Tag : 2024-05-31

8 attack reports | 81 vulnerabilities

Attack Reports

Title Published Tags Description Number of indicators
New banking trojan “CarnavalHeist” targets Brazil with overlay attacks May 31, 2024, 2:27 p.m. Cisco Talos has been observing an active campaign targeting Brazilian users with a new banking trojan dubbed 'CarnavalHeist'. The… 61
GRU’s BlueDelta Targets Key Networks in Europe with Multi-Phase Espionage Campaigns May 31, 2024, 2:17 p.m. Throughout the three phases, BlueDelta used phishing emails, legitimate internet services LIS, and living off-the-land binaries L… 30
Threat Intelligence Alert: Merry-Go-Round Conceals Ads from Users and Brands May 31, 2024, 1:45 p.m. HUMAN's Satori Threat Intelligence and Research Team uncovered an ad cloaking operation, dubbed 'Merry-Go-Round', which involves … 13
RedTail Cryptominer Threat Actors Adopt PAN-OS CVE-2024-3400 Exploit May 31, 2024, 1:41 p.m. Threat actors behind the RedTail cryptomining malware, initially reported in early 2024, have incorporated the recent Palo Alto P… 10
Chat Messenger voting topics - a new way to steal accounts is gaining momentum May 31, 2024, 1:24 p.m. The Government Emergency Response Team of Ukraine CERT-UA informs about the increase in the number of cyberattacks aimed at gaini… 230
Active exploitation of stored XSS vulnerabilities in WordPress Plugins May 31, 2024, 12:23 p.m. Recent months have witnessed active exploitation attempts targeting multiple cross-site scripting (XSS) vulnerabilities in popula… 28
AllaSenha: AllaKore variant leverages Azure cloud C2 to steal banking details in Latin America May 31, 2024, 12:22 p.m. Earlier in May, a security product detected a malicious payload aimed at stealing credentials required to access Brazilian bank a… 61
Disrupting FlyingYeti's campaign targeting Ukraine May 31, 2024, 12:19 p.m. This report details Cloudforce One's real-time effort to detect, deny, degrade, disrupt, and delay a phishing campaign by the Rus… 8

