ZDI shames Microsoft for – yet another – coordinated vulnerability disclosure snafu
ID: 0edb55a0-9be1-5d44-8eeb-1a127ed0f365
STIX ID: report--0edb55a0-9be1-5d44-8eeb-1a127ed0f365
Feed Name: The Register (Security)
Threat Score
The article reports on an actively exploited Microsoft MSHTML zero-day (`CVE-2024-38112`) that attackers (called Void Banshee) abused to resurrect Internet Explorer on modern Windows systems and deploy the Atlantida info-stealer to harvest cryptocurrency wallets across North America, Europe, and Southeast Asia; it also highlights a disclosure/credit dispute between Trend Micro's ZDI, Check Point, and Microsoft over the bug's reporting and patching process.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
