Register Now
June 14, 2024

Weekly Threat & Vulnerabilities Report

Executive Summary

Trending / Critical Vulnerabilities

Current trending vulnerabilities offer insights into the latest emerging and widely discussed threats, helping to make informed decisions.

CVE-ID Type of vulnerability Severity CVSS Affected Product Exploited-in-Wild EPSS score CISA-KEV Zero-day OSS
CVE-2024-4610 Privilege Escalation Medium 7.8 ARM Mali GPU Kernel Driver True 0.21262 True False False
CVE-2024-4577 Security Feature Bypass Critical 9.8 PHP-CGI True 0.93199 True True False
CVE-2024-26169 Improper Privilege Management High 7.8 Windows Error Reporting Service True 0.0004 True True False
CVE-2024-32896 Privilege Escalation High Unknown Google Pixel Firmware True 0.00154 True True False
CVE-2024-4358 Authentication bypass Critical 9.8 Telerik Report Server True 0.05027 True False False

Exploit Activity and Mass Scanning Observed on Cytellite Sensors

Telemetry collected from Loginsoft sensors were analyzed and processed to derive insights on what is actively being exploited and actively being scanned. As source of truth, source IPv4 addresses & payloads can be provided on need-to-know basis.

Vulnerabilities Product Severity Title CISA KEV
CVE-2024-4577 PHP-CGI on Windows Critical Critical argument injection vulnerability in PHP on Windows servers True
CVE-2024-1709 ConnectWise ScreenConnect Critical Authentication Bypass Vulnerability in ConnectWise ScreenConnect. True
CVE-2023-38646 Metabase open source/Enterprise Critical Remote code execution vulnerability in Metabase open source before 0.46.6.1 and Metabase Enterprise before 1.46.6.1. False

Vulnerabilities abused by Botnet

Identified vulnerabilities exploited by botnets, including recent CVEs logged in Misp. Presenting the top 5 CVEs with payloads suggestive of botnet activities, like utilizing wget with IP addresses.

Vulnerability Product Title Exploit Abused by Botnet
CVE-2023-1389 TP-Link Archer AX21 An unauthenticated command injection vulnerability found in the TP-Link Archer AX21 WiFi router. True AGoent, Gafgyt, Moobot, Miori, Mirai, Condi
CVE-2017-17215 Huawei HG532 Remote code execution vulnerability in Huawei HG532 router True HinataBot, Zerobot, Mirai, Bashlite, Gitpaste, Beastmode, Enemybot, PerlBot, QakBot, Ircbot
CVE-2016-10372 Eir D1000 modem Improper protocol access control vulnerability in Eir D1000 modem True Bashlite, BrickerBot, Tsunami, Mirai

Vulnerabilities Abused by Malware

We proactively monitor the vulnerabilities which are targeted by adversaries. Each vulnerability is humanly studied and mapped with Mitre ATT&CK tactics and techniques. Source of information is derived from our vulnerability intelligence platform collected and curated information from various sources such as Twitter, Telegram, OSINT groups, Blogs, Data leak Sites and more.

Vulnerability Severity Title Patch Targeted By Malware OSS
CVE-2024-26169 High Elevation of privilege vulnerability in the Windows Error Reporting Service. True Blackbasta False
CVE-2023-33246 Critical Remote code execution (RCE) vulnerability Apache RocketMQ. True Muhstik True

PRE-NVD observed for this week

It refers to vulnerabilities discovered and potentially exploited before their official inclusion in the National Vulnerability Database. The LOVI Platform aggregates and distributes data from open sources and social media, currently tracking over 100 security alerts and planning to expand.

CVE-ID Type of vulnerability Product Reference
CVE-2024-22512 Remote code execution Allegra Versions lower 7.5.1 Resource
CVE-2024-30419 Denial of service python-idna-3.7-1.fc39 Resource
CVE-2024-30420 Server-side request forgery a-blog cms Versions earlier than Ver.3.1.12 Resource
CVE-2024-36041 Broken Authentication and Session Management plasma-workspace package Resource
CVE-2024-5719 Command Injection Unified SecOps Platform Resource

Subscribe to our Newsletter