Summary: 2025/04/19 11:19

First reported date: 2015/09/03
Inquiry period : 2025/03/20 11:19 ~ 2025/04/19 11:19 (1 months), 62 search results

전 기간대비 34% 높은 트렌드를 보이고 있습니다.
전 기간대비 상승한 Top5 연관 키워드는
CVSS Vulnerability Exploit Update CVE 입니다.
공격자 UNC5221 도 새롭게 확인됩니다.
공격기술 Hijacking 도 새롭게 확인됩니다.
기관 및 기업 Apple Germany Mandiant Check Point 도 새롭게 확인됩니다.
기타 Kubernetes Ingress Patches Android NGINX 등 신규 키워드도 확인됩니다.

System은 컴퓨터 시스템 보안 취약점의 심각도를 평가하기 위한 무료 공개 산업 표준입니다. CVSS는 취약성에 심각도 점수를 할당하여 대응자가 위협에 따라 대응 및 리소스의 우선 순위를 지정할 수 있도록 합니다.

 * 최근 뉴스기사 Top3:
    ㆍ 2025/04/19 When Vulnerability Information Flows are Vulnerable Themselves
    ㆍ 2025/04/18 CVE-2025-24054 Under Active Attack—Steals NTLM Credentials on File Download
    ㆍ 2025/04/17 Strengthening Zero Trust Security with Expert Penetration Testing

Trend graph by period


Related keyword cloud
Top 100

# Trend Count Comparison
1CVSS 62 ▲ 21 (34%)
2Vulnerability 61 ▲ 20 (33%)
3Exploit 42 ▲ 14 (33%)
4Update 38 ▲ 13 (34%)
5CVE 24 ▲ 3 (13%)
6Malware 22 ▲ 4 (18%)
7attack 17 ▲ 4 (24%)
8Report 17 ▲ 7 (41%)
9target 15 ▲ 4 (27%)
10Software 15 ▲ 8 (53%)
11Remote Code Execution 14 ▼ -6 (-43%)
12RCE 13 ▲ 11 (85%)
13Critical 12 ▲ 5 (42%)
14United States 12 ▲ 8 (67%)
15intelligence 10 ▼ -1 (-10%)
16CISA 10 ▼ -1 (-10%)
17flaw 8 ▲ 6 (75%)
18Advertising 8 ▼ -2 (-25%)
19Windows 7 ▼ -1 (-14%)
20Java 6 ▲ 5 (83%)
21ZeroDay 6 - 0 (0%)
22Kubernetes 6 ▲ new
23Microsoft 5 ▼ -3 (-60%)
24Alert 5 - 0 (0%)
25Backdoor 5 ▲ 3 (60%)
26Campaign 5 ▲ 2 (40%)
27plugin 5 ▲ 3 (60%)
28WordPress 5 ▲ 2 (40%)
29Password 5 ▲ 4 (80%)
30Wordfence 4 ▲ 2 (50%)
31Linux 4 - 0 (0%)
32Apple 4 ▲ new
33Google 4 ▲ 2 (50%)
34Ingress 4 ▲ new
35Operation 4 ▼ -2 (-50%)
36Ransomware 4 - 0 (0%)
37Patches 3 ▲ new
38GitHub 3 ▲ 1 (33%)
39Android 3 ▲ new
40Supply chain 3 ▲ 1 (33%)
41Fortinet 3 ▲ 2 (67%)
42China 3 ▲ 2 (67%)
43NGINX 3 ▲ new
44Cisco 3 ▼ -2 (-67%)
45UNC5221 3 ▲ new
46CentreStack 3 ▲ new
47DDoS 3 ▲ 1 (33%)
48VMware 3 ▲ 1 (33%)
49js 3 ▲ new
50Next 3 ▲ new
51Apache 3 ▲ 2 (67%)
52DarkWeb 3 - 0 (0%)
53Victim 3 ▲ 1 (33%)
54ingressnginx 2 ▲ new
55Full 2 ▲ new
56Germany 2 ▲ new
57Roller 2 ▲ new
58Middleware 2 ▲ new
59Warns 2 ▲ new
60GameoverP2P 2 ▼ -1 (-50%)
61Router 2 ▲ 1 (50%)
62MacOS 2 ▲ 1 (50%)
63XSS 2 ▲ 1 (50%)
64Mandiant 2 ▲ new
65hijack 2 - 0 (0%)
66Cryptographic key 2 ▲ new
67Hijacking 2 ▲ new
68Docker 2 ▲ new
69CVEs 2 ▲ new
70공격 2 ▲ new
71file 2 ▲ 1 (50%)
72Active 2 ▲ new
73Ivanti 2 ▲ new
74access 2 ▲ new
75SonicWall 2 ▲ 1 (50%)
76Oracle 2 ▲ 1 (50%)
77Backup 2 ▲ new
78Veeam 2 ▲ new
79Firmware 2 ▲ 1 (50%)
80Government 2 - 0 (0%)
81MFA 2 - 0 (0%)
82Remote 2 - 0 (0%)
83SSH 2 ▲ new
84Broadcom 2 ▲ 1 (50%)
85Check Point 2 ▲ new
86SMA 2 ▲ new
87RATel 2 ▼ -1 (-50%)
88DYEPACK 2 ▼ -1 (-50%)
89Controller 2 ▲ new
90session 1 - 0 (0%)
91Trust 1 ▲ new
92iOS 1 ▲ new
93Tomcat 1 - 0 (0%)
94Flaws 1 ▼ -1 (-100%)
95SureTriggers 1 ▲ new
96Zero 1 ▲ new
97FortiSwitch 1 ▲ new
98MachineKey 1 ▲ new
99AiCloud 1 ▲ new
100HardCoded 1 ▲ new
Special keyword group
Top 5

