ZeroHour

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2020-1472
Unauthenticated Privilege Escalation (Zerologon) in Microsoft Netlogon Domain Controllers

CVE-2020-1472, widely known as "Zerologon," is an elevation-of-privilege flaw in how the Netlogon secure channel is established over the Netlogon Remote Protocol (MS-NRPC) on Microsoft domain controllers. An unauthenticated attacker with network reachability to a domain controller sends specially crafted Netlogon messages to establish a vulnerable secure channel and then runs a specially crafted application on the network to obtain domain administrator access. Successful exploitation yields domain administrator privileges, effectively full compromise of the Active Directory environment, and the flaw is known to be used in ransomware operations. Any organization running affected Windows Server versions (2008 through 20H2) as domain controllers is exposed, along with environments using Netlogon implementations from Samba and distributions or products from Fedora, openSUSE, Canonical (Ubuntu), Debian, Synology, and Oracle. Exploitation is highly active: a public Zerologon PoC/exploit is available, the flaw is on CISA's Known Exploited Vulnerabilities catalog (added 2021-11-03, with known ransomware use), and EPSS estimates a 99.4% probability of exploitation within 30 days.

Do: Apply the vendor updates on all domain controllers and other affected systems immediately, following Microsoft's two-phase Netlogon secure channel guidance (the enforcement phase of the phased rollout began in Q1 2021). Audit Netlogon secure-channel connections and event logs for clients still using vulnerable connections before enabling full enforcement, and install updated packages for Samba and other Netlogon implementations from Fedora, openSUSE, Ubuntu, Debian, Synology, and Oracle. Given known ransomware use, prioritize patching any domain controller reachable from user networks, VPNs, or the internet.

5.599% KEV ransomware PoC
  • Microsoft Windows Server (when acting as a domain controller)
  • Samba (Netlogon secure channel implementation)
  • Fedora Project Fedora Linux
  • +5 more
massmillions of domain controllers worldwide (essentially every Active Directory domain), with hundreds of thousands of domain controllers/RPC endpoints…
CVE-2021-44228
JNDI Injection Remote Code Execution in Apache Log4j2 (Log4Shell)

Apache Log4j2, an extremely widely used Java logging library, fails to protect its JNDI lookup feature against attacker-controlled JNDI-related endpoints (CWE-20, CWE-502), so crafted text processed by the logger causes the Java runtime to fetch and load attacker-supplied objects, leading to remote code execution. The flaw is triggered whenever attacker-controlled input reaches the logging API and is parsed for JNDI lookups, a pattern common in web servers and enterprise Java applications that log user-supplied fields such as headers or form values. Successful exploitation yields arbitrary code execution under the privileges of the affected application, giving attackers a foothold for lateral movement, data theft, and ransomware deployment. Any Java application or product that ships or bundles an affected Apache Log4j2 release is exposed, making this one of the most broadly deployed vulnerabilities ever disclosed. Exploitation is confirmed in the wild: CISA added it to the Known Exploited Vulnerabilities catalog on 2021-12-10 with known ransomware use, and EPSS assigns a 100% probability of exploitation within 30 days.

Do: Inventory all Java applications and dependencies for Apache Log4j2 and apply the vendor's patched updates, or remove affected assets from the network, as required by CISA's KEV catalog. Where updates are not yet available, use the temporary mitigations in CISA's ED-22-02 recommended-mitigation guidance, such as disabling message lookups, only until patches are applied. Prioritize internet-facing and business-critical systems and hunt for exploitation activity given known ransomware use.

10.0100% KEV ransomware PoC ×9
  • Apache Log4j2
masshundreds of millions of Java applications/devices, with hundreds of thousands of internet-exposed services
CVE-2022-47966
Unauthenticated SAML RCE in Zoho ManageEngine On-Premise Products

CVE-2022-47966 is a critical (CVSS 9.8), unauthenticated remote code execution flaw in roughly two dozen Zoho ManageEngine on-premise products caused by their bundled Apache Santuario xmlsec (XML Security for Java) 1.4.1 library, in which the XSLT features leave security protections to the application and ManageEngine did not provide them. An attacker triggers the flaw by sending a crafted SAML response containing a malicious XSLT transform to the SAML single sign-on (SSO) endpoint; exploitation is only possible if SAML SSO has ever been configured for the product (for some products, SAML SSO must be currently active). Successful exploitation yields arbitrary code execution in the context of the affected ManageEngine application, typically full compromise of the server and a foothold into the wider enterprise network. Any organization running an affected product version with SAML SSO enabled is affected, with internet-exposed ITSM/identity-management servers the most likely targets. Exploitation is confirmed in the wild: the flaw is in CISA KEV with known ransomware use, Rapid7 reported broad attacker interest, North Korea's Lazarus Group used it to deploy QuiteRAT, and Iranian government-backed actors have targeted U.S. energy and transit-sector organizations.

Do: Apply vendor updates immediately, upgrading each installed product to at least the fixed version listed (e.g., ServiceDesk Plus 14004+, ADSelfService Plus 6211+, Endpoint Central/Endpoint Central MSP 10.1.2228.11+, Password Manager Pro 12124+, ServiceDesk Plus MSP 13001+, ADAudit Plus 7081+, ADManager Plus 7162+, AD360 4310+); this is a CISA KEV required action. As an interim mitigation, disable or restrict SAML SSO (or limit access to the product's SSO endpoints), since SAML SSO must have been configured for exploitation. Prioritize patching internet-exposed instances and review those servers for signs of compromise, given documented use by Lazarus Group, ransomware operators, and Iranian nation-state actors.

9.8100% KEV ransomware PoC ×6
  • zohocorp ManageEngine Access Manager Plus before 4308
  • zohocorp ManageEngine Active Directory 360 (AD360) before 4310
  • zohocorp ManageEngine ADAudit Plus before 7081
  • +9 more
largetens of thousands of installations plausibly affected (thousands of instances internet-exposed), out of ManageEngine's very large on-prem install base
CVE-2023-20198
Unauthenticated Privilege Escalation in Cisco IOS XE Web UI (Actively Exploited)

CVE-2023-20198 is a critical (CVSS 10.0) unauthenticated privilege escalation flaw in the web UI of Cisco IOS XE software, triggered by sending crafted network requests to the exposed web management interface. An attacker with no credentials can use the flaw to gain initial access and issue a privilege 15 command, creating a local user with normal login access; the attacker then chained CVE-2023-20273 (CVSS 7.2) to elevate that account to root and write an implant to the file system. Successful exploitation yields full administrative control of the device, including persistence via the planted implant, on Cisco IOS XE devices with the web UI enabled and reachable from the internet or untrusted networks, including Rockwell Automation Allen-Bradley Stratix 5200 and 5800 switches running IOS XE. Exploitation is confirmed in the wild: the flaw was added to CISA's KEV on 2023-10-16 with a BOD 23-02 directive, EPSS stands at 99.6% (100th percentile), and ongoing campaigns (including the 'BADCANDY' activity flagged by Australia's ASD and Cisco-related telecom intrusions attributed to Salt Typhoon) have been reported.

