Skip to content
Threat Feed

Tag

Infrastructure

8 briefs RSS
low advisory

BIND 9 Denial of Service via Malformed DNS64 Response

A vulnerability in BIND 9 resolvers configured with DNS64 allows an authoritative server to cause a process crash through malformed responses, resulting in a denial of service.

BIND +5 denial-of-service network-infrastructure vulnerability dns infrastructure
1t 1c
medium advisory

Denial of Service Vulnerability in BIND Named Service

A memory management flaw in BIND 9 allows an attacker-controlled authoritative DNS server to trigger a service abort by providing a maliciously crafted 65536-byte negative DNS response.

BIND +10 denial-of-service dns infrastructure
1t 6c updated
high advisory

Multiple Critical Vulnerabilities in HPE Aruba Networking Products

HPE has disclosed a wide range of vulnerabilities across AOS-CX and Fabric Composer, including RCE, privilege escalation, and DoS flaws, impacting numerous versions of the network operating system.

AOS-CX +5 vulnerability networking infrastructure
3t
medium advisory

Kernel Denial of Service Vulnerability in vmxnet3 Driver

CVE-2026-68299 is a kernel-level denial of service vulnerability in the vmxnet3 virtual network driver caused by a BUG_ON condition when processing malformed Geneve-encapsulated packets.

vmxnet3 denial-of-service kernel infrastructure
1c
medium advisory

Multiple Denial of Service Vulnerabilities in PJSIP pjmedia

Multiple vulnerabilities in the PJSIP pjmedia library can be exploited by a remote, unauthenticated attacker to trigger a denial of service condition, potentially disrupting telecommunications services.

pjmedia denial-of-service voip infrastructure
1t
high advisory

CVE-2026-7473: Arista EOS Incomplete Comparison Vulnerability Leading to Incorrect Packet Forwarding

Arista Extensible Operating System (EOS) contains CVE-2026-7473, an incomplete comparison vulnerability that allows a switch to incorrectly decapsulate and forward unexpected tunneled packets if their destination IP matches the switch's configured decapsulation IP, potentially leading to unauthorized network access or bypass of security controls.

PoC Extensible Operating System +4 vulnerability cve network-device infrastructure
2r 3t 3c updated
medium advisory

GlassWorm V2 Infrastructure Rotation and GitHub Injection Analysis

Analysis of GlassWorm V2 reveals infrastructure rotation and GitHub injection techniques.

malware github infrastructure
2r 2t
medium advisory

ESXi Download Error Detection

Detection of failed file download attempts on ESXi hosts, potentially indicating unauthorized or malicious activity such as installing or updating components, including VIBs or scripts.

ESXi +3 vmware syslog anomaly T1601.001 T1685 ESXi Post Compromise Black Basta Ransomware Infrastructure +1
2r 2t