CyberNews: 30/08/2026 Edition
Today’s roundup
Summary
Ivanti has patched a third actively exploited zero-day, CVE-2024-21894, affecting Connect Secure and Policy Secure VPNs, which allows for privilege escalation. Organizations are urged to apply updates immediately to mitigate the threat.
Days after an international law enforcement disruption, the LockBit ransomware group claims it has recovered, moved its servers, and is resuming operations, threatening to leak data from previously compromised victims.
Microsoft's February 2024 Patch Tuesday addressed 73 vulnerabilities, including three actively exploited zero-days: CVE-2024-21351 (SmartScreen bypass), CVE-2024-21410 (Exchange Server EoP), and CVE-2024-21412 (Common Log File System RCE).
A critical remote code execution vulnerability (CVE-2023-46604) in Apache ActiveMQ has been actively exploited since October 2023, with threat actors deploying ransomware. Patches are available and should be applied promptly.
Researchers have uncovered "Pipedream 2.0," a new and sophisticated malware campaign targeting Industrial Control Systems (ICS). Attributed to state-sponsored actors, it features enhanced modules for reconnaissance and manipulation of critical infrastructure.
Google has released an emergency update for its Chrome browser to address a newly discovered and actively exploited zero-day vulnerability (CVE-2024-xxxx), urging users to update immediately.
A new zero-day vulnerability affecting PHP-FPM, related to a file descriptor leak, has been discovered. This flaw allows for local privilege escalation on web servers running PHP.
A critical vulnerability affecting a popular WordPress plugin, installed on over 1 million sites, has been disclosed. The flaw could allow remote code execution or data exfiltration, and patches are available.
A large-scale phishing campaign is actively targeting over 1.4 million Gen Z workers. The scam uses fake job offers, primarily distributed via LinkedIn and other platforms, to deliver information-stealing malware.
Want to dig deeper?
Vulnerabilities
| CVE-2024-21894 | High |
| CVE-2024-21351 | Medium |
| CVE-2024-21410 | High |
| CVE-2024-21412 | High |
| CVE-2023-46604 | Critical |