Atlassian CISO Urges Quick Action to Protect Confluence Instances From Critical Vulnerability

Enterprise software maker Atlassian on Monday urged all Confluence Data Center and Server customers to patch their instances against a critical-severity vulnerability that can be exploited without authentication.

The security defect, tracked as CVE-2023-22518 (CVSS score of 9.1), is described as an improper authorization bug that impacts all Confluence versions.

While it did not share technical details on the flaw in its advisory, Atlassian instead drew attention to the high impact successful exploitation would have.

“As part of our continuous security assessment processes, we have discovered that Confluence Data Center and Server customers are vulnerable to significant data loss if exploited by an unauthenticated attacker,” Atlassian CISO Bala Sathiamurthy notes.

“There are no reports of active exploitation at this time; however, customers must take immediate action to protect their instances,” Sathiamurthy continues.

According to Atlassian, the vulnerability has no impact on confidentiality, as no data exfiltration can occur from exploiting it.

The issue has been addressed with the release of Confluence Data Center and Server versions 7.19.16, 8.3.4, 8.4.4, 8.5.3, and 8.6.1.

Advertisement. Scroll to continue reading.

Customers that are unable to apply the patches are advised to back up their instances and block internet access to them until they can be patched.

“Instances accessible to the public internet, including those with user authentication, should be restricted from external network access until you can patch,” Atlassian notes.

The company also notes that, as per its policy regarding critical vulnerabilities, the patches will be back ported, and that new maintenance releases for all versions covered by the policy will become available.

“Atlassian Cloud sites are not affected by this vulnerability. If your Confluence site is accessed via an atlassian.net domain, it is hosted by Atlassian and is not vulnerable to this issue,” the software maker notes.

Related: US Gov Expects Widespread Exploitation of Atlassian Confluence Vulnerability

Related: Atlassian Patches Remote Code Execution Vulnerabilities in Confluence, Bamboo

Related: Organizations Warned of Critical Confluence Flaw as Exploitation Continues

https://www.securityweek.com/atlassian-ciso-urges-quick-action-to-protect-confluence-instances-from-critical-vulnerability/




Hackers Earn Over $1 Million at Pwn2Own Toronto 2023

The Zero Day Initiative’s Pwn2Own Toronto 2023 hacking competition concluded on Friday with two new zero-day exploits, bringing the total demonstrated vulnerabilities to 58.

Over the course of four days, participants successfully exploited routers, printers, smart speakers, NAS products, surveillance systems, and mobile phones, earning more than $1 million in rewards.

Following a busy first day of the competition, when 18 exploits were demonstrated and more than $400,000 earned in rewards, participants showcased 15 exploits on the second day, eight on the third day, and three on the last day.

The highest reward, of $100,000, was awarded on the second day of the contest to Chris Anastasio, for bugs in the P-Link Omada Gigabit router and one in the Lexmark CX331adwe printer.

Throughout the competition, team Viettel demonstrated multiple exploits, earning a total of $180,000 in rewards. Team Orca of Sea Security was also able to successfully demonstrate multiple exploits, earning roughly $116,000, while Pentest Limited earned $90,000 in rewards.

Interrupt Labs, Star Labs SG, a Devcore intern, ANHTUD, Claroty, team ECQ, Sina Kheirkhah, Binary Factory, Synacktiv, Rafal Goryl, Sonar, ToChim, Nguyen Quoc Viet, and others also demonstrated successful exploits, though not all of them targeted new vulnerabilities.

Some of the demonstrated exploits chained two or three vulnerabilities, but most of them were single-bug exploits. Many of the exploits led to remote code execution.

Advertisement. Scroll to continue reading.

All the vulnerabilities have been reported to the vendors, who have 90-days to address them before details are made public.

The total paid out at Pwn2Own Toronto 2023 was higher than last year, when 26 contestants signed up for 66 exploits and earned close to $1 million throughout the four-day event.

Related: Over $1 Million Offered at New Pwn2Own Automotive Hacking Contest

Related: Hackers Earn $180,000 for ICS Exploits at Pwn2Own Miami 2023

Related: Hackers Earn Over $1 Million at Pwn2Own Exploit Contest

https://www.securityweek.com/hackers-earn-over-1-million-at-pwn2own-toronto-2023/




F5 Warns of Critical Remote Code Execution Vulnerability in BIG-IP

Security and application delivery solutions provider F5 on Thursday warned customers of a critical-severity vulnerability in its BIG-IP product.

