Weekly Threat & Vulnerabilities Report

July 5, 2024
Executive Summary
Trending / Critical Vulnerabilities
Exploit Activity and Mass Scanning Observed on Cytellite Sensors
Vulnerabilities abused by Botnet
Vulnerabilities Abused by Malware
PRE-NVD observed for this week
Subscribe to our Reports

Executive Summary

Trending / Critical Vulnerabilities

Current trending vulnerabilities offer insights into the latest emerging and widely discussed threats, helping to make informed decisions.

CVE-IDType of vulnerabilitySeverityCVSSAffected ProductExploited-in-WildEPSS scoreCISA-KEVZero-dayOSS
CVE-2024-0769Command InjectionCritical9.8D-Link DIR-859 1.06B01True0.00212FalseFalseFalse
CVE-2024-20399OS Command InjectionMedium6.7Cisco NX-OSTrue0.02252TrueTrueFalse
CVE-2024-6387Race ConditionHigh8.1OpenSSH's server (sshd)True0.00046FalseFalseTrue
CVE-2024-39891Unauthenticated EndpointMedium5.3Twilio Authy APITrue0.00045FalseFalseFalse
CVE-2024-38366Remote Code ExecutionCritical10.0CocoaPods TrunkFalse0.00045FalseFalseTrue
CVE-2024-23692Template injectionCritical9.8Rejetto HTTP File ServerTrue0.0021FalseFalseFalse

Exploit Activity and Mass Scanning Observed on Cytellite Sensors

Telemetry collected from Loginsoft sensors were analyzed and processed to derive insights on what is actively being exploited and actively being scanned. As source of truth, source IPv4 addresses & payloads can be provided on need-to-know basis.

VulnerabilitiesProductSeverityTitleExploited-in-WildCISA KEV
CVE-2024-3400PaloAlto Networks PAN-OSCriticalCommand Injection vulnerability in the GlobalProtect feature of Palo Alto Networks PAN-OSTrueTrue
CVE-2024-29973Zyxel NAS326 and NAS542 devicesCriticalCommand Injection vulnerability in "setCookie" parameter in Zyxel NAS326 and NAS542 devicesFalseFalse
CVE-2024-22729NETIS SYSTEMS MW5360 V1.0.1.3031CriticalCommand injection vulnerability in NETIS SYSTEMS MW5360 V1.0.1.3031 via the password parameter on the login pageFalseFalse

Vulnerabilities abused by Botnet

Identified vulnerabilities exploited by botnets, including recent CVEs logged in Misp. Presenting the top 5 CVEs with payloads suggestive of botnet activities, like utilizing wget with IP addresses.

VulnerabilityProductTitleExploitAbused by Botnet
CVE-2018-10562Gpon Home RouterCommand Injection vulnerability in Gpon home routerTrueZergeca, Zerobot, LiquorBot, Mirai, Gafgyt
CVE-2017-17215Huawei HG532Remote code execution vulnerability in Huawei HG532 routerTrueHinataBot, Zerobot, Mirai, Bashlite, Tsunami, Gitpaste, Beastmode, Enemybot, PerlBot, Zergeca, Ircbot

Vulnerabilities Abused by Malware

We proactively monitor the vulnerabilities which are targeted by adversaries. Each vulnerability is humanly studied and mapped with Mitre ATT&CK tactics and techniques. Source of information is derived from our vulnerability intelligence platform collected and curated information from various sources such as Twitter, Telegram, OSINT groups, Blogs, Data leak Sites and more.

VulnerabilitySeverityTitlePatchTargeted By MalwareOSS
CVE-2024-20399MediumOS Command Injection vulnerability in the CLI of Cisco NX_OSTrueVelvet AntFalse
CVE-2024-23692CriticalTemplate Injection vulnerability in Rejetto HTTP File Server up to 2.3m versionFalseCoinMiner, XMRig, LemonDuck, XenoRATFalse

PRE-NVD observed for this week

It refers to vulnerabilities discovered and potentially exploited before their official inclusion in the National Vulnerability Database. The LOVI Platform aggregates and distributes data from open sources and social media, currently tracking over 100 security alerts and planning to expand.

CVE-IDType of vulnerabilityProductReference
CVE-2024-27980Remote Command ExecutionNode.js 18.x, 20.x, 21.x on windowsResource
CVE-2024-6249Stack-Based Buffer OverflowWyze Cam v3Resource
CVE-2024-6248Improper AuthenticationWyze Cam v3Resource

Get notified

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.

Latest Reports

Latest Reports