all InfoSec news
Magnet Goblin Targets Publicly Facing Servers Using 1-Day Vulnerabilities
March 9, 2024, 4:11 a.m. | MalBot
Malware Analysis, News and Indicators - Latest topics malware.news
Key Points
- Magnet Goblin is a financially motivated threat actor that quickly adopts and leverages 1-day vulnerabilities in public-facing services as an initial infection vector. At least in one case of Ivanti Connect Secure VPN (CVE-2024-21887), the exploit entered the group’s arsenal as fast as within 1 day after a POC for it was published.
- Campaigns that we were able to attribute to this actor targeted Ivanti, Magento, Qlink Sense and possibly Apache ActiveMQ.
- Analysis of the actor’s recent Ivanti …
actor arsenal case connect connect secure cve cve-2024-21887 exploit facing fast infection ivanti ivanti connect secure ivanti connect secure vpn key key points magnet malware analysis poc points public quickly secure vpn servers services threat threat actor vpn vulnerabilities
More from malware.news / Malware Analysis, News and Indicators - Latest topics
New Redline Version: Uses Lua Bytecode, Propagates Through GitHub
1 day, 3 hours ago |
malware.news
Showcasing Artwork by Max for Autism Awareness Month
1 day, 16 hours ago |
malware.news
Kaiser Permanente notifies 13.4M patients of potential data exposure
1 day, 17 hours ago |
malware.news
Jobs in InfoSec / Cybersecurity
SOC 2 Manager, Audit and Certification
@ Deloitte | US and CA Multiple Locations
Security Officer Hospital Laguna Beach
@ Allied Universal | Laguna Beach, CA, United States
Sr. Cloud DevSecOps Engineer
@ Oracle | NOIDA, UTTAR PRADESH, India
Cloud Operations Security Engineer
@ Elekta | Crawley - Cornerstone
Cybersecurity – Senior Information System Security Manager (ISSM)
@ Boeing | USA - Seal Beach, CA
Engineering -- Tech Risk -- Security Architecture -- VP -- Dallas
@ Goldman Sachs | Dallas, Texas, United States