Chinese APT Uses VPN Bug to Exploit Worldwide OT Orgs
ID: c5883905-67d1-5acd-ab6f-d7a76ff68a9f
STIX ID: report--c5883905-67d1-5acd-ab6f-d7a76ff68a9f
Feed Name: Dark Reading
Check Point researchers uncovered a months-long campaign exploiting CVE-2024-24919 (a path traversal bug in Check Point security gateways) that allowed unauthenticated attackers to access sensitive files and escalate privileges; the attackers—attributed with low confidence to APT41—used the access to move laterally in networks of OT and manufacturing organizations worldwide and install the ShadowPad backdoor, apparently to steal intellectual property. The activity affected two to three dozen victim organizations across the Americas, Europe, the Middle East, and Africa, with many targets being small manufacturers or supply-chain suppliers that lacked rapid patching and robust security.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
