⚡ THN Weekly Recap: Top Cybersecurity Threats, Tools and Tips
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2023-34990 | Unauthenticated Path Traversal to Code Execution in Fortinet FortiWLM CVE-2023-34990 is a relative path traversal (CWE-23) in Fortinet's Wireless LAN Manager (FortiWLM) that allows attackers to execute unauthorized code or commands. It is triggered by specially crafted web requests sent to the management interface, and the CVSS vector (network, low complexity, no privileges, no user interaction) indicates unauthenticated remote exploitation. Successful exploitation yields full command execution on the appliance, and related reporting suggests it can lead to administrator-level access on affected systems. Any organization running FortiWLM 8.6.0 through 8.6.5 or 8.5.0 through 8.5.4 is affected. There is no known public proof-of-concept and the flaw is not yet in CISA's KEV, but the 24.9% EPSS score (98th percentile) indicates a high predicted likelihood of exploitation attempts within 30 days. Do: Upgrade FortiWLM to a release outside the affected ranges — i.e., later than 8.6.5 on the 8.6 branch or later than 8.5.4 on the 8.5 branch — per Fortinet's advisory. Until patched, restrict access to the FortiWLM web management interface to trusted networks or VPN users and do not expose it directly to the internet. Check device logs for unexpected or anomalous web requests targeting the manager, and prioritize patching internet-facing instances given the high EPSS score. | 9.8 | 25% |
| moderateplausibly 1,000-10,000 FortiWLM deployments worldwide, with likely hundreds to low thousands of management interfaces internet-exposed | ||
| CVE-2023-48788 | Unauthenticated SQL Injection in Fortinet FortiClient EMS Fortinet FortiClient EMS — the central management server for FortiClient endpoint deployments — contains a SQL injection flaw (CWE-89) in versions 7.0.1 through 7.0.10 and 7.2.0 through 7.2.2. The CVSS 3.1 vector (AV:N/AC:L/PR:N/UI:N) shows it can be triggered remotely with no credentials and no user interaction: an unauthenticated attacker sends specially crafted packets to the vulnerable management server and can execute unauthorized code or commands. Successful exploitation effectively yields remote code execution on the EMS server and access to its database, enabling follow-on actions such as credential theft, abuse of endpoint management functions, and ransomware deployment. Any organization running the affected EMS versions is exposed, especially where the management server is reachable from the internet. Exploitation is confirmed in the wild: CISA added the bug to the KEV catalog on 2024-03-25 with known ransomware use, and EPSS assigns a ~98.4% probability of exploitation within 30 days (100th percentile). Do: Upgrade FortiClient EMS to the fixed releases per Fortinet's advisory for this CVE (7.2.3 and 7.0.11 or later, i.e., beyond the 7.2.2 and 7.0.10 affected ranges); the CISA KEV required action is to apply vendor mitigations or discontinue use if mitigations are unavailable. Until patched, limit exposure of the EMS web interface to untrusted networks and hunt for signs of compromise — anomalous requests to the management console, unexpected database or admin activity, and follow-on ransomware behavior — since exploitation with known ransomware use is confirmed. | 9.8 | 98% | KEV ransomware |
| largetens of thousands of EMS deployments worldwide, with a smaller subset (likely thousands) internet-exposed | |
| CVE-2024-10205 | Authentication Bypass vulnerability in Hitachi Ops Center Analyzer on Linux, 64 bit (Hitachi Ops Center Analyzer detail view component), Hitachi Infrastructure Authentication Bypass vulnerability in Hitachi Ops Center Analyzer on Linux, 64 bit (Hitachi Ops Center Analyzer detail view component), Hitachi Infrastructure Analytics Advisor on Linux, 64 bit (Hitachi Data Center Analytics component ).This issue affects Hitachi Ops Center Analyzer: from 10.0.0-00 before 11.0.3-00; Hitachi Infrastructure Analytics Advisor: from 2.1.0-00 through 4.4.0-00. NVD description · AI analysis pending | 9.4 | <1% | — | — | ||
| CVE-2024-10244 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ISDO Software Web Software allows SQL Injection. Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ISDO Software Web Software allows SQL Injection. This issue affects Web Software: before 3.6. NVD description · AI analysis pending | 9.8 | <1% | — | — | ||
