CVE-2024-21412
published 2024-02-13CVE-2024-21412: Internet Shortcut Files Security Feature Bypass Vulnerability
PriorityP192high8.1CVSS 3.1
AVNACLPRNUIRSUCHIHAN
KEVITWEXPLOITRansomware
CISA Known Exploited Vulnerabilitydue 2024-03-05
Exploited in the wild
EPSS
95.44%
99.9th percentile
Internet Shortcut Files Security Feature Bypass Vulnerability
Affected
37 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | windows_10_1809 | < 10.0.17763.5458 | 10.0.17763.5458 |
| microsoft | windows_10_21h2 | < 10.0.19044.4046 | 10.0.19044.4046 |
| microsoft | windows_10_22h2 | < 10.0.19045.4046 | 10.0.19045.4046 |
| microsoft | windows_10_version_1809 | >= 10.0.0 < 10.0.17763.5458 | 10.0.17763.5458 |
| microsoft | windows_10_version_1809 | >= 10.0.17763.0 < 10.0.17763.5458 | 10.0.17763.5458 |
| microsoft | windows_10_version_21h2 | >= 10.0.19043.0 < 10.0.19044.4046 | 10.0.19044.4046 |
| microsoft | windows_10_version_22h2 | >= 10.0.19045.0 < 10.0.19045.4046 | 10.0.19045.4046 |
| microsoft | windows_11_21h2 | < 10.0.22000.2777 | 10.0.22000.2777 |
| microsoft | windows_11_22h2 | < 10.0.22621.3155 | 10.0.22621.3155 |
| microsoft | windows_11_23h2 | < 10.0.22631.3155 | 10.0.22631.3155 |
| microsoft | windows_11_version_21h2 | >= 10.0.0 < 10.0.22000.2777 | 10.0.22000.2777 |
| microsoft | windows_11_version_22h2 | >= 10.0.22621.0 < 10.0.22621.3155 | 10.0.22621.3155 |
| microsoft | windows_11_version_22h3 | >= 10.0.22631.0 < 10.0.22631.3155 | 10.0.22631.3155 |
| microsoft | windows_11_version_23h2 | >= 10.0.22631.0 < 10.0.22631.3155 | 10.0.22631.3155 |
| microsoft | windows_server_2019 | < 10.0.17763.5458 | 10.0.17763.5458 |
| microsoft | windows_server_2019 | >= 10.0.17763.0 < 10.0.17763.5458 | 10.0.17763.5458 |
| microsoft | windows_server_2022 | < 10.0.20348.2322 | 10.0.20348.2322 |
| microsoft | windows_server_2022 | >= 10.0.20348.0 < 10.0.20348.2322 | 10.0.20348.2322 |
| microsoft | windows_server_2022_23h2 | < 10.0.25398.709 | 10.0.25398.709 |
| msrc | windows_10_version_1809_for_32-bit_systems | — | — |
| msrc | windows_10_version_1809_for_arm64-based_systems | — | — |
| msrc | windows_10_version_1809_for_x64-based_systems | — | — |
| msrc | windows_10_version_21h2_for_32-bit_systems | — | — |
| msrc | windows_10_version_21h2_for_arm64-based_systems | — | — |
| msrc | windows_10_version_21h2_for_x64-based_systems | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Hunt for MSI files spawning expand.exe to decompress a CAB named 'files.cab' into a %tmp%\MW-* directory, followed by execution of a signed binary (e.g., NVIDIA Share.exe) for DLL sideloading — a key DarkGate stage-3 indicator. ↗
- →Flag phishing lures using Google DoubleClick/DDM open redirect URLs in PDFs that chain to .MSI files — a delivery pattern observed in the CVE-2024-21412 DarkGate campaign. ↗
- →CVE-2024-21412 was used as a bypass for the previously patched CVE-2023-36025; correlate detections for both vulnerabilities as threat actors chain them — the .MSI stage also exploits CVE-2023-36025 via a ZIP in the path. ↗
- ·CVE-2024-21412 is itself a bypass of the previously patched CVE-2023-36025; defenders should ensure both patches are applied as threat actors actively chain these vulnerabilities. ↗
- ·The DarkGate AutoIt loader's Sophos directory check string is obfuscated/distorted in newer versions ('CProgramDataSophos'), so detection rules targeting the exact string 'C:\Program Files(x86)\Sophos' may miss updated samples. ↗
CVSS provenance
nvdv3.18.1HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N
vulncheck8.8HIGH
cisa8.1HIGH
vendor_msrc8.1HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-2mmw-g99r-5x3v: Internet Shortcut Files Security Feature Bypass Vulnerability
ghsa_unreviewed·2024-02-13
CVE-2024-21412 [HIGH] CWE-693 GHSA-2mmw-g99r-5x3v: Internet Shortcut Files Security Feature Bypass Vulnerability
Internet Shortcut Files Security Feature Bypass Vulnerability
VulnCheck
Microsoft SmartScreen Prompt Security Feature Bypass Vulnerability
vulncheck·2024·CVSS 7.8
CVE-2024-29988 [HIGH] CWE-693 Microsoft SmartScreen Prompt Security Feature Bypass Vulnerability
Microsoft SmartScreen Prompt Security Feature Bypass Vulnerability
Microsoft SmartScreen Prompt contains a security feature bypass vulnerability that allows an attacker to bypass the Mark of the Web (MotW) feature. This vulnerability can be chained with CVE-2023-38831 and CVE-2024-21412 to execute a malicious file.
Affected: Microsoft SmartScreen Prompt
Required Action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Exploitation References: https://www.zerodayinitiative.com/blog/2024/4/9/the-april-2024-security-updates-review; https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json; https://www.zerodayinitiative.com/blog/2024/8/14/cve-2024-38213-copy2pwn-exploit-evades-windows-web-protections; http
VulnCheck
Microsoft Windows Internet Shortcut Files Security Feature Bypass Vulnerability
vulncheck·2024·CVSS 8.1
CVE-2024-21412 [HIGH] CWE-693 Microsoft Windows Internet Shortcut Files Security Feature Bypass Vulnerability
Microsoft Windows Internet Shortcut Files Security Feature Bypass Vulnerability
Microsoft Windows Internet Shortcut Files contains an unspecified vulnerability that allows for a security feature bypass.
Affected: Microsoft Windows
Required Action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Known Ransomware Campaign Use: Known
Exploitation References: https://api.msrc.microsoft.com/cvrf/v3.0/cvrf/2024-Feb; https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-21412; https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json; https://www.trendmicro.com/en_us/research/24/b/cve202421412-water-hydra-targets-traders-with-windows-defender-s.html; https://www.trendmicro.com/en_us/research/24/c/c
VulnCheck
Microsoft Windows SmartScreen Security Feature Bypass Vulnerability
vulncheck·2023·CVSS 8.8
CVE-2023-36025 [HIGH] Microsoft Windows SmartScreen Security Feature Bypass Vulnerability
Microsoft Windows SmartScreen Security Feature Bypass Vulnerability
Microsoft Windows SmartScreen contains a security feature bypass vulnerability that could allow an attacker to bypass Windows Defender SmartScreen checks and their associated prompts.
Affected: Microsoft Windows
Required Action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Known Ransomware Campaign Use: Known
Exploitation References: https://api.msrc.microsoft.com/cvrf/v3.0/cvrf/2023-Nov; https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json; https://twitter.com/ffforward/status/1726540034462159165; https://www.trendmicro.com/en_us/research/24/a/cve-2023-36025-exploited-for-defense-evasion-in-phemedrone-steal.html; https://uni
CISA
Microsoft SmartScreen Prompt Security Feature Bypass Vulnerability
cisa·2024-04-30·CVSS 7.8
CVE-2024-29988 [HIGH] CWE-693 Microsoft SmartScreen Prompt Security Feature Bypass Vulnerability
Vulnerability: Microsoft SmartScreen Prompt Security Feature Bypass Vulnerability
Affected: Microsoft SmartScreen Prompt
Microsoft SmartScreen Prompt contains a security feature bypass vulnerability that allows an attacker to bypass the Mark of the Web (MotW) feature. This vulnerability can be chained with CVE-2023-38831 and CVE-2024-21412 to execute a malicious file.
Required Action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Notes: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-29988; https://nvd.nist.gov/vuln/detail/CVE-2024-29988
Remediation Due Date: 2024-05-21
Microsoft
Internet Shortcut Files Security Feature Bypass Vulnerability
vendor_msrc·2024-02-13·CVSS 8.1
CVE-2024-21412 [HIGH] CWE-693 Internet Shortcut Files Security Feature Bypass Vulnerability
Internet Shortcut Files Security Feature Bypass Vulnerability
FAQ: According to the CVSS metric, user interaction is required (UI:R). What interaction would the user have to do?
An attacker must send the user a malicious file and convince them to open it.
