#bluekeep
There are only two bug classes left: complexity and memory safety.

CurveBall (CVE-2020-0601)? Complexity.
BigSig (CVE-2021-43527)? Memory safety.
Log4Shell (CVE-2021-44228)? Complexity.
BlueKeep (CVE-2019-0708)? Memory safety.

Heartbleed looks like memory safety, but it's actually complexity.
April 15, 2026 at 7:08 PM
Kimsuky Exploits BlueKeep RDP Vulnerability to Breach Systems in South Korea and Japan
Kimsuky Exploits BlueKeep RDP Vulnerability to Breach Systems in South Korea and Japan
thehackernews.com
April 21, 2025 at 5:42 PM
North Korean APT group Kimsuky exploited patched BlueKeep vulnerability in South Korea & Japan, highlighting patching urgency. #cybersecurity #APT #NorthKorea
Kimsuky APT Exploits Patched BlueKeep RDP Vulnerability in South Korea and Japan
North Korean APT group Kimsuky exploited patched BlueKeep vulnerability in South Korea & Japan, highlighting patching urgency. #cybersecurity #APT #NorthKorea
securityaffairs.com
April 22, 2025 at 7:54 PM
AA19-168A: Microsoft Operating Systems BlueKeep Vulnerability

bit.ly/2WHHZYE
Microsoft Operating Systems BlueKeep Vulnerability | CISA
Official websites use .gov A .gov website belongs to an official government organization in the United States.
bit.ly
January 29, 2025 at 4:30 PM
A new CVSS 10.0 vulnerability, CVE-2026-29000, allows attackers to impersonate users with just the server's public key. Other notable CVSS 10.0 vulnerabilities include Log4Shell, EternalBlue, Heartbleed, and BlueKeep. What are other notable vulnerabilities, and which had the most impact?
With CVE-2026-29000, what are the most notable CVSS 10.0 vulnerabilities of all time?
A new CVSS 10.0 just dropped, pac4j-jwt authentication bypass. An attacker can impersonate any user (including admin) using just the server's public key. No credentials needed, no user interaction,...
reddit.com
March 5, 2026 at 1:42 PM
Forescout reveals 1.8M RDP and 1.6M VNC servers exposed online, with hundreds granting unauthenticated access to critical ICS/OT systems. Many run outdated Windows, vulnerable to BlueKeep exploits. #BlueKeep #ICS #Russia
Hundreds of Internet-Facing VNC Servers Expose ICS/OT
Millions of RDP and VNC servers are exposed to the internet—Forescout found roughly 1.8 million RDP and 1.6 million VNC instances, with tens of thousands tied to specific industries and hundreds providing unauthenticated access to ICS/OT panels. Many systems run unsupported Windows versions (over 19,000 RDP servers vulnerable to BlueKeep), and...
www.hendryadrian.com
April 29, 2026 at 4:00 PM
Wow bluekeep and eternal blue is still a problem in 2023.
June 23, 2023 at 9:21 AM
exploiting BlueKeep RDP vulnerability to breach systems in South Korea and Japan
- **Microsoft Zero-Day** (Nightmare Eclipse / GreatXML) bypasses BitLocker — CVE-2026-35273 also affects Oracle PeopleSoft

[Sources: Mastodon #infosec, #cybersecurity, #security, #databreach, #vulnerability,
June 18, 2026 at 5:34 AM
#Kimsuky is back—and digging deep.

A new Larva-24005 campaign is exploiting old RDP bugs (BlueKeep, CVE-2019-0708) to breach systems in South Korea, Japan & beyond—with targets across energy, finance & tech.
#CyberSecurity #CyberAttacks
thehackernews.com/2025/04/kims...
Kimsuky Exploits BlueKeep RDP Vulnerability to Breach Systems in South Korea and Japan
Kimsuky exploited CVE-2019-0708 and CVE-2017-11882 since Oct 2023 to target 15 countries.
thehackernews.com
April 21, 2025 at 7:34 PM
NightEagle patches AMSI mid-attack, then DCSyncs your domain controller for privileged password hashes. https://intel.threadlinqs.com/threat/TL-2026-2606 #ThreatIntel #CVE_2019_0708 #CVE_2020_0688 #GhostContainer
September 21, 2026 at 2:10 PM
**NightEagle targets Russian companies**

Over the past year, our Global Emergency Response Team (GERT) has investigated several incidents involving the NightEagle group (APT-Q-95). This group has been active since at least 2023 and originally focused on […]

[Original post on poliverso.org]
September 16, 2026 at 10:20 AM
NightEagleがBlueKeepとDCSyncを悪用し、Active Directoryドメインコントローラーへ侵入を試みる

