ZeroHour

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2023-28461
Unauthenticated RCE in Array Networks AG/vxAG SSL VPN Gateways (ArrayOS)

CVE-2023-28461 is a critical (CVSS 9.8) missing-authentication flaw in Array Networks' AG series and virtual vxAG SSL VPN gateways running ArrayOS 9.4.0.481 and earlier. An unauthenticated remote attacker sends an HTTP request to a vulnerable URL containing a 'flags' attribute in an HTTP header, which allows browsing the filesystem on the SSL VPN gateway; vendor and CERT reporting indicate this can be leveraged into full remote code execution, and JPCERT has confirmed active command-injection attacks. Successful exploitation gives the attacker code execution on the appliance, compromising the VPN gateway and potentially providing a foothold into the protected internal network. Any organization running an affected AG/vxAG gateway is exposed; these are enterprise SSL VPN appliances, with notable deployments in Japan and the wider Asia-Pacific region. Exploitation is confirmed in the wild: CISA added the flaw to its Known Exploited Vulnerabilities catalog on 2024-11-25 (ransomware use known), JPCERT/CC reports widespread exploitation, Chinese-linked activity including MirrorFace targeting Japanese firms has been reported, and EPSS places the 30-day exploitation probability at 68.1%.

Do: Upgrade AG/vxAG gateways to a fixed ArrayOS release per Array Networks' instructions — as of the 2023-03-09 advisory a fixed release was pending, so apply any release newer than 9.4.0.481 once available; if mitigations are unavailable, discontinue use per the CISA KEV required action, and federal agencies should follow CISA's directive to patch. Review gateway logs and downstream systems for signs of exploitation, and treat any compromised appliance as a potential network foothold given confirmed ransomware use.

9.868% KEV ransomware
  • Array Networks AG series and vxAG SSL VPN gateways (ArrayOS) 9.4.0.481 and earlier
moderatelikely on the order of thousands (roughly 1,000–10,000) of internet-exposed AG/vxAG gateway appliances, each typically serving many remote users (estimate)
CVE-2024-10542
The Spam protection, Anti-Spam, FireWall by CleanTalk plugin for WordPress is vulnerable to unauthorized Arbitrary Plugin Installation due to an authorization b

The Spam protection, Anti-Spam, FireWall by CleanTalk plugin for WordPress is vulnerable to unauthorized Arbitrary Plugin Installation due to an authorization bypass via reverse DNS spoofing on the checkWithoutToken function in all versions up to, and including, 6.43.2. This makes it possible for unauthenticated attackers to install and activate arbitrary plugins which can be leveraged to achieve remote code execution if another vulnerable plugin is installed and activated.

NVD description · AI analysis pending
7.515%
  • cleantalk anti-spam
CVE-2024-10781
The Spam protection, Anti-Spam, FireWall by CleanTalk plugin for WordPress is vulnerable to unauthorized Arbitrary Plugin Installation due to an missing empty v

The Spam protection, Anti-Spam, FireWall by CleanTalk plugin for WordPress is vulnerable to unauthorized Arbitrary Plugin Installation due to an missing empty value check on the 'api_key' value in the 'perform' function in all versions up to, and including, 6.44. This makes it possible for unauthenticated attackers to install and activate arbitrary plugins which can be leveraged to achieve remote code execution if another vulnerable plugin is installed and activated.

NVD description · AI analysis pending
7.54%
  • cleantalk spam protection\, antispam\, firewall
CVE-2024-11103
The Contest Gallery plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 24.0.7.

The Contest Gallery plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 24.0.7. This is due to the plugin not properly validating a user's identity prior to updating their password. This makes it possible for unauthenticated attackers to change arbitrary user's passwords, including administrators, and leverage that to gain access to their account.

NVD description · AI analysis pending
9.8<1%
  • contest-gallery contest gallery
CVE-2024-11680
Unauthenticated Config Tampering and Webshell Upload in ProjectSend (pre-r1720)

ProjectSend versions prior to r1720 fail to enforce authentication on requests to options.php (CWE-306, missing authentication for a critical function), a critical flaw rated CVSS 9.8. A remote, unauthenticated attacker can send crafted HTTP requests directly to options.php to modify the application's configuration without any user interaction. With configuration control, the attacker can enable registration and create accounts, upload webshells to achieve code execution on the server, and embed malicious JavaScript in the site. Any organization running ProjectSend earlier than r1720 — especially internet-facing deployments used for client file exchange — is affected. Exploitation is confirmed in the wild: the flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2024-12-03, carries a 91.7% EPSS probability of exploitation within 30 days, and public reporting and a Metasploit module are available.