FAQ: How could an attacker exploit the vulnerability?
An unauthenticated attacker could send the targeted user a specially crafted file that is designed to bypass displayed security checks. However, the attacker would have no way to force a user to view the attacker-controlled content. Instead, the attacker would have to convince them to take action by clicking on the file link.
Internet Shortcut Files: Internet Shortcut Files
Microsoft: Microsoft
Customer Action Required: Yes
Impact: Security Feature Bypass
Exploit Status: Publicl
CISA
Microsoft Windows Internet Shortcut Files Security Feature Bypass Vulnerability
cisa·2024-02-13·CVSS 8.1
CVE-2024-21412 [HIGH] CWE-693 Microsoft Windows Internet Shortcut Files Security Feature Bypass Vulnerability
Vulnerability: Microsoft Windows Internet Shortcut Files Security Feature Bypass Vulnerability
Affected: Microsoft Windows
Microsoft Windows Internet Shortcut Files contains an unspecified vulnerability that allows for a security feature bypass.
Required Action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Notes: https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2024-21412; https://nvd.nist.gov/vuln/detail/CVE-2024-21412
Remediation Due Date: 2024-03-05
No detection rules found.
No public exploits indexed.
Greynoiseio
The Noise in the Silence: Unmasking CISA's Hidden KEV Ransomware Updates
blogs_greynoiseio·2026-02-02
The Noise in the Silence: Unmasking CISA's Hidden KEV Ransomware Updates
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Find out immediately if an asset communicates with a malicious IP address
Vulnerability Prioritization Get real-time insight into active exploitation trends to better understand risk and severity
SOC Efficiency Filter out noisy, low priority and false-positive alerts from mass internet scanners
Incident Investigation Add context to incidents to speed the determinations of scope and timelines
Threat Hunting Quickly identify anomalous behavior and enrich your threat hunting campaigns
Why GreyNoise
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Fin
Sentinelone
DragonForce Ransomware Gang | From Hacktivists to High Street Extortionists
blogs_sentinelone·2025-05-03
DragonForce Ransomware Gang | From Hacktivists to High Street Extortionists
In recent weeks, the DragonForce ransomware group has been targeting UK retailers in a series of coordinated attacks causing major service disruptions. Prominent retailers such as Harrods, Marks and Spencer, and the Co-Op have all reported ongoing incidents affecting payment systems, inventory, payroll and other critical business functions.
DragonForce has previously been attributed for a number of notable cyber incidents including attacks on Honolulu OTS (Oahu Transit Services), the Government of Palau, Coca-Cola (Singapore), the Ohio State Lottery, and Yakult Australia.
In this post, we offer a high-level overview of the DragonForce group, discuss its targeting, initial access methods, and payloads. We further provide a comprehensive list of indicators and defensive recommendations to
Sentinelone
DragonForce Ransomware Gang | From Hacktivists to High Street Extortionists
blogs_sentinelone·2025-05-03
DragonForce Ransomware Gang | From Hacktivists to High Street Extortionists
In recent weeks, the DragonForce ransomware group has been targeting UK retailers in a series of coordinated attacks causing major service disruptions. Prominent retailers such as Harrods, Marks and Spencer, and the Co-Op have all reported ongoing incidents affecting payment systems, inventory, payroll and other critical business functions.
DragonForce has previously been attributed for a number of notable cyber incidents including attacks on Honolulu OTS (Oahu Transit Services), the Government of Palau, Coca-Cola (Singapore), the Ohio State Lottery, and Yakult Australia.
In this post, we offer a high-level overview of the DragonForce group, discuss its targeting, initial access methods, and payloads. We further provide a comprehensive list of indicators and defensive recommendations to
Bleepingcomputer
7-Zip fixes bug that bypasses Windows MoTW security warnings, patch now
blogs_bleepingcomputer·2025-01-21·CVSS 7.0
[HIGH] 7-Zip fixes bug that bypasses Windows MoTW security warnings, patch now
## 7-Zip fixes bug that bypasses Windows MoTW security warnings, patch now
## Sergiu Gatlan
A high-severity vulnerability in the 7-Zip file archiver allows attackers to bypass the Mark of the Web (MotW) Windows security feature and execute code on users' computers when extracting malicious files from nested archives.
7-Zip added support for MotW in June 2022 , starting with version 22.00. Since then, it has automatically added MotW flags (special 'Zone.Id' alternate data streams) to all files extracted from downloaded archives.
This flag informs the operating system, web browsers, and other applications that files may come from untrusted sources and should be treated with caution.
As a result, when double-clicking risky files extracted using 7-Zip, users will be warned that opening o
Tenable
Microsoft Patch Tuesday 2024 Year in Review
blogs_tenable·2024-12-10
Microsoft Patch Tuesday 2024 Year in Review
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Fortinet
Threat Actors Exploit GeoServer Vulnerability CVE-2024-36401 | FortiGuard Labs
blogs_fortinet·2024-09-05·CVSS 9.8
CVE-2024-36401 [CRITICAL] Threat Actors Exploit GeoServer Vulnerability CVE-2024-36401 | FortiGuard Labs
FORTIGUARD LABS THREAT RESEARCH
Threat Actors Exploit GeoServer Vulnerability CVE-2024-36401
Overview
GOREVERSE
SideWalk
Mirai Variant - JenX
Condi
CoinMiner
[1]
[2]
[3]
[4]
Conclusion
Fortinet Protection
IoC
URL
IP Address/Hostname
Wallet
SHA256Hash
By Cara Lin and Vincent Li | September 05, 2024
Affected Platforms: GeoServer prior to versions 2.23.6, 2.24.4, and 2.25.2
Impacted Users: Any organization
Impact: Remote attackers gain control of the vulnerable systems
Severity Level: Critical
GeoServer is an open-source software server written in Java that allows users to share and edit geospatial data. It is the reference implementation of the Open Geospatial Consortium (OGC) Web Feature Service (WFS) and Web Coverage Service (WCS) standards. On July 1, the project maintainers released
Trendmicro
CVE-2024-38213: Copy2Pwn Exploit Evades Windows Web Protections
blogs_trendmicro·2024-08-15·CVSS 8.1
CVE-2024-38213 [HIGH] CVE-2024-38213: Copy2Pwn Exploit Evades Windows Web Protections
## CVE-2024-38213: Copy2Pwn Exploit Evades Windows Web Protections
Learn how the cve-2024-38213 and copy2pwn exploit evades Windows web protections.
By: Peter Girnus 2024/08/15 Read time: ( words)
Save to Folio
Zero Day Initiative threat researchers discovered CVE-2024-38213, a simple and effective way to bypass Windows mark-of-the-web protections leading to remote code execution.
In March 2024, Trend Micro’s Zero Day Initiative Threat Hunting team started analyzing samples connected to the activity carried out by DarkGate operators to infect users through copy-and-paste operations. This DarkGate campaign was an update from a previous campaign in which the DarkGate operators were exploiting a zero-day vulnerability, CVE-2024-21412 , which we disclosed to Microsoft earlier this year.
Trendmicro
CVE-2024-38213: Copy2Pwn Exploit Evades Windows Web Protections
blogs_trendmicro·2024-08-15·CVSS 8.1
CVE-2024-38213 [HIGH] CVE-2024-38213: Copy2Pwn Exploit Evades Windows Web Protections
# CVE-2024-38213: Copy2Pwn Exploit Evades Windows Web Protections
Learn how the cve-2024-38213 and copy2pwn exploit evades Windows web protections.
By: Peter Girnus
2024/08/15
Read time: ( words)
Save to Folio
Zero Day Initiative threat researchers discovered CVE-2024-38213, a simple and effective way to bypass Windows mark-of-the-web protections leading to remote code execution.
In March 2024, Trend Micro’s Zero Day Initiative Threat Hunting team started analyzing samples connected to the activity carried out by DarkGate operators to infect users through copy-and-paste operations. This DarkGate campaign was an update from a previous campaign in which the DarkGate operators were exploiting a zero-day vulnerability, CVE-2024-21412, which we disclosed to Microsoft earlier this year.
T
Bleepingcomputer
New Windows SmartScreen bypass exploited as zero-day since March
blogs_bleepingcomputer·2024-08-13·CVSS 8.1
[HIGH] New Windows SmartScreen bypass exploited as zero-day since March
## New Windows SmartScreen bypass exploited as zero-day since March
## Sergiu Gatlan
"An attacker who successfully exploited this vulnerability could bypass the SmartScreen user experience. An attacker must send the user a malicious file and convince them to open it," Redmond explains in a security advisory published on Tuesday.
Despite the increased difficulty in exploiting it, Trend Micro security researcher Peter Girnus discovered that the vulnerability was being exploited in the wild in March. Girnus reported the attacks to Microsoft, who patched the flaw during the June 2024 Patch Tuesday. However, the company forgot to include the advisory with that month's security updates (or with July's).
