/var/log/active/syslog/secure
) for unauthorized root access attempts.sudo
utility:Issue | Impact | Exploited? | Mitigation |
---|---|---|---|
SharePoint ToolShell CVEs | RCE, ransomware, key theft | â High activity | Patch urgently, rotate keys, isolate hosts |
Cisco CUCM CVEâ20309 | Root login via static creds | â Not yet seen | Patch, monitor logs |
Linux sudo CVEs | Local root escalation | â Reported internally | Upgrade sudo |
Anthropic MCP CVEâ49596 | AI agent compromise | â (theoretically) | Use secure patched versions |
Honeywell Niagara ICS flaws | Physical system control | â Proof of concept | Apply SCADA/IoT patches |
Comdb2 DoS CVEs | Service disruption | â No reports yet | Patch, monitor traffic |