スパイ活動を専門とする脅威グループNightEagle(APT-Q-95としても追跡されている)は、活動範囲をアジア地域の標的からロシアの組織へと拡大しており、Active Directoryドメインコントローラーの侵害を最終目的とする多段階の侵入手口を用いています。 このキャンペーンは、企業侵害においてよく見られな
NightEagleがBlueKeepとDCSyncを悪用し、Active Directoryドメインコントローラーへ侵入を試みる
スパイ活動を専門とする脅威グループNightEagle(APT-Q-95としても追跡されている)は、活動範囲をアジア地域の標的からロシアの組織へと拡大しており、Active Directoryドメインコントローラーの侵害を最終目的とする多段階の侵入手口を用いています。 このキャンペーンは、企業侵害においてよく見られな
blackhatnews.tokyo
September 21, 2026 at 1:42 PM
NightEagle (APT-Q-95) has expanded from Asia to Russian companies, using stolen VPN credentials, GhostContainer on Exchange, BlueKeep exploitation, and tunneling to persist and move laterally. #Russia #NightEagle #APTQ95
NightEagle Targets Russian Companies
Kaspersky GERT reported that NightEagle (APT-Q-95) expanded its operations from Asia to Russian businesses, using stolen VPN credentials, GhostContainer on Microsoft Exchange, and multiple tunneling and lateral-movement techniques. The campaign also involved BlueKeep exploitation, DCSync-related activity, and tooling hosted under disguised GitHub repositories to maintain access and move across internal networks. #NightEagle #APTQ95 #GhostContainer #MicrosoftExchange #BlueKeep #DCSync
www.hendryadrian.com
September 16, 2026 at 12:15 PM
Daily IT Security Digest — 2026-07-15
requiring updated detection signatures and defensive postures. [Sources: Mastodon #threatintel]

## 8. NVIDIA Zero-Day (CVE-2026-35273) Affects Oracle PeopleSoft; BlueKeep RDP Exploitation Continues

A zero-day exploit affecting NVIDIA components and tracked as
July 15, 2026 at 5:02 AM
Daily IT Security Digest — 2026-07-15
CVE-2026-35273 is also impacting Oracle PeopleSoft systems. Separately, the long-dormant BlueKeep RDP vulnerability continues to be actively exploited by threat actors targeting systems in South Korea and Japan, demonstrating that known vulnerabilities remain
July 15, 2026 at 5:02 AM
Daily IT Security Digest — 2026-07-09
and its clients. Customers should review Accenture's breach response guidance and assess their own exposure.
Source: https://infosec.exchange/@beyondmachines1/116884957269615406

## 9. Kimsuky Exploits BlueKeep RDP Vulnerability
July 9, 2026 at 5:02 AM
Daily IT Security Digest — 2026-07-09
North Korean-linked group Kimsuky is exploiting the BlueKeep RDP vulnerability (CVE-2019-0708) to breach systems in South Korea and Japan. This demonstrates that legacy vulnerabilities remain a persistent threat vector even years after their disclosure.
July 9, 2026 at 5:02 AM
Daily IT Security Digest — 2026-07-07
in Check Point VPNs actively exploited by Qilin ransomware via IKEv1 auth bypass. Kimsuky is also exploiting the BlueKeep RDP zero-day in South Korea and Japan. Source: [@offseq@infosec.exchange](https://infosec.exchange/@offseq/116758965574886024)

## Bonus:
July 7, 2026 at 5:03 AM
Daily IT Security Digest — 2026-07-07
[@amitav63.bsky.social](https://timesofindia.indiatimes.com/world/us/chi...)

## 8. 🛡️ Active Exploits: Cisco SD-WAN, Check Point VPN, BlueKeep Resurgence
Cisco Catalyst SD-WAN Manager zero-day (CVE-2026-20262) exploited in the wild for root escalation.
July 7, 2026 at 5:03 AM
Kimsuky Exploits BlueKeep RDP Vulnerability to Breach Systems in South Korea and Japan
thehackernews.com/2025/04/kims...
Kimsuky Exploits BlueKeep RDP Vulnerability to Breach Systems in South Korea and Japan
Kimsuky exploited CVE-2019-0708 and CVE-2017-11882 since Oct 2023 to target 15 countries.
thehackernews.com
April 22, 2025 at 2:42 AM
La faille Bluekeep exploitée par des cybercriminels

ift.tt/2PLBFPW
La faille Bluekeep exploitée par des cybercriminels - ZDNET
Sécurité : Les attaquants utilisent la vulnérabilité BlueKeep pour pénétrer dans les systèmes Windows et installer un mineur de cryptomonnaies.
ift.tt
February 5, 2025 at 10:04 PM
Un botnet s’attaque à plus de 1,5 million de serveurs RDP

zdnet.fr/actualites/un-…
Un botnet s’attaque à plus de 1,5 million de serveurs RDP - ZDNET
Sécurité : En outre, les statistiques montrent que malgré BlueKeep, la plupart des attaques RDP sont aujourd’hui des attaques de force brute.
www.zdnet.fr
February 5, 2025 at 6:14 PM