified Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "flixprice.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2838",
          "title": "CISA KEV: CVE-2021-30713 \u2014 Apple macOS Unspecified Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "gxbrowser.net",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2917",
          "title": "CISA KEV: CVE-2020-7961 \u2014 Liferay Portal Deserialization of Untrusted Data Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "icloudserv.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2838",
          "title": "CISA KEV: CVE-2021-30713 \u2014 Apple macOS Unspecified Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "iotlmao.xyz",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2872",
          "title": "CISA KEV: CVE-2020-25506 \u2014 D-Link DNS-320 Device Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "irc.hoaxcalls.pw",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2876",
          "title": "CISA KEV: CVE-2020-8515 \u2014 Multiple DrayTek Vigor Routers Web Management Page Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "linebrand.xyz",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2838",
          "title": "CISA KEV: CVE-2021-30713 \u2014 Apple macOS Unspecified Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "mantrucks.xyz",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2838",
          "title": "CISA KEV: CVE-2021-30713 \u2014 Apple macOS Unspecified Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "media-seoengine.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2925",
          "title": "CISA KEV: CVE-2021-31955 \u2014 Microsoft Windows Kernel Information Disclosure Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        },
        {
          "id": "art-2934",
          "title": "CISA KEV: CVE-2021-31956 \u2014 Microsoft Windows NTFS Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "monotel.xyz",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2838",
          "title": "CISA KEV: CVE-2021-30713 \u2014 Apple macOS Unspecified Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "netlabs.gr",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-3073",
          "title": "CISA KEV: CVE-2019-9978 \u2014 WordPress Social Warfare Plugin Cross-Site Scripting (XSS) Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "nodeline.xyz",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2838",
          "title": "CISA KEV: CVE-2021-30713 \u2014 Apple macOS Unspecified Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "ntpserver.tk",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2943",
          "title": "CISA KEV: CVE-2017-7269 \u2014 Microsoft Windows Server Buffer Overflow Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "postgre.tk",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2943",
          "title": "CISA KEV: CVE-2017-7269 \u2014 Microsoft Windows Server Buffer Overflow Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "sidelink.xyz",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2838",
          "title": "CISA KEV: CVE-2021-30713 \u2014 Apple macOS Unspecified Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "sophosfirewallupdate.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-3043",
          "title": "CISA KEV: CVE-2020-12271 \u2014 Sophos SFOS SQL Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "statsmag.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2838",
          "title": "CISA KEV: CVE-2021-30713 \u2014 Apple macOS Unspecified Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "statsmag.xyz",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2838",
          "title": "CISA KEV: CVE-2021-30713 \u2014 Apple macOS Unspecified Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "support-box.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2804",
          "title": "CISA KEV: CVE-2021-27102 \u2014 Accellion FTA OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "supportversion.yourlinkforplaceforupgrading.info",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2839",
          "title": "CISA KEV: CVE-2021-30657 \u2014 Apple macOS Unspecified Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "szstaging.dsirflabs.eu",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2932",
          "title": "CISA KEV: CVE-2021-31199 \u2014 Microsoft Enhanced Cryptographic Provider Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "tcp.symantecserver.co",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2950",
          "title": "CISA KEV: CVE-2021-34473 \u2014 Microsoft Exchange Server Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "tekmat.net",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-3073",
          "title": "CISA KEV: CVE-2019-9978 \u2014 WordPress Social Warfare Plugin Cross-Site Scripting (XSS) Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "titiez.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2838",
          "title": "CISA KEV: CVE-2021-30713 \u2014 Apple macOS Unspecified Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "trendmicronano.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2838",
          "title": "CISA KEV: CVE-2021-30713 \u2014 Apple macOS Unspecified Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "viamarkt.hu",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-3073",
          "title": "CISA KEV: CVE-2019-9978 \u2014 WordPress Social Warfare Plugin Cross-Site Scripting (XSS) Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "www.1588-2040.co.kr",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2811",
          "title": "CISA KEV: CVE-2018-4878 \u2014 Adobe Flash Player Use-After-Free Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "www.dylboiler.co.kr",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2811",
          "title": "CISA KEV: CVE-2018-4878 \u2014 Adobe Flash Player Use-After-Free Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "www.korea-tax.info",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2811",
          "title": "CISA KEV: CVE-2018-4878 \u2014 Adobe Flash Player Use-After-Free Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "zx.ado-read-parser.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2935",
          "title": "CISA KEV: CVE-2021-31201 \u2014 Microsoft Enhanced Cryptographic Provider Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "103.255.44.56",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2843",
          "title": "CISA KEV: CVE-2021-30869 \u2014 Apple iOS, iPadOS, and macOS Type Confusion Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "104.248.238.198",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-3071",
          "title": "CISA KEV: CVE-2020-25213 \u2014 WordPress File Manager Plugin Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "117.79.132.174",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2943",
          "title": "CISA KEV: CVE-2017-7269 \u2014 Microsoft Windows Server Buffer Overflow Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "121.196.25.170",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2850",
          "title": "CISA KEV: CVE-2021-26084 \u2014 Atlassian Confluence Server and Data Center Object-Graph Navigation Language (OGNL) Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "122.9.48.250",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2850",
          "title": "CISA KEV: CVE-2021-26084 \u2014 Atlassian Confluence Server and Data Center Object-Graph Navigation Language (OGNL) Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "123.1.170.152",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2843",
          "title": "CISA KEV: CVE-2021-30869 \u2014 Apple iOS, iPadOS, and macOS Type Confusion Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "13.66.185.182",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-3071",
          "title": "CISA KEV: CVE-2020-25213 \u2014 WordPress File Manager Plugin Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "13.82.220.36",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-3071",
          "title": "CISA KEV: CVE-2020-25213 \u2014 WordPress File Manager Plugin Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "13.85.84.182",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-3071",
          "title": "CISA KEV: CVE-2020-25213 \u2014 WordPress File Manager Plugin Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "141.98.83.139",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2850",
          "title": "CISA KEV: CVE-2021-26084 \u2014 Atlassian Confluence Server and Data Center Object-Graph Navigation Language (OGNL) Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "144.34.179.162",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-3037",
          "title": "CISA KEV: CVE-2021-35211 \u2014 SolarWinds Serv-U Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "148.251.71.182",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2950",
          "title": "CISA KEV: CVE-2021-34473 \u2014 Microsoft Exchange Server Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "149.28.85.17",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2850",
          "title": "CISA KEV: CVE-2021-26084 \u2014 Atlassian Confluence Server and Data Center Object-Graph Navigation Language (OGNL) Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "155.94.160.40",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2803",
          "title": "CISA KEV: CVE-2021-27104 \u2014 Accellion FTA OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        },
        {
          "id": "art-2804",
          "title": "CISA KEV: CVE-2021-27102 \u2014 Accellion FTA OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        },
        {
          "id": "art-2805",
          "title": "CISA KEV: CVE-2021-27101 \u2014 Accellion FTA SQL Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        },
        {
          "id": "art-2806",
          "title": "CISA KEV: CVE-2021-27103 \u2014 Accellion FTA Server-Side Request Forgery (SSRF) Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "160.20.147.136",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-3071",
          "title": "CISA KEV: CVE-2020-25213 \u2014 WordPress File Manager Plugin Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "161.35.90.11",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-3071",
          "title": "CISA KEV: CVE-2020-25213 \u2014 WordPress File Manager Plugin Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "164.132.92.180",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2876",
          "title": "CISA KEV: CVE-2020-8515 \u2014 Multiple DrayTek Vigor Routers Web Management Page Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "169.40.2.68",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2935",
          "title": "CISA KEV: CVE-2021-31201 \u2014 Microsoft Enhanced Cryptographic Provider Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "176.113.115.89",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-3071",
          "title": "CISA KEV: CVE-2020-25213 \u2014 WordPress File Manager Plugin Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "178.170.117.50",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-3062",
          "title": "CISA KEV: CVE-2019-16759 \u2014 vBulletin PHP Module Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "178.32.148.5",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2876",
          "title": "CISA KEV: CVE-2020-8515 \u2014 Multiple DrayTek Vigor Routers Web Management Page Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "18.182.153.49",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2850",
          "title": "CISA KEV: CVE-2021-26084 \u2014 Atlassian Confluence Server and Data Center Object-Graph Navigation Language (OGNL) Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "18.185.109.135",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2876",
          "title": "CISA KEV: CVE-2020-8515 \u2014 Multiple DrayTek Vigor Routers Web Management Page Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "18.207.224.249",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-3071",
