top of page
Search
Pegasos 24/7 Threat Labs


CVE-2026-25253 "OpenClaw RCE" and Moltbook Database Exposure
DTG Threat Intelligence is tracking active exploitation of CVE-2026-25253, a high-severity remote code execution vulnerability impacting OpenClaw AI agent deployments, alongside a critical Moltbook database exposure. The flaws enable unauthenticated token theft, arbitrary command execution, and large-scale API key compromise. This advisory outlines confirmed exploitation activity, affected versions, and immediate remediation steps.
DTG Threat Management Team
Feb 125 min read


CVE-2026-1281 & CVE-2026-1340 "Ivanti EPMM Zero-Day Vulnerabilities”
DTG Threat Intelligence is tracking active zero-day exploitation of two critical vulnerabilities, CVE-2026-1281 and CVE-2026-1340, impacting Ivanti Endpoint Manager Mobile (EPMM). These unauthenticated remote code execution flaws allow attackers to fully compromise exposed EPMM appliances, placing enterprise mobile device fleets, credentials, and configuration data at immediate risk. This advisory outlines observed exploitation, affected versions, and urgent remediation steps
DTG Threat Management Team
Feb 38 min read


CVE-2024-37079 "vCenter DCERPC Overflow"
Pegasos24/7 Threat Labs Advisory Classification Threat Advisory Threat Level Critical Date Issued 18 June 2024 Distribution To: Security Operations Centers (SOC), Virtualization Teams, Infrastructure Teams, Cloud Operations Executive Summary CVE-2024-37079 , a critical (CVSS 9.8) heap-based buffer overflow vulnerability in VMware vCenter Server, permits unauthenticated remote attackers with network access to execute arbitrary code with root privileges. The vulnerability exist
DTG Threat Management Team
Feb 26 min read


CVE-2025-8088 "WinRAR ADS Escape"
A high-severity WinRAR vulnerability, CVE-2025-8088, is being actively exploited in the wild by multiple threat actors. This advisory outlines how the flaw enables arbitrary code execution via crafted archives, who is targeting it, and the immediate actions security teams should take to reduce risk.
DTG Threat Management Team
Jan 2910 min read


MongoDB Under Siege: Critical Memory Leak Exposes Secrets via MongoBleed
CVE-2025-14847 "MongoBleed” MongoDB Unauthenticated Memory Disclosure Vulnerability Classification: Threat Advisory Threat Level: High/Advisory Date Issued: 29 December 2025 Distribution: To: Security Operations Centers (SOC), Database Administrators (DBA), System Owners Executive Summary CVE-2025-14847, publicly disclosed and colloquially named "MongoBleed," is a critical, unauthenticated memory disclosure vulnerability affecting MongoDB Server across multiple versions.
DTG Threat Management Team
Jan 85 min read


Cisco AsyncOS Under Siege: Zero-Day Remote Code Execution Threatens Secure Email Appliances
Critical Zero-Day Exploited in Cisco Secure Email Appliances (CVE‑2025‑20393) DTG Threat Intelligence is tracking active exploitation of CVE-2025-20393, a critical zero‑day vulnerability (CVSS 10.0) impacting Cisco Secure Email Gateway and Cisco Secure Email and Web Manager appliances running AsyncOS. The flaw allows unauthenticated remote attackers to execute arbitrary commands with root privileges, resulting in complete system compromise. Analysis links attacks to China‑b
DTG Threat Management Team
Dec 22, 20253 min read


React2Shell (CVE-2025-55182): Critical RCE Impacting React and Next.js
Discovery and Disclosure On December 3, 2025, the React team disclosed CVE-2025-55182, a maximum‑severity (CVSS 10.0) remote code execution vulnerability in React Server Components, now widely referred to as “ React2Shell .” The flaw enables unauthenticated attackers to trigger server‑side code execution with a single crafted HTTP request against common React and Next.js deployments. React2Shell was discovered and responsibly disclosed by security researcher Lachlan Davids
DTG Threat Management Team
Dec 9, 20253 min read
bottom of page