"In March 2024, Trend Micro's Zero Day Initiative Threat Hunting team started analyzing s
Qualys
Cybersecurity Threat Landscape 2024 Midyear Review
blogs_qualys·2024-08-06
Cybersecurity Threat Landscape 2024 Midyear Review
## Table of Contents
Key Takeaways from the Threat Landscape Report 2024
Vulnerability and Threat Analysis in the Cybersecurity Landscape 2024
Cyber Threat Landscape 2024 A Detailed Review
Key Statistics and Their Impact on the 2024 Cybersecurity Landscape
Mid-2024s Most Exploited Vulnerabilities in the Cybersecurity Landscape
Conclusion
As we navigate the complexities of 2024, it’s crucial to pause and reflect on the evolving threat landscape that surrounds us. This moment offers a unique opportunity to scrutinize our triumphs and missteps, understand the events that have decisively shaped our environment, and consider those that have subtly influenced it. By extracting key lessons from our recent experiences, we can fortify our strategies and prepare more effectively for the emerg
Fortinet
Exploiting CVE-2024-21412: A Stealer Campaign Unleashed | FortiGuard Labs
blogs_fortinet·2024-07-23·CVSS 8.1
CVE-2024-21412 [HIGH] Exploiting CVE-2024-21412: A Stealer Campaign Unleashed | FortiGuard Labs
FORTIGUARD LABS THREAT RESEARCH
Exploiting CVE-2024-21412: A Stealer Campaign Unleashed
Initial Access
Shell Code Injector
Final Stealers
Conclusion
Fortinet Protections
IOCs
IP Addresses
Hostnames
Files
By Cara Lin | July 23, 2024
Affected Platforms: Microsoft Windows
Impacted Users: Microsoft Windows
Impact: The stolen information can be used for future attack
Severity Level: High
CVE-2024-21412 is a security bypass vulnerability in Microsoft Windows SmartScreen that arises from an error in handling maliciously crafted files. A remote attacker can exploit this flaw to bypass the SmartScreen security warning dialog and deliver malicious files. Over the past year, several attackers, including Water Hydra, Lumma Stealer, and Meduza Stealer, have exploited this vulnerability.
FortiGuard
Trendmicro
Behind the Great Wall: Void Arachne Targets Chinese-Speaking Users With the Winos 4.0 C&C Framework
blogs_trendmicro·2024-06-19
Behind the Great Wall: Void Arachne Targets Chinese-Speaking Users With the Winos 4.0 C&C Framework
APT y ataques dirigidos
## Behind the Great Wall: Void Arachne Targets Chinese-Speaking Users With the Winos 4.0 C&C Framework
We recently discovered a new threat actor group that we dubbed Void Arachne. This group targets Chinese-speaking users with malicious Windows Installer (MSI) files in a recent campaign. These MSI files contain legitimate software installer files for AI software and other popular software but are bundled with malicious Winos payloads.
By: Peter Girnus, Aliakbar Zahravi, Ahmed Mohamed Ibrahim Jun 19, 2024 Read time: ( words)
Save to Folio
Report highlights:
We recently discovered a new threat actor group that we dubbed Void Arachne. This group targets Chinese-speaking users with malicious Windows Installer (MSI) files in a recent campaign. These MSI files conta
Trendmicro
Behind the Great Wall: Void Arachne Targets Chinese-Speaking Users With the Winos 4.0 C&C Framework
blogs_trendmicro·2024-06-19
Behind the Great Wall: Void Arachne Targets Chinese-Speaking Users With the Winos 4.0 C&C Framework
APT & Targeted Attacks
## Behind the Great Wall: Void Arachne Targets Chinese-Speaking Users With the Winos 4.0 C&C Framework
We recently discovered a new threat actor group that we dubbed Void Arachne. This group targets Chinese-speaking users with malicious Windows Installer (MSI) files in a recent campaign. These MSI files contain legitimate software installer files for AI software and other popular software but are bundled with malicious Winos payloads.
By: Peter Girnus, Aliakbar Zahravi, Ahmed Mohamed Ibrahim Jun 19, 2024 Read time: ( words)
Save to Folio
Report highlights:
We recently discovered a new threat actor group that we dubbed Void Arachne. This group targets Chinese-speaking users with malicious Windows Installer (MSI) files in a recent campaign. These MSI files contai
Trendmicro
Behind the Great Wall: Void Arachne Targets Chinese-Speaking Users With the Winos 4.0 C&C Framework
blogs_trendmicro·2024-06-19
Behind the Great Wall: Void Arachne Targets Chinese-Speaking Users With the Winos 4.0 C&C Framework
APT & Targeted Attacks
## Behind the Great Wall: Void Arachne Targets Chinese-Speaking Users With the Winos 4.0 C&C Framework
We recently discovered a new threat actor group that we dubbed Void Arachne. This group targets Chinese-speaking users with malicious Windows Installer (MSI) files in a recent campaign. These MSI files contain legitimate software installer files for AI software and other popular software but are bundled with malicious Winos payloads.
By: Peter Girnus, Aliakbar Zahravi, Ahmed Mohamed Ibrahim 2024/06/19 Read time: ( words)
Save to Folio
Report highlights:
We recently discovered a new threat actor group that we dubbed Void Arachne. This group targets Chinese-speaking users with malicious Windows Installer (MSI) files in a recent campaign. These MSI files contain
Trendmicro
Behind the Great Wall: Void Arachne Targets Chinese-Speaking Users With the Winos 4.0 C&C Framework
blogs_trendmicro·2024-06-19
Behind the Great Wall: Void Arachne Targets Chinese-Speaking Users With the Winos 4.0 C&C Framework
APT & Targeted Attacks
# Behind the Great Wall: Void Arachne Targets Chinese-Speaking Users With the Winos 4.0 C&C Framework
We recently discovered a new threat actor group that we dubbed Void Arachne. This group targets Chinese-speaking users with malicious Windows Installer (MSI) files in a recent campaign. These MSI files contain legitimate software installer files for AI software and other popular software but are bundled with malicious Winos payloads.
By: Peter Girnus, Aliakbar Zahravi, Ahmed Mohamed Ibrahim
2024/06/19
Read time: ( words)
Save to Folio
Report highlights:
- We recently discovered a new threat actor group that we dubbed Void Arachne. This group targets Chinese-speaking users with malicious Windows Installer (MSI) files in a recent campaign. These MSI files contai
Securelist
Exploits and vulnerabilities in Q1 2024
blogs_securelist·2024-05-07·CVSS 7.8
CVE-2024-3094 [HIGH] Exploits and vulnerabilities in Q1 2024
Table of Contents
Statistics on registered vulnerabilities
Exploitation statistics
Windows and Linux vulnerability exploitation
Public exploit statistics
Most prevalent exploits
Vulnerability exploitation in APT attacks
Notable Q1 2024 vulnerabilities
CVE-2024-3094 (XZ)
CVE-2024-20656 (Visual Studio)
CVE-2024-21626 (runc)
CVE-2024-1708 (ScreenConnect)
CVE-2024-21412 (Windows Defender)
CVE-2024-27198 (TeamCity)
CVE-2023-38831 (WinRAR)
Conclusions and advice
Authors
Alexander Kolesnikov
Vitaly Morgunov
We at Kaspersky continuously monitor the evolving cyberthreat landscape to ensure we respond promptly to emerging threats, equipping our products with detection logic and technology. Software vulnerabilities that threat actors can exploit or are already actively exploiting a
Securelist
Analyzing the vulnerability landscape in Q1 2024
blogs_securelist·2024-05-07
Analyzing the vulnerability landscape in Q1 2024
Table of Contents
- Statistics on registered vulnerabilities
- Exploitation statistics
- Vulnerability exploitation in APT attacks
- Notable Q1 2024 vulnerabilities
- Conclusions and advice
Authors
- Alexander Kolesnikov
- Vitaly Morgunov
We at Kaspersky continuously monitor the evolving cyberthreat landscape to ensure we respond promptly to emerging threats, equipping our products with detection logic and technology. Software vulnerabilities that threat actors can exploit or are already actively exploiting are a critical component of that landscape. In this report, we present a series of insightful statistical and analytical snapshots relating to the trends in the emergence of new vulnerabilities and exploits, as well as the most prevalent vulnerabilities being used by attackers. Add
Trendmicro
The April 2024 Security Updates Review
blogs_trendmicro·2024-04-09
The April 2024 Security Updates Review
# The April 2024 Security Updates Review
Get the April 2024 security update and review.
