T1557: T1557
Essential information
- MITRE technique ID
T1557- Confidence
- 100/100
- Revoked
- No
- Published
- 16/12/2025 19:37
- Modified
- 27/03/2026 01:07
- Author / Source
- The MITRE Corporation
Aliases
Adversary-in-the-Middle
Platforms
windows macos linux Network Devices
Description
Kill chain phases
| Kill chain | Phase |
|---|---|
| mitre-attack | collection |
| mitre-attack | credential-access |
Marking (TLP)
TLP:CLEAR Copyright 2015-2025, The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation.
External references
Related entities
Intrusion sets, malware, reports, vulnerabilities, indicators and other entities linked to this technique.
Intrusion sets (APT) (36)
-
The MITRE Corporation Confidence 100
[Mustang Panda](https://attack.mitre.org/groups/G0129) is a China-based cyber espionage threat actor that has been conducting operations since at least 2012. [Mustang Panda](https://attack.mitre.org/groups/G0129) has been known to use tailored phishing lures …
First seen 01/01/1970 · Last seen 16/11/5138 Published 16/12/2025 19:39 · Modified 22/05/2026 04:12 -
The MITRE Corporation Confidence 100
[APT28](https://attack.mitre.org/groups/G0007) is a threat group that has been attributed to Russia's General Staff Main Intelligence Directorate (GRU) 85th Main Special Service Center (GTsSS) military unit 26165.(Citation: NSA/FBI Drovorub …
First seen 01/01/1970 · Last seen 16/11/5138 Published 16/12/2025 19:39 · Modified 08/04/2026 13:02 -
Storm-1575 usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 21/12/2025 08:11 · Modified 21/12/2025 08:11
-
UTA0218 usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 21/12/2025 04:18 · Modified 21/12/2025 04:18
-
Socgholish usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 21/12/2025 03:07 · Modified 21/12/2025 07:54
-
Blackwood usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 21/12/2025 02:55 · Modified 21/12/2025 02:55
-
PhaaS usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 21/12/2025 03:30 · Modified 21/12/2025 03:30
-
Russia usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 21/05/2026 18:50 · Modified 29/05/2026 12:20
-
The MITRE Corporation Confidence 100
[Turla](https://attack.mitre.org/groups/G0010) is a cyber espionage threat group that has been attributed to Russia's Federal Security Service (FSB). They have compromised victims in over 50 countries since at least …
First seen 01/01/1970 · Last seen 16/11/5138 Published 16/12/2025 19:39 · Modified 04/05/2026 16:33 -
The MITRE Corporation Confidence 100
[Kimsuky](https://attack.mitre.org/groups/G0094) is a North Korea-based cyber espionage group that has been active since at least 2012. The group initially targeted South Korean government agencies, think tanks, and subject-matter …
First seen 01/01/1970 · Last seen 16/11/5138 Published 16/12/2025 19:39 · Modified 04/05/2026 16:33 -
VexTrio usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 21/12/2025 02:40 · Modified 21/12/2025 02:54
-
Knownsec usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 12/01/2026 13:14 · Modified 12/01/2026 13:14
-
NullBulge usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 21/12/2025 05:59 · Modified 21/12/2025 05:59
-
Cosmic Leopard usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 21/12/2025 04:47 · Modified 21/12/2025 04:47
-
ALPHV Blackcat usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 21/12/2025 03:30 · Modified 21/12/2025 03:30
-
INC usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 17/06/2026 22:24 · Modified 17/06/2026 22:24
-
