{"id":56490,"date":"2024-07-05T14:59:53","date_gmt":"2024-07-05T14:59:53","guid":{"rendered":"https:\/\/packetstormsecurity.com\/news\/view\/36072\/Latest-Ghostscript-Vulnerability-Haunts-Experts-As-The-Next-Big-Breach-Enabler.html"},"modified":"2024-07-05T14:59:53","modified_gmt":"2024-07-05T14:59:53","slug":"latest-ghostscript-vulnerability-haunts-experts-as-the-next-big-breach-enabler","status":"publish","type":"post","link":"https:\/\/www.threatshub.org\/blog\/latest-ghostscript-vulnerability-haunts-experts-as-the-next-big-breach-enabler\/","title":{"rendered":"Latest Ghostscript Vulnerability Haunts Experts As The Next Big Breach Enabler"},"content":{"rendered":"<p>Infosec circles are awash with chatter about a vulnerability in Ghostscript some experts believe could be the cause of several major breaches in the coming months.<\/p>\n<p>Ghostscript is a Postscript and Adobe PDF interpreter that lets users of *nix, Windows, MacOS, and various embedded OSes and platforms view, print, and convert PDFs and image files. It is a default installation in many distros, as well as being used indirectly by other packages to support printing or conversion operations.<\/p>\n<p>Tracked as CVE-2024-29510 (Tenable designated it CVSS 5.5 \u2013 medium), the format string bug was originally reported to the Ghostscript team in March, and later mitigated in April&#8217;s version 10.03.1 of the open source interpreter for PostScript and PDF files.<\/p>\n<div aria-hidden=\"true\" class=\"adun\" data-pos=\"top\" data-raptor=\"condor\" data-xsm=\",fluid,mpu,\" data-sm=\",fluid,mpu,\" data-md=\",fluid,mpu,\"> <noscript> <a href=\"https:\/\/pubads.g.doubleclick.net\/gampad\/jump?co=1&amp;iu=\/6978\/reg_security\/research&amp;sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&amp;tile=2&amp;c=2Zogk0TkWsROW@@I8WLQVmgAAAFA&amp;t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0\" target=\"_blank\" rel=\"noopener\"> <img decoding=\"async\" src=\"https:\/\/pubads.g.doubleclick.net\/gampad\/ad?co=1&amp;iu=\/6978\/reg_security\/research&amp;sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&amp;tile=2&amp;c=2Zogk0TkWsROW@@I8WLQVmgAAAFA&amp;t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0\" alt> <\/a> <\/noscript> <\/div>\n<p>However, the blog of the researcher who discovered the flaw has sparked the first major wave of interest in the vulnerability since it became public.<\/p>\n<div aria-hidden=\"true\" class=\"adun\" data-pos=\"top\" data-raptor=\"falcon\" data-xmd=\",fluid,mpu,leaderboard,\" data-lg=\",fluid,mpu,leaderboard,\" data-xlg=\",fluid,billboard,superleaderboard,mpu,leaderboard,\" data-xxlg=\",fluid,billboard,superleaderboard,brandwidth,brandimpact,leaderboard,mpu,\"> <noscript> <a href=\"https:\/\/pubads.g.doubleclick.net\/gampad\/jump?co=1&amp;iu=\/6978\/reg_security\/research&amp;sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&amp;tile=4&amp;c=44Zogk0TkWsROW@@I8WLQVmgAAAFA&amp;t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0\" target=\"_blank\" rel=\"noopener\"> <img decoding=\"async\" src=\"https:\/\/pubads.g.doubleclick.net\/gampad\/ad?co=1&amp;iu=\/6978\/reg_security\/research&amp;sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&amp;tile=4&amp;c=44Zogk0TkWsROW@@I8WLQVmgAAAFA&amp;t=ct%3Dns%26unitnum%3D426raptor%3Dfalcon%26pos%3Dmid%26test%3D0\" alt> <\/a> <\/noscript> <\/div>\n<div class=\"adun_eagle_desktop_story_wrapper\">\n<div aria-hidden=\"true\" class=\"adun\" data-pos=\"mid\" data-raptor=\"eagle\" data-xxlg=\",mpu,dmpu,\"> <noscript> <a href=\"https:\/\/pubads.g.doubleclick.net\/gampad\/jump?co=1&amp;iu=\/6978\/reg_security\/research&amp;sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&amp;tile=3&amp;c=33Zogk0TkWsROW@@I8WLQVmgAAAFA&amp;t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0\" target=\"_blank\" rel=\"noopener\"> <img decoding=\"async\" src=\"https:\/\/pubads.g.doubleclick.net\/gampad\/ad?co=1&amp;iu=\/6978\/reg_security\/research&amp;sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&amp;tile=3&amp;c=33Zogk0TkWsROW@@I8WLQVmgAAAFA&amp;t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0\" alt> <\/a> <\/noscript> <\/div>\n<\/p><\/div>\n<p>Thomas Rinsma, lead security analyst at Dutch security shop Codean Labs, found a way to achieve remote code execution (RCE) on machines running Ghostscript after bypassing the -dSAFER sandbox.