Today’s roundup
Apple Discloses Critical Zero-Day Vulnerability Actively Exploited in the Wild
Google Discloses New Android Zero-Day Vulnerability Under Active Exploitation
FBI and International Partners Disrupt Notorious QakBot Botnet
Change Healthcare Cyberattack Costs UnitedHealth Group $1.6 Billion and Confirms Massive Data Breach
Critical Remote Code Execution Vulnerability in Apache ActiveMQ Actively Exploited
Adobe ColdFusion Hit by New RCE Vulnerability, Actively Exploited in the Wild
Critical Security Flaw in Atlassian Confluence DC/Server Actively Exploited
Summary
Apple has issued emergency security updates to address a critical zero-day vulnerability (CVE-2024-27806) in its WebKit engine. This flaw affects iOS, iPadOS, macOS, watchOS, and Safari, and is confirmed to be actively exploited in the wild. Users are urged to update their devices immediately.
Google has disclosed a new Android zero-day vulnerability (CVE-2024-32896) identified in May's security bulletin. This privilege escalation flaw specifically impacts Pixel devices and has been actively exploited by forensic companies to gain unauthorized access to data on target devices.
A global law enforcement operation led by the FBI has successfully disrupted the QakBot botnet, a major infrastructure used for financial fraud and ransomware attacks. The multi-national effort involved seizing servers, identifying compromised systems, and removing malware from numerous victim machines worldwide.
UnitedHealth Group has reported that the February cyberattack on its Change Healthcare subsidiary has incurred an estimated $1.6 billion in costs during the first quarter of 2024. The company confirmed that the ALPHV/BlackCat ransomware attack resulted in the exfiltration of protected health information (PHI) and personally identifiable information (PII) belonging to a substantial portion of Americans.
A critical remote code execution (RCE) vulnerability (CVE-2023-46604) in Apache ActiveMQ is under active exploitation. The flaw allows unauthenticated remote attackers to execute arbitrary shell commands on vulnerable servers, necessitating immediate patching by administrators.
Adobe has released security updates for ColdFusion to address a new remote code execution (RCE) vulnerability (CVE-2023-26369) that is actively exploited in the wild. The flaw affects multiple versions of ColdFusion and could allow attackers to execute arbitrary code.
Atlassian has alerted customers to a critical security flaw (CVE-2023-22515) in Confluence Data Center and Server. This vulnerability, actively exploited, allows unauthenticated remote attackers to create administrator accounts and gain full control over instances, requiring immediate patches.
Want to dig deeper?
Vulnerabilities
Malware Families