          "title": "CISA KEV: CVE-2020-25213 \u2014 WordPress File Manager Plugin Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "18.207.254.243",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-3071",
          "title": "CISA KEV: CVE-2020-25213 \u2014 WordPress File Manager Plugin Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "18.220.190.151",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2943",
          "title": "CISA KEV: CVE-2017-7269 \u2014 Microsoft Windows Server Buffer Overflow Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "18.221.115.241",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2950",
          "title": "CISA KEV: CVE-2021-34473 \u2014 Microsoft Exchange Server Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "185.141.24.222",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2858",
          "title": "CISA KEV: CVE-2018-0171 \u2014 Cisco IOS and IOS XE Software Smart Install Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "185.141.24.28",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2858",
          "title": "CISA KEV: CVE-2018-0171 \u2014 Cisco IOS and IOS XE Software Smart Install Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "185.239.242.63",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2872",
          "title": "CISA KEV: CVE-2020-25506 \u2014 D-Link DNS-320 Device Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "185.82.200.181",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2858",
          "title": "CISA KEV: CVE-2018-0171 \u2014 Cisco IOS and IOS XE Software Smart Install Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "185.82.202.34",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2858",
          "title": "CISA KEV: CVE-2018-0171 \u2014 Cisco IOS and IOS XE Software Smart Install Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "188.214.34.20",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2935",
          "title": "CISA KEV: CVE-2021-31201 \u2014 Microsoft Enhanced Cryptographic Provider Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "192.154.253.120",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2803",
          "title": "CISA KEV: CVE-2021-27104 \u2014 Accellion FTA OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        },
        {
          "id": "art-2804",
          "title": "CISA KEV: CVE-2021-27102 \u2014 Accellion FTA OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        },
        {
          "id": "art-2805",
          "title": "CISA KEV: CVE-2021-27101 \u2014 Accellion FTA SQL Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        },
        {
          "id": "art-2806",
          "title": "CISA KEV: CVE-2021-27103 \u2014 Accellion FTA Server-Side Request Forgery (SSRF) Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "192.3.45.185",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2876",
          "title": "CISA KEV: CVE-2020-8515 \u2014 Multiple DrayTek Vigor Routers Web Management Page Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "192.52.167.101",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2803",
          "title": "CISA KEV: CVE-2021-27104 \u2014 Accellion FTA OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        },
        {
          "id": "art-2804",
          "title": "CISA KEV: CVE-2021-27102 \u2014 Accellion FTA OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        },
        {
          "id": "art-2805",
          "title": "CISA KEV: CVE-2021-27101 \u2014 Accellion FTA SQL Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        },
        {
          "id": "art-2806",
          "title": "CISA KEV: CVE-2021-27103 \u2014 Accellion FTA Server-Side Request Forgery (SSRF) Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "192.99.35.149",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-3073",
          "title": "CISA KEV: CVE-2019-9978 \u2014 WordPress Social Warfare Plugin Cross-Site Scripting (XSS) Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "192.99.35.63",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-3073",
          "title": "CISA KEV: CVE-2019-9978 \u2014 WordPress Social Warfare Plugin Cross-Site Scripting (XSS) Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "193.27.229.26",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-3071",
          "title": "CISA KEV: CVE-2020-25213 \u2014 WordPress File Manager Plugin Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "194.88.104.24",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2803",
          "title": "CISA KEV: CVE-2021-27104 \u2014 Accellion FTA OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        },
        {
          "id": "art-2804",
          "title": "CISA KEV: CVE-2021-27102 \u2014 Accellion FTA OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        },
        {
          "id": "art-2805",
          "title": "CISA KEV: CVE-2021-27101 \u2014 Accellion FTA SQL Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        },
        {
          "id": "art-2806",
          "title": "CISA KEV: CVE-2021-27103 \u2014 Accellion FTA Server-Side Request Forgery (SSRF) Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "198.144.189.74",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2950",
          "title": "CISA KEV: CVE-2021-34473 \u2014 Microsoft Exchange Server Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "2.57.33.59",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2850",
          "title": "CISA KEV: CVE-2021-26084 \u2014 Atlassian Confluence Server and Data Center Object-Graph Navigation Language (OGNL) Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "20.185.0.202",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-3071",
          "title": "CISA KEV: CVE-2020-25213 \u2014 WordPress File Manager Plugin Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "203.159.80.241",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2872",
          "title": "CISA KEV: CVE-2020-25506 \u2014 D-Link DNS-320 Device Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "207.148.102.208",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2843",
          "title": "CISA KEV: CVE-2021-30869 \u2014 Apple iOS, iPadOS, and macOS Type Confusion Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "208.113.35.58",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-3037",
          "title": "CISA KEV: CVE-2021-35211 \u2014 SolarWinds Serv-U Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "209.141.50.210",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2850",
          "title": "CISA KEV: CVE-2021-26084 \u2014 Atlassian Confluence Server and Data Center Object-Graph Navigation Language (OGNL) Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "217.23.5.42",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2950",
          "title": "CISA KEV: CVE-2021-34473 \u2014 Microsoft Exchange Server Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "221.168.37.77",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2850",
          "title": "CISA KEV: CVE-2021-26084 \u2014 Atlassian Confluence Server and Data Center Object-Graph Navigation Language (OGNL) Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "34.226.244.53",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-3071",
          "title": "CISA KEV: CVE-2020-25213 \u2014 WordPress File Manager Plugin Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "34.247.148.227",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2850",
          "title": "CISA KEV: CVE-2021-26084 \u2014 Atlassian Confluence Server and Data Center Object-Graph Navigation Language (OGNL) Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "37.139.3.208",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2950",
          "title": "CISA KEV: CVE-2021-34473 \u2014 Microsoft Exchange Server Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "37.46.150.102",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2872",
          "title": "CISA KEV: CVE-2020-25506 \u2014 D-Link DNS-320 Device Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "37.59.35.206",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-3071",
          "title": "CISA KEV: CVE-2020-25213 \u2014 WordPress File Manager Plugin Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "37.59.55.45",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-3073",
          "title": "CISA KEV: CVE-2019-9978 \u2014 WordPress Social Warfare Plugin Cross-Site Scripting (XSS) Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "38.27.99.69",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-3043",
          "title": "CISA KEV: CVE-2020-12271 \u2014 Sophos SFOS SQL Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "45.133.1.133",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2872",
          "title": "CISA KEV: CVE-2020-25506 \u2014 D-Link DNS-320 Device Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "45.135.229.179",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2803",
          "title": "CISA KEV: CVE-2021-27104 \u2014 Accellion FTA OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        },
        {
          "id": "art-2804",
          "title": "CISA KEV: CVE-2021-27102 \u2014 Accellion FTA OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        },
        {
          "id": "art-2805",
          "title": "CISA KEV: CVE-2021-27101 \u2014 Accellion FTA SQL Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        },
        {
          "id": "art-2806",
          "title": "CISA KEV: CVE-2021-27103 \u2014 Accellion FTA Server-Side Request Forgery (SSRF) Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "46.30.189.6",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2854",
          "title": "CISA KEV: CVE-2020-3452 \u2014 Cisco ASA and FTD Read-Only Path Traversal Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "51.11.136.167",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-3071",
          "title": "CISA KEV: CVE-2020-25213 \u2014 WordPress File Manager Plugin Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "51.75.195.137",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2850",
          "title": "CISA KEV: CVE-2021-26084 \u2014 Atlassian Confluence Server and Data Center Object-Graph Navigation Language (OGNL) Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "52.186.156.31",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-3071",
          "title": "CISA KEV: CVE-2020-25213 \u2014 WordPress File Manager Plugin Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "52.207.232.106",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2943",
          "title": "CISA KEV: CVE-2017-7269 \u2014 Microsoft Windows Server Buffer Overflow Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "54.197.4.10",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2943",
          "title": "CISA KEV: CVE-2017-7269 \u2014 Microsoft Windows Server Buffer Overflow Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "66.42.98.220",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-3076",
          "title": "CISA KEV: CVE-2020-10189 \u2014 Zoho ManageEngine Desktop Central File Upload Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "66.7.149.161",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-3062",
          "title": "CISA KEV: CVE-2019-16759 \u2014 vBulletin PHP Module Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "68.235.178.32",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-3037",
          "title": "CISA KEV: CVE-2021-35211 \u2014 SolarWinds Serv-U Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "74.82.201.8",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-3076",
          "title": "CISA KEV: CVE-2020-10189 \u2014 Zoho ManageEngine Desktop Central File Upload Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "77.71.115.52",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-3072",
          "title": "CISA KEV: CVE-2020-11738 \u2014 WordPress Snap Creek Duplicator Plugin File Download Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "79.141.162.82",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2803",