<\/p>\n<p>&#8220;This vulnerability has significant impact on web applications and other services offering document conversion and preview functionalities as these often use Ghostscript under the hood,&#8221; said Rinsma.&nbsp;<\/p>\n<div aria-hidden=\"true\" class=\"adun\" data-pos=\"top\" data-raptor=\"falcon\" data-xsm=\",fluid,mpu,\" data-sm=\",fluid,mpu,\" data-md=\",fluid,mpu,\"> <noscript> <a href=\"https:\/\/pubads.g.doubleclick.net\/gampad\/jump?co=1&amp;iu=\/6978\/reg_security\/research&amp;sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&amp;tile=4&amp;c=44Zogk0TkWsROW@@I8WLQVmgAAAFA&amp;t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0\" target=\"_blank\" rel=\"noopener\"> <img decoding=\"async\" src=\"https:\/\/pubads.g.doubleclick.net\/gampad\/ad?co=1&amp;iu=\/6978\/reg_security\/research&amp;sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&amp;tile=4&amp;c=44Zogk0TkWsROW@@I8WLQVmgAAAFA&amp;t=ct%3Dns%26unitnum%3D426raptor%3Dfalcon%26pos%3Dmid%26test%3D0\" alt> <\/a> <\/noscript> <\/div>\n<p>Here he&#8217;s referring to Ghostscript&#8217;s wide-ranging use across the web. Most commonly it&#8217;s found powering functionality such as preview images in cloud storage and chat programs, and is often invoked when these images are rendered. It&#8217;s also heavily used in tasks such as PDF conversion and printing, and can be found powering optical character recognition (OCR) workflows too.<\/p>\n<p>&#8220;It is the kind of software that is so integral to so many wider solutions that its existence is often taken for granted,&#8221; Stephen Robinson, senior threat intelligence analyst at WithSecure, told <em>El Reg<\/em>.<\/p>\n<p>As Ghostscript became more popular, the dev team behind the project made the call to implement increasingly hardened sandboxing capabilities, Rinsma added. The -dSAFER sandbox is enabled by default and typically stops potentially dangerous operations such as command execution from taking place.<\/p>\n<div aria-hidden=\"true\" class=\"adun\" id=\"story_eagle_xsm_sm_md_xmd_lg_xlg\" data-pos=\"mid\" data-raptor=\"eagle\" data-xsm=\",mpu,dmpu,\" data-sm=\",mpu,dmpu,\" data-md=\",mpu,dmpu,\" data-xmd=\",mpu,dmpu,\" data-lg=\",mpu,dmpu,\" data-xlg=\",mpu,dmpu,\"> <noscript> <a href=\"https:\/\/pubads.g.doubleclick.net\/gampad\/jump?co=1&amp;iu=\/6978\/reg_security\/research&amp;sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&amp;tile=3&amp;c=33Zogk0TkWsROW@@I8WLQVmgAAAFA&amp;t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0\" target=\"_blank\" rel=\"noopener\"> <img decoding=\"async\" src=\"https:\/\/pubads.g.doubleclick.net\/gampad\/ad?co=1&amp;iu=\/6978\/reg_security\/research&amp;sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&amp;tile=3&amp;c=33Zogk0TkWsROW@@I8WLQVmgAAAFA&amp;t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0\" alt> <\/a> <\/noscript> <\/div>\n<p>The full technical details behind the exploit can be found in the researcher&#8217;s <a target=\"_blank\" href=\"https:\/\/codeanlabs.com\/blog\/research\/cve-2024-29510-ghostscript-format-string-exploitation\/\" rel=\"nofollow noopener\">blog<\/a>, including the link to download a proof of concept (PoC) exploit for Linux (x86-64), but the long and short of it is that it can allow attackers to arbitrarily read and write files, and achieve RCE on an affected system.<\/p>\n<p>Replying to a discussion thread about Rinsma&#8217;s PoC, the researcher confirmed it won&#8217;t work for everyone straight out of the box as the code assumes a number of things such as stack and structure offsets that may vary depending on the target system.<\/p>\n<p>&#8220;The PoC Codean Labs has shared is an EPS file, and so any image conversion service or workflow which is compatible with EPS could be exploited to achieve RCE,&#8221; Robinson said.<\/p>\n<p>&#8220;While the CVE has not been analysed by NVD, Tenable lists it as a local vulnerability which requires user interaction, and which has no risk of impacting integrity or availability, only confidentiality.