Tag : 2024-09-02

11 attack reports | 79 vulnerabilities

Attack Reports

Title Published Tags Description Number of indicators
Spoofed GlobalProtect Used to Deliver Unique WikiLoader Variant Sept. 2, 2024, 8:55 p.m. A variant of WikiLoader loader for rent, also known as WailingCrab, is being delivered via SEO poisoning and spoofing of GlobalPr… 46
Head Mare: adventures of a unicorn in Russia and Belarus Sept. 2, 2024, 8:52 p.m. Head Mare is a hacktivist group targeting companies in Russia and Belarus since 2023. They use phishing campaigns exploiting the … 52
Stone Wolf employs Meduza Stealer to hack Russian companies Sept. 2, 2024, 8:50 p.m. A malicious campaign by a group called Stone Wolf has been targeting Russian companies using phishing emails impersonating a legi… 41
North Korean threat actor Citrine Sleet exploiting Chromium zero-day Sept. 2, 2024, 8:46 p.m. Microsoft identified a North Korean threat actor exploiting a zero-day vulnerability in Chromium, now identified as CVE-2024-7971… 2
The Malware That Must Not Be Named: Suspected Espionage Campaign Delivers 'Voldemort' Sept. 2, 2024, 8:33 p.m. Proofpoint researchers uncovered an unusual campaign delivering custom malware named "Voldemort". The activity impersonated tax a… 27
Ransomware Roundup - Underground Sept. 2, 2024, 4:21 p.m. The Underground ransomware, first observed in July 2023, targets Windows machines by encrypting files and demanding ransom. Attri… 4
The trojan horse that wanted to fly Sept. 2, 2024, 4:18 p.m. Rocinante is a new strain of mobile malware originating from Brazil, capable of keylogging, stealing PII through phishing, and pe… 4
Exploring AsyncRAT and Infostealer Plugin Delivery Through… Sept. 2, 2024, 4:14 p.m. This analysis details an AsyncRAT infection observed in August 2024, delivered via email. The attack chain involves a Windows Scr… 8
Silent Intrusions: Godzilla Fileless Backdoors Targeting Atlassian Confluence Sept. 2, 2024, 4:06 p.m. Trend Micro researchers have identified a new attack vector exploiting CVE-2023-22527 in older versions of Atlassian Confluence D… 0
The Emerging Dynamics of Deepfake Scam Campaigns on the Web Sept. 2, 2024, 3:47 p.m. Researchers have uncovered dozens of scam campaigns utilizing deepfake videos featuring public figures like CEOs, news anchors, a… 428
Exploring Newly Released Top-Level Domains Sept. 2, 2024, 3:40 p.m. An investigation into 19 new top-level domains (TLDs) released in the past year revealed various malicious activities, including … 22