Do: Upgrade ProjectSend to r1720 or later, which restores proper authentication on options.php; per CISA's KEV required action, apply vendor mitigations or discontinue use of the product if mitigation is not possible. Prioritize internet-facing instances and hunt for signs of compromise, including unexpected or new user accounts, modified configuration, unexpected PHP files or webshells on the server, and injected JavaScript. Until patched, restrict network access to the installation and limit or protect access to options.php.

9.892% KEV PoC
  • ProjectSend All versions prior to r1720
moderateroughly 1,000–10,000 internet-exposed ProjectSend instances (self-hosted app; no central install count)
CVE-2024-42327
SQL Injection in Zabbix Frontend User API (CUser.get)

CVE-2024-42327 is a SQL injection (CWE-89) in the Zabbix frontend's CUser class, in the addRelatedObjects function, which is reached via the CUser.get API method. Any authenticated non-admin account holding the default User role, or any other role that grants API access, can trigger the flaw simply by calling user.get, with no user interaction required. The CVSS 3.1 score of 9.9 (network vector, low privileges, changed scope, high confidentiality/integrity/availability impact) indicates an attacker could read or alter database contents, potentially compromising the monitoring platform and its data beyond their own account's privileges. All Zabbix deployments whose frontends expose the API to non-admin users are affected, which is the default configuration. Exploitation has not been confirmed: the flaw is not in CISA's KEV catalog and no public PoC is known, but EPSS assigns a very high 78.7% probability of exploitation within 30 days.

Do: Upgrade each affected Zabbix instance to the patched release for your branch as specified in Zabbix's security advisory for CVE-2024-42327. As interim mitigation, audit which non-admin users and roles have API access and restrict or disable user.get access for untrusted accounts. Monitor frontend/API logs for anomalous user.get calls and unexpected SQL activity, since exploitation requires only low-privilege API credentials.

9.979%
  • Zabbix (frontend / API, CUser class)
largetens of thousands of internet-exposed Zabbix frontends, within a deployment base of hundreds of thousands of instances
CVE-2024-49035
Unauthenticated Privilege Escalation in Microsoft Partner Center

An improper access-control flaw (CWE-269) in Microsoft's Partner Center portal at Partner.Microsoft.com allows an unauthenticated, remote attacker to elevate privileges over the network, earning a critical CVSS 3.1 score of 9.8. The flaw is triggered by network requests to the internet-facing portal that bypass access-control checks, requiring no credentials or user interaction. A successful attacker gains elevated privileges within Partner Center, the portal partners use to manage Microsoft cloud customer tenants and reseller relationships, potentially exposing partner and customer management functions. Any organization using Microsoft Partner Center — typically CSP partners, direct bill partners, and indirect resellers — is affected. The flaw is actively exploited: Microsoft addressed it in its November 2024 security fixes with exploitation seen in active attacks, and CISA added it to the KEV catalog on 2025-02-25.

Do: Partner Center is a Microsoft-managed cloud service, so no customer-side upgrade version applies — confirm with Microsoft that the service-side fix is in place, and federal agencies must follow BOD 22-01/KEV required actions (apply vendor mitigations or discontinue use). Review Entra ID sign-in logs and Partner Center audit logs for unauthenticated access, unexpected role or privilege changes, and anomalous app registrations or consent grants, and rotate credentials for affected partner accounts if compromise is suspected.

9.81% KEV
  • Microsoft Partner Center (partner.microsoft.com) Cloud service; no version ranges specified in the data (remediated service-side by Microsoft)
masshundreds of thousands of partner organizations (Microsoft's partner ecosystem is commonly cited at 400k+ partners); exact account/user counts undisclosed
CVE-2024-49039
Windows Task Scheduler Elevation-of-Privilege Flaw Actively Exploited in the Wild

CVE-2024-49039 is an elevation-of-privilege vulnerability (CWE-287, improper authentication) in the Microsoft Windows Task Scheduler, scored 8.8 (High) with a local attack vector, low required privileges, and a changed scope indicating the exploit crosses a security boundary. A local attacker with limited user privileges can trigger the flaw through Task Scheduler to gain elevated rights on the affected system, typically SYSTEM- or administrator-level control, with no user interaction required. Every supported Windows desktop and server release in the vendor's affected list is impacted, since Task Scheduler is a core component of the operating system. The flaw was patched as an actively exploited zero-day in the November 2024 Patch Tuesday release, was added to CISA's Known Exploited Vulnerabilities catalog on 2024-11-12, and ransomware operators are known to use it. With an EPSS of 14.2% (96th percentile), defenders should treat this as a high-priority local privilege escalation for privilege-chaining and ransomware campaigns.

