Threat Alerts | Armis

Armis 2025 Cybersecurity Predictions

Read More
Armis Labs

Threat Alerts

Early Warning

Task Scheduler Elevation of Privilege Vulnerability
(CVE-2019-1069)
Early Warning
2 Years Earlier

CVE-2019-1069, also known as the Task Scheduler Elevation of Privilege Vulnerability, was identified in Microsoft Windows Task Scheduler.

Read More
OpenSSH Vulnerability
(CVE-2024-6387 regreSShion)
Early Warning
Not yet published on CISA KEV

The exploit requires 10,000 attempts and specific conditions related to the GNU C Library (glibc), making widespread exploitation unlikely.

Read More
NextGen Mirth Connect Remote Code Execution Vulnerability
(CVE-2023-43208)
Early Warning
64 Days Earlier

This is an easily exploitable unauthenticated remote code execution vulnerability affecting NextGen HealthCare’s Mirth Connect data integration platform.

Read More
JetBrains TeamCity Authentication Bypass
Early Warning
2 Days Earlier

JetBrains TeamCity contains an authentication bypass vulnerability that allows an attacker to perform admin actions.

Read More
Apple OS Memory Corruption Vulnerability
(CVE-2024-23225)
Early Warning
1 Day Earlier

Apple iOS, iPadOS, macOS, tvOS, watchOS, and visionOS kernel contain a memory corruption vulnerability that allows an attacker with arbitrary kernel read and write capability to bypass kernel memory protections.

Read More
Apple OS Memory Corruption Vulnerability
(CVE-2024-23296)
Early Warning
1 Day Earlier

Apple iOS, iPadOS, macOS, tvOS, and watchOS RTKit contain a memory corruption vulnerability that allows an attacker with arbitrary kernel read and write capability to bypass kernel memory protections.

Read More
D-LINK Command Injection Vulnerability
(CVE-2024-3273)
Early Warning
2 Days Earlier

D-Link DNS-320L, DNS-325, DNS-327L, and DNS-340L contain a command injection vulnerability.

Read More
Microsoft SmartScreen Prompt Security Bypass
(CVE-2024-29988)
Early Warning
20 Days Earlier

Microsoft SmartScreen Prompt contains a security feature bypass vulnerability that allows an attacker to bypass the Mark of the Web (MotW) feature.

Read More
Microsoft Windows Print Spooler Privilege Escalation Vulnerability
(CVE-2022-38028)
Early Warning
1 Day Earlier

Microsoft Windows Print Spooler service contains a privilege escalation vulnerability.

Read More
Crush FTP Unauthorized AccesS to File System
(CVE-2024-4040)
Early Warning
1 Day Earlier

CrushFTP contains an unspecified sandbox escape vulnerability that allows a remote attacker to escape the CrushFTP virtual file system (VFS).

Read More
Google Chrome Remote Code Execution
(CVE-2024-4947)
Early Warning
2 Days Earlier

Google Chromium V8 contains a type confusion vulnerability that allows a remote attacker to execute code via a crafted HTML page.

Read More
CheckPoint Quantum Security Gateway Information Disclosure
(CVE-2024-24919)
Early Warning
1 Day Earlier

Check Point Quantum Security Gateways contains an unspecified information disclosure vulnerability.

Read More
Progress Telerik Report Server Security Bypass
(CVE-2024-4358)
Early Warning
9 Days Earlier

Progress Telerik Report Server contains an authorization bypass by spoofing vulnerability that allows an attacker to obtain unauthorized access.

Read More
Rejetto HTTP File Server Remote Code Execution
(CVE-2024-23692)
Early Warning
13 Days Earlier

Rejetto HTTP File Server contains an improper neutralization of special elements used in a template engine vulnerability.

Read More

All

Task Scheduler Elevation of Privilege Vulnerability
(CVE-2019-1069)
Early Warning
2 Years Earlier

CVE-2019-1069, also known as the Task Scheduler Elevation of Privilege Vulnerability, was identified in Microsoft Windows Task Scheduler.