Tracked as CVE-2023-46747 (CVSS score of 9.8) and impacting the Traffic Management User Interface of the solution, the vulnerability allows an unauthenticated attacker to execute arbitrary code remotely.

“This vulnerability may allow an unauthenticated attacker with network access to the BIG-IP system through the management port and/or self IP addresses to execute arbitrary system commands. There is no data plane exposure; this is a control plane issue only,” F5 explains in an advisory.

According to Praetorian Security, which identified the bug, CVE-2023-46747 is a request smuggling issue that allows an unauthenticated attacker to gain full administrative privileges on an impacted BIG-IP system.

The flaw, Praetorian says, is closely related to CVE-2022-26377, a request smuggling flaw in the Apache HTTP Server, and can be exploited to bypass authentication and execute commands as root.

All BIG-IP systems with the Traffic Management User Interface exposed to the internet are affected by this vulnerability.

According to F5, the issue is rooted in the configuration utility component. BIG-IP versions 13.x through 17.x are impacted and F5 has released hotfixes for all of them.

Advertisement. Scroll to continue reading.

A shell script has been released for BIG-IP versions 14.1.0 and later to mitigate the issue. Details on how the script can be used are available in F5’s advisory.

According to Praetorian, there are more than 6,000 internet-facing instances of the application, all potentially at risk of exploitation. Some of these belong to government entities and Fortune 500 companies.

Technical details on this vulnerability will be released after most BIG-IP users have patched their instances.

BIG-IP users are advised to install the available patches as soon as possible. They should also restrict access to the Traffic Management User Interface.

“The portal itself should not be accessible at all from the public internet,” Praetorian notes.

F5 makes no mention of CVE-2023-46747 being exploited in malicious attacks.

Related: F5 BIG-IP Vulnerability Can Lead to DoS, Code Execution

Related: Critical Vulnerability Exploited to ‘Destroy’ BIG-IP Appliances

Related: F5 Warns BIG-IP Customers About 18 Serious Vulnerabilities

https://www.securityweek.com/f5-warns-of-critical-remote-code-execution-vulnerability-in-big-ip/




Critical Mirth Connect Vulnerability Could Expose Sensitive Healthcare Data

Open source data integration platform Mirth Connect is affected by a remote code execution vulnerability that can be exploited without authentication, cybersecurity firm Horizon3.ai warns.

Developed by NextGen HealthCare, Mirth Connect is a cross-platform interface engine that healthcare organizations rely on for information management.

Tracked as CVE-2023-43208, the newly disclosed issue is a bypass for a critical-severity RCE flaw (CVE-2023-37679, CVSS score of 9.8) that was disclosed in August 2023 and which was addressed with the release of Mirth Connect version 4.4.0.

According to Horizon3.ai, CVE-2023-37679 was said to only impact Mirth Connect instances using Java 8 or below, but further analysis of the vulnerability has revealed that, in fact, all Mirth Connect installs are impacted, regardless of the Java version they use.

Furthermore, the cybersecurity firm’s investigation has revealed that the patch for CVE-2023-37679 can be bypassed, and reported the findings to NextGen HealthCare, which released Mirth Connect version 4.4.1 to address the new issue.

“This is an easily exploitable, unauthenticated remote code execution vulnerability. Attackers would most likely exploit this vulnerability for initial access or to compromise sensitive healthcare data,” Horizon3.ai says.

For the time being, Horizon3.ai refrains from releasing technical details or an exploit for CVE-2023-43208, but warns that the methods for exploitation are well known.

Advertisement. Scroll to continue reading.

“We have verified that Mirth Connect versions going as far back as 2015/2016 are vulnerable,” the cybersecurity firm notes.

Horizon3.ai also points out that Mirth Connect appears to be deployed mostly on Windows machines, where it typically runs with System privileges, suggesting that the impact of a successful attack would be critical.

Additionally, the cybersecurity firm notes that it has identified more than 1,200 unique Mirth Connect instances that are directly accessible from the internet.

Mirth Connect users are advised to update to version 4.4.1 of the platform as soon as possible.

Related: Dozens of RCE Vulnerabilities Impact Milesight Industrial Router

Related: Exploitation of Recent Citrix ShareFile RCE Vulnerability Begins

Related: Fortinet Patches Critical RCE Vulnerability in FortiNAC

https://www.securityweek.com/critical-mirth-connect-vulnerability-could-expose-sensitive-healthcare-data/




Hackers Earn $350k on Second Day at Pwn2Own Toronto 2023

Hackers have earned roughly $350,000 in rewards after demonstrating successful exploits against a variety of devices on the second day of the Zero Day Initiative’s Pwn2Own Toronto 2023 competition.

