Compliance Node Overview
MITRE ATT&CK T1190 describes adversary exploitation of weaknesses in internet-facing applications, services, or APIs to gain initial network access. Notable real-world exploitations include MOVEit (CVE-2023-34362, Clop ransomware campaign 2,600+ victims), Log4Shell (CVE-2021-44228), Citrix Bleed (CVE-2023-4966), and Ivanti Connect Secure (CVE-2023-46805). Mandatory compliance obligations include vulnerability management programmes (NIST 800-53 RA-5/SI-2, ISO A.8.8), web application firewalls (PCI DSS Req 6.4.2), and rapid patching SLAs (NIS2 mandates 24-hour notification for actively exploited vulnerabilities).
Pillar: Cybersecurity · Authority: MITRE Corporation · Version: 1.0.0 · Last updated:
Primary source: https://attack.mitre.org/techniques/T1190/
SHA-256 integrity: 0ff620484b3db764aa1868a3ae238ada14725eb30371b5ae31b1bb237ee35fee
Primary Citations — 7 traced to source
- MITRE ATT&CK Technique T1190: Exploit Public-Facing Application (https://attack.mitre.org/techniques/T1190/)
- CISA Known Exploited Vulnerabilities (KEV) Catalog: authoritative real-time list of actively exploited CVEs requiring mandatory federal patching
+ 5 more citations (full bibliography, deterministic workflow, actionable schema and crosswalks) included in the vault unlock — $0.01 via Skyfire / L402 / Direct Base USDC.
Access
⚠ Important: Human Verification Required
Bidda compliance nodes are reference intelligence, not legal advice. Every node must be reviewed by a qualified compliance professional or legal counsel before implementation in any enterprise workflow, regulated system, or compliance programme. See bidda.com/disclaimer for full terms.