/var/log/active/syslog/secure
) for unauthorized root access attempts.sudo
utility:Issue | Impact | Exploited? | Mitigation |
---|---|---|---|
SharePoint ToolShell CVEs | RCE, ransomware, key theft | β High activity | Patch urgently, rotate keys, isolate hosts |
Cisco CUCM CVEβ20309 | Root login via static creds | β Not yet seen | Patch, monitor logs |
Linux sudo CVEs | Local root escalation | β Reported internally | Upgrade sudo |
Anthropic MCP CVEβ49596 | AI agent compromise | β (theoretically) | Use secure patched versions |
Honeywell Niagara ICS flaws | Physical system control | β Proof of concept | Apply SCADA/IoT patches |
Comdb2 DoS CVEs | Service disruption | β No reports yet | Patch, monitor traffic |