Hackers targeting WhatsUp Gold with public exploit since August
ID: 5b5c27b0-76f0-5c84-aa64-1067039fb675
STIX ID: report--5b5c27b0-76f0-5c84-aa64-1067039fb675
Feed Name: Bleeping Computer
Hackers are actively exploiting two SQL injection vulnerabilities in Progress Software's WhatsUp Gold (CVE-2024-6670 and CVE-2024-6671) to bypass authentication, obtain administrator passwords, and achieve remote code execution via Active Monitor PowerShell scripts; attackers then use msiexec to install multiple RATs (Atera Agent, Radmin, SimpleHelp, Splashtop) to establish persistence. PoC exploit code was published Aug 30 and Trend Micro telemetry observed exploitation within hours, while patches were released by the vendor on Aug 16—unpatched systems remain at high risk.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