Do: Upgrade affected devices to the fixed releases listed in Cisco's advisory (use Cisco's Software Checker) and, as immediate mitigation, disable the web UI or restrict it to trusted networks/addresses only. Check for compromise by looking for unexpected local user accounts and the implant artifacts Cisco identified (unexpected cisco_tac_alarm.log and cisco_tac.log files in /tmp or /usr/binos/conf), and immediately report positive findings to CISA per BOD 23-02. Keep in mind that patching alone does not remove a root implant, so devices with evidence of compromise should be reimaged or otherwise cleaned per vendor instructions.

10.0100% KEV
  • Cisco IOS XE (Web UI feature)
  • Rockwell Automation Allen-Bradley Stratix 5200 firmware
  • Rockwell Automation Allen-Bradley Stratix 5800 firmware
large≈40,000–50,000 internet-exposed IOS XE devices at the time of disclosure (public scan data), within an IOS XE install base in the millions
CVE-2023-20273
Authenticated Command Injection (Root) in Cisco IOS XE Web UI

CVE-2023-20273 is an OS command injection flaw (CWE-78) in the web UI feature of Cisco IOS XE Software, caused by insufficient input validation. An authenticated, remote attacker triggers it by sending crafted input to the web UI, and a successful exploit injects commands that run on the underlying operating system with root privileges, yielding full device compromise (in the October 2023 mass-exploitation campaign it was typically chained with the unauthenticated CVE-2023-20198 to obtain initial access and install a persistent implant). Any Cisco IOS XE device with the web UI enabled and reachable from the internet or an untrusted network is affected; this data does not specify the affected release ranges, which are enumerated in Cisco's advisory. Exploitation is confirmed in the wild: CISA added the flaw to the KEV on 2023-10-23 with BOD 23-02 response actions, EPSS is ~90% (100th percentile), and IOS XE edge devices remain recurring targets of Chinese-nexus espionage campaigns (e.g., Salt Typhoon activity against telecoms).

Do: Upgrade affected devices to a fixed IOS XE release per Cisco's advisory; as an interim mitigation, disable the HTTP/HTTPS server (ip http server / ip https server) or restrict Web UI access to trusted hosts only. Per BOD 23-02, hunt for compromise on any exposed device — check for unexpected level-15 local accounts and the implant.lua backdoor in flash memory — and immediately report positive findings to CISA.

7.290% KEV
  • Cisco IOS XE Software (Web UI feature)
mass≈100,000+ internet-exposed IOS XE devices (public scans observed ~40,000+ compromised within days of disclosure)
CVE-2023-22515
Unauthenticated Broken Access Control in Atlassian Confluence Data Center/Server

Atlassian Confluence Data Center and Server contain a broken access control flaw (CWE-20) in publicly accessible instances that allows unauthenticated remote attackers to create unauthorized Confluence administrator accounts and gain access to the instance; the associated public PoC is titled 'Atlassian Confluence Unauthenticated Remote Code Execution'. The flaw is triggered over the network (CVSS 3.1 9.8, AV:N/AC:L/PR:N/UI:N) against any self-managed Confluence instance reachable from the internet, with no privileges or user interaction required. Attackers who exploit it gain administrator-level control of the Confluence instance, and the public PoC demonstrates this extends to unauthenticated code execution. Only self-managed Confluence Data Center and Server deployments are affected; Atlassian Cloud sites hosted on atlassian.net domains are not vulnerable. Exploitation is confirmed in the wild: CISA added it to the KEV on 2023-10-05 with known ransomware use, EPSS is 99.2%, Atlassian reported a handful of customers were already exploited, and Microsoft warned of nation-state (China-linked) abuse.

Do: Patch all internet-facing Confluence Data Center and Server instances to a fixed release per Atlassian's advisory (specific fixed versions are not listed in this data), or restrict public access/discontinue use per CISA's required action. Audit every affected instance for evidence of compromise, especially unauthorized administrator accounts created through this flaw, and report positive findings to CISA. Treat this as urgent given active exploitation by both nation-state actors and ransomware groups.

9.899% KEV ransomware PoC
  • Atlassian Confluence Data Center
  • Atlassian Confluence Server
large≈ tens of thousands of internet-exposed Confluence Data Center/Server instances (order of ~30,000-50,000)
CVE-2023-23397
Zero-Click Elevation of Privilege in Microsoft Outlook (Forced NTLM Credential Leak)

CVE-2023-23397 is an elevation of privilege vulnerability in Microsoft Outlook caused by improper input validation (CWE-20) combined with authentication bypass via spoofed authentication data on the channel (CWE-294), allowing an attacker to force Outlook to authenticate to an attacker-controlled SMB/WebDAV server. It is triggered when Outlook processes a crafted email or calendar object — for example a meeting or task reminder whose sound property points to an attacker-supplied UNC path — and requires no user interaction. That authentication exchange leaks the victim's NTLM credential hash, which the attacker can crack offline or relay to authenticate as the victim and access resources such as Exchange mailboxes, effectively escalating privileges. Affected software spans Microsoft 365 Apps, Microsoft Office (including the Long Term Servicing Channel), and Microsoft Outlook, which are deployed across enterprises, governments, and militaries worldwide. It is actively exploited in the wild — added to CISA's Known Exploited Vulnerabilities catalog on 2023-03-14 with a 97.4% EPSS — and Microsoft has warned of exploitation by Russia-aligned threat actors in campaigns against government and military mail servers, with patches shipped in Microsoft's March 2023 security updates.

Do: Apply Microsoft's March 2023 security updates to Microsoft 365 Apps, Office/LTSC, and Outlook immediately, per CISA's required action. As interim mitigation, enable Extended Protection for Authentication or add accounts to the Protected Users group to block the NTLM credential leak, and audit calendar and task reminder sound properties for UNC paths (Microsoft published an audit/cleanup script for this) while watching for unexpected outbound SMB/WebDAV connections from hosts running Outlook.

9.897% KEV
  • Microsoft 365 Apps Affected builds as covered by Microsoft's March 2023 security updates; see Microsoft advisory for exact build ranges
  • Microsoft Office Affected builds as covered by Microsoft's March 2023 security updates; see Microsoft advisory for exact build ranges
  • Microsoft Office Long Term Servicing Channel (LTSC) Affected builds as covered by Microsoft's March 2023 security updates; see Microsoft advisory for exact build ranges
  • +1 more
masson the order of hundreds of millions of users (Outlook ships with Microsoft Office/Microsoft 365, the dominant enterprise and government email suite)
CVE-2023-27350
Authentication Bypass Leading to SYSTEM RCE in PaperCut MF/NG

PaperCut MF and PaperCut NG print management software contain an improper access control flaw (CWE-284) in the SetupCompleted class that allows an unauthenticated attacker to bypass authentication and reach internal administrative functionality. The flaw is triggered by sending crafted, unauthenticated requests to the PaperCut application's web interface, without requiring valid user credentials. A successful attacker gains the ability to execute code in the context of the SYSTEM account on the PaperCut server, typically a Windows print server, giving full control of that host. Any organization running PaperCut MF or NG is potentially affected, and exposure is highest where the server's web interface is reachable from the internet or by untrusted networks. Exploitation is confirmed in the wild: CISA added the flaw to the KEV on 2023-04-21 with known ransomware use, and EPSS rates exploitation probability at 100% within 30 days.