          "title": "CISA KEV: CVE-2021-27104 \u2014 Accellion FTA OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        },
        {
          "id": "art-2804",
          "title": "CISA KEV: CVE-2021-27102 \u2014 Accellion FTA OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        },
        {
          "id": "art-2805",
          "title": "CISA KEV: CVE-2021-27101 \u2014 Accellion FTA SQL Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        },
        {
          "id": "art-2806",
          "title": "CISA KEV: CVE-2021-27103 \u2014 Accellion FTA Server-Side Request Forgery (SSRF) Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "8.47.64.2",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-3073",
          "title": "CISA KEV: CVE-2019-9978 \u2014 WordPress Social Warfare Plugin Cross-Site Scripting (XSS) Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "82.221.136.27",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2952",
          "title": "CISA KEV: CVE-2021-1732 \u2014 Microsoft Win32k Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "86.105.195.120",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2850",
          "title": "CISA KEV: CVE-2021-26084 \u2014 Atlassian Confluence Server and Data Center Object-Graph Navigation Language (OGNL) Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "86.105.195.154",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2850",
          "title": "CISA KEV: CVE-2021-26084 \u2014 Atlassian Confluence Server and Data Center Object-Graph Navigation Language (OGNL) Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "86.57.38.156",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2950",
          "title": "CISA KEV: CVE-2021-34473 \u2014 Microsoft Exchange Server Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "87.106.194.46",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2850",
          "title": "CISA KEV: CVE-2021-26084 \u2014 Atlassian Confluence Server and Data Center Object-Graph Navigation Language (OGNL) Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "91.208.184.78",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-3076",
          "title": "CISA KEV: CVE-2020-10189 \u2014 Zoho ManageEngine Desktop Central File Upload Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "94.23.255.34",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-3073",
          "title": "CISA KEV: CVE-2019-9978 \u2014 WordPress Social Warfare Plugin Cross-Site Scripting (XSS) Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "97.77.97.58",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-3037",
          "title": "CISA KEV: CVE-2021-35211 \u2014 SolarWinds Serv-U Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "98.176.196.89",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-3037",
          "title": "CISA KEV: CVE-2021-35211 \u2014 SolarWinds Serv-U Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "98.239.93.20",
      "type": "ipv4",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2850",
          "title": "CISA KEV: CVE-2021-26084 \u2014 Atlassian Confluence Server and Data Center Object-Graph Navigation Language (OGNL) Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "09a5055db44fc1c9e3add608efff038c",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2925",
          "title": "CISA KEV: CVE-2021-31955 \u2014 Microsoft Windows Kernel Information Disclosure Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        },
        {
          "id": "art-2934",
          "title": "CISA KEV: CVE-2021-31956 \u2014 Microsoft Windows NTFS Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "25a16b0fca9acd71450e02a341064c8d",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2952",
          "title": "CISA KEV: CVE-2021-1732 \u2014 Microsoft Win32k Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "2798c0e836b907e8224520e7e6e4bb42",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2803",
          "title": "CISA KEV: CVE-2021-27104 \u2014 Accellion FTA OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        },
        {
          "id": "art-2804",
          "title": "CISA KEV: CVE-2021-27102 \u2014 Accellion FTA OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        },
        {
          "id": "art-2805",
          "title": "CISA KEV: CVE-2021-27101 \u2014 Accellion FTA SQL Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        },
        {
          "id": "art-2806",
          "title": "CISA KEV: CVE-2021-27103 \u2014 Accellion FTA Server-Side Request Forgery (SSRF) Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "31f05b4ee52f0512c96d0cc6f158e083",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2950",
          "title": "CISA KEV: CVE-2021-34473 \u2014 Microsoft Exchange Server Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "3375fe67827671e121d049f9aabefc3e",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2950",
          "title": "CISA KEV: CVE-2021-34473 \u2014 Microsoft Exchange Server Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "34623dc70d274157dbc6e08b21154a3f",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2950",
          "title": "CISA KEV: CVE-2021-34473 \u2014 Microsoft Exchange Server Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "3e6a16bcf7a9e9e0be25ae28551150f5",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-3050",
          "title": "CISA KEV: CVE-2018-14558 \u2014 Tenda AC7, AC9, and AC10 Routers Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "3e856162c36b532925c8226b4ed3481c",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-3076",
          "title": "CISA KEV: CVE-2020-10189 \u2014 Zoho ManageEngine Desktop Central File Upload Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "4a7bf7f013cc2297d62627b2b78c5b0b",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2850",
          "title": "CISA KEV: CVE-2021-26084 \u2014 Atlassian Confluence Server and Data Center Object-Graph Navigation Language (OGNL) Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "4ee942a0153ed74eb9a98f7ad321ec97",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-3050",
          "title": "CISA KEV: CVE-2018-14558 \u2014 Tenda AC7, AC9, and AC10 Routers Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "522cda0c18b410daa033dc66c48eb75a",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2935",
          "title": "CISA KEV: CVE-2021-31201 \u2014 Microsoft Enhanced Cryptographic Provider Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "5909983db4d9023e4098e56361c96a6f",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-3076",
          "title": "CISA KEV: CVE-2020-10189 \u2014 Zoho ManageEngine Desktop Central File Upload Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "6078c8a0c32f4e634f2952e3ebac2430",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2850",
          "title": "CISA KEV: CVE-2021-26084 \u2014 Atlassian Confluence Server and Data Center Object-Graph Navigation Language (OGNL) Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "659bd19b562059f3f0cc978e15624fd9",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-3076",
          "title": "CISA KEV: CVE-2020-10189 \u2014 Zoho ManageEngine Desktop Central File Upload Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "6bff8b6fd606e795385b84437d1e1e0a",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-3050",
          "title": "CISA KEV: CVE-2018-14558 \u2014 Tenda AC7, AC9, and AC10 Routers Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "733f71eb6cfca905e8904d0fb785fb43",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-3050",
          "title": "CISA KEV: CVE-2018-14558 \u2014 Tenda AC7, AC9, and AC10 Routers Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "73ffd45ab46415b41831faee138f306e",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-3050",
          "title": "CISA KEV: CVE-2018-14558 \u2014 Tenda AC7, AC9, and AC10 Routers Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "75259ee2db52d038efea5f939f68f122",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2850",
          "title": "CISA KEV: CVE-2021-26084 \u2014 Atlassian Confluence Server and Data Center Object-Graph Navigation Language (OGNL) Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "7966c2c546b71e800397a67f942858d0",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-3076",
          "title": "CISA KEV: CVE-2020-10189 \u2014 Zoho ManageEngine Desktop Central File Upload Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "7c2b567b659246d2b278da500daa9abe",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2950",
          "title": "CISA KEV: CVE-2021-34473 \u2014 Microsoft Exchange Server Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "8cc2b831e29dc9f4832a162e9f425649",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2850",
          "title": "CISA KEV: CVE-2021-26084 \u2014 Atlassian Confluence Server and Data Center Object-Graph Navigation Language (OGNL) Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "911e417b9bc8689a3eed828f0b39f579",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2850",
          "title": "CISA KEV: CVE-2021-26084 \u2014 Atlassian Confluence Server and Data Center Object-Graph Navigation Language (OGNL) Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "a43ad8a740081f0b5a89e219fe8475a3",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2850",
          "title": "CISA KEV: CVE-2021-26084 \u2014 Atlassian Confluence Server and Data Center Object-Graph Navigation Language (OGNL) Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "a89cefdf71f2fced35fba8612ad07174",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-3050",
          "title": "CISA KEV: CVE-2018-14558 \u2014 Tenda AC7, AC9, and AC10 Routers Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "a8eb59396d698bda5840c8b73c34a03b",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2850",
          "title": "CISA KEV: CVE-2021-26084 \u2014 Atlassian Confluence Server and Data Center Object-Graph Navigation Language (OGNL) Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "bdfd11b1b092b7c61ce5f02ffc5ad55a",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2803",
          "title": "CISA KEV: CVE-2021-27104 \u2014 Accellion FTA OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        },
        {
          "id": "art-2804",
          "title": "CISA KEV: CVE-2021-27102 \u2014 Accellion FTA OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        },
        {
          "id": "art-2805",
          "title": "CISA KEV: CVE-2021-27101 \u2014 Accellion FTA SQL Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        },
        {
          "id": "art-2806",
          "title": "CISA KEV: CVE-2021-27103 \u2014 Accellion FTA Server-Side Request Forgery (SSRF) Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "bf8a7b199f3293852c7f2b3578e8c0ae",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2850",
          "title": "CISA KEV: CVE-2021-26084 \u2014 Atlassian Confluence Server and Data Center Object-Graph Navigation Language (OGNL) Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "c5cb2b438ba6d809f1f71c776376d293",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-3050",
          "title": "CISA KEV: CVE-2018-14558 \u2014 Tenda AC7, AC9, and AC10 Routers Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "cfc0f745941ce1ec024cb86b1fd244f3",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-3050",
          "title": "CISA KEV: CVE-2018-14558 \u2014 Tenda AC7, AC9, and AC10 Routers Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "d4a55e486f5e28168bc4554cffa64ea0",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2950",
          "title": "CISA KEV: CVE-2021-34473 \u2014 Microsoft Exchange Server Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "d6b850c950379d5ee0f254f7164833e8",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2925",
          "title": "CISA KEV: CVE-2021-31955 \u2014 Microsoft Windows Kernel Information Disclosure Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        },