Hummer usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 21/12/2025 03:35 · Modified 21/12/2025 03:35
-
Tycoon Group usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 21/12/2025 02:53 · Modified 21/12/2025 02:53
-
AlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 21/12/2025 07:11 · Modified 21/12/2025 07:11
-
Trident Ursa usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 20/12/2025 23:08 · Modified 20/12/2025 23:08
-
Storm-3075 usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 09/06/2026 10:57 · Modified 09/06/2026 10:57
-
AlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 21/12/2025 13:02 · Modified 21/12/2025 13:02
-
UNC5337 usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 21/12/2025 08:44 · Modified 21/12/2025 08:44
-
MRxC0DER usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 21/12/2025 05:45 · Modified 21/12/2025 05:45
-
Fog ransomware group usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 21/12/2025 13:54 · Modified 21/12/2025 13:54
-
Sandworm usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 20/12/2025 23:15 · Modified 20/12/2025 23:15
-
ShinyHunters usesAlienVault Confidence 100
No description available
First seen 01/01/1970 · Last seen 16/11/5138 Published 02/02/2026 12:05 · Modified 20/03/2026 09:17 -
Water Curse usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 21/12/2025 14:16 · Modified 21/12/2025 14:16
-
ScamClub usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 21/12/2025 03:13 · Modified 21/12/2025 03:13
-
Zloader usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 21/12/2025 03:56 · Modified 21/12/2025 03:56
-
UNC6040, UNC6240 usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 21/12/2025 17:00 · Modified 21/12/2025 17:00
-
The MITRE Corporation Confidence 100
[Sea Turtle](https://attack.mitre.org/groups/G1041) is a Türkiye-linked threat actor active since at least 2017 performing espionage and service provider compromise operations against victims in Asia, Europe, and North America. [Sea …
First seen 01/01/1970 · Last seen 16/11/5138 Published 16/12/2025 19:39 · Modified 27/03/2026 01:14 -
COLDWASTREL usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 21/12/2025 05:58 · Modified 21/12/2025 05:58
-
BlindEagle usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 21/12/2025 06:53 · Modified 27/05/2026 15:52
-
UAT-5394 usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 21/12/2025 06:38 · Modified 21/12/2025 06:38
-
AlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 21/12/2025 14:55 · Modified 21/12/2025 14:55
Malware (92)
-
Lumma Stealer usesFamilyPublished 08/06/2026 19:36 · Modified 08/06/2026 19:36
-
SPAWNMOLE usesFamilyPublished 17/01/2025 17:17 · Modified 17/01/2025 17:17
-
LianSpy usesFamilyPublished 06/08/2024 10:03 · Modified 06/08/2024 10:03
- WarzoneRAT
-
AveMaria usesFamilyPublished 26/11/2025 14:09 · Modified 26/11/2025 14:09
-
SPAWNSNAIL usesFamilyPublished 17/01/2025 17:17 · Modified 17/01/2025 17:17
-
Zloader usesFamilyPublished 22/09/2025 19:40 · Modified 22/09/2025 19:40
-
Mamba 2FA usesFamilyPublished 07/10/2024 20:04 · Modified 07/10/2024 20:04
-
Lumma usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 20/12/2025 23:50 · Modified 21/12/2025 16:13
- BlackCat
-
GOVERSHELL usesFamilyPublished 28/04/2026 07:09 · Modified 28/04/2026 07:09
- UPSTYLE
-
FamilyPublished 28/03/2025 00:35 · Modified 28/03/2025 00:35
-
XenoRAT usesFamilyPublished 29/05/2026 10:49 · Modified 29/05/2026 10:49
-
Track2NFC usesFamilyPublished 23/04/2025 19:45 · Modified 23/04/2025 19:45
-
Stuxnet - S0603 usesFamilyPublished 21/05/2026 08:39 · Modified 21/05/2026 08:39
