Adobe Says Critical PDF Reader Zero-Day Being Exploited 

Software maker Adobe on Tuesday raised an alarm about new in-the-wild zero-day attacks hitting users of its widely deployed Adobe Acrobat and Reader product.

As part of its scheduled batch of Patch Tuesday updates, Adobe warned that hackers are exploiting a remotely exploitable vulnerability — CVE-2023-26369 — to launch code execution attacks.

Adobe describes the flaw as an out-of-bounds write memory safety issue affecting both Windows and macOS installations.

“Successful exploitation could lead to arbitrary code execution. Adobe is aware that CVE-2023-26369 has been exploited in the wild in limited attacks targeting Adobe Acrobat and Reader,” the company said in an advisory.

Adobe did not specify which operating system is being targeted by in-the-wild attackers.

The Adobe Acrobat and Reader patch headlines a Patch Tuesday release that provides fixes for at least five documented flaws across multiple products.

The company also pushed out a security update for Adobe Connect to fix a pair of bugs that could be exploited to launch arbitrary code execution attacks.   

Advertisement. Scroll to continue reading.

A separate patch was rolled out to fix two documented flaws in Adobe Experience Manager (AEM) and warned that successful exploitation of these vulnerabilities could result in arbitrary code execution.

So far this year, there has 64 documented in-the-wild zero-day attacks hitting a wide range of software products, according to data tracked by SecurityWeek.

Related: Patch Tuesday: Adobe Patches 30 Acrobat, Reader Vulns

Related: Adobe Patch Tuesday: Critical Flaws Haunt InDesign, ColdFusion

Related: Adobe Patch Tuesday: Code Execution Flaws in Acrobat, Reader

https://www.securityweek.com/adobe-says-critical-pdf-reader-zero-day-being-exploited/




Thousands of Code Packages Vulnerable to Repojacking Attacks

Despite GitHub’s efforts to prevent repository hijacking, cybersecurity researchers continue finding new attack methods, and thousands of code packages and millions of users could be at risk.

Repojacking is a repository hijacking method that involves renamed GitHub usernames. If a user renames their account, their old username can be registered by someone else, including malicious actors, and potentially abused for supply chain attacks.

Threat actors may be able to register an old username and create repositories that were previously associated with the old username, which could allow them to route traffic intended for the legitimate repository to their malicious repository. 

In order to prevent such attacks, GitHub has been implementing a retired namespace protection mechanism and it has been warning users about the potential risks associated with changing usernames. 

The namespace is the combination between the username and a specific repository name — for example, github.com/username/repo_name. If a user changes the username, the old username’s new owner cannot create a repository named ‘repo_name’ if the repository was previously cloned 100 times. This means that GitHub has retired the namespace. 

The problem is that researchers continue finding ways to bypass GitHub’s namespace retirement mechanism and conduct repojacking. 

The most recently disclosed attack method was discovered by researchers at cybersecurity firm Checkmarx in March and it was recently fixed by GitHub. 

This new method leveraged a race condition, with an API request being used to almost simultaneously create a new repository and change the account’s username. 

Advertisement. Scroll to continue reading.

If the attacker renames their account to the targeted username and later attempts to create a repository that would result in the creation of a retired namespace, their attempt would be blocked.

However — before GitHub rolled out a fix — if the account renaming and the repository creation were done at the same time, the attempt would be successful, enabling the attacker to obtain a namespace that would allow them to redirect traffic to their malicious repository. 

Checkmarx’s analysis showed that roughly 4,000 code packages in Go, PHP, Swift, as well as GitHub Actions were impacted, including hundreds of packages with more than 1,000 stars. 

“Poisoning a popular GitHub action could lead to major Supply Chain attacks with significant repercussions,” Checkmarx warned. 
The problem is that these packages will continue to be vulnerable to repojacking if a new bypass method is discovered in the future. 

“The discovery of this novel vulnerability in GitHub’s repository creation and username renaming operations underlines the persistent risks associated with the ‘Popular repository namespace retirement’ mechanism,” Checkmarx said in a blog post.