Read More
ImageMagick Code Execution Vulnerability
(CVE-2016-3714)
Early Warning
5 Years Earlier

CVE-2016-3714 is a critical vulnerability in ImageMagick that allows remote code execution due to insufficient input filtering. ImageMagick is a popular software suite for creating, editing, and converting bitmap images.

Read More
CrowdStrike Windows IT Outage
Flash Alert
Flash Alert

CrowdStrike is actively working with customers impacted by the defect found in a single content update for Windows hosts. Mac and Linux hosts are not impacted. This is not a security incident or cyberattack.

Read More
OpenSSH Vulnerability
(CVE-2024-6387 regreSShion)
Early Warning
Not yet published on CISA KEV

The exploit requires 10,000 attempts and specific conditions related to the GNU C Library (glibc), making widespread exploitation unlikely.

Read More
NextGen Mirth Connect Remote Code Execution Vulnerability
(CVE-2023-43208)
Early Warning
64 Days Earlier

This is an easily exploitable unauthenticated remote code execution vulnerability affecting NextGen HealthCare’s Mirth Connect data integration platform.

Read More
JetBrains TeamCity Authentication Bypass
Early Warning
2 Days Earlier

JetBrains TeamCity contains an authentication bypass vulnerability that allows an attacker to perform admin actions.

Read More
Apple OS Memory Corruption Vulnerability
(CVE-2024-23225)
Early Warning
1 Day Earlier

Apple iOS, iPadOS, macOS, tvOS, watchOS, and visionOS kernel contain a memory corruption vulnerability that allows an attacker with arbitrary kernel read and write capability to bypass kernel memory protections.

Read More
Apple OS Memory Corruption Vulnerability
(CVE-2024-23296)
Early Warning
1 Day Earlier

Apple iOS, iPadOS, macOS, tvOS, and watchOS RTKit contain a memory corruption vulnerability that allows an attacker with arbitrary kernel read and write capability to bypass kernel memory protections.

Read More
D-LINK Command Injection Vulnerability
(CVE-2024-3273)
Early Warning
2 Days Earlier

D-Link DNS-320L, DNS-325, DNS-327L, and DNS-340L contain a command injection vulnerability.

Read More
Microsoft SmartScreen Prompt Security Bypass
(CVE-2024-29988)
Early Warning
20 Days Earlier

Microsoft SmartScreen Prompt contains a security feature bypass vulnerability that allows an attacker to bypass the Mark of the Web (MotW) feature.

Read More
Microsoft Windows Print Spooler Privilege Escalation Vulnerability
(CVE-2022-38028)
Early Warning
1 Day Earlier

Microsoft Windows Print Spooler service contains a privilege escalation vulnerability.

Read More
Crush FTP Unauthorized AccesS to File System
(CVE-2024-4040)
Early Warning
1 Day Earlier

CrushFTP contains an unspecified sandbox escape vulnerability that allows a remote attacker to escape the CrushFTP virtual file system (VFS).

Read More
Google Chrome Remote Code Execution
(CVE-2024-4947)
Early Warning
2 Days Earlier

Google Chromium V8 contains a type confusion vulnerability that allows a remote attacker to execute code via a crafted HTML page.

Read More
CheckPoint Quantum Security Gateway Information Disclosure
(CVE-2024-24919)
Early Warning
1 Day Earlier

Check Point Quantum Security Gateways contains an unspecified information disclosure vulnerability.

Read More
Progress Telerik Report Server Security Bypass
(CVE-2024-4358)
Early Warning
9 Days Earlier

Progress Telerik Report Server contains an authorization bypass by spoofing vulnerability that allows an attacker to obtain unauthorized access.

Read More
Rejetto HTTP File Server Remote Code Execution
(CVE-2024-23692)
Early Warning
13 Days Earlier

Rejetto HTTP File Server contains an improper neutralization of special elements used in a template engine vulnerability.

Read More