-
Remcos usesFamilyPublished 05/05/2026 18:45 · Modified 05/05/2026 18:45
-
FASTCash usesFamilyPublished 17/10/2024 09:57 · Modified 17/10/2024 09:57
- Third Eye Remote Control
-
Z-NFC usesFamilyPublished 23/04/2025 19:45 · Modified 23/04/2025 19:45
-
Atomic macOS Stealer usesFamilyPublished 18/05/2026 17:52 · Modified 18/05/2026 17:52
-
SPAWNANT usesFamilyPublished 09/01/2025 08:56 · Modified 09/01/2025 08:56
-
FamilyPublished 30/04/2026 23:40 · Modified 30/04/2026 23:40
-
DarkCloud usesFamilyPublished 29/09/2025 09:34 · Modified 29/09/2025 09:34
-
Chrome MCP Server usesFamilyPublished 30/04/2026 23:40 · Modified 30/04/2026 23:40
-
Caffeine usesFamilyPublished 02/07/2024 15:45 · Modified 02/07/2024 15:45
- Evilginx2
- HrServ
-
XWorm usesFamilyPublished 27/03/2026 08:45 · Modified 27/03/2026 08:45
-
Passive Radar usesFamilyPublished 10/01/2026 13:29 · Modified 10/01/2026 13:29
-
MoonPeak usesFamilyPublished 20/05/2026 11:12 · Modified 20/05/2026 11:12
-
HeavyLift usesFamilyPublished 14/06/2024 08:31 · Modified 14/06/2024 08:31
-
DRYHOOK usesFamilyPublished 09/01/2025 08:56 · Modified 09/01/2025 08:56
- information stealer
-
GhostSocks usesFamilyPublished 08/06/2026 19:36 · Modified 08/06/2026 19:36
-
King NFC usesFamilyPublished 23/04/2025 19:45 · Modified 23/04/2025 19:45
- Win.Dropper.Scar
-
Tycoon2FA usesFamilyPublished 04/03/2026 19:42 · Modified 04/03/2026 19:42
-
Fog ransomware usesFamilyPublished 28/04/2025 04:42 · Modified 28/04/2025 04:42
-
HealthKick usesFamilyPublished 28/04/2026 07:09 · Modified 28/04/2026 07:09
-
AlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 20/12/2025 19:39 · Modified 27/05/2026 21:40
- Hummer
-
NGate usesFamilyPublished 21/04/2026 16:32 · Modified 21/04/2026 16:32
-
Sinobi usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 17/06/2026 22:24 · Modified 17/06/2026 22:24
-
Evilginx usesFamilyPublished 03/12/2025 17:58 · Modified 03/12/2025 17:58
- GOST
-
Sliver usesFamilyPublished 12/06/2026 21:29 · Modified 12/06/2026 21:29
-
Backdoor.JS.DULLRAT usesFamilyPublished 16/06/2025 13:03 · Modified 16/06/2025 13:03
- Win.Worm.Coinminer
-
Vidar usesFamilyPublished 16/06/2026 09:50 · Modified 16/06/2026 09:50
-
WarzoneRAT - S0670 usesFamilyPublished 26/11/2025 14:09 · Modified 26/11/2025 14:09
-
Rhadamanthys Stealer usesFamilyPublished 26/08/2025 16:14 · Modified 26/08/2025 16:14
-
Huiyi usesFamilyPublished 30/04/2026 23:40 · Modified 30/04/2026 23:40
-
ShadowPad - S0596 usesFamilyPublished 30/04/2026 19:11 · Modified 30/04/2026 19:11
- Dok
-
W32.Stuxnet usesFamilyPublished 21/05/2026 08:39 · Modified 21/05/2026 08:39
-
Reverse Recruiting usesFamilyPublished 30/04/2026 23:40 · Modified 30/04/2026 23:40
-
SPAWNSLOTH usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 21/12/2025 08:44 · Modified 21/12/2025 08:44
-
Lynx usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 21/12/2025 10:04 · Modified 21/12/2025 10:04
-
LockBit usesFamilyPublished 06/05/2026 10:26 · Modified 06/05/2026 10:26
-
LightSpy usesFamilyPublished 21/02/2025 15:28 · Modified 21/02/2025 15:28
-
WizardNet usesFamilyPublished 05/02/2026 20:16 · Modified 05/02/2026 20:16
-
Oyster usesFamilyPublished 08/06/2026 19:36 · Modified 08/06/2026 19:36
-
Brave Prince - S0252 usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 21/12/2025 06:47 · Modified 21/12/2025 06:47
-
Salty2FA usesFamilyPublished 02/12/2025 21:13 · Modified 02/12/2025 21:13
- Line Runner
- Infamouse Chisel
-
Fast16 usesFamilyPublished 21/05/2026 08:39 · Modified 21/05/2026 08:39
-
