Activity timeline
T1190 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-07 with 306 reports, and 955 of the 958 threats were reported in the twelve months to 2026-10.
How adversaries use it
T1190 Exploit Public-Facing Application is catalogued by MITRE ATT&CK under the Initial Access tactic in the Enterprise matrix. Threadlinqs maps 958 of 2623 tracked threats (36.5%) to it; by severity that is 525 critical, 348 high, 69 medium, 3 low.
Threats that use T1190 most often also use T1059 Command and Scripting Interpreter (504 threats), T1005 Data from Local System (428 threats), T1078 Valid Accounts (411 threats), T1082 System Information Discovery (398 threats), T1068 Exploitation for Privilege Escalation (372 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.
146 tracked threat actors appear in the threats that use T1190; the most frequent are APT28 (11), Qilin (11), ShinyHunters (10), Static Tundra (9), The Gentlemen (9).
Mitigations
MITRE ATT&CK lists 8 mitigations for T1190.
Data sources
Telemetry that can reveal T1190, per MITRE ATT&CK.
- Application Log — Application Log Content
- Network Traffic — Network Traffic Content
Threat actors using it
Tracked threats
The 30 most recent of 958 tracked threats that use T1190.
- Multiple cPanel & WHM Vulnerabilities (CVE-2026-93698, CVE-2026-93029, CVE-2026-93697) Enable Root Code…critical
- CISA adds Citrix NetScaler SAML memory overflow DoS (CVE-2026-88779) to KEV Cataloghigh
- TIKTOUK Toolkit Harvests AWS, SMTP and Database Credentials from Exposed WordPress Backups and Config Files…high
- Desktop AI Supercomputers, Uncensored Models and Agentic Frameworks (HexStrike-AI) Enable Automated…high
- AI-accelerated intrusions: Microsoft 2026 Digital Defense Report on phishing, public-facing app…high
- Red Hat Satellite Foreman template preview authorization flaw (CVE-2026-96659) enables root password theft…critical
- Rejetto HTTP File Server (HFS) 3.x session forgery via predictable Math.random() signing key leads to…critical
- AWS AI Agent Vulnerabilities (Loom, SageMaker Unified Studio) Let Attackers Bypass Authentication and Steal…critical
- Cling IoT botnet masquerades as Google STUN traffic for C2, exploiting Realtek Jungle SDK CVE-2021-35394high
- Fortra Patches Critical Vulnerabilities in BoKS Privileged Access Manager (CVE-2026-79901, CVE-2026-79898…critical
- The First 24 Hours of a Ransomware Intrusion: Exfiltration, Credential Theft and Backup Targeting (Akira…high
- Kiteworks 9.5.1 Patches 126 Vulnerabilities Including Critical Account Takeover in Core and Email Protection…critical
- Forgeable Session Cookie (Hard-Coded HMAC Secret) in Yard Management System Bypasses Entra ID MFA and…high
- Multiple Vulnerabilities in Apache HTTP Server 2.4.0 through 2.4.68 (20 CVEs, fixed in 2.4.69)medium
- City of Vicksburg, Mississippi shuts down systems after ransomware attackmedium
- Dell Container Storage Modules (CSM) flaws enable unauthenticated admin access and root on Kubernetes nodes…critical
- GitLab AI Gateway critical RCE via prompt template sandbox escape (CVE-2026-90970)critical
- Frontline Education data breach via exploited third-party software vulnerability exposes school district…high
- CISA adds two Zammad vulnerabilities to KEV: CVE-2026-102489 (session fixation to RCE) and CVE-2026-102490…critical
- DragonForce backdoors abuse Microsoft Teams TURN servers and MQTT for resilient C2high
- Warlock Ransomware Attackers Hit Water and Telecom Operators via SharePoint ToolShell Exploitation (Longlegs…critical
- Fortinet FortiMail critical path traversal flaw CVE-2026-104286 (FG-IR-26-175) exploited in zero-day attackscritical
- Operation KillSwitch: International Takedown of the KillSec Data-Theft Extortion Ransomware Grouphigh
- Bitget $387.5M Cryptocurrency Theft via Third-Party Security Product Zero-Day (Suspected DPRK / TraderTraitor)critical
- Cisco Catalyst SD-WAN Manager API authentication bypass zero-day (CVE-2026-76504) exploited in the wildcritical
- GTIG: AI-Era Vulnerability Discovery and Exploitation Surge — In-the-Wild Exploitation of BeyondTrust…critical
- CVE-2026-74864 / CVE-2026-74865: Authentication bypass in YunoHost-Apps sogo_yhn (SOGo proxy-auth trust)critical
- WatchGuard Fireware OS Critical Code Injection Vulnerability in BOVPN over TLS Client (CVE-2026-86131)critical
- Critical MikroTik RouterOS Integer Underflow Vulnerability (CVE-2026-84411) Enables Unauthenticated Remote…critical
- Agentic AI used for post-exploitation in breach of the Dutch Institute for Vulnerability Disclosure (DIVD)high
Detection coverage
Threadlinqs maintains 2364 detection rules mapped to T1190 (SPL 901, KQL 729, Sigma 734). Rule content is available to Blue tier accounts and above; this page shows counts only.