Weekly Threat & Vulnerabilities Report

June 28, 2024
Executive Summary
Trending / Critical Vulnerabilities
Exploit Activity and Mass Scanning Observed on Cytellite Sensors
Vulnerabilities abused by Botnet
Vulnerabilities Abused by Malware
PRE-NVD observed for this week
Subscribe to our Reports

Executive Summary

Trending / Critical Vulnerabilities

Current trending vulnerabilities offer insights into the latest emerging and widely discussed threats, helping to make informed decisions.

CVE-IDType of vulnerabilitySeverityCVSSAffected ProductExploited-in-WildEPSS scoreCISA-KEVZero-dayOSS
CVE-2024-29973Command InjectionCritical9.8Zyxel NAS326 firmwareFalse0.93664FalseFalseFalse
CVE-2024-5806Improper AuthenticationCritical9.1MOVEit TransferTrue0.00043FalseFalseFalse
CVE-2024-28995Path TraversalHigh7.5SolarWinds Serv-UTrue0.34343FalseFalseFalse
CVE-2022-2586Use-After-FreeHigh7.8Linux KernelTrue0.01048TrueFalseTrue
CVE-2022-24816Remote Code ExecutionCritical9.8GeoSolutionsGroup JAI-EXTTrue0.96777TrueFalseTrue
CVE-2020-13965Stored Cross Site ScriptingMedium6.1Roundcube WebmailTrue0.00483TrueFalseTrue

Exploit Activity and Mass Scanning Observed on Cytellite Sensors

Telemetry collected from Loginsoft sensors were analyzed and processed to derive insights on what is actively being exploited and actively being scanned. As source of truth, source IPv4 addresses & payloads can be provided on need-to-know basis.

VulnerabilitiesProductSeverityTitleExploited-in-WildCISA KEV
CVE-2024-23692Rejetto HTTP File ServerCriticalTemplate Injection vulnerability in Rejetto HTTP File Server 2.3mFalseFalse
CVE-2023-4415Ruijie RG-EW1200G 07161417 r483HighImproper Authentication vulnerability in Ruijie RG-EW1200G 07161417 r483FalseFalse
CVE-2023-38646Metabase open source/EnterpriseCriticalRemote code execution vulnerability in Metabase open source before 0.46.6.1 and Metabase Enterprise before 1.46.6.1.TrueFalse

Vulnerabilities abused by Botnet

Identified vulnerabilities exploited by botnets, including recent CVEs logged in Misp. Presenting the top 5 CVEs with payloads suggestive of botnet activities, like utilizing wget with IP addresses.

VulnerabilityProductTitleExploitAbused by Botnet
CVE-2023-1389TP-Link Archer AX21An unauthenticated command injection vulnerability found in the TP-Link Archer AX21 WiFi router.TrueAGoent, Gafgyt, Moobot, Miori, Mirai, Condi
CVE-2023-26801LB-LINK BL DevicesCommand injection vulnerability in LB-LINK BL-AC1900_2.0 1.0.1, BL-WR9000 2.4.9, BL-X26 1.2.5 and BL-LTE300 1.0.8TrueMirai, IZ1H9

Vulnerabilities Abused by Malware

We proactively monitor the vulnerabilities which are targeted by adversaries. Each vulnerability is humanly studied and mapped with Mitre ATT&CK tactics and techniques. Source of information is derived from our vulnerability intelligence platform collected and curated information from various sources such as Twitter, Telegram, OSINT groups, Blogs, Data leak Sites and more.

VulnerabilitySeverityTitlePatchTargeted By MalwareOSS
CVE-2024-29973CriticalCommand Injection vulnerability in "setCookie" parameter in Zyxel NAS326 and NAS542 devicesTrueMiraiFalse

PRE-NVD observed for this week

It refers to vulnerabilities discovered and potentially exploited before their official inclusion in the National Vulnerability Database. The LOVI Platform aggregates and distributes data from open sources and social media, currently tracking over 100 security alerts and planning to expand.

CVE-IDType of vulnerabilityProductReference
CVE-2024-1867Local Privilege EscalationG DATA Total SecurityResource
CVE-2024-33605Path TraversalSharp and Toshiba Tec multi-function printersResource
CVE-2024-2201Information DisclosureNative Spectre v2Resource

Get notified

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.

Latest Reports

Latest Reports