Just as on the first day of the hacking contest, NAS devices, printers, smart speakers, and mobile phones were hacked on Wednesday, with successful exploits also demonstrated against routers.

The highest reward went to Chris Anastasio, who earned $100,000 for exploits targeting a vulnerability in the P-Link Omada Gigabit router and one in the Lexmark CX331adwe printer, ZDI announced.

On the second day of the competition, a Devcore intern earned $50,000 for a stack buffer overflow issue in the TP-Link Omada Gigabit router and two flaws in the QNAP TS-464 NAS device.

Team Orca of Sea Security also earned $50,000 on Wednesday, for a bug in the Synology RT6600ax router and a three-bug chain against the QNAP TS-464 NAS device.

Rewards of $30,000 were handed out for a command injection in the Wyze Cam v3 security camera and an out-of-bounds write issue in the Sonos Era 100 smart speaker.

ZDI also announced high rewards for an improper input validation bug and a permissive list of allowed inputs flaw in Samsung Galaxy S23 ($25,000), a stack-based buffer overflow issue in the HP Color LaserJet Pro MFP 4301fdw ($20,000), and a stack-based buffer overflow vulnerability in the Canon imageCLASS MF753Cdw printer ($10,000).

Advertisement. Scroll to continue reading.

Additionally, multiple low-tier rewards were handed out for exploits targeting known vulnerabilities in QNAP TS-464, Wyze Cam v3, Synology BC500, and Canon imageCLASS MF753Cdw.

Overall, ZDI says, participating hackers have earned more than $800,000 in rewards on the first two days of the competition, which is set to conclude on Friday.

Related: Hackers Earn $400k on First Day at Pwn2Own Toronto 2023

Related: Over $1 Million Offered at New Pwn2Own Automotive Hacking Contest

Related: Hackers Earn $180,000 for ICS Exploits at Pwn2Own Miami 2023

https://www.securityweek.com/hackers-earn-350k-on-second-day-at-pwn2own-toronto-2023/




iLeakage Attack Exploits Safari to Steal Sensitive Data From Macs, iPhones

A team of academic researchers has disclosed the details of a new Spectre-style side-channel attack that exploits Safari to steal sensitive information from Macs, iPhones and iPads.

Described as a timerless speculative execution attack and named iLeakage, the new method can be used to induce Safari to render an arbitrary webpage and harvest information from that page. 

The attacker needs to lure the targeted Safari user to a malicious website, which then automatically opens the site from which they want to steal information. This is possible because the rendering process handles both the iLeakage attack website and the targeted site.

iLeakage was discovered by researchers from the University of Michigan, Georgia Institute of Technology, and Ruhr University Bochum, who this week published a paper detailing their findings. 

The experts showed how the attack could be used to obtain passwords and other sensitive information. They published video demos showing how the iLeakage attack can be leveraged to steal Instagram credentials autofilled by a password manager, email subject lines from a Gmail inbox, and a user’s YouTube watch history

The findings were reported to Apple in September 2022, but the tech giant has so far only made available a mitigation for Safari on macOS, and it’s not enabled by default, in addition to being unstable, according to the researchers.

Apple told SecurityWeek that the proof of concept developed by the researchers advances the company’s understanding of these types of threats. Apple plans on further addressing the issue in its next scheduled software release.

Advertisement. Scroll to continue reading.

On one hand, there is no evidence that iLeakage has been exploited in the wild and the attack is not easy to conduct. “[It] requires advanced knowledge of browser-based side-channel attacks and Safari’s implementation,” the researchers said.

On the other hand, the experts noted that the attack would be difficult to detect since it runs in Safari and does not leave any trace in system log files.

On macOS, iLeakage only impacts Safari because other browsers such as Edge, Firefox and Chrome use different JavaScript engines, the researchers said. However, on iOS the attack can work with other browsers as well because Chrome, Edge and Firefox are basically ‘wrappers on top of Safari’.

“iLeakage shows that the Spectre attack is still relevant and exploitable, even after nearly 6 years of effort to mitigate it since its discovery,” the researchers noted. 