| CVE-2024-11349 | The AdForest theme for WordPress is vulnerable to authentication bypass in all versions up to, and including, 5.1.6. The AdForest theme for WordPress is vulnerable to authentication bypass in all versions up to, and including, 5.1.6. This is due to the plugin not properly verifying a user's identity prior to authenticating them through the sb_login_user_with_otp_fun() function. This makes it possible for unauthenticated attackers to log in as arbitrary users, including administrators. NVD description · AI analysis pending | 9.8 | 1% |
| — | ||
| CVE-2024-12356 | Unauthenticated Command Injection in BeyondTrust Privileged Remote Access/Remote Support BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) contain an unauthenticated command injection flaw (CWE-77) that allows a remote attacker to inject commands that are executed as a site user. The vulnerability is network-facing with low attack complexity and requires no privileges or user interaction (CVSS 3.1: AV:N/AC:L/PR:N/UI:N), so any attacker who can reach the affected PRA/RS interface can trigger it. Successful exploitation yields arbitrary command execution in the context of the site user, with high impact ratings for confidentiality, integrity, and availability. Any organization running BeyondTrust PRA or RS — particularly where those remote-access/remote-support services are exposed to the internet — is affected; the available data does not specify affected version ranges. The flaw is being actively exploited: it was added to CISA's Known Exploited Vulnerabilities catalog on 2024-12-19, carries an 88% EPSS probability of exploitation within 30 days (100th percentile), and was reportedly used in the breach of the U.S. Treasury alongside a PostgreSQL vulnerability. Do: Apply BeyondTrust's patches or vendor-specified mitigations immediately — remediation is mandatory for U.S. federal agencies under the KEV listing, and the source data does not include fixed build numbers, so confirm the correct upgrade version in BeyondTrust's security bulletin. As an interim measure, restrict or remove internet exposure of PRA/RS endpoints and hunt for signs of exploitation (unexpected commands executed as the site user), noting this flaw was used in the U.S. Treasury intrusion. If mitigations are unavailable, CISA's required action is to discontinue use of the product. | 9.8 | 88% | KEV PoC |
| moderate≈ a few thousand internet-exposed PRA/RS instances (order-of-magnitude estimate from public internet scans) | |
| CVE-2024-12371 | A device takeover vulnerability exists in the Rockwell Automation Power Monitor 1000. A device takeover vulnerability exists in the Rockwell Automation Power Monitor 1000. This vulnerability allows configuration of a new Policyholder user without any authentication via API. Policyholder user is the most privileged user that can perform edit operations, creating admin users and performing factory reset. NVD description · AI analysis pending | 9.3 | <1% | — | — | ||
| CVE-2024-12372 | A denial-of-service and possible remote code execution vulnerability exists in the Rockwell Automation Power Monitor 1000. A denial-of-service and possible remote code execution vulnerability exists in the Rockwell Automation Power Monitor 1000. The vulnerability results in corruption of the heap memory which may compromise the integrity of the system, potentially allowing for remote code execution or a denial-of-service attack. NVD description · AI analysis pending | 9.3 | <1% | — | — | ||
| CVE-2024-12373 | A denial-of-service vulnerability exists in the Rockwell Automation Power Monitor 1000. A denial-of-service vulnerability exists in the Rockwell Automation Power Monitor 1000. The vulnerability results in a buffer-overflow, potentially causing denial-of-service. NVD description · AI analysis pending | 9.3 | <1% | — | — | ||
| CVE-2024-12626 | The AutomatorWP – Automator plugin for no-code automations, webhooks & custom integrations in WordPress plugin for WordPress is vulnerable to Reflected Cross-Si The AutomatorWP – Automator plugin for no-code automations, webhooks & custom integrations in WordPress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the ‘a-0-o-search_field_value’ parameter in all versions up to, and including, 5.0.9 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link. When used in conjunction with the plugin's import and code action feature, this vulnerability can be leveraged to execute arbitrary code. NVD description · AI analysis pending | 9.6 | <1% |
