Weekly Threat Digest: December 09 – December 15, 2024
For a detailed threat digest, download the PDF file here
Summary
HiveForce Labs recently made several significant discoveries in the realm of cybersecurity threats. In the past week alone, thirteen attacks were executed, four vulnerabilities were uncovered, and one active adversaries were identified, underscoring the persistent danger of cyberattacks.
HiveForce Labs has uncovered that threat actors are actively exploiting CVE-2023-46604 in Apache ActiveMQ to achieve remote code execution, install backdoors, deploy Quasar RAT and proxy tools, and potentially trigger Mauri ransomware to encrypt data. To mitigate this threat, immediate patching and proactive security measures are crucial.
Furthermore, CVE-2024-50623 and CVE-2024-55956 critical zero-day vulnerabilities in Cleo’s file transfer solutions, are being exploited in the wild. These flaw allows unrestricted file uploads and downloads, leading to remote code execution (RCE) and posing a severe risk to affected organizations. Additionally, Pumakit, a sophisticated Linux rootkit, employs advanced stealth techniques and privilege escalation, featuring a multi-layered design with a dropper, executables, and rootkits. These escalating threats represent a significant and urgent risk to global users.
Subscribe to receive our weekly threat digests and newsletters directly in your inbox.