Vulnerabilities

CVE CVSS Published Product impacted Tags
CVE-2024-28100 8.9 Sept. 2, 2024, 6:15 p.m. LOGO-VULNERABLEeLabFTW
CVE-2024-41157 8.8 Sept. 2, 2024, 5:15 a.m. LOGO-VULNERABLEOpenHarmony
CVE-2024-41160 8.8 Sept. 2, 2024, 5:15 a.m. LOGO-VULNERABLEOpenHarmony
CVE-2024-7932 8.7 Sept. 2, 2024, 12:15 p.m. LOGO-VULNERABLE3DSwymer
CVE-2024-7938 8.7 Sept. 2, 2024, 12:15 p.m. LOGO-VULNERABLE3DDashboard
CVE-2024-7939 8.7 Sept. 2, 2024, 12:15 p.m. LOGO-VULNERABLE3DSwym
CVE-2024-8004 8.7 Sept. 2, 2024, 12:15 p.m. LOGO-VULNERABLEENOVIA Collaborative Industry Innovator
CVE-2024-38386 8.4 Sept. 2, 2024, 5:15 a.m. LOGO-VULNERABLEOpenHarmony
CVE-2024-39816 8.4 Sept. 2, 2024, 5:15 a.m. LOGO-VULNERABLEOpenHarmony
CVE-2024-23365 8.4 Sept. 2, 2024, 12:15 p.m. LOGO-VULNERABLEUNKNOWN
CVE-2024-33035 8.4 Sept. 2, 2024, 12:15 p.m. LOGO-VULNERABLEQualcomm Graphics Component
CVE-2024-33045 8.4 Sept. 2, 2024, 12:15 p.m. LOGO-VULNERABLEQualcomm ADSP firmware
CVE-2024-33047 8.4 Sept. 2, 2024, 12:15 p.m. LOGO-VULNERABLEUNKNOWN
CVE-2024-33060 8.4 Sept. 2, 2024, 12:15 p.m. LOGO-VULNERABLEUNKNOWN
CVE-2024-23359 8.2 Sept. 2, 2024, 12:15 p.m. LOGO-VULNERABLEQualcomm chipset
CVE-2024-33038 7.8 Sept. 2, 2024, 12:15 p.m. LOGO-VULNERABLEUNKNOWN
CVE-2024-33042 7.8 Sept. 2, 2024, 12:15 p.m. LOGO-VULNERABLEQualcomm Chipset
CVE-2024-33052 7.8 Sept. 2, 2024, 12:15 p.m. LOGO-VULNERABLEUNKNOWN
CVE-2024-33054 7.8 Sept. 2, 2024, 12:15 p.m. LOGO-VULNERABLEUNKNOWN
CVE-2024-38401 7.8 Sept. 2, 2024, 12:15 p.m. LOGO-VULNERABLEQualcomm Product
CVE-2024-38402 7.8 Sept. 2, 2024, 12:15 p.m. LOGO-VULNERABLEUNKNOWN
CVE-2024-23358 7.5 Sept. 2, 2024, 12:15 p.m. LOGO-VULNERABLEQualcomm Modem
CVE-2024-23364 7.5 Sept. 2, 2024, 12:15 p.m. LOGO-VULNERABLEQualcomm WLAN firmware
CVE-2024-33048 7.5 Sept. 2, 2024, 12:15 p.m. LOGO-VULNERABLEQualcomm WiFi driver
CVE-2024-33050 7.5 Sept. 2, 2024, 12:15 p.m. LOGO-VULNERABLEQualcomm WLAN Driver
CVE-2024-33051 7.5 Sept. 2, 2024, 12:15 p.m. LOGO-VULNERABLEQualcomm WiFi Driver
CVE-2024-33057 7.5 Sept. 2, 2024, 12:15 p.m. LOGO-VULNERABLEUNKNOWN
CVE-2024-5148 7.5 Sept. 2, 2024, 12:15 p.m. LOGO-VULNERABLEgnome-remote-desktop
CVE-2024-45311 7.5 Sept. 2, 2024, 6:15 p.m. LOGO-VULNERABLEQuinn
CVE-2024-45388 7.5 Sept. 2, 2024, 6:15 p.m. LOGO-VULNERABLEHoverfly
CVE-2024-42471 7.3 Sept. 2, 2024, 6:15 p.m. LOGO-VULNERABLEGitHub Actions Toolkit
CVE-2024-23362 7.1 Sept. 2, 2024, 12:15 p.m. LOGO-VULNERABLEUNKNOWN
CVE-2024-33016 6.8 Sept. 2, 2024, 12:15 p.m. LOGO-VULNERABLEQualcomm chipset firmware
CVE-2024-39775 6.5 Sept. 2, 2024, 5:15 a.m. LOGO-VULNERABLEOpenHarmony
CVE-2024-45308 6.5 Sept. 2, 2024, 6:15 p.m. LOGO-VULNERABLEHedgeDoc
CVE-2024-43792 6.3 Sept. 2, 2024, 6:15 p.m. LOGO-VULNERABLEHalo
CVE-2024-43797 6.3 Sept. 2, 2024, 6:15 p.m. LOGO-VULNERABLEaudiobookshelf
CVE-2024-8365 6.2 Sept. 2, 2024, 5:15 a.m. LOGO-VULNERABLEVault Community Edition
CVE-2024-38382 5.5 Sept. 2, 2024, 5:15 a.m. LOGO-VULNERABLEOpenHarmony
CVE-2024-39612 5.5 Sept. 2, 2024, 5:15 a.m. LOGO-VULNERABLEOpenHarmony
CVE-2024-33043 5.5 Sept. 2, 2024, 12:15 p.m. LOGO-VULNERABLEUNKNOWN
