What you need to know today.
Active exploitation of critical vulnerabilities by ransomware groups, including Fortinet, Check Point, and Citrix flaws, dominates today's threat landscape.

A critical authentication bypass vulnerability in Fortinet FortiOS and FortiProxy (CVE-2024-55591) is being actively exploited by the "The Gentlemen" ransomware group. This flaw allows unauthenticated remote attackers to gain super administrator privileges, enabling them to bypass security controls and potentially deploy ransomware. The group is also noted for employing EDR kill techniques and custom C2 frameworks, as detailed by Infosecurity Magazine and Cyber Security News.
Check Point has issued a warning regarding a critical zero-day vulnerability (CVE-2024-24919) in its VPN products that is being exploited in the wild. This flaw allows attackers to potentially read sensitive information from connected Security Gateways. CISA has mandated urgent patching for federal agencies, highlighting the severity and active exploitation of this vulnerability, as reported by BleepingComputer.
The INC ransomware group has emerged as a significant threat, reportedly compromising over 830 victims since 2023. This group leverages various attack vectors, including unauthenticated remote code execution flaws like CVE-2023-3519 in Citrix Systems, and employs custom encryptors for both Windows and Linux/ESXi environments, according to reports from The Hacker News and Cyber Security News.
A critical command injection vulnerability in CyberPanel (CVE-2024-51378) allows unauthenticated attackers to execute arbitrary commands on affected systems. The flaw resides in the getresetstatus functionality within the DNS and FTP modules, enabling attackers to bypass authentication. This vulnerability poses a significant risk to systems running unpatched versions of CyberPanel.
WinRAR, a widely used file archiving utility, has a critical vulnerability (CVE-2023-38831) that allows for arbitrary code execution when a user attempts to open a specially crafted ZIP archive. This flaw, which has been exploited by Russian threat actors against Ukrainian organizations, occurs due to how WinRAR processes certain file types within archives, as detailed by Dark Reading.