Do: Apply the November 2024 Windows security updates across all affected Windows 10, Windows 11, and Windows Server branches, prioritizing servers, jump hosts, and machines used by privileged users given confirmed ransomware use. Confirm no supported Windows host is left unpatched, review local task creation and authentication logs for signs of privilege escalation, and follow CISA's required action to apply vendor mitigations or discontinue use if patches are unavailable.

8.814% KEV ransomware
  • Microsoft Windows 10 1507
  • Microsoft Windows 10 1607
  • Microsoft Windows 10 1809
  • +9 more
masshundreds of millions of Windows systems (Task Scheduler ships with every Windows 10, Windows 11, and Windows Server installation)
CVE-2024-49805
+2 in the same advisory: …49806 …49803
IBM Security Verify Access Appliance 10.0.0 through 10.0.8 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own i

IBM Security Verify Access Appliance 10.0.0 through 10.0.8 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data.

NVD description · AI analysis pending
9.8
group max
<1%
  • ibm security verify access
CVE-2024-50357
FutureNet NXR series routers provided by Century Systems Co., Ltd.

FutureNet NXR series routers provided by Century Systems Co., Ltd. have REST-APIs, which are configured as disabled in the initial (factory default) configuration. But, REST-APIs are unexpectedly enabled when the affected product is powered up, provided either http-server (GUI) or Web authentication is enabled. The factory default configuration makes http-server (GUI) enabled, which means REST-APIs are also enabled. The username and the password for REST-APIs are configured in the factory default configuration. As a result, an attacker may obtain and/or alter the affected product's settings via REST-APIs.

NVD description · AI analysis pending
9.8<1%
CVE-2024-52338
Deserialization of untrusted data in IPC and Parquet readers in the Apache Arrow R package versions 4.0.0 through 16.1.0 allows arbitrary code execution.

Deserialization of untrusted data in IPC and Parquet readers in the Apache Arrow R package versions 4.0.0 through 16.1.0 allows arbitrary code execution. An application is vulnerable if it reads Arrow IPC, Feather or Parquet data from untrusted sources (for example, user-supplied input files). This vulnerability only affects the arrow R package, not other Apache Arrow implementations or bindings unless those bindings are specifically used via the R package (for example, an R application that embeds a Python interpreter and uses PyArrow to read files from untrusted sources is still vulnerable if the arrow R package is an affected version). It is recommended that users of the arrow R package upgrade to 17.0.0 or later. Similarly, it is recommended that downstream libraries upgrade their dependency requirements to arrow 17.0.0 or later. If using an affected version of the package, untrusted data can read into a Table and its internal to_data_frame() method can be used as a workaround (e.g., read_parquet(..., as_data_frame = FALSE)$to_data_frame()). This issue affects the Apache Arrow R package: from 4.0.0 through 16.1.0. Users are recommended to upgrade to version 17.0.0, which fixes the issue.

NVD description · AI analysis pending
9.82%
  • apache arrow
CVE-2024-52490
Unrestricted Upload of File with Dangerous Type vulnerability in pathomation Pathomation pathomation allows Upload a Web Shell to a Web Server.This issue affect

Unrestricted Upload of File with Dangerous Type vulnerability in pathomation Pathomation pathomation allows Upload a Web Shell to a Web Server.This issue affects Pathomation: from n/a through <= 2.5.1.