It added, “Many GitHub users, including users that control popular repositories and packages, choose to use the ‘User rename’ feature GitHub offers. For that reason, the attempt to bypass the ‘Popular repository namespace retirement’ remains an attractive attack point for supply chain attackers with the potential to cause substantial damages.”

The security firm has released an open source tool named ChainJacking that can be used to identify vulnerable packages. 

Related: Developers Warned of Malicious PyPI, NPM, Ruby Packages Targeting Macs

Related: ChatGPT Hallucinations Can Be Exploited to Distribute Malicious Code Packages

Related: Malicious NuGet Packages Used to Target .NET Developers

https://www.securityweek.com/thousands-of-code-packages-vulnerable-to-repojacking-attacks/




Vulnerabilities Allow Hackers to Hijack, Disrupt Socomec UPS Devices

Some uninterruptible power supply (UPS) products made by Socomec are affected by several vulnerabilities that can be exploited to hijack and disrupt devices.

Socomec is a France-based electrical equipment manufacturing company that specializes in low voltage energy performance. Its offering includes modular UPS devices that are used by businesses in various sectors around the world.

Aaron Flecha Menendez, an ICS security consultant at Spain-based cybersecurity firm S21sec, discovered that some Socomec UPS devices, specifically MODULYS GP (MOD3GP-SY-120K), are affected by seven vulnerabilities.

The list includes cross-site scripting (XSS), plaintext password storage, code injection, session cookie theft, cross-site request forgery (CSRF), and insecure storage of sensitive information, with severities ranging from ‘medium’ to ‘critical’.

US cybersecurity agency CISA last week published an advisory to notify organizations about these vulnerabilities, pointing out that the impacted product has reached end of life. 

Organizations have been advised by the vendor to stop using the outdated product and upgrade to MODULYS GP2 (M4-S-XXX), which should not be impacted by the security flaws.

Businesses still using the vulnerable product could be exposing themselves to significant risks, as the security holes can allow an attacker who has knowledge of how the system works to modify its behavior and prevent it from functioning properly. 

“Among the scenarios that can be achieved, the worst-case scenario would undoubtedly be disrupting the UPS management and affecting its ability to provide backup power,” Flecha Menendez told SecurityWeek.

Advertisement. Scroll to continue reading.

Fortunately, there do not appear to be any vulnerable UPS products that are directly exposed to the internet. However, an attacker who is inside the targeted organization’s network could chain some of the MODULYS GP vulnerabilities for a higher impact.

“The use of the ‘unsafe storage of sensitive information’ vulnerability (CVE-2023-41965), allows obtaining a valid session cookie that does not expire (CVE-2023-41084), which can then be used for remote code injection (CVE-2023-40221). The combination of these 3 vulnerabilities would allow the attacker to gain full control of the device at the management level and affect its correct functioning,” the researcher explained. 

The researcher has not tested the newer product models so he cannot confirm that they are indeed not affected by the vulnerabilities, as claimed by the vendor. 

It’s important that organizations using the vulnerable product take action, as attacks targeting UPS devices are not unheard of. The US government last year issued a warning to businesses about such attacks, providing guidance on how the threat can be mitigated. 

Related: Power Management Product Flaws Can Expose Data Centers to Damaging Attacks, Spying

Related: CISA Informs Organizations of Flaws in Unsupported Industrial Telecontrol Devices

Related: Millions of APC Smart UPS Devices Can Be Remotely Hacked, Damaged

https://www.securityweek.com/vulnerabilities-allow-hackers-to-hijack-disrupt-socomec-ups-devices/




Cisco ASA Zero-Day Exploited in Akira Ransomware Attacks

Cisco this week raised the alarm on a zero-day in Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) software that has been exploited in Akira ransomware attacks since August.

Tracked as CVE-2023-20269 (CVSS score of 5.0, medium severity), the issue exists in the remote access VPN feature of Cisco ASA and FTD and can be exploited remotely, without authentication, in brute force attacks. 