By: Dustin Childs
2024/04/09
Read time: ( words)
Save to Folio
It’s the second Tuesday of the month, and Adobe and Microsoft have released a fresh crop of security updates. Take a break from your other activities and join us as we review the details of their latest advisories. If you’d rather watch the full video recap covering the entire release, you can check it out here:
Adobe Patches for April 2024
For April, Adobe released nine patches addressing 24 CVEs in Adobe After Effects, Photoshop, Commerce, InDesign, Experience Manager, Media Encoder, Bridge, Illustrator, and Adobe Animate. The largest of these updates is for Experience Manager, however, all of the bugs being patched are simple Cross
Bleepingcomputer
Microsoft fixes two Windows zero-days exploited in malware attacks
blogs_bleepingcomputer·2024-04-09·CVSS 6.7
CVE-2024-26234 [MEDIUM] Microsoft fixes two Windows zero-days exploited in malware attacks
## Microsoft fixes two Windows zero-days exploited in malware attacks
## Sergiu Gatlan
Microsoft has fixed two actively exploited zero-day vulnerabilities during the April 2024 Patch Tuesday, although the company failed to initially tag them as such.
The first, tracked as CVE-2024-26234 and described as a proxy driver spoofing vulnerability, was issued to track a malicious driver signed using a valid Microsoft Hardware Publisher Certificate that was found by Sophos X-Ops in December 2023 and reported by team lead Christopher Budd.
This malicious file was labeled as "Catalog Authentication Client Service" by "Catalog Thales," likely an attempt to impersonate Thales Group. However, further investigation revealed that it was previously bundled with a marketing software called LaiXi Androi
Tenable
Microsoft’s April 2024 Patch Tuesday Addresses 147 CVEs (CVE-2024-29988)
blogs_tenable·2024-04-09·CVSS 8.8
[HIGH] Microsoft’s April 2024 Patch Tuesday Addresses 147 CVEs (CVE-2024-29988)
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Bleepingcomputer
Microsoft April 2024 Patch Tuesday fixes 150 security flaws, 67 RCEs
blogs_bleepingcomputer·2024-04-09·CVSS 8.1
[HIGH] Microsoft April 2024 Patch Tuesday fixes 150 security flaws, 67 RCEs
## Microsoft April 2024 Patch Tuesday fixes 150 security flaws, 67 RCEs
## Lawrence Abrams
There were also fixes for twenty-six Secure Boot bypasses released this month, including two from Lenovo.
The number of bugs in each vulnerability category is listed below:
31 Elevation of Privilege Vulnerabilities
29 Security Feature Bypass Vulnerabilities
67 Remote Code Execution Vulnerabilities
13 Information Disclosure Vulnerabilities
7 Denial of Service Vulnerabilities
3 Spoofing Vulnerabilities
The total count of 150 flaws does not include 5 Microsoft Edge flaws fixed on April 4th and 2 Mariner flaws. Mariner is an open-source Linux distribution developed by Microsoft for its Microsoft Azure services.
To learn more about the non-security updates released today, you can review our ded
Trendmicro
The April 2024 Security Updates Review
blogs_trendmicro·2024-04-09
The April 2024 Security Updates Review
## The April 2024 Security Updates Review
Get the April 2024 security update and review.
By: Dustin Childs 2024/04/09 Read time: ( words)
Save to Folio
It’s the second Tuesday of the month, and Adobe and Microsoft have released a fresh crop of security updates. Take a break from your other activities and join us as we review the details of their latest advisories. If you’d rather watch the full video recap covering the entire release, you can check it out here:
Adobe Patches for April 2024
For April, Adobe released nine patches addressing 24 CVEs in Adobe After Effects, Photoshop, Commerce, InDesign, Experience Manager, Media Encoder, Bridge, Illustrator, and Adobe Animate. The largest of these updates is for Experience Manager , however, all of the bugs being patched are simple Cros
Krebs
April’s Patch Tuesday Brings Record Number of Fixes
blogs_krebs·2024-04-09·CVSS 8.1
[HIGH] April’s Patch Tuesday Brings Record Number of Fixes
If only Patch Tuesdays came around infrequently — like total solar eclipse rare — instead of just creeping up on us each month like The Man in the Moon. Although to be fair, it would be tough for Microsoft to eclipse the number of vulnerabilities fixed in this month’s patch batch — a record 147 flaws in Windows and related software.
Yes, you read that right. Microsoft today released updates to address 147 security holes in Windows, Office , Azure , .NET Framework , Visual Studio , SQL Server , DNS Server , Windows Defender , Bitlocker , and Windows Secure Boot .
“This is the largest release from Microsoft this year and the largest since at least 2017,” said Dustin Childs , from Trend Micro’s Zero Day Initiative (ZDI). “As far as I can tell, it’s the largest Patch Tuesday release from Mic
Krebs
April’s Patch Tuesday Brings Record Number of Fixes
blogs_krebs·2024-04-09·CVSS 8.1
[HIGH] April’s Patch Tuesday Brings Record Number of Fixes
If only Patch Tuesdays came around infrequently — like total solar eclipse rare — instead of just creeping up on us each month like The Man in the Moon. Although to be fair, it would be tough for Microsoft to eclipse the number of vulnerabilities fixed in this month’s patch batch — a record 147 flaws in Windows and related software.
Yes, you read that right. Microsoft today released updates to address 147 security holes in Windows, Office, Azure, .NET Framework, Visual Studio, SQL Server, DNS Server, Windows Defender, Bitlocker, and Windows Secure Boot.
“This is the largest release from Microsoft this year and the largest since at least 2017,” said Dustin Childs, from Trend Micro’s Zero Day Initiative (ZDI). “As far as I can tell, it’s the largest Patch Tuesday release from Microsoft of
Trendmicro
DarkGate nutzt Windows SmartScreen-Bypass aus
blogs_trendmicro·2024-03-19·CVSS 8.1
CVE-2024-21412 [HIGH] DarkGate nutzt Windows SmartScreen-Bypass aus
APT und gezielte Angriffe
## DarkGate nutzt Windows SmartScreen-Bypass aus
Die ZDI entdeckte eine DarkGate-Kampagne, bei der die Schwachstelle CVE-2024-21412 ausgenutzt wurde. Wir haben untersucht, wie der Bypass zusammen mit Open Redirects und Fake Installern zur Verbreitung von Malware führt.
By: Peter Girnus, Aliakbar Zahravi, Simon Zuckerbraun Mar 19, 2024 Read time: ( words)
Save to Folio
Die Zero Day Initiative (ZDI) hat Mitte Januar 2024 eine DarkGate-Kampagne aufgedeckt, bei der die Schwachstelle CVE-2024-21412 mit Hilfe von gefälschten Software-Installationsprogrammen ausgenutzt wurde. Nutzer wurden zum Einsatz von PDFs geködert, die offene Weiterleitungen von Google DoubleClick Digital Marketing (DDM) enthielten. Darüber kamen ahnungslose Opfer zu kompromittierten Websites,
Trendmicro
CVE-2024-21412: DarkGate Operators Exploit Microsoft Windows SmartScreen Bypass in Zero-Day Campaign
blogs_trendmicro·2024-03-13·CVSS 8.1
CVE-2024-21412 [HIGH] CVE-2024-21412: DarkGate Operators Exploit Microsoft Windows SmartScreen Bypass in Zero-Day Campaign
Exploits & Vulnerabilities
## CVE-2024-21412: DarkGate Operators Exploit Microsoft Windows SmartScreen Bypass in Zero-Day Campaign
In addition to our Water Hydra APT zero day analysis, the Zero Day Initiative (ZDI) observed a DarkGate campaign which we discovered in mid-January 2024 where DarkGate operators exploited CVE-2024-21412.
By: Peter Girnus, Aliakbar Zahravi, Simon Zuckerbraun Mar 13, 2024 Read time: ( words)
Save to Folio
The Zero Day Initiative (ZDI) recently uncovered a DarkGate campaign in mid-January 2024, which exploited CVE-2024-21412 through the use of fake software installers. During this campaign, users were lured using PDFs that contained Google DoubleClick Digital Marketing (DDM) open redirects that led unsuspecting victims to compromised sites hosting the Microso
Trendmicro
CVE-2024-21412: DarkGate Operators Exploit Microsoft Windows SmartScreen Bypass in Zero-Day Campaign
blogs_trendmicro·2024-03-13·CVSS 8.1
CVE-2024-21412 [HIGH] CVE-2024-21412: DarkGate Operators Exploit Microsoft Windows SmartScreen Bypass in Zero-Day Campaign
Exploits & Vulnerabilities
## CVE-2024-21412: DarkGate Operators Exploit Microsoft Windows SmartScreen Bypass in Zero-Day Campaign
In addition to our Water Hydra APT zero day analysis, the Zero Day Initiative (ZDI) observed a DarkGate campaign which we discovered in mid-January 2024 where DarkGate operators exploited CVE-2024-21412.