Do: Apply the vendor's updates as instructed (this is the required action in CISA KEV) — upgrade PaperCut MF/NG to the patched releases listed in PaperCut's security advisory rather than relying on unpatched installs. Until patched, restrict network access to the PaperCut web/admin interface so it is reachable only from trusted hosts, and check the server for signs of compromise given known ransomware use. Prioritize internet-facing PaperCut servers, which public scans show are exposed in the thousands.

9.8100% KEV ransomware PoC ×3
  • PaperCut MF
  • PaperCut NG
masstens of thousands of organizations (~70k+) and millions of users; thousands of internet-exposed PaperCut servers
CVE-2023-27997
Pre-Auth Heap Buffer Overflow RCE in Fortinet FortiOS/FortiProxy SSL-VPN

CVE-2023-27997 is a heap-based buffer overflow (CWE-122, with associated out-of-bounds write CWE-787) in the SSL-VPN component of Fortinet FortiOS and FortiProxy, reachable by unauthenticated users. A remote attacker can trigger it with specially crafted requests to the SSL-VPN web interface, gaining the ability to execute arbitrary code or commands on the gateway. Full control of an edge VPN/firewall appliance enables credential theft, session hijacking, and pivoting into the protected network, which makes the bug attractive to ransomware operators. Any organization exposing the SSL-VPN portal on the affected FortiOS builds (7.2.4 and below, 7.0.11 and below, 6.4.12 and below, 6.0.16 and below) or FortiProxy builds (7.2.3 and below, 7.0.9 and below, 2.0.12 and below, and 1.1/1.2 all versions) is potentially exposed. The flaw is under active exploitation: CISA added it to the KEV on 2023-06-13 with known ransomware use, EPSS estimates an ~86% probability of exploitation within 30 days (100th percentile), and reporting indicates it was likely being exploited in the wild, with Fortinet also warning that some attackers retained access to FortiGate devices even after patching.

Do: Apply Fortinet's updates to all SSL-VPN-enabled FortiOS and FortiProxy appliances as required by the CISA KEV listing, upgrading each affected branch beyond the listed versions (end-of-life FortiProxy 1.1/1.2 requires migration to a supported release); if SSL-VPN is not needed, disable the web portal or restrict it to trusted source addresses. After patching, hunt for signs of compromise and rotate credentials and VPN-related secrets, since Fortinet warned that some attackers retained access to FortiGate devices post-patching.

9.886% KEV ransomware
  • Fortinet FortiOS (SSL-VPN) 7.2.4 and below; 7.0.11 and below; 6.4.12 and below; 6.0.16 and below
  • Fortinet FortiProxy (SSL-VPN) 7.2.3 and below; 7.0.9 and below; 2.0.12 and below; 1.2 (all versions); 1.1 (all versions)
masson the order of several hundred thousand internet-exposed SSL-VPN endpoints (≈300k–500k per public scans)
CVE-2023-31241
+2 in the same advisory: …28386 …28649
Snap One OvrC cloud servers contain a route an attacker can use to bypass requirements and claim devices outright.

Snap One OvrC cloud servers contain a route an attacker can use to bypass requirements and claim devices outright.

NVD description · AI analysis pending
10.0
group max
<1%
  • snapone orvc
CVE-2023-2868
Unauthenticated Command Injection in Barracuda Email Security Gateway Appliances via .tar Files

CVE-2023-2868 is a critical (CVSS 9.8) remote command injection vulnerability in the Barracuda Email Security Gateway (ESG) appliance form factor (models 300, 400, 600, 800 and 900), caused by incomplete input validation of user-supplied .tar archives, specifically the names of the files contained within them. An attacker can deliver a specially crafted .tar file whose internal file names are formatted so that, when the ESG processes the archive, commands are executed through Perl's qx operator. Successful exploitation yields remote command execution with the privileges of the ESG product, and in the observed campaign attackers deployed a backdoor (reported as "SUBMARINE") and persisted on compromised appliances. Only customers running ESG appliances on versions 5.1.3.001 through 9.2.0.006 are affected. Exploitation is confirmed in the wild — CISA added it to the KEV on 2023-05-26, EPSS puts 30-day exploitation probability at 87.7%, and public reporting attributes active exploitation to a Chinese-nexus espionage group (associated in headlines with Salt Typhoon) targeting government, military, and telecom victims; Barracuda's BNSF-36456 patch was applied automatically to customer appliances.

Do: Verify that each ESG appliance received the automatic BNSF-36456 patch (running fixed firmware at or above 9.2.0.006's successor per vendor instructions), and check appliances for indicators of compromise, including unauthorized command activity and the "SUBMARINE" backdoor, using Barracuda's IOC guidance. Because the espionage campaign established persistence, Barracuda urged full replacement rather than patching of compromised appliances; replace any ESG showing signs of compromise and review email logs for malicious .tar attachments. Limit or monitor internet exposure of ESG management interfaces while remediation proceeds.

9.888% KEV
  • Barracuda Networks Email Security Gateway (ESG) 300 firmware (appliance form factor) 5.1.3.001 – 9.2.0.006
  • Barracuda Networks Email Security Gateway (ESG) 400 firmware (appliance form factor) 5.1.3.001 – 9.2.0.006
  • Barracuda Networks Email Security Gateway (ESG) 600 firmware (appliance form factor) 5.1.3.001 – 9.2.0.006
  • +2 more
largetens of thousands of deployed ESG appliances (public scans show Barracuda ESGs among commonly internet-exposed email security devices); Barracuda's incident…
CVE-2023-34362
Unauthenticated SQL Injection in Progress MOVEit Transfer

CVE-2023-34362 is an unauthenticated SQL injection flaw (CWE-89) in Progress MOVEit Transfer that allows an attacker with no credentials to gain unauthorized access to the product's database. It is triggered remotely via crafted input submitted to the MOVEit Transfer web application, with the impact varying by the backend database engine in use (MySQL, Microsoft SQL Server, or Azure SQL). A successful attacker can infer the structure and contents of the database and, depending on the engine, execute SQL statements that alter or delete database elements, exposing data handled by the file-transfer service. Any organization running an internet-reachable MOVEit Transfer instance is affected; public internet-exposure scans around disclosure identified on the order of a few thousand servers, each typically serving enterprise or government user bases. Exploitation is confirmed in the wild: the flaw was added to CISA KEV on 2023-06-02 with known ransomware use and an EPSS exploitation probability of 99.9% (100th percentile), while no public PoC is known.