&#8221;<\/p>\n<h3 class=\"crosshead\">Experts sound the alarm<\/h3>\n<p>Cybersec bods picked up on Rinsma&#8217;s research this week and were quick to pinpoint the potential dangers around it, and how its assigned severity rating might not be telling the full picture.<\/p>\n<p>The <a target=\"_blank\" href=\"https:\/\/www.theregister.com\/2024\/03\/22\/opinion_column_nist\/\" rel=\"noopener\">slowdown at the National Vulnerability Database<\/a> (NVD) appears to be showing itself with this one.<\/p>\n<p>Bob Rudis, VP of data science at GreyNoise, <a target=\"_blank\" href=\"https:\/\/cyberplace.social\/@hrbrmstr@mastodon.social\/112722994029961934\" rel=\"nofollow noopener\">said<\/a> the advisories and accompanying severity assessments from the likes of Tenable and Red Hat (both rated the bug 5.5 using CVSS 3.0) were missing the mark in some aspects.<\/p>\n<p>Namely, Rudis and other onlookers believe that no user interaction is required for the exploit to be successful. Both Red Hat and Tenable assessed the opposite to be the case, a decision that, if incorrect, would mean the severity score is currently lower than what it should be.<\/p>\n<p>&#8220;Comparing this to CVE-2023-36664, an earlier GhostScript RCE, which was listed as high risk for integrity, availability, and confidentiality, it seems more correct for an RCE,&#8221; said Robinson.<\/p>\n<p>&#8220;It is true that the file must be local and that the process must be initiated, but as Ghostscript is so often included in automated workflows that are processing untrusted files, this vulnerability may be more severe than the 5.5 CVSS 3.0 base score that Tenable has assigned it.&#8221;<\/p>\n<p>Organizations use the CVE program and accompanying severity scores as quick guides on how much of a priority fixing certain vulnerabilities should be. When bugs aren&#8217;t properly assessed, it opens up the possibility that patches and mitigations aren&#8217;t applied with the requisite urgency.<\/p>\n<p>Just the fact that the industry has only recently woken up to the severity of this particular vulnerability months after it was fixed is evidence in itself that accurate severity assessments are hugely important for the infosec industry.<\/p>\n<p>Rudis also <a target=\"_blank\" href=\"https:\/\/cyberplace.social\/@hrbrmstr@mastodon.social\/112722533836471520\" rel=\"nofollow noopener\">said<\/a> in the next six months he expects to be getting between 5-10 notifications from organizations offering the usual year of free credit monitoring following a material breach.<\/p>\n<p>Bill Mill, a full stack developer at ReadMe, <a target=\"_blank\" href=\"https:\/\/hachyderm.io\/@llimllib\/112722578840238142\" rel=\"nofollow noopener\">said<\/a> he has already seen attacks in the wild. So now that a PoC is released \u2013 which Mill branded &#8220;trivial&#8221; to exploit \u2013 and a ton of attention is on CVE-2024-29510, getting those patches applied should be any organization&#8217;s top priority.<\/p>\n<h3 class=\"crosshead\">Double trouble<\/h3>\n<p>It&#8217;s the second time in 12 months that a concerning RCE has been disclosed in Ghostscript. In July last year, PoCs for CVE-2023-36664 hit the headlines after Kroll&#8217;s researchers published an <a target=\"_blank\" href=\"https:\/\/www.kroll.com\/en\/insights\/publications\/cyber\/ghostscript-cve-2023-36664-remote-code-execution-vulnerability\" rel=\"nofollow noopener\">investigation<\/a> into the bug.<\/p>\n<p>This one was rated 9.8 on the severity scale \u2013 a critical flaw that security teams would unlikely pass up the opportunity to patch. All that was required to exploit it was to convince a target to open a malicious file.