TTPwire Vol. 1 · MITRE ATT&CK·Tagged

← All stories

The Hacker News

CISA Adds 4 Exploited Flaws to KEV, Sets May 2026 Federal Deadline

[email protected] (The Hacker News) · 2026-04-25 · Read original ↗

ATT&CK techniques detected

3 predictions
T1190Exploit Public-Facing Application
97%
“to execute arbitrary code on the host in the context of the simplehelp server user. - cve - 2024 - 7399 ( cvss score : 8. 8 ) - a path traversal vulnerability in samsung magicinfo 9 server that could allow an attacker to write arbitrary files as system authority. - cve - 2025 - 2…”
T1190Exploit Public-Facing Application
79%
“cisa adds 4 exploited flaws to kev, sets may 2026 federal deadline the u. s. cybersecurity and infrastructure security agency ( cisa ) on friday added four vulnerabilities impacting simplehelp, samsung magicinfo 9 server, and d - link dir - 823x series routers to its known exploi…”
T1584.005Botnet
52%
“activity deploying the mirai botnet in the past. as for cve - 2025 - 29635, akamai disclosed earlier this week that it recorded attempts against d - link devices to deliver a mirai botnet variant named " tuxnokill. " to mitigate the active threats, federal civilian executive bran…”

Summary

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday added four vulnerabilities impacting SimpleHelp, Samsung MagicINFO 9 Server, and D-Link DIR-823X series routers to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation. The list of vulnerabilities is below - CVE-2024-57726 (CVSS score: 9.9) - A missing authorization vulnerability in