“This vulnerability is due to improper separation of authentication, authorization, and accounting (AAA) between the remote access VPN feature and the HTTPS management and site-to-site VPN features,” Cisco explains in an advisory.

To exploit this vulnerability during a brute force attack, an unauthenticated, remote attacker needs to specify a default connection profile/tunnel group, which would allow them to identify valid username-password pairs.

According to Cisco, an attacker with access to valid user credentials can exploit the flaw to establish a clientless SSL VPN session with an unauthorized user.

The tech giant notes that this vulnerability cannot be exploited to establish a client-based remote access VPN tunnel or to bypass authentication.

The vulnerability is exploitable in brute force attacks if an affected device has a user configured “with a password in the local database or HTTPS management authentication points to a valid AAA server” and if “SSL VPN is enabled on at least one interface or IKEv2 VPN is enabled on at least one interface”.

Advertisement. Scroll to continue reading.

To establish a clientless SSL VPN session by exploiting this bug, four conditions need to be met: the attacker needs valid credentials, the device is running Cisco ASA version 9.16 or earlier, SSL VPN needs to be enabled on at least one interface, and the clientless SSL VPN protocol needs to be allowed.

Devices running Cisco FTD are not susceptible to this attack as FTD does not offer support for clientless SSL VPN sessions.

The company is working on security updates to address the vulnerability in both Cisco ASA and FTD software.

Cisco says it first identified the vulnerability last month, when investigating Akira ransomware attacks in which organizations were compromised via Cisco VPNs that lacked multi-factor authentication.

“In August 2023, the Cisco Product Security Incident Response Team (PSIRT) became aware of attempted exploitation of this vulnerability in the wild. Cisco strongly recommends that customers upgrade to a fixed software release to remediate this vulnerability once available and apply one of the suggested workarounds in the meantime,” Cisco notes.

The tech giant has provided a list of indicators of compromise (IoCs) to help organizations identify potential malicious activity, as well as details on how organizations can protect against the clientless SSL VPN session exploitation of the bug.

Related: Cisco Patches Critical Vulnerability in BroadWorks Platform

Related: Cisco Patches Vulnerabilities Exposing Switches, Firewalls to DoS Attacks

Related: Dozens of Organizations Targeted by Akira Ransomware

https://www.securityweek.com/cisco-asa-zero-day-exploited-in-akira-ransomware-attacks/




In Other News: LastPass Vault Hacking, Russia Targets Ukraine Energy Facility, NXP Breach 

SecurityWeek is publishing a weekly cybersecurity roundup that provides a concise compilation of noteworthy stories that might have slipped under the radar.

We provide a valuable summary of stories that may not warrant an entire article, but are nonetheless important for a comprehensive understanding of the cybersecurity landscape.

Each week, we will curate and present a collection of noteworthy developments, ranging from the latest vulnerability discoveries and emerging attack techniques to significant policy changes and industry reports.

Here are this week’s stories:  

SentinelOne ends Wiz collaboration following acquisition rumors

SentinelOne has ended its collaboration with cloud security firm Wiz following reports of a potential merger valued at $5-6 billion. SentinelOne shut down the rumors that it’s being acquired by Wiz a few days later, when it announced its decision to unilaterally terminate its six-month-old partnership with Wiz “as a result of their continued lack of execution against their commitments”.

Hackers may be breaking into LastPass vaults compromised in data breach 

Advertisement. Scroll to continue reading.

Some experts believe that threat actors may be breaking into the LastPass vaults compromised in a data breach last year, security blogger Brian Krebs reported. An investigation showed that many security-conscious individuals who had a total of $35 million worth of cryptocurrency stolen from them had used LastPass to store their private key.

Semiconductor company NXP discloses data breach

Dutch semiconductor designer and manufacturer NPX has disclosed a data breach affecting the email addresses of users who had registered an account on npx.com, but had not used it for at least 18 months. No other information was exposed, NPX said. 

