Microsoft's July Update Patches 143 Flaws, Including Two Actively Exploited
ID: 3883ad87-956f-5867-9f41-17a098ce68fa
STIX ID: report--3883ad87-956f-5867-9f41-17a098ce68fa
Feed Name: The Hacker News
Microsoft's monthly security updates address 143 vulnerabilities, including two actively exploited flaws: CVE-2024-38112 (an MSHTML spoofing issue abused via .URL/IE to deliver the Atlantida infostealer) and CVE-2024-38080 (a Hyper-V elevation-of-privilege). Check Point and other researchers observed campaigns delivering Atlantida via compromised WordPress sites using .HTA and PowerShell, targeting users in Turkey and Vietnam and possibly multiple financially motivated groups; additional high-severity RCE and privilege escalation bugs (including a zero-click Office RCE) were also patched.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
