CVE-2023-45858
Beyond the plain patch information, the alert provides no evidence of active exploitation; the flaw allows reading local files and is fixed in version 23.4.88.1429.
CTI status
As of:
Last pipeline run:
Source reliability
Information credibility
NATO Admiralty (AJP-2.1) grades confidence, independent of the risk score. Cross-source corroboration isn't tracked for non-CVE news, so single-source items are capped at a lower credibility number; a low number does not imply low quality.
Beyond the plain patch information, the alert provides no evidence of active exploitation; the flaw allows reading local files and is fixed in version 23.4.88.1429.
The GRU actor Sandworm is chaining Cisco vulnerabilities to spread an upgraded Cyclops Blink variant and maintain persistent control over compromised network devices.
The use of a signed kernel driver as a rootkit shows the group is deliberately bypassing EDR detection on Windows endpoints and servers, not merely exfiltrating data.
For the first time, an APT actor is documented systematically using agentic AI tooling (playbooks, exploit automation, payload generation) across the entire post-compromise lifecycle, significantly increasing the speed and scalability of intrusions.
The report provides no information beyond the patch details about active exploitation or new attack vectors.
The report provides no information beyond the plain CVE description; there is no indication of active exploitation, a PoC, or threat actors.
Beyond the pure patch information, the report provides no indications of active exploitation, threat actor groups, or affected victim sectors.
Beyond the plain patch information, the report adds no new insight: there is no indication of active exploitation, nor any details on TTPs or affected sectors.
The combination of a Linux kernel rootkit, BYOVD EDR neutralisation and cross-platform C2 in a single, widely deployed implant shows that kernel-level evasion techniques are no longer reserved for top-tier state actors.
ClickFix campaigns use legitimate system services for persistent attacks and therefore require user awareness rather than pure patch management.
The report does not provide specific CVE IDs or attack details, so the actual exposure and urgency remain unclear.
The vulnerability in Paessler PRTG allows information disclosure, which can compromise the confidentiality of monitoring data.