logo

Microsoft's July Update Patches 143 Flaws, Including Two Actively Exploited

ID: 3883ad87-956f-5867-9f41-17a098ce68fa

STIX ID: report--3883ad87-956f-5867-9f41-17a098ce68fa

Feed Name: The Hacker News

Threat Score
75/100

Date Published: 2024-07-10

Date Updated: 2026-05-08

Author: [email protected] (The Hacker News)

...
...

Microsoft's monthly security updates address 143 vulnerabilities, including two actively exploited flaws: CVE-2024-38112 (an MSHTML spoofing issue abused via .URL/IE to deliver the Atlantida infostealer) and CVE-2024-38080 (a Hyper-V elevation-of-privilege). Check Point and other researchers observed campaigns delivering Atlantida via compromised WordPress sites using .HTA and PowerShell, targeting users in Turkey and Vietnam and possibly multiple financially motivated groups; additional high-severity RCE and privilege escalation bugs (including a zero-click Office RCE) were also patched.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.