DMZ//THREAT INTEL
FEED ACTIVELAST SYNC: 06:13:27ZSOURCES: 14CRITICAL: 30
⚠ ACTIVE ALERTS
@FalconFeedsio CRITICAL — 🚨 Ransomware Alert: The Gentlemen RaaS group continues active DLS postings. Now at 478… /// @DarkWebInformer CRITICAL — 🚨 ServiceNow discloses June 5 security update tied to anomalous activity — KB3067321.… /// @MsftSecIntel CRITICAL — MSTIC analysis of The Gentlemen ransomware (tracked internally): self-propagating… /// @GossiTheDog CRITICAL — ServiceNow KB3067321 situation is worse than the vendor comms suggest. Advisory was gated… /// @AlvieriD CRITICAL — The '340M OnlyFans' listing on the leak forum is a compiled corpus — seller confirmed to…
30Critical Threats
15Active CVEs
1IOCs Tracked
14New Advisories
HIGH#cve

CVE-2026-28318: CISA KEV-Listed SolarWinds Serv-U Unauthenticated DoS Actively Exploited — 12,000+ Internet-Exposed Instances, FCEB Deadline June 19

CISA added CVE-2026-28318 to its Known Exploited Vulnerabilities catalog on June 5, confirming active in-the-wild exploitation of an unauthenticated denial-of-service flaw in SolarWinds Serv-U. Attackers can crash the file-transfer service without credentials by sending a specially crafted HTTP POST request using the Content-Encoding: deflate header, forcing uncontrolled resource consumption. Shodan tracks over 12,000 internet-exposed Serv-U instances and the fix — Serv-U 15.5.4 Hotfix 1 — requires a separate hotfix install even for administrators who recently upgraded to 15.5.4. Federal agencies face a June 19 remediation deadline; no threat actor attribution or ransomware linkage has been confirmed, though Serv-U has historically been weaponized by Cl0p and Chinese state actors.

Shodan tracks over 12,000 internet-exposed Serv-U instances and the fix — Serv-U 15.5.4 Hotfix 1 — requires a separate hotfix install even for administrators who recently upgraded to 15.5.4.

This intelligence brief has been compiled from open-source reporting and corroborated across multiple threat intelligence sources. Defenders should treat the high severity rating as a guide to prioritization within their environment.

For the latest indicators of compromise, formatted SIEM queries, and unredacted actor intelligence related to this brief, DMZ Operator subscribers receive automated IOC packages via email the moment new advisories are published.

STAY AHEAD OF THREATS
Daily intel briefs and IOC packages — delivered to your inbox the moment a new advisory drops.
SUBSCRIBE — $29/MO →
SHARE BRIEF:✕ Post on Xin Share on LinkedIn