The US Cybersecurity and Infrastructure Security Agency (CISA) has identified a medium-severity vulnerability in Versa Director, which has been exploited actively. Tracked as CVE-2024-39717, the flaw involves a file upload bug in the “Change Favicon” feature, enabling threat actors to upload malicious files disguised as PNG image files. Federal Civilian Executive Branch agencies are required to apply vendor-provided fixes by September 13, 2024.

Prank trojan in Russia, European Commission data leak, and other cybersecurity news – ForkLog
Prank trojan in Russia, European Commission data leak, and other cybersecurity news ForkLog

.webp?w=0&resize=0,0&ssl=1)