| — | ||
| CVE-2024-12727 | A pre-auth SQL injection vulnerability in the email protection feature of Sophos Firewall versions older than 21.0 MR1 (21.0.1) allows access to the reporting d A pre-auth SQL injection vulnerability in the email protection feature of Sophos Firewall versions older than 21.0 MR1 (21.0.1) allows access to the reporting database and can lead to remote code execution if a specific configuration of Secure PDF eXchange (SPX) is enabled in combination with the firewall running in High Availability (HA) mode. NVD description · AI analysis pending | 9.8 group max | 1% |
| — | ||
| CVE-2024-46873 | Multiple SHARP routers leave the hidden debug function enabled. Multiple SHARP routers leave the hidden debug function enabled. An arbitrary OS command may be executed with the root privilege by a remote unauthenticated attacker. NVD description · AI analysis pending | 9.8 | <1% | — | — | ||
| CVE-2024-47810 +1 in the same advisory: …49576 | A use-after-free vulnerability exists in the way Foxit Reader 2024.3.0.26795 handles a 3D page object. A use-after-free vulnerability exists in the way Foxit Reader 2024.3.0.26795 handles a 3D page object. A specially crafted Javascript code inside a malicious PDF document can trigger this vulnerability, which can lead to memory corruption and result in arbitrary code execution. An attacker needs to trick the user into opening the malicious file to trigger this vulnerability. Exploitation is also possible if a user visits a specially crafted, malicious site if the browser plugin extension is enabled. NVD description · AI analysis pending | 8.8 | 1% | PoC ×2 |
| — | |
| CVE-2024-49775 | A vulnerability has been identified in Opcenter Execution Foundation (All versions < V2501.0001), Opcenter Intelligence (All versions < V2501.0001), Opcenter Qu A vulnerability has been identified in Opcenter Execution Foundation (All versions < V2501.0001), Opcenter Intelligence (All versions < V2501.0001), Opcenter Quality (All versions < V2512), Opcenter RDnL (All versions < V2410), SIMATIC PCS neo V4.0 (All versions), SIMATIC PCS neo V4.1 (All versions < V4.1 Update 3), SIMATIC PCS neo V5.0 (All versions < V5.0 Update 1), SINEC NMS (All versions if operated in conjunction with UMC < V2.15), Totally Integrated Automation Portal (TIA Portal) V16 (All versions), Totally Integrated Automation Portal (TIA Portal) V17 (All versions), Totally Integrated Automation Portal (TIA Portal) V18 (All versions), Totally Integrated Automation Portal (TIA Portal) V19 (All versions). Affected products contain a heap-based buffer overflow vulnerability in the integrated UMC component. This could allow an unauthenticated remote attacker to execute arbitrary code. NVD description · AI analysis pending | 9.3 | 2% | — | — | ||
| CVE-2024-4995 | Wapro ERP Desktop is vulnerable to MS SQL protocol downgrade request from a server side, what could lead to an unencrypted communication vulnerable to data inte Wapro ERP Desktop is vulnerable to MS SQL protocol downgrade request from a server side, what could lead to an unencrypted communication vulnerable to data interception and modification. This issue affects Wapro ERP Desktop versions before 9.00.0. NVD description · AI analysis pending | 9.1 | <1% | — | — | ||
| CVE-2024-51466 | IBM Cognos Analytics 11.2.0 through 11.2.4 FP4 and 12.0.0 through 12.0.4 is vulnerable to an Expression Language (EL) Injection vulnerability. IBM Cognos Analytics 11.2.0 through 11.2.4 FP4 and 12.0.0 through 12.0.4 is vulnerable to an Expression Language (EL) Injection vulnerability. A remote attacker could exploit this vulnerability to expose sensitive information, consume memory resources, and/or cause the server to crash when using a specially crafted EL statement. NVD description · AI analysis pending | 9.0 | <1% |
| — | ||