NVD description · AI analysis pending
10.0<1%
  • WordPress
CVE-2024-53676
Unauthenticated Directory Traversal to RCE in HPE Insight Remote Support

CVE-2024-53676 is a directory traversal flaw (CWE-22, CWE-552) in HPE Insight Remote Support, HPE's remote monitoring and support service deployed alongside ProLiant server estates, which may allow attackers to escape the intended path restrictions and achieve remote code execution. It is triggered by sending crafted, network-based requests containing traversal sequences to the service, with no authentication required (AV:N/AC:L/PR:N/UI:N). A successful attacker gains code execution on the server hosting Insight Remote Support, with the CVSS score indicating high impact on confidentiality, integrity, and availability. Any organization running HPE Insight Remote Support to monitor HPE ProLiant servers is potentially affected. There is no public proof-of-concept, it is not in CISA KEV, and no confirmed in-the-wild exploitation is known, but the 56.3% EPSS score (99th percentile) indicates a high likelihood of exploitation attempts within the next 30 days.

Do: Upgrade Insight Remote Support to the patched release identified in HPE's official security advisory, since no version numbers are provided in the current data. Until patched, restrict network access to the Insight Remote Support service to trusted management networks and confirm it is not exposed to the internet. Because EPSS is high, watch for HPE advisories and monitor the host for unexpected process launches or outbound connections.

9.856%
  • HPE Insight Remote Support
largelikely tens of thousands of installations worldwide, with a smaller subset directly internet-exposed
CVE-2024-8672
Authenticated RCE via eval() in WordPress Widget Options Plugin (≤ 4.0.7)

CVE-2024-8672 is a code-injection flaw (CWE-94) in the Widget Options WordPress plugin, where the display-logic feature that extends several page builders passes user-supplied input directly into PHP eval() with no filtering or capability checks. An attacker holding contributor-level credentials or higher on a site running Widget Options can submit crafted input through this feature to execute arbitrary code on the web server. Successful exploitation yields full remote code execution with high impact on confidentiality, integrity, and availability, and the changed-scope CVSS metric indicates the compromise can extend beyond the vulnerable component. All sites running Widget Options version 4.0.7 or earlier are affected. There is no public proof-of-concept or confirmed in-the-wild exploitation yet, but EPSS places the probability of exploitation within 30 days at 43.6% (99th percentile), and the vendor's patch is considered released although researchers note it could still be further hardened.

Do: Update Widget Options to a patched release beyond 4.0.7 immediately and treat this as a priority given the high EPSS. Because the researchers note the current patch may leave residual risk, audit which contributor-and-above accounts exist on affected sites, review or restrict use of the plugin's display-logic widgets, and monitor server logs for unexpected code execution or admin activity.

9.944%
  • Widget Options – The #1 WordPress Widget & Block Control Plugin (WordPress plugin) all versions up to and including 4.0.7
largeon the order of 100,000+ WordPress sites (plugin lists roughly 100k+ active installs)
CVE-2024-9680
Use-After-Free in Mozilla Firefox Animation Timelines Allows Code Execution

Mozilla Firefox and Firefox ESR contain a use-after-free (CWE-416) in the browser's animation timelines component, which CISA describes as allowing code execution in the content process. The flaw is reachable through malicious web content: a crafted page can manipulate animation timelines so that an in-use object is freed, producing exploitable memory corruption. A successful attacker gains code execution in the content process, the sandboxed process that renders web pages, on the machine of the user who loaded the content. All users of Firefox and Firefox ESR are affected by the flaw itself. It is being actively exploited: the vulnerability was added to CISA's Known Exploited Vulnerabilities catalog on 2024-10-15 with known ransomware use, and EPSS assigns it a 23.2% probability of exploitation in the next 30 days (98th percentile).

Do: Apply Mozilla's patched Firefox/Firefox ESR release immediately and verify the running version via the browser's About Firefox dialog, since many installs only pick up auto-updates after a restart (per CISA's required action: apply mitigations per vendor instructions or discontinue use). Given the known ransomware use, prioritize enterprise ESR rollout and check for managed-update failures, auto-update-disabled installs, or unmanaged Firefox copies on user machines. Note that no public proof-of-concept is known, but KEV listing confirms exploitation, so patching should not wait for PoC availability.

9.823% KEV ransomware
  • Mozilla Firefox
  • Mozilla Firefox ESR
masshundreds of millions of users (Firefox's global desktop user base of roughly 150-200M active users, plus enterprise Firefox ESR deployments)
Full article2,309 words · extracted from thehackernews.com · click to collapse

Ravie LakshmananDec 02, 2024Cyber Threats / Weekly Recap

Ever wonder what happens in the digital world every time you blink? Here's something wild - hackers launch about 2,200 attacks every single day, which means someone's trying to break into a system somewhere every 39 seconds.