Do: Apply the vendor's updates immediately, per Progress instructions and CISA's required action. Until patched, restrict internet exposure of MOVEit Transfer and check the backend database for unexpected structure or content changes and deletions. Because in-the-wild exploitation and ransomware use are confirmed, treat any unpatched, internet-facing instance as potentially compromised and review stored transfer data and access logs for anomalies.

9.8100% KEV ransomware PoC
  • Progress MOVEit Transfer
large≈2,000-3,000 internet-exposed MOVEit Transfer servers (public internet-exposure scans)
CVE-2023-3519
Unauthenticated RCE in Citrix NetScaler ADC and NetScaler Gateway

CVE-2023-3519 is a critical (CVSS 9.8) unauthenticated remote code execution flaw caused by improper code-injection handling (CWE-94) in Citrix NetScaler ADC and NetScaler Gateway. A remote attacker with no credentials can trigger it by sending crafted requests to an appliance configured as a Gateway (VPN/ICA proxy/RDP proxy) or AAA authentication virtual server, gaining arbitrary code execution on the appliance. Exploitation typically yields a foothold behind the VPN edge — access to internal networks, credential theft, and follow-on activity such as espionage or ransomware deployment. Any organization running unpatched NetScaler ADC/Gateway appliances, especially internet-facing remote-access endpoints, is affected; NetScaler is one of the most widely deployed enterprise VPN/ADC platforms. Exploitation is confirmed in the wild: the flaw was added to CISA's KEV on 2023-07-19 with known ransomware use, EPSS estimates a 99.7% exploitation probability, and researchers have linked activity to China-nexus espionage (Silk Typhoon) and ransomware operations.

Do: Immediately upgrade internet-facing NetScaler ADC/Gateway appliances to the fixed builds in Citrix's advisory (14.1-8.50+, 13.1-49.13+, 13.0-82.45+, 12.1-55.300+, including FIPS/NDcPP equivalents) — per CISA KEV, apply these mitigations or discontinue use if patching is unavailable. Confirm whether each appliance is configured as a Gateway or AAA virtual server (only those are affected), and hunt for compromise — unexpected configuration changes, unfamiliar accounts, webshells, or anomalous VPN sessions — rotating credentials on any suspected compromise.

9.8100% KEV ransomware PoC
  • Citrix NetScaler ADC Supported releases before the July 2023 fixes, per Citrix advisory: 14.1 before 14.1-8.50; 13.1 before 13.1-49.13; 13.0 before 13.0-82.45; 12.1 before 12.1-55.3
  • Citrix NetScaler Gateway Same affected builds as NetScaler ADC (before 14.1-8.50, 13.1-49.13, 13.0-82.45, 12.1-55.300, and FIPS/NDcPP equivalents); affected when the appliance serves as
largetens of thousands of internet-exposed NetScaler Gateway/ADC appliances (order 10k-100k at disclosure), serving hundreds of thousands to millions of downstream…
CVE-2023-42793
Authentication bypass in JetBrains TeamCity enables unauthenticated RCE

JetBrains TeamCity Server, a widely used CI/CD build server, contains an authentication bypass vulnerability (CWE-288) that lets a remote, unauthenticated attacker gain administrative access without valid credentials. By sending crafted requests to the TeamCity server over the network, the attacker bypasses authentication and can then execute arbitrary code on the server via administrative and build features, achieving full remote code execution. An attacker gains control of the build server and, with it, access to source code, build artifacts, stored secrets and credentials, and a foothold for lateral movement or ransomware deployment. Any organization running an affected TeamCity Server is affected, especially instances reachable from the internet. Exploitation is confirmed in the wild: CISA added the flaw to its KEV catalog on 2023-10-04 with known ransomware use, and EPSS assigns a 100% probability of exploitation within 30 days.

Do: Upgrade TeamCity Server to 2023.05.4 or later per JetBrains' instructions, or apply vendor mitigations or discontinue use if patching is not possible (per the CISA KEV required action). Also take unpatched instances off the public internet, and hunt for signs of compromise such as unauthorized administrator accounts, unexpected changes in audit logs and build configurations, and stored secrets or tokens that may have been stolen, given known ransomware exploitation.

9.8100% KEV ransomware PoC ×2
  • JetBrains TeamCity (TeamCity Server) On-premises TeamCity Server prior to the fixed release (2023.05.4 per the vendor advisory); the CISA entry lists the affected product without a version range
largeTens of thousands of TeamCity Server deployments, of which several thousand are internet-exposed
CVE-2023-49103
Unauthenticated phpinfo credential leak in ownCloud graphapi

CVE-2023-49103 is an unauthenticated information disclosure flaw in ownCloud's graphapi app (0.2.x before 0.2.1 and 0.3.x before 0.3.1), which ships a third-party GetPhpInfo.php page that returns the full PHP phpinfo output when its URL is requested. An attacker with no credentials or user interaction simply accesses that URL over the network, and the phpinfo output reveals all of the webserver's environment variables plus other potentially sensitive configuration details. In containerized deployments these environment variables frequently include the ownCloud admin password, mail server credentials, and license key, giving attackers direct credentials for the server; notably, disabling the graphapi app does not remove the exposed file. Affected deployments are ownCloud installations running the vulnerable graphapi versions, especially ownCloud Docker images built after February 2023, while containers built before February 2023 are not vulnerable to the credential disclosure. Exploitation is confirmed in the wild: CISA added it to the Known Exploited Vulnerabilities catalog on 2023-11-30, the EPSS score is 78.4% (top percentile), and public reporting says threat actors have begun exploiting the flaw, though no public PoC is known.

Do: Upgrade the graphapi app to version 0.2.1 or 0.3.1, and note that simply disabling the app is not sufficient — ensure the GetPhpInfo.php file is removed per vendor instructions. Operators of containerized ownCloud deployments (Docker images from February 2023 onward) should assume the ownCloud admin password, mail server credentials, and license key were exposed, rotate them, and review web logs for requests to the GetPhpInfo.php URL. CISA KEV requires applying vendor mitigations or discontinuing use of the product if mitigations are unavailable.