| CVE-2024-52875 | CRLF Injection/Open Redirect in GFI Kerio Control Enables Reflected XSS and RCE CVE-2024-52875 is an HTTP response splitting flaw (CWE-113) in GFI Kerio Control 9.2.5 through 9.4.5, where the unauthenticated 'dest' GET parameter on the /nonauth/addCertException.cs, /nonauth/guestConfirm.cs and /nonauth/expiration.cs pages is placed into the Location header of a 302 redirect without sanitization. An attacker triggers it by convincing a user to open a crafted link containing CRLF sequences in the 'dest' parameter, which yields open redirects, HTTP response splitting, and reflected cross-site scripting. Beyond XSS, the flaw can be escalated to remote command execution by abusing the upgrade feature in the Kerio Control admin interface, as demonstrated in published research. Any organization running Kerio Control 9.2.5 through 9.4.5 — typically SMB firewall/VPN gateway appliances or virtual appliances — is affected. No confirmed in-the-wild exploitation is documented and the issue is not in CISA KEV, but two public proofs of concept exist and a 29.6% EPSS score (98th percentile) indicates a high likelihood of exploitation attempts within 30 days. Do: Upgrade Kerio Control to a release later than 9.4.5, which resolves this issue. Until patched, minimize internet exposure of the Kerio Control admin and /nonauth/ pages (restrict management access to trusted networks) and treat any emailed or linked URLs pointing to the appliance's addCertException.cs, guestConfirm.cs or expiration.cs pages as untrusted. Monitor the appliance for unexpected upgrade activity or admin-interface sessions, since the known escalation path runs through the admin upgrade feature. | 8.8 | 30% | PoC ×2 |
| large≈ tens of thousands of internet-exposed Kerio Control instances (estimated, no official install base in source data) | |
| CVE-2024-56050 | Unrestricted Upload of File with Dangerous Type vulnerability in VibeThemes WPLMS wplms_plugin allows Upload a Web Shell to a Web Server.This issue affects WPLM Unrestricted Upload of File with Dangerous Type vulnerability in VibeThemes WPLMS wplms_plugin allows Upload a Web Shell to a Web Server.This issue affects WPLMS: from n/a through < 1.9.9.5.3. NVD description · AI analysis pending | 8.8 | <1% |
| — | ||
| CVE-2024-56145 | Unauthenticated Code Injection RCE in Craft CMS CVE-2024-56145 is an improper code-injection flaw (CWE-94) in Craft CMS that allows remote code execution over the network without authentication. The flaw is triggered on installations where the PHP configuration option `register_argc_argv` is enabled, a common setting, exposing an RCE vector to unauthenticated attackers. Successful exploitation gives attackers high-impact control over the host, with high confidentiality, integrity, and availability impact per the CVSS 4.0 score of 9.3. Users of Craft CMS 3.x, 4.x, and 5.x prior to the fixed releases are affected; the flaw has been added to CISA's Known Exploited Vulnerabilities catalog (as of 2025-06-02), carries a 97.4% EPSS probability of exploitation within 30 days, and has a public proof-of-concept available. Do: Upgrade Craft CMS to version 3.9.14, 4.13.2, or 5.5.2 as applicable to your major version. If upgrading is not immediately possible, set register_argc_argv=Off in php.ini and restart the PHP service to mitigate. Because the issue is in CISA's KEV catalog with active exploitation, check internet-facing Craft CMS instances for signs of compromise and apply required BOD 22-01 timelines if applicable. | 9.3 | 97% | KEV PoC |
| largelikely tens of thousands of exposed sites (Craft CMS powers on the order of 100k-200k live websites, and register_argc_argv is enabled in many default PHP… | |
| CVE-2024-6386 | The WPML plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 4.6.12 via Twig Server-Side Template Injection. The WPML plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 4.6.12 via Twig Server-Side Template Injection. This is due to missing input validation and sanitization on the render function. This makes it possible for authenticated attackers, with Contributor-level access and above, to execute code on the server. NVD description · AI analysis pending | 8.8 | 26% | PoC |
| — |
Full article2,551 words · extracted from thehackernews.com · click to collapse
Ravie LakshmananDec 23, 2024Cybersecurity / Weekly Recap
The online world never takes a break, and this week shows why. From ransomware creators being caught to hackers backed by governments trying new tricks, the message is clear: cybercriminals are always changing how they attack, and we need to keep up.