Related: Nearly All Modern CPUs Leak Data to New Collide+Power Side-Channel Attack

Related: New GPU Side-Channel Attack Allows Malicious Websites to Steal Data

Related: New ‘Inception’ Side-Channel Attack Targets AMD Processors

https://www.securityweek.com/ileakage-attack-exploits-safari-to-steal-sensitive-data-from-macs-iphones/




Hackers Earn $400k on First Day at Pwn2Own Toronto 2023

The Pwn2Own Toronto 2023 hacking contest kicked off yesterday and participants successfully hacked NAS, printers, mobile phones, and other types of devices, earning a total of more than $400,000 on the first day.

The highest reward of the day went to team Orca of Sea Security, which executed a two-vulnerability exploit chain (out-of-bounds read and use-after-free) against the Sonos Era 100 speaker, earning $60,000.

The Pentest Limited team earned the second highest reward of the day, at $50,000, for an improper input validation exploit targeting the Samsung Galaxy S23 mobile phone.

The team also earned a $40,000 reward for a two-bug exploit chain (denial-of-service and server-side request forgery) leading to the compromise of Western Digital’s My Cloud Pro Series PR4100 network-attached storage (NAS) product.

Two other $40,000 rewards were earned for exploits targeting the Xiaomi 13 Pro mobile phone (team Viettel – single-bug exploit) and the QNAP TS-464 NAS device (team ECQ – a three-bug exploit chain involving a server-side request forgery and two injection flaws).

Vulnerabilities in the Synology BC500 IP camera were also exploited on the first day of the contest, with hackers earning roughly $50,000 for the exploits.

Additional exploits targeting the Xiaomi 13 Pro and the Samsung Galaxy S23 were demonstrated as well and earned the hacking teams more than $40,000 in rewards.

Advertisement. Scroll to continue reading.

The participating teams and individual hackers also pwned the Canon imageCLASS MF753Cdw and the Lexmark CX331adwe printers, earning more than $60,000 for their exploits.

According to ZDI, not all the exploits demonstrated on the first day of Pwn2Own Toronto 2023 were new, but participants still earned lower-tier rewards for their efforts.

The hacking competition will continue until Friday, with exploits to be demonstrated in the NAS devices, smart speakers, printers, mobile phones, and surveillance systems categories.

Missing from the contest are smart vehicles, which will be present at Pwn2Own Automotive, set to be hosted at the Automotive World conference, in January 2024, in Tokyo, Japan. It will be the first Pwn2Own competition dedicated to automotive.

Related: Mikrotik Belatedly Patches RouterOS Flaw Exploited at Pwn2Own

Related: VMware Patches Critical Vulnerability Disclosed at Pwn2Own Hacking Contest

Related: ZDI Discusses First Automotive Pwn2Own

https://www.securityweek.com/hackers-earn-400k-on-first-day-at-pwn2own-toronto-2023/




Censys Banks $75M for Attack Surface Management Technology

Michigan startup Censys has deposited $75 million in new funding as venture capital investors continue to bet big on technology to help organizations automate the finding and fixing of serious security problems.

Censys said the new financing included a $50 million Series C venture round and $25M in debt funding led by SVB Capital, Silicon Valley Bank.

The Series C was led by Decibel Partners, GV, Greylock and Intel Capital and included new investors Ascension Ventures and Four Rivers Partners.

Censys, based in Ann Arbor, competes with the likes of Randori, Bishop Fox, NCC Group, CyCognito and a wave of new startups hawking tools to help defenders with Internet-wide scans for exposed corporate assets.

The company claims it has built the most complete and accurate collection of global internet infrastructure data and provides technology to enrich the data with context to drive security decisions.

Since its last raise, a $35 million round led by Intel Capital, Censys said it recorded 130% annual recurring revenue (ARR) growth, a key metric used by subscription-based SaaS companies.

Censys counts prominent organizations like Google, NATO, the Swiss Armed Forces, and the U.S. Department of Homeland Security among its customer base.

Advertisement. Scroll to continue reading.

The attack surface management category has grown in importance to solve problems with vulnerability and patch management, especially for software and other assets that are exposed to the internet.

Related: Censys Scores $35M Series B Investment

Related: CyCognito Snags $100M Investment for Attack Surface Management 

Related: Microsoft to Acquire Threat Intelligence Vendor RiskIQ

Related: The Rise of Continuous Attack Surface Management

https://www.securityweek.com/censys-banks-75m-for-attack-surface-management-technology/




VMware vCenter Flaw So Critical, Patches Released for End-of-Life Products

Virtualization technology powerhouse VMware is calling urgent attention to a critical remote code execution flaw haunting its vCenter Server and VMware Cloud Foundation products.

