29th April – Threat Intelligence Report
ID: 0b7cc79f-27a0-54b4-be73-3657ab621e4f
STIX ID: report--0b7cc79f-27a0-54b4-be73-3657ab621e4f
Feed Name: Check Point Research
**Executive summary:** This bulletin reports multiple high-impact active threats: long-running state-sponsored espionage targeting Volkswagen and government networks, active exploitation of a CrushFTP unauthenticated zero-day (CVE-2024-4040), ransomware incidents with data exfiltration (Medusa, Skanlog) disrupting services, and campaigns abusing Cisco perimeter devices (ArcaneDoor). It also highlights vulnerability disclosures and patches (Chrome, Flowmon PoC), and technical analyses of APTs and malware (APT28/GooseEgg, CoralRaider, LightSpy, ToddyCat), recommending urgent patching and heightened monitoring for affected systems.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
