CVE-2024-43461 is a spoofing vulnerability in Microsoft Windows MSHTML, exploited in zero-day attacks by the Void Banshee APT group. It used encoded braille whitespace characters to hide malicious file extensions, making dangerous files appear as harmless PDFs. This enabled the execution of malware, such as the Atlantida info-stealer. Microsoft patched the issue as part of the September 2024 Patch Tuesday updates.
What’s new on HivePro
Get through updates and upcoming events, and more directly in your inbox