Tag : 2024-10-03

4 attack reports | 52 vulnerabilities

Attack Reports

Title Published Tags Description Number of indicators
Stonefly: Extortion Attacks Continue Against U.S. Targets Oct. 3, 2024, 5:08 p.m. In several of the attacks, Stonefly’s custom malware Backdoor.Preft (aka Dtrack, Valefor) was deployed. This tool is exclusively … 50
XWorm: Analysis of Latest Version and Execution Flow Oct. 3, 2024, 3:16 p.m. XWorm, a versatile tool discovered in 2022, enables attackers to access sensitive information, gain remote access, and deploy add… 8
The Dark Knight Returns: Joker malware analysis Oct. 3, 2024, 2:43 p.m. The report details sophisticated command and control (C2) techniques employed by the APT41 threat group. APT41 uses custom malwar… 8
Separating the bee from the panda: CeranaKeeper making a beeline for Thailand Oct. 3, 2024, 9:50 a.m. This intelligence report details a sophisticated malware campaign targeting multiple industries across various countries. The thr… 16

Vulnerabilities

CVE CVSS Published Product impacted Tags
CVE-2024-9313 8.8 Oct. 3, 2024, 11:15 a.m. LOGO-VULNERABLEAuthd PAM module
CVE-2024-41589 8.8 Oct. 3, 2024, 7:15 p.m. LOGO-VULNERABLEDrayTek Vigor310
CVE-2024-36474 8.4 Oct. 3, 2024, 4:15 p.m. LOGO-VULNERABLEGNOME Project G Structured File Library (libgsf)
CVE-2024-42415 8.4 Oct. 3, 2024, 4:15 p.m. LOGO-VULNERABLEGNOME Structured File Library (libgsf)
CVE-2024-41586 8.0 Oct. 3, 2024, 7:15 p.m. LOGO-VULNERABLEDrayTek Vigor310
CVE-2024-41592 8.0 Oct. 3, 2024, 7:15 p.m. LOGO-VULNERABLEDrayTek Vigor3910
CVE-2024-41595 8.0 Oct. 3, 2024, 7:15 p.m. LOGO-VULNERABLEDrayTek Vigor310
CVE-2024-41596 8.0 Oct. 3, 2024, 7:15 p.m. LOGO-VULNERABLEDrayTek Vigor310
CVE-2024-47134 7.8 Oct. 3, 2024, 3:15 a.m. LOGO-VULNERABLEKostac PLC Programming Software (Formerly Koyo PLC Programming Software)
CVE-2024-47135 7.8 Oct. 3, 2024, 3:15 a.m. LOGO-VULNERABLEKostac PLC Programming Software (Formerly Koyo PLC Programming Software)
CVE-2024-47136 7.8 Oct. 3, 2024, 3:15 a.m. LOGO-VULNERABLEKostac PLC Programming Software (Former name: Koyo PLC Programming Software)
CVE-2024-39755 7.8 Oct. 3, 2024, 4:15 p.m. LOGO-VULNERABLEVeertu Anka Build
CVE-2024-8352 7.5 Oct. 3, 2024, 4:15 a.m. LOGO-VULNERABLESocial Web Suite - Social Media Auto Post, Social Media Auto Publish plugin for WordPress
CVE-2024-47614 7.5 Oct. 3, 2024, 3:15 p.m. LOGO-VULNERABLEasync-graphql
CVE-2024-5803 7.5 Oct. 3, 2024, 3:15 p.m. LOGO-VULNERABLEAVG/Avast Antivirus
CVE-2024-25590 7.5 Oct. 3, 2024, 4:15 p.m. LOGO-VULNERABLEUNKNOWN
CVE-2024-41163 7.5 Oct. 3, 2024, 4:15 p.m. LOGO-VULNERABLEVeertu Anka
CVE-2024-41922 7.5 Oct. 3, 2024, 4:15 p.m. LOGO-VULNERABLEVeertu Anka
