
Critical Zero-Click WeChat Worm Discovered, GitLab Patches Exploited Vulnerabilities, and Multiple Security Threats Emerge
Researchers at Khif discovered a zero-click self-replicating worm that spreads through WeChat calls, affecting both Android and iOS devices. The worm exploits a memory corruption issue in the WeChat VoIP stack, takes only seconds to execute, and gives attackers full control of WeChat accounts to read and send messages and make calls. GitLab released patches for several vulnerabilities including CVE-2024-85706, a path traversal issue with a 10.0 CVSS score that allows unauthenticated users to read arbitrary files from GitLab servers using a single HTTP request, which was already being exploited in the wild according to Watchtower Labs. New research revealed an attack called DDR OP (DROP) targeting memory protection in Intel and AMD systems used by cloud servers, specifically affecting trusted execution environments like Intel TDX, requiring physical access and an inexpensive hardware interposer to execute. Two additional vulnerabilities were found in JFROG Artifactory and are being actively exploited in the wild according to Wiz. Anthropic released a 154-page writeup on threat actors using Claude for agentic threat operations, and Mullvad VPN announced they are shutting down their public encrypted DNS over HTTP servers to support Quad9 instead.