And get this - while we're all worried about regular hackers, there are now AI systems out there that can craft phishing emails so convincingly, that even cybersecurity experts have trouble spotting them. What's even crazier? Some of the latest malware is like a digital chameleon - it literally watches how you try to catch it and changes its behavior to slip right past your defenses.

Pretty mind-bending stuff, right? This week's roundup is packed with eye-opening developments that'll make you see your laptop in a whole new light.

⚡ Threat of the Week

T-Mobile Spots Hackers Trying to Break In: U.S. telecom service provider T-Mobile caught some suspicious activity on their network recently - basically, someone was trying to sneak into their systems. The good news? They spotted it early and no customer data was stolen. While T-Mobile isn't pointing fingers directly, cybersecurity experts think they know who's behind it - a hacking group nicknamed 'Salt Typhoon,' which apparently has ties to China. What makes this really interesting is that these hackers have a brand new trick up their sleeve: they're using a previously unknown backdoor tool called GHOSTSPIDER. Think of it as a skeleton key that no one knew existed until now. They've been using this same tool to target telecom companies across Southeast Asia.

Phish Kit Teardown Phish Kit Teardown

Webinar: Phish Kit Teardown — How AitM phish kits evade detection

Do your employees keep getting phished with adversary-in-the-middle (AitM) kits like Evilginx, Nakedpages, and Tycoon? You aren’t the only one… Ride along with Push Security as they tear down popular AitM phishing kits to demonstrate how attackers are finding ways through your detection controls.

Register Now

🔔 Top News

  • Prototype UEFI Bootkit Targeting Linux Detected: Bootkits refer to a type of malware that is designed to infect a computer's boot loader or boot process. In doing so, the idea is to execute malicious code before even initializing the operating system and bypass security measures, effectively granting the attackers absolute control over the system. While bootkits discovered to date have only targeted Windows machines, the discovery of Bootkitty indicates that it's no longer the case. That said, it's assessed to be a proof-of-concept (PoC) and there is no evidence that it has been put to use in real-world attacks.
  • Avast Anti-Rootkit Driver Used to Disarm Security Software: A new malware campaign is leveraging a technique called Bring Your Own Vulnerable Driver (BYOVD) to obtain elevated privileges and terminate security-related processes by making use of the legitimate Avast Anti-Rootkit driver (aswArPot.sys). The exact initial access vector used to drop the malware is currently not clear. It's also not known what the end goal of these attacks are, who are the targets, or how widespread they are.
  • RomCom Exploits Mozilla Fire and Windows 0-Days: The Russia-aligned threat actor known as RomCom chained two zero-day security flaws in Mozilla Firefox (CVE-2024-9680, CVSS score: 9.8) and Microsoft Windows (CVE-2024-49039, CVSS score: 8.8) as part of attacks designed to deliver the eponymous backdoor on victim systems without requiring any user interaction. The vulnerabilities were fixed by Mozilla and Microsoft in October and November 2024, respectively.
  • LockBit and Hive Ransomware Operator Arrested in Russia: Mikhail Pavlovich Matveev, a Russian national who is wanted in the U.S. in connection with LockBit and Hive ransomware operations, has been arrested and charged in the country for developing malicious programs that can encrypt files and for seeking ransom payments in exchange for a decryption key. While he is unlikely to be extradited to the U.S., the development comes a little over a month after four members of the now-defunct REvil ransomware operation were sentenced to several years in prison in Russia.
  • New Botnet Linked to DDoS Campaign: A script kiddie likely of Russian origin has been using publicly available malware tools from GitHub and exploits targeting weak credentials, configurations, and known security flaws to assemble a distributed denial-of-service (DDoS) botnet capable of disruption on a global scale. The threat actor has established a store of sorts on Telegram, where customers can buy different DDoS plans and services in exchange for a cryptocurrency payment.

‎️‍🔥 Trending CVEs

We’ve spotted some big security issues in popular software this week. Whether you’re running a business or just managing a personal site, these could affect you. The fix? Keep your software updated. Most of these problems are solved with the latest security patches from the vendors.