Vulnerabilities

CVE CVSS Published Product impacted Tags
CVE-2024-23692 9.8 May 31, 2024, 10:15 a.m. LOGO-VULNERABLERejetto HTTP File Server
CVE-2024-36108 9.8 May 31, 2024, 3:15 p.m. LOGO-VULNERABLEcasgate
CVE-2024-29822 9.6 May 31, 2024, 6:15 p.m. LOGO-VULNERABLEIvanti EPM
CVE-2024-29823 9.6 May 31, 2024, 6:15 p.m. LOGO-VULNERABLEIvanti EPM
CVE-2024-29824 9.6 May 31, 2024, 6:15 p.m. LOGO-VULNERABLEIvanti EPM
CVE-2024-29825 9.6 May 31, 2024, 6:15 p.m. LOGO-VULNERABLEIvanti EPM
CVE-2024-29826 9.6 May 31, 2024, 6:15 p.m. LOGO-VULNERABLEIvanti EPM
CVE-2024-29827 9.6 May 31, 2024, 6:15 p.m. LOGO-VULNERABLEIvanti EPM
CVE-2024-5345 8.8 May 31, 2024, 3:15 a.m. LOGO-VULNERABLEResponsive Owl Carousel for Elementor plugin for WordPress
CVE-2024-5523 8.8 May 31, 2024, 8:15 a.m. LOGO-VULNERABLEAstrotalks
CVE-2024-22059 8.8 May 31, 2024, 6:15 p.m. LOGO-VULNERABLEIvanti Neurons for ITSM
CVE-2024-22060 8.7 May 31, 2024, 6:15 p.m. LOGO-VULNERABLEIvanti Neurons for ITSM
CVE-2024-35142 8.4 May 31, 2024, 5:15 p.m. LOGO-VULNERABLEIBM Security Verify Access Docker
CVE-2024-29828 8.4 May 31, 2024, 6:15 p.m. LOGO-VULNERABLEIvanti EPM
CVE-2024-29829 8.4 May 31, 2024, 6:15 p.m. LOGO-VULNERABLEIvanti EPM
CVE-2024-29830 8.4 May 31, 2024, 6:15 p.m. LOGO-VULNERABLEIvanti EPM
CVE-2024-29846 8.4 May 31, 2024, 6:15 p.m. LOGO-VULNERABLEIvanti EPM
CVE-2024-5525 8.3 May 31, 2024, 8:15 a.m. LOGO-VULNERABLEAstrotalks
CVE-2023-38551 8.2 May 31, 2024, 6:15 p.m. LOGO-VULNERABLEIvanti Connect Secure
CVE-2024-5565 8.1 May 31, 2024, 3:15 p.m. LOGO-VULNERABLEVanna library
CVE-2024-36120 8.1 May 31, 2024, 5:15 p.m. LOGO-VULNERABLEjavascript-deobfuscator
CVE-2023-38042 7.8 May 31, 2024, 6:15 p.m. LOGO-VULNERABLEIvanti Secure Access Client for Windows
CVE-2024-22058 7.8 May 31, 2024, 6:15 p.m. LOGO-VULNERABLEIvanti EPM
CVE-2024-35140 7.7 May 31, 2024, 5:15 p.m. LOGO-VULNERABLEIBM Security Verify Access Docker
CVE-2024-5564 7.4 May 31, 2024, 7:15 p.m. LOGO-VULNERABLENetworkManager
CVE-2023-46810 7.3 May 31, 2024, 6:15 p.m. LOGO-VULNERABLEIvanti Secure Access Client for Linux
CVE-2024-2793 7.2 May 31, 2024, 5:15 a.m. LOGO-VULNERABLEAtarim plugin for WordPress
CVE-2024-29848 7.2 May 31, 2024, 6:15 p.m. LOGO-VULNERABLEIvanti Avalanche
CVE-2024-5418 6.4 May 31, 2024, 3:15 a.m. LOGO-VULNERABLEDethemeKit For Elementor plugin for WordPress
CVE-2024-4376 6.4 May 31, 2024, 6:15 a.m. LOGO-VULNERABLEPremium Addons for Elementor plugin
CVE-2024-5427 6.4 May 31, 2024, 7:15 a.m. LOGO-VULNERABLEWPCafe - Online Food Ordering, Restaurant Menu, Delivery, and Reservations for WooCommerce plugin for WordPress
CVE-2024-4160 6.4 May 31, 2024, 10:15 a.m. LOGO-VULNERABLEWordPress Download Manager plugin
CVE-2024-5041 6.4 May 31, 2024, 10:15 a.m. LOGO-VULNERABLEHappy Addons for Elementor plugin for WordPress
CVE-2024-5347 6.4 May 31, 2024, 10:15 a.m. LOGO-VULNERABLEHappy Addons for Elementor plugin for WordPress
CVE-2024-31908 6.4 May 31, 2024, 1:15 p.m. LOGO-VULNERABLEIBM Planning Analytics Local
CVE-2023-7073 6.4 May 31, 2024, 3:15 p.m. LOGO-VULNERABLEAuto Featured Image (Auto Post Thumbnail) plugin for WordPress
CVE-2024-4379 5.4 May 31, 2024, 6:15 a.m. LOGO-VULNERABLEPremium Addons for Elementor plugin
