A malware botnet is using a vulnerability in end-of-life GeoVision devices to conduct DDoS or cryptomining attacks. The flaw, CVE-2024-11120, allows unauthenticated attackers to execute commands on the device. About 17,000 GeoVision devices are exposed and vulnerable to the flaw. The botnet is a Mirai variant which usually performs DDoS or cryptomining operations. The end-of-life devices should ideally be replaced, but at minimum, their security settings should be updated.

Apache ActiveMQ Flaw Exploited to Deploy DripDropper Malware on Cloud Linux Systems
Threat actors are exploiting a nearly two-year-old security flaw in Apache ActiveMQ to gain persistent access to cloud Linux systems and deploy malware called DripDropper.