HeadLace usesFamilyPublished 05/08/2024 08:30 · Modified 05/08/2024 08:30
-
gh0st RAT - S0032 usesFamilyPublished 17/04/2026 23:18 · Modified 17/04/2026 23:18
-
Un-Mail usesFamilyPublished 10/01/2026 13:29 · Modified 10/01/2026 13:29
- ApolloShadow
- Endpoint-Collector
-
CastleRAT usesFamilyPublished 23/04/2026 14:16 · Modified 23/04/2026 14:16
-
Remcos RAT usesFamilyPublished 17/06/2026 18:20 · Modified 17/06/2026 18:20
-
FamilyPublished 22/05/2026 17:38 · Modified 22/05/2026 17:38
-
GravityRAT - S0237 usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 20/12/2025 19:44 · Modified 21/12/2025 04:47
-
Supersonic AI usesFamilyPublished 30/04/2026 23:40 · Modified 30/04/2026 23:40
-
Chat AI for Chrome usesFamilyPublished 30/04/2026 23:40 · Modified 30/04/2026 23:40
-
DarkNimbus usesFamilyPublished 05/02/2026 20:16 · Modified 05/02/2026 20:16
-
Hijack Loader usesFamilyPublished 08/06/2026 19:36 · Modified 08/06/2026 19:36
-
PhantomCore usesFamilyPublished 23/01/2026 10:12 · Modified 23/01/2026 10:12
-
Amadey - S1025 usesFamilyPublished 29/09/2025 08:06 · Modified 29/09/2025 08:06
-
FamilyPublished 22/05/2026 17:38 · Modified 22/05/2026 17:38
-
QuasarRAT usesFamilyPublished 25/02/2026 11:35 · Modified 25/02/2026 11:35
-
NetSupport usesFamilyPublished 03/11/2025 14:28 · Modified 03/11/2025 14:28
-
Mydoor usesFamilyPublished 17/04/2026 23:18 · Modified 17/04/2026 23:18
-
Async RAT usesFamilyPublished 01/03/2026 05:26 · Modified 01/03/2026 05:26
-
POISONPLUG.SHADOW usesFamilyPublished 30/04/2026 19:11 · Modified 30/04/2026 19:11
-
PHASEJAM usesFamilyPublished 09/01/2025 08:56 · Modified 09/01/2025 08:56
-
GhostX usesFamilyPublished 10/01/2026 13:29 · Modified 10/01/2026 13:29
-
AMOS usesFamilyPublished 18/05/2026 17:52 · Modified 18/05/2026 17:52
Reports (46)
-
AlienVault Confidence 100 4 CVEs 19 MITREs 4 Malwares 25 IOCs 25 Observables 1 APTPublished 17/06/2026 15:38 · Modified 17/06/2026 20:24 · threat-report
-
AlienVault Confidence 100 20 MITREs 1 IOC 1 ObservablePublished 11/06/2026 23:09 · Modified 15/06/2026 19:16 · threat-report
-
20 MITREs 39 ObservablesPublished 11/06/2026 16:31 · Modified 15/06/2026 19:46
-
20 MITREs 5 Malwares 9 Observables 1 APTPublished 08/06/2026 19:36 · Modified 09/06/2026 08:57
-
20 MITREs 3 ObservablesPublished 04/06/2026 02:46 · Modified 04/06/2026 09:39
-
Threat landscape — Belgium relatedConfidence 100 18 CVEs 200 MITREs 200 Malwares 20 APTs 26 ToolsPublished 29/05/2026 11:51 · threat-report
-
Threat landscape — insurance relatedConfidence 100 199 MITREs 11 APTsPublished 27/05/2026 15:46 · threat-report
-
5 CVEs 14 MITREs 2 Malwares 5 ObservablesPublished 22/05/2026 17:38 · Modified 25/05/2026 10:51
-
10 MITREs 3 Malwares 1 APTPublished 21/05/2026 08:39 · Modified 21/05/2026 16:50
-
20 MITREs 2 Observables 1 APTPublished 09/05/2026 11:15 · Modified 11/05/2026 09:56
-
14 MITREs 1 ObservablePublished 08/05/2026 16:10 · Modified 11/05/2026 10:26
-
AlienVault Confidence 100 1 CVE 20 MITREs 9 IOCs 9 ObservablesPublished 04/05/2026 21:18 · Modified 05/05/2026 10:06 · threat-report
-
AlienVault Confidence 100 1 CVE 20 MITREs 6 Malwares 20 IOCs 20 ObservablesPublished 01/05/2026 01:40 · Modified 04/05/2026 14:30 · threat-report
-
AlienVault Confidence 100 21 MITREs 2 Malwares 132 IOCs 132 ObservablesPublished 28/04/2026 09:09 · Modified 28/04/2026 14:36 · threat-report
-
AlienVault Confidence 100 1 CVE 6 MITREs 58 IOCs 58 Observables 1 APTPublished 07/04/2026 15:57 · Modified 08/04/2026 11:02 · threat-report
-
9 MITREs 22 ObservablesPublished 18/03/2026 16:24 · Modified 18/03/2026 16:50
-
