Date: June 12, 2024 Focus: Active Exploits, Zero-Day Vulnerabilities, and Critical Intelligence
As we pass the midpoint of June 2024, the cybersecurity landscape is witnessing a sharp uptick in activity. This week’s bulletin highlights critical zero-day vulnerabilities currently being exploited in the wild and updates the "Hitlist"—a roster of the most targeted vulnerabilities currently facing enterprise environments.
Security teams are advised to prioritize patching and mitigation for the following issues immediately. 0-day and Hitlist Week -06-12-2024-
CVE: CVE-2024-24919 Severity: High
Check Point disclosed a vulnerability in their Security Gateways that allows unauthenticated remote attackers to read arbitrary files. Security Bulletin: 0-Day and Hitlist Week (June 12,
This week has seen a shift in focus from mass exploitation to targeted supply chain chaining. The "Hitlist" (assets being actively prepped for exploitation by ransomware groups) shows a 40% increase in scanning against edge network devices compared to last week.
CVE: Assigned as of June 2024 (e.g., related to CVE-2024-5806) Severity: Critical (CVSS 9.0+) The Exploit: Malicious actors are actively exploiting this
For the second consecutive year, the MOVEit Transfer file transfer application is under siege. Security researchers identified a new SQL Injection vulnerability distinct from the 2023 Clop ransomware attacks.
Comments
Comments have to be in English, and in full sentences. They cannot be abusive or personal. Please abide by our community guidelines for posting your comments.
We have migrated to a new commenting platform. If you are already a registered user of TheHindu Businessline and logged in, you may continue to engage with our articles. If you do not have an account please register and login to post comments. Users can access their older comments by logging into their accounts on Vuukle.