        {
          "id": "art-2934",
          "title": "CISA KEV: CVE-2021-31956 \u2014 Microsoft Windows NTFS Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "f0551696774f66ad3485445d9e3f7214",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2850",
          "title": "CISA KEV: CVE-2021-26084 \u2014 Atlassian Confluence Server and Data Center Object-Graph Navigation Language (OGNL) Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "085a136c03f8b024a173068768c67b1a5ad928c1",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2839",
          "title": "CISA KEV: CVE-2021-30657 \u2014 Apple macOS Unspecified Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "0902181D1B9433B5616763646A089B1BDF428262",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2943",
          "title": "CISA KEV: CVE-2017-7269 \u2014 Microsoft Windows Server Buffer Overflow Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "0AB00045D0D403F2D8F8865120C1089C09BA4FEE",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2943",
          "title": "CISA KEV: CVE-2017-7269 \u2014 Microsoft Windows Server Buffer Overflow Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "11D7694987A32A91FB766BA221F9A2DE3C06D173",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2943",
          "title": "CISA KEV: CVE-2017-7269 \u2014 Microsoft Windows Server Buffer Overflow Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "20ac95c44549710a434902267394525333e96c0b",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2839",
          "title": "CISA KEV: CVE-2021-30657 \u2014 Apple macOS Unspecified Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "31721AE37835F792EE792D8324E307BA423277AE",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2943",
          "title": "CISA KEV: CVE-2017-7269 \u2014 Microsoft Windows Server Buffer Overflow Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "3664e6e27fb2784f44f6dba6105ac8b90793032a",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2950",
          "title": "CISA KEV: CVE-2021-34473 \u2014 Microsoft Exchange Server Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "37D4CC67351B2BD8067AB99973C4AFD7090DB1E9",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2943",
          "title": "CISA KEV: CVE-2017-7269 \u2014 Microsoft Windows Server Buffer Overflow Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "52413AE19BBCDB9339D38A6F305E040FE83DEE1B",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2943",
          "title": "CISA KEV: CVE-2017-7269 \u2014 Microsoft Windows Server Buffer Overflow Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "55869270ed20956e5c3e5533fb4472e4eb533dc2",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2839",
          "title": "CISA KEV: CVE-2021-30657 \u2014 Apple macOS Unspecified Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "76640508b1e7759e548771a5359eaed353bf1eec",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-3036",
          "title": "CISA KEV: CVE-2020-10148 \u2014 SolarWinds Orion Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "83d21bb502b73016ec0ad7d6c725d71aaffa0f6d",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2950",
          "title": "CISA KEV: CVE-2021-34473 \u2014 Microsoft Exchange Server Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "9FCB3943660203E99C348F17A8801BA077F7CB40",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2943",
          "title": "CISA KEV: CVE-2017-7269 \u2014 Microsoft Windows Server Buffer Overflow Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "A0BC6EA2BFA1D3D895FE8E706737D490D5FE3987",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2943",
          "title": "CISA KEV: CVE-2017-7269 \u2014 Microsoft Windows Server Buffer Overflow Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "bffa4462901b74dbfbfffaa3a3db27daa61211412",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2925",
          "title": "CISA KEV: CVE-2021-31955 \u2014 Microsoft Windows Kernel Information Disclosure Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        },
        {
          "id": "art-2934",
          "title": "CISA KEV: CVE-2021-31956 \u2014 Microsoft Windows NTFS Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "dafd571da1df72fb53bcd250e8b901103b51d6e4",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2935",
          "title": "CISA KEV: CVE-2021-31201 \u2014 Microsoft Enhanced Cryptographic Provider Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "e63ed3b56a5f9a1ea5c92d3d2444196ea13be94b",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2925",
          "title": "CISA KEV: CVE-2021-31955 \u2014 Microsoft Windows Kernel Information Disclosure Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        },
        {
          "id": "art-2934",
          "title": "CISA KEV: CVE-2021-31956 \u2014 Microsoft Windows NTFS Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "ef949770ae46bb58918b0fe127bec0ec300b18a9",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2950",
          "title": "CISA KEV: CVE-2021-34473 \u2014 Microsoft Exchange Server Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "02ac3a4f1cfb2723c20f3c7678b62c340c7974b95f8d9320941641d5c6fd2fee",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2950",
          "title": "CISA KEV: CVE-2021-34473 \u2014 Microsoft Exchange Server Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "03bfec4e039805091fe30fa978d5ec7f28431bb0fca4b137e075257b3e1c0dd4",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-3062",
          "title": "CISA KEV: CVE-2019-16759 \u2014 vBulletin PHP Module Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "051baaabf205c7c0f5fd455ac5775447f9f3df0cc9bc5f66f6d386f368520581",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-3062",
          "title": "CISA KEV: CVE-2019-16759 \u2014 vBulletin PHP Module Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "05908f2a1325c130e3a877a32dfdf1c9596d156d031d0eaa54473fe342206a65",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2917",
          "title": "CISA KEV: CVE-2020-7961 \u2014 Liferay Portal Deserialization of Untrusted Data Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "0747988a77c89c1267a882b663fbd4168e25aed239fb1553e65bb4ac74ecda67",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-3062",
          "title": "CISA KEV: CVE-2019-16759 \u2014 vBulletin PHP Module Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "097549cf7d0f76f0d99edf8b2d91c60977fd6a96e4b8c3c94b0b1733dc026d3e",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2992",
          "title": "CISA KEV: CVE-2021-26857 \u2014 Microsoft Exchange Server Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "1900e09983acf7ddc658b860be7875a527bc914cbffcf0aaff0b4182ecef047b",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-3062",
          "title": "CISA KEV: CVE-2019-16759 \u2014 vBulletin PHP Module Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "1cf9ac9150d59de25ca5ac1f855fadf1b03f13b4e9ced63a12acef9c8292a648",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-3062",
          "title": "CISA KEV: CVE-2019-16759 \u2014 vBulletin PHP Module Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "26b3c9a5077232c1bbb5c5b4fc5513e3e0b54a735c32ae90a6d6c1e1d7e4cc0f",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2952",
          "title": "CISA KEV: CVE-2021-1732 \u2014 Microsoft Win32k Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "2a09719254934fe8ee8f200a0a7537d35a293fe1f8d0e396e23374e9b209f273",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2872",
          "title": "CISA KEV: CVE-2020-25506 \u2014 D-Link DNS-320 Device Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "2e0df09fa37eabcae645302d9865913b818ee0993199a6d904728f3093ff48c7",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2803",
          "title": "CISA KEV: CVE-2021-27104 \u2014 Accellion FTA OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        },
        {
          "id": "art-2804",
          "title": "CISA KEV: CVE-2021-27102 \u2014 Accellion FTA OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        },
        {
          "id": "art-2805",
          "title": "CISA KEV: CVE-2021-27101 \u2014 Accellion FTA SQL Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        },
        {
          "id": "art-2806",
          "title": "CISA KEV: CVE-2021-27103 \u2014 Accellion FTA Server-Side Request Forgery (SSRF) Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "32519b85c0b422e4656de6e6c41878e95fd95026267daab4215ee59c107d6c77",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-3036",
          "title": "CISA KEV: CVE-2020-10148 \u2014 SolarWinds Orion Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "372ab5c1c23d198b594353239a96d6cf620cc56588f5fdf5dfb32919dd019020",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-3062",
          "title": "CISA KEV: CVE-2019-16759 \u2014 vBulletin PHP Module Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "39b6d72101adae2b71815328599f8e67ee27955849dfb3825c5b2731d504696b",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-3062",
          "title": "CISA KEV: CVE-2019-16759 \u2014 vBulletin PHP Module Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "3b1395f620e428c5f68c6497a2338da0c4f749feb64e8f12e4c5b1288cc57a1c",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2811",
          "title": "CISA KEV: CVE-2018-4878 \u2014 Adobe Flash Player Use-After-Free Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "41ef0133acaca395ea957e796dc1b939b9825b1414541c616b8ca8bdfadb8d16",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2876",
          "title": "CISA KEV: CVE-2020-8515 \u2014 Multiple DrayTek Vigor Routers Web Management Page Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "4ff21e69b11566336f4fd56ac2829cdcf215182e8ff807f8e744c0a2b08f726f",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-3062",
          "title": "CISA KEV: CVE-2019-16759 \u2014 vBulletin PHP Module Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "54077a5b15638e354fa02318623775b7a1cc0e8c21e59bcbab333035369e377f",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2935",
          "title": "CISA KEV: CVE-2021-31201 \u2014 Microsoft Enhanced Cryptographic Provider Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "554bee9f896a7a013804485894875348ff760b08ff7b0ae14c210e2b37da75f6",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2872",
          "title": "CISA KEV: CVE-2020-25506 \u2014 D-Link DNS-320 Device Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "5f1e0e3cc38f7888b89a9adddb745a341c5f65165dadc311ca389789cc9c6889",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-3071",
          "title": "CISA KEV: CVE-2020-25213 \u2014 WordPress File Manager Plugin Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "5fa2b9546770241da7305356d6427847598288290866837626f621d794692c1b",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2803",
          "title": "CISA KEV: CVE-2021-27104 \u2014 Accellion FTA OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        },
        {
          "id": "art-2804",
          "title": "CISA KEV: CVE-2021-27102 \u2014 Accellion FTA OS Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        },
        {
          "id": "art-2805",
          "title": "CISA KEV: CVE-2021-27101 \u2014 Accellion FTA SQL Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        },
        {
          "id": "art-2806",
          "title": "CISA KEV: CVE-2021-27103 \u2014 Accellion FTA Server-Side Request Forgery (SSRF) Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "60d22223625c86d7f3deb20f41aec40bc8e1df3ab02cf379d95554df05edf55c",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2950",
          "title": "CISA KEV: CVE-2021-34473 \u2014 Microsoft Exchange Server Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "65dca34b04416f9a113f09718cbe51e11fd58e7287b7863e37f393ed4d25dde7",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2935",
          "title": "CISA KEV: CVE-2021-31201 \u2014 Microsoft Enhanced Cryptographic Provider Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "667640d293e4ce2287546fc2e0056ee14f414868bf5b77f72078096c516a9fb0",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2872",