CVE-2024-31889 5.4 May 31, 2024, 1:15 p.m. LOGO-VULNERABLEIBM Planning Analytics Local
CVE-2024-31907 5.4 May 31, 2024, 1:15 p.m. LOGO-VULNERABLEIBM Planning Analytics Local
CVE-2024-5524 5.3 May 31, 2024, 8:15 a.m. LOGO-VULNERABLEAstrotalks
CVE-2024-4205 4.3 May 31, 2024, 6:15 a.m. LOGO-VULNERABLEPremium Addons for Elementor plugin
CVE-2024-22338 4.0 May 31, 2024, 11:15 a.m. LOGO-VULNERABLEIBM Security Verify Access OIDC Provider
CVE-2024-35196 2.0 May 31, 2024, 6:15 p.m. LOGO-VULNERABLESentry
CVE-2024-37017 None May 31, 2024, 12:15 a.m. LOGO-VULNERABLEasdcplib (AS-DCP Lib)
CVE-2024-37018 None May 31, 2024, 1:15 a.m. LOGO-VULNERABLEOpenDaylight
CVE-2024-32850 None May 31, 2024, 2:15 a.m. LOGO-VULNERABLESkyBridge MB-A100/MB-A110 firmware
CVE-2024-37032 None May 31, 2024, 4:15 a.m. LOGO-VULNERABLEOllama
CVE-2024-23847 None May 31, 2024, 6:15 a.m. LOGO-VULNERABLEUnifier and Unifier Cast
CVE-2024-36246 None May 31, 2024, 6:15 a.m. LOGO-VULNERABLEUnifier
CVE-2024-4469 None May 31, 2024, 6:15 a.m. LOGO-VULNERABLEWP STAGING WordPress Backup Plugin
CVE-2024-5436 None May 31, 2024, 9:15 a.m. LOGO-VULNERABLESnapchat LensCore
CVE-2024-5484 None May 31, 2024, 11:15 a.m. LOGO-VULNERABLEUNKNOWN
CVE-2024-5538 None May 31, 2024, 11:15 a.m. LOGO-VULNERABLEUNKNOWN
CVE-2024-1980 None May 31, 2024, 3:15 p.m. LOGO-VULNERABLEUNKNOWN
CVE-2022-25037 None May 31, 2024, 4:15 p.m. LOGO-VULNERABLEwanEditor
CVE-2022-25038 None May 31, 2024, 4:15 p.m. LOGO-VULNERABLEwanEditor
CVE-2024-28736 None May 31, 2024, 4:15 p.m. LOGO-VULNERABLEDebezium Community debezium-ui
CVE-2021-44534 None May 31, 2024, 6:15 p.m. LOGO-VULNERABLEUNKNOWN
CVE-2024-1275 None May 31, 2024, 6:15 p.m. LOGO-VULNERABLEWelch Ally Connex Spot Monitor
CVE-2024-31030 None May 31, 2024, 6:15 p.m. LOGO-VULNERABLEFreeCoAP
CVE-2024-5144 None May 31, 2024, 6:15 p.m. LOGO-VULNERABLEUNKNOWN
CVE-2024-5176 None May 31, 2024, 6:15 p.m. LOGO-VULNERABLEWelch Allyn Configuration Tool
CVE-2024-23316 None May 31, 2024, 7:15 p.m. LOGO-VULNERABLEPing Identity PingAccess
CVE-2024-33996 None May 31, 2024, 8:15 p.m. LOGO-VULNERABLECalendar Web Service
CVE-2024-33997 None May 31, 2024, 8:15 p.m. LOGO-VULNERABLEUnknown
CVE-2024-33998 None May 31, 2024, 8:15 p.m. LOGO-VULNERABLEUNKNOWN
CVE-2024-33999 None May 31, 2024, 8:15 p.m. LOGO-VULNERABLEUNKNOWN
CVE-2024-34000 None May 31, 2024, 8:15 p.m. LOGO-VULNERABLEUNKNOWN
CVE-2024-34001 None May 31, 2024, 8:15 p.m. LOGO-VULNERABLEUnknown
CVE-2024-36843 None May 31, 2024, 8:15 p.m. LOGO-VULNERABLElibmodbus
CVE-2024-36844 None May 31, 2024, 8:15 p.m. LOGO-VULNERABLElibmodbus
CVE-2024-36845 None May 31, 2024, 8:15 p.m. LOGO-VULNERABLElibmodbus
CVE-2024-34002 None May 31, 2024, 9:15 p.m. LOGO-VULNERABLEMoodle
CVE-2024-34003 None May 31, 2024, 9:15 p.m. LOGO-VULNERABLEMoodle
CVE-2024-34004 None May 31, 2024, 9:15 p.m. LOGO-VULNERABLEMoodle
CVE-2024-34005 None May 31, 2024, 9:15 p.m. LOGO-VULNERABLEMoodle
CVE-2024-34006 None May 31, 2024, 9:15 p.m. LOGO-VULNERABLEUNKNOWN
CVE-2024-34007 None May 31, 2024, 9:15 p.m. LOGO-VULNERABLEMFA
CVE-2024-34008 None May 31, 2024, 9:15 p.m. LOGO-VULNERABLEUNKNOWN
CVE-2024-34009 None May 31, 2024, 9:15 p.m. LOGO-VULNERABLEUNKNOWN
CVE-2024-5138 None May 31, 2024, 9:15 p.m. LOGO-VULNERABLEUbuntu snapd