By: Peter Girnus, Aliakbar Zahravi, Simon Zuckerbraun 2024/03/13 Read time: ( words)
Save to Folio
The Zero Day Initiative (ZDI) recently uncovered a DarkGate campaign in mid-January 2024, which exploited CVE-2024-21412 through the use of fake software installers. During this campaign, users were lured using PDFs that contained Google DoubleClick Digital Marketing (DDM) open redirects that led unsuspecting victims to compromised sites hosting the Microsoft
Bleepingcomputer
Hackers exploit Windows SmartScreen flaw to drop DarkGate malware
blogs_bleepingcomputer·2024-03-13·CVSS 8.1
[HIGH] Hackers exploit Windows SmartScreen flaw to drop DarkGate malware
## Hackers exploit Windows SmartScreen flaw to drop DarkGate malware
## Bill Toulas
Attackers can exploit the flaw by creating a Windows Internet shortcut (.url file) that points to another .url file hosted on a remote SMB share, which would cause the file at the final location to be executed automatically.
Microsoft fixed the flaw in mid-February, with Trend Micro disclosing that the financially motivated Water Hydra hacking group previously exploited it as a zero-day to drop their DarkMe malware onto traders' systems.
Today, Trend Micro analysts reported that DarkGate operators are exploiting the same flaw to improve their chances of success (infection) on targeted systems.
This is a significant development for the malware, which, together with Pikabot, has filled the void created b
Trendmicro
CVE-2024-21412: DarkGate Operators Exploit Microsoft Windows SmartScreen Bypass in Zero-Day Campaign
blogs_trendmicro·2024-03-13·CVSS 8.1
CVE-2024-21412 [HIGH] CVE-2024-21412: DarkGate Operators Exploit Microsoft Windows SmartScreen Bypass in Zero-Day Campaign
Ausnutzung von Schwachstellen
## CVE-2024-21412: DarkGate Operators Exploit Microsoft Windows SmartScreen Bypass in Zero-Day Campaign
In addition to our Water Hydra APT zero day analysis, the Zero Day Initiative (ZDI) observed a DarkGate campaign which we discovered in mid-January 2024 where DarkGate operators exploited CVE-2024-21412.
By: Peter Girnus, Aliakbar Zahravi, Simon Zuckerbraun Mar 13, 2024 Read time: ( words)
Save to Folio
The Zero Day Initiative (ZDI) recently uncovered a DarkGate campaign in mid-January 2024, which exploited CVE-2024-21412 through the use of fake software installers. During this campaign, users were lured using PDFs that contained Google DoubleClick Digital Marketing (DDM) open redirects that led unsuspecting victims to compromised sites hosting the Micr
Trendmicro
CVE-2024-21412: DarkGate Operators Exploit Microsoft Windows SmartScreen Bypass in Zero-Day Campaign
blogs_trendmicro·2024-03-13·CVSS 8.1
CVE-2024-21412 [HIGH] CVE-2024-21412: DarkGate Operators Exploit Microsoft Windows SmartScreen Bypass in Zero-Day Campaign
Exploits & Vulnerabilities
# CVE-2024-21412: DarkGate Operators Exploit Microsoft Windows SmartScreen Bypass in Zero-Day Campaign
In addition to our Water Hydra APT zero day analysis, the Zero Day Initiative (ZDI) observed a DarkGate campaign which we discovered in mid-January 2024 where DarkGate operators exploited CVE-2024-21412.
By: Peter Girnus, Aliakbar Zahravi, Simon Zuckerbraun
2024/03/13
Read time: ( words)
Save to Folio
The Zero Day Initiative (ZDI) recently uncovered a DarkGate campaign in mid-January 2024, which exploited CVE-2024-21412 through the use of fake software installers. During this campaign, users were lured using PDFs that contained Google DoubleClick Digital Marketing (DDM) open redirects that led unsuspecting victims to compromised sites hosting the Microsoft
Trendmicro
CVE-2024-21412: DarkGate Operators Exploit Microsoft Windows SmartScreen Bypass in Zero-Day Campaign
blogs_trendmicro·2024-03-13·CVSS 8.1
CVE-2024-21412 [HIGH] CVE-2024-21412: DarkGate Operators Exploit Microsoft Windows SmartScreen Bypass in Zero-Day Campaign
Exploits y vulnerabilidades
## CVE-2024-21412: DarkGate Operators Exploit Microsoft Windows SmartScreen Bypass in Zero-Day Campaign
In addition to our Water Hydra APT zero day analysis, the Zero Day Initiative (ZDI) observed a DarkGate campaign which we discovered in mid-January 2024 where DarkGate operators exploited CVE-2024-21412.
By: Peter Girnus, Aliakbar Zahravi, Simon Zuckerbraun Mar 13, 2024 Read time: ( words)
Save to Folio
The Zero Day Initiative (ZDI) recently uncovered a DarkGate campaign in mid-January 2024, which exploited CVE-2024-21412 through the use of fake software installers. During this campaign, users were lured using PDFs that contained Google DoubleClick Digital Marketing (DDM) open redirects that led unsuspecting victims to compromised sites hosting the Micros
Checkpoint
19th February – Threat Intelligence Report
blogs_checkpoint·2024-02-19
CVE-2024-21413 19th February – Threat Intelligence Report
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 19th February – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 19th February, please download our Threat_Intelligence Bulletin .
TOP ATTACKS AND BREACHES
Romanian hospital patients’ data management system, Hipocrate IT Platform, was hit by a ransomware attack, leading to data encryption of over 20 Bucharest hospitals. The attack rendered the hospital staff resorting to manual logging and tracking of critical patient data and progress. Another 79 Romanian hospitals using
Trendmicro
SmartScreen Vulnerability CVE-2024-21412: Fakten und Fixes
blogs_trendmicro·2024-02-16·CVSS 8.8
CVE-2024-21412 [HIGH] SmartScreen Vulnerability CVE-2024-21412: Fakten und Fixes
APT und gezielte Angriffe
## SmartScreen Vulnerability CVE-2024-21412: Fakten und Fixes
Derzeit nutzt die APT-Gruppe Water Hydra die Schwachstelle CVE-2024-21412 aktiv aus. Wir liefern alle nötigen Informationen zu CVE-2024-21412, wie sie von Bedrohungsakteuren eingesetzt werden kann und wie Unternehmen sich schützen können.
By: Trend Micro Feb 16, 2024 Read time: ( words)
Save to Folio
Am 13. Februar 2024 veröffentlichte Microsoft einen Patch für CVE-2024-21412, eine Microsoft Defender SmartScreen -Schwachstelle bezüglich Internet Shortcuts. Zuvor hatten wir entdeckt, dass eine APT-Gruppe namens Water Hydra CVE-2024-21412 in einer ausgeklügelten Kampagne mit Ziel Finanzmarkthändler ausnutzt. Die Lücke erlaubt es, den Microsoft Defender SmartScreen zu umgehen und potenzielle Opfer mit
Trendmicro
SmartScreen Vulnerability: CVE-2024-21412 Facts and Fixes
blogs_trendmicro·2024-02-13·CVSS 8.8
CVE-2024-21412 [HIGH] SmartScreen Vulnerability: CVE-2024-21412 Facts and Fixes
Exploits y vulnerabilidades
## SmartScreen Vulnerability: CVE-2024-21412 Facts and Fixes
This entry aims to provide additional context to CVE-2024-21412, how it can be used by threat actors, and how Trend protects customers from this specific vulnerability.
By: Trend Micro Research Feb 13, 2024 Read time: ( words)
Save to Folio
On Feb. 13, 2024, Microsoft issued a patch for CVE-2024-21412, a Microsoft Defender SmartScreen vulnerability revolving around internet shortcuts. Previously, we discovered that an advanced persistent threat (APT) group we track under the name Water Hydra has been exploiting CVE-2024-21412 in a sophisticated campaign targeting financial market traders, allowing the group to bypass Microsoft Defender SmartScreen and infect its victims with the DarkMe remote acce
Tenable
Microsoft’s February 2024 Patch Tuesday Addresses 73 CVEs (CVE-2024-21351, CVE-2024-21412)
blogs_tenable·2024-02-13·CVSS 7.6
[HIGH] Microsoft’s February 2024 Patch Tuesday Addresses 73 CVEs (CVE-2024-21351, CVE-2024-21412)
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Bleepingcomputer
Microsoft February 2024 Patch Tuesday fixes 2 zero-days, 73 flaws
blogs_bleepingcomputer·2024-02-13·CVSS 7.6
[HIGH] Microsoft February 2024 Patch Tuesday fixes 2 zero-days, 73 flaws
## Microsoft February 2024 Patch Tuesday fixes 2 zero-days, 73 flaws
## Lawrence Abrams
16 Elevation of Privilege Vulnerabilities
3 Security Feature Bypass Vulnerabilities
30 Remote Code Execution Vulnerabilities
5 Information Disclosure Vulnerabilities
9 Denial of Service Vulnerabilities
10 Spoofing Vulnerabilities
The total count of 73 flaws does not include 6 Microsoft Edge flaws fixed on February 8th and 1 Mariner flaw.
