TrustedSec Tech Brief - Week of August 19, 2024

Опубликовано: 11 Апрель 2026
на канале: TrustedSec
197
8

Welcome to the TrustedSec Tech Brief! Director of Security Intelligence Carlos Perez goes over security news and vulnerabilities for the week of August 19, 2024.

News:

Chinese hacking group Velvet Ant is exploiting CVE-2024-20399 on Cisco NX-OS devices.

https://thehackernews.com/2024/08/chi...

Researchers have found that Shanghai Fudan Microelectronics, the leading Chinese manufacturer of unlicensed “MIFARE compatible” chips has a backdoor in their FM11RF08S cards.

“The FM11RF08S backdoor enables any entity with knowledge of it to compromise all user-defined keys on these cards, even when fully diversified, simply by accessing the card for a few minutes,” -Quarkslab

https://eprint.iacr.org/2024/1275?ref...

Vulnerability:

CVE-2024-28000
CVSS: 9.8
Product: Litespeed Cache plugin
Affects: 6.3.0.1
POC: No
Exploited: Yes

The flaw allows unauthenticated users to spoof their user ID, setting it to that of an administrator.

https://thehackernews.com/2024/08/cri...

CVE-2024-7971
CVSS: 8.7
Affects: Chrome 128
POC: No
Exploited: Yes

Type confusion in V8. Reported by Microsoft Threat Intelligence Center (MSTIC).

https://chromereleases.googleblog.com...

CVE-2024-28987
CVSS: 9.1
SolarWinds Web Help Desk
Versions: 12.8.3 Hotfix 2
POC: No
Exploited: No

CISA warns of rapid exploitation given how a previous vulnerability is currently being exploited in the wild (CVE-2024-28986).

https://support.solarwinds.com/Succes...