Hackers are using everyday tools in harmful ways, hiding spyware in trusted apps, and finding new ways to take advantage of old security gaps. These events aren’t random—they show just how clever and flexible cyber threats can be.
In this edition, we’ll look at the most important cyber events from the past week and share key takeaways to help you stay safe and prepared. Let’s get started.
⚡ Threat of the Week
LockBit Developer Rostislav Panev Charged in the U.S. — Rostislav Panev, a 51-year-old dual Russian and Israeli national, has been charged in the U.S. for allegedly acting as the developer of the now-disrupted LockBit ransomware-as-a-service (RaaS) operation, netting about $230,000 between June 2022 and February 2024. Panev was arrested in Israel in August 2024 and is currently pending extradition. With the latest development, a total of seven LockBit members have been charged in the U.S. That said, the group appears to be readying a new version, LockBit 4.0, that's scheduled for release in February 2025.
🔔 Top News
- Lazarus Group Continues to Evolve Tactics — The North Korea-linked Lazarus Group has been observed targeting nuclear engineers with a new modular malware called CookiePlus as part of a long-running cyber espionage campaign dubbed Operation Dream Job. CookiePlus is only the latest manifestation of what security researchers have described as the growing sophistication that threat actors have begun incorporating into their malware and tactics. The variety of TTPs used highlights the versatility and diversity of the hacking group.
- APT29 Uses Open-Source Tool to Set Up Proxies in RDP Attacks — The Russian state-sponsored group tracked as APT29 has repurposed a legitimate red teaming attack methodology that involves the use of an open-source proxy tool dubbed PyRDP to set up intermediate servers that are responsible for connecting victim machines to rogue RDP servers, deploy additional payloads, and even exfiltrate data. The development illustrates how it's possible for bad actors to accomplish their goals without having to design highly customized tools.
- Serbian Journalist Targeted by Cellebrite and NoviSpy — An independent Serbian journalist, Slaviša Milanov, had his phone first unlocked by Cellebrite's forensic tool and subsequently compromised by a previously undocumented spyware codenamed NoviSpy, which comes with capabilities to capture personal data from a target's phone and remotely turn on the phone's microphone or camera. The spyware attacks, detailed by Amnesty International, are the first time two different invasive technologies have been used against civil society members to facilitate the covert gathering of data. Serbia's police characterized the report as "absolutely incorrect."
- The Mask Makes a Comeback — A little-known cyber espionage actor known as The Mask has been linked to a new set of attacks targeting an unnamed organization in Latin America twice in 2019 and 2022. The group, first documented by Kaspersky back in early 2014, infected the company with malware such as FakeHMP, Careto2, and Goreto that are designed to harvest files, keystrokes, and screenshots; run shell commands; and deploy more malware. The origins of the threat actor are presently not known.