          "title": "CISA KEV: CVE-2020-25506 \u2014 D-Link DNS-320 Device Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "66ea76a427b69f153486f962baff29d4a68393e985c7d88c94d773b25ad4964a",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2872",
          "title": "CISA KEV: CVE-2020-25506 \u2014 D-Link DNS-320 Device Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "68132010d9a543a6a2a9ea61e771cf2c041cea259cc76affdfe663e20c130a45",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-3062",
          "title": "CISA KEV: CVE-2019-16759 \u2014 vBulletin PHP Module Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "695a0b2ef0d46027d2f106c060dade52b34e3bb7342a8eae906c7d2b15a99fc3",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2876",
          "title": "CISA KEV: CVE-2020-8515 \u2014 Multiple DrayTek Vigor Routers Web Management Page Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "6ae71f71db042e43077941abe4d56753e0947b9464eac4e03567ec5356d9a22b",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-3026",
          "title": "CISA KEV: CVE-2020-11652 \u2014 SaltStack Salt Path Traversal Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        },
        {
          "id": "art-3027",
          "title": "CISA KEV: CVE-2020-11651 \u2014 SaltStack Salt Authentication Bypass Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "6e25ad03103a1a972b78c642bac09060fa79c460011dc5748cbb433cc459938b",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-3071",
          "title": "CISA KEV: CVE-2020-25213 \u2014 WordPress File Manager Plugin Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "6f191f598589b7708b1890d56b374b45c6eb41610d34f976f0b4cfde8d5731af",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2953",
          "title": "CISA KEV: CVE-2021-34527 \u2014 Microsoft Windows Print Spooler Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "72492605815c59579170adef1519231a5e3f17ada26428d20bd7948041c812a3",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2876",
          "title": "CISA KEV: CVE-2020-8515 \u2014 Multiple DrayTek Vigor Routers Web Management Page Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "77b4f7f0d66a0333d756116eaae567a8540392f558c49d507bf6da10bd047fe3",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-3062",
          "title": "CISA KEV: CVE-2019-16759 \u2014 vBulletin PHP Module Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "7b64a739836c6b436c179eac37c446fee5ba5abc6c96206cf8e454744a0cd5f2",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2952",
          "title": "CISA KEV: CVE-2021-1732 \u2014 Microsoft Win32k Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "7c7273d0ac2aaba3116c3021530c1c868dc848b6fdd2aafa1deecac216131779",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2917",
          "title": "CISA KEV: CVE-2020-7961 \u2014 Liferay Portal Deserialization of Untrusted Data Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "80cd13bfcc2fc29096abf18525d17766700a6d25a9806e55c7b7de776cba0302",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2872",
          "title": "CISA KEV: CVE-2020-25506 \u2014 D-Link DNS-320 Device Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "80fb66c6b1191954c31734355a236b7342dc3fd074ead47f9c1ed465561c6e8c",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-3062",
          "title": "CISA KEV: CVE-2019-16759 \u2014 vBulletin PHP Module Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "84448ee487010d6fed918febe230b71a8ec1266e300f85933014db2566645857",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-3062",
          "title": "CISA KEV: CVE-2019-16759 \u2014 vBulletin PHP Module Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "88ddd8a1b77477aaffd1bb163b9770d72a77bf29bfca226e79c28d15bef983ed",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-3062",
          "title": "CISA KEV: CVE-2019-16759 \u2014 vBulletin PHP Module Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "8a17279ba26c8fbe6966ea3300fdefb1adae1b3ed68f76a7fc81413bd8c1a5f6",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2925",
          "title": "CISA KEV: CVE-2021-31955 \u2014 Microsoft Windows Kernel Information Disclosure Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        },
        {
          "id": "art-2934",
          "title": "CISA KEV: CVE-2021-31956 \u2014 Microsoft Windows NTFS Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "8b5810e07cf21ebb1c2ff23c13ce88022c1dd5bc2df32f4d7e5480b4ddb82de2",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-3062",
          "title": "CISA KEV: CVE-2019-16759 \u2014 vBulletin PHP Module Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "8dd620d9aeb35960bb766458c8890ede987c33d239cf730f93fe49d90ae759dd",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2916",
          "title": "CISA KEV: CVE-2021-30116 \u2014 Kaseya Virtual System/Server Administrator (VSA) Information Disclosure Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "8fae0d5860aa44b5c7260ef7a0b277bcddae8c02cea7d3a9c19f1a40388c223f",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2843",
          "title": "CISA KEV: CVE-2021-30869 \u2014 Apple iOS, iPadOS, and macOS Type Confusion Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "94f02ea10b4546da71bd46916f0fe260b40c8ed4deccf0588687e62ca3819ad7",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-3062",
          "title": "CISA KEV: CVE-2019-16759 \u2014 vBulletin PHP Module Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "982f7c4700c75b81833d5d59ad29147c392b20c760fe36b200b541a0f841c8a9",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2925",
          "title": "CISA KEV: CVE-2021-31955 \u2014 Microsoft Windows Kernel Information Disclosure Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        },
        {
          "id": "art-2934",
          "title": "CISA KEV: CVE-2021-31956 \u2014 Microsoft Windows NTFS Privilege Escalation Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "98ccde0e1a5e6c7071623b8b294df53d8e750ff2fa22070b19a88faeaa3d32b0",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2950",
          "title": "CISA KEV: CVE-2021-34473 \u2014 Microsoft Exchange Server Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "994889422b24a5b4759eda30265f1b933a458e15927b4f7949d4a3ba79eb43ca",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-3062",
          "title": "CISA KEV: CVE-2019-16759 \u2014 vBulletin PHP Module Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "99d06d1c82af244b1533c1173ca10da7f29bfbf753073f20f5dc7a0016152a4c",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-3062",
          "title": "CISA KEV: CVE-2019-16759 \u2014 vBulletin PHP Module Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "a447bb67be310702807ff148f53f2b4c64ddba0c37f92caf6acabdfaa9ad6603",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2872",
          "title": "CISA KEV: CVE-2020-25506 \u2014 D-Link DNS-320 Device Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "a68ab806c8e111e98ba46d5bfdabd9091a68839dd39dfe81e887361bd4994a62",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-3071",
          "title": "CISA KEV: CVE-2020-25213 \u2014 WordPress File Manager Plugin Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "a7373fa18b367edbcd4462345a5da087821e34734bdf05d1c4060a7694868c5e",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-3062",
          "title": "CISA KEV: CVE-2019-16759 \u2014 vBulletin PHP Module Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "ab671fc0c68ed1c249c2bb52b28ae3d70df8bd1614d86f6d6a3f4c21d7841d72",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-3062",
          "title": "CISA KEV: CVE-2019-16759 \u2014 vBulletin PHP Module Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "ac4f2e74a7b90b772afb920f10b789415355451c79b3ed359ccad1976c1857a8",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2917",
          "title": "CISA KEV: CVE-2020-7961 \u2014 Liferay Portal Deserialization of Untrusted Data Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "ac6818140883e0f8bf5cef9b5f965861ff64cebfe181ff025e1f0aee9c72506c",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2917",
          "title": "CISA KEV: CVE-2020-7961 \u2014 Liferay Portal Deserialization of Untrusted Data Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "b2122c5a9c738d964fa770760db40d6708de377e2e671feccb836054ceda2f47",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2872",
          "title": "CISA KEV: CVE-2020-25506 \u2014 D-Link DNS-320 Device Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "b4cb04709f613b5363514e75984084ef1d3eaba7c50638b2a5a284680831b992",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-3062",
          "title": "CISA KEV: CVE-2019-16759 \u2014 vBulletin PHP Module Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "b75f163ca9b9240bf4b37ad92bc7556b40a17e27c2b8ed5c8991385fe07d17d0",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2992",
          "title": "CISA KEV: CVE-2021-26857 \u2014 Microsoft Exchange Server Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "bd72be4f7d64795b902f352e47b1654eaee6b5a71cddfaf2c245dba1b2d602eb",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-3062",
          "title": "CISA KEV: CVE-2019-16759 \u2014 vBulletin PHP Module Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "beb0b7178b242f2dba21c3d91abf80e8738847b8086d2a42e9352738c83542b5",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2872",
          "title": "CISA KEV: CVE-2020-25506 \u2014 D-Link DNS-320 Device Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "c379139347470254f19041f05e19f5454750e052f04f6d377ec8df19ce959519",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-3062",
          "title": "CISA KEV: CVE-2019-16759 \u2014 vBulletin PHP Module Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "cbbfd767774de9fecc4f8d2bdc4c23595c804113a3f6246ec4dfe2b47cb4d34c",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2843",
          "title": "CISA KEV: CVE-2021-30869 \u2014 Apple iOS, iPadOS, and macOS Type Confusion Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "cf172b4629e321e4c78a1d0717130bbb693392712a86d3d85d035bae1f377dbd",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-3062",
          "title": "CISA KEV: CVE-2019-16759 \u2014 vBulletin PHP Module Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "cf5edcff4053e29cb236d3ed1fe06ca93ae6f64f26e25117d68ee130b9bc60c8",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2843",
          "title": "CISA KEV: CVE-2021-30869 \u2014 Apple iOS, iPadOS, and macOS Type Confusion Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "d55f983c994caa160ec63a59f6b4250fe67fb3e8c43a388aec60a4a6978e9f1e",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2916",
          "title": "CISA KEV: CVE-2021-30116 \u2014 Kaseya Virtual System/Server Administrator (VSA) Information Disclosure Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "d854f775ab1071eebadc0eb44d8571c387567c233a71d2e26242cd9a80e67309",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-3076",
          "title": "CISA KEV: CVE-2020-10189 \u2014 Zoho ManageEngine Desktop Central File Upload Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "dc4186dd9b3a4af8565f87a9a799644fce8af25e3ee8777d90ae660d48497a04",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2950",
          "title": "CISA KEV: CVE-2021-34473 \u2014 Microsoft Exchange Server Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "dd603db3e2c0800d5eaa262b6b8553c68deaa486b545d4965df5dc43217cc839",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-3071",
          "title": "CISA KEV: CVE-2020-25213 \u2014 WordPress File Manager Plugin Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "de9ef08a148305963accb8a64eb22117916aa42ab0eddf60ccb8850468a194fc",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-3076",
          "title": "CISA KEV: CVE-2020-10189 \u2014 Zoho ManageEngine Desktop Central File Upload Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "dec56b06e03665d2c656b530d3b6f90ca0ec2925bec4559d8a2cec5da3a7700b",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-3062",
