Tag : 2024-10-04

7 attack reports | 90 vulnerabilities

Attack Reports

Title Published Tags Description Number of indicators
Pig Butchering Alert: Fraudulent Trading App targeted iOS and Android users Oct. 4, 2024, 10:27 a.m. A large-scale fraud campaign involving fake trading apps targeting Apple iOS and Android users across multiple regions has been u… 9
Tweaking AsyncRAT: Using Python and TryCloudflare to Deploy Malware Oct. 4, 2024, 10:23 a.m. A new AsyncRAT malware campaign utilizes TryCloudflare quick tunnels and Python packages to deliver malicious payloads. The attac… 15
CHARMING KITTEN Oct. 4, 2024, 10:16 a.m. Since June 2024, the Iran-nexus actor CHARMING KITTEN has been creating new network infrastructure for credential phishing, targe… 11
Bulbature, beneath the waves of GobRAT Oct. 4, 2024, 10:11 a.m. This report examines an infrastructure used to control compromised edge devices transformed into Operational Relay Boxes for laun… 120
perfctl: A Stealthy Malware Targeting Millions of Linux Servers Oct. 4, 2024, 10:08 a.m. A sophisticated Linux malware named 'perfctl' has been actively targeting millions of servers worldwide for the past 3-4 years. I… 9
Threat actor believed to be spreading new MedusaLocker variant since 2022 Oct. 4, 2024, 10:06 a.m. A financially motivated threat actor has been active since 2022, delivering a MedusaLocker ransomware variant called 'BabyLockerK… 11
Threat Brief: Understanding Akira Ransomware Oct. 4, 2024, 10:04 a.m. Akira is a prolific ransomware operating since March 2023, targeting multiple industries in North America, the UK, and Australia.… 3