- Multiple npm Packages Fall Victim to Supply Chain Attacks — Unknown threat actors managed to compromise three different npm packages, @rspack/core, @rspack/cli, and vant, and push malicious versions to the repository containing code to deploy a cryptocurrency miner on infected systems. Following discovery, respective project maintainers stepped in to remove the rogue versions.
️🔥 Trending CVEs
Heads up! Some popular software has serious security flaws, so make sure to update now to stay safe. The list includes — CVE-2024-12727, CVE-2024-12728, CVE-2024-12729 (Sophos Firewall), CVE-2023-48788 (Fortinet FortiClient EMS), CVE-2023-34990, (Fortinet FortiWLM), CVE-2024-12356 (BeyondTrust Privileged Remote Access and Remote Support), CVE-2024-6386 (WPML plugin), CVE-2024-49576, CVE-2024-47810 (Foxit Software), CVE-2024-49775 (Siemens Opcenter Execution Foundation), CVE-2024-12371, CVE-2024-12372, CVE-2024-12373 (Rockwell Automation PowerMonitor 1000), CVE-2024-52875 (GFI KerioControl), CVE-2024-56145 (Craft CMS), CVE-2024-56050, CVE-2024-56052, CVE-2024-56054, CVE-2024-56057 (VibeThemes WPLMS), CVE-2024-12626 (AutomatorWP plugin), CVE-2024-11349 (AdForest theme), CVE-2024-51466 (IBM Cognos Analytics), CVE-2024-10244 (ISDO Software Web Software), CVE-2024-4995 (Wapro ERP Desktop), CVE-2024-10205 (Hitachi Ops Center Analyzer), and CVE-2024-46873 (Sharp router)
📰 Around the Cyber World
- Recorded Future Gets Labeled "Undesirable" in Russia — Russian authorities have tagged U.S. threat intelligence firm Recorded Future as an "undesirable" organization, accusing it of participating in propaganda campaigns and cyberattacks against Moscow. Russia's Office of Prosecutor General also said the company is "actively cooperating" with U.S. and foreign intelligence services to help search, gather, and analyze data on Russian military activities, as well as Ukraine with "unrestricted access" to programs used in offensive information operations against Russia. "Some things in life are rare compliments. This being one," Recorded Future’s chief executive, Christopher Ahlberg, wrote on X.
- China Accuses the U.S. of Conducting Cyber Attacks — The National Computer Network Emergency Response Technical Team/Coordination Center of China (CNCERT) accused the U.S. government of launching cyber attacks against two Chinese technology companies in a bid to steal trade secrets. CNCERT said one of the attacks, detected in August 2024, singled out an advanced material design and research unit by exploiting a vulnerability in an electronic document security management system to break into the upgrade management server and deliver trojan to over 270 hosts and siphon "a large amount of trade secret information and intellectual property." The second attack, on the other hand, targeted an unnamed high-tech enterprise of smart energy and digital information since May 2023 by weaponizing flaws in Microsoft Exchange Server to plant backdoors with an aim to harvest mail data. "At the same time, the attacker used the mail server as a springboard to attack and control more than 30 devices of the company and its subordinate enterprises, stealing a large amount of trade secret information from the company," CNCERT said. The allegations come in the midst of the U.S. accusing Chinese threat actors like Salt Typhoon of breaching its telecommunication infrastructure.
- New Android Spyware Distributed via Amazon Appstore — Cybersecurity researchers uncovered a new Android malware that was available for download from the Amazon Appstore. Masquerading as a body mass index (BMI) calculator, the app ("BMI CalculationVsn" or com.zeeee.recordingappz) came with features to stealthily record the screen, as well as collect the list of installed apps and incoming SMS messages. "On the surface, this app appears to be a basic tool, providing a single page where users can input their weight and height to calculate their BMI," McAfee Labs said. "However, behind this innocent appearance lies a range of malicious activities." The app has been taken down following responsible disclosure.
