VMware releases additional updates to address recently patched critical bug
The fixes released on September 17 did not fully address CVE-2024-38812, the company said.
The fixes released on September 17 did not fully address CVE-2024-38812, the company said.
The campaign, tracked under the identifier UAC-0215, has been in preparation since at least August 2024.
Collectively, the four firms will pay over $6.9 million in penalties.
The malicious code activates only when the package is actively used.
The attackers used the compromised credentials to infiltrate the system of a third-party KYC vendor.
In recent campaigns, Latrodectus has been used by initial access brokers such as TA577 and TA578.
In addition to espionage, Moscow gained the capability to sabotage Georgia’s power and communications networks.
The attackers reportedly were able to gain access to over 800,000 support tickets.
Cisco said that a small number of files, which were not intended for public download, had been accessed and potentially published.
The new bypass is a cross-process Spectre attack that undermines ASLR and can leak sensitive data.
Showing elements 1201 - 1210