Threat Advisories:
Highlights of Our CISO Dinner
Upgrading struggling vulnerability management programs to Threat Exposure Management, with Host, CISO Al Lindseth formerly from Plains All American Pipeline and PWC - 6 minute podcast
0:00
0:00
👥 Play Count: Loading...

Windows Zero-Day Vulnerability Exploited by Void Banshee APT

Red | Vulnerability Report
Download PDF

CVE-2024-43461 is a spoofing vulnerability in Microsoft Windows MSHTML, exploited in zero-day attacks by the Void Banshee APT group. It used encoded braille whitespace characters to hide malicious file extensions, making dangerous files appear as harmless PDFs. This enabled the execution of malware, such as the Atlantida info-stealer. Microsoft patched the issue as part of the September 2024 Patch Tuesday updates.

What’s new on HivePro

Get through updates and upcoming events, and more directly in your inbox