          "title": "CISA KEV: CVE-2019-16759 \u2014 vBulletin PHP Module Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "ded23c3f5f2950257d8cfb215c40d5f54b28fde23c02f61ce1eb746843f43397",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-3062",
          "title": "CISA KEV: CVE-2019-16759 \u2014 vBulletin PHP Module Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "def1959fae2d8a3dfe606126ceb9d5403deae97a4b4e216dc8e60354980eeac4",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2872",
          "title": "CISA KEV: CVE-2020-25506 \u2014 D-Link DNS-320 Device Command Injection Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "df5b588f555cccdf4bbf695158b10b5d3a5f463da7e36d26bdf8b7ba0f8ed144",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2843",
          "title": "CISA KEV: CVE-2021-30869 \u2014 Apple iOS, iPadOS, and macOS Type Confusion Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "e1546323dc746ed2f7a5c973dcecc79b014b68bdd8a6230239283b4f775f4bbd",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2811",
          "title": "CISA KEV: CVE-2018-4878 \u2014 Adobe Flash Player Use-After-Free Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "e2a24ab94f865caeacdf2c3ad015f31f23008ac6db8312c2cbfb32e4a5466ea2",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2916",
          "title": "CISA KEV: CVE-2021-30116 \u2014 Kaseya Virtual System/Server Administrator (VSA) Information Disclosure Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "e3eac25c3beb77ffed609c53b447a81ec8a0e20fb94a6442a51d72ca9e6f7cd2",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2950",
          "title": "CISA KEV: CVE-2021-34473 \u2014 Microsoft Exchange Server Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "ef2a6b37568e14dacd5d8894ce2e4bbc593ffd58e197827a052d2c2f0a756949",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-3062",
          "title": "CISA KEV: CVE-2019-16759 \u2014 vBulletin PHP Module Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "f0b12413c9d291e3b9edd1ed1496af7712184a63c066e1d5b2bb528376d66ebc",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2843",
          "title": "CISA KEV: CVE-2021-30869 \u2014 Apple iOS, iPadOS, and macOS Type Confusion Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "f1c5bed9560a1afe9d5575e923e480e7e8030e10bc3d7c0d842b1a64f49f8794",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-3071",
          "title": "CISA KEV: CVE-2020-25213 \u2014 WordPress File Manager Plugin Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "f30bb52c0e32dfe524fc0dfda1724a1ffb88647c39c33a66dfd66109fecceec7",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-3062",
          "title": "CISA KEV: CVE-2019-16759 \u2014 vBulletin PHP Module Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "f91f2a7e1944734371562f18b066f193605e07223aab90bd1e8925e23bbeaa1c",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-3076",
          "title": "CISA KEV: CVE-2020-10189 \u2014 Zoho ManageEngine Desktop Central File Upload Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "fa7575bd0cd2a83995ea34d8d008eb07c2062a843e5e155e2e8d8b35a0cf7901",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-3062",
          "title": "CISA KEV: CVE-2019-16759 \u2014 vBulletin PHP Module Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "fd63b9c7e9dce51348d9600f67139ea8959fdbbca84d505b5e9317bbdca74016",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-3062",
          "title": "CISA KEV: CVE-2019-16759 \u2014 vBulletin PHP Module Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "fec71b8479f3a416fa58580ae76a8c731c2294c24663c601a1267e0e5c2678a0",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-2811",
          "title": "CISA KEV: CVE-2018-4878 \u2014 Adobe Flash Player Use-After-Free Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "fed0f0d3e9d990f8a83b86d29e586d46e7cac54efb0eae2f07112d61afb9b885",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "CISA KEV"
      ],
      "articles": [
        {
          "id": "art-3062",
          "title": "CISA KEV: CVE-2019-16759 \u2014 vBulletin PHP Module Remote Code Execution Vulnerability",
          "link": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
          "published": "2021-11-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-11-03"
    },
    {
      "value": "CVE-2017-20162",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-3125",
          "title": "Plugins to put Node.js application security and observability in your IDE",
          "link": "https://snyk.io/blog/lightrun-snyk-plugins-node-js-application-security-observability-ide/",
          "published": "2021-08-23",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-08-23"
    },
    {
      "value": "CVE-2020-9484",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-3127",
          "title": "How Snyk Social Trends help you fix essential security vulnerabilities",
          "link": "https://snyk.io/blog/snyk-social-trends-fix-security-vulnerabilities/",
          "published": "2021-08-18",
          "sev": "high"
        }
      ],
      "first_seen": "2021-08-18"
    },
    {
      "value": "CVE-2020-8184",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-3132",
          "title": "Better Ruby Gemfile security: A step-by-step guide using Snyk",
          "link": "https://snyk.io/blog/better-ruby-gemfile-security-step-by-step-guide-snyk/",
          "published": "2021-08-10",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-08-10"
    },
    {
      "value": "CVE-2021-26291",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-3144",
          "title": "Why you should upgrade to Maven version 3.8.1",
          "link": "https://snyk.io/blog/why-you-should-upgrade-to-maven-version-3-8-1/",
          "published": "2021-07-19",
          "sev": "high"
        }
      ],
      "first_seen": "2021-07-19"
    },
    {
      "value": "dreamslab.com",
      "type": "domain",
      "confidence": "high",
      "extraction": "defanged",
      "severity": "med",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-3148",
          "title": "SnykCon 2021 excitement is starting, but the CFP is ending (soon)",
          "link": "https://snyk.io/blog/snykcon-2021-excitement-starting-cfp-ending/",
          "published": "2021-07-12",
          "sev": "med"
        }
      ],
      "first_seen": "2021-07-12"
    },
    {
      "value": "CVE-2019-11253",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-3149",
          "title": "Hardening Amazon EKS security with RBAC, secure IMDS, and audit logging",
          "link": "https://snyk.io/blog/hardening-aws-eks-security-rbac-secure-imds-audit-logging/",
          "published": "2021-07-07",
          "sev": "high"
        }
      ],
      "first_seen": "2021-07-07"
    },
    {
      "value": "CVE-2020-8559",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-3149",
          "title": "Hardening Amazon EKS security with RBAC, secure IMDS, and audit logging",
          "link": "https://snyk.io/blog/hardening-aws-eks-security-rbac-secure-imds-audit-logging/",
          "published": "2021-07-07",
          "sev": "high"
        }
      ],
      "first_seen": "2021-07-07"
    },
    {
      "value": "CVE-2018-12120",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-3177",
          "title": "Snyk uncovers supply chain security vulnerabilities in Visual Studio Code extensions",
          "link": "https://snyk.io/blog/vulnerable-visual-studio-code-extensions-marketplace/",
          "published": "2021-05-26",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-05-26"
    },
    {
      "value": "CVE-2019-13567",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-3177",
          "title": "Snyk uncovers supply chain security vulnerabilities in Visual Studio Code extensions",
          "link": "https://snyk.io/blog/vulnerable-visual-studio-code-extensions-marketplace/",
          "published": "2021-05-26",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-05-26"
    },
    {
      "value": "CVE-2020-8801",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-3188",
          "title": "SuiteCRM: PHAR deserialization vulnerability to code execution",
          "link": "https://snyk.io/blog/suitecrm-phar-deserialization-vulnerability-to-code-execution/",
          "published": "2021-05-07",
          "sev": "high"
        }
      ],
      "first_seen": "2021-05-07"
    },
    {
      "value": "6b8f472cd174d02167bc0a0c908ec9e0",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-3188",
          "title": "SuiteCRM: PHAR deserialization vulnerability to code execution",
          "link": "https://snyk.io/blog/suitecrm-phar-deserialization-vulnerability-to-code-execution/",
          "published": "2021-05-07",
          "sev": "high"
        }
      ],
      "first_seen": "2021-05-07"
    },
    {
      "value": "571cbfa209da4c8280a5359f301115de25b4c6e3",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-3188",
          "title": "SuiteCRM: PHAR deserialization vulnerability to code execution",
          "link": "https://snyk.io/blog/suitecrm-phar-deserialization-vulnerability-to-code-execution/",
          "published": "2021-05-07",
          "sev": "high"
        }
      ],
      "first_seen": "2021-05-07"
    },
    {
      "value": "c365dec0cfdf64d8cfd43ebd8f2bcd534cfe7b71849796dfb3030b4fe5ff7f93",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-3213",
          "title": "Developer driven workflows: Dockerfile image scanning, prioritization, and remediation",
          "link": "https://snyk.io/blog/dockerfile-optimization-and-docker-image-security-scanning/",
          "published": "2021-03-26",
          "sev": "high"
        }
      ],
      "first_seen": "2021-03-26"
    },
    {
      "value": "CVE-2020-8554",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-3230",
          "title": "Snyk IaC scanning enhancements include Azure and AWS infrastructure as code",
          "link": "https://snyk.io/blog/snyk-iac-scanning-enhancements-include-aws-infrastructure-as-code/",
          "published": "2021-02-23",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-02-23"
    },
    {
      "value": "adae6cf9abdb84b63919cc27c2ecafcb",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-3237",
          "title": "AWS vulnerability scanning using the Snyk integration",
          "link": "https://snyk.io/blog/aws-vulnerability-scanning-using-the-snyk-integration/",
          "published": "2021-02-10",
          "sev": "high"
        }
      ],
      "first_seen": "2021-02-10"
    },
    {
      "value": "ca6c19e25b4d7917769ee535f0b073e04e8ddc32ead83493c03abc65e82e5e6c",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-3237",
          "title": "AWS vulnerability scanning using the Snyk integration",
          "link": "https://snyk.io/blog/aws-vulnerability-scanning-using-the-snyk-integration/",
          "published": "2021-02-10",
          "sev": "high"
        }
      ],
      "first_seen": "2021-02-10"
    },
    {
      "value": "cd100d7c505ced1f5c4f4eb6fbd7ac83a623f9bb483db1e828fb4cd3b3c01bd9",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-3237",
          "title": "AWS vulnerability scanning using the Snyk integration",
          "link": "https://snyk.io/blog/aws-vulnerability-scanning-using-the-snyk-integration/",
          "published": "2021-02-10",
          "sev": "high"
        }
      ],
      "first_seen": "2021-02-10"
    },
    {
      "value": "CVE-2020-28473",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-3248",
          "title": "Cache poisoning in popular open source packages",
          "link": "https://snyk.io/blog/cache-poisoning-in-popular-open-source-packages/",
          "published": "2021-01-18",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-01-18"
    },
    {
      "value": "CVE-2021-23336",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-3248",
          "title": "Cache poisoning in popular open source packages",
          "link": "https://snyk.io/blog/cache-poisoning-in-popular-open-source-packages/",
          "published": "2021-01-18",
