<?xml version='1.0' encoding='utf-8'?>
<rss version="2.0"><channel><title>Cybersecurity Tracker: Apache Watch</title><link>https://cybersecuritytracker.ai/?stack=1</link><description>Stories and vulnerabilities involving Apache.</description><lastBuildDate>Sun, 26 Jul 2026 22:32:51 GMT</lastBuildDate><item><title>How much cyber risk does AI create for organizations? 457 million security issues. Here’s what you can do about it.</title><link>https://tenable.com/blog/how-much-cyber-risk-does-ai-create-for-organizations-457-million-security-issues-heres-what</link><guid isPermaLink="false">cst-382</guid><description>Tenable detected 457 million AI-related security issues across over 7,000 organizations during a 30-day period, averaging 62,000 exposures per organization. These issues stem primarily from misconfigurations and unmanaged dependencies rather than traditional CVEs, and organizations continue to struggle with patching known vulnerabilities, with median time-to-patch increasing to 43 days. Security teams need to shift from CVE-focused approaches to comprehensive exposure management using automated workflows and AI-driven tools to address the full attack surface.</description><pubDate>Wed, 24 Jun 2026 13:00:00 GMT</pubDate></item><item><title>The Most Organized Threat Actors Use Your ITSM (BMC FootPrints Pre-Auth Remote Code Execution Chains)</title><link>https://labs.watchtowr.com/thanks-itsms-threat-actors-have-never-been-so-organized-bmc-footprints-pre-auth-remote-code-execution-chains</link><guid isPermaLink="false">cst-563</guid><description>watchTowr Labs discovered four chained vulnerabilities in BMC FootPrints ITSM solution, including authentication bypass, server-side request forgery, and deserialization flaws that enable pre-authenticated remote code execution. The vulnerabilities affect BMC FootPrints versions 20.20.02 through 20.24.01.001, and disclosure to BMC began in June 2025. ITSM solutions like FootPrints are high-value targets because they manage IT inventory, configuration data, and incident information that organized threat actors leverage for ransomware campaigns.</description><pubDate>Wed, 18 Mar 2026 10:02:49 GMT</pubDate></item><item><title>Apache ActiveMQ Exploit Leads to LockBit Ransomware</title><link>https://thedfirreport.com/2026/02/23/apache-activemq-exploit-leads-to-lockbit-ransomware</link><guid isPermaLink="false">cst-577</guid><description>A threat actor exploited CVE-2023-46604 on an exposed Apache ActiveMQ server in mid-February 2024 to achieve remote code execution using a Java Spring class, leading to LockBit ransomware deployment. The intrusion demonstrates how unpatched critical vulnerabilities in internet-facing services remain an effective attack vector for ransomware operators.</description><pubDate>Mon, 23 Feb 2026 14:09:43 GMT</pubDate></item><item><title>GreyNoise Observes Active Exploitation of Critical Apache Tomcat RCE Vulnerability (CVE-2025-24813)</title><link>https://greynoise.io/blog/active-exploitation-critical-apache-tomcat-rce-vulnerability-cve-2025-24813</link><guid isPermaLink="false">cst-1911</guid><description>GreyNoise has detected active exploitation of CVE-2025-24813, a critical remote code execution vulnerability in Apache Tomcat, with multiple IP addresses conducting attacks across several regions. The vulnerability allows attackers to execute arbitrary code on affected Tomcat servers.</description><pubDate>Thu, 20 Mar 2025 00:00:00 GMT</pubDate></item><item><title>Critical Vuln: Apache ActiveMQ CVE-2023-46604 Exploited | Huntress</title><link>https://huntress.com/blog/critical-vulnerability-exploitation-of-apache-activemq-cve-2023-46604</link><guid isPermaLink="false">cst-1025</guid><description>CVE-2023-46604 is a critical remote code execution vulnerability affecting Apache ActiveMQ that is being actively exploited in the wild. Organizations running affected versions should apply patches immediately to prevent unauthorized code execution.</description><pubDate>Thu, 02 Nov 2023 00:00:00 GMT</pubDate></item><item><title>Critical RCE Vulnerability Updates (log4j - CVE-2021-44228) | Huntress</title><link>https://huntress.com/blog/rapid-response-critical-rce-vulnerability-is-affecting-java</link><guid isPermaLink="false">cst-1161</guid><description>Huntress released analysis of CVE-2021-44228, a critical remote code execution vulnerability in the Java logging library Log4j that enables unauthenticated attackers to execute arbitrary code on affected systems.</description><pubDate>Fri, 10 Dec 2021 00:00:00 GMT</pubDate></item></channel></rss>