Threat actors exploit TBK DVR and TP-Link routers to spread Mirai botnets
Attackers are exploiting a known vulnerability (CVE-2024-3721) affecting TBK DVR-4104 and DVR-4216 devices.
More recent incidents show a shift toward social engineering and alternative entry points.
Attackers are exploiting a known vulnerability (CVE-2024-3721) affecting TBK DVR-4104 and DVR-4216 devices.
In brief: Microsoft and Adobe fix zero-days, the Russian Grinex crypto exchange hacked for 1 billion rubles, and more.
CERT-UA believes the attacks may also target individuals connected to Ukraineu2019s Defense Forces
Once inside a system, the malware targets cloud metadata services to extract temporary credentials.
In addition to the SharePoint zero-day, Microsoft also patched a publicly disclosed privilege-escalation flaw.
There are no other public reports so far confirming active exploitation of CVE-2020-9715, CVE-2023-36424, or CVE-2025-60710 besides CISAu2019s KEV list.