Vulnerabilities

CVE CVSS Published Product impacted Tags
CVE-2024-9514 8.8 Oct. 4, 2024, 2:15 p.m. LOGO-VULNERABLED-Link DIR-605L
CVE-2024-9515 8.8 Oct. 4, 2024, 2:15 p.m. LOGO-VULNERABLED-Link DIR-605L
CVE-2024-47183 8.1 Oct. 4, 2024, 3:15 p.m. LOGO-VULNERABLEParse Server
CVE-2024-47850 7.5 Oct. 4, 2024, 5:15 a.m. LOGO-VULNERABLECUPS cups-browsed
CVE-2024-47769 7.5 Oct. 4, 2024, 3:15 p.m. LOGO-VULNERABLEIDURAR
CVE-2024-38040 7.5 Oct. 4, 2024, 6:15 p.m. LOGO-VULNERABLEEsri Portal for ArcGIS
CVE-2024-47911 6.7 Oct. 4, 2024, 9:15 p.m. LOGO-VULNERABLESonarSource SonarQube
CVE-2024-8519 6.4 Oct. 4, 2024, 5:15 a.m. LOGO-VULNERABLEUltimate Member Plugin for WordPress
CVE-2024-9368 6.4 Oct. 4, 2024, 5:15 a.m. LOGO-VULNERABLEAggregator Advanced Settings plugin for WordPress
CVE-2024-9372 6.4 Oct. 4, 2024, 5:15 a.m. LOGO-VULNERABLEWP Blocks Hub plugin for WordPress
CVE-2024-9421 6.4 Oct. 4, 2024, 5:15 a.m. LOGO-VULNERABLELogin Logout Shortcode plugin for WordPress
CVE-2024-9445 6.4 Oct. 4, 2024, 5:15 a.m. LOGO-VULNERABLEDisplay Medium Posts plugin for WordPress
CVE-2024-8804 6.4 Oct. 4, 2024, 6:15 a.m. LOGO-VULNERABLECode Embed plugin for WordPress
CVE-2024-9242 6.4 Oct. 4, 2024, 6:15 a.m. LOGO-VULNERABLEMemberful – Membership Plugin plugin for WordPress
CVE-2024-9071 6.4 Oct. 4, 2024, 10:15 a.m. LOGO-VULNERABLEWordPress Easy Demo Importer plugin
CVE-2024-9271 6.4 Oct. 4, 2024, 10:15 a.m. LOGO-VULNERABLERe:WP plugin for WordPress
CVE-2024-6442 6.3 Oct. 4, 2024, 6:15 a.m. LOGO-VULNERABLEUNKNOWN
CVE-2024-6443 6.3 Oct. 4, 2024, 6:15 a.m. LOGO-VULNERABLEZephyr Project
CVE-2024-6444 6.3 Oct. 4, 2024, 7:15 a.m. LOGO-VULNERABLEZephyr Project
CVE-2024-8802 6.1 Oct. 4, 2024, 5:15 a.m. LOGO-VULNERABLEClio Grow plugin for WordPress
CVE-2024-9204 6.1 Oct. 4, 2024, 5:15 a.m. LOGO-VULNERABLESmart Custom 404 Error Page plugin for WordPress
CVE-2024-9237 6.1 Oct. 4, 2024, 5:15 a.m. LOGO-VULNERABLEWooCommerce Fish and Ships Shipping Rate Plugin
CVE-2024-9345 6.1 Oct. 4, 2024, 5:15 a.m. LOGO-VULNERABLEWooCommerce - Lite plugin for WordPress
CVE-2024-9349 6.1 Oct. 4, 2024, 5:15 a.m. LOGO-VULNERABLEAuto Amazon Links – Amazon Associates Affiliate Plugin plugin for WordPress
CVE-2024-9353 6.1 Oct. 4, 2024, 5:15 a.m. LOGO-VULNERABLEPopularis Extra plugin for WordPress
CVE-2024-9375 6.1 Oct. 4, 2024, 5:15 a.m. LOGO-VULNERABLEWordPress Captcha Plugin by Captcha Bank
CVE-2024-9384 6.1 Oct. 4, 2024, 5:15 a.m. LOGO-VULNERABLEQuantity Dynamic Pricing & Bulk Discounts for WooCommerce plugin for WordPress
CVE-2024-47854 6.1 Oct. 4, 2024, 6:15 a.m. LOGO-VULNERABLEVeritas Data Insight
CVE-2024-9435 6.1 Oct. 4, 2024, 7:15 a.m. LOGO-VULNERABLEShiftController Employee Shift Scheduling plugin for WordPress
CVE-2024-25691 6.1 Oct. 4, 2024, 6:15 p.m. LOGO-VULNERABLEEsri Portal for ArcGIS
CVE-2024-38037 6.1 Oct. 4, 2024, 6:15 p.m. LOGO-VULNERABLEEsri Portal for ArcGIS
CVE-2024-38038 6.1 Oct. 4, 2024, 6:15 p.m. LOGO-VULNERABLEEsri Portal for ArcGIS
CVE-2024-8148 6.1 Oct. 4, 2024, 6:15 p.m. LOGO-VULNERABLEEsri Portal for ArcGIS
CVE-2024-44204 5.5 Oct. 4, 2024, 12:15 a.m. LOGO-VULNERABLEiOS
CVE-2024-38039 5.4 Oct. 4, 2024, 6:15 p.m. LOGO-VULNERABLEEsri Portal for ArcGIS
CVE-2024-8520 5.3 Oct. 4, 2024, 5:15 a.m. LOGO-VULNERABLEUltimate Member Plugin
CVE-2024-9410 5.3 Oct. 4, 2024, 2:15 p.m. LOGO-VULNERABLEUNKNOWN
CVE-2024-9481 5.1 Oct. 4, 2024, 1:15 p.m. LOGO-VULNERABLEAVG/Avast Antivirus
CVE-2024-9482 5.1 Oct. 4, 2024, 1:15 p.m. LOGO-VULNERABLEAvast Antivirus
CVE-2024-9483 5.1 Oct. 4, 2024, 1:15 p.m. LOGO-VULNERABLEAVG/Avast Antivirus
CVE-2024-9484 5.1 Oct. 4, 2024, 1:15 p.m. LOGO-VULNERABLEAVG/Avast Antivirus
CVE-2024-25694 4.8 Oct. 4, 2024, 6:15 p.m. LOGO-VULNERABLEEsri Portal for ArcGIS Enterprise
CVE-2024-25701 4.8 Oct. 4, 2024, 6:15 p.m. LOGO-VULNERABLEEsri Portal for ArcGIS Enterprise Experience Builder
CVE-2024-25702 4.8 Oct. 4, 2024, 6:15 p.m. LOGO-VULNERABLEEsri Portal for ArcGIS Enterprise Sites
