📣 Send us your press release
Site updates every 15 minutes
Technology

Picus Security Reports on August Malware, Vulnerabilities, and Exploits

Picus Security's August 2024 threat intelligence roundup highlights critical vulnerabilities in VMware ESXi and ServiceNow. The report details how these flaws are being actively exploited by ransomware gangs and other threat actors.

30 September 2026
Picus Security Reports on August Malware, Vulnerabilities, and Exploits
Image is an AI-generated illustration

Picus Security has released its August 2024 review of significant cyber threats, vulnerabilities, and exploits. The report details how adversaries are actively targeting systems, with a focus on recently disclosed vulnerabilities.

Key among these is CVE-2024-37085, a VMware ESXi authentication bypass vulnerability. This flaw has been exploited by ransomware groups, including those deploying Akira and Black Basta. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued directives urging federal agencies to patch this vulnerability, highlighting its severity.

Additionally, the report addresses critical vulnerabilities in the ServiceNow platform: CVE-2024-4879 and CVE-2024-5217. These allow unauthenticated remote code execution and have been observed in global reconnaissance campaigns targeting organizations across various sectors, including government, energy, and software development, particularly in the United States, the United Kingdom, India, and the European Union.

Picus Security emphasizes the importance of staying informed about emerging threats. The company offers a threat intelligence platform designed to provide customized insights, helping organizations understand specific threats to their industry and region, and offering mitigation strategies.

Original source: picussecurity.com