November 11, 2024

Monthly Threat Digest: October 2024

For a detailed threat digest, download the pdf file here

Summary

In October, the cybersecurity arena drew significant attention with the active exploitation of

twenty-one zero-day vulnerabilities. Among them, CVE-2024-47575 in FortiManager was exploited by UNC5820 to compromise over 50 devices, enabling the theft of configurations, IP addresses, and credentials from FortiGate systems. Mozilla also fixed the critical zero-day flaw CVE-2024-9680 in Firefox, which had been actively exploited to execute arbitrary code.

During this period, ransomware attacks surged, with variants such as Akira, Fog, Cicada3301, LockBit 3.0, Babuk, and Embargo Ransomware aggressively targeting victims. As ransomware tactics grow more sophisticated, organizations must bolster their defenses by implementing comprehensive backup and disaster recovery strategies. Additionally, training employees to detect and prevent phishing attacks remains essential.

Since August 2024, Akira and Fog ransomware strains have exploited vulnerabilities in SonicWall’s SonicOS (CVE-2024-40766) and Veeam Backup & Replication (CVE-2024-40711), resulting in over 30 incidents involving unauthorized access and arbitrary code execution.

Concurrently, Seventeen threat actors have engaged in various campaigns. GoldenJackal, a skilled APT group, launched advanced cyberattacks on government and diplomatic targets in Europe, aiming to breach air-gapped systems and exfiltrate sensitive data. The Chinese APT group Evasive Panda employed a toolset called CloudScout to infiltrate organizations in Taiwan. As the cybersecurity landscape evolves, organizations must remain vigilant and proactively address emerging threats.


Subscribe to keep up on a weekly basis with our weekly threat digests and newsletters.

Recent Resources

Dive into our library of resources for expert insights, guides, and in-depth analysis on maximizing Uni5 Xposure’s capabilities

Book a demo and find out more about how Hive Pro can double your operational efficiency

Book a Demo