Check Point VPN zero-day exploited in attacks since April 30
ID: 700d22e2-b4c6-5345-a894-3d1510528616
STIX ID: report--700d22e2-b4c6-5345-a894-3d1510528616
Feed Name: Bleeping Computer
Threat Score
Check Point disclosed a high-severity Remote Access VPN zero-day (CVE-2024-24919) actively exploited since late April/May to enumerate and extract password hashes and Active Directory data (including ntds.dit) from vulnerable appliances; attackers have used the information for lateral movement and tunnelling, and Check Point released hotfixes and mitigation guidance to block weak credential logins and detect exploitation attempts.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