CVE-2024-25707 4.8 Oct. 4, 2024, 6:15 p.m. LOGO-VULNERABLEEsri Portal for ArcGIS
CVE-2024-8499 4.7 Oct. 4, 2024, 1:15 p.m. LOGO-VULNERABLECheckout Field Editor (Checkout Manager) for WooCommerce plugin
CVE-2024-38036 4.6 Oct. 4, 2024, 6:15 p.m. LOGO-VULNERABLEEsri Portal for ArcGIS
CVE-2024-8149 4.6 Oct. 4, 2024, 6:15 p.m. LOGO-VULNERABLEEsri Portal for ArcGIS
CVE-2024-9306 4.4 Oct. 4, 2024, 7:15 a.m. LOGO-VULNERABLEWP Booking Calendar plugin for WordPress
CVE-2024-44207 4.3 Oct. 4, 2024, 12:15 a.m. LOGO-VULNERABLEiOS
CVE-2024-9513 3.7 Oct. 4, 2024, 1:15 p.m. LOGO-VULNERABLENetAdmin IAM
CVE-2024-47855 None Oct. 4, 2024, 6:15 a.m. LOGO-VULNERABLEJSON-lib
CVE-2024-47651 None Oct. 4, 2024, 12:15 p.m. LOGO-VULNERABLEShilpi Client Dashboard
CVE-2024-6400 None Oct. 4, 2024, 12:15 p.m. LOGO-VULNERABLEFinrota Netahsilat
CVE-2024-47652 None Oct. 4, 2024, 1:15 p.m. LOGO-VULNERABLEShilpi Client Dashboard
CVE-2024-47653 None Oct. 4, 2024, 1:15 p.m. LOGO-VULNERABLEShilpi Client Dashboard
CVE-2024-47654 None Oct. 4, 2024, 1:15 p.m. LOGO-VULNERABLEShilpi Client Dashboard
CVE-2024-47655 None Oct. 4, 2024, 1:15 p.m. LOGO-VULNERABLEShilpi Client Dashboard
CVE-2024-47656 None Oct. 4, 2024, 1:15 p.m. LOGO-VULNERABLEShilpi Client Dashboard
CVE-2024-47657 None Oct. 4, 2024, 1:15 p.m. LOGO-VULNERABLEShilpi Net Back Office
CVE-2024-47789 None Oct. 4, 2024, 1:15 p.m. LOGO-VULNERABLED3D Security IP Camera
CVE-2024-47790 None Oct. 4, 2024, 1:15 p.m. LOGO-VULNERABLED3D Security IP Camera
CVE-2024-47765 None Oct. 4, 2024, 3:15 p.m. LOGO-VULNERABLEMinecraft MOTD Parser
CVE-2024-47768 None Oct. 4, 2024, 3:15 p.m. LOGO-VULNERABLELif Authentication Server
CVE-2024-46409 None Oct. 4, 2024, 5:15 p.m. LOGO-VULNERABLESeedDMS
CVE-2024-46486 None Oct. 4, 2024, 5:15 p.m. LOGO-VULNERABLETP-LINK TL-WDR5620
CVE-2024-41511 None Oct. 4, 2024, 6:15 p.m. LOGO-VULNERABLECADClick
CVE-2024-41512 None Oct. 4, 2024, 6:15 p.m. LOGO-VULNERABLECADClick
CVE-2024-41513 None Oct. 4, 2024, 6:15 p.m. LOGO-VULNERABLECADClick
CVE-2024-41514 None Oct. 4, 2024, 6:15 p.m. LOGO-VULNERABLECADClick
CVE-2024-41515 None Oct. 4, 2024, 6:15 p.m. LOGO-VULNERABLECADClick
CVE-2024-41516 None Oct. 4, 2024, 6:15 p.m. LOGO-VULNERABLECADClick
CVE-2024-44439 None Oct. 4, 2024, 6:15 p.m. LOGO-VULNERABLEShanghai Zhouma Network Technology CO., Ltd IMS Intelligent Manufacturing Collaborative Internet of Things System
CVE-2024-47211 None Oct. 4, 2024, 6:15 p.m. LOGO-VULNERABLEOpenStack Ironic
CVE-2023-26770 None Oct. 4, 2024, 7:15 p.m. LOGO-VULNERABLETaskCafe
CVE-2023-26771 None Oct. 4, 2024, 7:15 p.m. LOGO-VULNERABLETaskcafe
CVE-2024-46077 None Oct. 4, 2024, 7:15 p.m. LOGO-VULNERABLEOnline Tours and Travels Management System
CVE-2024-46078 None Oct. 4, 2024, 7:15 p.m. LOGO-VULNERABLEitsourcecode Sports Management System Project
CVE-2024-43683 None Oct. 4, 2024, 8:15 p.m. LOGO-VULNERABLEMicrochip TimeProvider 4100
CVE-2024-43684 None Oct. 4, 2024, 8:15 p.m. LOGO-VULNERABLEMicrochip TimeProvider 4100
CVE-2024-43685 None Oct. 4, 2024, 8:15 p.m. LOGO-VULNERABLEMicrochip TimeProvider 4100
CVE-2024-43686 None Oct. 4, 2024, 8:15 p.m. LOGO-VULNERABLEMicrochip TimeProvider 4100
CVE-2024-43687 None Oct. 4, 2024, 8:15 p.m. LOGO-VULNERABLEMicrochip TimeProvider 4100
CVE-2024-47764 None Oct. 4, 2024, 8:15 p.m. LOGO-VULNERABLEcookie
CVE-2024-7801 None Oct. 4, 2024, 8:15 p.m. LOGO-VULNERABLEMicrochip TimeProvider 4100
CVE-2024-9054 None Oct. 4, 2024, 8:15 p.m. LOGO-VULNERABLEMicrochip TimeProvider 4100 (Configuration modules)
CVE-2024-37868 None Oct. 4, 2024, 9:15 p.m. LOGO-VULNERABLEItsourcecode Online Discussion Forum Project
CVE-2024-37869 None Oct. 4, 2024, 9:15 p.m. LOGO-VULNERABLEItsourcecode Online Discussion Forum Project
CVE-2024-47910 None Oct. 4, 2024, 9:15 p.m. LOGO-VULNERABLESonarQube
CVE-2024-47913 None Oct. 4, 2024, 10:15 p.m. LOGO-VULNERABLEMediaWiki