Weekly Threat Digest: October 21 – October 27, 2024
For a detailed threat digest, download the pdf file here
Summary
HiveForce Labs has uncovered several critical cybersecurity threats, highlighting the alarming frequency and sophistication of cyber incidents. Over the past week, nine attacks were executed, seven exploited vulnerabilities, and three active threat groups were identified, underscoring the relentless rise in cyber intrusions.
One significant vulnerability, CVE-2024-44133, known as “HM Surf,” enables attackers to bypass macOS’s TCC framework, granting unauthorized access to sensitive data, including camera and microphone controls. Meanwhile, Crypt Ghouls, an emerging cybercrime group, has initiated ransomware campaigns that aggressively target Russian businesses and government entities.
Additionally, a Cross-Site Scripting (XSS) vulnerability in the Roundcube Webmail client (CVE-2024-37383) has been exploited in targeted phishing attacks against a government organization within a Commonwealth of Independent States (CIS) country. Fortinet has also detected active exploits of a zero-day vulnerability in the FortiManager API, tracked as CVE-2024-47575. These escalating threats underscore the urgent need for enhanced cybersecurity defenses worldwide.
Subscribe to receive our weekly threat digests and newsletters directly in your inbox.