21 MITREs 1 Malware 3 ObservablesPublished 11/03/2026 11:10 · Modified 16/03/2026 09:21
-
7 MITREs 3 ObservablesPublished 23/12/2025 15:09 · Modified 23/12/2025 17:50
-
3 MITREs 1 Malware 15 ObservablesPublished 03/12/2025 17:58 · Modified 21/12/2025 18:21
-
5 CVEs 11 MITREs 5 Malwares 3 Observables 1 APTPublished 26/11/2025 14:09 · Modified 21/12/2025 18:07
-
14 MITREs 1 MalwarePublished 22/09/2025 19:40 · Modified 22/09/2025 21:14
-
12 MITREs 19 Observables 1 APTPublished 03/09/2025 15:30 · Modified 03/09/2025 20:28
-
6 MITREs 3 Malwares 27 Observables 1 APTPublished 26/08/2025 16:14 · Modified 26/08/2025 19:09
-
Security Incident Response Team related1 CVE 13 MITREs 6 ObservablesPublished 14/05/2025 18:57 · Modified 21/05/2025 20:32
-
1 CVE 5 MITREsPublished 27/03/2025 18:47 · Modified 27/03/2025 19:22
-
12 MITREs 1 Malware 27 ObservablesPublished 21/02/2025 15:28 · Modified 21/02/2025 16:00
-
9 MITREs 6 ObservablesPublished 30/01/2025 12:55 · Modified 30/01/2025 14:03
-
7 MITREs 1 Malware 200 ObservablesPublished 24/01/2025 08:28 · Modified 24/01/2025 09:09
-
4 CVEs 10 MITREs 6 Malwares 7 Observables 1 APTPublished 09/01/2025 08:56 · Modified 09/01/2025 09:09
-
5 MITREs 22 ObservablesPublished 31/10/2024 19:46 · Modified 01/11/2024 00:26
-
13 MITREs 3 Malwares 1 ObservablePublished 29/10/2024 14:25 · Modified 29/10/2024 14:56
-
9 MITREs 1 Malware 12 Observables 1 APTPublished 17/10/2024 09:57 · Modified 17/10/2024 10:21
-
A Website Attacked related4 MITREs 1 Malware 72 Observables 1 APTPublished 16/10/2024 09:29 · Modified 16/10/2024 09:49
-
7 MITREs 1 MalwarePublished 07/10/2024 20:04 · Modified 08/10/2024 08:34
-
15 MITREs 2 Malwares 17 ObservablesPublished 09/09/2024 11:16 · Modified 09/09/2024 11:21
-
20 MITREs 3 Malwares 42 Observables 1 APTPublished 21/08/2024 13:02 · Modified 21/08/2024 13:29
-
12 MITREs 28 Observables 1 APTPublished 14/08/2024 15:04 · Modified 14/08/2024 15:45
-
9 MITREs 1 MalwarePublished 06/08/2024 10:03 · Modified 06/08/2024 10:05
-
18 MITREs 3 Malwares 9 Observables 1 APTPublished 16/07/2024 14:51 · Modified 16/07/2024 14:56
-
16 MITREs 14 ObservablesPublished 10/07/2024 09:42 · Modified 10/07/2024 10:03
-
11 MITREs 1 ObservablePublished 05/07/2024 15:37 · Modified 05/07/2024 16:21
-
9 MITREs 1 Malware 25 Observables 1 APTPublished 02/07/2024 15:45 · Modified 02/07/2024 15:51
-
15 MITREs 2 Malwares 142 Observables 1 APTPublished 14/06/2024 08:31 · Modified 14/06/2024 09:11
-
4 MITREs 200 ObservablesPublished 21/05/2024 08:22 · Modified 21/05/2024 13:06
-
4 MITREs 1 Malware 74 ObservablesPublished 08/05/2024 15:37 · Modified 08/05/2024 17:30
-
Zloader Learns Old Tricks related20 MITREs 1 Malware 8 Observables 1 APTPublished 30/04/2024 14:41 · Modified 01/05/2024 23:09
Vulnerabilities (CVE) (30)
Microsoft's Netlogon Remote Protocol (MS-NRPC) contains a privilege escalation vulnerability when an attacker establishes a vulnerable Netlogon secure channel connection to a …
- Attack vector
- Local
- Published
- 03/11/2021
- Modified
- 27/05/2026
vulnerability exists in the FOXMAN-UN/UNEM server / API Gateway that if exploited an attacker could use to allow unintended commands or code …
- Published
- 11/06/2024
- Modified
- 11/06/2024
Fortinet FortiFone, FortiVoice, FortiNDR and FortiMail contain a stack-based overflow vulnerability that may allow a remote unauthenticated attacker to execute arbitrary code …
- Attack vector
- Network
- Published
- 14/05/2025
- Modified
- 14/01/2026
Citrix NetScaler ADC and NetScaler Gateway contains a code injection vulnerability that allows for unauthenticated remote code execution.
