CPE
medium
advisory
Denial of Service Vulnerability in Red Hat Enterprise Linux opentelemetry-collector
1 TTP 1 CVEA vulnerability in the opentelemetry-collector package within Red Hat Enterprise Linux allows a remote, unauthenticated attacker to trigger a denial of service condition, potentially disrupting monitoring and telemetry data collection services.
opentelemetry-collector
vulnerability
denial-of-service
1t
1c
high
advisory
Malicious Packagist Composer Themes Deploying iOS Spyware
4 TTPs 2 CVEs 1 IOCThreat actors are distributing 13 malicious Composer themes via Packagist to compromise streaming websites and deploy a WebKit-to-kernel exploit chain against iOS visitors for data exfiltration and cryptocurrency wallet theft.
iOS +1
supply-chain
mobile-malware
web-security
cryptocurrency-theft
spyware
4t
2c
1i
critical
threat
CVE-2024-23222 Apple Safari Type Confusion Leading to Sandbox Escape
2 rules 2 TTPs 1 CVE 1 IOCA type confusion vulnerability exists in Apple Safari, as detailed in CVE-2024-23222. A public exploit demonstrates successful exploitation of the vulnerability on iOS 16.4.1, leading to a sandbox escape, which has been patched in iOS 17.3 and macOS 14.3.
Safari
cve-2024-23222
type-confusion
sandbox-escape
webkit
2r
2t
1c
1i