Malware Type
Malware Type

This is the type of malware that is becoming an issue.


Keyword Average Label
Ransomware
4 (36.4%)
GameoverP2P
2 (18.2%)
RATel
2 (18.2%)
DYEPACK
2 (18.2%)
MeshAgent
1 (9.1%)
Attacker & Actors
Attacker & Actors

The status of the attacker or attack group being issued.


Keyword Average Label
UNC5221
3 (100%)
Attack technique
Technique

This is an attack technique that is becoming an issue.


Keyword Average Label
Exploit
42 (47.2%)
Remote Code Execution
14 (15.7%)
RCE
13 (14.6%)
Backdoor
5 (5.6%)
Campaign
5 (5.6%)
Country & Company
Country & Company

This is a country or company that is an issue.


Keyword Average Label
United States
12 (22.2%)
CISA
10 (18.5%)
Microsoft
5 (9.3%)
Apple
4 (7.4%)
Google
4 (7.4%)
Threat info
Last 5

SNS

(Total : 18)
  Total keyword

CVSS Vulnerability CVE Update Exploit Attacker RCE ZeroDay Password Malware MeshAgent Report Docker Telegram attack powershell CISA Firmware Cisco Fortinet VMware Windows Kubernetes Apple UNC5221 Safari hijack iPhone Hijacking Java Mandiant China iCloud

No Title Date
1Dark Web Informer - Cyber Threat Intelligence @DarkWebInformer
????ASUS AiCloud Vulnerability (CVE-2025-2492) Enables Remote Function Execution via Authentication Bypass CVSS Score: 9.2 https://t.co/0YofUq1hWX
2025.04.18
2The Hacker News @TheHackersNews
???? Actively Exploited SonicWall Flaw Hits CISA’s KEV List. Remote attackers can execute code via SMA 100 Series bug (CVE-2021-20035, CVSS 7.2). ➡️ Injects OS commands as ‘nobody’ user ➡️ Impacts SMA 200–500v on outdated firmware ➡️ FCEB agencies must patch by May 7, 2025 Your https://t.co/U3Xbw
2025.04.17
3The Hacker News @TheHackersNews
???? CVSS 10.0 ALERT: Remote Code Execution in Erlang/OTP SSH (CVE-2025-32433) No auth. Full control. Widespread impact. Used in Cisco, Ericsson, OT/IoT, and edge systems, this bug lets attackers run code without logging in. If SSH runs as root? Game over. ???? ???? Full details → https://t.co/K
2025.04.17
4Hunter @HunterMapping
????Alert???? CVE-2025-32433 (CVSS 10): Critical SSH Flaw Allows Unauthenticated RCE in Erlang/OTP.It affects versions prior to OTP-27.3.3, OTP-26.2.5.11, and OTP-25.3.2.20 ????490K+ Services are found on the https://t.co/ysWb28Crld yearly. ????Hunter Link:https://t.co/NhdSN1rRIh ????Query https://t
2025.04.17
5The Hacker News @TheHackersNews
???? Alert — A 9.0 CVSS flaw in Gladinet’s CentreStack also affects Triofox—both used for remote access. Attackers exploited it as a zero-day in March, hitting 7 orgs by April 11. ???? Root cause: Hardcoded crypto keys → enabled RCE via PowerShell + DLL sideloading ???? Read: https://t.co/w6EXAZH
2025.04.15

Additional information

No data
No data
No data
No data
Beta Service, If you select keyword, you can check detailed information.