Botnet exploits GeoVision zero-day to install Mirai malware
ID: 2d7d6d88-5e10-5bca-a282-72a6d4d7e7cb
STIX ID: report--2d7d6d88-5e10-5bca-a282-72a6d4d7e7cb
Feed Name: Bleeping Computer
A critical zero-day OS command injection (CVE-2024-11120, CVSS 9.8) in end-of-life GeoVision devices is being actively exploited by a Mirai-like botnet to recruit roughly 17,000 internet-exposed devices—primarily for DDoS and cryptomining. Affected models (GV-VS12, GV-VS11, GV-DSP LPR V3, GV-LX4C V2/V3) are unsupported, leaving no vendor patches; recommended mitigations include device replacement, isolation on a dedicated subnet, resetting devices, changing default credentials, disabling remote access, and firewalling.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
