CERT Germany and Zyxel have alerted about a serious vulnerability in Zyxel firewalls, identified as CVE-2024-11667. This flaw is being exploited to spread Helldown ransomware, with reports of at least five affected organizations in Germany.
CVE-2024-11667 is a directory traversal vulnerability in Zyxel’s ZLD firmware versions 5.00 to 5.38. Exploiting it allows attackers to upload and download files using crafted URLs, which can compromise sensitive information like system credentials. This may lead to further attacks, such as creating rogue VPN connections and changing firewall settings.
By infosecbulletin
/ Monday , January 6 2025
On Friday, the Indian government released the draft Digital Personal Data Protection Rules, requiring social media and online platforms to...
Read More
By infosecbulletin
/ Monday , January 6 2025
Microsoft recently shared a vision for the future of American technology and economic competitiveness, highlighting Artificial Intelligence (AI) as central...
Read More
By infosecbulletin
/ Saturday , January 4 2025
Around 3.3 million servers are running POP3/IMAP email services without encryption (TLS) enabled, the Shadowserver Foundation, a nonprofit security organization,...
Read More
By infosecbulletin
/ Thursday , January 2 2025
Researchers have demonstrated a method to bypass Windows 11’s BitLocker encryption, enabling the extraction of Full Volume Encryption Keys (FVEKs)...
Read More
By infosecbulletin
/ Thursday , January 2 2025
SafeBreach Labs revealed a zero-click vulnerability in the Windows Lightweight Directory Access Protocol (LDAP) service, dubbed “LDAP Nightmare”. This critical...
Read More
By infosecbulletin
/ Tuesday , December 31 2024
Bangladesh Cyber Security Intelligence (BCSI) has published Financial Threat Assessment report for 2024. In an era where financial institutions and...
Read More
By infosecbulletin
/ Tuesday , December 31 2024
Cybersecurity researchers have uncovered three security weaknesses in Microsoft's Azure Data Factory Apache Airflow integration that, if successfully exploited, could...
Read More
By infosecbulletin
/ Tuesday , December 31 2024
The US Treasury Department said on Monday that Chinese-linked hackers were able to gain access to ‘unclassified documents’ after compromising...
Read More
By infosecbulletin
/ Monday , December 30 2024
Security researchers have warned that a Proof-of-Concept (PoC) exploit has been publicly released for a critical vulnerability affecting Oracle WebLogic...
Read More
By infosecbulletin
/ Monday , December 30 2024
Microsoft is forcing .NET developers to quickly update their apps and developer pipelines so they do not use 'azureedge.net' domains...
Read More
The affected devices include:
Zyxel ATP and USG FLEX series firewalls in on-premise mode, using ZLD firmware versions 4.32 to 5.38 with remote management or SSL VPN enabled. Devices using Nebula cloud management are not affected.
Initial Release date: 21, November 2024
Updated date: 27, November-2024
Current Date: November 29, 202
Zyxel Europe was reportedly one of the victims.
At least 32 victims worldwide have been reported on Helldown’s data leak site
According to CERT-Bund, five German groups are potential targets
To keep your network safe, Zyxel suggests taking these steps:
Update Firmware: Update your device to the latest firmware..
Disable Remote Access: If updates can’t be applied right away, temporarily turn off remote access to your device until the firmware is patched.
Review Best Practices: Review general cybersecurity guidelines.