
Lead Article
Feature Article
Feature Article
According to Cybersixgill’s data, 325 ransomware results were detected on our Investigative Platform in February, in comparison with 313 results in January. The ransomware gang LockBit were responsible for the highest number of ransomware attacks this month. The top targeted industries were manufacturing, scientific and technical services, and construction. The United States, Italy, Canada, France and the UK were the top targeted countries.
1.
The current DVE score is 9.55. This is a critical authentication bypass vulnerability that affects the web component of Ivanti Connect Secure (ICS), formerly known as Pulse Connect Secure, and Ivanti Policy Secure gateways. This vulnerability impacts all supported versions, including Version 9.x and 22.x.
CVSS: 8.2
DVE: 9.55
2.
The current DVE score is 9.42. This vulnerability relates to a Microsoft Exchange Server Elevation of Privilege Vulnerability.
CVSS: 9.8
DVE: 9.42
3.
The current DVE score is 9.2. This relates to a vulnerability in PHP versions 8.0., 8.1., and 8.2.*. It involves insufficient length checking when loading a phar file, which can lead to a stack buffer overflow and potentially result in memory corruption or remote code execution (RCE).
CVSS: 9.8
DVE: 9.2
The most mentioned malware for February 2024
In February, Redline Stealer malware had the highest number of mentions on the underground according to the Cybersixgill Investigative Portal.
This malware harvests information from browsers such as saved credentials and credit card information. More recent versions of the malware added the ability to steal cryptocurrency.
Redline Stealer is a Malware-as-a-Service (MaaS), so threat actors can purchase it then sell the stolen data on dark web forums.