To learn more about the non-security updates released today, you can review our dedicated articles on the new Windows 11 KB5034765 cumulative update and the Windows 10 KB5034763 update .
## Two zero-days fixed
This month's Patch Tuesday fixes two actively exploited zero-day vulnerabilities, which Microsoft classifies as a flaw that is publicly disclosed or ac
Qualys
Microsoft and Adobe Patch Tuesday, February 2024 Security Update Review | Qualys
blogs_qualys·2024-02-13
Microsoft and Adobe Patch Tuesday, February 2024 Security Update Review | Qualys
#### Table of Contents
- Microsoft Patch Tuesday for February 2024
- Adobe Patches for February 2024
- Zero-day Vulnerabilities Patched in February Patch Tuesday Edition
- Other Critical Severity Vulnerabilities Patched in February Patch Tuesday Edition
- Other Microsoft Vulnerability Highlights
- Microsoft Release Summary
- Discover and Prioritize Vulnerabilities in Vulnerability Management, Detection & Response (VMDR)
- Rapid Response with Patch Management (PM)
- EVALUATE Vendor-Suggested Mitigation with Policy Compliance (PC)
- Qualys Monthly Webinar Series
The new Microsoft Patch Tuesday Edition for February 2024 is now live! We invite you to join us to review and discuss the details of these security updates and patches.
## Microsoft Patch Tuesday for February 2024
Microsoft Patch
Bleepingcomputer
Hackers used new Windows Defender zero-day to drop DarkMe malware
blogs_bleepingcomputer·2024-02-13·CVSS 8.8
CVE-2024-21412 [HIGH] Hackers used new Windows Defender zero-day to drop DarkMe malware
## Hackers used new Windows Defender zero-day to drop DarkMe malware
## Sergiu Gatlan
"However, the attacker would have no way to force a user to view the attacker-controlled content. Instead, the attacker would have to convince them to take action by clicking on the file link."
Trend Micro security researcher Peter Girnus, credited for reporting this zero-day, revealed that the CVE-2024-21412 flaw bypasses another Defender SmartScreen vulnerability (CVE-2023-36025).
CVE-2023-36025 was patched during the November 2023 Patch Tuesday , and, as Trend Micro revealed last month, it was also exploited to bypass Windows security prompts when opening URL files to deploy the Phemedrone info-stealer malware .
## Zero-day used to target financial market traders
The zero-day that Microsoft patch
Qualys
Microsoft and Adobe Patch Tuesday, February 2024 Security Update Review
blogs_qualys·2024-02-13
Microsoft and Adobe Patch Tuesday, February 2024 Security Update Review
## Table of Contents
Microsoft Patch Tuesday for February 2024
Adobe Patches for February 2024
Zero-day Vulnerabilities Patched in February Patch Tuesday Edition
Other Critical Severity Vulnerabilities Patched in February Patch Tuesday Edition
Other Microsoft Vulnerability Highlights
Microsoft Release Summary
Discover and Prioritize Vulnerabilities in Vulnerability Management, Detection & Response (VMDR)
Rapid Response with Patch Management (PM)
EVALUATE Vendor-Suggested Mitigation with Policy Compliance (PC)
Qualys Monthly Webinar Series
The new Microsoft Patch Tuesday Edition for February 2024 is now live! We invite you to join us to review and discuss the details of these security updates and patches.
## Microsoft Patch Tuesday for February 2024
Microsoft Patch Tuesday’s Fe
Trendmicro
SmartScreen Vulnerability: CVE-2024-21412 Facts and Fixes
blogs_trendmicro·2024-02-13·CVSS 8.8
CVE-2024-21412 [HIGH] SmartScreen Vulnerability: CVE-2024-21412 Facts and Fixes
Exploits & Vulnerabilities
## SmartScreen Vulnerability: CVE-2024-21412 Facts and Fixes
This entry aims to provide additional context to CVE-2024-21412, how it can be used by threat actors, and how Trend protects customers from this specific vulnerability.
By: Trend Micro Research 2024/02/13 Read time: ( words)
Save to Folio
On Feb. 13, 2024, Microsoft issued a patch for CVE-2024-21412, a Microsoft Defender SmartScreen vulnerability revolving around internet shortcuts. Previously, we discovered that an advanced persistent threat (APT) group we track under the name Water Hydra has been exploiting CVE-2024-21412 in a sophisticated campaign targeting financial market traders, allowing the group to bypass Microsoft Defender SmartScreen and infect its victims with the DarkMe remote access
Trendmicro
CVE-2024-21412: Water Hydra Targets Traders with Microsoft Defender SmartScreen Zero-Day
blogs_trendmicro·2024-02-13·CVSS 8.1
CVE-2024-21412 [HIGH] CVE-2024-21412: Water Hydra Targets Traders with Microsoft Defender SmartScreen Zero-Day
Ausnutzung von Schwachstellen
## CVE-2024-21412: Water Hydra Targets Traders With Microsoft Defender SmartScreen Zero-Day
The APT group Water Hydra has been exploiting the Microsoft Defender SmartScreen vulnerability (CVE-2024-21412) in its campaigns targeting financial market traders. This vulnerability, which has now been patched by Microsoft, was discovered and disclosed by the Trend Micro Zero Day Initiative.
By: Peter Girnus, Aliakbar Zahravi, Simon Zuckerbraun Feb 13, 2024 Read time: ( words)
Save to Folio
The Trend Micro Zero Day Initiative discovered the vulnerability CVE-2024-21412 which we track as ZDI-CAN-23100, and alerted Microsoft of a Microsoft Defender SmartScreen bypass used as part of a sophisticated zero-day attack chain by the advanced persistent threat (APT) group
Krebs
Fat Patch Tuesday, February 2024 Edition
blogs_krebs·2024-02-13·CVSS 5.4
CVE-2024-21412 [MEDIUM] Fat Patch Tuesday, February 2024 Edition
Microsoft Corp. today pushed software updates to plug more than 70 security holes in its Windows operating systems and related products, including two zero-day vulnerabilities that are already being exploited in active attacks.
Top of the heap on this Fat Patch Tuesday is CVE-2024-21412, a “security feature bypass” in the way Windows handles Internet Shortcut Files that Microsoft says is being targeted in active exploits. Redmond’s advisory for this bug says an attacker would need to convince or trick a user into opening a malicious shortcut file.
Researchers at Trend Micro have tied the ongoing exploitation of CVE-2024-21412 to an advanced persistent threat group dubbed “Water Hydra,” which they say has being using the vulnerability to execute a malicious Microsoft Installer File (.msi)
Trendmicro
CVE-2024-21412: Water Hydra Targets Traders with Microsoft Defender SmartScreen Zero-Day
blogs_trendmicro·2024-02-13·CVSS 8.1
CVE-2024-21412 [HIGH] CVE-2024-21412: Water Hydra Targets Traders with Microsoft Defender SmartScreen Zero-Day
Exploits & Vulnerabilities
# CVE-2024-21412: Water Hydra Targets Traders With Microsoft Defender SmartScreen Zero-Day
The APT group Water Hydra has been exploiting the Microsoft Defender SmartScreen vulnerability (CVE-2024-21412) in its campaigns targeting financial market traders. This vulnerability, which has now been patched by Microsoft, was discovered and disclosed by the Trend Micro Zero Day Initiative.
By: Peter Girnus, Aliakbar Zahravi, Simon Zuckerbraun
2024/02/13
Read time: ( words)
Save to Folio
The Trend Micro Zero Day Initiative discovered the vulnerability CVE-2024-21412 which we track as ZDI-CAN-23100, and alerted Microsoft of a Microsoft Defender SmartScreen bypass used as part of a sophisticated zero-day attack chain by the advanced persistent threat (APT) group we t
Krebs
Fat Patch Tuesday, February 2024 Edition
blogs_krebs·2024-02-13·CVSS 5.4
CVE-2024-21412 [MEDIUM] Fat Patch Tuesday, February 2024 Edition
Microsoft Corp. today pushed software updates to plug more than 70 security holes in its Windows operating systems and related products, including two zero-day vulnerabilities that are already being exploited in active attacks.
Top of the heap on this Fat Patch Tuesday is CVE-2024-21412 , a “security feature bypass” in the way Windows handles Internet Shortcut Files that Microsoft says is being targeted in active exploits. Redmond’s advisory for this bug says an attacker would need to convince or trick a user into opening a malicious shortcut file.
