Rewterz

Rewterz Threat Alert – MuddyWater Campaign Using ScreenConnect RAT

February 12, 2021
Rewterz

Rewterz Threat Advisory – Solarwinds Orion Platform privilege escalation

February 15, 2021

Rewterz Threat Advisory – Apache Thrift denial of service

Severity

High

Analysis Summary

CVE-2020-13949

Apache Thrift is vulnerable to a denial of service, caused by improper input validation. By sending specially-crafted messages, a remote attacker could exploit this vulnerability to cause a large memory allocation, and results in a denial of service condition.

Impact

Denial of service

Affected Vendors

Apache

Affected Products

Apache Thrift 0.13.0

Remediation

Upgrade to the latest version of Thrift (0.14.0 or later)

Reading this advisory was a good start.

Make it a habit.

Rewterz publishes threat advisories ahead of mainstream cybersecurity media, informed by an AI-Native Autonomous SOC that sees regional threat actor activity in real time. Subscribe to receive each new advisory as it publishes, plus a monthly Middle East threat landscape brief drawn from our own SOC telemetry. For teams evaluating their detection coverage, a 30-minute consultation with a senior analyst is also available, at your pace, when you're ready.