Weekly Threat Digest: September 16 – September 22, 2024
For a detailed threat digest, download the pdf file here
Summary
HiveForce Labs recently made several significant discoveries in the realm of cybersecurity threats. In the past week alone, ten attacks were executed, seven vulnerabilities were uncovered, and three active adversaries were identified, underscoring the persistent danger of cyberattacks.
HiveForce Labs has reported that the hacktivist group Head Mare is actively targeting organizations in Russia and Belarus, exposing sensitive information about their victims. In these attacks, the group has exploited the WinRAR zero-day vulnerability, CVE-2023-38831, to gain initial access to the targeted systems.
Additionally, Ivanti has issued a critical patch for vulnerabilities CVE-2024-8190 and CVE-2024-8963 in its Cloud Services Appliance (CSA), both actively exploited in the wild. These flaws allow attackers to bypass admin authentication and execute commands. Similarly, attackers are exploiting SQL injection vulnerabilities, including CVE-2024-6670, in WhatsUp Gold, with active attacks following the release of PoC exploit code. These escalating threats pose a significant and immediate risk to users worldwide.
Subscribe to receive our weekly threat digests and newsletters directly in your inbox.