Check Point warns customers to patch VPN vulnerability under active exploitation
ID: 1a071cd4-34af-546c-b38b-b2b9929f01e1
STIX ID: report--1a071cd4-34af-546c-b38b-b2b9929f01e1
Feed Name: The Register (Security)
Infosec roundup: Check Point warns of an actively exploited Remote Access VPN zero-day (CVE-2024-24919) that can expose local files (password hashes, SSH keys, certificates) and enable lateral movement; a Linux kernel privilege-escalation bug (CVE-2024-1086) affecting many kernel versions is also under active exploitation; multiple critical ICS/medical vulnerabilities are listed; Proofpoint documents a large advanced-fee "free piano" scam targeting academia; and Cooler Master confirmed a breach with ~103 GB of data stolen and claims of up to ~500,000 affected customers, including payment data — patches, MFA, and account hardening are recommended.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
