Weekly Threat & Vulnerabilities Report

June 14, 2024
Executive Summary
Trending / Critical Vulnerabilities
Exploit Activity and Mass Scanning Observed on Cytellite Sensors
Vulnerabilities abused by Botnet
Vulnerabilities Abused by Malware
PRE-NVD observed for this week
Subscribe to our Reports

Executive Summary

Trending / Critical Vulnerabilities

Current trending vulnerabilities offer insights into the latest emerging and widely discussed threats, helping to make informed decisions.

CVE-IDType of vulnerabilitySeverityCVSSAffected ProductExploited-in-WildEPSS scoreCISA-KEVZero-dayOSS
CVE-2024-4610Privilege EscalationMedium7.8ARM Mali GPU Kernel DriverTrue0.21262TrueFalseFalse
CVE-2024-4577Security Feature BypassCritical9.8PHP-CGITrue0.93199TrueTrueFalse
CVE-2024-26169Improper Privilege ManagementHigh7.8Windows Error Reporting ServiceTrue0.0004TrueTrueFalse
CVE-2024-32896Privilege EscalationHighUnknownGoogle Pixel FirmwireTrue0.00154TrueTrueFalse
CVE-2024-4358Authentication bypassCritical9.8Telerik Report ServerTrue0.05027TrueFalseFalse

Exploit Activity and Mass Scanning Observed on Cytellite Sensors

Telemetry collected from Loginsoft sensors were analyzed and processed to derive insights on what is actively being exploited and actively being scanned. As source of truth, source IPv4 addresses & payloads can be provided on need-to-know basis.

VulnerabilitiesProductSeverityTitleCISA KEV
CVE-2024-4577PHP-CGI on WindowsCriticalCritical argument injection vulnerability in PHP on Windows serversTrue
CVE-2024-1709ConnectWise ScreenConnectCriticalAuthentication Bypass Vulnerability in ConnectWise ScreenConnect.True
CVE-2023-38646Metabase open source/EnterpriseCriticalRemote code execution vulnerability in Metabase open source before 0.46.6.1 and Metabase Enterprise before 1.46.6.1.False

Vulnerabilities abused by Botnet

Identified vulnerabilities exploited by botnets, including recent CVEs logged in Misp. Presenting the top 5 CVEs with payloads suggestive of botnet activities, like utilizing wget with IP addresses.

VulnerabilityProductTitleExploitAbused by Botnet
CVE-2023-1389TP-Link Archer AX21An unauthenticated command injection vulnerability found in the TP-Link Archer AX21 WiFi router.TrueAGoent, Gafgyt, Moobot, Miori, Mirai, Condi
CVE-2017-17215Huawei HG532Remote code execution vulnerability in Huawei HG532 routerTrueHinataBot, Zerobot, Mirai, Bashlite, Gitpaste, Beastmode, Enemybot, PerlBot, QakBot, Ircbot
CVE-2016-10372Eir D1000 modemImproper protocol access control vulnerability in Eir D1000 modemTrueBashlite, BrickerBot, Tsunami, Mirai

Vulnerabilities Abused by Malware

We proactively monitor the vulnerabilities which are targeted by adversaries. Each vulnerability is humanly studied and mapped with Mitre ATT&CK tactics and techniques. Source of information is derived from our vulnerability intelligence platform collected and curated information from various sources such as Twitter, Telegram, OSINT groups, Blogs, Data leak Sites and more.

VulnerabilitySeverityTitlePatchTargeted By MalwareOSS
CVE-2024-26169HighElevation of privilege vulnerability in the Windows Error Reporting Service.TrueBlackbastaFalse
CVE-2023-33246CriticalRemote code execution (RCE) vulnerability Apache RocketMQ.TrueMuhstikTrue

PRE-NVD observed for this week

It refers to vulnerabilities discovered and potentially exploited before their official inclusion in the National Vulnerability Database. The LOVI Platform aggregates and distributes data from open sources and social media, currently tracking over 100 security alerts and planning to expand.

CVE-IDType of vulnerabilityProductReference
CVE-2024-22512Remote code executionAllegra Versions lower 7.5.1Resource
CVE-2024-30419Denial of servicepython-idna-3.7-1.fc39Resource
CVE-2024-30420Server-side request forgerya-blog cms Versions earlier than Ver.3.1.12Resource
CVE-2024-36041Broken Authentication and Session Managementplasma-workspace packageResource
CVE-2024-5719Command InjectionUnified SecOps PlatformResource

Get notified

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.

Latest Reports

Latest Reports