Data breach at golf equipment maker Callaway impacts one million people

Callaway, a company that makes clubs, balls and other golf equipment, has disclosed a data breach affecting more than one million people. The firm said it discovered unauthorized access to information such as name, email address, phone number, order history, password, and security question answer. 

New report details how China is weaponizing software vulnerabilities

A new report from the Atlantic Council details how China is weaponizing software vulnerabilities, often leveraging the fact that entities are required by law to report flaws to the Ministry of Industry and Information Technology (MIIT) within 48 hours of their discovery. 

Vulnerability in Mend.io application security platform

WithSecure has found and disclosed a vulnerability in a Mend.io platform designed to help software developers identify and address vulnerabilities in code libraries. An attacker could have accessed the data of other Mend.io users in the same SaaS environment by needing only a valid email address associated with the victim. 

Flipper Zero used for targeting Apple devices via Bluetooth 

A researcher has demonstrated how the Flipper Zero hacking device can be used to spam Apple phones and tablets via Bluetooth advertising packets. An attacker can use the method for pranks (get notifications to pop up on nearby devices), but the researcher has also promised to show how it can be leveraged for more malicious purposes. 

MinIO vulnerabilities exploited for new cloud attack vector

Two vulnerabilities patched in March in the MinIO object storage suite have been exploited in what researchers described as a new vector for cloud attacks. In observed attacks, threat actors exploited CVE-2023-28434 and CVE-2023-28432 to replace the original MinIO executable with an evil version containing a backdoor. 

Russian APT targets energy facility in Ukraine

Ukraine’s government computer emergency response team CERT-UA said it spotted an attack launched by Russian state-sponsored threat group APT28 against an energy facility in the country. CERT-UA’s report describes the initial stages of the attack and it’s unclear if the attackers may have been trying to target ICS and cause a power outage, as they did in the past. 

Interesting dynamically seeded DGAs

Akamai researchers have analyzed the dynamically seeded domain generation algorithm (DGA) used by the Pushdo and Necurs botnets and observed interesting behaviors that suggest cybercriminals are trying to extend the lifespan of C&C channels and avoid detection. 

W3LL phishing kit used to target corporate Microsoft 365 accounts 

A custom phishing kit called W3LL Panel has been acquired by at least 500 threat actors and used to target over 56,000 corporate Microsoft 365 accounts, according to Group-IB. The cybersecurity firm estimates that the W3LL tool’s developers may have made $500,000 in the last 10 months. 

TXOne Networks announces new Edge v2 engine

Industrial cybersecurity firm TXOne Networks has announced the second generation of its Edge engine. The Edge v2 engine enables network segmentation via automated rule generation and learning. 

Related: In Other News: Hacking Encrypted Linux Computers, Android Fuzzing, Skype Leaking IPs

Related: In Other News: Africa Cybercrime Crackdown, Unpatched macOS Flaw, Investor Disclosures

https://www.securityweek.com/in-other-news-lastpass-vault-hacking-russia-targets-ukraine-energy-facility-nxp-breach/




Apple Patches Actively Exploited iOS, macOS Zero-Days

Apple on Thursday pushed out an urgent point-update to its flagship iOS and macOS platforms to fix a pair of security defects being exploited in the wild.

The vulnerabilities, fixed in the latest iOS 16.6.1 and macOS Ventura 13.5.2 releases, are credited to the Citizen Lab at The University of Torontoʼs Munk School, suggesting exploitation in commercial surveillance spyware products.

The Citizen Lab at The University of Torontoʼs Munk School actively tracks PSOAs (private sector offensive actors) and the expanding market for companies that sell hacking and exploitation tools and services.

According to an advisory from Cupertino’s security response team, both flaws could be exploited via rigged image files to launch code execution attacks.

From the bulletin:

  • CVE-2023-41064 (ImageIO) — A Processing a maliciously crafted image may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited. A buffer overflow issue was addressed with improved memory handling.
  • CVE-2023-41061 (Wallet) — A maliciously crafted attachment may result in arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited. A validation issue was addressed with improved logic.

