October 3, 2024

Monthly Threat Digest: September 2024

For a detailed threat digest, download the pdf file here

Summary

In September, the cybersecurity arena garnered significant attention following the discovery of fifteen zero-day vulnerabilities. North Korean hackers leveraged a recently patched Google Chrome zero-day, CVE-2024-7971, to deploy the FudModule rootkit, further escalating concerns.

At the same time, ransomware incidents surged, with aggressive variants such as Meow, RansomHub, LockBit, Babuk, and INC ransomware targeting numerous victims. As ransomware tactics become increasingly sophisticated, organizations must strengthen their defenses by adopting robust backup and disaster recovery solutions.

Meanwhile, Mustang Panda, a notorious advanced persistent threat (APT) group, has ramped up its operations, deploying new malware variants and refining its attack methods. The group has orchestrated complex worm-based attacks aimed at high-value targets. Additionally, CVE-2024-43461, a spoofing vulnerability in Microsoft Windows MSHTML, has been actively exploited in zero-day campaigns by the Void Banshee APT group. This vulnerability facilitated the deployment of malware, including the Atlantida info-stealer. As the threat landscape continues to evolve, it is crucial for organizations to remain vigilant and proactively address emerging risks

Subscribe to keep up on a weekly basis with our weekly threat digests and newsletters.

Recent Resources

Dive into our library of resources for expert insights, guides, and in-depth analysis on maximizing Uni5 Xposure’s capabilities

Book a demo and find out more about how Hive Pro can double your operational efficiency

Book a Demo