- Attack vector
- Network
- Published
- 19/07/2023
- Modified
- 27/05/2026
A logging issue was addressed with improved data redaction. This issue is fixed in iOS 18.4 and iPadOS 18.4, macOS Sequoia 15.4, …
- Attack vector
- Local
- Complexity
- Low
- Published
- 30/05/2025
- Modified
- 02/04/2026
When a BIG-IP APM Access Policy is configured on a virtual server, undisclosed traffic can cause TMM to terminate. Note: Software versions …
- Attack vector
- Network
- Complexity
- Low
- Published
- 15/10/2025
- Modified
- 04/04/2026
Citrix NetScaler ADC and Gateway contain an out-of-bounds read vulnerability due to insufficient input validation. This vulnerability can lead to memory overread …
- Attack vector
- Network
- Published
- 10/07/2025
- Modified
- 21/12/2025
Microsoft Office Outlook contains a privilege escalation vulnerability that allows for a NTLM Relay attack against another service to authenticate as the …
- Attack vector
- Network
- Published
- 14/03/2023
- Modified
- 21/12/2025
Exposure of sensitive information to an unauthorized actor in Windows File Explorer allows an unauthorized attacker to perform spoofing over a network.
- Attack vector
- Network
- Published
- 11/03/2025
- Modified
- 27/05/2026
Ivanti Connect Secure (ICS, formerly known as Pulse Connect Secure) and Ivanti Policy Secure contain a command injection vulnerability in the web …
- Attack vector
- Network
- Published
- 10/01/2024
- Modified
- 27/05/2026
Next.js is a React framework for building full-stack web applications. Starting in version 1.11.4 and prior to versions 12.3.5, 13.5.9, 14.2.25, and …
- Attack vector
- NETWORK
- Published
- 21/03/2025
- Modified
- 21/12/2025
TP-Link TL-WR841N dropbearpwd Improper Authentication Information Disclosure Vulnerability. This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of TP-Link …
- Published
- 03/09/2025
- Modified
- 08/04/2026
Microsoft Active Directory Domain Services contains an unspecified vulnerability that allows for privilege escalation.
- Published
- 11/04/2022
- Modified
- 20/12/2025
Fortinet FortiClient EMS contains a SQL injection vulnerability that allows an unauthenticated attacker to execute commands as SYSTEM via specifically crafted requests.
