Your external attack surface shows 3 critical vulnerabilities requiring immediate attention. The most concerning finding is an outdated Apache web server (2.4.49) running on www.cybershore.com.au with a known remote code execution vulnerability (CVE-2021-41773). Additionally, an RDP port (3389) is publicly exposed on app.cybershore.com.au, creating a direct brute-force attack vector, and your mail server IP appears on the Spamhaus Blocklist — all outbound email may be rejected by recipients.
Your DNS hygiene is mixed: SPF and DKIM are correctly configured, but DMARC is set to "none", allowing anyone to spoof emails from your domain. DNSSEC is not enabled, and a wildcard DNS record resolves to your primary IP, expanding your subdomain attack surface.
Infrastructure monitoring detected a WHOIS nameserver drift event in the last 24 hours — verify this change was authorised with your domain registrar immediately. Your primary SSL certificate expires in 12 days, which will trigger browser security warnings if not renewed.
A lookalike typosquatting domain "cybersh0re.com.au" has been registered and is resolving, posing a phishing risk to your customers.
Priority actions: upgrade Apache, close port 3389 at the firewall, and renew your SSL certificate.
CyberShore Demo
Monitored assets and open findings.
Demo
28/100Cyber Health
Critical3
High3
Medium3
Score starts at 100:
-15per Critical (alerts + ports)
-8per High (alerts + ports)
-1per Medium (alerts + ports)
Actionable Items
15 findings
|
Open RDP Port (3389) Detected on Primary Application Server
Critical
Outdated Apache Version (2.4.49) with Known RCE Vulnerability
Critical
Domain Listed on Spamhaus Blocklist (SBL)
Critical
Port 3389 (ms-wbt-server)
Critical
Port 443 (https)
Critical
DMARC Policy Set to 'none' — Email Spoofing Possible
High
WHOIS Drift Detected: Nameserver Change on Primary Domain
High
SSL Certificate Expiring in 12 Days
High
Port 3306 (mysql)
High
WHOIS Drift Detected: Nameserver Change on Primary Domain