The list includes:: CVE-2024-11680 (ProjectSend), CVE-2023-28461 (Array Networks AG and vxAG), CVE-2024-10542, CVE-2024-10781 (Spam protection, Anti-Spam, and FireWall plugin), CVE-2024-49035 (Microsoft Partner Center), CVE-2024-49806, CVE-2024-49803, CVE-2024-49805 (IBM Security Verify Access Appliance), CVE-2024-50357 (FutureNet NXR routers), CVE-2024-52338 (Apache Arrow R package), CVE-2024-52490 (Pathomation), CVE-2024-8672 (Widget Options – The #1 WordPress Widget & Block Control plugin), CVE-2024-11103 (Contest Gallery plugin), CVE-2024-42327 (Zabbix), and CVE-2024-53676 (Hewlett Packard Enterprise Insight Remote Support).

📰 Around the Cyber World

  • Five Unpatched NTLM Flaws Detailed: While Microsoft may have confirmed its plans to deprecate NTLM in favor of Kerberos, the technology continues to harbor security weaknesses that could enable attackers to obtain NTLM hashes and stage pass-the-hash attacks that allow them to authenticate themselves as a victim user. Cybersecurity firm Morphisec said it identified five significant NTLM vulnerabilities that could be exploited to leak the credentials via Malicious RTF Document Auto Link in Microsoft Word, Remote Image Tag in Microsoft Outlook, Remote Table Refresh in Microsoft Access, Legacy Player Files in Microsoft Media Player, and Remote Recipient List in Microsoft Publisher. Microsoft has acknowledged these flaws but noted that they are either by design or do not meet the bar for immediate servicing. It's recommended to restrict NTLM usage, enable SMB signing and encryption, block outbound SMB connections to untrusted networks, and switch to Kerberos-only authentication.
  • Raspberry Robin's Anti-Analysis Methods Revealed: Cybersecurity researchers have detailed the several binary-obfuscation and techniques Raspberry Robin, a malware downloader also known as Roshtyak, has incorporated to fly under the radar. "When Raspberry Robin detects an analysis environment, it responds by deploying a decoy payload to mislead researchers and security tools," Zscaler ThreatLabz said. "Raspberry Robin is protected and unwrapped by several code layers. All code layers use a set of obfuscation techniques, such as control flow flattening and Mixed Boolean-Arithmetic (MBA) obfuscation." Obfuscation and encryption have also been hallmarks of another malware family tracked as XWorm, highlighting the threat actor's ability to adapt and bypass detection effects. The disclosure comes as Rapid7 detailed the technical similarities and differences between AsyncRAT and Venom RAT, two open-source trojans that have been widely adopted by several threat actors over the years. "While they indeed belong to the Quasar RAT family, they are still different RATs," it noted. "Venom RAT presents more advanced evasion techniques, making it a more sophisticated threat."
  • BianLian Ransomware Shifts to Pure Extortion: U.S. and Australian cybersecurity agencies have revealed that the developers of the BianLian ransomware are likely based in Russia and that they "shifted primarily to exfiltration-based extortion around January 2023 and shifted to exclusively exfiltration-based extortion around January 2024." The change follows the release of a free BianLian decryptor in early 2023. Besides using PowerShell scripts to conduct reconnaissance, the attacks are notable for printing ransom notes on printers connected to the compromised network and placing threatening calls to employees of the victim companies to apply pressure. According to data collected by Corvus, RansomHub, Play, LockBit 3.0, MEOW, and Hunters International have accounted for 40% of all attacks observed in Q3 2024. A total of 1,257 victims were posted on data leak sites, up from 1,248 in Q2 2024. "The number of active ransomware groups increased to 59, continuing the trend of new groups entering the landscape, with activity overall becoming more distributed across numerous smaller groups," the company said.
  • VietCredCare and Ducktail Campaigns Compared: Both VietCredCare and Ducktail are information stealers that are specifically designed to target Facebook Business accounts. They are believed to be operated by threat actors within Vietnam. A law enforcement exercise undertaken by Vietnamese law enforcement agencies in May 2024 led to the arrest of more than 20 individuals likely involved in these activities, resulting in a substantial reduction in campaigns distributing VietCredCare. However, Ducktail-related campaigns appear to be ongoing. "While both target Facebook business accounts, they differ significantly in their code structures," Group-IB said. "Threat actors use different methods of malware proliferation and approaches to monetizing stolen credentials. This makes us think that the operators behind both campaigns are not related to each other." Despite these differences, it has been discovered that the threat actors behind the different malware families share the same Vietnamese-speaking communities to sell the stolen credentials for follow-on malvertising campaigns.
  • CyberVolk, a Pro-Russian Hacktivist Collective Originating from India: The threat actors behind CyberVolk (aka GLORIAMIST) have been observed launching ransomware and DDoS attacks against public and government entities that it perceives as opposed to Russian interests. It's allegedly led by a threat actor, who goes by the online alias Hacker-K. But it's unclear where the group is currently based or who its other members are. Since at least May 2024, the group has been found to quickly embrace and modify existing ransomware builders such as AzzaSec, Diamond, Doubleface (aka Invisible), LockBit, Chaos, and Babuk to launch its attacks. It's worth noting that the source code of AzzaSec and Doubleface have suffered leaks of their own in recent months. "Additionally, CyberVolk has promoted other ransomware families like HexaLocker and Parano," SentinelOne said, while distributing info stealer malware and webshells. "These groups and the tools they leverage are all closely intertwined." As of early November 2024, CyberVolk has had its Telegram channel banned, prompting it to shift to X.