          "sev": "crit"
        }
      ],
      "first_seen": "2021-01-18"
    },
    {
      "value": "CVE-2017-7308",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-3268",
          "title": "Kernel privilege escalation: how Kubernetes container isolation impacts privilege escalation attacks",
          "link": "https://snyk.io/blog/kernel-privilege-escalation/",
          "published": "2020-12-03",
          "sev": "crit"
        }
      ],
      "first_seen": "2020-12-03"
    },
    {
      "value": "01a2038b20d165ab7df81934f9849bdfbc59bd6f6322c5d11e341504f66ec266",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-3280",
          "title": "Container image formats under the hood",
          "link": "https://snyk.io/blog/container-image-formats/",
          "published": "2020-11-18",
          "sev": "high"
        }
      ],
      "first_seen": "2020-11-18"
    },
    {
      "value": "171857c49d0f5e2ebf623e6cb36a8bcad585ed0c2aa99c87a055df034c1e5848",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-3280",
          "title": "Container image formats under the hood",
          "link": "https://snyk.io/blog/container-image-formats/",
          "published": "2020-11-18",
          "sev": "high"
        }
      ],
      "first_seen": "2020-11-18"
    },
    {
      "value": "33a51d09088285451e7a7525d4bd64fc15563264afe5a91ef84a8b3042018899",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-3280",
          "title": "Container image formats under the hood",
          "link": "https://snyk.io/blog/container-image-formats/",
          "published": "2020-11-18",
          "sev": "high"
        }
      ],
      "first_seen": "2020-11-18"
    },
    {
      "value": "419640447d267f068d2f84a093cb13a56ce77e130877f5b8bdb4294f4a90a84f",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-3280",
          "title": "Container image formats under the hood",
          "link": "https://snyk.io/blog/container-image-formats/",
          "published": "2020-11-18",
          "sev": "high"
        }
      ],
      "first_seen": "2020-11-18"
    },
    {
      "value": "45c6f8f1b2fe15adaa72305616d69a6cd641169bc8b16886756919e7c01fa48b",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-3280",
          "title": "Container image formats under the hood",
          "link": "https://snyk.io/blog/container-image-formats/",
          "published": "2020-11-18",
          "sev": "high"
        }
      ],
      "first_seen": "2020-11-18"
    },
    {
      "value": "46076a325f0de3f745254638b8b0f0de343685b34e7ca6ec5cd0b6b7930eb7fa",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-3280",
          "title": "Container image formats under the hood",
          "link": "https://snyk.io/blog/container-image-formats/",
          "published": "2020-11-18",
          "sev": "high"
        }
      ],
      "first_seen": "2020-11-18"
    },
    {
      "value": "468327b5cd7ce539db695bd0ef05dae8a4ff77b02870a8e823ed74dedad4bd55",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-3280",
          "title": "Container image formats under the hood",
          "link": "https://snyk.io/blog/container-image-formats/",
          "published": "2020-11-18",
          "sev": "high"
        }
      ],
      "first_seen": "2020-11-18"
    },
    {
      "value": "56def654ec22f857f480cdcc640c474e2f84d4be2e549a9d16eaba3f397596e9",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-3280",
          "title": "Container image formats under the hood",
          "link": "https://snyk.io/blog/container-image-formats/",
          "published": "2020-11-18",
          "sev": "high"
        }
      ],
      "first_seen": "2020-11-18"
    },
    {
      "value": "61e52f862619ab016d3bcfbd78e5c7aaaa1989b4c295e6dbcacddd2d7b93e1f5",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-3280",
          "title": "Container image formats under the hood",
          "link": "https://snyk.io/blog/container-image-formats/",
          "published": "2020-11-18",
          "sev": "high"
        }
      ],
      "first_seen": "2020-11-18"
    },
    {
      "value": "8bf067b107a6f7444876e33c6ed85652355f679ac98ebab97ab3ebad63f0dff3",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-3280",
          "title": "Container image formats under the hood",
          "link": "https://snyk.io/blog/container-image-formats/",
          "published": "2020-11-18",
          "sev": "high"
        }
      ],
      "first_seen": "2020-11-18"
    },
    {
      "value": "afa93a8ce255ca452ca8c88f4b5c821a466cf0a3e0148a31d0d97dfdb91d9aef",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-3280",
          "title": "Container image formats under the hood",
          "link": "https://snyk.io/blog/container-image-formats/",
          "published": "2020-11-18",
          "sev": "high"
        }
      ],
      "first_seen": "2020-11-18"
    },
    {
      "value": "e80b8affb2361dc632c1fa8fcbf6b6514f750eb6ef99b7e7f825a55f849bfd89",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-3280",
          "title": "Container image formats under the hood",
          "link": "https://snyk.io/blog/container-image-formats/",
          "published": "2020-11-18",
          "sev": "high"
        }
      ],
      "first_seen": "2020-11-18"
    },
    {
      "value": "CVE-2020-7733",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-3297",
          "title": "Regular Expression Denial of Service (REDoS) in UAParser.js",
          "link": "https://snyk.io/blog/regular-expression-denial-of-service-redos-in-uaparser-js/",
          "published": "2020-10-26",
          "sev": "crit"
        }
      ],
      "first_seen": "2020-10-26"
    },
    {
      "value": "CVE-2020-7729",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-3321",
          "title": "Arbitrary code execution in Grunt",
          "link": "https://snyk.io/blog/arbitrary-code-execution-in-js-grunt/",
          "published": "2020-09-21",
          "sev": "crit"
        }
      ],
      "first_seen": "2020-09-21"
    },
    {
      "value": "CVE-2020-7699",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-3337",
          "title": "Prototype pollution in express-fileupload",
          "link": "https://snyk.io/blog/prototype-pollution-in-express-fileupload/",
          "published": "2020-08-24",
          "sev": "high"
        }
      ],
      "first_seen": "2020-08-24"
    },
    {
      "value": "9329a7706dd43d6ed64d022ad0e7b13b",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-3336",
          "title": "SourMint malicious SDK research writeup",
          "link": "https://snyk.io/blog/sour-mint-malicious-sdk/",
          "published": "2020-08-24",
          "sev": "high"
        }
      ],
      "first_seen": "2020-08-24"
    },
    {
      "value": "CVE-2020-11981",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-3345",
          "title": "Breaking out of message brokers",
          "link": "https://snyk.io/blog/message-brokers/",
          "published": "2020-08-05",
          "sev": "crit"
        }
      ],
      "first_seen": "2020-08-05"
    },
    {
      "value": "CVE-2020-11982",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-3345",
          "title": "Breaking out of message brokers",
          "link": "https://snyk.io/blog/message-brokers/",
          "published": "2020-08-05",
          "sev": "crit"
        }
      ],
      "first_seen": "2020-08-05"
    },
    {
      "value": "CVE-2020-7667",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-3353",
          "title": "Arbitrary File Write via Archive Extraction (Zip Slip) in go-rpmutils",
          "link": "https://snyk.io/blog/arbitrary-file-write-via-archive-extraction-in-go-rpmutils/",
          "published": "2020-07-20",
          "sev": "high"
        }
      ],
      "first_seen": "2020-07-20"
    },
    {
      "value": "CVE-2019-16786",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-3358",
          "title": "Demystifying HTTP request smuggling",
          "link": "https://snyk.io/blog/demystifying-http-request-smuggling/",
          "published": "2020-06-30",
          "sev": "crit"
        }
      ],
      "first_seen": "2020-06-30"
    },
    {
      "value": "CVE-2020-12440",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-3358",
          "title": "Demystifying HTTP request smuggling",
          "link": "https://snyk.io/blog/demystifying-http-request-smuggling/",
          "published": "2020-06-30",
          "sev": "crit"
        }
      ],
      "first_seen": "2020-06-30"
    },
    {
      "value": "CVE-2020-7662",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-3362",
          "title": "Regular Expression Denial-of-Service in websocket-extensions",
          "link": "https://snyk.io/blog/regular-expression-denial-of-service-in-websocket-extensions/",
          "published": "2020-06-22",
          "sev": "crit"
        }
      ],
      "first_seen": "2020-06-22"
    },
    {
      "value": "CVE-2020-7663",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-3362",
          "title": "Regular Expression Denial-of-Service in websocket-extensions",
          "link": "https://snyk.io/blog/regular-expression-denial-of-service-in-websocket-extensions/",
          "published": "2020-06-22",
          "sev": "crit"
        }
      ],
      "first_seen": "2020-06-22"
    },
    {
      "value": "CVE-2019-10777",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-3375",
          "title": "Why do organizations trust Snyk to win the open source security battle?",
          "link": "https://snyk.io/blog/why-snyk-wins-open-source-security-battle/",
          "published": "2020-05-27",
          "sev": "crit"
        }
      ],
      "first_seen": "2020-05-27"
    },
    {
      "value": "CVE-2019-10795",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-3375",
          "title": "Why do organizations trust Snyk to win the open source security battle?",
          "link": "https://snyk.io/blog/why-snyk-wins-open-source-security-battle/",
          "published": "2020-05-27",
          "sev": "crit"
        }
      ],
      "first_seen": "2020-05-27"
    },
    {
      "value": "CVE-2020-7599",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-3411",
          "title": "Vulnerable Gradle plugin-publish plugin reveals sensitive information",
          "link": "https://snyk.io/blog/vulnerable-gradle-plugin/",
          "published": "2020-03-31",
          "sev": "crit"
        }
      ],
      "first_seen": "2020-03-31"
    },
    {
      "value": "CVE-2019-11247",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-3412",
          "title": "March in review: State of Open Source Security survey, All.The.Talks virtual conference, and more",
          "link": "https://snyk.io/blog/march-in-review-security-news/",
          "published": "2020-03-31",
          "sev": "high"
        }
      ],
      "first_seen": "2020-03-31"
    },
    {
      "value": "CVE-2019-11249",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-3412",
          "title": "March in review: State of Open Source Security survey, All.The.Talks virtual conference, and more",
          "link": "https://snyk.io/blog/march-in-review-security-news/",
          "published": "2020-03-31",
          "sev": "high"
        }
      ],
      "first_seen": "2020-03-31"
    },
    {
      "value": "CVE-2020-7598",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-3417",
          "title": "Exploring the minimist prototype pollution security vulnerability",
          "link": "https://snyk.io/blog/prototype-pollution-minimist/",
          "published": "2020-03-26",
          "sev": "crit"
        }
      ],
      "first_seen": "2020-03-26"
    },
    {
      "value": "c4fbb68607bcbb25407e0362dab0b2ea",
      "type": "md5",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-3421",
          "title": "What is a backdoor? Let\u2019s build one with Node.js",
          "link": "https://snyk.io/blog/what-is-a-backdoor/",
          "published": "2020-03-19",
          "sev": "high"
        }
      ],
      "first_seen": "2020-03-19"
    },
    {
      "value": "CVE-2019-15604",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-3444",