Emergency patches for zero-day iOS and macOS flaws have become a regular occurrence as Apple struggles to keep pace with highly skilled attackers.

So far this year, Apple has rolled out fixes for 13 documented in-the-wild zero-days in iOS, iPadOS and macOS platforms.  The company has also shipped ‘Lockdown Mode’ in direct response to these attacks but the pace of exploitation has not slowed.

UPDATE: Citizen Lab has confirmed that these flaws were captured during exploitation activity linked to NSO Group’s Pegasus mercenary spyware.

Advertisement. Scroll to continue reading.

“Last week, while checking the device of an individual employed by a Washington DC-based civil society organization with international offices, Citizen Lab found an actively exploited zero-click vulnerability being used to deliver NSO Group’s Pegasus mercenary spyware,” Citizen Group said.

The research unit tagged the exploit chain as BLASTPASS and said it was capable of compromising iPhones running the latest version of iOS (16.6) without any interaction from the victim.

Citizen Lab warned that the exploit involved PassKit attachments containing malicious images sent from an attacker iMessage account to the victim.

Related: Apple Patches New macOS, iOS Zero-Days

Related: Apple Ships Urgent Fix for Under-Attack iOS Zero-Day

Related: Apple Ships Emergency Fixes for Exploited iOS Zero-Day

elated: Google Spots Attacks Exploiting iOS Zero-Day Flaws

https://www.securityweek.com/apple-patches-actively-exploited-ios-macos-zero-days/




Rigged Software and Zero-Days: North Korean APT Caught Hacking Security Researchers

Google’s threat hunting unit has again intercepted an active North Korean APT actor sliding into the DMs of security researchers and using zero-days and rigged software tools to take control of their computers.

Google’s Threat Analysis Group (TAG) on Thursday outed the government-backed hacking team’s social media accounts and warned that at least one actively exploited zero-day is being used and is currently unpatched.

Using platforms like X (the successor to Twitter) as their initial point of contact, the North Korean threat actor cunningly forged relationships with targeted researchers through prolonged interactions and discussions.

“In one case, they carried on a months-long conversation, attempting to collaborate with a security researcher on topics of mutual interest. After initial contact via X, they moved to an encrypted messaging app such as Signal, WhatsApp or Wire. Once a relationship was developed with a targeted researcher, the threat actors sent a malicious file that contained at least one 0-day in a popular software package,” Google explained.

Google did not identify the vulnerable software package.

Google said the zero-day exploit was used to plant shellcode that conducts a series of anti-virtual machine checks and then sends the collected information, along with a screenshot, back to an attacker-controlled command and control domain. 

“The shellcode used in this exploit is constructed in a similar manner to shellcode observed in previous North Korean exploits,” Google said, noting that the security defect has been reported to the affected vendor and is in the process of being patched. 

Advertisement. Scroll to continue reading.

Google said it is withholding technical details and analysis of the exploits until a patch is available. 

In addition to targeting researchers with zero-day exploits, Google’s malware hunters also caught the APT group distributing a standalone Windows tool that has the stated goal of ‘download debugging symbols from Microsoft, Google, Mozilla and Citrix symbol servers for reverse engineers.’ 

The source code for the utility, was first published on GitHub a year ago,  has been updated multiple times with features to help with the quick and easy downloading symbol information from a number of different sources. 

However, Google warns that the tool has been rigged to hijack data from user machines.

“The tool also has the ability to download and execute arbitrary code from an attacker-controlled domain. If you have downloaded or run this tool, TAG recommends taking precautions to ensure your system is in a known clean state, likely requiring a reinstall of the operating system,” Google said.

This isn’t the first documented case of North Korean government hackers targeting security researchers, particularly those that operate in the offensive space.

In January 2021, Google caught a “government-backed entity based in North Korea” targeting and hacking into computer systems belonging to security researchers working on vulnerability research and development at different companies and organizations.

That campaign, which was well organized across multiple online platforms, included drive-by browser compromises from booby-trapped websites and sustained direct-touch activities on social media websites.

