Tag : 2024-06-28

5 attack reports | 74 vulnerabilities

Attack Reports

Title Published Tags Description Number of indicators
Supposed Grasshopper: operators impersonate Israeli government and private companies to deploy open-source malware June 28, 2024, 2:58 p.m. A long-running campaign was identified involving malicious actors impersonating Israeli entities and private companies. The opera… 18
An Android RAT targets Telegram Users June 28, 2024, 2:49 p.m. This analysis discusses SpyMax, a Remote Access Trojan (RAT) that targets Android devices and specifically aims at obtaining data… 4
Kimsuky Deploys TRANSLATEXT Chrome Extension June 28, 2024, 7:46 a.m. In March 2024, the cybersecurity firm Zscaler observed a new activity from Kimsuky, a North Korean state-sponsored hacker group. … 10
Examining Water Infection Routine Leading to an XMRig Cryptominer June 28, 2024, 7:39 a.m. This report details the multi-stage loading technique utilized by the threat actor Water Sigbin to deliver the PureCrypter loader… 13
We're not talking about cryptocurrency as much as we used to, but there are still plenty of scammers out there June 28, 2024, 7:35 a.m. While cryptocurrency and blockchain have lost mainstream attention, cybercriminals continue to exploit these technologies through… 4

Vulnerabilities

CVE CVSS Published Product impacted Tags
CVE-2024-39349 9.8 June 28, 2024, 6:15 a.m. LOGO-VULNERABLESynology Camera Firmware
CVE-2024-5827 9.8 June 28, 2024, 8:15 p.m. LOGO-VULNERABLEVanna
CVE-2024-29039 9.0 June 28, 2024, 4:15 p.m. LOGO-VULNERABLEtpm2
CVE-2024-38521 8.8 June 28, 2024, 4:15 p.m. LOGO-VULNERABLEHush Line
CVE-2024-37905 8.8 June 28, 2024, 6:15 p.m. LOGO-VULNERABLEauthentik
CVE-2024-38371 8.6 June 28, 2024, 6:15 p.m. LOGO-VULNERABLEauthentik
CVE-2024-37282 8.1 June 28, 2024, 5:15 a.m. LOGO-VULNERABLEElasticsearch
CVE-2024-5712 8.1 June 28, 2024, 8:15 p.m. LOGO-VULNERABLEstitionai/devika
CVE-2024-39348 7.5 June 28, 2024, 7:15 a.m. LOGO-VULNERABLESynology Router Manager (SRM)
CVE-2024-39350 7.5 June 28, 2024, 7:15 a.m. LOGO-VULNERABLESynology Camera Firmware
CVE-2024-31912 7.5 June 28, 2024, 6:15 p.m. LOGO-VULNERABLEIBM MQ
CVE-2024-38374 7.5 June 28, 2024, 6:15 p.m. LOGO-VULNERABLEcyclonedx-core-java
CVE-2024-38528 7.5 June 28, 2024, 8:15 p.m. LOGO-VULNERABLEnptd-rs
CVE-2024-38514 7.4 June 28, 2024, 7:15 p.m. LOGO-VULNERABLENextChat
CVE-2023-47802 7.2 June 28, 2024, 6:15 a.m. LOGO-VULNERABLESynology Camera Firmware
CVE-2024-39351 7.2 June 28, 2024, 6:15 a.m. LOGO-VULNERABLESynology Camera Firmware
CVE-2024-39708 7.0 June 28, 2024, 1:15 a.m. LOGO-VULNERABLEDelinea Privilege Manager (formerly Thycotic Privilege Manager)
CVE-2024-6402 6.5 June 28, 2024, 5:15 p.m. LOGO-VULNERABLETenda A301
CVE-2024-6403 6.5 June 28, 2024, 5:15 p.m. LOGO-VULNERABLETenda A301
CVE-2024-35155 6.5 June 28, 2024, 6:15 p.m. LOGO-VULNERABLEIBM MQ Console
CVE-2024-25031 6.5 June 28, 2024, 7:15 p.m. LOGO-VULNERABLEIBM Storage Defender - Resiliency Service
CVE-2024-35156 6.5 June 28, 2024, 7:15 p.m. LOGO-VULNERABLEIBM MQ
CVE-2024-6296 6.4 June 28, 2024, 4:15 a.m. LOGO-VULNERABLEStackable - Page Builder Gutenberg Blocks plugin for WordPress
CVE-2024-5788 6.4 June 28, 2024, 7:15 a.m. LOGO-VULNERABLEWordPress Silesia theme
CVE-2024-5796 6.4 June 28, 2024, 7:15 a.m. LOGO-VULNERABLEWordPress Infinite theme
CVE-2024-5424 6.4 June 28, 2024, 9:15 a.m. LOGO-VULNERABLEWordPress Gallery Blocks with Lightbox Plugin
CVE-2024-5662 6.4 June 28, 2024, 9:15 a.m. LOGO-VULNERABLEThe Ultimate Post Kit Addons For Elementor plugin for WordPress
CVE-2024-5922 6.4 June 28, 2024, 9:15 a.m. LOGO-VULNERABLEWordPress Scylla Lite Theme
CVE-2024-5925 6.4 June 28, 2024, 9:15 a.m. LOGO-VULNERABLEWordPress Theron Lite theme
CVE-2024-38522 6.3 June 28, 2024, 5:15 p.m. LOGO-VULNERABLEHush Line