7.578% KEV
  • ownCloud graphapi (graphapi app) 0.2.x before 0.2.1; 0.3.x before 0.3.1
largeTens of thousands of internet-exposed ownCloud instances (order of magnitude 10k–100k), within a self-hosted user base in the millions
CVE-2023-4966
Info-Disclosure Buffer Overflow (CitrixBleed) in Citrix NetScaler ADC/Gateway

Citrix NetScaler ADC and NetScaler Gateway appliances contain a buffer overflow (CWE-119) that leaks sensitive information from device memory when the appliance is configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, or RDP Proxy) or as an AAA virtual server. A remote attacker who can reach such a configuration can trigger the overflow and read memory contents, harvesting sensitive data such as session tokens (a technique that enables session hijacking which can bypass multi-factor authentication). Any organization running an affected NetScaler ADC or Gateway appliance in these configurations is exposed, with appliances deployed as VPN or access gateways being the primary concern. Exploitation is confirmed in the wild: the flaw was added to CISA's KEV catalog on 2023-10-18 with known ransomware use and a 100% EPSS exploitation probability, although no public proof-of-concept is known at this time. Because tokens stolen from memory can remain valid even after patching, responders must terminate all active and persistent sessions as part of remediation.

Do: Upgrade affected appliances to the patched builds cited in Citrix's advisory, then immediately kill all active and persistent ICA/AAA sessions per the vendor instructions, since patching alone does not invalidate session tokens attackers may have already stolen. If patching is not immediately possible, discontinue use of the affected Gateway/AAA configurations as CISA directs. Given known ransomware abuse, also hunt for signs of exploitation such as logins from unexpected sources, anomalous session reuse, or suspicious mailbox changes, and reset credentials for potentially exposed accounts.

7.5100% KEV ransomware
  • Citrix NetScaler ADC and NetScaler Gateway
masshundreds of thousands of internet-exposed NetScaler ADC/Gateway appliances (public internet scan counts), plus an unknown number of VPN-only or internal…
CVE-2024-10470
Unauthenticated File Read/Deletion Leading to RCE in WPLMS WordPress Theme

CVE-2024-10470 is a path traversal flaw (CWE-22) in the WPLMS Learning Management System theme for WordPress by vibethemes, where the readfile and unlink functions lack sufficient file path validation and permission checks. An unauthenticated attacker can send network requests that reach these functions to read arbitrary files on the server and, more critically, delete arbitrary files. Deleting the right file, such as wp-config.php, can easily lead to remote code execution, while file reads can expose sensitive server contents. All versions up to and including 4.962 are affected, and the theme remains vulnerable even when it is installed but not activated, so exposure extends beyond actively used installations. No public proof-of-concept or confirmed in-the-wild exploitation is known yet, but EPSS assigns a 34.4% probability of exploitation within 30 days (98th percentile), making this a high-priority patch.

Do: Update WPLMS to a patched version newer than 4.962 as soon as one is available. Audit every WordPress installation that has the theme installed, including sites where the theme is inactive, and remove or update unused copies. Until patched, monitor logs for unauthenticated requests triggering file read/delete operations and watch for unexpected deletions of critical files such as wp-config.php.

9.834%
  • vibethemes WPLMS Learning Management System (WordPress LMS theme) all versions up to and including 4.962
large≈ tens of thousands of WordPress sites
CVE-2024-10924
Unauthenticated Authentication Bypass in Really Simple Security WordPress Plugin

CVE-2024-10924 is a critical (CVSS 9.8) unauthenticated authentication bypass in the Really Simple Security plugin for WordPress (Free, Pro, and Pro Multisite editions), affecting versions 9.0.0 through 9.1.1.1. It stems from improper user check error handling in the 'check_login_and_get_user' function used by the two-factor REST API actions, and can be triggered when the plugin's 'Two-Factor Authentication' setting is enabled (it is disabled by default). An unauthenticated attacker can exploit it to log in as any existing user on the site, including an administrator, gaining full control of the affected WordPress site. Any WordPress site running one of the affected plugin versions with two-factor authentication turned on is exposed, and public reporting indicates the plugin is installed on more than 4 million sites. As of the latest data there is no confirmed in-the-wild exploitation, no public proof-of-concept, and it is not in CISA's KEV catalog, but EPSS assigns an 82% probability of exploitation within the next 30 days (99th+ percentile), so rapid patching is warranted.

Do: Update the Really Simple Security plugin to a fixed release (any version after 9.1.1.1) on all Free, Pro, and Pro Multisite installations. As an interim mitigation, disable the 'Two-Factor Authentication' setting or restrict access to the WordPress REST API until patched. After updating, review recent authentication logs and administrator accounts for signs of unauthorized logins.

9.882%
  • really-simple-plugins Really Simple Security (Free) WordPress plugin 9.0.0 through 9.1.1.1 (inclusive)
  • really-simple-plugins Really Simple Security (Pro) WordPress plugin 9.0.0 through 9.1.1.1 (inclusive)
  • really-simple-plugins Really Simple Security (Pro Multisite) WordPress plugin 9.0.0 through 9.1.1.1 (inclusive)
mass≈4,000,000+ WordPress sites install the plugin, though only the subset with Two-Factor Authentication enabled is directly exploitable
CVE-2024-10979
Incorrect control of environment variables in PostgreSQL PL/Perl allows an unprivileged database user to change sensitive process environment variables (e.g.

Incorrect control of environment variables in PostgreSQL PL/Perl allows an unprivileged database user to change sensitive process environment variables (e.g. PATH). That often suffices to enable arbitrary code execution, even if the attacker lacks a database server operating system user. Versions before PostgreSQL 17.1, 16.5, 15.9, 14.14, 13.17, and 12.21 are affected.

NVD description · AI analysis pending
8.84% PoC
  • postgresql postgresql
CVE-2024-11120
Unauthenticated OS Command Injection in GeoVision Devices

Multiple GeoVision devices contain an unauthenticated OS command injection flaw (CWE-78) that allows a remote attacker to inject and execute arbitrary system commands on the device. Because no authentication is required, any party that can reach an affected device's network services can trigger the flaw with crafted input; no public proof-of-concept is known. Successful exploitation gives the attacker remote command execution on the device, which can be used to compromise surveillance infrastructure or pivot into connected networks. Organizations running GeoVision devices are affected, and CISA notes the impacted products may be end-of-life (EoL) and/or end-of-service (EoS), meaning some may no longer receive fixes. The vulnerability was added to the CISA Known Exploited Vulnerabilities catalog on 2025-05-07, confirming exploitation in the wild; EPSS estimates a 28.4% probability of exploitation in the next 30 days (98th percentile), and ransomware use is not yet confirmed.

Do: Inventory all GeoVision devices (including EoL/EoS models) and consult the vendor advisory for affected models and any available firmware mitigations or patches. Restrict internet exposure of GeoVision devices while remediating (firewall rules/ACLs, remove direct port forwarding), and replace or retire EoL/EoS units if the vendor offers no mitigation. Because the flaw is confirmed exploited in the wild, check devices for signs of compromise and unusual outbound traffic.

