Site icon TheCyberThrone

TheCyberThrone Security Weekly Review – November 9, 2024

Advertisements

QNAP addresses CVE-2024-50389 in QuRouter

QNAP has addressed a critical zero-day vulnerability in its QuRouter network security appliance, exploited by security researchers during the recent Pwn2Own hacking contest in Ireland.

The vulnerability, tracked as CVE-2024-50389 with a CVSS score of 7.8, allowed the Viettel Cyber Security team to compromise a QuRouter devices……

PoC Exploit released for Microsoft flaw CVE-2024-43532

Researcher from Akamai has released a proof-of-concept (PoC) exploit code for a critical Elevation of Privilege vulnerability, that’s tracked as CVE-2024-43532 with a CVSS score of 8.8.

This vulnerability exploits a fallback mechanism in the WinReg client, which insecurely uses obsolete transport protocols if the preferred SMB transport is unavailable. This enables  attackers to relay NTLM authentication details, potentially compromising sensitive systems……

Advertisements

Google fixes CVE-2024-43093 in Android OS

Google has come with a warning about a vulnerability in the Android OS that is actively exploited in the wild.

The vulnerability tracked as CVE-2024-43093, with a CVSS score of 5.4 is a privilege escalation issue in the Android Framework component. Successful exploitation of the vulnerability could lead to unauthorized access to “Android/data,” “Android/obb,” and “Android/sandbox” directories and associated sub-directories.

SUBSCRIBE TO OUR BLOG TODAY !

We understand the importance of staying on top of the latest threats and vulnerabilities that can harm your digital life. You’ll receive the latest cybersecurity news, insights, resources, offers and analysis straight to your inbox every day

Veeam Fixes CVE-2024-40715 with a hotfix release

Veeam has released a patch for a vulnerability impacting Veeam Backup Enterprise Manager. that is  vulnerable to Man-in-the-Middle (MITM) attacks.

The vulnerability tracked as CVE-2024-40715, with a CVSS score of 7.7 allows attackers to bypass authentication through a MITM attack, which could have significant implications for organizations relying on Veeam’s backup solutions for data security…..

Advertisements

Interlock Ransomware Dissection

A new ransomware group came into the threat landscape dubbed as Interlock, with targeted attacks across sectors including US healthcare, IT and government, and European manufacturing with its attack chain spans around 2-3 weeks approximately.

Interlock employs both hunting and double extortion tactics, where compromised data is stolen and threatened to be released publicly unless a ransom is paid. They have a data leak site known as Worldwide Secrets Blog to publish stolen data……

Exit mobile version