CVE-2024-35137 6.2 June 28, 2024, 4:15 p.m. LOGO-VULNERABLEIBM Security Access Manager Docker
CVE-2024-35139 6.2 June 28, 2024, 4:15 p.m. LOGO-VULNERABLEIBM Security Access Manager Docker
CVE-2024-39347 5.9 June 28, 2024, 7:15 a.m. LOGO-VULNERABLESynology Router Manager (SRM)
CVE-2024-31919 5.9 June 28, 2024, 6:15 p.m. LOGO-VULNERABLEIBM MQ
CVE-2024-25053 5.9 June 28, 2024, 7:15 p.m. LOGO-VULNERABLEIBM Cognos Analytics
CVE-2024-35116 5.9 June 28, 2024, 7:15 p.m. LOGO-VULNERABLEIBM MQ
CVE-2024-5863 5.4 June 28, 2024, 4:15 a.m. LOGO-VULNERABLEEasy Image Collage plugin for WordPress
CVE-2024-25041 5.4 June 28, 2024, 7:15 p.m. LOGO-VULNERABLEIBM Cognos Analytics
CVE-2023-47803 5.3 June 28, 2024, 6:15 a.m. LOGO-VULNERABLESynology Camera Firmware
CVE-2024-2795 5.3 June 28, 2024, 7:15 a.m. LOGO-VULNERABLESEO SIMPLE PACK plugin for WordPress
CVE-2024-38322 5.3 June 28, 2024, 7:15 p.m. LOGO-VULNERABLEIBM Storage Defender - Resiliency Service
CVE-2024-39352 4.9 June 28, 2024, 6:15 a.m. LOGO-VULNERABLESynology Camera Firmware
CVE-2024-6288 4.7 June 28, 2024, 7:15 a.m. LOGO-VULNERABLEConversios - Google Analytics 4 (GA4), Meta Pixel & more Via Google Tag Manager For WooCommerce plugin for WordPress
CVE-2024-38518 4.6 June 28, 2024, 9:15 p.m. LOGO-VULNERABLEBigBlueButton
CVE-2024-5864 4.3 June 28, 2024, 4:15 a.m. LOGO-VULNERABLEEasy Affiliate Links plugin for WordPress
CVE-2024-29038 4.3 June 28, 2024, 2:15 p.m. LOGO-VULNERABLEtpm2-tools
CVE-2024-29040 4.3 June 28, 2024, 9:15 p.m. LOGO-VULNERABLETrusted Computing Group's (TCG) TPM2 Software Stack (TSS)
CVE-2022-38383 4.0 June 28, 2024, 7:15 p.m. LOGO-VULNERABLEIBM Cloud Pak for Security (CP4S)
CVE-2024-37137 3.8 June 28, 2024, 2:15 a.m. LOGO-VULNERABLEDell Key Trust Platform
CVE-2024-30109 3.7 June 28, 2024, 6:15 a.m. LOGO-VULNERABLEHCL DRYiCE AEX
CVE-2024-30110 3.7 June 28, 2024, 7:15 a.m. LOGO-VULNERABLEHCL DRYiCE AEX
CVE-2024-39302 3.7 June 28, 2024, 9:15 p.m. LOGO-VULNERABLEBigBlueButton
CVE-2024-38531 3.6 June 28, 2024, 2:15 p.m. LOGO-VULNERABLENix package manager
CVE-2024-39307 3.5 June 28, 2024, 9:15 p.m. LOGO-VULNERABLEKavita
CVE-2024-30111 3.3 June 28, 2024, 7:15 a.m. LOGO-VULNERABLEHCL DRYiCE AEX
CVE-2024-30135 3.3 June 28, 2024, 8:15 a.m. LOGO-VULNERABLEUNKNOWN
CVE-2024-5570 None June 28, 2024, 6:15 a.m. LOGO-VULNERABLESimple Photoswipe WordPress plugin
CVE-2024-5727 None June 28, 2024, 6:15 a.m. LOGO-VULNERABLEWidget4Call WordPress plugin
CVE-2024-5728 None June 28, 2024, 6:15 a.m. LOGO-VULNERABLEAnimated AL List WordPress plugin
CVE-2024-5729 None June 28, 2024, 6:15 a.m. LOGO-VULNERABLESimple AL Slider WordPress plugin
CVE-2024-5730 None June 28, 2024, 6:15 a.m. LOGO-VULNERABLEPagerank tools WordPress plugin
CVE-2024-5735 None June 28, 2024, 12:15 p.m. LOGO-VULNERABLEAdmirorFrames Joomla! extension
CVE-2024-5736 None June 28, 2024, 12:15 p.m. LOGO-VULNERABLEJoomla! AdmirorFrames extension
CVE-2024-5737 None June 28, 2024, 12:15 p.m. LOGO-VULNERABLEAdmirorFrames Joomla! extension
CVE-2024-37741 None June 28, 2024, 1:15 p.m. LOGO-VULNERABLEOpenPLC
CVE-2024-39704 None June 28, 2024, 1:15 p.m. LOGO-VULNERABLESoft Circle French-Bread Melty Blood: Actress Again: Current Code
CVE-2024-3800 None June 28, 2024, 1:15 p.m. LOGO-VULNERABLES@M CMS (Concept Intermedia)
CVE-2024-3801 None June 28, 2024, 1:15 p.m. LOGO-VULNERABLES@M CMS (Concept Intermedia)
CVE-2024-3816 None June 28, 2024, 1:15 p.m. LOGO-VULNERABLES@M CMS (Concept Intermedia)
CVE-2022-27540 None June 28, 2024, 7:15 p.m. LOGO-VULNERABLEHP BIOS
CVE-2024-27628 None June 28, 2024, 7:15 p.m. LOGO-VULNERABLEDCMTK
CVE-2024-27629 None June 28, 2024, 7:15 p.m. LOGO-VULNERABLEdc2niix
CVE-2024-5972 None June 28, 2024, 7:15 p.m. LOGO-VULNERABLEUNKNOWN
CVE-2024-3995 None June 28, 2024, 8:15 p.m. LOGO-VULNERABLEHelix ALM