qlik News Articles
Recent news articles refferecing the vendors vulnerabilities.
PrickSense How Cactus exploits Qlik Sense
Who is Cactus? The Cactus ransomware group is a relative newcomer, targeting major commercial enterprises since March 2023. Since then, it has established a strong foothold in the ransomware ecosystem by...

Shadowserver (@shadowserver.bsky.social)
Attention: we are sharing a one-off special report on Cactus ransomware group campaign targeting Qlik Sense (data viz & business intelligence tool): https://shadowserver.org/what-we-do/network-reporting/critical-vulnerable-compromised-qlik-sense-special-report/ 2894 IPs found vulnerable to CVE-2023...
CVE-2023-41265, CVE-2023-41266 & CVE-2023-48365 | Arctic Wolf
Arctic Wolf has recently worked multiple incident response cases where we have observed ransomware groups exploiting CVE-2023-41265, CVE-2023-41266 & CVE-2023-48365 to gain initial access.
CACTUS Qlik Ransomware: Vulnerabilities Exploited
Learn all about the CACTUS Qlik ransomware and stay updated with evolving cyber threats to keep your network and infrastructure secure.
Qlik Sense flaws exploited in Cactus ransomware campaign - Help Net Security
Attackers are exploiting three critical vulnerabilities in internet-facing Qlik Sense instances to deliver Cactus ransomware to target orgs.
CACTUS Ransomware Exploits Qlik Sense Vulnerabilities in Targeted Attacks
A CACTUS ransomware campaign has been observed exploiting vulnerabilities in the Qlik Sense cloud analytics and business intelligence platform.
Cactus ransomware exploiting Qlik Sense flaws to breach networks
Cactus ransomware has been exploiting critical vulnerabilities in the Qlik Sense data analytics solution to get initial access on corporate networks.
Qlik Sense Vulnerabilities Exploited in Ransomware Attacks
Qlik Sense vulnerabilities CVE-2023-41266, CVE-2023-41265 and CVE-2023-48365 exploited for initial access in Cactus ransomware attacks.

DoubleQlik: Bypassing the Fix for CVE-2023-41265 to Achieve Unauthenticated Remote Code Execution
We identified a bypass for the original fix for CVE-2023-41265 which allowed for unauthenticated RCE. We then validated Qlik's new patch.