In October 2024, notable breaches included the CosmicSting attack on Adobe Commerce, a ransomware hit on UnitedHealth’s Change Healthcare, and exploitive campaigns by Lazarus Group and Chinese hackers. Additionally, the APT34 group targeted critical infrastructure in the Gulf region.
1. CosmicSting Exploits Adobe Commerce Vulnerability

This October, Cybercriminals took advantage of a major vulnerability in the Adobe Commerce and Magento platforms, raising significant alarm in the software sector. This security weakness, labeled CVE-2024-34102 and given a nearly perfect CVSS score of 9.8, has been dubbed “CosmicSting” by specialists. It is reckoned to have affected more than 4,000 online stores and led to the compromise of customer payment information at an alarming number of those stores. It worked like this: hackers managed to get a line of malicious code to run on a vulnerable system, and that code intercepted customer payment data at the very moment it was going to be processed.
Ryan Naraine, Editor-at-Large at SecurityWeek, emphasized the importance of immediate intervention: “Store owners are urged to update their systems and apply Adobe’s recommended mitigations to protect against these ongoing attacks.”
The vulnerability of CosmicSting was particularly serious because it allowed attackers to read files from targeted Adobe Commerce instances. They did this by taking advantage of some very poor programming that occurred at Adobe. But wasn’t a patch issued by Adobe in June 2024 supposed to fix this? Yes, it was, but Adobe’s attempts to shore up the security of these various systems were undermined by a series of automated attacks that went after Adobe’s keys. The attackers, in short, didn’t lose any opportunity to take advantage of a seemingly sorry state of security at Adobe.
Seven threat groups, including Bobry, Polyovki, and Surki, have been identified by Sansec, a cybersecurity firm, as the ones behind the ongoing theft of cryptographic keys that are used to protect many kinds of systems. The key thefts, however, were only part of the problem. A related vulnerability (CVE-2024-2961) that was found in a widely used software package made the situation even worse by allowing the groups to run arbitrary code on the servers and set up backdoors, which meant they could come and go as they pleased.
It is imperative that store owners and software professionals practice good cybersecurity hygiene if they wish to avoid data breaches. The National Cybersecurity Center of Excellence reminds these professionals of the need for robust cybersecurity measures and the updating of patches to avert serious breaches in their operations. Nevertheless, the timely updating of such patches is a constant problem for many of us.
2. Massive Healthcare Breach at UnitedHealth’s Change Healthcare
A major incident has unfolded for the healthcare and cybersecurity sectors. Change Healthcare, a part of the healthcare giant UnitedHealth, suffered a debilitating ransomware assault carried out by the infamous ALPHV/BlackCat group. This attack, however, wasn’t simply a shakedown for bitcoins. It ended up being a huge medical data hack, with the personal health information of 100 million individuals breached — one of the largest hacks of medical records in recent history.
Not only was this breach on a large scale, but it also had a great financial impact and caused plenty of criticism directed at wide-ranging cybersecurity practices. The U.S. healthcare system remains particularly vulnerable to ransomware attacks, as highlighted by a survey from Sophos, despite a decrease in incidents across other industries.
“It’s our personal health information that we are talking about; breaches do not happen in secret anymore. And when they do happen, we need to talk about them, not just as a way of nudging ourselves toward better protective measures but also because these breaches naturally lead to questions about whom we can trust with our health in the first place.” — Darius Tahir, KFF Health News
Darius Tahir of KFF Health News stated that the breach’s effects on consumers could prove to be long-lasting. They certainly won’t help rebuild the already shaky public trust that healthcare providers enjoy.
As data privacy increasingly takes on a role of prominence, organizations are reexamining their security strategies with the aim of providing better protection for the sensitive health information they maintain. Certainly, the spotlight that the 2019 breach placed on UnitedHealth could lead one to think that the company occupies a perch on cybersecurity’s Wall of Shame, right along with Equifax and Yahoo! in terms of scale and scope. But the truth is far more complicated.
