The North Korea-linked threat actor known as Kimsuky has been linked to a new set of attacks targeting university staff, researchers, and professors for intelligence gathering purposes.
Cybersecurity firm Resilience said it identified the activity in late July 2024 after it observed an operation security (OPSEC) error made by the hackers.
Kimsuky, also known by the names APT43, ARCHIPELAGO,
A vulnerability classified as critical has been found in jupyterhub up to 4.1.5/5.1.0. This affects an unknown part of the component Group Membership Handler. The manipulation leads to improper handling of insufficient privileges.
This vulnerability is uniquely identified as CVE-2024-41942. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability was found in Edimax IC-6220DC and IC-5150W up to 3.06. It has been rated as critical. Affected by this issue is the function cgiFormString of the file ipcam_cgi. The manipulation of the argument host leads to command injection.
This vulnerability is handled as CVE-2024-7616. Access to the local network is required for this attack to succeed. There is no exploit available.
The vendor was contacted early about this disclosure but did not respond in any way.
A vulnerability was found in Tenda FH1206 1.2.0.8. It has been declared as critical. Affected by this vulnerability is the function fromSafeClientFilter/fromSafeMacFilter/fromSafeUrlFilter. The manipulation leads to stack-based buffer overflow.
This vulnerability is known as CVE-2024-7615. The attack can be launched remotely. Furthermore, there is an exploit available.
The vendor was contacted early about this disclosure but did not respond in any way.
A vulnerability was found in Tenda FH1206 1.2.0.8(8155). It has been classified as critical. Affected is the function fromqossetting of the file /goform/qossetting. The manipulation of the argument page leads to stack-based buffer overflow.
This vulnerability is traded as CVE-2024-7614. It is possible to launch the attack remotely. Furthermore, there is an exploit available.
The vendor was contacted early about this disclosure but did not respond in any way.
A vulnerability was found in Tenda FH1206 1.2.0.8(8155) and classified as critical. This issue affects the function fromGstDhcpSetSer of the file /goform/GstDhcpSetSer. The manipulation of the argument dips leads to buffer overflow.
The identification of this vulnerability is CVE-2024-7613. The attack may be initiated remotely. Furthermore, there is an exploit available.
The vendor was contacted early about this disclosure but did not respond in any way.
A vulnerability has been found in KAON AR2140 up to 4.2.15 and classified as critical. This vulnerability affects unknown code of the component Administrative Portal. The manipulation leads to os command injection.
This vulnerability was named CVE-2024-3659. The attack can only be initiated within the local network. There is no exploit available.
It is recommended to upgrade the affected component.
A vulnerability, which was classified as very critical, was found in PostgreSQL up to 12.19/13.15/14.12/15.7/16.3. This affects the function pg_dump. The manipulation leads to time-of-check time-of-use.
This vulnerability is uniquely identified as CVE-2024-7348. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.