Fake attachment. Roundcube mail server attacks exploit CVE-2024-37383 vulnerability.


In September 2024, threat intelligence experts from the Positive Technologies Security Expert Center (PT ESC) discovered an email sent to a governmental organization belonging to a CIS country. Timestamps indicate that the email was sent back in June 2024. The email appeared to be a message without text, containing only an attached document.

However, the email client didn’t show the attachment. The body of the email contained distinctive tags with the statement eval(atob(…)), which decode and execute JavaScript code:

Read more…
Source: Positive Technologies


Sign up for our Newsletter


Related:

  • Hackers breach Foreign Office computers in cyber attack on Government countryside outpost

    January 15, 2021

    It is understood the attack is not connected to the devastating cyber attack on the Solar Winds Orion software, which US officials pin on Russian hackers. The Foreign Office has not commented on any suspects of its investigation, but tonight confirmed the breach, which was first reported by The Sun. A Government spokesperson said: ‘We take data ...

  • Xiaomi added to US list of alleged Communist Chinese military companies

    January 15, 2021

    Chinese hardware manufacturer Xiaomi has been added to a list of alleged Communist Chinese military companies by the United States Department of Defense. “The Department is determined to highlight and counter the People’s Republic of China’s (PRC) Military-Civil Fusion development strategy, which supports the modernisation goals of the People’s Liberation Army by ensuring its access to ...

  • Microsoft addresses a Critical RCE vulnerability affecting the Netlogon protocol CVE-2020-1472

    January 14, 2021

    Microsoft addressed a Critical RCE vulnerability affecting the Netlogon protocol (CVE-2020-1472) on August 11, 2020. We are reminding our customers that beginning with the February 9, 2021 Security Update release we will be enabling Domain Controller enforcement mode by default. This will block vulnerable connections from non-compliant devices. DC enforcement mode requires that all Windows ...

  • Apple removes feature that allowed its apps to bypass macOS firewalls and VPNs

    January 14, 2021

    Apple has removed a controversial feature from the macOS operating system that allowed 53 of Apple’s own apps to bypass third-party firewalls, security tools, and VPN apps installed by users for their protection. Known as the ContentFilterExclusionList, the list was included in macOS 11, also known as Big Sur. The exclusion list included some of Apple’s biggest ...

  • CISCO says it won’t patch 74 security bugs in older RV routers that reached EOL

    January 14, 2021

    Networking equipment vendor Cisco said yesterday it was not going to release firmware updates to fix 74 vulnerabilities that had been reported in its line of RV routers, which had reached end-of-life (EOL). Affected devices include Cisco Small Business RV110W, RV130, RV130W, and RV215W systems, which can be used as both routers, firewalls, and VPNs. All four ...

  • The Top Worry In Cloud Security for 2021

    January 13, 2021

    The cloud is an environment full of potential. It provides easy access to technologies that simple weren’t available a decade ago. You can now launch the equivalent of an entire data center with a single command. Scaling to meet the demands of millions of customers can be entirely automated. Advanced machine learning analysis is as simple ...