3. Lazarus Group’s Chrome Zero-Day Exploitation

The infamous Lazarus Group demonstrated their unparalleled technical abilities yet again in October 2024 by taking advantage of a zero-day vulnerability in Google Chrome. Associated with North Korea, this advanced persistent threat group is known for its well-crafted and serious cyber threats. Investing a substantial amount of time and effort into their latest campaign, they attempted to compromise as many unsuspecting cryptocurrency investors as possible. Central to this scheme was a completely phony DeFi platform masquerading as a legitimate cryptocurrency investment opportunity, created by the group to lure in potential targets, detankzone.com.
The cyberattack that occurred was not any run-of-the-mill cyberattack; it was sophisticated and cutting-edge. What made it so sophisticated? The group known as Lazarus—which is often linked to the North Korean government—had found and used a previously unknown vulnerability in Google’s Chrome browser. This particular type confusion bug, known as CVE-2024-5274, was so severe that it had been given a 9.8 out of 10 severity rating on the Common Vulnerability Scoring System. It was used to execute arbitrary code, which is impressive enough, but to do this and get away with it, the hackers also had to use another previously unknown bug to escape a virtual environment inside the browser. When they finally did escape, they used all of these vulnerabilities to install a piece of malware they had also designed: Manuscrypt.
This threat came to light thanks to the work of Kaspersky researchers. They weren’t just investigating an ordinary malware infection. They had stumbled upon a scheme to ensnare thousands of people—likely because they used some of the most convincing social engineering tactics ever attempted. The group behind it built fake social media accounts and used them to promote a fake game. Kaspersky’s Boris Larin and Vasily Berdnikov underscored this elaborate approach, noting,
“They focused on building a sense of trust to maximize the campaign’s effectiveness, designing details to make the promotional activities appear as genuine as possible.”
This campaign is a reminder of the danger that state-sponsored cyber activities represent. The actions of the Lazarus Group show how much cyber threats have changed and how much they really can’t be ignored. For those of us in the U.S. who are invested in the kinds of entities that the North Koreans seem to be interested in, being aware and on guard is prudent.
4. Chinese Hackers Suspected in Ivanti CSA Zero-Day Attacks
![]()
Next, the world saw one of the most audacious cyber spying incidents ever. Chinese state-affiliated hackers attacked the Ivanti Cloud Services Application. This sophisticated operation exploited several zero-day vulnerabilities, which allowed for remote code execution and lateral movement within the affected systems. Part of a larger, seemingly China-directed espionage operation, the Ivanti attack had the appearance of a “smash and grab” in that it went after highly sensitive data within the affected systems.
Researchers have identified a certain group of cyber actors, called Salt Typhoon, that now seem to be working for China. They have linked this group to several attacks, but high on the list is a recent effort to collect phone call audio from prominent U.S. political figures, as reported by The Washington Post. The group’s significant targets included attempts to compromise the phone systems used by the Trump and Harris campaigns. These kinds of activities remind us that cyberspace is now a key battlefield for any country trying to project power, and that hack attempts on the political class are the espionage equivalent of a human intelligence (HUMINT) operation.
(Quote) This was underscored by a recent joint statement from the FBI and the Cybersecurity and Infrastructure Security Agency. They noted that “agencies across the U.S. Government are collaborating to aggressively mitigate this threat,” which covers a range of symmetric attacks directed at our commercial telecom infrastructures.
Because of how direct and forceful these attacks are, U.S. authorities have been led to investigate them thoroughly. This statement was featured by several news outlets, including the Insurance Journal, and shows how closely U.S. authorities are watching this situation.
Grasping the profundity of these links offers software industry professionals and security aficionados precious insights. The connections made here stress the ever more critical need for not just defense in depth but for ongoing diligence in cybersecurity practices.
5. APT34’s Targeted Attacks in the Gulf Region

The Gulf region experienced a substantial uptick in cyber offensive activity from APT34, a group aligned with Iran’s Ministry of Intelligence and Security. Also known as OilRig or Earth Simnavaz, APT34 has focused much of its recent activity on the United Arab Emirates, hitting numerous government sector entities with a newly developed backdoor known as “StealHook.” They managed to compromise critical infrastructure sectors such as oil and gas, finance, and telecommunications.
