[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"focus:cisa-adds-seven-exploited-flaws-as-attackers-deploy-reverse-shells-and-crypto-mi-mtm0ldj9":3},{"item":4},{"id":5,"title":6,"slug":7,"summary":8,"severity":9,"category":10,"cve_ids":11,"affected_products":12,"action_required":18,"article_ids":19,"ioc_summary":21,"source_urls":22,"status":24,"expires_at":25,"created_at":26,"updated_at":27,"articles":28},"791306ce-4db0-4c4f-aaec-243b8ff3dbd4","CISA Adds Seven Exploited Flaws as Attackers Deploy Reverse Shells and Crypto Miners","cisa-adds-seven-exploited-flaws-as-attackers-deploy-reverse-shells-and-crypto-mi-mtm0ldj9","CISA added seven actively exploited vulnerabilities to the KEV catalog affecting SonicWall, Sangoma, JFrog, Kludex, Kestra, and Berri LiteLLM. Threat actors are chaining these flaws to deploy reverse shells, escalate privileges, and install crypto miners. Qilin ransomware operators have already weaponized at least one exploit chain.","critical","advisory",[],[13,14,15,16,17],"SMA 1000 Appliances","SonicWall","Switchvox","Sangoma","Artifactory","Immediately inventory and patch affected products. Prioritize SonicWall, Sangoma, and JFrog instances. Monitor for suspicious outbound connections (reverse shell indicators), new administrative accounts, and anomalous crypto miner process signatures.",[20],"055dd0a8-052e-4338-b40e-693b50a63bbd",null,[23],"https:\u002F\u002Fthehackernews.com\u002F2026\u002F09\u002Fcisa-adds-seven-exploited-flaws-as.html","active","2026-09-05T21:05:47.886+00:00","2026-09-03T21:05:51.140483+00:00","2026-09-03T21:05:54.815876+00:00",[29],{"id":20,"title":6,"url":23}]