US and UK govts warn: Russia scanning for your unpatched vulnerabilities
ID: 63687e16-69f6-5ae8-b75e-b9d6a962e8d6
STIX ID: report--63687e16-69f6-5ae8-b75e-b9d6a962e8d6
Feed Name: The Register (Security)
A joint US/UK advisory warns that SVR-linked APT29 operators are mass-scanning and opportunistically exploiting a list of 24 known CVEs, increasing global risk; the bulletin also urges patching for a critical GitLab flaw (CVE-2024-9164), recommends encrypting persistent cookies on F5 Big‑IP LTM devices to prevent network enumeration, calls out rising phone-assisted phishing (TOAD) social-engineering campaigns, and notes Google’s new Global Signal Exchange to share scam indicators. Organizations are advised to prioritize patches, harden configurations, disable unnecessary internet-facing services, baseline devices, and train staff against phone-based scams.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
