CVE
CVE-2021-4034
- First Reported
- Jun 3, 2026
- Latest Reported
- Sep 14, 2026
Reported Context (3)
- evil.c, evil2.c, evil3.cExploitShared library payloads for exploiting PwnKit (CVE-2021-4034). Exposed Directory Reveals FortiGate and MeshCentral Intrusion Targeting Thai Broadband Provider
- The operator staged code for multiple known exploits: CVE-2021-4034 (PwnKit), CVE-2021-3156 (sudo), CVE-2017-7269 (IIS WebDAV). Unattended Hermes AI Agent Used in Targeting of Thailand Finance Ministry, Researchers Find
- 79 files across 13 subdirectories totaling 4 MB. Key contents included a pwnkit/ directory with CVE-2021-4034 (834 KB across 7 files), a TLS certificate and private key pair for C2 authentication, and a Python PCPJack Used 230 Cloud Linux Servers in a Hidden SMTP Relay Network
CVE (15)
Malware (2)
People (2)
Threat Actors (2)
MITRE ATT&CK (37)
Vendors (6)
Products (20)
Tools (13)
Industries (2)
Countries (6)
Note: Related entities, including threat actors, malware, CVEs, MITRE ATT&CK techniques, vendors, products, tools, countries, and industries, are shown when they appear in the same reporting. Their presence does not necessarily mean they were targeted, compromised, vulnerable, responsible for the activity, or directly involved in the incident.