Hackers exploit Microsoft Defender SmartScreen bug CVE-2024-21412 to deliver ACR, Lumma, and Meduza Stealers - #CVE-2012-4792
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued warnings about two actively exploited vulnerabilities: a use-after-free flaw in outdated Microsoft Internet Explorer versions (CVE-2012-4792) and an information disclosure vulnerability in Twilio Authy's two-factor authentication app (CVE-2024-39891). Additionally, researchers discovered a malware campaign exploiting a Microsoft Defender SmartScreen vulnerability (CVE-2024-21412) to distribute information stealers like Meduza, ACR, and Lumma. CISA has mandated federal agencies to remediate these vulnerabilities and urged users to apply security updates, discontinue using outdated software, enable strong authentication, and monitor for suspicious activity.