- HeartCrypt Packer-as-a-Service Operation Exposed — A new packer-as-a-service (PaaS) called HeartCrypt has been advertised for sale on Telegram and underground forums since February 2024 to protect malware such as Remcos RAT, XWorm, Lumma Stealer, and Rhadamanthys. Said to be in development since July 2023, its operators charge $20 per file to pack, supporting both Windows x86 and .NET payloads. "In HeartCrypt's PaaS model, customers submit their malware via Telegram or other private messaging services, where the operator then packs and returns it as a new binary," Palo Alto Networks Unit 42 said, adding it identified over 300 distinct legitimate binaries that were used to inject the malicious payload. It's suspected that the service allows clients to select a specific binary for injection so as to tailor them based on the intended target. At its core, the packer works by inserting the main payload into the binary's .text section and hijacking its control flow in order to enable the execution of the malware. The packer also takes steps to add several resources that are designed to evade detection and analysis, while simultaneously offering an optional method to establish persistence using Windows Registry modifications. "During HeartCrypt's eight months of operation, it has been used to pack over 2,000 malicious payloads, involving roughly 45 different malware families," Unit 42 said.
- Chinese and Vietnamese-speaking Users Target of CleverSoar Installer — A highly evasive malware installer called CleverSoar is being used to target Chinese and Vietnamese-speaking victims with the Winos 4.0 framework and the Nidhogg rootkit. The malware distribution starts with MSI installer packages that likely impersonate fake software or gaming-related applications, which extract the files and subsequently execute the CleverSoar installer. "These tools enable capabilities such as keystroke logging, data exfiltration, security bypasses, and covert system control, suggesting that the campaign is part of a potentially prolonged espionage effort," Rapid7 said, describing it as an advanced and targeted threat. "The campaign's selective targeting of Chinese and Vietnamese-speaking users, along with its layered anti-detection measures, points to a persistent espionage effort by a capable threat actor." It's suspected that the threat actor is also responsible for other campaigns distributing Winos 4.0 and ValleyRAT.
- Thousands of SonicWall Devices Vulnerable to Critical Flaws — As many as 119,503 publicly accessible SonicWall SSL-VPN devices are susceptible to serious security flaws (25,485 of critical severity and 94,018 of high severity), with over 20,000 using a SonicOS/OSX firmware version that's no longer supported by the vendor. "The majority of series 7 devices exposed online are impacted by at least one vulnerability of high or critical severity," cybersecurity company Bishop Fox said. A total of 430,363 unique SonicOS/OSX instances have been found exposed on the internet.
- Industrial Systems Targeted in New Malware Attacks — Siemens engineering workstations (EWS) have been targeted by a malware called Chaya_003 that's capable of terminating the Siemens TIA portal process, alongside those related to Microsoft Office applications, Google Chrome, and Mozilla Firefox. The malware, once installed, establishes connections with a Discord webhook to fetch instructions for carrying out system reconnaissance and process disruption. Forescout said it also identified two incidents in which Mitsubishi EWSs were infected with the Ramnit worm. It's currently not clear if the attackers directly targeted the operational technology (OT) systems or if it was propagated via some other means, such as phishing or compromised USB drives. OT networks have also been increasingly the target of ransomware attacks, with 552 incidents reported in Q3 2024, up from 312 in Q2 2024, per Dragos. No less than 23 new ransomware groups have targeted industrial organizations during the time period. Some of the most impacted verticals included manufacturing, industrial control systems (ICS) equipment and engineering, transportation, communications, oil and gas, electric, and government.
- Cracked Version of Acunetix Scanner Linked to Turkish IT Firm — Threat actors are selling thousands of credential sets stolen using Araneida, a cracked version of the Acunetix web app vulnerability scanner. According to Krebs on Security and Silent Push, Araneida is believed to be sold as a cloud-based attack tool to other criminal actors. Further analysis of the digital trail left by the threat actors has traced them to an Ankara-based software developer named Altuğ Şara, who has worked for a Turkish IT company called Bilitro Yazilim.