CVE-2024-47561 7.3 Oct. 3, 2024, 11:15 a.m. LOGO-VULNERABLEApache Avro
CVE-2024-9460 7.3 Oct. 3, 2024, 3:15 p.m. LOGO-VULNERABLECodezips Online Shopping Portal
CVE-2024-9100 6.5 Oct. 3, 2024, 3:15 p.m. LOGO-VULNERABLEZohocorp ManageEngine Analytics Plus
CVE-2024-45870 6.5 Oct. 3, 2024, 4:15 p.m. LOGO-VULNERABLEBandisoft BandiView
CVE-2024-8159 6.4 Oct. 3, 2024, 6:15 a.m. LOGO-VULNERABLEDeep Freeze
CVE-2024-45871 6.3 Oct. 3, 2024, 5:15 p.m. LOGO-VULNERABLEBandisoft BandiView
CVE-2024-45872 6.3 Oct. 3, 2024, 5:15 p.m. LOGO-VULNERABLEBandisoft BandiView
CVE-2024-47617 6.1 Oct. 3, 2024, 3:15 p.m. LOGO-VULNERABLESulu CMS
CVE-2024-47762 5.8 Oct. 3, 2024, 6:15 p.m. LOGO-VULNERABLE@backstage/plugin-app-backend
CVE-2024-8508 5.3 Oct. 3, 2024, 5:15 p.m. LOGO-VULNERABLENLnet Labs Unbound
CVE-2024-41583 4.7 Oct. 3, 2024, 7:15 p.m. LOGO-VULNERABLEDrayTek Vigor3910
CVE-2024-41584 4.7 Oct. 3, 2024, 7:15 p.m. LOGO-VULNERABLEDrayTek Vigor3910
CVE-2024-9266 4.7 Oct. 3, 2024, 7:15 p.m. LOGO-VULNERABLEExpress
CVE-2024-42504 4.3 Oct. 3, 2024, 7:15 a.m. LOGO-VULNERABLEHPE IceWall Agent
CVE-2024-0123 3.3 Oct. 3, 2024, 5:15 p.m. LOGO-VULNERABLENVIDIA CUDA toolkit
CVE-2024-0124 3.3 Oct. 3, 2024, 5:15 p.m. LOGO-VULNERABLENVIDIA CUDA Toolkit
CVE-2024-0125 3.3 Oct. 3, 2024, 5:15 p.m. LOGO-VULNERABLENVIDIA CUDA Toolkit
CVE-2024-47554 None Oct. 3, 2024, 12:15 p.m. LOGO-VULNERABLEApache Commons IO
CVE-2024-47618 None Oct. 3, 2024, 3:15 p.m. LOGO-VULNERABLESulu
CVE-2024-7824 None Oct. 3, 2024, 5:15 p.m. LOGO-VULNERABLEWebroot SecureAnywhere - Web Shield
CVE-2024-7825 None Oct. 3, 2024, 5:15 p.m. LOGO-VULNERABLEWebroot SecureAnywhere - Web Shield
CVE-2024-7826 None Oct. 3, 2024, 5:15 p.m. LOGO-VULNERABLEWebroot SecureAnywhere - Web Shield
CVE-2023-37822 None Oct. 3, 2024, 6:15 p.m. LOGO-VULNERABLEEufy HomeBase 2 model T8010X
CVE-2024-34535 None Oct. 3, 2024, 6:15 p.m. LOGO-VULNERABLEMastodon
CVE-2024-41987 None Oct. 3, 2024, 6:15 p.m. LOGO-VULNERABLETEM Opera Plus FM Family Transmitter
CVE-2024-41988 None Oct. 3, 2024, 6:15 p.m. LOGO-VULNERABLETEM Opera Plus FM Family Transmitter
CVE-2024-41585 None Oct. 3, 2024, 7:15 p.m. LOGO-VULNERABLEDrayTek Vigor3910
CVE-2024-41587 None Oct. 3, 2024, 7:15 p.m. LOGO-VULNERABLEDrayTek Vigor310
CVE-2024-41588 None Oct. 3, 2024, 7:15 p.m. LOGO-VULNERABLEDrayTek Vigor3910
CVE-2024-41590 None Oct. 3, 2024, 7:15 p.m. LOGO-VULNERABLEDrayTek Vigor310
CVE-2024-41591 None Oct. 3, 2024, 7:15 p.m. LOGO-VULNERABLEDrayTek Vigor3910 devices
CVE-2024-41593 None Oct. 3, 2024, 7:15 p.m. LOGO-VULNERABLEDrayTek Vigor310
CVE-2024-41594 None Oct. 3, 2024, 7:15 p.m. LOGO-VULNERABLEDrayTek Vigor310
CVE-2024-46658 None Oct. 3, 2024, 9:15 p.m. LOGO-VULNERABLESyrotech SY-GOPON-8OLT-L3