Remote access infrastructure
CriticalIvanti VPN appliances under active exploitation
Patch Ivanti appliances immediately, restrict external management access, and hunt for web shell indicators.
Reference documentationActive exploitation alerts
High-signal exploitation patterns that should drive patching, logging, and incident triage.
Remote access infrastructure
CriticalPatch Ivanti appliances immediately, restrict external management access, and hunt for web shell indicators.
Reference documentationCloud identity and enterprise email
HighEnforce phishing-resistant MFA, revoke suspicious sessions, and review risky sign-ins and OAuth app consent grants.
Reference documentationWindows servers and enterprise endpoints
HighDisable public RDP exposure, enforce VPN-only access, enable account lockout policies, and monitor brute-force activity.
Reference documentationPerimeter security appliances
CriticalPatch internet-facing devices, review administrative logins, rotate credentials, and validate firmware integrity.
Reference documentationCorporate workstations and user credentials
HighReset compromised credentials, enable endpoint detection, monitor browser credential theft alerts, and enforce MFA.
Reference documentation