9.828% KEV PoC
  • GeoVision
largeon the order of tens of thousands of internet-exposed GeoVision devices, with a larger legacy installed base
CVE-2024-49039
+1 in the same advisory: …43451
Windows Task Scheduler Elevation-of-Privilege Flaw Actively Exploited in the Wild

CVE-2024-49039 is an elevation-of-privilege vulnerability (CWE-287, improper authentication) in the Microsoft Windows Task Scheduler, scored 8.8 (High) with a local attack vector, low required privileges, and a changed scope indicating the exploit crosses a security boundary. A local attacker with limited user privileges can trigger the flaw through Task Scheduler to gain elevated rights on the affected system, typically SYSTEM- or administrator-level control, with no user interaction required. Every supported Windows desktop and server release in the vendor's affected list is impacted, since Task Scheduler is a core component of the operating system. The flaw was patched as an actively exploited zero-day in the November 2024 Patch Tuesday release, was added to CISA's Known Exploited Vulnerabilities catalog on 2024-11-12, and ransomware operators are known to use it. With an EPSS of 14.2% (96th percentile), defenders should treat this as a high-priority local privilege escalation for privilege-chaining and ransomware campaigns.

Do: Apply the November 2024 Windows security updates across all affected Windows 10, Windows 11, and Windows Server branches, prioritizing servers, jump hosts, and machines used by privileged users given confirmed ransomware use. Confirm no supported Windows host is left unpatched, review local task creation and authentication logs for signs of privilege escalation, and follow CISA's required action to apply vendor mitigations or discontinue use if patches are unavailable.

8.8
group max
14% KEV ransomware
  • Microsoft Windows 10 1507
  • Microsoft Windows 10 1607
  • Microsoft Windows 10 1809
  • +9 more
masshundreds of millions of Windows systems (Task Scheduler ships with every Windows 10, Windows 11, and Windows Server installation)
CVE-2024-47574
A authentication bypass using an alternate path or channel in Fortinet FortiClientWindows version 7.4.0, versions 7.2.4 through 7.2.0, versions 7.0.12 through 7

A authentication bypass using an alternate path or channel in Fortinet FortiClientWindows version 7.4.0, versions 7.2.4 through 7.2.0, versions 7.0.12 through 7.0.0, and 6.4.10 through 6.4.0 allows low privilege attacker to execute arbitrary code with high privilege via spoofed named pipe messages.

NVD description · AI analysis pending
7.8<1%
  • fortinet forticlient
CVE-2024-50381
A vulnerability exists in Snap One OVRC cloud where an attacker can impersonate a Hub device and send requests to claim and unclaim devices.

A vulnerability exists in Snap One OVRC cloud where an attacker can impersonate a Hub device and send requests to claim and unclaim devices. The attacker only needs to provide the MAC address of the targeted device and can make a request to unclaim it from its original connection and make a request to claim it.

NVD description · AI analysis pending
8.8<1%
CVE-2024-5910
Unauthenticated Admin Account Takeover in Palo Alto Networks Expedition

CVE-2024-5910 is a missing authentication flaw (CWE-306) in Palo Alto Networks Expedition, a tool used to migrate, tune, and enrich firewall configurations. An attacker with network access to an Expedition instance can exploit the unauthenticated critical function to take over the Expedition admin account without any credentials. Once in control, the attacker can access configuration secrets, credentials, and other data imported into Expedition, and public research (horizon3.ai) shows it can be chained with other Expedition bugs for full system compromise. Any organization running Expedition — particularly instances reachable from the internet or shared networks — is affected. The flaw is actively exploited: it was added to CISA's Known Exploited Vulnerabilities catalog on 2024-11-07, carries a 91.8% EPSS exploitation probability, and is being exploited alongside related Expedition and firewall bugs (CVE-2024-9463, CVE-2024-9465).

Do: Apply the vendor's patched Expedition release per Palo Alto Networks' advisory; if the tool is no longer needed, decommission or discontinue it, as CISA permits. Until patched, restrict network access to Expedition to trusted management hosts and remove it from internet exposure. Check Expedition logs for signs of unauthorized admin access and rotate any credentials or secrets stored in the tool.

9.392% KEV PoC
  • Palo Alto Networks Expedition
nichelikely low thousands of deployments worldwide; unknown for internet-exposed instances
CVE-2024-7340
The Weave server API allows remote users to fetch files from a specific directory, but due to a lack of input validation, it is possible to traverse and leak ar

The Weave server API allows remote users to fetch files from a specific directory, but due to a lack of input validation, it is possible to traverse and leak arbitrary files remotely. In various common scenarios, this allows a low-privileged user to assume the role of the server admin.

NVD description · AI analysis pending
8.85%
CVE-2024-8069
+1 in the same advisory: …8068
Insecure Deserialization RCE in Citrix Session Recording

CVE-2024-8069 is a deserialization of untrusted data flaw (CWE-502) in Citrix Session Recording that permits limited remote code execution running with Network Service account privileges. It is triggered when an authenticated user on the same intranet as the Session Recording server sends maliciously crafted serialized data to the server, so it does not require internet exposure or unauthenticated access. A successful attacker gains code execution on the Session Recording server with Network Service–level privileges, a limited but useful foothold for lateral movement. Only organizations that have deployed the Session Recording component of Citrix Virtual Apps and Desktops are affected. CISA added the flaw to the Known Exploited Vulnerabilities catalog on 2025-08-25, confirming exploitation in the wild, and EPSS estimates a 14.6% chance of exploitation in the next 30 days (96th percentile).

Do: Upgrade Citrix Session Recording to the patched releases listed in Citrix's security bulletin, and first confirm whether the optional Session Recording component is actually installed in your Virtual Apps and Desktops environment, since many deployments omit it. Restrict network access to Session Recording servers to trusted, authenticated intranet users, and apply CISA BOD 22-01 remediation deadlines if you are a federal agency.

5.115% KEV
  • Citrix Session Recording
moderate≈10,000 server deployments (order of magnitude) among enterprises running Citrix Virtual Apps and Desktops
CVE-2024-9463
+1 in the same advisory: …9465
Unauthenticated OS Command Injection in Palo Alto Networks Expedition

CVE-2024-9463 is a critical (CVSS 4.0: 9.9) OS command injection flaw (CWE-78) in Palo Alto Networks Expedition, the vendor's on-premises migration and firewall-management tool. An unauthenticated, network-adjacent attacker can send crafted input to trigger arbitrary operating system command execution with root privileges, requiring no credentials or user interaction. A successful compromise exposes the sensitive data Expedition holds for managed PAN-OS firewalls, including usernames, cleartext passwords, device configurations, and device API keys, which can enable follow-on attacks against the firewalls themselves. Any organization running an Expedition deployment, typically as a management appliance that is sometimes reachable from the internet, is affected. Exploitation is confirmed in the wild: Palo Alto Networks confirmed active exploitation (reported alongside SQL injection flaw CVE-2024-9465), CISA added it to the Known Exploited Vulnerabilities catalog on 2024-11-14, and EPSS assigns a 98.5% probability of exploitation within 30 days.