CVE-2024-45313 5.4 Sept. 2, 2024, 6:15 p.m. LOGO-VULNERABLEOverleaf Server Pro
CVE-2024-45312 5.3 Sept. 2, 2024, 6:15 p.m. LOGO-VULNERABLEOverleaf Community Edition
CVE-2024-43801 4.6 Sept. 2, 2024, 6:15 p.m. LOGO-VULNERABLEJellyfin
CVE-2024-45306 4.5 Sept. 2, 2024, 6:15 p.m. LOGO-VULNERABLEVim
CVE-2020-36830 4.3 Sept. 2, 2024, 6:15 p.m. LOGO-VULNERABLEnescalance urlregex
CVE-2024-28044 3.3 Sept. 2, 2024, 5:15 a.m. LOGO-VULNERABLEOpenHarmony
CVE-2023-7279 2.6 Sept. 2, 2024, 6:15 p.m. LOGO-VULNERABLESecure Systems Engineering Connaisseur
CVE-2024-45305 2.5 Sept. 2, 2024, 6:15 p.m. LOGO-VULNERABLEgix-path
CVE-2024-45269 None Sept. 2, 2024, 12:15 a.m. LOGO-VULNERABLEWordPress plugin Carousel Slider
CVE-2024-45270 None Sept. 2, 2024, 12:15 a.m. LOGO-VULNERABLEWordPress Carousel Slider plugin
CVE-2024-45522 None Sept. 2, 2024, 12:15 a.m. LOGO-VULNERABLEUNKNOWN
CVE-2024-20084 None Sept. 2, 2024, 5:15 a.m. LOGO-VULNERABLEUNKNOWN
CVE-2024-20085 None Sept. 2, 2024, 5:15 a.m. LOGO-VULNERABLEUNKNOWN
CVE-2024-20086 None Sept. 2, 2024, 5:15 a.m. LOGO-VULNERABLEUNKNOWN
CVE-2024-20087 None Sept. 2, 2024, 5:15 a.m. LOGO-VULNERABLEUNKNOWN
CVE-2024-20088 None Sept. 2, 2024, 5:15 a.m. LOGO-VULNERABLEUNKNOWN
CVE-2024-20089 None Sept. 2, 2024, 5:15 a.m. LOGO-VULNERABLEMediaTek WLAN driver
CVE-2024-43772 None Sept. 2, 2024, 5:15 a.m. LOGO-VULNERABLEEasytest Online Test Platform
CVE-2024-43773 None Sept. 2, 2024, 5:15 a.m. LOGO-VULNERABLEEasytest Online Test Platform
CVE-2024-43774 None Sept. 2, 2024, 5:15 a.m. LOGO-VULNERABLEEasytest Online Test Platform
CVE-2024-43775 None Sept. 2, 2024, 5:15 a.m. LOGO-VULNERABLEEasytest Online Test Platform
CVE-2024-43776 None Sept. 2, 2024, 5:15 a.m. LOGO-VULNERABLEEasytest Online Test Platform
CVE-2024-45527 None Sept. 2, 2024, 5:15 a.m. LOGO-VULNERABLEREDCap
CVE-2024-45528 None Sept. 2, 2024, 5:15 a.m. LOGO-VULNERABLECodeAstro MembershipM-PHP
CVE-2024-7871 None Sept. 2, 2024, 5:15 a.m. LOGO-VULNERABLEEasytest Online Test Platform
CVE-2024-7354 None Sept. 2, 2024, 8:15 a.m. LOGO-VULNERABLENinja Forms WordPress plugin
CVE-2024-7690 None Sept. 2, 2024, 8:15 a.m. LOGO-VULNERABLEDN Popup WordPress plugin
CVE-2024-7691 None Sept. 2, 2024, 8:15 a.m. LOGO-VULNERABLEFlaming Forms WordPress plugin
CVE-2024-7692 None Sept. 2, 2024, 8:15 a.m. LOGO-VULNERABLEFlaming Forms WordPress plugin
CVE-2024-38858 None Sept. 2, 2024, 12:15 p.m. LOGO-VULNERABLECheckmk
CVE-2024-44947 None Sept. 2, 2024, 6:15 p.m. LOGO-VULNERABLELinux kernel
CVE-2024-6919 None Sept. 2, 2024, 6:15 p.m. LOGO-VULNERABLENAC Telecommunication Systems Inc. NACPremium
CVE-2024-6920 None Sept. 2, 2024, 6:15 p.m. LOGO-VULNERABLENAC Telecommunication Systems Inc. NACPremium
CVE-2024-6921 None Sept. 2, 2024, 6:15 p.m. LOGO-VULNERABLENACPremium
CVE-2024-45621 None Sept. 2, 2024, 7:15 p.m. LOGO-VULNERABLERocket.Chat Electron desktop application
CVE-2024-45622 None Sept. 2, 2024, 7:15 p.m. LOGO-VULNERABLECodeIgniter
CVE-2024-1621 None Sept. 2, 2024, 8:15 p.m. LOGO-VULNERABLEuniFLOW Online
CVE-2024-45623 None Sept. 2, 2024, 9:15 p.m. LOGO-VULNERABLED-Link DAP-2310 Hardware A Firmware