APT34 did not just attack haphazardly; this group instead carefully and selectively targeted a specific Windows privilege escalation flaw, CVE-2024-30088 in order to lead a specific kind of user action that would result in an even bigger security hole on the Exchange server. The group then set to work using that unpatched hole as a way to get inside the victim’s network and access all sorts of sensitive data. Because the group itself was inside the victim’s network and had the kind of privilege that allowed it to act as if it were any kind of user at any kind of machine, it was able to reach all sorts of juicy targets.
“Their hacking efforts are of such high caliber that the term ‘sophisticated threat’ could have been invented to describe them,” noted experts from a report by Trend Micro.
A variety of tools was used in the operation, including web shells for malicious code execution, ngrok, and other command-and-control methodologies, to quietly and orderly exfiltrate vast amounts of data from various targets. Web shells are used to execute code in a web server environment. What makes web shells particularly dangerous is that they enable a cyber adversary to take full control over the target system. Command-and-control is an overarching term that describes how a cyber adversary communicates with the compromised systems under their control.
Nation-state actors like APT34 are relentless in their attempts to defeat an organization’s cybersecurity. Patching known vulnerabilities and adopting a Zero Trust security model are two sensible measures that organizations should take to counter these types of threats.
FAQ
What was the CosmicSting vulnerability and its impact?
A serious security weakness was found in the Adobe Commerce and Magento platforms, dubbed the CosmicSting vulnerability. It was assigned the name CVE-2024-34102 and had a critical CVSS score of 9.8. The vulnerability affected more than 4,000 online stores and was exploited by cybercriminals to capture customer payment information. They inserted malicious code into checkout pages to do it, and the way the attacked systems were set up—specifically improper restrictions in XML external entity references—made it especially easy for the hackers to get what they were after.
“The CosmicSting vulnerability is one of the most severe we’ve seen, affecting thousands of online businesses globally,” said a cybersecurity expert.
Who was behind the ransomware attack on UnitedHealth’s Change Healthcare?
The Change Healthcare ransomware attack was conducted by the ALPHV/BlackCat group. It resulted in a personal health data breach that affected 100 million individuals—one of the largest in recent memory. And it raises questions about the cybersecurity of both Change and its parent company, UnitedHealth Group.
How did the Lazarus Group exploit a Google Chrome vulnerability?
Associated with North Korea, the Lazarus Group took advantage of a previously unknown flaw in Google Chrome. They targeted their phishing campaign toward crypto investors and used a fake gaming site to entice victims. The attack hinged on a type confusion bug (CVE-2024-5274) located in the V8 JavaScript engine and WebAssembly of Chrome, which allowed the group to execute arbitrary code and bypass all the normal security precautions built into the browser.
What was the nature of the cyberattack involving Chinese hackers on Ivanti Cloud Services?
Hackers supported by the Chinese state struck the Ivanti Cloud Services Application and several of its other elements in October 2024. They were after a series of newly publicized “zero-day” vulnerabilities—flaws that had not previously been disclosed and for which no fixes had been provided. Taking full advantage of this situation, the adversaries used the remote code execution (RCE) weaknesses they found to try to navigate within the target’s network and find valuable data to snatch.
What were the primary targets of APT34’s cyber offensive in the Gulf region?
APT34, which has ties to Iran’s Ministry of Intelligence and Security, has gone after U.S. and allied government agencies and private sector entities in the Gulf region and elsewhere. Their targets include critical infrastructure sectors such as oil and gas, finance, and telecommunications. To break in and steal sensitive data, they exploited a Windows privilege escalation flaw CVE-2024-30088.
The article draws upon multiple sources to provide detailed insights into the cybersecurity incidents. References include Forbes, The Washington Post, Infosecurity Magazine, KUOW, and the Insurance Journal. These sources are crucial in understanding the scope and impact of the breaches discussed.