          "title": "Node.js release fixes a critical HTTP security vulnerability",
          "link": "https://snyk.io/blog/node-js-release-fixes-a-critical-http-security-vulnerability/",
          "published": "2020-02-06",
          "sev": "high"
        }
      ],
      "first_seen": "2020-02-06"
    },
    {
      "value": "CVE-2019-15605",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-3444",
          "title": "Node.js release fixes a critical HTTP security vulnerability",
          "link": "https://snyk.io/blog/node-js-release-fixes-a-critical-http-security-vulnerability/",
          "published": "2020-02-06",
          "sev": "high"
        }
      ],
      "first_seen": "2020-02-06"
    },
    {
      "value": "CVE-2019-15606",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-3444",
          "title": "Node.js release fixes a critical HTTP security vulnerability",
          "link": "https://snyk.io/blog/node-js-release-fixes-a-critical-http-security-vulnerability/",
          "published": "2020-02-06",
          "sev": "high"
        }
      ],
      "first_seen": "2020-02-06"
    },
    {
      "value": "CVE-2019-10773",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-3463",
          "title": "Understanding filesystem takeover vulnerabilities in npm JavaScript package manager",
          "link": "https://snyk.io/blog/understanding-filesystem-takeover-vulnerabilities-in-npm-javascript-package-manager/",
          "published": "2020-01-07",
          "sev": "crit"
        }
      ],
      "first_seen": "2020-01-07"
    },
    {
      "value": "CVE-2019-16776",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-3463",
          "title": "Understanding filesystem takeover vulnerabilities in npm JavaScript package manager",
          "link": "https://snyk.io/blog/understanding-filesystem-takeover-vulnerabilities-in-npm-javascript-package-manager/",
          "published": "2020-01-07",
          "sev": "crit"
        }
      ],
      "first_seen": "2020-01-07"
    },
    {
      "value": "CVE-2019-16777",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-3463",
          "title": "Understanding filesystem takeover vulnerabilities in npm JavaScript package manager",
          "link": "https://snyk.io/blog/understanding-filesystem-takeover-vulnerabilities-in-npm-javascript-package-manager/",
          "published": "2020-01-07",
          "sev": "crit"
        }
      ],
      "first_seen": "2020-01-07"
    },
    {
      "value": "CVE-2016-2781",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-3474",
          "title": "Showing application vulnerabilities in Kubernetes-native tooling",
          "link": "https://snyk.io/blog/showing-application-vulnerabilities-in-kubernetes-native-tooling/",
          "published": "2019-11-19",
          "sev": "high"
        }
      ],
      "first_seen": "2019-11-19"
    },
    {
      "value": "CVE-2005-2541",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-3476",
          "title": "Uncharted territory - discovering vulnerabilities in public Helm Charts",
          "link": "https://snyk.io/blog/uncharted-territory-discovering-vulnerabilities-in-public-helm-charts/",
          "published": "2019-11-18",
          "sev": "high"
        }
      ],
      "first_seen": "2019-11-18"
    },
    {
      "value": "CVE-2019-9619",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-3476",
          "title": "Uncharted territory - discovering vulnerabilities in public Helm Charts",
          "link": "https://snyk.io/blog/uncharted-territory-discovering-vulnerabilities-in-public-helm-charts/",
          "published": "2019-11-18",
          "sev": "high"
        }
      ],
      "first_seen": "2019-11-18"
    },
    {
      "value": "fe8a0be91ee3e7dea812e8694491e1dde5b75e6d",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-3501",
          "title": "Everything you wanted to know about addressing security vulnerabilities in Linux-based containers",
          "link": "https://snyk.io/blog/everything-you-wanted-to-know-about-addressing-security-vulnerabilities-in-linux-based-containers/",
          "published": "2019-09-18",
          "sev": "high"
        }
      ],
      "first_seen": "2019-09-18"
    },
    {
      "value": "CVE-2019-10748",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-3503",
          "title": "Sequelize ORM npm library found vulnerable to SQL Injection attacks",
          "link": "https://snyk.io/blog/sequelize-orm-npm-library-found-vulnerable-to-sql-injection-attacks/",
          "published": "2019-09-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2019-09-11"
    },
    {
      "value": "CVE-2019-10749",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-3503",
          "title": "Sequelize ORM npm library found vulnerable to SQL Injection attacks",
          "link": "https://snyk.io/blog/sequelize-orm-npm-library-found-vulnerable-to-sql-injection-attacks/",
          "published": "2019-09-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2019-09-11"
    },
    {
      "value": "CVE-2019-10752",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-3503",
          "title": "Sequelize ORM npm library found vulnerable to SQL Injection attacks",
          "link": "https://snyk.io/blog/sequelize-orm-npm-library-found-vulnerable-to-sql-injection-attacks/",
          "published": "2019-09-11",
          "sev": "crit"
        }
      ],
      "first_seen": "2019-09-11"
    },
    {
      "value": "CVE-2019-14379",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-3510",
          "title": "Jackson Deserialization Vulnerability",
          "link": "https://snyk.io/blog/jackson-deserialization-vulnerability/",
          "published": "2019-08-21",
          "sev": "crit"
        }
      ],
      "first_seen": "2019-08-21"
    },
    {
      "value": "CVE-2019-14439",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-3510",
          "title": "Jackson Deserialization Vulnerability",
          "link": "https://snyk.io/blog/jackson-deserialization-vulnerability/",
          "published": "2019-08-21",
          "sev": "crit"
        }
      ],
      "first_seen": "2019-08-21"
    },
    {
      "value": "CVE-2019-10744",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-3519",
          "title": "Staying ahead of security vulnerabilities with security patches",
          "link": "https://snyk.io/blog/staying-ahead-of-security-vulnerabilities-with-security-patches/",
          "published": "2019-07-31",
          "sev": "crit"
        },
        {
          "id": "art-3530",
          "title": "Snyk research team discovers severe prototype pollution security vulnerabilities affecting all versions of lodash",
          "link": "https://snyk.io/blog/snyk-research-team-discovers-severe-prototype-pollution-security-vulnerabilities-affecting-all-versions-of-lodash/",
          "published": "2019-07-05",
          "sev": "crit"
        }
      ],
      "first_seen": "2019-07-31"
    },
    {
      "value": "CVE-2019-13354",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-3529",
          "title": "Concerns of supply-chain attacks amplify as remote code execution was found in Ruby gem strong_password",
          "link": "https://snyk.io/blog/ruby-gem-strong_password-found-to-contain-remote-code-execution-code-in-a-malicious-version-further-strengthening-worries-of-growth-in-supply-chain-attacks/",
          "published": "2019-07-07",
          "sev": "crit"
        }
      ],
      "first_seen": "2019-07-07"
    },
    {
      "value": "366d6162fe36fc81dadc114558b43c6c8890c8bcc7e90e2949ae6344d0785dc0",
      "type": "sha256",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-3568",
          "title": "Malicious remote code execution backdoor discovered in the popular bootstrap-sass Ruby gem",
          "link": "https://snyk.io/blog/malicious-remote-code-execution-backdoor-discovered-in-the-popular-bootstrap-sass-ruby-gem/",
          "published": "2019-04-04",
          "sev": "high"
        }
      ],
      "first_seen": "2019-04-04"
    },
    {
      "value": "CVE-2019-5736",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-3587",
          "title": "A serious security flaw in runC can result in root privilege escalation in Docker and Kubernetes",
          "link": "https://snyk.io/blog/a-serious-security-flaw-in-runc-can-result-in-root-privilege-escalation-in-docker-and-kubernetes/",
          "published": "2019-02-13",
          "sev": "crit"
        }
      ],
      "first_seen": "2019-02-13"
    },
    {
      "value": "CVE-2018-1002105",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-3601",
          "title": "Critical Arbitrary Code Execution Vulnerability Found in Kubernetes",
          "link": "https://snyk.io/blog/critical-arbitrary-code-execution-vulnerability-found-in-kubernetes/",
          "published": "2018-12-20",
          "sev": "high"
        }
      ],
      "first_seen": "2018-12-20"
    },
    {
      "value": "CVE-2018-8008",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-3622",
          "title": "Behind the disclosure: the Zip Slip vulnerability",
          "link": "https://snyk.io/blog/behind-the-disclosure-the-zip-slip-vulnerability/",
          "published": "2018-08-15",
          "sev": "crit"
        }
      ],
      "first_seen": "2018-08-15"
    },
    {
      "value": "CVE-2018-8009",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-3622",
          "title": "Behind the disclosure: the Zip Slip vulnerability",
          "link": "https://snyk.io/blog/behind-the-disclosure-the-zip-slip-vulnerability/",
          "published": "2018-08-15",
          "sev": "crit"
        }
      ],
      "first_seen": "2018-08-15"
    },
    {
      "value": "CVE-2018-0495",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-3627",
          "title": "Container vulnerability management for developers",
          "link": "https://snyk.io/blog/container-vulnerability-management-for-developers/",
          "published": "2018-06-28",
          "sev": "high"
        }
      ],
      "first_seen": "2018-06-28"
    },
    {
      "value": "CVE-2018-1315",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-3636",
          "title": "Attacking an FTP Client: MGETting more than you bargained for",
          "link": "https://snyk.io/blog/attacking-an-ftp-client/",
          "published": "2018-04-04",
          "sev": "high"
        }
      ],
      "first_seen": "2018-04-04"
    },
    {
      "value": "305f2ddcd4eff7cc7c518aca6bb2b2d2daad8fef",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-3650",
          "title": "Using the Snyk API to find and fix vulnerabilities",
          "link": "https://snyk.io/blog/using-the-snyk-api-to-find-and-fix-vulnerabilities/",
          "published": "2018-01-03",
          "sev": "high"
        }
      ],
      "first_seen": "2018-01-03"
    },
    {
      "value": "CVE-2016-6037",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-3664",
          "title": "XSS Attacks: The Next Wave",
          "link": "https://snyk.io/blog/xss-attacks-the-next-wave/",
          "published": "2017-06-08",
          "sev": "crit"
        }
      ],
      "first_seen": "2017-06-08"
    },
    {
      "value": "CVE-2017-8801",
      "type": "cve",
      "confidence": "high",
      "extraction": "regex",
      "severity": "crit",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-3664",
          "title": "XSS Attacks: The Next Wave",
          "link": "https://snyk.io/blog/xss-attacks-the-next-wave/",
          "published": "2017-06-08",
          "sev": "crit"
        }
      ],
      "first_seen": "2017-06-08"
    },
    {
      "value": "1bfdedf6a6e345f322fe956d5df5bd08a8ce84dc",
      "type": "sha1",
      "confidence": "high",
      "extraction": "regex",
      "severity": "high",
      "sources": [
        "Snyk"
      ],
      "articles": [
        {
          "id": "art-3691",
          "title": "Yarn is Micro Secure",
          "link": "https://snyk.io/blog/yarn-is-micro-secure/",
          "published": "2016-10-25",
          "sev": "high"
        }
      ],
      "first_seen": "2016-10-25"
    }
  ]
}