Researchers at Trend Micro have tied the ongoing exploitation of CVE-2024-21412 to an advanced persistent threat group dubbed “ Water Hydra ,” which they say has being using the vulnerability to execute a malicious Microsoft Installer File (.m
Trendmicro
CVE-2024-21412: Water Hydra Targets Traders with Microsoft Defender SmartScreen Zero-Day
blogs_trendmicro·2024-02-13·CVSS 8.1
CVE-2024-21412 [HIGH] CVE-2024-21412: Water Hydra Targets Traders with Microsoft Defender SmartScreen Zero-Day
Exploits & Vulnerabilities
## CVE-2024-21412: Water Hydra Targets Traders With Microsoft Defender SmartScreen Zero-Day
The APT group Water Hydra has been exploiting the Microsoft Defender SmartScreen vulnerability (CVE-2024-21412) in its campaigns targeting financial market traders. This vulnerability, which has now been patched by Microsoft, was discovered and disclosed by the Trend Micro Zero Day Initiative.
By: Peter Girnus, Aliakbar Zahravi, Simon Zuckerbraun Feb 13, 2024 Read time: ( words)
Save to Folio
The Trend Micro Zero Day Initiative discovered the vulnerability CVE-2024-21412 which we track as ZDI-CAN-23100, and alerted Microsoft of a Microsoft Defender SmartScreen bypass used as part of a sophisticated zero-day attack chain by the advanced persistent threat (APT) group we
Trendmicro
SmartScreen Vulnerability: CVE-2024-21412 Facts and Fixes
blogs_trendmicro·2024-02-13·CVSS 8.8
CVE-2024-21412 [HIGH] SmartScreen Vulnerability: CVE-2024-21412 Facts and Fixes
Exploits & Vulnerabilities
## SmartScreen Vulnerability: CVE-2024-21412 Facts and Fixes
This entry aims to provide additional context to CVE-2024-21412, how it can be used by threat actors, and how Trend protects customers from this specific vulnerability.
By: Trend Micro Research Feb 13, 2024 Read time: ( words)
Save to Folio
On Feb. 13, 2024, Microsoft issued a patch for CVE-2024-21412, a Microsoft Defender SmartScreen vulnerability revolving around internet shortcuts. Previously, we discovered that an advanced persistent threat (APT) group we track under the name Water Hydra has been exploiting CVE-2024-21412 in a sophisticated campaign targeting financial market traders, allowing the group to bypass Microsoft Defender SmartScreen and infect its victims with the DarkMe remote acces
Trendmicro
SmartScreen Vulnerability: CVE-2024-21412 Facts and Fixes
blogs_trendmicro·2024-02-13·CVSS 8.8
CVE-2024-21412 [HIGH] SmartScreen Vulnerability: CVE-2024-21412 Facts and Fixes
Exploits & Vulnerabilities
# SmartScreen Vulnerability: CVE-2024-21412 Facts and Fixes
This entry aims to provide additional context to CVE-2024-21412, how it can be used by threat actors, and how Trend protects customers from this specific vulnerability.
By: Trend Micro Research
2024/02/13
Read time: ( words)
Save to Folio
On Feb. 13, 2024, Microsoft issued a patch for CVE-2024-21412, a Microsoft Defender SmartScreen vulnerability revolving around internet shortcuts. Previously, we discovered that an advanced persistent threat (APT) group we track under the name Water Hydra has been exploiting CVE-2024-21412 in a sophisticated campaign targeting financial market traders, allowing the group to bypass Microsoft Defender SmartScreen and infect its victims with the DarkMe remote access
Trendmicro
CVE-2024-21412: Water Hydra Targets Traders with Microsoft Defender SmartScreen Zero-Day
blogs_trendmicro·2024-02-13·CVSS 8.1
CVE-2024-21412 [HIGH] CVE-2024-21412: Water Hydra Targets Traders with Microsoft Defender SmartScreen Zero-Day
Exploits & Vulnerabilities
## CVE-2024-21412: Water Hydra Targets Traders With Microsoft Defender SmartScreen Zero-Day
The APT group Water Hydra has been exploiting the Microsoft Defender SmartScreen vulnerability (CVE-2024-21412) in its campaigns targeting financial market traders. This vulnerability, which has now been patched by Microsoft, was discovered and disclosed by the Trend Micro Zero Day Initiative.
By: Peter Girnus, Aliakbar Zahravi, Simon Zuckerbraun 2024/02/13 Read time: ( words)
Save to Folio
The Trend Micro Zero Day Initiative discovered the vulnerability CVE-2024-21412 which we track as ZDI-CAN-23100, and alerted Microsoft of a Microsoft Defender SmartScreen bypass used as part of a sophisticated zero-day attack chain by the advanced persistent threat (APT) group we t
Trendmicro
CVE-2024-21412: Water Hydra Targets Traders with Microsoft Defender SmartScreen Zero-Day
blogs_trendmicro·2024-02-13·CVSS 8.1
CVE-2024-21412 [HIGH] CVE-2024-21412: Water Hydra Targets Traders with Microsoft Defender SmartScreen Zero-Day
Exploits y vulnerabilidades
## CVE-2024-21412: Water Hydra Targets Traders With Microsoft Defender SmartScreen Zero-Day
The APT group Water Hydra has been exploiting the Microsoft Defender SmartScreen vulnerability (CVE-2024-21412) in its campaigns targeting financial market traders. This vulnerability, which has now been patched by Microsoft, was discovered and disclosed by the Trend Micro Zero Day Initiative.
By: Peter Girnus, Aliakbar Zahravi, Simon Zuckerbraun Feb 13, 2024 Read time: ( words)
Save to Folio
The Trend Micro Zero Day Initiative discovered the vulnerability CVE-2024-21412 which we track as ZDI-CAN-23100, and alerted Microsoft of a Microsoft Defender SmartScreen bypass used as part of a sophisticated zero-day attack chain by the advanced persistent threat (APT) group w
Trendmicro
The February 2024 Security Update Review
blogs_trendmicro·2024-02-12·CVSS 7.5
[HIGH] The February 2024 Security Update Review
## The February 2024 Security Update Review
Get the Feburary 2024 security update and review.
By: Dustin Childs 2024/02/12 Read time: ( words)
Save to Folio
It’s the second patch Tuesday of the year, and Adobe and Microsoft have released a fresh crop of security updates just in time to be our Valentine. Take a break from your other activities and join us as we review the details of their latest advisories. For those interested in the Microsoft 0-day discovered by the ZDI Threat Hunting Team, you can watch this special edition of the Patch Report:
If you’d rather watch the full video recap covering the entire release, you can check out here:
CVE
Title
Severity
CVSS
Public
Exploited
Type
CVE-2024-21412
Internet Shortcut Files Security Feature Bypass Vulnerability
Important
8.
Trendmicro
The February 2024 Security Update Review
blogs_trendmicro·2024-02-12
The February 2024 Security Update Review
# The February 2024 Security Update Review
Get the Feburary 2024 security update and review.
By: Dustin Childs
2024/02/12
Read time: ( words)
Save to Folio
It’s the second patch Tuesday of the year, and Adobe and Microsoft have released a fresh crop of security updates just in time to be our Valentine. Take a break from your other activities and join us as we review the details of their latest advisories. For those interested in the Microsoft 0-day discovered by the ZDI Threat Hunting Team, you can watch this special edition of the Patch Report:
If you’d rather watch the full video recap covering the entire release, you can check out here:
Adobe Patches for February 2024
For February, Adobe released six patches addressing 29 CVEs in Adobe Acrobat and Reader, Commerce, Substance 3D
Trendmicro
The February 2024 Security Update Review
blogs_trendmicro·2024-02-12·CVSS 7.5
[HIGH] The February 2024 Security Update Review
## The February 2024 Security Update Review
Get the Feburary 2024 security update and review.
By: Dustin Childs Feb 12, 2024 Read time: ( words)
Save to Folio
It’s the second patch Tuesday of the year, and Adobe and Microsoft have released a fresh crop of security updates just in time to be our Valentine. Take a break from your other activities and join us as we review the details of their latest advisories. For those interested in the Microsoft 0-day discovered by the ZDI Threat Hunting Team, you can watch this special edition of the Patch Report:
If you’d rather watch the full video recap covering the entire release, you can check out here:
CVE
Title
Severity
CVSS
Public
Exploited
Type
CVE-2024-21412
Internet Shortcut Files Security Feature Bypass Vulnerability
Important
Trendmicro
The February 2024 Security Update Review
blogs_trendmicro·2024-02-12·CVSS 7.5
[HIGH] The February 2024 Security Update Review
## The February 2024 Security Update Review
Get the February 2024 security update and review.
