logo

Exploits and vulnerabilities in Q1 2024

ID: a378c3f5-4c09-51ba-a814-46f040fc39a2

STIX ID: report--a378c3f5-4c09-51ba-a814-46f040fc39a2

Feed Name: Securelist by Kaspersky

Threat Score
85/100

Date Published: 2024-05-07

Date Updated: 2026-04-29

Author: Alexander Kolesnikov, Vitaly Morgunov

...
...

Kaspersky presents an analysis of vulnerability trends and exploit activity for 2023–Q1 2024, showing increasing numbers of registered CVEs and publicly available exploits, active exploitation observed in telemetry, and APT usage patterns; notable Q1 2024 issues include an injected backdoor in the XZ compression library, a Visual Studio DACL-reset privilege escalation, a container escape in runc, active ScreenConnect and TeamCity web vulnerabilities, a SmartScreen bypass technique, and continued exploitation of the WinRAR flaw, with recommendations to prioritize asset visibility, patch management, and layered defenses.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.