🎥 Expert Webinar

  • 🤖 Building Secure AI Apps—No More Guesswork — AI is taking the world by storm, but are your apps ready for the risks? Whether it’s guarding against data leaks or preventing costly operational chaos, we’ve got you covered. In this webinar, we’ll show you how to bake security right into your AI apps, protect your data, and dodge common pitfalls. You’ll walk away with practical tips and tools to keep your AI projects safe and sound. Ready to future-proof your development game? Save your spot today!
  • 🔑 Protect What Matters Most: Master Privileged Access Security — Privileged accounts are prime targets for cyberattacks, and traditional PAM solutions often leave critical gaps. Join our webinar to uncover blind spots, gain full visibility, enforce least privilege and Just-in-Time policies, and secure your organization against evolving threats. Strengthen your defenses—register now!

🔧 Cybersecurity Tools

  • Sigma Rule ConverterAn open-source tool that simplifies translating Sigma rules into query formats compatible with various SIEM systems like Splunk and Elastic. Ideal for threat hunting, incident response, and security operations, it streamlines integration, ensures rapid deployment of updated detection rules, and supports multiple backends via pySigma. With its user-friendly interface and regular updates, it enables security teams to adapt quickly to evolving threats.
  • CodeQL Vulnerability Detection Tool: CodeQL is a powerful tool that helps developers and security researchers find bugs in codebases like Chrome. It works by creating a database with detailed information about the code, allowing you to run advanced searches to spot vulnerabilities. Pre-built Chromium CodeQL databases make it easy to dive into Chrome's massive codebase of over 85 million lines. With its ability to track data flow, explore code structures, and detect similar bugs, CodeQL is perfect for improving security. Google’s collaboration with the CodeQL team ensures continuous updates for better performance.

🔒 Tip of the Week

Your Screenshots Are Secretly Talking Behind Your Back — Every screenshot you share could reveal your device info, location, OS version, username, and even internal system paths without your knowledge. Last month, a tech company accidentally leaked their project codenames through screenshot metadata! Here's your 30-second fix: On Windows, right-click → Properties → Details → Remove Properties before sharing. Mac users can use Preview's export feature (uncheck "More Options"), while mobile users should use built-in editing tools before sharing. For automation, grab ImageOptim (free) - it strips metadata with a simple drag-and-drop. Quick verification: Upload any screenshot to exif.app and prepare to be surprised at how much hidden data you've been sharing. Pro tip: Create a designated 'sanitized screenshots' folder with automated metadata stripping for your sensitive work-related captures. Remember, in 2023, screenshot metadata became a primary reconnaissance tool for targeted attacks - don't let your images do the attackers' work for them.

Conclusion

So here's the thing that keeps security folks up at night - some of today's smartest malware can actually hide inside your computer's memory without ever touching the hard drive (spooky, right?). It's like a ghost in your machine.

But don't worry, it's not all doom and gloom. The good guys are cooking up some seriously cool defenses too. Think AI systems that can predict attacks before they happen (kind of like Minority Report, but for cyber crimes), and new ways to encrypt data that even quantum computers can't crack. Wild stuff!

Before you head back to your digital life, remember this fun fact: your smartphone today has more computing power than all of NASA had when they first put humans on the moon - and yes, that means both the good guys and the bad guys have that same power at their fingertips. Stay safe out there, keep your updates running, and we'll see you next week with more fascinating tales from the cyber frontier.

Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.

Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2024/12/thn-recap-top-cybersecurity-threats.html