logo

CISA warns of Windows flaw used in infostealer malware attacks

ID: c5c80f1c-a4ef-5127-a868-40384fd71a89

STIX ID: report--c5c80f1c-a4ef-5127-a868-40384fd71a89

Feed Name: Bleeping Computer

Threat Score
85/100

Date Published: 2024-09-16

Date Updated: 2026-04-20

Author: Sergiu Gatlan

...
...

CISA ordered U.S. federal agencies to patch a Microsoft MSHTML zero-day (CVE-2024-43461) actively exploited by the Void Banshee APT in an exploit chain that delivered HTA files disguised as PDFs (using encoded braille whitespace) to deploy the Atlantida information-stealer; Microsoft confirmed pre-patch exploitation and advised applying both July and September security updates.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.