Do: Upgrade Expedition to the vendor-fixed release per Palo Alto Networks' advisory, and remove or restrict internet exposure of the Expedition web interface; if patching is not immediately possible, CISA's required action is to apply vendor mitigations or discontinue use of the product. Because exploitation can disclose cleartext firewall usernames, passwords, and API keys, rotate those credentials and review firewall configurations and Expedition logs for signs of compromise, particularly given confirmed active exploitation alongside CVE-2024-9465.

9.9
group max
99% KEV
  • Palo Alto Networks Expedition
nichelikely in the low thousands of on-premises deployments worldwide, with public scans showing only on the order of hundreds of internet-exposed instances
Full article2,229 words · extracted from thehackernews.com · click to collapse

Ravie LakshmananNov 18, 2024Cybersecurity / Infosec

What do hijacked websites, fake job offers, and sneaky ransomware have in common? They’re proof that cybercriminals are finding smarter, sneakier ways to exploit both systems and people.

This week makes one thing clear: no system, no person, no organization is truly off-limits. Attackers are getting smarter, faster, and more creative—using everything from human trust to hidden flaws in technology. The real question is: are you ready?

💪 Every attack holds a lesson, and every lesson is an opportunity to strengthen your defenses. This isn’t just news—it’s your guide to staying safe in a world where cyber threats are everywhere. Let’s dive in.

⚡ Threat of the Week

Palo Alto Networks Warns of Zero-Day: A remote code execution flaw in the Palo Alto Networks PAN-OS firewall management interface is the newest zero-day to be actively exploited in the wild. The company began warning about potential exploitation concerns on November 8, 2024. It has since been confirmed that it has been weaponized in limited attacks to deploy a web shell. The critical vulnerability has no patches as yet, which makes it all the more crucial that organizations limit management interface access to trusted IP addresses. The development comes as three different critical flaws in Palo Alto Networks Expedition (CVE-2024-5910, CVE-2024-9463, and CVE-2024-9465) have also seen active exploitation attempts. Details are sparse on who is exploiting them and the scale of the attacks.

SANS Cyber Defense Initiative 2024 SANS Cyber Defense Initiative 2024

8 Benefits of a Backup Service for Microsoft 365

Modernize your data protection solutions with an as-a-service solution. Read this e‑book, “8 Benefits of a Backup Service for Microsoft 365”, to understand what makes cloud‑based backup services so appealing for companies using Microsoft 365 — and why it may be just the thing to keep your business running.

Download NOW

🔔 Top News

  • BrazenBamboo Exploits Unpatched Fortinet Flaw: A threat-actor known as BrazenBamboo has exploited an unresolved security flaw in Fortinet's FortiClient for Windows to extract VPN credentials as part of a modular framework called DEEPDATA. Volexity described BrazenBamboo as the developer of three distinct malware families DEEPDATA, DEEPPOST, and LightSpy, and not necessarily one of the operators using them. BlackBerry, which also detailed DEEPDATA, said it has been put to use by the China-linked APT41 actor.
  • About 70,000 Domains Hijacked by Sitting Ducks Attack: Multiple threat actors have been found taking advantage of an attack technique called Sitting Ducks to hijack legitimate domains for using them in phishing attacks and investment fraud schemes for years. Sitting Ducks exploits misconfigurations in a web domain's domain name system (DNS) settings to take control of it. Of the nearly 800,000 vulnerable registered domains over the past three months, approximately 9% (70,000) have been subsequently hijacked.
  • Got a Dream Job Offer on LinkedIn? It May Be Iranian Hackers: The Iranian threat actor known as TA455 is targeting LinkedIn users with enticing job offers intended to trick them into running a Windows-based malware named SnailResin. The attacks have been observed targeting the aerospace, aviation, and defense industries since at least September 2023. Interestingly, the tactics overlap with that of the notorious North Korea-based Lazarus Group.
  • WIRTE Targets Israel With SameCoin Wiper: WIRTE, a Middle Eastern threat actor affiliated with Hamas, has orchestrated cyber espionage operations against the Palestinian Authority, Jordan, Iraq, Saudi Arabia, and Egypt, as well as carried out disruptive attacks that exclusively target Israeli entities using SameCoin wiper. The destructive operations were first flagged at the start of the year.
  • ShrinkLocker Decryptor Released: Romanian cybersecurity company Bitdefender has released a free decryptor to help victims recover data encrypted using the ShrinkLocker ransomware. First identified earlier this year, ShrinkLocker is notable for its abuse of Microsoft's BitLocker utility for encrypting files as part of extortion attacks targeting entities in Mexico, Indonesia, and Jordan.

🔥 Trending CVEs

Recent cybersecurity developments have highlighted several critical vulnerabilities, including: CVE-2024-10924, CVE-2024-10470, CVE-2024-10979, CVE-2024-9463, CVE-2024-9465, CVE-2024-43451, CVE-2024-49039, CVE-2024-8068, CVE-2024-8069, CVE-2023-28649, CVE-2023-31241, CVE-2023-28386, CVE-2024-50381, CVE-2024-7340, and CVE-2024-47574. These security flaws are serious and could put both companies and regular people at risk. To stay safe, everyone needs to keep their software updated, upgrade their systems, and constantly watch out for threats.