<\/p>\n<p>Concern abounded at the time, as it has done this week, mainly over the realization of just how prevalent Ghostscript is in modern software. Kroll said Debian 12 had 131 packages that depended on Ghostscript and popular apps like those in the <a target=\"_blank\" href=\"https:\/\/www.theregister.com\/2024\/04\/04\/germanys_northernmost_state_ditches_windows\/\" rel=\"noopener\">LibreOffice<\/a> suite also make use of the interpreter. \u00ae<\/p>\n<p> READ MORE <a href=\"https:\/\/packetstormsecurity.com\/news\/view\/36072\/Latest-Ghostscript-Vulnerability-Haunts-Experts-As-The-Next-Big-Breach-Enabler.html\">HERE<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>READ MORE HERE&#8230;<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"colormag_page_layout":"default_layout","footnotes":""},"categories":[277],"tags":[145],"class_list":["post-56490","post","type-post","status-publish","format-standard","hentry","category-cybersecurity-blogs","tag-headlinehackerdata-lossflaw"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.1 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Latest Ghostscript Vulnerability Haunts Experts As The Next Big Breach Enabler 2026 | ThreatsHub Cybersecurity News<\/title>\n<meta name=\"description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.threatshub.org\/blog\/latest-ghostscript-vulnerability-haunts-experts-as-the-next-big-breach-enabler\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Latest Ghostscript Vulnerability Haunts Experts As The Next Big Breach Enabler 2026 | ThreatsHub Cybersecurity News\" \/>\n<meta property=\"og:description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.threatshub.org\/blog\/latest-ghostscript-vulnerability-haunts-experts-as-the-next-big-breach-enabler\/\" \/>\n<meta property=\"og:site_name\" content=\"ThreatsHub Cybersecurity News\" \/>\n<meta property=\"article:published_time\" content=\"2024-07-05T14:59:53+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/pubads.g.doubleclick.net\/gampad\/ad?co=1&amp;iu=\/6978\/reg_security\/research&amp;sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&amp;tile=2&amp;c=2Zogk0TkWsROW@@I8WLQVmgAAAFA&amp;t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0\" \/>\n<meta name=\"author\" content=\"TH Author\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@threatshub\" \/>\n<meta name=\"twitter:site\" content=\"@threatshub\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"TH Author\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"5 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/latest-ghostscript-vulnerability-haunts-experts-as-the-next-big-breach-enabler\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/latest-ghostscript-vulnerability-haunts-experts-as-the-next-big-breach-enabler\\\/\"},\"author\":{\"name\":\"TH Author\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\"},\"headline\":\"Latest Ghostscript Vulnerability Haunts Experts As The Next Big Breach Enabler\",\"datePublished\":\"2024-07-05T14:59:53+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/latest-ghostscript-vulnerability-haunts-experts-as-the-next-big-breach-enabler\\\/\"},\"wordCount\":1017,\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/latest-ghostscript-vulnerability-haunts-experts-as-the-next-big-breach-enabler\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/pubads.g.doubleclick.net\\\/gampad\\\/ad?co=1&amp;iu=\\\/6978\\\/reg_security\\\/research&amp;sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&amp;tile=2&amp;c=2Zogk0TkWsROW@@I8WLQVmgAAAFA&amp;t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0\",\"keywords\":[\"headline,hacker,data loss,flaw\"],\"articleSection\":[\"CyberSecurity Blogs\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/latest-ghostscript-vulnerability-haunts-experts-as-the-next-big-breach-enabler\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/latest-ghostscript-vulnerability-haunts-experts-as-the-next-big-breach-enabler\\\/\",\"name\":\"Latest Ghostscript Vulnerability Haunts Experts As The Next Big Breach Enabler 2026 | ThreatsHub Cybersecurity News\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/latest-ghostscript-vulnerability-haunts-experts-as-the-next-big-breach-enabler\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/latest-ghostscript-vulnerability-haunts-experts-as-the-next-big-breach-enabler\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/pubads.g.doubleclick.net\\\/gampad\\\/ad?co=1&amp;iu=\\\/6978\\\/reg_security\\\/research&amp;sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&amp;tile=2&amp;c=2Zogk0TkWsROW@@I8WLQVmgAAAFA&amp;t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0\",\"datePublished\":\"2024-07-05T14:59:53+00:00\",\"description\":\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/latest-ghostscript