"Void Banshee Exploits Microsoft Zero-Day to Spread Malware"

TL;DR Summary
The APT group Void Banshee is exploiting a zero-day vulnerability in Microsoft's MHTML browser engine (CVE-2024-38112) to spread the Atlantida information stealer. This flaw, addressed in Microsoft's recent Patch Tuesday, is used in multi-stage attacks involving spear-phishing emails and malicious URL files. The campaign highlights the rapid exploitation of disclosed vulnerabilities and the ongoing threat posed by advanced cyber actors.
Topics:technology#atlantida-stealer#cve-2024-38112#cybersecurity#data-security-vulnerability#microsoft-mhtml#void-banshee
- Void Banshee APT Exploits Microsoft MHTML Flaw to Spread Atlantida Stealer The Hacker News
- Microsoft Windows Deadline—You Have 21 Days To Update Your PC Forbes
- Resurrecting Internet Explorer: Threat Actors Using Zero-day Tricks in Internet Shortcut File to Lure Victims (CVE-2024-38112) Check Point Research
- CVE-2024-38112: Void Banshee Targets Windows Users Through Zombie Internet Explorer in Zero-Day Attacks Trend Micro
- Attackers Have Been Leveraging Microsoft Zero-Day for 18 Months Dark Reading
Reading Insights
Total Reads
0
Unique Readers
9
Time Saved
3 min
vs 4 min read
Condensed
90%
626 → 60 words
Want the full story? Read the original article
Read on The Hacker News