📰 Around the Cyber World

  • The Top Routinely Exploited Vulnerabilities of 2023 Revealed: Cybersecurity agencies from the Five Eyes nations, Australia, Canada, New Zealand, the U.K., and the U.S., have released the list of top 15 vulnerabilities threat actors have been observed routinely exploiting in 2023. This includes security flaws from Citrix NetScaler (CVE-2023-3519, CVE-2023-4966), Cisco (CVE-2023-20198, CVE-2023-20273), Fortinet (CVE-2023-27997), Progress MOVEit Transfer (CVE-2023-34362), Atlassian (CVE-2023-22515), Apache Log4j (CVE-2021-44228), Barracuda Networks ESG (CVE-2023-2868), Zoho ManageEngine (CVE-2022-47966), PaperCut MF/NG (CVE-2023-27350), Microsoft Netlogon (CVE-2020-1472), JetBrains TeamCity (CVE-2023-42793), Microsoft Outlook (CVE-2023-23397), and ownCloud (CVE-2023-49103). "More routine initial exploitation of zero-day vulnerabilities represents the new normal which should concern end-user organizations and vendors alike as malicious actors seek to infiltrate networks," the U.K. NCSC said. The disclosure coincided with Google's announcement that it will begin issuing "CVEs for critical Google Cloud vulnerabilities, even when we do not require customer action or patching" to boost vulnerability transparency. It also came as the CVE Program recently turned 25, with over 400 CVE Numbering Authorities (CNAs) and more than 240,000 CVE identifiers assigned as of October 2024. The U.S. National Institute of Standards and Technology (NIST), for its part, said it now has a "full team of analysts on board, and we are addressing all incoming CVEs as they are uploaded into our system" to address the backlog of CVEs that built up earlier this calendar year.
  • GeoVision Zero-Day Under Attack: A new zero-day flaw in end-of-life GeoVision devices (CVE-2024-11120, CVSS score: 9.8), a pre-auth command injection vulnerability, is being exploited to compromise and enlist them into a Mirai botnet for likely DDoS or cryptomining attacks. "We observed a 0day exploit in the wild used by a botnet targeting GeoVision EOL devices," the Shadowserver Foundation said. Users of GV-VS12, GV-VS11, GV-DSP_LPR_V3, GVLX 4 V2, and GVLX 4 V3 are recommended to replace them.
  • New Banking Trojan Silver Shifting Yak Targets Latin America: A new Windows-based banking trojan named Silver Shifting Yak has been observed targeting Latin American users with the goal of stealing information from financial institutions such as Banco Itaú, Banco do Brasil, Banco Bandresco, Foxbit, and Mercado Pago Brasil, among others, as well as credentials used to access Microsoft portals such as Outlook, Azure, and Xbox. The initial attack stages of the malware are believed to be initiated by phishing emails that lead the victims to malicious .ZIP archives hosted on fake websites. The development comes as the threat actor known as Hive0147 has begun to use a new malicious downloader called Picanha to deploy the Mekotio banking trojan. "Hive0147 also distributes other banking trojans, such as Banker.FN also known as Coyote, and is likely affiliated with several other Latin American cyber crime groups operating different downloaders and banking trojans to enable banking fraud," IBM X-Force said.
  • Tor Network Faces IP Spoofing Attack: The Tor Project said the Tor anonymity network was the target of a "coordinated IP spoofing attack" starting October 20, 2024. The attacker "spoofed non-exit relays and other Tor-related IPs to trigger abuse reports aimed at disrupting the Tor Project and the Tor network," the project said. "The origin of these spoofed packets was identified and shut down on November 7, 2024." The Tor Project said the incident had no impact on its users, but said it did take a few relays offline temporarily. It's unclear who is behind the attack.
  • FBI Warns About Criminals Sending Fraudulent Police Data Requests: The FBI is warning that hackers are obtaining private user information from U.S.-based tech companies by compromising U.S. and foreign government/police email addresses to submit "emergency" data requests. The abuse of emergency data requests by malicious actors such as LAPSUS$ has been reported in the past, but this is the first time the FBI has formally admitted that the legal process is being exploited for criminal purposes. "Cybercriminals understand the need for exigency, and use it to their advantage to shortcut the necessary analysis of the emergency data request," the agency said.
  • New Trends in Ransomware: A financially-motivated threat actor known as Lunar Spider has been linked to a malvertising campaign targeting financial services that employs SEO poisoning to deliver the Latrodectus malware, which, in turn, is used to deploy the Brute Ratel C4 (BRc4) post-exploitation framework. In this campaign detected in October 2024, users searching for tax-related content on Bing are lured into downloading an obfuscated JavaScript. Upon execution, this script retrieves a Windows Installer (MSI) from a remote server, which installs Brute Ratel. The toolkit then connects to command-and-control (C2) servers for further instructions, allowing the attacker to control the infected system. It's believed that the end goal of the attacks is to deploy ransomware on compromised hosts. Lunar Spider is also the developer behind IcedID, suggesting that the threat actor is continuing to evolve their malware deployment approach to counter law enforcement efforts. It's not just Lunar Spider. Another infamous cybercrime gang called Scattered Spider has been acting as an initial access broker for the RansomHub ransomware operation, employing advanced social engineering tactics to obtain privileged access and deploy the encryptor to impact a critical ESXi environment in just six hours." The disclosure comes as ransomware attacks, including those aimed at cloud services, continue to be a persistent threat, even as the volume of the incidents is beginning to witness a drop and there is a steady decline in the ransom payment rates. The appearance of new ransomware families like Frag, Interlock, and Ymir notwithstanding, one of the noteworthy trends in 2024 has been the rise of unaffiliated ransomware actors, the so-called "lone wolves" who operate independently.

🔥 Resources, Guides & Insights

🎥 Expert Webinar

  • How to be Ready for Rapid Certificate Replacement — Is certificate revocation a nightmare for your business? Join our free webinar and learn how to replace certificates with lightning speed. We'll share secrets to minimize downtime, automate replacements, master crypto agility, and implement best practices for ultimate resilience.
  • Building Tomorrow, Securely—AI Security in App Development — AI is revolutionizing the world, but are you prepared for the risks? Learn how to build secure AI applications from the ground up, protect against data breaches and operational nightmares, and integrate robust security into your development process. Reserve your spot now and discover the essential tools to safeguard your AI initiatives.

🔧 Cybersecurity Tools

  • Grafana — Grafana is an open-source monitoring and observability platform that enables cybersecurity teams to query, visualize, and alert on security metrics from any data source. It offers customizable dashboards with flexible visualizations and template variables, allowing for real-time threat monitoring, intrusion detection, and incident response. Features such as ad-hoc queries and dynamic drill-downs facilitate the exploration of metrics related to network traffic, user behavior, and system logs. Seamless log exploration with preserved filters supports forensic investigations, while visual alert definitions ensure timely notifications to security operations centers through integrations with tools like Slack and PagerDuty. Additionally, Grafana's ability to mix different data sources—including custom ones—provides comprehensive security monitoring across diverse environments, enhancing the organization's ability to maintain a robust cybersecurity posture.
  • URLCrazy is an OSINT tool designed for cybersecurity professionals to generate and test domain typos or variations, effectively detecting and preventing typo squatting, URL hijacking, phishing, and corporate espionage. By creating 15 types of domain variants and leveraging over 8,000 common misspellings across more than 1,500 top-level domains, URLCrazy helps organizations protect their brand by registering popular typos, identifying domains diverting traffic intended for their legitimate sites, and conducting phishing simulations during penetration tests.

🔒 Tip of the Week

Use Canary Tokens to Detect Intrusions — Hackers rely on staying hidden, but canary tokens help you catch them early. These are fake files, links, or credentials, like "Confidential_Report_2024.xlsx" or a fake AWS key, placed in spots hackers love to snoop—shared drives, admin folders, or cloud storage. If someone tries to access them, you get an instant alert with details like their IP address and time of access.

They’re easy to set up using free tools like Canarytokens.org and don’t need any advanced skills. Just keep them realistic, put them in key places, and check for alerts. Make sure you test your tokens after setup to ensure they work and avoid overusing them to prevent unnecessary noise. Place them strategically in high-value areas, and monitor alerts closely to act quickly if triggered. It’s a smart, low-effort way to spot hackers before they can do damage.

Conclusion

That’s it for this week’s cybersecurity updates. The threats might seem complicated, but protecting yourself doesn’t have to be. Start simple: keep your systems updated, train your team to spot risks, and always double-check anything that seems off.

Cybersecurity isn’t just something you do—it’s how you think. Stay curious, stay cautious, and stay protected. We’ll be back next week with more tips and updates to keep you ahead of the threats.

Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.

Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2024/11/thn-recap-top-cybersecurity-threats_18.html