Monthly Threat Digest: September 2024
For a detailed threat digest, download the pdf file here
Summary
In September, the cybersecurity arena garnered significant attention following the discovery of fifteen zero-day vulnerabilities. North Korean hackers leveraged a recently patched Google Chrome zero-day, CVE-2024-7971, to deploy the FudModule rootkit, further escalating concerns.
At the same time, ransomware incidents surged, with aggressive variants such as Meow, RansomHub, LockBit, Babuk, and INC ransomware targeting numerous victims. As ransomware tactics become increasingly sophisticated, organizations must strengthen their defenses by adopting robust backup and disaster recovery solutions.
Meanwhile, Mustang Panda, a notorious advanced persistent threat (APT) group, has ramped up its operations, deploying new malware variants and refining its attack methods. The group has orchestrated complex worm-based attacks aimed at high-value targets. Additionally, CVE-2024-43461, a spoofing vulnerability in Microsoft Windows MSHTML, has been actively exploited in zero-day campaigns by the Void Banshee APT group. This vulnerability facilitated the deployment of malware, including the Atlantida info-stealer. As the threat landscape continues to evolve, it is crucial for organizations to remain vigilant and proactively address emerging risks
Subscribe to keep up on a weekly basis with our weekly threat digests and newsletters.