The company said the vulnerability, tagged as CVE-2023-34048, allows a malicious hacker with network access to launch remote code execution exploits.

A critical-severity advisory from VMware described the bug as an out-of-bounds write issue in its implementation of the DCE/RPC protocol.  The company flagged the bug with a CVSS severity score of 9.8/10.

Due to the critical nature of this issue, VMware also released patches for older, end-of-life products, including vCenter Server 6.7U3, 6.5U3, VCF 3.x, and vCenter Server 8.0U1. Asynchronous vCenter Server patches for VCF 5.x and 4.x are also available.

The bulletin also documents a second moderate-severity flaw — CVE-2023-34056 — that could lead to the partial disclosure of information.

A malicious actor with non-administrative privileges can exploit this to access unauthorized data, VMware said, urging vCenter Server and Cloud Foundation users to urgently apply the available updates.

In a separate advisory covering security problems in VMware Aria Operations for Logs, the company warned that exploit code for an authentication bypass flaw has been published online, adding to the urgency to apply available patches.

Advertisement. Scroll to continue reading.

“An unauthenticated, malicious actor can inject files into the operating system of an impacted appliance which can result in remote code execution,” VMWare warned.

The VMware Aria Operations for Logs vulnerability, tracked as CVE-2023-34051, carries a maximum CVSSv3 base score of 8.1/10.  

Related: Exploit Code Published for Critical-Severity VMware Security Defect

Related: VMware Patches Major Security Flaws in Network Monitoring Product

Related: VMware Patches Code Execution Vulnerabilities in vCenter Server

Related:VMware Confirms Live Exploits Hitting Just-Patched Security Flaw

https://www.securityweek.com/vmware-vcenter-flaw-so-critical-patches-released-for-end-of-life-products/




Number of Cisco Devices Hacked via Zero-Day Remains High as Attackers Update Implant

The number of Cisco devices hacked through the exploitation of two new zero-day vulnerabilities remains very high, but recent scans appeared to show a significant drop due to the attackers updating their implant.

Unidentified hackers have been exploiting the Cisco IOS XE vulnerabilities tracked as CVE-2023-20198 and CVE-2023-20273 to create high-privileged accounts on affected devices and deploy a Lua-based backdoor implant that gives them complete control of the system. 

Patches are now available for both vulnerabilities. 

Shortly after Cisco disclosed the existence of the first flaw, the cybersecurity community started scanning the internet for compromised devices and quickly found that as many as 50,000 switches and routers had the malicious implant. 

A few days later, the scans showed that the number of hacked devices dropped to 100, with some speculating that the attackers were trying to hide the implant. The security community warned that many devices were likely still compromised, even if they did not show up during scans.

Cisco and others have confirmed that the attackers have updated the implant and compromised devices cannot be identified any longer using the initial scan method.

However, NCC Group-owned security firm Fox-IT found a new fingerprinting method and identified nearly 38,000 Cisco devices still hosting the implant. 

Advertisement. Scroll to continue reading.

Vulnerability intelligence firm VulnCheck has confirmed that thousands of devices are still under the attackers’ control.

Cisco has confirmed uncovering a new variant that “hinders identification of compromised systems”.  This second version, which attackers started deploying on October 20, has roughly the same core functionality, but adds a preliminary check for a specific HTTP authorization header.  

“The addition of the header check in the implant by the attackers is likely a reactive measure to prevent identification of compromised systems. This header check is primarily used to thwart compromise identification using a previous version of the curl command provided by Talos. Based on the information assessed to date, we believe the addition of the header check in the implant likely resulted in a recent sharp decline in visibility of public-facing infected systems,” Cisco explained.

The networking giant has shared indicators of compromise (IoCs) and instructions for checking whether a device has been hacked. 

It’s worth noting that the implant deployed by the threat actor is not persistent — it gets removed if the device is rebooted — but the high-privileged account created through the exploitation of CVE-2023-20198 remains on the device even after it has been restarted. 

This malicious campaign is reminiscent of the recent operation in which a China-linked APT targeted Barracuda ESG appliances. The attackers gained deep access to targeted systems, to the point where the vendor and the FBI urged victims to replace compromised devices

Related: Cisco Warns of IOS Software Zero-Day Exploitation Attempts

Related: Cisco ASA Zero-Day Exploited in Akira Ransomware Attacks

https://www.securityweek.com/number-of-cisco-devices-hacked-via-zero-day-remains-high-as-attackers-update-implant/