CISA Adds WhatsUp Gold, MSHTML Vulnerabilities List
ID: 7cf0636f-211b-51bb-a93e-8fd9faa2585d
STIX ID: report--7cf0636f-211b-51bb-a93e-8fd9faa2585d
Feed Name: Cyble Blog
Threat Score
Cyble warns that CISA has added two actively exploited vulnerabilities to its Known Exploited Vulnerabilities catalog: CVE-2024-6670 (Progress WhatsUp Gold, critical 9.8, exploited quickly after PoC with observed RCE and 381 internet-exposed instances) and CVE-2024-43461 (MSHTML UI-spoofing used in a chained exploit); organizations are urged to apply vendor patches, check for IOCs, and follow recommended mitigation best practices.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
