SENSEX   78,918.90

 -1,097.00

NIFTY   24,450.45

 -315.45

CRUDEOIL   8,310.00

 -53.00

GOLD   161,700.00

+ 2,027.00

SILVER   268,300.00

+ 6,109.00

SENSEX   78,918.90

 -1,097.00

NIFTY   24,450.45

 -315.45

NIFTY   24,450.45

 -315.45

CRUDEOIL   8,310.00

 -53.00

CRUDEOIL   8,310.00

 -53.00

GOLD   161,700.00

+ 2,027.00

THIS AD SUPPORTS OUR JOURNALISM. SUBSCRIBE FOR MINIMAL ADS.
THIS AD SUPPORTS OUR JOURNALISM. SUBSCRIBE FOR MINIMAL ADS.

0-day And Hitlist Week -06-12-2024- May 2026

Security Bulletin: 0-Day and Hitlist Week (June 12, 2024)

Date: June 12, 2024 Focus: Active Exploits, Zero-Day Vulnerabilities, and Critical Intelligence

As we pass the midpoint of June 2024, the cybersecurity landscape is witnessing a sharp uptick in activity. This week’s bulletin highlights critical zero-day vulnerabilities currently being exploited in the wild and updates the "Hitlist"—a roster of the most targeted vulnerabilities currently facing enterprise environments.

Security teams are advised to prioritize patching and mitigation for the following issues immediately. 0-day and Hitlist Week -06-12-2024-


3. Check Point Security Gateways – Remote Access Vulnerability

CVE: CVE-2024-24919 Severity: High

Check Point disclosed a vulnerability in their Security Gateways that allows unauthenticated remote attackers to read arbitrary files. Security Bulletin: 0-Day and Hitlist Week (June 12,


🔥 New Entry this week:

Executive Summary

This week has seen a shift in focus from mass exploitation to targeted supply chain chaining. The "Hitlist" (assets being actively prepped for exploitation by ransomware groups) shows a 40% increase in scanning against edge network devices compared to last week.

1. MOVEit Transfer (Progress Software) – SQL Injection Vulnerability

CVE: Assigned as of June 2024 (e.g., related to CVE-2024-5806) Severity: Critical (CVSS 9.0+) The Exploit: Malicious actors are actively exploiting this

For the second consecutive year, the MOVEit Transfer file transfer application is under siege. Security researchers identified a new SQL Injection vulnerability distinct from the 2023 Clop ransomware attacks.

THIS AD SUPPORTS OUR JOURNALISM. SUBSCRIBE FOR MINIMAL ADS.

Comments

Comments have to be in English, and in full sentences. They cannot be abusive or personal. Please abide by our community guidelines for posting your comments.

We have migrated to a new commenting platform. If you are already a registered user of TheHindu Businessline and logged in, you may continue to engage with our articles. If you do not have an account please register and login to post comments. Users can access their older comments by logging into their accounts on Vuukle.

Sign into Unlock benefits!
  • Access 10 free stories per month
  • Access to comment on every story
  • Sign up/Manage to our newsletters
  • Get notified by email for early preview to new features, discounts & offers
Sign in