⤷ Title: Critical SSRF Flaw in Esri Portal for ArcGIS Exposes Internal Networks
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 02 Jun 2025 00:40:21 +0000
════════════════════════
⌗ Tags: #Vulnerability #ArcGIS #critical patch #cybersecurity #data exfiltration #Esri #network_security #Portal for ArcGIS #Remote Code Execution #ssrf
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Mon, 02 Jun 2025 00:40:21 +0000
════════════════════════
⌗ Tags: #Vulnerability #ArcGIS #critical patch #cybersecurity #data exfiltration #Esri #network_security #Portal for ArcGIS #Remote Code Execution #ssrf
Daily CyberSecurity
Critical SSRF Flaw in Esri Portal for ArcGIS Exposes Internal Networks
Esri patches a critical SSRF vulnerability in Portal for ArcGIS, allowing unauthenticated remote attackers to bypass protections and access internal services.
⤷ Title: Critical CVSS 10.0 SQL Injection Vulnerability Patched in Esri ArcGIS Server
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 09 Oct 2025 03:51:35 +0000
════════════════════════
⌗ Tags: #Vulnerability #ArcGIS Server #Critical Vulnerability #Esri #geospatial #GIS #security patch #sql injection
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 09 Oct 2025 03:51:35 +0000
════════════════════════
⌗ Tags: #Vulnerability #ArcGIS Server #Critical Vulnerability #Esri #geospatial #GIS #security patch #sql injection
Daily CyberSecurity
Critical CVSS 10.0 SQL Injection Vulnerability Patched in Esri ArcGIS Server
Esri released a patch for a Critical (CVSS 10.0) SQL Injection flaw in ArcGIS Server v11.3, 11.4, and 11.5 that allows RCE and data access. Update immediately.
⤷ Title: China-Backed Flax Typhoon APT Maintained Year-Long Access by Turning ArcGIS SOE into Web Shell Backdoor
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 16 Oct 2025 01:36:29 +0000
════════════════════════
⌗ Tags: #Cyber Security #APT #ArcGIS #China_Backed #Flax Typhoon #Java SOE #persistence #Supply Chain #Web Shell
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 16 Oct 2025 01:36:29 +0000
════════════════════════
⌗ Tags: #Cyber Security #APT #ArcGIS #China_Backed #Flax Typhoon #Java SOE #persistence #Supply Chain #Web Shell
Daily CyberSecurity
China-Backed Flax Typhoon APT Maintained Year-Long Access by Turning ArcGIS SOE into Web Shell Backdoor
ReliaQuest exposed Flax Typhoon for a year-long breach, where the China-backed APT turned a legitimate ArcGIS Java SOE into a web shell and embedded it in backups to ensure persistence.
⤷ Title: China-Backed Flax Typhoon APT Maintained Year-Long Access by Turning ArcGIS SOE into Web Shell Backdoor
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Thu, 16 Oct 2025 08:27:30 +0000
════════════════════════
⌗ Tags: #Cyber Security #APT #ArcGIS #Flax Typhoon #Java SOE #Living_off_the_land #persistence #SoftEther VPN #Web Shell
════════════════════════
𐀪 Author: ddos
════════════════════════
ⴵ Time: Thu, 16 Oct 2025 08:27:30 +0000
════════════════════════
⌗ Tags: #Cyber Security #APT #ArcGIS #Flax Typhoon #Java SOE #Living_off_the_land #persistence #SoftEther VPN #Web Shell
Penetration Testing Tools
China-Backed Flax Typhoon APT Maintained Year-Long Access by Turning ArcGIS SOE into Web Shell Backdoor
ReliaQuest exposed Flax Typhoon (China-backed APT) for a year-long breach, where it modified an ArcGIS Java SOE into a web shell and embedded it in backups for resilient persistence.
⤷ Title: Critical 9.8 CVSS Flaws Hit ArcGIS Infrastructure
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 23 Apr 2026 12:02:03 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #API Key Vulnerability #ArcGIS #CVE_2026_33518 #CVE_2026_33519 #cybersecurity #Esri #GIS Security #infosec #OAuth 2.0 #Patch Alert #Portal for ArcGIS
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Thu, 23 Apr 2026 12:02:03 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #API Key Vulnerability #ArcGIS #CVE_2026_33518 #CVE_2026_33519 #cybersecurity #Esri #GIS Security #infosec #OAuth 2.0 #Patch Alert #Portal for ArcGIS
Daily CyberSecurity
Critical 9.8 CVSS Flaws Hit ArcGIS Infrastructure
Esri issues an urgent fix for critical 9.8 CVSS flaws in ArcGIS. Over-scoped developer credentials could expose GIS data. Patch your portal immediately.
⤷ Title: Critical ArcGIS Server Security Patch Fixes Severe Flaws
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 02 Jun 2026 00:30:01 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #ArcGIS Server #CVE_2026_9181 #Directory Traversal #Esri Security #Software Patch
════════════════════════
𐀪 Author: Ddos
════════════════════════
ⴵ Time: Tue, 02 Jun 2026 00:30:01 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #ArcGIS Server #CVE_2026_9181 #Directory Traversal #Esri Security #Software Patch
Daily CyberSecurity
Critical ArcGIS Server Security Patch Fixes Severe Flaws
Esri recently launched an urgent ArcGIS Server security patch to address critical vulnerabilities within its core application framework. Specifically, the newly issued software update resolves mul…
⤷ Title: Critical ArcGIS Account Recovery Targeted in Active Attacks
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Sat, 20 Jun 2026 17:23:20 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Account Recovery #ArcGIS #Esri #Vulnerability
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Sat, 20 Jun 2026 17:23:20 +0000
════════════════════════
⌗ Tags: #Cybercriminals #Account Recovery #ArcGIS #Esri #Vulnerability
Daily CyberSecurity
Critical ArcGIS Account Recovery Targeted in Active Attacks
Attackers exploit ArcGIS Account Recovery flaws. Read this security bulletin to secure your enterprise by disabling default accounts and enabling SMTP.