SonicWall has disclosed a critical vulnerability (CVE-2024-40764) in its SonicOS IPSec VPN, potentially allowing remote attackers to create a Denial of Service condition. The flaw, found in various versions of SonicWall’s Gen6 and Gen7 platforms, has a severity level of 7.5. SonicWall has released a workaround and is developing a patch to fix the issue.

Apache ActiveMQ Flaw Exploited to Deploy DripDropper Malware on Cloud Linux Systems
Threat actors are exploiting a nearly two-year-old security flaw in Apache ActiveMQ to gain persistent access to cloud Linux systems and deploy malware called DripDropper.