By: Dustin Childs Feb 12, 2024 Read time: ( words)
Save to Folio
It’s the second patch Tuesday of the year, and Adobe and Microsoft have released a fresh crop of security updates just in time to be our Valentine. Take a break from your other activities and join us as we review the details of their latest advisories. For those interested in the Microsoft 0-day discovered by the ZDI Threat Hunting Team, you can watch this special edition of the Patch Report:
If you’d rather watch the full video recap covering the entire release, you can check out here:
CVE
Title
Severity
CVSS
Public
Exploited
Type
CVE-2024-21412
Internet Shortcut Files Security Feature Bypass Vulnerability
Important
Fortinet
Deceptive Cracked Software Spreads Lumma Variant on YouTube | FortiGuard Labs
blogs_fortinet·2024-01-08
Deceptive Cracked Software Spreads Lumma Variant on YouTube | FortiGuard Labs
FORTIGUARD LABS THREAT RESEARCH
Deceptive Cracked Software Spreads Lumma Variant on YouTube
Initial Infection Vector
.NET Executable – Installer-Install-2023_v0y.6.6.exe
DLL File – Agacantwhitey.dll
Lumma Stealer Variant
Conclusion
Fortinet Protections
IOCs
IP Addresses
Hostnames
Files
By Cara Lin | January 08, 2024
Affected Platforms: Microsoft Windows
Impacted Users: Microsoft Windows
Impact: The information collected can be used for future attacks
Severity Level: High
FortiGuard Labs recently discovered a threat group using YouTube channels to distribute a Lumma Stealer variant. We found and reported on a similar attack method via YouTube in March 2023. These YouTube videos typically feature content related to cracked applications, presenting users with similar installation guides a
Fortinet
Insights on TorrentLocker
blogs_fortinet·2016-07-25
Insights on TorrentLocker
FORTIGUARD LABS THREAT RESEARCH
Insights on TorrentLocker
By Lilia Elena Gonzalez Medina | July 25, 2016
Summary
During the last weeks there have been several cases of international brand names being used by malware authors to propagate malware through phishing emails. These emails contain misleading links that download malicious Zip files, which, in turn, contain a JavaScript file that downloads the TorrentLocker ransomware. The malicious files have been detected as JS/Agent.2867!tr or JS/Nemucod.AFA!tr.dldr or JS/Nemucod.AFE!tr.dldr by the Fortinet Antivirus service.
Since most of the available reports about this threat cover the encryption functionality, this report focuses on some less known but still critical aspects of this threat.
JavaScript File
Figure 1. The Obfuscated Code
Huntress
CVE-2024-21412 Vulnerability: Analysis, Detection, Removal | Huntress
blogs_huntress·CVSS 8.1
CVE-2024-21412 [HIGH] CVE-2024-21412 Vulnerability: Analysis, Detection, Removal | Huntress
## CVE-2024-21412 Vulnerability
Published: 12/05/2025
Written by: Lizzie Danielson
## What is CVE-2024-21412 Vulnerability?
CVE-2024-21412 is a r emote code execution (RCE) vulnerability found in certain versions of [specific software/system name here]. Exploiting this flaw allows attackers to execute arbitrary commands or malicious payloads on the victim’s system. It is tracked under the Common Vulnerabilities and Exposures (CVE) system with the identifier CVE-2024-21412 and has a CVSS score of [insert score here], indicating its severity.
## When was it discovered?
CVE-2024-21412 was first disclosed by Trend Micro Zero Day Initiative. Following its discovery, the vulnerability was publicly recognized on [public disclosure date], emphasizing the timeline urgency for patch deployment
Trendmicro
Trend Micro
blogs_trendmicro
Trend Micro
Elimine la separación entre la protección frente a amenazas y la gestión del riesgo cibernético
El líder en gestión de exposiciones: convirtiendo la visibilidad de los ciberriesgos en una seguridad proactiva y decisiva
Detenga a los adversarios con una visibilidad sin igual, impulsada por la inteligencia de XDR, SIEM agente y SOAR agente para dejar a los atacantes en ningún lugar
La plataforma de seguridad en la nube más fiable para desarrolladores, equipos de seguridad y empresas
Amplíe la visibilidad de la nube y optimice las investigaciones del SOC
Simplifique la seguridad de sus aplicaciones nativas en la nube con un avanzado análisis de imágenes de contenedor, control de admisión con base en política y protección de tiempo de ejecución del contenedor
Proteja el flujo de trabajo
Trendmicro
Trend Micro
blogs_trendmicro
Trend Micro
Bridge threat protection and cyber risk management
Browse Trend-approved partner solutions for our leading platform
Your environment, your choice – deploy Trend Vision One™ as SaaS or customer hosted
The leader in Exposure Management – turning cyber risk visibility into decisive, proactive security
Stop adversaries with unrivaled visibility, powered by the intelligence of XDR, Agentic SIEM, and Agentic SOAR to leave attackers with nowhere left to hide
The most trusted cloud security platform for developers, security teams, and businesses
Extend visibility to the cloud and streamline SOC investigations
Secure your data center, cloud, and containers without compromising performance by leveraging a cloud security platform with CNAPP capabilities
Simplify security for your cloud-native
Trendmicro
Trend Micro
blogs_trendmicro
Trend Micro
Verbindet den Schutz vor Bedrohungen und das Management des Cyberrisikos
Spitzenreiter im Bereich Exposure Management – macht Cyberrisiken transparent und sorgt für entschlossene, proaktive Sicherheit
Stoppen Sie Angreifer mit unübertroffener Transparenz, unterstützt durch XDR, agentenbasiertes SIEM und SOAR – damit Angreifer sich nirgendwo mehr verstecken können
Nutzen Sie die bewährte Cloud-Sicherheitsplattform für Entwickler, Sicherheitsteams und Unternehmen.
Erweiterung der Transparenz auf die Cloud und Optimierung von SOC-Untersuchungen
Vereinfachen Sie die Sicherheit für Ihre Cloud-nativen Anwendungen durch erweitertes Container-Image-Scanning, richtlinienbasierte Zugriffssteuerung und Container-Laufzeitschutz.
Schützen Sie Anwendungsworkflows und Cloud-Speicher vor neuen und k
Crowdstrike
February 2024 Patch Tuesday: Updates and Analysis
blogs_crowdstrike·CVSS 7.5
CVE-2026-20929 [HIGH] February 2024 Patch Tuesday: Updates and Analysis
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
How Charlotte AI AgentWorks Fuels Security's Agentic Ecosystem Mar 25, 2026
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
How Charlotte AI AgentWorks Fuels Security's Agentic Ecosystem Mar 25, 2026
Video Highlights the 4 Key Steps to Successful Incident Response Dec 02, 2019
Helping Non-Security Stakeholders Understand ATT&CK in 10 Minutes or Less [VI
Trendmicro
Trend Micro
blogs_trendmicro
Trend Micro
Bridge threat protection and cyber risk management
Browse Trend-approved partner solutions for our leading platform
Your environment, your choice – deploy Trend Vision One™ as SaaS or customer hosted
The leader in Exposure Management – turning cyber risk visibility into decisive, proactive security
Stop adversaries with unrivaled visibility, powered by the intelligence of XDR, Agentic SIEM, and Agentic SOAR to leave attackers with nowhere left to hide
The most trusted cloud security platform for developers, security teams, and businesses
Extend visibility to the cloud and streamline SOC investigations
Secure your data centre, cloud, and containers without compromising performance by leveraging a cloud security platform with CNAPP capabilities
Simplify security for your cloud-native
Trendmicro
Trend Micro
blogs_trendmicro
Trend Micro
Bridge threat protection and cyber risk management
Browse Trend-approved partner solutions for our leading platform
Your environment, your choice – deploy Trend Vision One™ as SaaS or customer hosted
The leader in Exposure Management – turning cyber risk visibility into decisive, proactive security
Stop adversaries with unrivaled visibility, powered by the intelligence of XDR, Agentic SIEM, and Agentic SOAR to leave attackers with nowhere left to hide
The most trusted cloud security platform for developers, security teams, and businesses
Extend visibility to the cloud and streamline SOC investigations
Secure your data center, cloud, and containers without compromising performance by leveraging a cloud security platform with CNAPP capabilities
Simplify security for your cloud-native
Trendmicro
Trend Micro
blogs_trendmicro
Trend Micro
Collega la protezione dalle minacce e la gestione del rischio informatico
Scopri le soluzioni dei partner approvate da Trend per la nostra piattaforma leader
Il leader nella gestione dell'esposizione: trasformare la visibilità del rischio informatico in una sicurezza decisiva e proattiva
Blocca gli aggressori con una visibilità ineguagliabile, basata sull'intelligenza di XDR, Agentic SIEM e Agentic SOAR, che non lascia agli aggressori alcun posto dove nascondersi.
La piattaforma di sicurezza cloud più affidabile per sviluppatori, team di sicurezza e aziende
Estensione della visibilità al cloud e semplificazione delle indagini SOC
Semplifica la sicurezza delle applicazioni native per il cloud con scansione avanzata delle immagini dei container, controllo dell'accesso basato su criteri
2024-02-13
Published
2024-02-13
Added to CISA KEV
Exploited in the wild