Today’s roundup
Fortra Patches Critical RCE in GoAnywhere MFT - CVE-2024-0204
New DarkGate Loader Campaign Spotted, Distributes via Malicious Ads
Critical Cisco IOS XE Zero-Day (CVE-2023-20198) Actively Exploited
Russia-Linked APT29 Exploiting Microsoft Outlook Zero-Day (CVE-2023-23397)
Critical Remote Code Execution in Ivanti Connect Secure VPN (CVE-2023-46805, CVE-2024-21887)
Akira Ransomware Targets Cisco ASA/FTD Devices via VPN Vulnerability
Iranian APT "OilRig" Exploits VMware ESXi and Windows for Espionage
Google Patches Chrome Zero-Day (CVE-2024-0001) Actively Exploited
Critical RCE in Apache ActiveMQ (CVE-2023-46604) Exploited by HelloKitty Ransomware
New Zero-Day (CVE-2023-XXXX) in D-Link Routers Allows Remote Takeover
Summary
Fortra patched CVE-2024-0204, a critical RCE/auth bypass in GoAnywhere MFT, allowing unauthenticated admin creation and full control; immediate update advised.
A new DarkGate loader campaign uses malvertising on search engines, redirecting users to compromised sites for fake software updates installing the malware.
Cisco warns of CVE-2023-20198, a critical IOS XE zero-day actively exploited to create admin accounts and establish persistent control; immediate patching required.
Russia-linked APT29 (Nobelium) exploits CVE-2023-23397, a critical Outlook zero-day, stealing NTLM hashes from crafted emails without user interaction, bypassing MFA for espionage.
Ivanti patched CVE-2023-46805 (auth bypass) and CVE-2024-21887 (RCE) in Connect Secure VPN, actively exploited for initial network access; immediate updates and factory resets urged.
Akira ransomware targets Cisco ASA/FTD VPNs, exploiting vulnerabilities via brute-force or stolen credentials for data exfiltration and ransomware deployment; secure VPNs immediately.
Iranian APT "OilRig" (APT34) conducts espionage via VMware ESXi and Windows vulnerabilities, establishing persistence and exfiltrating data from government and Middle East targets.
Google patched CVE-2024-0001, a critical Chrome zero-day (V8 heap buffer overflow) actively exploited for arbitrary code execution; users must update browsers immediately.
CVE-2023-46604, a critical RCE in Apache ActiveMQ, is actively exploited by HelloKitty ransomware via crafted OpenWire commands, gaining initial access for deployment; patch systems.
A new zero-day (CVE-2023-XXXX) in D-Link routers allows unauthenticated remote takeover via authentication bypass and arbitrary command execution; active exploitation suspected.
Want to dig deeper?
Vulnerabilities
Cyber Groups
| Akira | GOLD SAHARA, PUNK SPIDER, Howling Scorpius |
| APT29 | IRON RITUAL, IRON HEMLOCK, NobleBaron, Dark Halo, NOBELIUM, UNC2452, YTTRIUM, The Dukes, Cozy Bear, CozyDuke, SolarStorm, Blue Kitsune, UNC3524, Midnight Blizzard |
| OilRig | COBALT GYPSY, IRN2, APT34, Helix Kitten, Evasive Serpens, Hazel Sandstorm, EUROPIUM, ITG13, Earth Simnavaz, Crambus, TA452 |
Malware Families