Recent cybersecurity reports highlight significant vulnerabilities and attacks targeting various platforms and software. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical security flaw, CVE-2023-28461, affecting Array Networks AG and vxAG gateways, to its Known Exploited Vulnerabilities catalog due to active exploitation. This follows reports of more than 2,000 attacks on Palo Alto Networks PAN-OS firewalls since security flaws were patched earlier this month. Additionally, Russian hackers have been linked to the exploitation of zero-day vulnerabilities in Firefox (CVE-2024-9680) and Windows (CVE-2024-49039), allowing them to deliver the RomCom backdoor malware without user interaction. Concurrently, a previously unknown China-linked hacking group named Earth Estries has been identified using custom malware to target telecommunications and technology sectors across Southeast Asia. Furthermore, a new threat named Matrix has emerged, utilizing IoT devices in a widespread DDoS attack campaign. These incidents underscore the ongoing challenges in cybersecurity as attackers leverage both old and new vulnerabilities across various platforms.
APT-C-60 Exploits WPS Office Vulnerability to Deploy SpyGlace Backdoor: https://t.co/hZZfnWGVo6 by The Hacker News #infosec #cybersecurity #technology #news
APT-C-60 strikes again – this time with a targeted attack exploiting the WPS Office #vulnerability (CVE-2024-7262) to deploy the SpyGlace backdoor. Read more about how this advanced attack works: https://t.co/WjyK2dKbmd #cybersecurity #infosec
Russian RomCom APT Group Leverages Zero-Day Flaws in Firefox and Windows https://t.co/3BDAaNsoiW