27

Based on past attacks, It wouldn’t be surprising to see active targeting this time too.

top 1 comments
sorted by: hot top controversial new old
[-] autotldr@lemmings.world 3 points 1 month ago

This is the best summary I could come up with:


More than 1.5 million email servers are vulnerable to attacks that can deliver executable attachments to user accounts, security researchers said.

Tracked as CVE-2024-39929 and carrying a severity rating of 9.1 out of 10, the vulnerability makes it trivial for threat actors to bypass protections that normally prevent the sending of attachments that install apps or execute code.

“I can confirm this bug,” Exim project team member Heiko Schlittermann wrote on a bug-tracking site.

More than 1.5 million of the Exim servers, or roughly 31 percent, are running a vulnerable version of the open-source mail app.

Threat actors can exploit it to bypass extension blocking and deliver executable attachments in emails sent to end users.

Given the requirement that end users must click on an attached executable for the attack to work, this Exim vulnerability isn’t as serious as the one that was exploited starting in 2019.


The original article contains 294 words, the summary contains 147 words. Saved 50%. I'm a bot and I'm open source!

this post was submitted on 12 Jul 2024
27 points (100.0% liked)

Cybersecurity

5236 readers
17 users here now

c/cybersecurity is a community centered on the cybersecurity and information security profession. You can come here to discuss news, post something interesting, or just chat with others.

THE RULES

Instance Rules

Community Rules

If you ask someone to hack your "friends" socials you're just going to get banned so don't do that.

Learn about hacking

Hack the Box

Try Hack Me

Pico Capture the flag

Other security-related communities !databreaches@lemmy.zip !netsec@lemmy.world !cybersecurity@lemmy.capebreton.social !securitynews@infosec.pub !netsec@links.hackliberty.org !cybersecurity@infosec.pub !pulse_of_truth@infosec.pub

Notable mention to !cybersecuritymemes@lemmy.world

founded 1 year ago
MODERATORS