Related: North Korean Hackers Caught Rigging Legit Software

Related: North Korea Lazarus Behind $100 Million Horizon Bridge Heist

Related: DPRK Gov Hackers Caught Sharing Chrome Zero-Day

Related: Google: North Korean Gov Hackers Targeting Security Researchers

https://www.securityweek.com/rigged-software-and-zero-days-north-korean-apt-caught-hacking-security-researchers/




Cisco Patches Critical Vulnerability in BroadWorks Platform

Cisco on Wednesday announced patches for a critical-severity vulnerability in the BroadWorks Application Delivery Platform and BroadWorks Xtended Services Platform.

Tracked as CVE-2023-20238, the vulnerability affecting the BroadWorks calling and collaboration platform was identified in the single sign-on (SSO) implementation and could be exploited by remote, unauthenticated attackers to forge credentials and access affected systems.

“This vulnerability is due to the method used to validate SSO tokens. An attacker could exploit this vulnerability by authenticating to the application with forged credentials. A successful exploit could allow the attacker to commit toll fraud or to execute commands at the privilege level of the forged account,” Cisco explains in an advisory.

The tech giant notes that the attacker would need a valid user ID associated with the affected BroadWorks system to exploit the flaw. Despite this condition, the vulnerability has a CVSS score of 10.0.

The issue, Cisco says, impacts affected BroadWorks releases running AuthenticationService, BWCallCenter, BWReceptionist, CustomMediaFilesRetrieval, ModeratorClientApp, PublicECLQuery, PublicReporting, UCAPI, Xsi-Actions, Xsi-Events, Xsi-MMTel, or Xsi-VTR.

Cisco BroadWorks Application Delivery Platform and BroadWorks Xtended Services Platform version AP.platform.23.0.1075.ap385341 resolves the vulnerability. Cisco also announced independent releases 2023.06_1.333 and 2023.07_1.332 that contain the necessary patches.

On Wednesday, Cisco also released patches for a high-severity denial-of-service (DoS) vulnerability in the Identity Services Engine (ISE).

Advertisement. Scroll to continue reading.

Tracked as CVE-2023-20243, the issue exists because certain RADIUS accounting requests are not handled properly. An attacker sending crafted requests to a network access device that uses Cisco ISE directly could cause the RADIUS process to restart, denying user access to the network or service.

The vulnerability impacts Cisco ISE versions 3.1 and 3.2 only and was addressed with the release of Cisco ISE versions 3.1P7 and 3.2P3.

The tech giant says it is not aware of any of these vulnerabilities being exploited in malicious attacks.

Additional information can be found on Cisco’s product security page.

Related: Cisco Patches Vulnerabilities Exposing Switches, Firewalls to DoS Attacks

Related: Cisco Patches High-Severity Vulnerabilities in Enterprise Applications

Related: PoC Exploit Published for Cisco AnyConnect Secure Vulnerability

https://www.securityweek.com/cisco-patches-critical-vulnerability-in-broadworks-platform/




Chrome 116 Update Patches High-Severity Vulnerabilities

Google on Tuesday announced the release of a Chrome 116 update that patches four high-severity vulnerabilities reported by external researchers.

Tracked as CVE-2023-4761, the first bug is described as an out-of-bounds memory access issue in the FedCM (Federated Credential Management) API.

Out-of-bounds memory access errors occur when a program reads memory addresses outside of the bounds of a buffer, which could ultimately allow an attacker to cause a denial-of-service (DoS) condition or exploit additional weaknesses to achieve code execution.

The second flaw is a type confusion issue in the V8 JavaScript engine. Tracked as CVE-2023-4762, the vulnerability could lead to out-of-bounds memory access.

The third bug, CVE-2023-4763, is a use-after-free issue in Chrome’s Networks component, Google’s advisory reads.

A type of memory corruption bugs, use-after-free issues can be exploited to execute arbitrary code or cause a DoS condition and, if combined with other vulnerabilities, could lead to full system compromise.

