logo

'Void Banshee' Exploits Second Microsoft Zero-Day

ID: 64271472-00fa-502e-9516-792b976ea588

STIX ID: report--64271472-00fa-502e-9516-792b976ea588

Feed Name: Dark Reading

Threat Score
85/100

Date Published: 2024-09-16

Date Updated: 2026-04-21

Author: Jai Vijayan, Contributing Writer

...
...

Microsoft reclassified CVE-2024-43461 as a zero-day being exploited in the wild by the Void Banshee group in an attack chain that leverages a separate MSHTML vulnerability (CVE-2024-38112) to spoof HTA/URL handling and deliver Atlantida malware; the flaw affects all supported Windows versions, Microsoft and CISA have issued advisories, and organizations are urged to apply the July and September security updates to mitigate the active exploitation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.