-vulnerability-haunts-experts-as-the-next-big-breach-enabler\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/latest-ghostscript-vulnerability-haunts-experts-as-the-next-big-breach-enabler\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/latest-ghostscript-vulnerability-haunts-experts-as-the-next-big-breach-enabler\\\/#primaryimage\",\"url\":\"https:\\\/\\\/pubads.g.doubleclick.net\\\/gampad\\\/ad?co=1&amp;iu=\\\/6978\\\/reg_security\\\/research&amp;sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&amp;tile=2&amp;c=2Zogk0TkWsROW@@I8WLQVmgAAAFA&amp;t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0\",\"contentUrl\":\"https:\\\/\\\/pubads.g.doubleclick.net\\\/gampad\\\/ad?co=1&amp;iu=\\\/6978\\\/reg_security\\\/research&amp;sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&amp;tile=2&amp;c=2Zogk0TkWsROW@@I8WLQVmgAAAFA&amp;t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/latest-ghostscript-vulnerability-haunts-experts-as-the-next-big-breach-enabler\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"headline,hacker,data loss,flaw\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/tag\\\/headlinehackerdata-lossflaw\\\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"Latest Ghostscript Vulnerability Haunts Experts As The Next Big Breach Enabler\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"name\":\"ThreatsHub Cybersecurity News\",\"description\":\"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"alternateName\":\"Threatshub.org\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\",\"name\":\"ThreatsHub.org\",\"alternateName\":\"Threatshub.org\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"width\":432,\"height\":435,\"caption\":\"ThreatsHub.org\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/x.com\\\/threatshub\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\",\"name\":\"TH Author\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"caption\":\"TH Author\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Latest Ghostscript Vulnerability Haunts Experts As The Next Big Breach Enabler 2026 | ThreatsHub Cybersecurity News","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.threatshub.org\/blog\/latest-ghostscript-vulnerability-haunts-experts-as-the-next-big-breach-enabler\/","og_locale":"en_US","og_type":"article","og_title":"Latest Ghostscript Vulnerability Haunts Experts As The Next Big Breach Enabler 2026 | ThreatsHub Cybersecurity News","og_description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","og_url":"https:\/\/www.threatshub.org\/blog\/latest-ghostscript-vulnerability-haunts-experts-as-the-next-big-breach-enabler\/","og_site_name":"ThreatsHub Cybersecurity News","article_published_time":"2024-07-05T14:59:53+00:00","og_image":[{"url":"https:\/\/pubads.g.doubleclick.net\/gampad\/ad?co=1&amp;iu=\/6978\/reg_security\/research&amp;sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&amp;tile=2&amp;c=2Zogk0TkWsROW@@I8WLQVmgAAAFA&amp;t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0","type":"","width":"","height":""}],"author":"TH Author","twitter_card":"summary_large_image","twitter_creator":"@threatshub","twitter_site":"@threatshub","twitter_misc":{"Written by":"TH Author","Est. reading time":"5 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.threatshub.org\/blog\/latest-ghostscript-vulnerability-haunts-experts-as-the-next-big-breach-enabler\/#article","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/latest-ghostscript-vulnerability-haunts-experts-as-the-next-big-breach-enabler\/"},"author":{"name":"TH Author","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476"},"headline":"Latest Ghostscript Vulnerability Haunts Experts As The Next Big Breach Enabler","datePublished":"2024-07-05T14:59:53+00:00","mainEntityOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/latest-ghostscript-vulnerability-haunts-experts-as-the-next-big-breach-enabler\/"},"wordCount":1017,"publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/latest-ghostscript-vulnerability-haunts-experts-as-the-next-big-breach-enabler\/#primaryimage"},"thumbnailUrl":"https:\/\/pubads.g.doubleclick.net\/gampad\/ad?co=1&amp;iu=\/6978\/reg_security\/research&amp;sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&amp;tile=2&amp;c=2Zogk0TkWsROW@@I8WLQVmgAAAFA&amp;t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0","keywords":["headline,hacker,data