Cyber risk and advisory programs that identify security gaps and build strategies to address them.
MDR that provides improved detection, 24/7 threat hunting, end-to-end coverage and most of all, complete Response.
Our team delivers the fastest response time in the industry. Threat suppression within just 4 hours of being engaged.
Be protected by the best from Day 1.
24/7 Threat Investigation and Response.
Expert hunting, research and content.
Defend brute force attacks, active intrusions and unauthorized scans.
Protect assets from ransomware, trojans, rootkits and more.
Intelligence and visibility across AWS, O365, DevOps and more.
Configuration escalations, policy and posture management.
Detects malicious insider behavior leveraging Machine Learning models.
eSentire has observed active exploitation attempts of the Drupal remote code execution vulnerability, CVE-2018-7600. Drupal is an open source content management framework. Websites using default or common Drupal installations, that lack the most recent security patches, are at a high risk of exploitation. CVE-2018-7600 allows remote attackers to execute code without authentication on vulnerable Drupal websites 1. Code execution may result in the complete compromise of websites. The issue was originally identified at the end of March but recent reports state that attack attempts have been identified since April 11, 20182.
CVE-2018-7600 affects versions 6 to 8 of Drupal that were configured with default or common configurations. The vulnerability is caused by a lack of process sanitation, allowing an attacker to pass a malicious payload to the application.
Proof of Concept (PoC) code to exploit CVE-2018-7600 has also been made publicly available, lowering the technical skill required to carry out this attack 5