'Void Banshee' Exploits Second Microsoft Zero-Day
ID: 64271472-00fa-502e-9516-792b976ea588
STIX ID: report--64271472-00fa-502e-9516-792b976ea588
Feed Name: Dark Reading
Threat Score
Microsoft reclassified CVE-2024-43461 as a zero-day being exploited in the wild by the Void Banshee group in an attack chain that leverages a separate MSHTML vulnerability (CVE-2024-38112) to spoof HTA/URL handling and deliver Atlantida malware; the flaw affects all supported Windows versions, Microsoft and CISA have issued advisories, and organizations are urged to apply the July and September security updates to mitigate the active exploitation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