loss,flaw"],"articleSection":["CyberSecurity Blogs"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.threatshub.org\/blog\/latest-ghostscript-vulnerability-haunts-experts-as-the-next-big-breach-enabler\/","url":"https:\/\/www.threatshub.org\/blog\/latest-ghostscript-vulnerability-haunts-experts-as-the-next-big-breach-enabler\/","name":"Latest Ghostscript Vulnerability Haunts Experts As The Next Big Breach Enabler 2026 | ThreatsHub Cybersecurity News","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/latest-ghostscript-vulnerability-haunts-experts-as-the-next-big-breach-enabler\/#primaryimage"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/latest-ghostscript-vulnerability-haunts-experts-as-the-next-big-breach-enabler\/#primaryimage"},"thumbnailUrl":"https:\/\/pubads.g.doubleclick.net\/gampad\/ad?co=1&amp;iu=\/6978\/reg_security\/research&amp;sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&amp;tile=2&amp;c=2Zogk0TkWsROW@@I8WLQVmgAAAFA&amp;t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0","datePublished":"2024-07-05T14:59:53+00:00","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","breadcrumb":{"@id":"https:\/\/www.threatshub.org\/blog\/latest-ghostscript-vulnerability-haunts-experts-as-the-next-big-breach-enabler\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.threatshub.org\/blog\/latest-ghostscript-vulnerability-haunts-experts-as-the-next-big-breach-enabler\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/latest-ghostscript-vulnerability-haunts-experts-as-the-next-big-breach-enabler\/#primaryimage","url":"https:\/\/pubads.g.doubleclick.net\/gampad\/ad?co=1&amp;iu=\/6978\/reg_security\/research&amp;sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&amp;tile=2&amp;c=2Zogk0TkWsROW@@I8WLQVmgAAAFA&amp;t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0","contentUrl":"https:\/\/pubads.g.doubleclick.net\/gampad\/ad?co=1&amp;iu=\/6978\/reg_security\/research&amp;sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&amp;tile=2&amp;c=2Zogk0TkWsROW@@I8WLQVmgAAAFA&amp;t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0"},{"@type":"BreadcrumbList","@id":"https:\/\/www.threatshub.org\/blog\/latest-ghostscript-vulnerability-haunts-experts-as-the-next-big-breach-enabler\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.threatshub.org\/blog\/"},{"@type":"ListItem","position":2,"name":"headline,hacker,data loss,flaw","item":"https:\/\/www.threatshub.org\/blog\/tag\/headlinehackerdata-lossflaw\/"},{"@type":"ListItem","position":3,"name":"Latest Ghostscript Vulnerability Haunts Experts As The Next Big Breach Enabler"}]},{"@type":"WebSite","@id":"https:\/\/www.threatshub.org\/blog\/#website","url":"https:\/\/www.threatshub.org\/blog\/","name":"ThreatsHub Cybersecurity News","description":"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform","publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"alternateName":"Threatshub.org","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.threatshub.org\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.threatshub.org\/blog\/#organization","name":"ThreatsHub.org","alternateName":"Threatshub.org","url":"https:\/\/www.threatshub.org\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","width":432,"height":435,"caption":"ThreatsHub.org"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/x.com\/threatshub"]},{"@type":"Person","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476","name":"TH Author","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","caption":"TH Author"}}]}},"_links":{"self":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/56490","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/comments?post=56490"}],"version-history":[{"count":0,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/56490\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media?parent=56490"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/categories?post=56490"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/tags?post=56490"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}