In Chrome, use-after-free flaws can be combined with bugs in the browser process or with issues in the underlying operating system to escape Chrome’s sandbox.

Advertisement. Scroll to continue reading.

The fourth vulnerability patched with this Chrome 116 update is CVE-2023-4764, an incorrect security UI flaw in BFCache (the in-memory cache where a complete snapshot of a page is stored), allowing a remote attacker to use a crafted HTML page to spoof the contents of the URL bar (Omnibox).

Google has yet to determine the bug bounty rewards the reporting researchers will receive for their findings.

The latest Chrome iteration is now rolling out as version 116.0.5845.179 for macOS and Linux and as versions 116.0.5845.179/.180 for Windows.

The internet giant also announced that the Chrome Extended Stable channel was updated to version 116.0.5845.179 for macOS and to version 116.0.5845.180 for Windows.

Google makes no mention of any of these vulnerabilities being exploited in malicious attacks.

Related: High-Severity Memory Corruption Vulnerabilities Patched in Firefox, Chrome

Related: First Weekly Chrome Security Update Patches High-Severity Vulnerabilities

Related: Chrome 116 Patches 26 Vulnerabilities

https://www.securityweek.com/chrome-116-update-patches-high-severity-vulnerabilities/




AtlasVPN to Patch IP Leak Vulnerability After Public Disclosure

AtlasVPN developers are working on a patch for an IP leak vulnerability whose details were made public by a researcher who decided to take the full disclosure route after responsible disclosure attempts were ignored.

The researcher, who apparently wants to remain anonymous, shared the details on the Full Disclosure mailing list and on Reddit, claiming that he had unsuccessfully attempted to contact AtlasVPN support in an effort to find a security contact or an official channel for reporting the vulnerability.

The security hole impacts the AtlasVPN Linux client and it can be exploited by luring the targeted user to a website hosting the exploit code. 

The exploit causes AtlasVPN to disconnect, which results in the user’s real IP address being leaked to the attacker’s website.

“The AtlasVPN Linux Client consists of two parts. A daemon (atlasvpnd) that manages the connections and a client (atlasvpn) that the user controls to connect, disconnect and list services. The client does not connect via a local socket or any other secure means but instead it opens an API on localhost on port 8076,” the researcher explained. 

“It does not have ANY authentication. This port can be accessed by ANY program running on the computer, including the browser. A malicious javascript on ANY website can therefore craft a request to that port and disconnect the VPN,” the researcher added.

The exploit code has been made public and it’s not difficult to use for malicious purposes. An attacker simply needs to upload it to a site they control. 

Advertisement. Scroll to continue reading.

After the findings were made public and AtlasVPN was contacted for comment by SecurityWeek, the company apologized for its slow reaction and promised to improve its vulnerability reporting process.

AtlasVPN told SecurityWeek in an emailed statement that it does take security and user privacy seriously and it’s actively working on a patch. Impacted users will be prompted to update their Linux app to the latest version as soon as the fix becomes available. 

“The vulnerability affects Atlas VPN Linux client version 1.0.3. As the researcher stated, due to the vulnerability, the application and, hence, encrypted traffic between a user and the VPN gateway can be disconnected by a malicious actor. This could lead to the user’s IP address disclosure,” AtlasVPN said. 

“We greatly appreciate the cybersecurity researchers’ vital role in identifying and addressing security flaws in systems, which helps safeguard against potential cyberattacks, and we thank them for bringing this vulnerability to our attention. We will implement more security checks in the development process to avoid such vulnerabilities in the future. Should anyone come across any other potential threats related to our service, please contact us via security(at)atlasvpn.com,” it added.

Related: Is Enterprise VPN on Life Support or Ripe for Reinvention?

Related: Fortinet Patches Critical FortiGate SSL VPN Vulnerability

Related: In Other News: macOS Security Reports, Keyboard Spying, VPN Vulnerabilities 

https://www.securityweek.com/atlasvpn-to-patch-ip-leak-vulnerability-after-public-disclosure/