- Attack vector
- Network
- Published
- 25/03/2024
- Modified
- 21/12/2025
In the Linux kernel, the following vulnerability has been resolved: crypto: algif_aead - Revert to operating out-of-place This mostly reverts commit 72548b093ee3 …
- Attack vector
- LOCAL
- Complexity
- LOW
- EPSS
- 0.0001 (P0.6%)
- Published
- 22/04/2026
- Modified
- 23/05/2026
Microsoft Windows contains an NTLMv2 hash spoofing vulnerability that could result in disclosing a user's NTLMv2 hash to an attacker via a …
- Attack vector
- Network
- Published
- 12/11/2024
- Modified
- 27/05/2026
Palo Alto Networks PAN-OS GlobalProtect feature contains a command injection vulnerability that allows an unauthenticated attacker to execute commands with root privileges …
- Attack vector
- Network
- Published
- 12/04/2024
- Modified
- 21/12/2025
Malicious code was discovered in the upstream tarballs of xz, starting with version 5.6.0. Through a series of complex obfuscations, the liblzma …
- Attack vector
- NETWORK
- Published
- 29/03/2024
- Modified
- 21/12/2025
A vulnerability in the VPN web server of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense …
- Attack vector
- Network
- Published
- 25/09/2025
- Modified
- 21/12/2025
Microsoft Windows SMB Client contains an improper access control vulnerability that could allow for privilege escalation. An attacker could execute a specially …
- Attack vector
- Network
- Published
- 20/10/2025
- Modified
- 27/05/2026
A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.5, Ivanti Policy Secure before version 22.7R1.2, and Ivanti Neurons for ZTA …
- Attack vector
- LOCAL
- Published
- 09/01/2025
- Modified
- 21/12/2025
A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.5, Ivanti Policy Secure before version 22.7R1.2, and Ivanti Neurons for ZTA …
- Attack vector
- Network
- Published
- 08/01/2025
- Modified
- 21/12/2025
RARLAB WinRAR contains an unspecified vulnerability that allows an attacker to execute code when a user attempts to view a benign file …
- Attack vector
- Local
- Published
- 24/08/2023
- Modified
- 27/05/2026
SimpleHelp remote support software v5.5.7 and before is vulnerable to multiple path traversal vulnerabilities that enable unauthenticated remote attackers to download arbitrary …
- Attack vector
- Network
- Published
- 13/02/2025
- Modified
- 21/12/2025
A vulnerability in the VPN web server of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense …
- Attack vector
- Network
- Published
- 25/09/2025
- Modified
- 21/12/2025
Ivanti Connect Secure (ICS, formerly known as Pulse Connect Secure) and Ivanti Policy Secure gateways contain an authentication bypass vulnerability in the …
- Attack vector
- Network
- Published
- 10/01/2024
- Modified
- 27/05/2026
Microsoft Windows NTLM contains an external control of file name or path vulnerability that allows an unauthorized attacker to perform spoofing over …
- Attack vector
- Network
- Published
- 17/04/2025
- Modified
- 27/05/2026
A pre-authentication remote code execution vulnerability exists in React Server Components versions 19.0.0, 19.1.0, 19.1.1, and 19.2.0 including the following packages: react-server-dom-parcel, …
- Attack vector
- Network
- Published
- 05/12/2025
- Modified
- 29/05/2026
Microsoft Active Directory Domain Services contains an unspecified vulnerability that allows for privilege escalation.
- Published
- 11/04/2022
- Modified
- 20/12/2025
Microsoft Windows SmartScreen contains a security feature bypass vulnerability that could allow an attacker to bypass Windows Defender SmartScreen checks and their …
- Attack vector
- Network
- Published
- 14/11/2023
- Modified
- 21/12/2025
Attack patterns (MITRE) (4)
-
DHCP Spoofing subtechnique-of
-
T1557.001 subtechnique-ofLLMNR/NBT-NS Poisoning and SMB Relay
-
Evil Twin subtechnique-of
-
T1557.002 subtechnique-ofARP Cache Poisoning
Course Of Action (7)
- Network Intrusion Prevention mitigates
- Limit Access to Resource Over Network mitigates
- User Training mitigates
- Filter Network Traffic mitigates
- Encrypt Sensitive Information mitigates
- Disable or Remove Feature or Program mitigates
- Network Segmentation mitigates
Tool (2)
-
NPPSPY usesThe MITRE Corporation Confidence 100
NPPSPY is an implementation of a theoretical mechanism first presented in 2004 for capturing credentials submitted to a Windows system via a rogue Network Provider API item. NPPSPY …
Published 16/12/2025 19:37 · Modified 27/03/2026 01:07 -
evilginx2 usesThe MITRE Corporation Confidence 75
[evilginx2](https://attack.mitre.org/software/S9003) is an open-source adversary-in-the-middle (AiTM) attack framework based on the open-source nginx web server. [evilginx2](https://attack.mitre.org/software/S9003) can be used as a reverse proxy between victims and legitimate web …
Published 30/01/2026 21:15 · Modified 04/05/2026 16:31
Campaign (1)
- ArcaneDoor uses