🎥 Expert Webinar
- Preparing for the Next Wave of Ransomware in 2025 — Ransomware is getting smarter, using encryption to hide and strike when you least expect it. Are you prepared for what’s coming next? Join Emily Laufer and Zscaler ThreatLabz to explore the latest ransomware trends, how attackers use encrypted channels to stay hidden, and smart strategies to stop them. Learn how to protect your organization before it’s too late—secure your spot today!
- The Enterprise Guide to Certificate Automation and Beyond — Join our live demo to see how DigiCert ONE simplifies trust across users, devices, and software. Discover how to centralize certificate management, automate operations, and meet compliance demands while reducing complexity and risk. Whether for IT, IoT, or DevOps, learn how to future-proof your digital trust strategy. Don’t miss out—register now!
🔧 Cybersecurity Tools
- AttackGen — It is an open-source tool that helps organizations prepare for cyber threats. It uses advanced AI models and the MITRE ATT&CK framework to create incident response scenarios tailored to your organization's size, industry, and selected threat actors. With features like quick templates for common attacks and a built-in assistant for refining scenarios, AttackGen makes planning for cyber incidents easy and effective. It supports both enterprise and industrial systems, helping teams stay ready for real-world threats.
- Brainstorm — It is a tool that makes web fuzzing more effective by using local AI models alongside ffuf. It analyzes links from a target website and generates smart guesses for hidden files, directories, and API endpoints. By learning from each discovery, it reduces the number of requests needed while finding more endpoints compared to traditional wordlists. This tool is perfect for optimizing fuzzing tasks, saving time, and avoiding detection. It’s easy to set up, works with local LLMs like Ollama, and adapts to your target.
- GPOHunter - This tool helps identify and fix security flaws in Active Directory Group Policy Objects (GPOs). It detects issues like clear text passwords, weak authentication settings, and vulnerable GPP passwords, providing detailed reports in multiple formats. Easy to use and highly effective, GPOHunter simplifies securing your GPOs and strengthening your environment.
🔒 Tip of the Week
Don’t Let Hackers Peek into Your Cloud — Cloud storage makes life easier, but it can also expose your data if not secured properly. Many people don’t realize that misconfigured settings, like public folders or weak permissions, can let anyone access their files. This is how major data leaks happen—and it’s preventable.
Start by auditing your cloud. Tools like ScoutSuite can scan for vulnerabilities, such as files open to the public or missing encryption. Next, control access by only allowing those who need it. A tool like Cloud Custodian can automate these policies to block unauthorized access.
Finally, always encrypt your data before uploading it. Tools like rclone make it simple to lock your files with a key only you can access. With these steps, your cloud will stay safe, and your data will remain yours.
Conclusion
The holidays are a time for celebration, but they’re also peak season for cyber risks. Cybercriminals are more active than ever, targeting online shoppers, gift exchanges, and even festive email greetings. Here’s how you can enjoy a secure and worry-free holiday:
- 🎁 Wrap Your Digital Gifts with Security: If you’re gifting smart gadgets, set them up with strong passwords and enable updates before wrapping them. This ensures your loved ones start safe from day one.
- 📦 Track Packages, Not Scammers: Be wary of fake delivery notifications. Use official apps or tracking links from trusted retailers to follow your shipments.
- ✨ Make Your Accounts Jolly Secure: Use a password manager to update weak passwords across your accounts. A few minutes now can save hours of frustration later.
- 🎮 Game On, Safely: If new gaming consoles or subscriptions are on your list, make sure to activate parental controls and use unique account details. Gaming scams spike during the holidays.
As we head into the New Year, let’s make cybersecurity a priority for ourselves and our families. After all, staying safe online is the gift that keeps on giving.
Happy Holidays, and here’s to a secure and joyful season! 🎄🔒
Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.
Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2024/12/thn-weekly-recap-top-cybersecurity.html