6月WhatsUp Gold修補漏洞,8月初駭客攻擊行動開始現蹤
支付動態 · 2024-08-09

本月初Shadowserver基金會發現,Progress在6月修補的RCE漏洞CVE-2024-4885,已被實際用於攻擊行動,呼籲IT人員要儘速修補

今年6月Progress針對網路監控系統WhatsUp Gold發布更新,當中修補重大層級的漏洞CVE-2024-4883、CVE-2024-4884、CVE-2024-4885(CVSS風險評分皆達到9.8),攻擊者能在未經授權的情況下,利用這些漏洞遠端執行任意程式碼(RCE),如今有研究人員提出警告,部分漏洞已出現實際攻擊行動。

Shadowserver基金會提出警告,他們自8月1日看到來自6個IP位址的攻擊行動,駭客利用CVE-2024-4885,企圖存取WhatsUp Gold系統的/NmAPI/RecurringReport。

研究人員特別提到,由於這項漏洞的概念性驗證程式碼(PoC)已被公開,駭客無需自行從頭拆解,就能快速將漏洞用於攻擊行動,IT人員應盡快套用相關更新。目前而言,Shadowserver基金會與該組織的全球漏洞濫用儀表板,都尚未公布目前曝險的系統數量。

Popular articles
Across 6 Cities: HUIDU Invites You to 8 World Cup Parties Redefining High-Value Social Networking
HUIDU Focus
Brazil Proposes Raising Gambling Tax Rate to 24%, With Revenue Allocated to Social Security and Healthcare
Regulation
Vietnam's tightening online gaming policy creates new market opportunities
Southeast Asia
British gambling levy rates confirmed for each vertical
Regulation
UK MPs reopen 2025 gambling inquiry as reform stalls
Regulation
SBC Summit Canada to Make Player Safety a Key Pillar of 2026 Agenda
Marketing
1spin4win releases unique slot Don Catleone Hold and Win featuring gangster cats
Online Game
GAT CDMX 2025 Institutional Academy: Leaders and Experts Analyze the Present and Future of the Gaming Industry in Mexico and Lat
Sports Game
Super PAC Raises $48 Million: Sports Betting Forces Ramp Up Political Push
Regulation
GAT Expo Puerto Rico Will Pulse with the New Era of Gaming in the Caribbean
Marketing
1spin4win grows its Latin American presence by partnering with Fortuna Juegos
Online Game
Kazakhstan plans to penalise online casino promotions
Regulation
Institutional Academy that exceeded expectations marked the opening of GAT CDMX
Online Game
Are you ready to maximize your earnings? Try ProPush.me Constructor!
Marketing
GGC Awards 2026 Shines in Colombo: Honoring Leaders and Innovators in the iGaming Industry
HUIDU Focus
Home
Game
Cooperation
Find
My