Cyble Sensors Uncover Cyberattacks Targeting Key Vulnerabilities
ID: 95c553ba-3dac-5e78-a9e4-3f70f7df11ed
STIX ID: report--95c553ba-3dac-5e78-a9e4-3f70f7df11ed
Feed Name: The Cyber Express
Cyble’s sensors detected active exploitation between October 2–8, 2024 of more than 40 vulnerabilities, highlighting four high-risk issues — Ruby SAML signature verification bypass (CVE-2024-45409), aiohttp path traversal (CVE-2024-23334), D-Link NAS hard-coded credentials (CVE-2024-3272), and PriceListo WordPress SQLi (CVE-2024-38793) — and reported thousands of brute-force attacks (mainly targeting ports 22, 445, 23, 3389) plus 351 new phishing email addresses; the report recommends patching, retiring affected EOL devices, disabling insecure options, and enforcing strong password policies.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
